EIN: 160928736
UEI: JS2HEZCF5346
Audited by: Bonadio & Co., LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of August 28, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on May 30, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by November 30, 2026 (92 days from today).
What is a management decision? →FAC accepted this audit on May 30, 2025 — management decision was due November 30, 2025.
Finding 2024-002 – 84.425 COVID-19 Education Stabilization Fund Federal Agency – U.S. Department of Education Grant Period – Year ended August 31, 2023 Compliance Requirement – C. Cash Management L. Reporting Criteria – A requirement of accepting the Higher Education Emergency Relief Fund (HEERF) award is to minimize the time between drawing down funds from G5 and paying obligations. Institutional funds specifically require funds to be drawn and applied to allowable disbursements within three business days and reporting requirements which state that the College must conspicuously post the quarterly reports 10 days following the quarter end on the College’s website. Condition – Due to delays in reconciliations, the College was not able to gather and identify allowable expenditures. Under prior management, the funds were drawn in advance of allowable expenses charged to the grant through June 30, 2023. This therefore also resulted in the quarterly reporting due April 10 and July 10, 2023 to not be completed timely. It was also explained that management was not aware of the required quarterly reporting and therefore the reports were not completed timely and posted on the College’s website. The College was aware of the annual 2023 reporting and completed and submitted that timely. Cause – The College has experienced significant turnover in its Budget and Finance department in 2023 resulting in one individual being primarily responsible for HEERF reconciliations and reporting. Due to other delays in reconciliations, not all allowable expenses were identified within the required draw period. Effect – The College was able to reconcile the books and identify allowable expenses, however, some were incurred in June, beyond the 3 days of the draw and required quarterly reporting was not completed. Recommendation –We recommend that the College enacts policies and procedures to ensure that all accounts in the general ledger are reconciled regularly. This ensure expenses are properly identified and applied to specific grant funding for reimbursement. The College also needs to assign responsibility for required reporting to designated employees and ensure there is a process for transferring that responsibility upon turnover.
Show full finding ▾Hide full finding ▴Finding 2024-002 – 84.425 COVID-19 Education Stabilization Fund Federal Agency – U.S. Department of Education Grant Period – Year ended August 31, 2023 Compliance Requirement – C. Cash Management L. Reporting Criteria – A requirement of accepting the Higher Education Emergency Relief Fund (HEERF) award is to minimize the time between drawing down funds from G5 and paying obligations. Institutional funds specifically require funds to be drawn and applied to allowable disbursements within three business days and reporting requirements which state that the College must conspicuously post the quarterly reports 10 days following the quarter end on the College’s website. Condition – Due to delays in reconciliations, the College was not able to gather and identify allowable expenditures. Under prior management, the funds were drawn in advance of allowable expenses charged to the grant through June 30, 2023. This therefore also resulted in the quarterly reporting due April 10 and July 10, 2023 to not be completed timely. It was also explained that management was not aware of the required quarterly reporting and therefore the reports were not completed timely and posted on the College’s website. The College was aware of the annual 2023 reporting and completed and submitted that timely. Cause – The College has experienced significant turnover in its Budget and Finance department in 2023 resulting in one individual being primarily responsible for HEERF reconciliations and reporting. Due to other delays in reconciliations, not all allowable expenses were identified within the required draw period. Effect – The College was able to reconcile the books and identify allowable expenses, however, some were incurred in June, beyond the 3 days of the draw and required quarterly reporting was not completed. Recommendation –We recommend that the College enacts policies and procedures to ensure that all accounts in the general ledger are reconciled regularly. This ensure expenses are properly identified and applied to specific grant funding for reimbursement. The College also needs to assign responsibility for required reporting to designated employees and ensure there is a process for transferring that responsibility upon turnover.
Tompkins cortland community college will pass a resolution this summer requiring the comptroller's Department to reconcile monthly all accounts restricted and unrestricted in the college. ln turn the Comptroller and eventualty the vice president of Finance will be responsible to verify that the Ledger and subsidiary Ledgers are correct and fairly state the accurate financial picture of the College. The assistant comptroller will be reconciling all the college operating, capital and restricted accounts. There will be a process giving them until the 15h of every month to reconcile to the college's General Ledger. The comptroller will be signing off at all the reconciliations and relevant entries ensuring accuracy and completenessof the accounting records for the college and between component units. The principal account clerk will be reconciling all the restricted and unrestricted accounts for the Foundation and the FSA. The employee will have until the 15th of every month to reconcile all the accounts including all the Foundaiion and FSA general Ledgers. The comptroller will review and sign off on all the reconciliations and relevant journal entries ensuring accuracy and completeness of the accounting records for the Foundation, FSA and between component units. component units.
2023-002
FAC accepted this audit on May 31, 2024 — management decision was due December 1, 2024.
Criteria – Institutions participating in Title IV programs are required to comply with various laws and regulations as part of their signed Program Participation Agreement (PPA), including but not limited to, the Federal Trade Commission’s Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition – The College has not performed a formal risk assessment of their technology environment since 2018. In addition, the College’s written information security program (WISP) has not been updated and does not address the seven required minimum elements per the 2023 Compliance Supplement. Cause – The College had not performed any additional review or updates since 2018 to its WISP and/or risk assessment to include the required elements or document any updates to the College’s Information Technology (IT) environment. Effect – The College was not in compliance with the Department of Education’s requirements for GLBA. Recommendation – The College needs to conduct a formal risk assessment and update its WISP to ensure the seven required elements are addressed. As part of this process, IT policies should be updated to align with the College’s current IT environment and be formally approved and implemented throughout the College. View of Responsible Officials – The Vice President of Information Technology will designate a manager responsible for overseeing, implementing, and maintaining the College’s information security program and enforcing the information security program.
Show full finding ▾Hide full finding ▴Criteria – Institutions participating in Title IV programs are required to comply with various laws and regulations as part of their signed Program Participation Agreement (PPA), including but not limited to, the Federal Trade Commission’s Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition – The College has not performed a formal risk assessment of their technology environment since 2018. In addition, the College’s written information security program (WISP) has not been updated and does not address the seven required minimum elements per the 2023 Compliance Supplement. Cause – The College had not performed any additional review or updates since 2018 to its WISP and/or risk assessment to include the required elements or document any updates to the College’s Information Technology (IT) environment. Effect – The College was not in compliance with the Department of Education’s requirements for GLBA. Recommendation – The College needs to conduct a formal risk assessment and update its WISP to ensure the seven required elements are addressed. As part of this process, IT policies should be updated to align with the College’s current IT environment and be formally approved and implemented throughout the College. View of Responsible Officials – The Vice President of Information Technology will designate a manager responsible for overseeing, implementing, and maintaining the College’s information security program and enforcing the information security program.
• VP of IT designates a Manager responsible for overseeing, implementing, and maintaining the institution’s or servicer’s information security program and enforcing the information security program (16 C.F.R. 314.4(a)). • Provides for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution or servicer) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 C.F.R. 314.4(b)). • Provides for the design and implementation of safeguards to control the risks the institution or servicer identifies through its risk assessment (16 C.F.R. 314.4(c)). At a minimum, the written information security program must address the implementation of the minimum safeguards identified in 16 C.F.R. 314.4(c)(1) through (8). • Provides for the institution to continuously monitor vulnerabilities, or conduct annual penetration tests and systemic scans and reviews of known vulnerabilities at least every six months. (16 C.F.R. 314.4(d)). • Provides for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 C.F.R. 314.4(e)). • Addresses how the institution or servicer will oversee its information system service providers (16 C.F.R. 314.4(f)). • Provides for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the information security program (16 C.F.R. 314.4(g)). • Address the establishment of a written incident response plan (16 C.F.R. 314.4(h)). • Address the requirement for its Qualified Individual to report regularly and at least annually to The President and Board of Trustees on the institution’s information security program (16 C.F.R. 314.4(i)).
Criteria – A requirement of accepting the Higher Education Emergency Relief Fund (HEERF) award is compliance with reporting requirements which state that the College must submit an Annual Performance Report Form in March 2023 covering calendar year 2022 expenditures. Condition – Per inquiry with College management, it was noted that the Annual Performance Report Form was not submitted to the Department of Education. Cause – The College has experienced significant turnover in its Budget and Finance department in 2023 resulting in loss of institutional knowledge regarding requirements to file reports with regulatory bodies. Effect – The College was not in compliance with the Department of Education’s requirements for reporting. Recommendation – The College needs to establish and maintain a schedule for required reporting to ensure that all compliance requirements are able to be met regardless if turnover occurs. The College also needs to assign responsibility for required reporting to designated employees and ensure there is a process for transferring that responsibility upon turnover. View of Responsible Officials – The Vice President of Finance and Administration will maintain a Schedule of Financial Reporting for the College. New engagements that require reporting will be added to this schedule detailing the type of report and the relevant deadlines. The Comptroller or other designated employee will be assigned with the responsibility to maintain new engagement records and satisfy all of the reporting requirements. The Comptroller or other designated employee will report the completion of each requirement to the Vice President of Finance and Administration to update this schedule. This schedule will be shared with auditors to verify compliance.
Show full finding ▾Hide full finding ▴Criteria – A requirement of accepting the Higher Education Emergency Relief Fund (HEERF) award is compliance with reporting requirements which state that the College must submit an Annual Performance Report Form in March 2023 covering calendar year 2022 expenditures. Condition – Per inquiry with College management, it was noted that the Annual Performance Report Form was not submitted to the Department of Education. Cause – The College has experienced significant turnover in its Budget and Finance department in 2023 resulting in loss of institutional knowledge regarding requirements to file reports with regulatory bodies. Effect – The College was not in compliance with the Department of Education’s requirements for reporting. Recommendation – The College needs to establish and maintain a schedule for required reporting to ensure that all compliance requirements are able to be met regardless if turnover occurs. The College also needs to assign responsibility for required reporting to designated employees and ensure there is a process for transferring that responsibility upon turnover. View of Responsible Officials – The Vice President of Finance and Administration will maintain a Schedule of Financial Reporting for the College. New engagements that require reporting will be added to this schedule detailing the type of report and the relevant deadlines. The Comptroller or other designated employee will be assigned with the responsibility to maintain new engagement records and satisfy all of the reporting requirements. The Comptroller or other designated employee will report the completion of each requirement to the Vice President of Finance and Administration to update this schedule. This schedule will be shared with auditors to verify compliance.
• The Vice President of Finance and Administration will maintain a Schedule of Financial Reporting for the College. • New engagements that require reporting will be added to the above mentioned Schedule detailing the type of report and the relevant deadlines • The Comptroller or other designated employee will be assigned with the responsibility to maintain new engagement records and satisfy all of the reporting requirements. • The Comptroller or other designated employee will report the completion of the requirement to the Vice President of Finance and Administration to update the Schedule. • The Schedule of Financial reporting will be shared with auditors to verify compliance.
FAC accepted this audit on April 18, 2023 — management decision was due October 18, 2023.
FAC accepted this audit on May 4, 2022 — management decision was due November 4, 2022.
FAC accepted this audit on July 20, 2021 — management decision was due January 20, 2022.
FAC accepted this audit on May 25, 2020 — management decision was due November 25, 2020.
FAC accepted this audit on March 4, 2019 — management decision was due September 4, 2019.
FAC accepted this audit on February 9, 2018 — management decision was due August 9, 2018.
FAC accepted this audit on February 15, 2017 — management decision was due August 15, 2017.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-002
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in New York →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.