EIN: 166002650
UEI: NQRLEYNNEWK4
Audited by: Bonadio & Co., LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of August 28, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 4, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 4, 2026 (4 days from today).
What is a management decision? →Finding 2025-001 – Student Financial Assistance Cluster Federal Agency – U.S. Department of Education Grant Period – Year ended August 31, 2025 Compliance Requirement – N. Gramm-Leach-Bliley Act–Student Information Security Criteria – Institutions participating in Title IV programs are required to comply with various laws and regulations as part of their signed Program Participation Agreement (PPA), including but not limited to, the Federal Trade Commission’s Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition – The College has not performed a formal risk assessment of their technology environment. In addition, the College’s management indicated that the majority of the elements required are in place; however, they are not formally documented. This includes policies related to vendor management, user access, transmission and destruction of student data, change management, and a formal inventory of where student data is stored, collected and transmitted. per the 2025 Compliance Supplement. Cause – The College has experienced significant changes in administration with additional vacancies and turnover in the technology and finance departments. Along with budget constraints the ability to complete a risk assessment and formal documentation of the IT policies and procedures has been delayed. Effect – The College was not in compliance with the Department of Education’s requirements for GLBA. Recommendation – The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, this would include the completion of a documented, thorough, and standardized risk assessment. As part of this process, IT policies should be updated and documented to align with the College’s current IT environment and be formally approved and implemented throughout the College. Management response - Over the past year, the College experienced significant changes in leadership, including vacancies and turnover within the finance and technology departments. As a result, finalizing the remaining GLBA documentation has been delayed. Some of the required work has already been completed operationally, and we are committed to finalizing the written policies and procedures in the coming months.
Show full finding ▾Hide full finding ▴Finding 2025-001 – Student Financial Assistance Cluster Federal Agency – U.S. Department of Education Grant Period – Year ended August 31, 2025 Compliance Requirement – N. Gramm-Leach-Bliley Act–Student Information Security Criteria – Institutions participating in Title IV programs are required to comply with various laws and regulations as part of their signed Program Participation Agreement (PPA), including but not limited to, the Federal Trade Commission’s Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition – The College has not performed a formal risk assessment of their technology environment. In addition, the College’s management indicated that the majority of the elements required are in place; however, they are not formally documented. This includes policies related to vendor management, user access, transmission and destruction of student data, change management, and a formal inventory of where student data is stored, collected and transmitted. per the 2025 Compliance Supplement. Cause – The College has experienced significant changes in administration with additional vacancies and turnover in the technology and finance departments. Along with budget constraints the ability to complete a risk assessment and formal documentation of the IT policies and procedures has been delayed. Effect – The College was not in compliance with the Department of Education’s requirements for GLBA. Recommendation – The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, this would include the completion of a documented, thorough, and standardized risk assessment. As part of this process, IT policies should be updated and documented to align with the College’s current IT environment and be formally approved and implemented throughout the College. Management response - Over the past year, the College experienced significant changes in leadership, including vacancies and turnover within the finance and technology departments. As a result, finalizing the remaining GLBA documentation has been delayed. Some of the required work has already been completed operationally, and we are committed to finalizing the written policies and procedures in the coming months.
The College agrees with the finding. While many GLBA-required safeguards are operationally in place, documentation and a formal enterprise risk assessment have not been fully completed. The College will engage a qualified third party to perform a comprehensive GLBA-aligned risk assessment using a recognized framework such as NIST. Based on the results, the College will document identified risks, existing safeguards, and remediation plans. Additionally, the College will formalize and update its Written Information Security Program, including policies addressing vendor management, user access controls, data transmission and destruction, change management, and data inventory. Policies will be reviewed and approved through the College’s governance process. Responsible Party: Kyle Brown, Executive Director of Technology, Jamestown Community College, kylebrown@sunyjcc.edu, 716.338.1118 Anticipated Completion Date: August 31, 2026
FAC accepted this audit on February 7, 2025 — management decision was due August 7, 2025.
FAC accepted this audit on February 28, 2024 — management decision was due August 28, 2024.
FAC accepted this audit on January 23, 2023 — management decision was due July 23, 2023.
FAC accepted this audit on February 15, 2022 — management decision was due August 15, 2022.
FAC accepted this audit on April 25, 2021 — management decision was due October 25, 2021.
FAC accepted this audit on February 7, 2020 — management decision was due August 7, 2020.
FAC accepted this audit on January 29, 2019 — management decision was due July 29, 2019.
FAC accepted this audit on January 30, 2018 — management decision was due July 30, 2018.
FAC accepted this audit on January 30, 2017 — management decision was due July 30, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in New York →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.