← Back to home

Jamestown Community CollegeHigher Education

EIN: 166002650

UEI: NQRLEYNNEWK4

Audited by: Bonadio & Co., LLP

Oversight agency: 84 [Department of Education]

View federal awards & risk assessment →

Data as of August 28, 2026

Jamestown Community College10 audit years1 findings
10
Audit Years
1
Total Findings
0
Repeat Findings
$10.1M
Federal Awards Expended (FY 2025)

FY 2025-08-31

LOW-RISK AUDITEE$10,112,726 federal awards expended

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 4, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 4, 2026 (4 days from today).

What is a management decision? →
2025-001
Other
SIGNIFICANT DEFICIENCY

Finding 2025-001 – Student Financial Assistance Cluster Federal Agency – U.S. Department of Education Grant Period – Year ended August 31, 2025 Compliance Requirement – N. Gramm-Leach-Bliley Act–Student Information Security Criteria – Institutions participating in Title IV programs are required to comply with various laws and regulations as part of their signed Program Participation Agreement (PPA), including but not limited to, the Federal Trade Commission’s Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition – The College has not performed a formal risk assessment of their technology environment. In addition, the College’s management indicated that the majority of the elements required are in place; however, they are not formally documented. This includes policies related to vendor management, user access, transmission and destruction of student data, change management, and a formal inventory of where student data is stored, collected and transmitted. per the 2025 Compliance Supplement. Cause – The College has experienced significant changes in administration with additional vacancies and turnover in the technology and finance departments. Along with budget constraints the ability to complete a risk assessment and formal documentation of the IT policies and procedures has been delayed. Effect – The College was not in compliance with the Department of Education’s requirements for GLBA. Recommendation – The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, this would include the completion of a documented, thorough, and standardized risk assessment. As part of this process, IT policies should be updated and documented to align with the College’s current IT environment and be formally approved and implemented throughout the College. Management response - Over the past year, the College experienced significant changes in leadership, including vacancies and turnover within the finance and technology departments. As a result, finalizing the remaining GLBA documentation has been delayed. Some of the required work has already been completed operationally, and we are committed to finalizing the written policies and procedures in the coming months.

Show full finding ▾
Full finding narrative

Finding 2025-001 – Student Financial Assistance Cluster Federal Agency – U.S. Department of Education Grant Period – Year ended August 31, 2025 Compliance Requirement – N. Gramm-Leach-Bliley Act–Student Information Security Criteria – Institutions participating in Title IV programs are required to comply with various laws and regulations as part of their signed Program Participation Agreement (PPA), including but not limited to, the Federal Trade Commission’s Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition – The College has not performed a formal risk assessment of their technology environment. In addition, the College’s management indicated that the majority of the elements required are in place; however, they are not formally documented. This includes policies related to vendor management, user access, transmission and destruction of student data, change management, and a formal inventory of where student data is stored, collected and transmitted. per the 2025 Compliance Supplement. Cause – The College has experienced significant changes in administration with additional vacancies and turnover in the technology and finance departments. Along with budget constraints the ability to complete a risk assessment and formal documentation of the IT policies and procedures has been delayed. Effect – The College was not in compliance with the Department of Education’s requirements for GLBA. Recommendation – The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, this would include the completion of a documented, thorough, and standardized risk assessment. As part of this process, IT policies should be updated and documented to align with the College’s current IT environment and be formally approved and implemented throughout the College. Management response - Over the past year, the College experienced significant changes in leadership, including vacancies and turnover within the finance and technology departments. As a result, finalizing the remaining GLBA documentation has been delayed. Some of the required work has already been completed operationally, and we are committed to finalizing the written policies and procedures in the coming months.

Corrective Action Plan

The College agrees with the finding. While many GLBA-required safeguards are operationally in place, documentation and a formal enterprise risk assessment have not been fully completed. The College will engage a qualified third party to perform a comprehensive GLBA-aligned risk assessment using a recognized framework such as NIST. Based on the results, the College will document identified risks, existing safeguards, and remediation plans. Additionally, the College will formalize and update its Written Information Security Program, including policies addressing vendor management, user access controls, data transmission and destruction, change management, and data inventory. Policies will be reviewed and approved through the College’s governance process. Responsible Party: Kyle Brown, Executive Director of Technology, Jamestown Community College, kylebrown@sunyjcc.edu, 716.338.1118 Anticipated Completion Date: August 31, 2026

About Other →

FY 2024-08-31

LOW-RISK AUDITEE$9,762,033 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 7, 2025 — management decision was due August 7, 2025.

FY 2023-08-31

LOW-RISK AUDITEE$9,578,744 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 28, 2024 — management decision was due August 28, 2024.

FY 2022-08-31

LOW-RISK AUDITEE$13,775,732 federal awards expendedNo findings recorded this year

FAC accepted this audit on January 23, 2023 — management decision was due July 23, 2023.

FY 2021-08-31

LOW-RISK AUDITEE$15,301,631 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 15, 2022 — management decision was due August 15, 2022.

FY 2020-08-31

LOW-RISK AUDITEE$13,604,929 federal awards expendedNo findings recorded this year

FAC accepted this audit on April 25, 2021 — management decision was due October 25, 2021.

FY 2019-08-31

LOW-RISK AUDITEE$12,115,873 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 7, 2020 — management decision was due August 7, 2020.

FY 2018-08-31

LOW-RISK AUDITEE$12,823,670 federal awards expendedNo findings recorded this year

FAC accepted this audit on January 29, 2019 — management decision was due July 29, 2019.

FY 2017-08-31

LOW-RISK AUDITEE$13,283,885 federal awards expendedNo findings recorded this year

FAC accepted this audit on January 30, 2018 — management decision was due July 30, 2018.

FY 2016-08-31

LOW-RISK AUDITEE$15,192,847 federal awards expendedNo findings recorded this year

FAC accepted this audit on January 30, 2017 — management decision was due July 30, 2017.

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Browse other Single Audit organizations in New York

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and filing records.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.