EIN: 231639911
UEI: HNUUWKKDLDA5
Audited by: BAKER TILLY US, LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of August 28, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on October 26, 2023. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by April 26, 2024 (855 days ago).
What is a management decision? →FAC accepted this audit on October 25, 2022 — management decision was due April 25, 2023.
FAC accepted this audit on October 20, 2021 — management decision was due April 20, 2022.
FAC accepted this audit on February 25, 2021 — management decision was due August 25, 2021.
FAC accepted this audit on November 17, 2019 — management decision was due May 17, 2020.
Finding 2019-001 - Gramm-Leach-Bliley Act ("GLBA") CFDA No.: 84.033, 84.268, 84.063, 84.038, 84.007 Federal Award Year: June 30, 2019 Federal Agency: U.S. Department of Education Criteria In accordance with Title IV regulations (CFR 314.1 (b)), an Institution is required to designate an individual to coordinate the information security program, perform a risk assessment that addresses (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures, and document safeguards for identified risks. Condition The University has not designated an individual for coordinating an information security program, nor was a risk assessment performed to address employee training and management, information systems, and detecting, preventing and responding to system attacks or failures. Questioned costs None noted. Context Through discussions with management, specific procedures and processes surrounding the GLBA do not exist. Effect With no formal policies and procedures surrounding student information security, the University may be susceptible to threats of consumer nonpublic personal information. Cause The University does not have a designated coordinator nor has it performed proper risk assessment procedures to address GLBA. Recommendation The University should designate an individual responsible for coordinating the information security program. The individual should have the appropriate experience and authority to identify the risks relevant to consumer nonpublic personal information (e.g., banking and financial data from students/parents/guardians applying for financial aid). The individual should also be able to coordinate the implementation of the appropriate technical, administrative, and physical safeguards to address the identified risks. Additionally, the University should perform and document an annual risk assessment to determine the University's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the University should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the University should identify and document at least one safeguard (i.e., control) for each of the risks identified and document in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Management Response The University is undertaking an independent security assessment from a third party vendor. The assessment should be complete by the end of calendar year 2019. The report will identify, assess, and prioritize our security vulnerabilities and offer high level remediation options. Issues that take us out of compliance with GLBA will be top priority. Once the report is delivered, the University will move to address all issues that have compliance implications. The University plans on conducting an annual risk assessment update. Additionally, the University plans to retain the services of an external Chief Information Security Officer (?CISO?) resource during the 2020 fiscal year who will guide the remediation efforts that emerge from the security assessment, as well as oversee the University?s information security program and information safeguard program. The University?s Director of Information Services has been designated as the primary on-staff position responsible for working with the CISO to interpret and implement the recommendations that come out of the security risk assessment, and to implement ongoing employee training is this area.
Show full finding ▾Hide full finding ▴Finding 2019-001 - Gramm-Leach-Bliley Act ("GLBA") CFDA No.: 84.033, 84.268, 84.063, 84.038, 84.007 Federal Award Year: June 30, 2019 Federal Agency: U.S. Department of Education Criteria In accordance with Title IV regulations (CFR 314.1 (b)), an Institution is required to designate an individual to coordinate the information security program, perform a risk assessment that addresses (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures, and document safeguards for identified risks. Condition The University has not designated an individual for coordinating an information security program, nor was a risk assessment performed to address employee training and management, information systems, and detecting, preventing and responding to system attacks or failures. Questioned costs None noted. Context Through discussions with management, specific procedures and processes surrounding the GLBA do not exist. Effect With no formal policies and procedures surrounding student information security, the University may be susceptible to threats of consumer nonpublic personal information. Cause The University does not have a designated coordinator nor has it performed proper risk assessment procedures to address GLBA. Recommendation The University should designate an individual responsible for coordinating the information security program. The individual should have the appropriate experience and authority to identify the risks relevant to consumer nonpublic personal information (e.g., banking and financial data from students/parents/guardians applying for financial aid). The individual should also be able to coordinate the implementation of the appropriate technical, administrative, and physical safeguards to address the identified risks. Additionally, the University should perform and document an annual risk assessment to determine the University's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the University should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the University should identify and document at least one safeguard (i.e., control) for each of the risks identified and document in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Management Response The University is undertaking an independent security assessment from a third party vendor. The assessment should be complete by the end of calendar year 2019. The report will identify, assess, and prioritize our security vulnerabilities and offer high level remediation options. Issues that take us out of compliance with GLBA will be top priority. Once the report is delivered, the University will move to address all issues that have compliance implications. The University plans on conducting an annual risk assessment update. Additionally, the University plans to retain the services of an external Chief Information Security Officer (?CISO?) resource during the 2020 fiscal year who will guide the remediation efforts that emerge from the security assessment, as well as oversee the University?s information security program and information safeguard program. The University?s Director of Information Services has been designated as the primary on-staff position responsible for working with the CISO to interpret and implement the recommendations that come out of the security risk assessment, and to implement ongoing employee training is this area.
CORRECTIVE ACTION PLAN October 31, 2019 The University of the Arts (`the University?) respectfully submits the following corrective action plan for the year ended June 30, 2019. Name and address of independent public accounting firm: Baker Tilly Virchow Krause, LLP 1650 Market Street, Suite 4500 Philadelphia, Pennsylvania 19103 Audit period: June 30, 2019 The findings from the June 30, 2019 schedule of findings and questioned costs are discussed below. FINDINGS ? FEDERAL AWARD FINDINGS AND QUESTIONED COSTS Finding 2019-001 - Gramm-Leach-Bliley Act ("GLBA") Recommendation: The University should designate an individual responsible for coordinating the information security program. The individual should have the appropriate experience and authority to identify the risks relevant to consumer nonpublic personal information (e.g., banking and financial data from students/parents/guardians applying for financial aid). The individual should also be able to coordinate the implementation of the appropriate technical, administrative, and physical safeguards to address the identified risks. Additionally, the University should perform and document an annual risk assessment to determine the University's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the University should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the University should identify and document at least one safeguard (i.e., control) for each of the risks identified and document in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Action Plan: Management understands what is required to fully comply with GLBA, and while not fully in compliance yet, we have taken significant steps toward full compliance. Specifically: Our ERP is only accessible on our network or through a secure VPN. Our data centers are locked, and only accessible to a few staff members. Users who can log into our systems are trained in advance, and their ERP passwords are reset every 90 days. No credit card numbers are stored on any of our enterprise applications. Users? security rights are audited annually to make sure that they are aligned with their current job responsibilities. Sensitive data in encrypted in transit over our network. The student network is separated from the faculty and staff network. Accounts from employees who leave the university are deleted after 90 days. There are multiple projects underway as of the date of this report, to identify and address these challenges. First, we are in the process of implementing a new password policy that will require that users reset their network passwords more frequently. We are also implementing Multi-factor Authentication (MFA), and this should be in place by March 31, 2021. MFA will be leveraged for all users attempting to access our VPN or attempting to log in to our single-sign-on platform. Second, we are taking efforts to formalize implement a data and document retention practice at the University. This process has included crafting and implementing a policy, and should be completed by the end of the 2019 calendar year with staff training and destruction of obsolete documents and data. Third, and most importantly, the University is undertaking an independent security assessment from a third party vendor. The assessment should be complete by the end of calendar year 2019. The report will identify, assess, and prioritize our security vulnerabilities and offer high level remediation options. Issues that take us out of compliance with GLBA will be top priority. Once the report is delivered, the University will move to address all issues that have compliance implications. The University plans on conducting an annual risk assessment update. Finally, the University plans to retain the services of an external Chief Information Security Officer (?CISO?) resource during the 2020 fiscal year who will guide the remediation efforts that emerge from the security assessment, as well as oversee the University?s information security program and information safeguard program. The University?s Director of Information Services has been designated as the primary on-staff position responsible for working with the CISO to interpret and implement the recommendations that come out of the security risk assessment, and to implement ongoing employee training is this area. If there are any questions regarding this plan please call Charles Avner, Assistant Vice President and Controller, at cavner@uarts.edu. Sincerely yours, Charles Avner Assistant Vice President and Controller
FAC accepted this audit on March 5, 2019 — management decision was due September 5, 2019.
FAC accepted this audit on November 28, 2017 — management decision was due May 28, 2018.
FAC accepted this audit on December 1, 2016 — management decision was due June 1, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.