EIN: 160973001
UEI: SJHAGXNEXB51
Audited by: Bonadio & Co. LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of September 2, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on February 20, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by August 20, 2026 (14 days ago).
What is a management decision? →FAC accepted this audit on March 14, 2025 — management decision was due September 14, 2025.
FAC accepted this audit on April 10, 2024 — management decision was due October 10, 2024.
FAC accepted this audit on February 26, 2023 — management decision was due August 26, 2023.
FAC accepted this audit on March 7, 2022 — management decision was due September 7, 2022.
FAC accepted this audit on March 10, 2021 — management decision was due September 10, 2021.
FAC accepted this audit on March 19, 2020 — management decision was due September 19, 2020.
The College has not performed a thorough information security risk assessment which should include employee training, information security incident response, and general security controls. Cause: The College?s information security program does not include procedures for the performance of regular risk assessments. Effect: As the College has not performed a thorough information security risk assessment, it may be unaware of the risks to its sensitive data, specifically datasets protected under GLBA. Recommendation: The College should work to implement a standardized and detailed risk management framework, such as those provided by National Institute of Standards and Technology (NIST). Risk assessment documentation should include detailed information regarding current procedures in place, justifications for scoring, safeguards for each identified risk, and remediation plans.
Show full finding ▾Hide full finding ▴Finding 2019-001 - 84.268, 84.063, 84.033, 84.007 Student Financial Aid Cluster Federal Agency - U.S. Department of Education Grant Period ? Year ended August 31, 2019 Criteria: Institutions participating in Title IV programs are required to comply with various laws and regulations as part of their signed Program Participation Agreement (PPA), including but not limited to, the Federal Trade Commission?s Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition: The College has not performed a thorough information security risk assessment which should include employee training, information security incident response, and general security controls. Cause: The College?s information security program does not include procedures for the performance of regular risk assessments. Effect: As the College has not performed a thorough information security risk assessment, it may be unaware of the risks to its sensitive data, specifically datasets protected under GLBA. Recommendation: The College should work to implement a standardized and detailed risk management framework, such as those provided by National Institute of Standards and Technology (NIST). Risk assessment documentation should include detailed information regarding current procedures in place, justifications for scoring, safeguards for each identified risk, and remediation plans.
Finding 2019-001 - 84.268, 84.063, 84.033, 84.007 Student Financial Aid Cluster Federal Agency - U.S. Department of Education Grant Period ? Year ended August 31, 2019 Management Response: The College will work to implement a standardized and detailed risk management framework in compliance with GLBA standards. The College will perform the following: ? Designate an employee or employees to coordinate the formation of the security program. ? Perform a campus wide risk assessment that identifies reasonable and foreseeable internal and external risks to security, confidentiality and integrity of student information that could result in unauthorized disclosure, misuse, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. ? At a minimum, the risk assessment will include consideration of risks in each of the following operational areas: o Employee training and management, o Information systems, including network and software design as well as information processing, o Storage, transmission and disposal, and o Detection and prevention of and response to attacks, intrusions, or other system failures. ? Design and implement information safeguards to control the risks identified through risk assessment and regularly test or monitor the effectiveness of the safeguards? key controls, systems and procedures. ? Oversee service providers by taking steps to select and retain providers capable of maintaining appropriate safeguards for customer information. ? Contractually require service providers to implement and maintain such safeguards. ? Periodically evaluate and adjust the information security program, based on the results of the testing and monitoring mentioned above, any material changes to operations or any other circumstances known to have or that may have a material effect on the information security program.
FAC accepted this audit on March 3, 2019 — management decision was due September 3, 2019.
FAC accepted this audit on February 8, 2018 — management decision was due August 8, 2018.
FAC accepted this audit on March 2, 2017 — management decision was due September 2, 2017.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in New York →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.