EIN: 250964126
UEI: JTQRBGTSWUM7
Audited by: Baker Tilly US, LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of August 28, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 31, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by October 1, 2026 (32 days from today).
What is a management decision? →The Corporation did not disburse all funds that were drawn down within three business days of the initial draw down. The Corporation disbursed the funds over 30 days and did not return the excess funds for 1 drawdown in our sample of 5 drawdowns. The sample was not a statistically valid sample. Questioned Costs: There are $99,711 in known questioned costs associated with this finding. Cause: The Corporation drew down funds in December 2024 in anticipation of the Corporation being unable to draw funds in January 2025 due to the government shutdown. Effect: The Corporation was in possession of the funds for longer than three business days and therefore was in possession of excess cash longer than the allowable period. Recommendations: The Corporation should increase emphasis on timely disbursement of funds that are drawn down. Views of Responsible Officials: Management acknowledges and concurs with the finding. Management believes that the occurrence was a one-time event due to the anticipated government shutdown. They have no plans to draw down funds without planned disbursements within three business days in the future.
Show full finding ▾Hide full finding ▴Finding 2025-003: Cash Management Federal Program - Student Financial Aid Cluster, Federal Direct Student Loans Federal Agency - U.S. Department of Education Assistance Listing Number - 84.268 Federal Award Year - June 30, 2025 Criteria: For institutions on the Advance Payment Method, any amount of Title IV funds not disbursed to recipients by the end of the third business day is considered excess cash. ED allows an institution to retain, for up to seven days, excess cash that does not exceed one percent of the total amount of funds drawn by the institution in the prior award year. The institution must return to ED any excess cash over the tolerable amount (one percent) and any amount remaining after the tolerable period (seven days). Condition: The Corporation did not disburse all funds that were drawn down within three business days of the initial draw down. The Corporation disbursed the funds over 30 days and did not return the excess funds for 1 drawdown in our sample of 5 drawdowns. The sample was not a statistically valid sample. Questioned Costs: There are $99,711 in known questioned costs associated with this finding. Cause: The Corporation drew down funds in December 2024 in anticipation of the Corporation being unable to draw funds in January 2025 due to the government shutdown. Effect: The Corporation was in possession of the funds for longer than three business days and therefore was in possession of excess cash longer than the allowable period. Recommendations: The Corporation should increase emphasis on timely disbursement of funds that are drawn down. Views of Responsible Officials: Management acknowledges and concurs with the finding. Management believes that the occurrence was a one-time event due to the anticipated government shutdown. They have no plans to draw down funds without planned disbursements within three business days in the future.
Finding 2025-003- Cash Management: Untimely Disbursement of Direct Loan Funds Condition: Direct Loan funds drawn down in December 2024 were not disbursed within the required 3-day timeframe. Corrective Action Plan: The College will improve compliance with federal cash management requirements using Colleague by: • Establishing written procedures requiring same-day or next-day disbursement processing after funds are received. • Performing a monthly reconciliation between drawdowns and student account postings. • Providing training on cash management requirements established by the U.S. Department of Education. Responsible Party: Director of Student Accounts Anticipated Completion Date: June 30, 2026
The Corporation did not notify the National Student Loan Data System (NSLDS) in a timely manner for one student with a status change in our sample of 25 students. The sample was not a statistically valid sample. Questioned Costs: There are no questioned costs associated with this finding. Cause: The Corporation’s procedures for reporting all students were not designed appropriately in order to allow for timely reporting to the NSLDS. Effect: The accuracy of Title IV student loan records depends heavily on the accuracy of the enrollment information reported by the schools. If an institution does not review, update and verify student enrollment statuses, effective dates of the enrollment status and the anticipated completion dates, then the Title IV student loan records will be inaccurate. Recommendations: The Corporation should review its procedures for student status changes and NSLDS notifications to ensure there are follow-up and review procedures being performed for all students with status changes at the Corporation. Views of Responsible Officials: Management acknowledges and concurs with this finding. The Corporation will periodically perform independent reviews of the information provided to the NSLDS to ensure the status change information has been updated in the NSLDS during the required time period.
Show full finding ▾Hide full finding ▴Finding 2025-004: Enrollment Reporting Federal Program - Student Financial Aid Cluster, Federal Direct Student Loans Federal Agency - U.S. Department of Education Assistance Listing Number - 84.268 Federal Award Year - June 30, 2025 Criteria: Title IV regulations (34 CFR Section 685.309(b)) require that upon receipt of an enrollment report from the Secretary, institutions must update all information included in the report and return the report to the Secretary: (i) in the manner and format prescribed by the Secretary; and (ii) within the timeframe prescribed by the Secretary. Unless it expects to submit its next updated enrollment report to the Secretary within the next 60 days, an institution must notify the Secretary within 30 days after the date the institution discovers that: (i) a loan under Title IV of the Act was made to or on behalf of a student who was enrolled or accepted for enrollment at the institution, and the student has ceased to be enrolled on at least a half-time basis or failed to enroll on at least a half-time basis for the period for which the loan was intended; or (ii) a student who is enrolled at the institution and who received a loan under Title IV of the Act has changed his or her permanent address. Condition: The Corporation did not notify the National Student Loan Data System (NSLDS) in a timely manner for one student with a status change in our sample of 25 students. The sample was not a statistically valid sample. Questioned Costs: There are no questioned costs associated with this finding. Cause: The Corporation’s procedures for reporting all students were not designed appropriately in order to allow for timely reporting to the NSLDS. Effect: The accuracy of Title IV student loan records depends heavily on the accuracy of the enrollment information reported by the schools. If an institution does not review, update and verify student enrollment statuses, effective dates of the enrollment status and the anticipated completion dates, then the Title IV student loan records will be inaccurate. Recommendations: The Corporation should review its procedures for student status changes and NSLDS notifications to ensure there are follow-up and review procedures being performed for all students with status changes at the Corporation. Views of Responsible Officials: Management acknowledges and concurs with this finding. The Corporation will periodically perform independent reviews of the information provided to the NSLDS to ensure the status change information has been updated in the NSLDS during the required time period.
Finding 2025-004 - Enrollment Reporting: Untimely Status Update Condition: One student who graduated in December 2024 was not reported within the required 60-day timeframe. Corrective Action Plan: The College will strengthen enrollment reporting controls within Colleague by: • Performing a monthly reconciliation between Registrar records and enrollment reporting files submitted to NSLDS. • Utilizing Colleague reporting tools to identify recent graduates and status changes requiring updates. • Establishing a compliance calendar with system reminders for required reporting deadlines. • Training staff on reporting requirements aligned with the National Student Loan Data System. Responsible Party: Mandy Schnorr, Director of Financial Aid, Cara Moyer, Registrar Anticipated Completion Date: June 30, 2026
FAC accepted this audit on March 24, 2025 — management decision was due September 24, 2025.
FAC accepted this audit on March 27, 2024 — management decision was due September 27, 2024.
The Corporation did not notify the National Student Loan Data System (NSLDS) in a timely manner for 4 students with status changes in our sample of 25 students. The sample was not a statistically valid sample. Questioned Costs: There are no questioned costs associated with this finding. Cause: The Corporation's procedures for reporting all students were not designed appropriately in order to allow for timely reporting to the NSLDS. Effect or Potential Effect: The accuracy of Title IV student loan records depends heavily on the accuracy of the enrollment information reported by schools. If an institution does not review, update and verify student enrollment statuses, effective dates of the enrollment status and the anticipated completion dates, then the Title IV student loan records will be inaccurate. Recommendations: We recommend that the Corporation review its procedures for student status changes and NSLDS notifications to ensure there are follow-up and review procedures being performed for all students with status changes at the Corporation. Management Response: Management concurs with the finding and the Corporation will periodically perform independent reviews of the information provided to the NSLDS to ensure the status change information has been updated in the NSLDS during the required time period.
Show full finding ▾Hide full finding ▴Criteria: Title IV regulations (34 CFR Section 685.309(b)) require that upon receipt of an enrollment report from the Secretary, institutions must update all information included in the report and return the report to the Secretary: (i) in the manner and format prescribed by the Secretary; and (ii) within the timeframe prescribed by the Secretary. Unless it expects to submit its next updated enrollment report to the Secretary within the next 60 days, an institution must notify the Secretary within 30 days after the date the institution discovers that: (i) a loan under Title IV of the Act was made to or on behalf of a student who was enrolled or accepted for enrollment at the institution, and the student has ceased to be enrolled on at least a half-time basis or failed to enroll on at least a half-time basis for the period for which the loan was intended; or (ii) a student who is enrolled at the institution and who received a loan under Title IV of the Act has changed his or her permanent address. Condition: The Corporation did not notify the National Student Loan Data System (NSLDS) in a timely manner for 4 students with status changes in our sample of 25 students. The sample was not a statistically valid sample. Questioned Costs: There are no questioned costs associated with this finding. Cause: The Corporation's procedures for reporting all students were not designed appropriately in order to allow for timely reporting to the NSLDS. Effect or Potential Effect: The accuracy of Title IV student loan records depends heavily on the accuracy of the enrollment information reported by schools. If an institution does not review, update and verify student enrollment statuses, effective dates of the enrollment status and the anticipated completion dates, then the Title IV student loan records will be inaccurate. Recommendations: We recommend that the Corporation review its procedures for student status changes and NSLDS notifications to ensure there are follow-up and review procedures being performed for all students with status changes at the Corporation. Management Response: Management concurs with the finding and the Corporation will periodically perform independent reviews of the information provided to the NSLDS to ensure the status change information has been updated in the NSLDS during the required time period.
Response to Finding 2023-001: Status Changes Management Response Saint Vincent College concurs with the finding of delays in reporting changes of student enrollment status to the National Student Loan Data System (NSLDS) and attributes the delays to 1.) the first cohort of a joint program with another institution reaching completion 2.) a data breach reported by National Student Clearinghouse (NSC) in June 2023. All students identified as being reported outside of the required time period are enrolled in the joint Bachelor of Science degree in Nursing between Saint Vincent College and Carlow University that began in Fall 2019. Under the agreement for this program, the Registrar’s office of Saint Vincent College reports enrollment to the NSLDS via the NSC. Students graduate with a Carlow University degree. Saint Vincent College is to report program completers as withdrawn at the end of the final enrollment period and Carlow University is to report the students as graduated. The first cohort through this arrangement completed the program requirements in May of 2023. The students in this cohort were not included with the other student enrollment status changes reported in May 2023 following the end of the semester/graduation. While Saint Vincent did ultimately report the cohort as withdrawn, it occurred outside of the required time frame. Saint Vincent’s primary method of reporting status changes to the NSLDS is through the NSC. The NSC reported a data breach on June 26, 2023, at which point the College’s IT department instructed the Registrar to immediately stop sending data to the NSC. The resulted in the aforementioned cohort of students not being reported to the NSC or NSLDS until September 2023 when the College’s IT department provided approval for the Registrar to resume sending data to the NSC. Corrective Action Beginning March 1, 2024, Saint Vincent College’s Financial Aid Office in conjunction with Registrar’s office has implemented a 45-day report to verify that all withdrawals and completions have reached NSLDS via the National Student Clearinghouse. The discovery of any that did not reach NSLDS will be manually reported directly on the NSLDS platform to avoid being outside of the 60-day requirement. Further, during any period of known issues/outages of NSC, the College will report status changes directly to NSLDS. Conclusion The College deems that the corrective action steps outlined above will sufficiently resolve the findings and prevent any future instances of untimely reporting of enrollment data to the NSLDS. Responsible Party, Joshua A. Guiser, CPA. Vice President for Finance and Treasurer Chief Financial Officer
FAC accepted this audit on March 27, 2023 — management decision was due September 27, 2023.
FAC accepted this audit on September 18, 2022 — management decision was due March 18, 2023.
FAC accepted this audit on July 20, 2021 — management decision was due January 20, 2022.
The Corporation has not performed a risk assessment to address (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures as required by the GLBA. Questioned Costs: There are no questioned costs associated with this finding. Cause: The Corporation does not have formal procedures and processes in place specific to GLBA. Effect: Failure to comply with the requirements of GLBA standards puts the Corporation at risk of compromising consumer nonpublic personal information. Recommendation: The Corporation should perform and document an annual risk assessment to determine the Corporation's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the Corporation should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4(b). Finally, the Corporation should identify and document at least one safeguard (i.e. control) for each of the risks identified and documented in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Management Response: Management agrees with the finding. Risk assessments will be performed and documented on an annual basis to determine the Corporation's specific risks relevant to protecting consumer nonpublic personal information. The Corporation will produce the appropriate number of risk statements and identify the appropriate number of safeguards that properly align with the risks documented. Also see corrective action plan.
Show full finding ▾Hide full finding ▴Finding 2020-001: Gramm-Leach Bliley Act (GLBA) Federal Program: Student Financial Assistance Cluster Federal Agency: U.S. Department of Education Pass-Through Entity: Not applicable CFDA: 84.007, 84.033, 84.038, 84.063, 84.268 Federal Award Number: P007A193698, P033A193698, P063P192153, P268K202153 Federal Award year: June 30, 2020 Criteria: In accordance with Title IV regulations (16 CFR 314.1(b)), an institution must protect student financial aid information by designating an individual to coordinate the information security program, perform a risk assessment that addresses (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures, and document safeguards for identified risks. Condition: The Corporation has not performed a risk assessment to address (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures as required by the GLBA. Questioned Costs: There are no questioned costs associated with this finding. Cause: The Corporation does not have formal procedures and processes in place specific to GLBA. Effect: Failure to comply with the requirements of GLBA standards puts the Corporation at risk of compromising consumer nonpublic personal information. Recommendation: The Corporation should perform and document an annual risk assessment to determine the Corporation's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the Corporation should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4(b). Finally, the Corporation should identify and document at least one safeguard (i.e. control) for each of the risks identified and documented in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Management Response: Management agrees with the finding. Risk assessments will be performed and documented on an annual basis to determine the Corporation's specific risks relevant to protecting consumer nonpublic personal information. The Corporation will produce the appropriate number of risk statements and identify the appropriate number of safeguards that properly align with the risks documented. Also see corrective action plan.
RE: Finding 2020-001 - Gramm-Leach Bliley Act (GLBA) Condition: The Corporation has not performed a risk assessment to address (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusion, or other systems failures as required by the GLBA. Management Response: Saint Vincent College concurs a formalized risk assessment specific to address (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures as required by the GLBA was not performed for the 2019-2020 fiscal year. The College leadership has allocated budgetary funds for the 2020-2021 Fiscal Year for a formal risk assessment and are in the process of remediating the finding through the creation of a formalized technology risk assessment process. Please find details including Root Cause Evaluation, Action Steps, and Benchmarks below. Root Cause Evaluation: Informal risk assessment practices previously followed were determined not to meet the federal requirements for GLBA. As the College worked towards a formalized risk assessment process in between December 2019- February 2020, the global COVID Pandemic began to escalate in February resulting in a Pennsylvania State stay-at-home declaration beginning in March 2020. During this period, we informally determined risks for remote work while implementing safeguards for mitigation such as enabling Two-Factor Authentication (2FA) across our staff accounts, deployed 2FA requirements in front of our VPN and Virtual Desktop Environment, and integrated internal web application with Microsoft proxy for greater authentication and auditing capabilities. The order of events and the effects of the pandemic for the College's IT Department ability to focus on GLBA compliance are summarized as follows: ? The information Technology Department became aware of new GLBA risk assessment requirements on October 30,2019. ? Upon further research through November of 2019, the IT Department began securing risk assessment quotes and deliverables from engaged IT risk assessment partners in December 2019 through January 2020. ? In February/March 2020, the escalating pandemic forced IT staff resources into crisis-mode to ensure the continuity of critical business and academic processes during the spring 2020 academic semester. The College pivoted from an in-person academic model to 100% online model. All technology staff resources were actively involved in supporting this pivot. ? The PA State stay-at-home declarations (March 2020) and an uncertain economic situation resulted in in an inability to secure or perform a formal risk assessment during 2019-2020 Fiscal Year. ? Lastly, a change in the CIO leadership role occurred between the months of September through mid- October of 2020 resulting in a hold on strategic technology initiatives until November/December 2020. Action Steps: The College will: 1. Immediately perform a formal technology risk assessment for federal aid systems covered by CFDA: 84.007, 84.033, 84.038, 84.063, 84.268. to be completed by June 2021. 2. Share the technology risk assessment findings to Senior Cabinet. 3. Document a minimum of one risk including an implementation of a formal policy and a mitigating safeguard (control) for employee training and management. 4. Document a minimum of one risk including an implementation of a policy and mitigating safeguard ( control) for information systems, including network and software design, as well as information processing, storage, transmission and disposal. 5. Document a minimum of one risk including an implementation of a formal policy and a mitigating safeguard (control) for detecting, preventing and responding to attacks, intrusions, or other systems failures. 6. Create a formal, iterative risk assessment process to be performed and updated on an annual fiscal term addressing the required areas for GLBA compliance. "See Corrective Action Plan for chart/table"
FAC accepted this audit on March 25, 2020 — management decision was due September 25, 2020.
FAC accepted this audit on March 18, 2019 — management decision was due September 18, 2019.
FAC accepted this audit on March 21, 2018 — management decision was due September 21, 2018.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
FAC accepted this audit on March 19, 2017 — management decision was due September 19, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.