EIN: 231352626
UEI: MUMJENHYFLG3
Audited by: CliftonLarsonAllen LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of August 28, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on June 22, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by December 22, 2026 (113 days from today).
What is a management decision? →Certain students’ enrollment information was not reported accurately or timely to the NSLDS. Questioned Costs: None. Context: During our testing, we noted the following: • 4 students out of a sample of 40 students tested were not reported to the campus-level record in the NSLDS in a timely manner. • 1 student out of a sample of 40 students had an enrollment effective date in the program-level records that did not match what was reflected in the College’s records and the campus-level record in the NSLDS. Cause: Management's procedures to report accurate and timely information to the NSLDS were not operating effectively. Effect: Inaccurate reporting to the NSLDS can impact when students enter repayment periods or affect their interest rates. Repeat Finding: Yes, 2024-004. Recommendation: We recommend the College evaluate its procedures and review policies in overseeing submissions to the NSLDS completed by the third-party servicer. Additionally, we recommend the College review its policies and procedures on reporting enrollment information to the NSLDS to ensure that all relevant information is being captured and reported timely in accordance with applicable regulations. Views of Responsible Officials: There is no disagreement with the audit finding.
Show full finding ▾Hide full finding ▴2025–002: National Student Loan Database System (NSLDS) Reporting Federal Agency: U.S. Department of Education Federal Program Name: Federal Pell Grant Program; Federal Direct Student Loans Assistance Listing Number: 84.063, 84.268 Federal Award Identification Number and Year: P063P242088; P268K252088 - 2025 Award Period: July 01, 2024 - June 30, 2025 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or Specific Requirement: Per U.S. Department of Education (ED) regulations, all schools participating (or approved to participate) in the Federal Student Aid programs must have an arrangement to report student enrollment data to the NSLDS through a roster file. The school is required to report enrollment status at both the school and program level. The school is required to report changes in the student’s enrollment status, the effective date of the status and an anticipated completion date. An academic program is defined as the combination of the school’s Office of Postsecondary Education Identification (OPEID) number and the program’s Classification of Instructional Program (CIP) code, credential level, and published program length. ED requires the College to report changes in enrollment status and indicate the date that the changes occurred (34 CFR 685.309). Changes in enrollment status must be reported within 30 days. However, if a roster file is expected within 60 days, you may provide the date on that roster file. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that don’t pass the NSLDS enrollment reporting edits. ED requires the College to report changes in enrollment status within 30 or 60 days that the College determined the changes occurred (34 CFR 682.610). Condition: Certain students’ enrollment information was not reported accurately or timely to the NSLDS. Questioned Costs: None. Context: During our testing, we noted the following: • 4 students out of a sample of 40 students tested were not reported to the campus-level record in the NSLDS in a timely manner. • 1 student out of a sample of 40 students had an enrollment effective date in the program-level records that did not match what was reflected in the College’s records and the campus-level record in the NSLDS. Cause: Management's procedures to report accurate and timely information to the NSLDS were not operating effectively. Effect: Inaccurate reporting to the NSLDS can impact when students enter repayment periods or affect their interest rates. Repeat Finding: Yes, 2024-004. Recommendation: We recommend the College evaluate its procedures and review policies in overseeing submissions to the NSLDS completed by the third-party servicer. Additionally, we recommend the College review its policies and procedures on reporting enrollment information to the NSLDS to ensure that all relevant information is being captured and reported timely in accordance with applicable regulations. Views of Responsible Officials: There is no disagreement with the audit finding.
Finding 2025-002: National Student Loan Database System (NSLDS) Reporting Significant Deficiency in Internal Control over Compliance / Other Matters Views of Responsible Officials and Planned Corrective Actions: Management concurs with the audit findings and acknowledges that controls over accurate and timely reporting of student enrollment information to the NSLDS were not operating effectively, including procedures related to oversight of reporting performed by a third-party servicer. To address this finding, management is implementing the following corrective actions: Management is evaluating and formalizing its oversight procedures related to NSLDS submissions performed by the third-party servicer, including defined responsibilities, review procedures, and escalation protocols. Periodic internal reviews of NSLDS submissions are being implemented to verify the accuracy and timeliness of campus-level and program-level enrollment reporting. Management is updating policies and procedures to ensure that all enrollment status changes and effective dates are captured and reported in accordance with U.S. Department of Education regulations. Management expects these corrective actions to be substantially implemented and will continue to monitor compliance to prevent recurrence.
2024-004
Under an institution’s Program Participation Agreement with the U.S. Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned Costs: None Context: During our audit procedures, it was noted that the College had not performed penetration testing and did not have an IT risk assessment performed.. Cause: The College did not perform penetration testing and did not have an IT risk assessment performed as required by the Gramm-Leach-Bliley Act. Effect: The students’ personal information could be vulnerable. Repeat Finding: Yes, 2024-005. Recommendation: The College should develop and implement annual penetration testing and perform IT risk assessment. Views of Responsible Officials: There is no disagreement with the audit finding.
Show full finding ▾Hide full finding ▴2025-003: Gramm-Leach-Bliley Act Federal Agency: U.S. Department of Education Federal Program Name: Federal Supplemental Educational Opportunity Grants; Federal Pell Grant Program; Federal Direct Student Loans; Federal Work Study Program Assistance Listing Number: 84.007, 84.063, 84.268, Federal Award Identification Number and Year: P063P242088; P007A243557; P268K252088; P033A243557 - 2025 Award Period: July 01, 2024 - June 30, 2025 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or Specific Requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). Condition: Under an institution’s Program Participation Agreement with the U.S. Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned Costs: None Context: During our audit procedures, it was noted that the College had not performed penetration testing and did not have an IT risk assessment performed.. Cause: The College did not perform penetration testing and did not have an IT risk assessment performed as required by the Gramm-Leach-Bliley Act. Effect: The students’ personal information could be vulnerable. Repeat Finding: Yes, 2024-005. Recommendation: The College should develop and implement annual penetration testing and perform IT risk assessment. Views of Responsible Officials: There is no disagreement with the audit finding.
Finding 2025-003: Gramm-Leach-Bliley Act (GLBA) Significant Deficiency in Internal Control over Compliance / Other Matters Views of Responsible Officials and Planned Corrective Actions: Management concurs with the audit finding and acknowledges that, during the fiscal year ended June 30, 2025, the College had not performed penetration testing or completed an IT risk assessment as required under the Gramm-Leach-Bliley Act. Subsequent to fiscal year-end, management has taken decisive corrective action to remediate this deficiency and strengthen the College’s information security control environment: Penetration Testing: Management engaged an independent, qualified third-party cybersecurity firm, Counter Measures Security, LLC, to perform penetration testing. A professional services agreement was executed in August 2025, and penetration testing was completed on October 17, 2025, in accordance with the Penetration Testing Execution Standard (PTES). Management has reviewed the results and is addressing identified recommendations as appropriate. Documentation supporting the completion of these services is retained by the College. IT Risk Assessment and Information Security Program: Management is formalizing an IT risk assessment process consistent with GLBA requirements and incorporating penetration testing results into the College’s broader information security program. Ongoing Monitoring: Management will establish a recurring schedule for penetration testing and IT risk assessments and will maintain documentation of results, remediation efforts, and management review to support ongoing compliance. Penetration testing was completed as of October 17, 2025, and management expects the IT risk assessment process and ongoing monitoring controls to be fully implemented during fiscal year 2026.
2024-005
FAC accepted this audit on March 31, 2025 — management decision was due October 1, 2025.
During our testing, it was noted that an individual did not receive exit counseling after their departure from the College. Questioned costs: None. Context: 1 out of 40 students tested did not receive exit counseling within the required 30 days of a student ceasing attendance. Cause: The College did not follow its policies and procedures to ensure students who departed the College received direct loan exit counseling. Effect: Students are not receiving the proper loan counseling which may contribute to a higher default rate. Repeat Finding: Yes, 2023-004. Recommendation: We recommend the College review its policies and procedures around sending exit counseling information to students to ensure students are receiving proper counseling. Views of responsible officials: There is no disagreement with the audit finding.
Show full finding ▾Hide full finding ▴2024–002: Exit Counseling Federal Agency: U.S. Department of Education Federal Program Name: Federal Direct Student Loans Assistance Listing Number: 84.268 Federal Award Identification Number and Year: P268K252088 - 2024 Award Period: July 01, 2023 - June 30, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 685.304 require entrance counseling be performed before disbursing loan funds to the student for Direct Subsidized Loan, Direct Unsubsidized Loan and Direct PLUS Loan to a graduate or professional student. The regulations also require exit counseling for all students who cease at least half-time study at the school. Condition: During our testing, it was noted that an individual did not receive exit counseling after their departure from the College. Questioned costs: None. Context: 1 out of 40 students tested did not receive exit counseling within the required 30 days of a student ceasing attendance. Cause: The College did not follow its policies and procedures to ensure students who departed the College received direct loan exit counseling. Effect: Students are not receiving the proper loan counseling which may contribute to a higher default rate. Repeat Finding: Yes, 2023-004. Recommendation: We recommend the College review its policies and procedures around sending exit counseling information to students to ensure students are receiving proper counseling. Views of responsible officials: There is no disagreement with the audit finding.
2024-002 Federal Direct Student Loans - Assistance Listing No. 84.268 Recommendation: We recommend the College review its policies and procedures around sending exit counseling information to students to ensure students are receiving proper counseling. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: While the Office of Financial Aid has revamped how it manages exit notices and has made an improvement, our report has failed to pick up students that went from undergraduate to graduate in consecutive semesters. We will develop and implement a new report to ensure that this population is picked and exit notices are sent in a timely manner. Name(s) of the contact person(s) responsible for corrective action: Jossie Johnson, Director of Financial Aid, and Micheal Reig, Registrar Planned completion date for corrective action plan: June 30, 2025
2023-004
During our testing, it was noted the College’s process did not ensure scheduled breaks were properly factored into the R2T4 calculations for the Spring 2024 term. Questioned costs: $259. Context: The College did not correctly factor in scheduled breaks to 5 of the 8 students tested. The College used 12 days of scheduled breaks but should have factored in 14 days in the Spring 2024 R2T4 calculations. Cause: Management had a process in place for using the correct withdrawal date and number of days in the schedule break, but the process was not followed for 5 students. Effect: The College did not complete an accurate calculation as defined by Federal regulations. Repeat Finding: No Recommendation: We recommend the College review the R2T4 requirements and implement procedures to ensure scheduled breaks are properly factored into the R2T4 calculations. Views of responsible officials: There is no disagreement with the audit finding.
Show full finding ▾Hide full finding ▴2024–003: Return of Title IV (R2T4) Calculations Federal Agency: U.S. Department of Education Federal Program Name: Federal Supplemental Educational Opportunity Grants; Federal Pell Grant Program; Federal Direct Student Loans; Teacher Education Assistance for College and Higher Education Grants Assistance Listing Number: 84.007, 84.063, 84.268, 84.379 Federal Award Identification Number and Year: P007A243557, P063P242088, P063Q232088, P268K252088 - 2024; P379T232088 - 2023 Award Period: July 01, 2023 - June 30, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Once a students’ withdrawal date is determined, a school needs to calculate the percentage of the payment period or period of enrollment completed. Institutionally scheduled breaks of five or more consecutive days are excluded from the return of Title IV calculation as periods of nonattendance and, therefore, do not affect the calculation of the amount of Federal Student Aid earned (34 CFR 668.22(f)(2)(i)). Condition: During our testing, it was noted the College’s process did not ensure scheduled breaks were properly factored into the R2T4 calculations for the Spring 2024 term. Questioned costs: $259. Context: The College did not correctly factor in scheduled breaks to 5 of the 8 students tested. The College used 12 days of scheduled breaks but should have factored in 14 days in the Spring 2024 R2T4 calculations. Cause: Management had a process in place for using the correct withdrawal date and number of days in the schedule break, but the process was not followed for 5 students. Effect: The College did not complete an accurate calculation as defined by Federal regulations. Repeat Finding: No Recommendation: We recommend the College review the R2T4 requirements and implement procedures to ensure scheduled breaks are properly factored into the R2T4 calculations. Views of responsible officials: There is no disagreement with the audit finding.
2024-003 Federal Supplemental Educational Opportunity Grants; Federal Pell Grant Program; Federal Direct Student Loans; Teacher Education Assistance for College and Higher Education Grants- Assistance Listing Nos: 84.007, 84.063, 84.268, 84.379 Recommendation: We recommend the College review the R2T4 requirements and implement procedures to ensure scheduled breaks are properly factored into the R2T4 calculations. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The Office of Financial Aid will work with the Registrar to ensure that we receive the academic calendar in a timely manner. Once received, breaks will be verified by the Assistant Director of Financial Aid and then confirmed by the Director of Financial Aid. Name(s) of the contact person(s) responsible for corrective action: Jossie Johnson, Director of Financial Aid Planned completion date for corrective action plan: June 30, 2025
Certain students’ enrollment information was not reported accurately or timely to the NSLDS. Questioned costs: None. Context: During our testing, we noted the following: • 15 out of a sample of 40 students tested had an enrollment effective date in the program-level records in the NSLDS that did not match what was reflected in the College’s records and the campus-level record in the NSLDS. • 4 out of a sample of 40 students tested had an enrollment status in the program-level records in the NSLDS that did not match what was reflected in the College’s records and the campus-level record in the NSLDS • 2 out of a sample of 40 students tested were not reported to the campus-level record in the NSLDS in a timely manner. Cause: Management's procedures to report accurate and timely information to the NSLDS were not operating effectively. Effect: Inaccurate reporting to the NSLDS can impact when students enter repayment periods or affect their interest rates. Repeat Finding: Yes, 2023-006. Recommendation: We recommend the College evaluate its procedures and review policies in overseeing submissions to the NSLDS completed by the third-party servicer. Additionally, we recommend the College review its policies and procedures on reporting enrollment information to the NSLDS to ensure that all relevant information is being captured and reported timely in accordance with applicable regulations. Views of responsible officials: There is no disagreement with the audit finding.
Show full finding ▾Hide full finding ▴2024–004: National Student Loan Database System (NSLDS) Reporting Federal Agency: U.S. Department of Education Federal Program Name: Federal Pell Grant Program; Federal Direct Student Loans Assistance Listing Number: 84.063, 84.268 Federal Award Identification Number and Year: P063P242088, P063Q232088, P268K252088 - 2024 Award Period: July 01, 2023 - June 30, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per U.S. Department of Education (ED) regulations, all schools participating (or approved to participate) in the Federal Student Aid programs must have an arrangement to report student enrollment data to the NSLDS through a roster file. The school is required to report enrollment status at both the school and program level. The school is required to report changes in the student’s enrollment status, the effective date of the status and an anticipated completion date. An academic program is defined as the combination of the school’s Office of Postsecondary Education Identification (OPEID) number and the program’s Classification of Instructional Program (CIP) code, credential level, and published program length. ED requires the College to report changes in enrollment status and indicate the date that the changes occurred (34 CFR 685.309). Changes in enrollment status must be reported within 30 days. However, if a roster file is expected within 60 days, you may provide the date on that roster file. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that don’t pass the NSLDS enrollment reporting edits. ED requires the College to report changes in enrollment status within 30 or 60 days that the College determined the changes occurred (34 CFR 682.610). Condition: Certain students’ enrollment information was not reported accurately or timely to the NSLDS. Questioned costs: None. Context: During our testing, we noted the following: • 15 out of a sample of 40 students tested had an enrollment effective date in the program-level records in the NSLDS that did not match what was reflected in the College’s records and the campus-level record in the NSLDS. • 4 out of a sample of 40 students tested had an enrollment status in the program-level records in the NSLDS that did not match what was reflected in the College’s records and the campus-level record in the NSLDS • 2 out of a sample of 40 students tested were not reported to the campus-level record in the NSLDS in a timely manner. Cause: Management's procedures to report accurate and timely information to the NSLDS were not operating effectively. Effect: Inaccurate reporting to the NSLDS can impact when students enter repayment periods or affect their interest rates. Repeat Finding: Yes, 2023-006. Recommendation: We recommend the College evaluate its procedures and review policies in overseeing submissions to the NSLDS completed by the third-party servicer. Additionally, we recommend the College review its policies and procedures on reporting enrollment information to the NSLDS to ensure that all relevant information is being captured and reported timely in accordance with applicable regulations. Views of responsible officials: There is no disagreement with the audit finding.
2024-004 Federal Pell Grant Program; Federal Direct Student Loans -Assistance Listing No. 84.063, 84.268 Recommendation: We recommend the College evaluate its procedures and review policies in overseeing submissions to the NSLDS completed by the third-party servicer. Additionally, we recommend the College review its policies and procedures on reporting enrollment information to the NSLDS to ensure that all relevant information is being captured and reported timely in accordance with applicable regulations. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The Office of the Registrar is reviewing its policies and procedures to ensure that all data is captured and reported in a timely manner as required by federal regulations. A software issue that caused inaccurate data to be reported has been identified and resolved by a software update. The Office of the Registrar is working with the Office of Information Technology to test the accuracy of the updated software. Name(s) of the contact person(s) responsible for corrective action: Micheal Reig, Registrar Planned completion date for corrective action plan: June 30, 2025
2023-006
Under an institution’s Program Participation Agreement with the U.S. Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned costs: None Context: During our audit procedures, it was noted that the College had not developed and implemented an approved written information security program. Cause: The College did not develop and implement a written information security program as required by the Gramm-Leach-Bliley Act. Effect: The students’ personal information could be vulnerable. Repeat Finding: Yes, 2023-008. Recommendation: The College should develop and implement an approved written information security program and verify there is a risk management section that describes how the College is identifying, assessing and communicating risks. In addition, there should be a description on the evaluation of safeguard sufficiency in mitigating risks. The information security program should also include the following: • IT Security Policy • Acceptable Use Policy • Incident Response Policy • Data Classification Policies • Vendor Management Policy • Patch Management Policy • Data Disposal Policy • Risk Assessment Policy • Logical Access and User Access Review Policies • Evidence of Review by CIO/CISO and responsibility of program Views of responsible officials: There is no disagreement with the audit finding.
Show full finding ▾Hide full finding ▴2024-005: Gramm-Leach-Bliley Act Federal Agency: U.S. Department of Education Federal Program Name: Federal Supplemental Educational Opportunity Grants; Federal Pell Grant Program; Federal Direct Student Loans; Teacher Education Assistance for College and Higher Education Grants Assistance Listing Number: 84.007, 84.063, 84.268, 84.379 Federal Award Identification Number and Year: P007A243557, P063P242088, P063Q232088, P268K252088 - 2024; P379T232088 - 2023 Award Period: July 01, 2023 - June 30, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). Condition: Under an institution’s Program Participation Agreement with the U.S. Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned costs: None Context: During our audit procedures, it was noted that the College had not developed and implemented an approved written information security program. Cause: The College did not develop and implement a written information security program as required by the Gramm-Leach-Bliley Act. Effect: The students’ personal information could be vulnerable. Repeat Finding: Yes, 2023-008. Recommendation: The College should develop and implement an approved written information security program and verify there is a risk management section that describes how the College is identifying, assessing and communicating risks. In addition, there should be a description on the evaluation of safeguard sufficiency in mitigating risks. The information security program should also include the following: • IT Security Policy • Acceptable Use Policy • Incident Response Policy • Data Classification Policies • Vendor Management Policy • Patch Management Policy • Data Disposal Policy • Risk Assessment Policy • Logical Access and User Access Review Policies • Evidence of Review by CIO/CISO and responsibility of program Views of responsible officials: There is no disagreement with the audit finding.
2024-005 Federal Supplemental Educational Opportunity Grants; Federal Pell Grant Program; Federal Direct Student Loans; Teacher Education Assistance for College and Higher Education Grants - Assistance Listing No. 84.007, 84.063, 84.268, 84.379 Recommendation: The College should develop and implement an approved written information security program and verify there is a risk management section that describes how the College is identifying, assessing and communicating risks. In addition, there should be a description on the evaluation of safeguard sufficiency in mitigating risks. The information security program should also include the following: • IT Security Policy • Acceptable Use Policy • Incident Response Policy • Data Classification Policies • Vendor Management Policy • Patch Management Policy • Data Disposal Policy • Risk Assessment Policy • Logical Access and User Access Review Policies • Evidence of Review by CIO/CISO and responsibility of program Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The College will develop and implement an information security program to verify our risk management efforts. This plan will identify how we are identifying, assessing and communicating risk. Name(s) of the contact person(s) responsible for corrective action: Scott Seidman, Director of IT Planned completion date for corrective action plan: June 30, 2025
2023-008
FAC accepted this audit on April 1, 2024 — management decision was due October 1, 2024.
During our testing of Title IV checks, we noted refunds of Title IV financial aid outstanding more than 240 days. Questioned costs: $129 Context: During our testing, we noted 2 Title IV refund checks not returned to the Department of Education within 240 days. Cause: Due to management turnover and lack of following policies and procedures, these checks were missed being escheated back to the Department of Education. Effect: The College is not in compliance with Department of Education requirements that all student refund checks that are outstanding for more than 240 days be returned to the Department of Education. Repeat Finding: No Recommendation: We recommend the College review its policies and procedures related to Title IV outstanding checks to ensure they are being returned to the Department of Education after 240 days. Views of responsible officials: There is no disagreement with the finding.
Show full finding ▾Hide full finding ▴2023–002: Outstanding Checks Federal agency: U.S. Department of Education Federal program title: Student Financial Aid Cluster Assistance Listing Numbers: 84.007, 84.033, 84.063, 84.268, 84.379 Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 668.164(l)(3) states that an institution that attempts to disburse funds by check and the check is not cashed, the institution must return the funds to the Secretary no later than 240 days after the date it issued that check. Condition: During our testing of Title IV checks, we noted refunds of Title IV financial aid outstanding more than 240 days. Questioned costs: $129 Context: During our testing, we noted 2 Title IV refund checks not returned to the Department of Education within 240 days. Cause: Due to management turnover and lack of following policies and procedures, these checks were missed being escheated back to the Department of Education. Effect: The College is not in compliance with Department of Education requirements that all student refund checks that are outstanding for more than 240 days be returned to the Department of Education. Repeat Finding: No Recommendation: We recommend the College review its policies and procedures related to Title IV outstanding checks to ensure they are being returned to the Department of Education after 240 days. Views of responsible officials: There is no disagreement with the finding.
Student Financial Aid Cluster – Assistance Listing No. 84.007, 84.033, 84.063, 84.268, 84.379 Recommendation: We recommend the College review its policies and procedures related to Title IV outstanding checks to ensure they are being returned to the Department of Education after 240 days. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The office of Financial Aid and Accounting will review outstanding checks on a monthly basis. In addition, any checks related to financial aid returns or refunds will be sent to the Department of Education within the required time frame. Name(s) of the contact person(s) responsible for corrective action: Larz Jeter – Controller and Jossie Johnson – Financial Aid Director Planned completion date for corrective action plan: September 30, 2024.
During our testing of 40 disbursements, we noted 4 disbursements that were not reported to COD in a timely manner. Questioned costs: None. Context: Disbursements were not reported to COD within the required 15 days. Cause: Due to turnover, management did not ensure disbursements were reported to COD within prescribed timeframes. Effect: The College is not in compliance with the Department of Education regulations. Repeat Finding: No Recommendation: We recommend the College evaluate its procedures and policies around reporting to the COD to ensure that student information is reported timely. Views of responsible officials: There is no disagreement with the finding.
Show full finding ▾Hide full finding ▴2023–003: Common Origination and Disbursement (COD) Reporting Federal agency: U.S. Department of Education Federal program title: Student Financial Aid Cluster Assistance Listing Numbers: 84.268, 84.063 Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Department of Education requires the College to report the disbursement dates and amounts to the COD system within 15 days of disbursing Pell (34 CFR 690.83(b)(2)) and Direct Loan (34 CFR 685.309) funds to a student. Condition: During our testing of 40 disbursements, we noted 4 disbursements that were not reported to COD in a timely manner. Questioned costs: None. Context: Disbursements were not reported to COD within the required 15 days. Cause: Due to turnover, management did not ensure disbursements were reported to COD within prescribed timeframes. Effect: The College is not in compliance with the Department of Education regulations. Repeat Finding: No Recommendation: We recommend the College evaluate its procedures and policies around reporting to the COD to ensure that student information is reported timely. Views of responsible officials: There is no disagreement with the finding.
Student Financial Aid Cluster – Assistance Listing No. 84.063, 84.268 Recommendation: We recommend the College evaluate its procedures and policies around reporting to the COD to ensure that student information is reported timely. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: Financial Aid policies and procedures will be reviewed and amended as necessary. In conjunction with the Registrar’s Office all student changes and information will be reported and reconciled timely. Name(s) of the contact person(s) responsible for corrective action: Jossie Johnson – Director of Financial Aid Planned completion date for corrective action plan: September 30, 2024
During our testing, it was noted that individuals did not receive exit counseling after their departure from the College. Questioned costs: None. Context: 3 out of 40 students tested did not receive exit counseling within the required 30 days of a student ceasing attendance. Cause: The College did not follow its policies and procedures to ensure students who departed the College received direct loan exit counseling. Effect: Students are not receiving the proper loan counseling which may contribute to a higher default rate. Repeat Finding: No Recommendation: We recommend the College review its policies and procedures around sending exit counseling information to students to ensure students are receiving proper counseling. Views of responsible officials: There is no disagreement with the finding.
Show full finding ▾Hide full finding ▴2023–004: Exit Counseling Federal agency: U.S. Department of Education Federal program title: Student Financial Aid Cluster Assistance Listing Numbers: 84.268 Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Code of Federal Regulations, 34 CFR 685.304 require entrance counseling be performed before disbursing loan funds to the student for Direct Subsidized Loan, Direct Unsubsidized Loan and Direct PLUS Loan to a graduate or professional student. The regulations also require exit counseling for all students who cease at least half-time study at the school. Condition: During our testing, it was noted that individuals did not receive exit counseling after their departure from the College. Questioned costs: None. Context: 3 out of 40 students tested did not receive exit counseling within the required 30 days of a student ceasing attendance. Cause: The College did not follow its policies and procedures to ensure students who departed the College received direct loan exit counseling. Effect: Students are not receiving the proper loan counseling which may contribute to a higher default rate. Repeat Finding: No Recommendation: We recommend the College review its policies and procedures around sending exit counseling information to students to ensure students are receiving proper counseling. Views of responsible officials: There is no disagreement with the finding.
Student Financial Aid Cluster – Assistance Listing No. 84.268 Recommendation: We recommend the College review its policies and procedures around sending exit counseling information to students to ensure students are receiving proper counseling. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: Action taken in response to finding: We have conducted a thorough review of our exit counseling procedures and have identified areas of opportunity. Our team is committed to making the necessary corrections to ensure compliance with regulatory requirements. Our goal is to enhance our exit counseling program to better support students in understanding their rights and responsibilities regarding their federal student loans. We will execute this plan by including exit notices in our biweekly notifications, emailing students once an R2T4 is completed and notifying students that are less than halftime students the day after add/ period of each semester. For graduating students, we will host an event leading up to graduation where students can learn about the repayment process and an opportunity for students to complete their exit counseling. . Name(s) of the contact person(s) responsible for corrective action: Jossie Johnson – Director of Financial Aid Planned completion date for corrective action plan: April 30, 2024
During our testing, it was noted that R2T4 calculations were not completed for 2 students. Questioned costs: None. Context: 2 out of 7 students tested should have had a R2T4 calculation completed upon withdrawing from the College. Cause: The College followed their procedures but the report that identifies students who withdrew did not include these students. Effect: Funds are not being returned to the Department of Education. Repeat Finding: No Recommendation: We recommend reviewing the report that is run to identify withdrawn students to understand why these students were not included, as well as implement a compensating control to ensure future students are not missed. Views of responsible officials: There is no disagreement with the finding.
Show full finding ▾Hide full finding ▴2023–005: Return of Title IV (R2T4) Calculations Federal agency: U.S. Department of Education Federal program title: Student Financial Aid Cluster Assistance Listing Numbers: 84.007, 84.063, 84.268, 84.379 Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: In accordance with 34 CFR 668.22(a)(1), when a recipient of Title IV grant or loan assistance withdraws from an institution during a payment period or period of enrollment in which the recipient began attendance, the institution must determine the amount of Title IV grant or loan assistance that the student earned as of the student’s withdrawal date. Condition: During our testing, it was noted that R2T4 calculations were not completed for 2 students. Questioned costs: None. Context: 2 out of 7 students tested should have had a R2T4 calculation completed upon withdrawing from the College. Cause: The College followed their procedures but the report that identifies students who withdrew did not include these students. Effect: Funds are not being returned to the Department of Education. Repeat Finding: No Recommendation: We recommend reviewing the report that is run to identify withdrawn students to understand why these students were not included, as well as implement a compensating control to ensure future students are not missed. Views of responsible officials: There is no disagreement with the finding.
Student Financial Aid Cluster – Assistance Listing No. 84.007, 84.063, 84.268, 84.379 Recommendation: We recommend reviewing the report that is run to identify withdrawn students to understand why these students were not included, as well as implement a compensating control to ensure future students are not missed. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The Financial Aid Office fully understands federal requirements surrounding the completion of R2T4s and strive to remain up to date with R2T4 best practice. We are fully committed to identifying the root cause, implementing corrective actions, and improving the system to prevent similar issues in the future. Name(s) of the contact person(s) responsible for corrective action: Jossie Johnson – Director of Financial Aid and Michael Reig – Registrar. Planned completion date for corrective action plan: April 30, 2024
Certain students’ enrollment information was not reported accurately to the NSLDS. Questioned costs: None. Context: 7 out of 28 students tested were reported with the incorrect effective date on the program-level in NSLDS. Cause: The College's student information system was pulling the effective dates incorrectly for the reports sent to the third-party servicer who report to the NSLDS for which are used for the program-level of the NSLDS. Effect: Inaccurate reporting to the NSLDS can result in incorrect determination of when the students’ grace period should begin. Repeat Finding: No Recommendation: We recommend the College evaluate its procedures and review regulations set by the Department of Education around NSLDS to ensure the College understands the definitions for each enrollment information that gets reported. Views of responsible officials: There is no disagreement with the finding.
Show full finding ▾Hide full finding ▴2023–006: National Student Loan Database System (NSLDS) Reporting Federal agency: U.S. Department of Education Federal program title: Student Financial Aid Cluster Assistance Listing Numbers: 84.063, 84.268 Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: Per U.S. Department of Education (ED) regulations, all schools participating (or approved to participate) in the Federal Student Aid programs must have an arrangement to report student enrollment data to the NSLDS through a roster file. The school is required to report enrollment status at both the school and program level. The school is required to report changes in the student’s enrollment status, the effective date of the status and an anticipated completion date. An academic program is defined as the combination of the school’s Office of Postsecondary Education Identification (OPEID) number and the program’s Classification of Instructional Program (CIP) code, credential level, and published program length. ED requires the College to report changes in enrollment status and indicate the date that the changes occurred (34 CFR 685.309). Condition: Certain students’ enrollment information was not reported accurately to the NSLDS. Questioned costs: None. Context: 7 out of 28 students tested were reported with the incorrect effective date on the program-level in NSLDS. Cause: The College's student information system was pulling the effective dates incorrectly for the reports sent to the third-party servicer who report to the NSLDS for which are used for the program-level of the NSLDS. Effect: Inaccurate reporting to the NSLDS can result in incorrect determination of when the students’ grace period should begin. Repeat Finding: No Recommendation: We recommend the College evaluate its procedures and review regulations set by the Department of Education around NSLDS to ensure the College understands the definitions for each enrollment information that gets reported. Views of responsible officials: There is no disagreement with the finding.
Student Financial Aid Cluster – Assistance Listing No. 84.063, 84.268 Recommendation: We recommend the College evaluate its procedures and review regulations set by the Department of Education around NSLDS to ensure the College understands the definitions for each enrollment information that gets reported. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The college will evaluate our procedures and review regulations to ensure the appropriate enrollment information is reported, timely. Name(s) of the contact person(s) responsible for corrective action: Jossie Johnson – Director of Financial Aid and Michael Reig – Registrar. Planned completion date for corrective action plan: June 30, 2024
Funds were not returned to the Department of Education within 45 days of the College determining the withdrawal. Questioned costs: None. Context: During our testing of R2T4, 1 student out of 7 tested did not have the funds returned to the Department of Education within 45 days. Cause: Due to turnover, management did not ensure funds were returned through the Common Origination and Disbursement (COD) system in the required timeframe. Effect: The College is not in compliance with the Department of Education regulations. Repeat Finding: No Recommendation: We recommend the College evaluate its procedures and policies around reporting to the COD to ensure that student information is reported timely. Views of responsible officials: There is no disagreement with the finding.
Show full finding ▾Hide full finding ▴2023–007: Return of Title IV (R2T4) Returning of Funds Federal agency: U.S. Department of Education Federal program title: Student Financial Aid Cluster Assistance Listing Numbers: 84.007, 84.063, 84.268, 84.379 Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: In accordance with 34 CFR 668.22(j)(1), An institution must return the amount of title IV funds for which it is responsible to return as soon as possible but no later than 45 days after the date of the institution's determination that the student withdrew. Condition: Funds were not returned to the Department of Education within 45 days of the College determining the withdrawal. Questioned costs: None. Context: During our testing of R2T4, 1 student out of 7 tested did not have the funds returned to the Department of Education within 45 days. Cause: Due to turnover, management did not ensure funds were returned through the Common Origination and Disbursement (COD) system in the required timeframe. Effect: The College is not in compliance with the Department of Education regulations. Repeat Finding: No Recommendation: We recommend the College evaluate its procedures and policies around reporting to the COD to ensure that student information is reported timely. Views of responsible officials: There is no disagreement with the finding.
Student Financial Aid Cluster – Assistance Listing No. 84.007, 84.063, 84.268, 84.379 Recommendation: We recommend the College evaluate its procedures and policies around reporting to the COD to ensure that student information is reported timely. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The college will evaluate our procedures and review regulations to ensure the appropriate enrollment information is reported, timely. In the summer of 2023, the financial aid office implemented weekly COD mismatch updates and real time R2T4 adjustments. In doing so, we are ensuring that COD has the most accurate information and adjustments are reported in a timely manner. Name(s) of the contact person(s) responsible for corrective action: Jossie Johnson – Director of Financial Aid and Michael Reig – Registrar. Planned completion date for corrective action plan: June 30, 2024
Under an institution’s Program Participation Agreement with the U.S. Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned costs: None Context: During our audit procedures, it was noted that the College had not developed and implemented an approved written information security program. Cause: The College did not develop and implement a written information security program as required by the Gramm-Leach-Bliley Act. Effect: The students’ personal information could be vulnerable. Repeat Finding: No Recommendation: The College should develop and implement an approved written information security program and verify there is a risk management section that describes how the College is identifying, assessing and communicating risks. In addition, there should be a description on the evaluation of safeguard sufficiency in mitigating risks. The information security program should also include the following: • IT Security Policy • Acceptable Use Policy • Incident Response Policy • Data Classification Policies • Vendor Management Policy • Patch Management Policy • Data Disposal Policy • Risk Assessment Policy • Logical Access and User Access Review Policies • Evidence of Review by CIO/CISO and responsibility of program Views of responsible officials: There is no disagreement with the finding.
Show full finding ▾Hide full finding ▴2023–008: Gramm-Leach-Bliley Act Federal agency: U.S. Department of Education Federal program title: Student Financial Aid Cluster Assistance Listing Numbers: 84.007, 84.033, 84.038, 84.063, 84.268, 84.379 Award Period: July 1, 2022 through June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). Condition: Under an institution’s Program Participation Agreement with the U.S. Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned costs: None Context: During our audit procedures, it was noted that the College had not developed and implemented an approved written information security program. Cause: The College did not develop and implement a written information security program as required by the Gramm-Leach-Bliley Act. Effect: The students’ personal information could be vulnerable. Repeat Finding: No Recommendation: The College should develop and implement an approved written information security program and verify there is a risk management section that describes how the College is identifying, assessing and communicating risks. In addition, there should be a description on the evaluation of safeguard sufficiency in mitigating risks. The information security program should also include the following: • IT Security Policy • Acceptable Use Policy • Incident Response Policy • Data Classification Policies • Vendor Management Policy • Patch Management Policy • Data Disposal Policy • Risk Assessment Policy • Logical Access and User Access Review Policies • Evidence of Review by CIO/CISO and responsibility of program Views of responsible officials: There is no disagreement with the finding.
Student Financial Aid Cluster – Assistance Listing No. 84.007, 84.033, 84.038, 84.063, 84.268, 84.379 Recommendation: The College should develop and implement an approved written information security program and verify there is a risk management section that describes how the College is identifying, assessing and communicating risks. In addition, there should be a description on the evaluation of safeguard sufficiency in mitigating risks. The information security program should also include the following: • IT Security Policy • Acceptable Use Policy • Incident Response Policy • Data Classification Policies • Vendor Management Policy • Patch Management Policy • Data Disposal Policy • Risk Assessment Policy • Logical Access and User Access Review Policies • Evidence of Review by CIO/CISO and responsibility of program Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The college will develop and implement an information security program to verify our risk management efforts. This plan will identify how we are identifying, assessing and communicating risks. Name(s) of the contact person(s) responsible for corrective action: Jossie Johnson - Director of Financial Aid and Scott Seidman – Director of IT Planned completion date for corrective action plan: September 30, 2024
FAC accepted this audit on March 30, 2023 — management decision was due September 30, 2023.
The University has not performed a risk assessments to address (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures and document safeguards for identified risks as required by the Gramm-Leach Bliley Act (GLBA). In addition, the College has not documented safeguards for identified risks. Cause: The College did not have an updated security assessment completed during the year to address procedures and processes in place specific to GLBA and therefore, did not document the required risk assessment or risk mitigation. Effect: With no updated policies and procedures surrounding student information security, the College may be susceptible to threats of consumer nonpublic personal information. Failure to comply with GLBA standards may bring penalties ranging from monetary fines to restriction or loss of eligibility for Title IV funding. Questioned Costs: None. Recommendation: The College should perform and document an annual risk assessment to determine the College's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the College should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the College should identify and document at least one safeguard (i.e., control) for each of the risks identified and document in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Management Response: The College will complete a GLBA risk assessment that addresses (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures and document safeguards for identified risks. The College will complete the assessment in accordance with the December 9, 2021 Federal Trade Commission (FTC) issued final regulations to amend the Standards for Safeguarding Customer Information, including ensuring the College?s written information security program includes the nine elements included in the FTC?s regulations. The College?s risk assessment will be completed by June 2023.
Show full finding ▾Hide full finding ▴Finding 2022-001 - Gramm-Leach Bliley Act (GLBA) CFDA No.: 84.007 Federal Supplemental Education Opportunity Grant, 84.033 Federal Work Study Program, 84.038 Federal Perkins Loans, 84.063 Federal Pell Grant Program, 84.268 Federal Direct Loan Program, 84.379 Teacher Education Assistance for College and Higher Education Grants Award Year: July 1, 2021 - June 30, 2022 Federal Agency: U.S. Department of Education Pass Through Entity: Not applicable Criteria: In accordance with Title IV regulations (CFR 314.1 (b)), an Institution must protect student financial aid information by designating an individual to coordinate the information security program, perform a risk assessment that addresses (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures and document safeguards for identified risks. Condition: The University has not performed a risk assessments to address (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures and document safeguards for identified risks as required by the Gramm-Leach Bliley Act (GLBA). In addition, the College has not documented safeguards for identified risks. Cause: The College did not have an updated security assessment completed during the year to address procedures and processes in place specific to GLBA and therefore, did not document the required risk assessment or risk mitigation. Effect: With no updated policies and procedures surrounding student information security, the College may be susceptible to threats of consumer nonpublic personal information. Failure to comply with GLBA standards may bring penalties ranging from monetary fines to restriction or loss of eligibility for Title IV funding. Questioned Costs: None. Recommendation: The College should perform and document an annual risk assessment to determine the College's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the College should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the College should identify and document at least one safeguard (i.e., control) for each of the risks identified and document in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Management Response: The College will complete a GLBA risk assessment that addresses (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures and document safeguards for identified risks. The College will complete the assessment in accordance with the December 9, 2021 Federal Trade Commission (FTC) issued final regulations to amend the Standards for Safeguarding Customer Information, including ensuring the College?s written information security program includes the nine elements included in the FTC?s regulations. The College?s risk assessment will be completed by June 2023.
FINDING 2022-001: 84.007 Federal Supplemental Education Opportunity Grant, 84.033 Federal Work Study Program, 84.038 Federal Perkins Loans, 84.063 Federal Pell Grant Program, 84.268 Federal Direct Loan Program, 84.379 Teacher Education Assistance for College and Higher Education Grants Recommendation: The College should perform and document an annual risk assessment to determine the College's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the College should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the College should identify and document at least one safeguard (i.e., control) for each of the risks identified and document in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Action To Be Taken: The College will complete a GLBA risk assessment that addresses (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures and document safeguards for identified risks. The College will complete the assessment in accordance with the December 9, 2021 Federal Trade Commission (FTC) issued final regulations to amend the Standards for Safeguarding Customer Information, including ensuring the College?s written information security program includes the nine elements included in the FTC?s regulations. Responsible Individual for Corrective Action: Scott Seidman, Director of IT Services Anticipated Completion Date: June 15, 2023
FAC accepted this audit on July 10, 2022 — management decision was due January 10, 2023.
FAC accepted this audit on July 25, 2021 — management decision was due January 25, 2022.
FAC accepted this audit on March 26, 2020 — management decision was due September 26, 2020.
The College has not designated an individual for coordinating an information security program, nor was a risk assessment performed to address employee training and management, information systems, and detecting, preventing and responding to system attacks or failures. Questioned Costs: None noted. Context: Through discussions with management, specific procedures and processes surrounding the GLBA do not exist. Effect: With no formal policies and procedures surrounding student information security, the College may be susceptible to threats of consumer nonpublic personal information. Cause: The College does not have a designated coordinator nor has it performed proper risk assessment procedures to address GLBA. Recommendation: The College should designate an individual responsible for coordinating the information security program. The individual should have the appropriate experience and authority to identify the risks relevant to consumer nonpublic personal information (e.g., banking and financial data from students/parents/guardians applying for financial aid). The individual should also be able to coordinate the implementation of the appropriate technical, administrative, and physical safeguards to address the identified risks. Additionally, the College should perform and document an annual risk assessment to determine the College's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the College should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the College should identify and document at least one safeguard (i.e., control) for each of the risks identified and document in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. The College has recently designated its IT Director as the individual responsible for coordinating an information security program that complies with the requirements of the Gramm-Leach-Bliley Act. Specifically, the IT Director has been charged with the responsibility of conducting an annual risk assessment that includes consideration of relevant risks in each of the following areas: employee training and management; information systems, including network and software design, as well as information processing, storage, transmission and disposal; and detecting, preventing and responding to attacks, intrusions, or other systems failures, and document safeguards for identified risks.
Show full finding ▾Hide full finding ▴Criteria: In accordance with Title IV regulations (CFR 314.1 (b)), an College is required to designate an individual to coordinate the information security program, perform a risk assessment that addresses (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures, and document safeguards for identified risks. Condition: The College has not designated an individual for coordinating an information security program, nor was a risk assessment performed to address employee training and management, information systems, and detecting, preventing and responding to system attacks or failures. Questioned Costs: None noted. Context: Through discussions with management, specific procedures and processes surrounding the GLBA do not exist. Effect: With no formal policies and procedures surrounding student information security, the College may be susceptible to threats of consumer nonpublic personal information. Cause: The College does not have a designated coordinator nor has it performed proper risk assessment procedures to address GLBA. Recommendation: The College should designate an individual responsible for coordinating the information security program. The individual should have the appropriate experience and authority to identify the risks relevant to consumer nonpublic personal information (e.g., banking and financial data from students/parents/guardians applying for financial aid). The individual should also be able to coordinate the implementation of the appropriate technical, administrative, and physical safeguards to address the identified risks. Additionally, the College should perform and document an annual risk assessment to determine the College's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the College should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the College should identify and document at least one safeguard (i.e., control) for each of the risks identified and document in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. The College has recently designated its IT Director as the individual responsible for coordinating an information security program that complies with the requirements of the Gramm-Leach-Bliley Act. Specifically, the IT Director has been charged with the responsibility of conducting an annual risk assessment that includes consideration of relevant risks in each of the following areas: employee training and management; information systems, including network and software design, as well as information processing, storage, transmission and disposal; and detecting, preventing and responding to attacks, intrusions, or other systems failures, and document safeguards for identified risks.
Finding 2019-001 - N. Special Tests and Provisions - Gramm-Leach-Bliley Act ("GLBA") Recommendation: The College should designate an individual responsible for coordinating the information security program. The individual should have the appropriate experience and authority to identify the risks relevant to consumer nonpublic personal information (e.g., banking and financial data from students/parents/guardians applying for financial aid). The individual should also be able to coordinate the implementation of the appropriate technical, administrative, and physical safeguards to address the identified risks. Additionally, the College should perform and document an annual risk assessment to determine the College's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the College should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the College should identify and document at least one safeguard (i.e., control) for each of the risks identified and document in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. Effective March 1, 2020, the College designated its IT Director as the individual responsible for coordinating an information security program that complies with the requirements of the Gramm-Leach-Bliley Act. Specifically, the IT Director has been charged with the responsibility of conducting an annual risk assessment that includes consideration of relevant risks in each of the following areas: employee training and management; information systems, including network and software design, as well as information processing, storage, transmission and disposal; and detecting, preventing and responding to attacks, intrusions, or other systems failures, and document safeguards for identified risks.
G5 Drawdown requests were not documented as reviewed and approved by a responsible party separate from the preparer. Questioned Costs: None noted. Context: The College drew funds from the G5 44 times during the period 7/1/18-6/30/19. Five of the five G5 draws tested did not contain documentation of review or approval by someone other than the preparer. The sample was not a statistically valid sample. Effect: Due to the lack of documented review and approval, the College could be at risk for erroneous or fraudulent drawdowns to be requested. Cause: The funds were being requested by the Controller and discussed with the Vice President of Financial Affairs, but no documentation of review or approval of amounts drawn from G5 was maintained. Recommendation: We recommend the College maintain documentation of the review and approval of G5 drawdown requests by a responsible party separate from the preparer. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. Effective immediately, funds identified by the Director of Financial Aid as being available for drawdown from G5 will be communicated to the Controller. The Controller and the Vice President for Financial Affairs (VPFA) will review the amount to be drawn down and the VPFA will approve the amount to be drawn prior to the draw being made by the Controller. The review and approval by the VPFA of the G5 drawdown request will be properly documented.
Show full finding ▾Hide full finding ▴Criteria: Title IV regulations (34 CFR 668.16) require recipients of federal awards to administer its federal programs with an adequate system of internal controls over Cash Management. Condition: G5 Drawdown requests were not documented as reviewed and approved by a responsible party separate from the preparer. Questioned Costs: None noted. Context: The College drew funds from the G5 44 times during the period 7/1/18-6/30/19. Five of the five G5 draws tested did not contain documentation of review or approval by someone other than the preparer. The sample was not a statistically valid sample. Effect: Due to the lack of documented review and approval, the College could be at risk for erroneous or fraudulent drawdowns to be requested. Cause: The funds were being requested by the Controller and discussed with the Vice President of Financial Affairs, but no documentation of review or approval of amounts drawn from G5 was maintained. Recommendation: We recommend the College maintain documentation of the review and approval of G5 drawdown requests by a responsible party separate from the preparer. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. Effective immediately, funds identified by the Director of Financial Aid as being available for drawdown from G5 will be communicated to the Controller. The Controller and the Vice President for Financial Affairs (VPFA) will review the amount to be drawn down and the VPFA will approve the amount to be drawn prior to the draw being made by the Controller. The review and approval by the VPFA of the G5 drawdown request will be properly documented.
Finding 2019-002 - C. Cash Management Recommendation: We recommend the College require the G5 drawdown request to be reviewed and approved by a responsible party separate from the preparer. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. Effective immediately, funds identified by the Director of Financial Aid as being available for drawdown from G5 will be communicated to the Controller. The Controller and the Vice President for Financial Affairs (VPFA) will review the amount to be drawn down and the VPFA will approve the amount to be drawn prior to the draw being made by the Controller. The review and approval by the VPFA of the G5 drawdown request will be properly documented.
The monthly reconciliations of direct loans were not completed timely, and documentation of completed reconciliations were not maintained. Questioned Costs: None noted. Context: We selected a sample of 3 monthly direct loan reconciliations. The College was unable to provide documentation of the reconciliation for any of the 3 months selected. The sample was not statistically valid. Effect: The College did not have an appropriate system of internal controls over compliance in place to prevent noncompliance. The College failed to reconcile direct loans to the COD as required. Cause: Due to turn over within the Student Financial Aid department, reconciliations were not completed timely, if at all. No evidence of complete reconciliations throughout the year were maintained. Recommendation: We recommend the College review and follow its procedures for monthly reconciliations to ensure their system agrees to the activity within COD and that they are in compliance with SAS reconciliation obligations. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. The College has recently named a Director of Financial Aid and hired an Executive Director of Student Financial Services and instituted new policies and procedures to ensure that reconciliations are performed on a timely basis as required by DOE. The Executive Director of Student Financial Services has been charged with the responsibility of ensuring that monthly reconciliations are completed and submitted to the Controller for review and approval.
Show full finding ▾Hide full finding ▴Criteria: Title IV regulations (34 CFR 668.16) requires recipients of federal awards to administer its federal programs with an adequate system of internal controls over Federal Direct Loan Reconciliations. Colleges must report all loan disbursements and submit required records to U.S. Department of Education Common Origination & Disbursement (COD) within 15 days of disbursement (OMB No. 1845-0021). Each month, the COD provides Colleges with a College Account Statement ("SAS") data file which consists of a Cash Summary, Cash Detail, and (optional at the request of the College ) Loan Detail records. The College is required to reconcile these files to the College's financial records. Since up to three Direct Loan program years may be open at any given time, College?s may receive three SAS data files each month (34 CFR 685.102(b), 685.301, and 303). Condition: The monthly reconciliations of direct loans were not completed timely, and documentation of completed reconciliations were not maintained. Questioned Costs: None noted. Context: We selected a sample of 3 monthly direct loan reconciliations. The College was unable to provide documentation of the reconciliation for any of the 3 months selected. The sample was not statistically valid. Effect: The College did not have an appropriate system of internal controls over compliance in place to prevent noncompliance. The College failed to reconcile direct loans to the COD as required. Cause: Due to turn over within the Student Financial Aid department, reconciliations were not completed timely, if at all. No evidence of complete reconciliations throughout the year were maintained. Recommendation: We recommend the College review and follow its procedures for monthly reconciliations to ensure their system agrees to the activity within COD and that they are in compliance with SAS reconciliation obligations. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. The College has recently named a Director of Financial Aid and hired an Executive Director of Student Financial Services and instituted new policies and procedures to ensure that reconciliations are performed on a timely basis as required by DOE. The Executive Director of Student Financial Services has been charged with the responsibility of ensuring that monthly reconciliations are completed and submitted to the Controller for review and approval.
Finding 2019-003 - N. Special Tests and Provisions-Direct Loan Reconciliation Recommendation: We recommend the College review and follow its procedures for monthly reconciliations to ensure their system agrees to the activity within COD and that they are in compliance with SAS reconciliation obligations. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. The College has recently named a Director of Financial Aid and hired an Executive Director of Student Financial Services and instituted new policies and procedures to ensure that reconciliations are performed on a timely basis as required by DOE. Effective march 9, 2020, the Executive Director of Student Financial Services has been charged with the responsibility of ensuring that monthly reconciliations are completed and submitted to the Controller for review and approval.
During testing we noted one instance where the College awarded a Graduate Plus loan to a student that caused the student's financial assistance received to be greater than the student's cost of attendance. Questioned Costs: One student was awarded $7,546 in Graduate Plus Loan funds that the student was not eligible for, resulting in an over award of Title IV funds and actual questioned costs. Questioned costs of this finding projected over the program are $177,732. Context: We selected 44 students and identified 1 over award. The student was in the Doctoral program and the over-award was related to their summer session, which most students receiving funds would not qualify for. The sample was not statistically valid. Effect: The student received Graduate Plus loan funds that the student was not eligible to receive. Cause: Due to turn over within the Student Financial Aid department, the student?s change in cost of attendance was not updated on the student account prior to disbursement, resulting in an over award. Recommendation: The College should ensure all changes to cost of attendance are captured in the student accounts, and result in a reassessment of award eligibility, as necessary. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. The College has recently named a Director of Financial Aid and hired an Executive Director of Student Financial Services. New policies and procedures have been instituted to ensure that Direct Subsidized, Direct Unsubsidized, or Direct PLUS Loan amounts do not exceed the student?s estimated cost of attendance for the period of enrollment for which the loans were intended, less the student?s estimated financial assistance for that period and the borrower?s expected family contribution for that period. Since it has been discovered that there is no fail-safe in the Powerfaids system to ensure that students are not over-awarded when there is a change in credits during drop/add period after initial packaging is completed, the Financial Aid Director has recently implemented an internal report to catch those occurrences. This report is generated by the Director of Financial aid on a weekly basis for financial aid staff members to complete packaging adjustments prior to Title-IV loan disbursements. In addition, all Title-IV refunds are reviewed by the Director of Financial Aid and/or the Assistant Director of Financial aid to ensure that Direct Subsidized, Direct Unsubsidized, or Direct PLUS Loans have not exceeded the student?s cost of attendance, with approval by the Executive Director of Student Financial Services before a refund is issued.
Show full finding ▾Hide full finding ▴Criteria: Title IV regulations (34 CFR 685.203) states in no case may Direct Subsidized, Direct Unsubsidized, or Direct PLUS Loan amount exceed the student's estimated cost of attendance for the period of enrollment for which the loans were intended, less (1) the student's estimated financial assistance for that period and (2) the borrower's expected family contribution for that period. Condition: During testing we noted one instance where the College awarded a Graduate Plus loan to a student that caused the student's financial assistance received to be greater than the student's cost of attendance. Questioned Costs: One student was awarded $7,546 in Graduate Plus Loan funds that the student was not eligible for, resulting in an over award of Title IV funds and actual questioned costs. Questioned costs of this finding projected over the program are $177,732. Context: We selected 44 students and identified 1 over award. The student was in the Doctoral program and the over-award was related to their summer session, which most students receiving funds would not qualify for. The sample was not statistically valid. Effect: The student received Graduate Plus loan funds that the student was not eligible to receive. Cause: Due to turn over within the Student Financial Aid department, the student?s change in cost of attendance was not updated on the student account prior to disbursement, resulting in an over award. Recommendation: The College should ensure all changes to cost of attendance are captured in the student accounts, and result in a reassessment of award eligibility, as necessary. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. The College has recently named a Director of Financial Aid and hired an Executive Director of Student Financial Services. New policies and procedures have been instituted to ensure that Direct Subsidized, Direct Unsubsidized, or Direct PLUS Loan amounts do not exceed the student?s estimated cost of attendance for the period of enrollment for which the loans were intended, less the student?s estimated financial assistance for that period and the borrower?s expected family contribution for that period. Since it has been discovered that there is no fail-safe in the Powerfaids system to ensure that students are not over-awarded when there is a change in credits during drop/add period after initial packaging is completed, the Financial Aid Director has recently implemented an internal report to catch those occurrences. This report is generated by the Director of Financial aid on a weekly basis for financial aid staff members to complete packaging adjustments prior to Title-IV loan disbursements. In addition, all Title-IV refunds are reviewed by the Director of Financial Aid and/or the Assistant Director of Financial aid to ensure that Direct Subsidized, Direct Unsubsidized, or Direct PLUS Loans have not exceeded the student?s cost of attendance, with approval by the Executive Director of Student Financial Services before a refund is issued.
Finding 2019-004 - E. Eligibility- Direct Plus Loans Recommendation: The College should ensure all changes to cost of attendance are captured in the student accounts, and result in a reassessment of award eligibility, as necessary. Management Response: Management acknowledges the finding reported by Baker Tilly and its recommendation to safeguard against reoccurrence of the reported condition. The College has recently named a Director of Financial Aid and hired an Executive Director of Student Financial Services. New policies and procedures have been instituted to ensure that Direct Subsidized, Direct Unsubsidized, or Direct PLUS Loan amounts do not exceed the student?s estimated cost of attendance for the period of enrollment for which the loans were intended, less the student?s estimated financial assistance for that period and the borrower?s expected family contribution for that period. Since it has been discovered that there is no fail-safe in the Powerfaids system to ensure that students are not over-awarded when there is a change in credits during drop/add period after initial packaging is completed, the Financial Aid Director has recently implemented an internal report effective January 1, 2020 to catch those occurrences. This report is generated by the Director of Financial aid on a weekly basis for financial aid staff members to complete packaging adjustments prior to Title-IV loan disbursements. In addition, all Title-IV refunds are reviewed by the Director of Financial Aid and/or the Assistant Director of Financial aid to ensure that Direct Subsidized, Direct Unsubsidized, or Direct PLUS Loans have not exceeded the student?s cost of attendance, with approval by the Executive Director of Student Financial Services before a refund is issued.
FAC accepted this audit on March 27, 2019 — management decision was due September 27, 2019.
FAC accepted this audit on March 6, 2018 — management decision was due September 6, 2018.
FAC accepted this audit on February 1, 2017 — management decision was due August 1, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in Pennsylvania →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.