EIN: 161476258
UEI: FSCUSJ12BVA8
Data as of August 19, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on February 27, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by August 27, 2025, which was (358 days ago).
What is a management decision? →Finding 2024-001 U.S. Department of Education Student Financial Assistance Cluster Gramm Leach Bliley Act (GLBA) Criteria - Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. GLBA requires institutions to implement certain written policies. Condition - The University does not have the following required written policies that are required under GLBA: • The written information security program does not include a change management policy. • A written information security staff training policy is not in place. • A written vendor management policy is not in place. Cause - The University has not established formal policies to ensure compliance with the GLBA requirements. Resource constraints and competing priorities were contributing factors. Effect - The University is not fully compliant with GLBA requirements. Recommendation - We recommend that the University develop and implement a comprehensive written information security program that addresses all minimum elements required by GLBA. Additionally, we recommend that the University establish a formal written policy for staff training on data security and privacy and develop and implement a vendor management policy to ensure third-party service providers safeguard customer information appropriately. Views of Responsible Officials – The University acknowledges the recommendation and is committed to implementing a comprehensive written information security program that fully addresses all GLBA requirements. The University has drafted a formal data security and privacy training policy for staff. The University currently requires faculty and staff to complete annual security and privacy trainings as directed through the employee handbook. The University has drafted a vendor management policy to ensure third-party service providers maintain appropriate safeguards for customer information. A dedicated security team will oversee the development and implementation of these measures, ensuring compliance with GLBA regulations and the protection of sensitive student data.
The University has drafted a comprehensive written information security program to address the minimum requirements for compliance with GLBA, including the following: -The University has drafted a formal data security and privacy training policy for faculty and staff to be incorporated within the comprehensive written information security program. This is in addition to the mandatory annual security and privacy training for all faculty and staff, as directed through the employee handbook. -The University has drafted a vendor management policy to ensure thirdparty providers maintain appropriate safeguards for customer information. - The University has also drafted a change and patch management policy. A dedicated team from the Integrated Information Technology Services department will oversee the development and implementation of the above policies to ensure compliance with GLBA and the protection of sensitive student data. The University has completed a draft of a comprehensive written information security program to address the minimum requirements noted above. TheUniversity plans to have the comprehensive written information plan reviewed and finalized by February 28, 2025.
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on February 12, 2017. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by August 12, 2017, which was (3295 days ago).
What is a management decision? →GSA_MIGRATION
GSA_MIGRATION
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.