← Back to home

Chatham UniversityHigher Education

EIN: 250717890

UEI: M9MKPRAMFD85

Audited by: CliftonLarsonAllen LLP

Oversight agency: 84 [Department of Education]

View federal awards & risk assessment →

Data as of September 7, 2026

Chatham University10 audit years3 findings
10
Audit Years
3
Total Findings
0
Repeat Findings
$27.8M
Federal Awards Expended (FY 2025)

FY 2025-06-30

LOW-RISK AUDITEE$27,802,566 federal awards expended

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 27, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 27, 2026 (15 days from today).

What is a management decision? →
Funder? Track this deadline →
2025-001
Eligibility / Special Tests & Provisions
SIGNIFICANT DEFICIENCYOTHER MATTERS

The University was unable to produce documentation of the internal controls being performed for certain items selected for testing described above. Questioned Costs: N/A Cause: The University did not have internal control documentation retained for all items selected for testing. Effects: No documentation of internal controls being performed. Repeat Finding: Not a repeat finding. Recommendation: Management should review internal control documentation processes. Views of Responsible Officials: Management agrees and has a plan to correct the finding.

Show full finding ▾
Full finding narrative

Retention of Certain Internal Control Documentation Federal Agencies: United States Department of Education Federal Program Title: Student Financial Assistance Cluster Federal Assistance Listing Number: 84.063, 84.007, 84.033, 84.268 Award Period: 7/1/2024-6/30/2025 Type of Finding: Significant Deficiency in Internal Controls Over Compliance and Other Matter Criteria or Specific Requirement: The Student Financial Assistance cluster requires that there be documented procedures and controls in place to ensure timely and accurate COD Disbursement reporting, as well as documented procedures and controls in place to ensure excess federal aid disbursed to students accounts is either paid to the student within 14 days, or if the institution obtained an authorization to hold credit balance, by the end of the loan period or last payment period in the award year for which the funds were awarded. Condition: The University was unable to produce documentation of the internal controls being performed for certain items selected for testing described above. Questioned Costs: N/A Cause: The University did not have internal control documentation retained for all items selected for testing. Effects: No documentation of internal controls being performed. Repeat Finding: Not a repeat finding. Recommendation: Management should review internal control documentation processes. Views of Responsible Officials: Management agrees and has a plan to correct the finding.

Corrective Action Plan

United States Department of Education Student Financial Assistance Cluster - Assistance Listing No. 84.SFA Condition: The University was unable to provide documentation of certain instances of internal controls procedures occurring. Recommendation: Management should review policies and procedures over retention of internal control documentation. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: Processes and procedues were reviewed, updated, documented and implemented upon the hiring of Assistant Vice President of Financial Aid, Jill Bittel on September 15, 2025. Name(s) of the contact person(s) responsible for corrective action: Jill Bittel, Assistant Vice President, Financial Aid Planned completion date for corrective action plan: Complete and provided to audit to prove current processes in place with all new staff are corretly implemented.

About Eligibility, Special Tests and Provisions →

FY 2024-06-30

LOW-RISK AUDITEE$29,127,317 federal awards expendedNo findings recorded this year

FAC accepted this audit on January 3, 2025 — management decision was due July 3, 2025.

FY 2023-06-30

LOW-RISK AUDITEE$32,261,995 federal awards expended

FAC accepted this audit on March 29, 2024 — management decision was due September 29, 2024.

2023-002
Special Tests & Provisions
SIGNIFICANT DEFICIENCYOTHER MATTERS

The University does was not able to demonstrate its compliance with 16 CFR 314.4(f). Cause: The University does not currently have a vendor management review process in place. Effect or potential effect: Without consideration for oversight of its information system service providers, the University’s information system security program may not adequately address the risks that these service providers, and their systems, have on the University’s environment. Questioned Costs: None noted. Context: We were unable to verify that the University has a vendor management review process in place. Identification as a Repeat Finding: This is not a repeat finding. Recommendation: We recommend that policies and procedures be put in place to ensure that regular vendor management reviews on information system service providers are conducted in an appropriate manner. Views of Responsible Officials: Management concurs with this finding. See management’s corrective action plan document.

Show full finding ▾
Full finding narrative

Federal Program Information: Student Financial Assistance Cluster (ALN: Various), U.S. Department of Education. 2022-2023 Federal Award Year. Criteria or Specific Requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314). The audit finding was based on 16 CFR 314.4(f), which requires that the University have a policy that addresses how the institution will oversee its information system service providers. Condition: The University does was not able to demonstrate its compliance with 16 CFR 314.4(f). Cause: The University does not currently have a vendor management review process in place. Effect or potential effect: Without consideration for oversight of its information system service providers, the University’s information system security program may not adequately address the risks that these service providers, and their systems, have on the University’s environment. Questioned Costs: None noted. Context: We were unable to verify that the University has a vendor management review process in place. Identification as a Repeat Finding: This is not a repeat finding. Recommendation: We recommend that policies and procedures be put in place to ensure that regular vendor management reviews on information system service providers are conducted in an appropriate manner. Views of Responsible Officials: Management concurs with this finding. See management’s corrective action plan document.

Corrective Action Plan

Chatham University’s Response to Schneider Downs’ Finding 2023 - 002 - Student Financial Assistance - Cluster, Department of Education Programs, in connection with their audit of the University’s financial statements for the year ended June 30, 2023. The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314). The audit finding was based on 16 CFR 314.4(f), which requires the University to have a policy addressing how the institution will oversee its information system service providers. Issue and Cause: The University does not have a vendor management review process for information system service providers. Action Plan: The University acknowledges the specific requirements outlined in the finding and presents the following action plan to address the requirements of 16 CFR 314. • The University has a draft Vendor Access to Internal Systems Policy developed in 2021 that needs to be finalized and formally adopted. • The Chief Information Officer will review, update, and finalize this policy to ensure compliance with 16 CFR 314, 4(f). • The policy will be added to the University’s Cyber & Regulatory Compliance Policy document on the Intranet and any public-facing web pages as necessary. • The policy will be distributed to applicable information system service providers. • A process for the mandatory annual review and acknowledgment of the policy with applicable vendors will be implemented. • The University will consider the costs and benefits of using external resources or firms to advise and help implement this action plan. Chatham University’s Chief Information Officer, Paul Steinhaus, is responsible for implementing this corrective action by May 1, 2024.

About Special Tests and Provisions →

FY 2022-06-30

LOW-RISK AUDITEE$33,563,460 federal awards expendedNo findings recorded this year

FAC accepted this audit on January 19, 2023 — management decision was due July 19, 2023.

FY 2021-06-30

LOW-RISK AUDITEE$32,974,036 federal awards expendedNo findings recorded this year

FAC accepted this audit on November 21, 2021 — management decision was due May 21, 2022.

FY 2020-06-30

LOW-RISK AUDITEE$33,443,884 federal awards expendedNo findings recorded this year

FAC accepted this audit on June 21, 2021 — management decision was due December 21, 2021.

FY 2019-06-30

LOW-RISK AUDITEE$34,414,809 federal awards expended

FAC accepted this audit on November 19, 2019 — management decision was due May 19, 2020.

2019-001
Special Tests & Provisions
SIGNIFICANT DEFICIENCYOTHER MATTERS

The University did not have written documentation to demonstrate its compliance with the requirements of 16 CFR 314. Cause: The University has not yet formalized its student financial aid security program in a formal manner. Effect or potential effect: If the University has not performed a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and documented safeguards for identified risks, there may be inadequate safeguards of student financial aid information. Questioned Costs: None noted. Context: We were unable to verify whether the University?s designated individual coordinated the information security program, performed a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and documented safeguards for identified risks. Identification as a Repeat Finding: This is not a repeat finding. Recommendation: We recommend that the University formally coordinate the information security program, perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and document safeguards for identified risks. Views of Responsible Officials: Management concurs with this finding. (See separate corrective action plan document.)

Show full finding ▾
Full finding narrative

SECTION 1 - SUMMARY OF AUDITORS? RESULTS Financial Statements: Type of report the auditor issued on whether the financial statements were prepared in accordance with accounting principles generally accepted in the United States of America: Unmodified Internal control over financial reporting: Material weakness identified? - no Significant deficiency identified? yes Noncompliance material to financial statements notes - no Federal Awards: Internal control over major programs: Material weakness identified? - no Significant deficiency identified? yes Type of auditors? report on compliance for major federal programs: Unmodified Any audit findings disclosed that are required to be reported in accordance with 2 CFR 200.516(a)? no Identification of major federal programs: CFDA Numbers Name of Federal Program or Cluster: 84.063, 84.007, 84.033, 84.038, 84.268 Student Financial Aid Cluster Dollar threshold used to distinguish between Type A and Type B programs: $750,000 Auditee qualified as low-risk auditee? yes SECTION II - FINANCIAL STATEMENT FINDINGS This section identifies the significant deficiencies, material weaknesses, fraud, noncompliance with provisions of laws, regulations, contracts, grant agreements and abuse related to the consolidated financial statements for which Government Auditing Standards require reporting. See Section III - Federal Awards Findings and Questioned Costs for the full context of Finding 2019-001, which was both a financial statement and federal award finding. SECTION III - FEDERAL AWARD FINDINGS AND QUESTIONED COSTS This section identifies the audit findings required to be reported by 2 CFR 200.516(a) (significant deficiencies, material weaknesses, material instances of noncompliance, including questioned costs and material abuse). Finding 2019-001 Student Financial Assistance - Cluster, Department of Education Programs Program Names: 84.007 - Federal Supplemental Educational Opportunity Grants, 84.033 - Federal Work-Study Program, 84.038 - Federal Perkins Loan, 84.063 - Federal Pell Grant Program, 84.268 - Federal Direct Student Loans Criteria or Specific Requirement: Under an institution?s Program Participation Agreement with the Department of Education (Department) and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. (16 CFR 314.3; HEA 483(a)(3)(E) and HEA 485B(d)(2)) Condition: The University did not have written documentation to demonstrate its compliance with the requirements of 16 CFR 314. Cause: The University has not yet formalized its student financial aid security program in a formal manner. Effect or potential effect: If the University has not performed a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and documented safeguards for identified risks, there may be inadequate safeguards of student financial aid information. Questioned Costs: None noted. Context: We were unable to verify whether the University?s designated individual coordinated the information security program, performed a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and documented safeguards for identified risks. Identification as a Repeat Finding: This is not a repeat finding. Recommendation: We recommend that the University formally coordinate the information security program, perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and document safeguards for identified risks. Views of Responsible Officials: Management concurs with this finding. (See separate corrective action plan document.)

Corrective Action Plan

Chatham University?s (University) Response to Schneider Downs? Finding 2019-01, in connection with their audit of the University?s financial statements for the year ended June 30, 2019: The University takes the responsibility of protecting student financial aid information very seriously. The University?s Chief Information Officer (CIO) is the designated individual with responsibility for coordination of the information security program. Personally identifiable information related to student financial aid and account information is stored securely in the CampusVue student information system. Access to CampusVue is restricted to those employees whose job functions require access to personally identifiable information. These employees have a strong understanding of risk relevant to this information and take necessary precautions to ensure that personally identifiable information is not compromised. The University acknowledges the specific documentation requirements outlined in the finding and presents the following action plan to address the requirements of 16 CFR 314. Action Plan: The CIO will design and execute a plan to adopt a comprehensive risk assessment process relative to information security that includes the three requirements 16 CFR 314.4 (b). The plan will include the following goals: - The risk assessment program will be in place by June 30, 2020. - Action plans resulting from the risk assessment will be developed to identify preventive or detective controls which address the risks. - The risk assessment will be formally documented and performed on a recurring basis to address changes in the information security environment. - Employees, particularly those with access to personally identifiable information, will receive training on information security. - Documentation of the training will be maintained by the Information Technology Department. - The plan will include a timetable for recurring training for employees. The University will consider the costs and benefits of utilizing external resources or firms to accomplish this action plan.

About Special Tests and Provisions →

FY 2018-06-30

LOW-RISK AUDITEE$34,119,647 federal awards expendedNo findings recorded this year

FAC accepted this audit on November 14, 2018 — management decision was due May 14, 2019.

FY 2017-06-30

LOW-RISK AUDITEE$29,416,012 federal awards expendedNo findings recorded this year

FAC accepted this audit on November 9, 2017 — management decision was due May 9, 2018.

FY 2016-06-30

LOW-RISK AUDITEE$28,021,584 federal awards expendedNo findings recorded this year

FAC accepted this audit on November 14, 2016 — management decision was due May 14, 2017.

Browse other Single Audit organizations in Pennsylvania

Start tracking findings →

Do you fund this organization?

Add it to a monitored group and get alerted when a new audit, finding, repeat finding, or management-decision deadline shows up — instead of checking back.

Checking several at once? Portfolio view →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.