← Back to home

Wells CollegeHigher Education

EIN: 150532276

UEI: L7Z6C842FBY5

Audited by: Bonadio & Co., LLP

Oversight agency: 84 [Department of Education]

View federal awards & risk assessment →

Data as of August 31, 2026

Wells College8 audit years1 findings
8
Audit Years
1
Total Findings
0
Repeat Findings
$4.2M
Federal Awards Expended (FY 2023)

FY 2023-06-30

LOW-RISK AUDITEE$4,174,195 federal awards expended

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on February 16, 2024. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by August 16, 2024 (747 days ago).

What is a management decision? →
2023-001
Special Tests & Provisions
SIGNIFICANT DEFICIENCYOTHER MATTERS

Finding 2023-001 – Student Financial Assistance Cluster Federal Agency – U.S. Department of Education Grant Period – Year ended June 30, 2023 Compliance Requirement – N. Gramm-Leach-Bliley Act–Student Information Security Criteria – Institutions participating in Title IV programs are required to comply with various laws and regulations as part of their signed Program Participation Agreement (PPA), including but not limited to, the Federal Trade Commission’s Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition – The College has not performed a formal risk assessment of their technology environment since 2018. In addition, the College’s written information security program (WISP) has not been updated and does not address the seven required minimum elements per the 2023 Compliance Supplement. Cause – The College had not performed any additional review or updates since 2018 to its WISP and/or risk assessment to include the required elements or document any updates to the College’s Information Technology (IT) environment. Effect – The College was not in compliance with the Department of Education’s requirements for GLBA. Recommendation – The College needs to conduct a formal risk assessment and update its WISP to ensure the seven required elements are addressed. As part of this process, IT policies should be updated to align with the College’s current IT environment and be formally approved and implemented throughout the College.

Show full finding ▾
Full finding narrative

Finding 2023-001 – Student Financial Assistance Cluster Federal Agency – U.S. Department of Education Grant Period – Year ended June 30, 2023 Compliance Requirement – N. Gramm-Leach-Bliley Act–Student Information Security Criteria – Institutions participating in Title IV programs are required to comply with various laws and regulations as part of their signed Program Participation Agreement (PPA), including but not limited to, the Federal Trade Commission’s Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition – The College has not performed a formal risk assessment of their technology environment since 2018. In addition, the College’s written information security program (WISP) has not been updated and does not address the seven required minimum elements per the 2023 Compliance Supplement. Cause – The College had not performed any additional review or updates since 2018 to its WISP and/or risk assessment to include the required elements or document any updates to the College’s Information Technology (IT) environment. Effect – The College was not in compliance with the Department of Education’s requirements for GLBA. Recommendation – The College needs to conduct a formal risk assessment and update its WISP to ensure the seven required elements are addressed. As part of this process, IT policies should be updated to align with the College’s current IT environment and be formally approved and implemented throughout the College.

Corrective Action Plan

Wells College (the College) respectfully submits the following corrective action plan for the year ended June 30, 2023. Name and address of independent public accounting firm: Bonadio & Co., LLP 432 North Franklin Street #60 Syracuse, New York 13204 Audit period: July 1, 2022 - June 30, 2023 The findings from the 2023 schedule of findings and questioned costs are discussed below. The findings are numbered consistently with the numbers assigned in the schedule. FINDINGS AND QUESTIONED COSTS - MAJOR FEDERAL AWARD PROGRAMS AUDIT Finding 2023-001 - Student Financial Assistance Cluster Compliance Requirement N. Gramm-Leach-Bliley Act-Student Information Security Recommendation: Our auditors recommend that we conduct a formal risk assessment and update our written information security program (WISP) to ensure the seven required elements are addressed. As part of this process, Information Technology (IT) policies should be updated to align with our current IT environment and be formally approved and implemented throughout the College. Action Taken: Wells College is partnering with Grey Castle Security to do a Risk Assessment and Penetration test. This will be completed in February. Additionally, Grey Castle has helped to redraft our Incident Response Plan. This has been completed, and training on this plan is scheduled for later in January, with Tabletop simulations occurring with the Wells College Emergency Planning Team and IT in February. Over the next couple of months, IT will be refreshing its policies in collaboration with the Wells College Technology Advisory Group (TAG), a committee representing all areas of the college. Once TAG has approved policies, they will go to the Cabinet for approval. Multiple policies will be merged to create the WISP as a self-contained document, rather than the multiple policies in place. The Chief Financial Officer, Robert Cree, is responsible for implementing this plan by June 30, 2024, and can be reached at (315) 364-3408 or rcree@wells.edu .

About Special Tests and Provisions →

FY 2022-06-30

LOW-RISK AUDITEE$5,737,511 federal awards expendedNo findings recorded this year

FAC accepted this audit on October 18, 2022 — management decision was due April 18, 2023.

FY 2021-06-30

LOW-RISK AUDITEE$5,123,388 federal awards expendedNo findings recorded this year

FAC accepted this audit on November 30, 2021 — management decision was due May 30, 2022.

FY 2020-06-30

LOW-RISK AUDITEE$5,091,069 federal awards expendedNo findings recorded this year

FAC accepted this audit on April 15, 2021 — management decision was due October 15, 2021.

FY 2019-06-30

LOW-RISK AUDITEE$5,367,281 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 4, 2020 — management decision was due August 4, 2020.

FY 2018-06-30

LOW-RISK AUDITEE$5,664,795 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 18, 2019 — management decision was due August 18, 2019.

FY 2017-06-30

LOW-RISK AUDITEE$6,015,730 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 5, 2018 — management decision was due August 5, 2018.

FY 2016-06-30

LOW-RISK AUDITEE$6,522,590 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 8, 2017 — management decision was due August 8, 2017.

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Browse other Single Audit organizations in New York

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and filing records.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.