EIN: 161393336
UEI: MA2YMDBA4LN5
Data as of August 23, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on April 14, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by October 14, 2026 (51 days from today).
What is a management decision? →Finding 2025-001 – Student Financial Assistance Cluster Federal Agency – U.S. Department of Education Grant Period – Year ended August 31, 2025 Compliance Requirement – Return of Title IV Funds Criteria – Federal regulations require institutions to calculate and return unearned Title IV funds. Condition – During our testing for Return of Title IV (R2T4) calculations, we identified 2 instances out of 25 students selected for testing where the R2T4 was properly calculated. However, the Title IV funds were not correctly and accurately returned. Cause – The College had a lack of review controls and segregation of duties in their Return of Title IV Funds process. Based on discussion with the client, these errors were manual errors that were not identified due to a lack of review control and segregation of duties. As a result, the controls over Return of Title IV funds were not operating effectively. Effect – The amount and type of Title IV funds were not being returned correctly. Recommendation – We recommend that management strength internal controls over correctly and accurately returning Title IV funds by implementing formalized procedures to ensure proper review of the R2T4 calculation and review that the correct type and amount of funds are returned. Management Response – The College acknowledges the instances identified during testing where the errors in the calculation of Return to Title IV (R2T4) funds, resulted in incorrect amounts of federal aid being returned for certain withdrawn students. These instances were the result of manual processing errors that were not identified due to a lack of review control and segregation of duties. R2T4 calculations and return amounts were completed and finalized by a single staff member without a required secondary review, increasing the risk of calculation errors.
Show full finding ▾Hide full finding ▴Finding 2025-001 – Student Financial Assistance Cluster Federal Agency – U.S. Department of Education Grant Period – Year ended August 31, 2025 Compliance Requirement – Return of Title IV Funds Criteria – Federal regulations require institutions to calculate and return unearned Title IV funds. Condition – During our testing for Return of Title IV (R2T4) calculations, we identified 2 instances out of 25 students selected for testing where the R2T4 was properly calculated. However, the Title IV funds were not correctly and accurately returned. Cause – The College had a lack of review controls and segregation of duties in their Return of Title IV Funds process. Based on discussion with the client, these errors were manual errors that were not identified due to a lack of review control and segregation of duties. As a result, the controls over Return of Title IV funds were not operating effectively. Effect – The amount and type of Title IV funds were not being returned correctly. Recommendation – We recommend that management strength internal controls over correctly and accurately returning Title IV funds by implementing formalized procedures to ensure proper review of the R2T4 calculation and review that the correct type and amount of funds are returned. Management Response – The College acknowledges the instances identified during testing where the errors in the calculation of Return to Title IV (R2T4) funds, resulted in incorrect amounts of federal aid being returned for certain withdrawn students. These instances were the result of manual processing errors that were not identified due to a lack of review control and segregation of duties. R2T4 calculations and return amounts were completed and finalized by a single staff member without a required secondary review, increasing the risk of calculation errors.
The institution reviewed the identified R2T4 calculations and, where necessary, corrected the amounts returned to ensure compliance with federal regulations. The College implemented several procedural and staffing changes to strengthen internal controls and improve segregation of duties related to the Return of Title IV Funds process. These improvements include: • Establishing a formal secondary review of all R2T4 calculations and fund return transactions prior to processing. A second qualified Finance staff member will review and verify: • The withdrawal date • The calculation methodology • The percentage of the payment period completed • The final amount of Title IV funds returned • Separating responsibilities for calculation, review, and posting of Title IV fund returns to ensure appropriate segregation of duties. • Implementing documented procedures and checklists to verify that the correct type and amount of Title IV funds are returned in accordance with federal requirements. • Providing additional staff training related to R2T4 processing and compliance requirements. Management believes that these corrective actions significantly strengthen internal controls and reduce the likelihood of similar errors occurring in the future. The College will continue to monitor compliance with these procedures and perform periodic supervisory reviews to ensure that controls remain effective.
FAC accepted this audit on April 15, 2024 — management decision was due October 15, 2024.
During our testing, we noted the following: The annual risk assessment was performed during the audit year; however, results were not communicated to management and there is no mention of any risks to technology, information security, data protections, assets, cybersecurity, or regulatory compliance. Annual security awareness training for employees is in place; however, completion of the training is not enforced. A vendor management program is not in place. Mobile device management is not in place. While protections are in place for data backups, a Disaster Recovery Plan and Business Continuity Plan are not in place. GBLA rules also require that a basic set of policies and procedures, as well as a program for annual risk assessment and reporting, is in place. The polices supplied by the College were missing the expected areas. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor’s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College agrees that it should become compliant with GLBA Safeguarding rules as soon as reasonably possible. A project to create, approve, implement, and monitor a comprehensive risk assessment process is in process and the College will commit the resources necessary to bring us into compliance in a timely fashion. Progress update meetings will be scheduled accordingly and reported to the Audit and Finance Committee of the College's Board of Trustees.
Show full finding ▾Hide full finding ▴Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires the College, on an annual basis, to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer (student) information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, the GLBA risk assessment should include consideration of risk in each relevant area of operations, including: Employee training and management. Information systems, including network and software design, as well as information processing, storage, transmission, and disposal. Detecting, preventing, and responding to attacks, intrusions, or other system failures. Condition: During our testing, we noted the following: The annual risk assessment was performed during the audit year; however, results were not communicated to management and there is no mention of any risks to technology, information security, data protections, assets, cybersecurity, or regulatory compliance. Annual security awareness training for employees is in place; however, completion of the training is not enforced. A vendor management program is not in place. Mobile device management is not in place. While protections are in place for data backups, a Disaster Recovery Plan and Business Continuity Plan are not in place. GBLA rules also require that a basic set of policies and procedures, as well as a program for annual risk assessment and reporting, is in place. The polices supplied by the College were missing the expected areas. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor’s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College agrees that it should become compliant with GLBA Safeguarding rules as soon as reasonably possible. A project to create, approve, implement, and monitor a comprehensive risk assessment process is in process and the College will commit the resources necessary to bring us into compliance in a timely fashion. Progress update meetings will be scheduled accordingly and reported to the Audit and Finance Committee of the College's Board of Trustees.
Robert Walker, Interim CIO, and Conal Larkin, Director of ITS will be jointly responsible for the corrective action plan. 1. Complete annual risk assessments including these areas of focus, with the status of each item reported collectively to the Executive Council immediately following the assessment: a. Security policies and procedures b. Incident-response procedures c. Disaster recovery and business continuity plans d. Network security controls e. Identity and access controls f. Media protection g. Physical security of IT assets h. Physical security of hard copy documentation i. User education and awareness j. Third-party security (vendors/suppliers/outsourcing) 2. Create draft Vendor Management policy and procedure 3. Continue to use Jamf to manage Apple mobile devices; continue to restrict Windows mobile devices to segmented network with internet access only; continue to not allow any mobile device to be joined to the domain 4. Create draft Disaster Recovery Plan and Business Continuity Plan 5. Forward following draft policies for approval: Outsourcing, Secure Authentication and Responsible Use, Security Awareness Training, Third party Connection, Remote Access, Information Security, Email, Wireless Access, Backup, Password, and Mobile Device The Vice President of Academic Affairs, Controller and Vice President of Administrative & Financial Affairs shall review and approve the Corrective Action Plan and all revised or new policies shall be reviewed and approved by the Executive Council and the Board of Trustees no later than August 16, 2024. Implementation deadline: 8/16/24
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.