EIN: 314379515
UEI: RRUANWMAHDZ3
Audited by: Schneider Downs
Oversight agency: 10 [Department of Agriculture]
View federal awards & risk assessment →
Data as of August 28, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 27, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 27, 2026 (27 days from today).
What is a management decision? →FAC accepted this audit on March 27, 2025 — management decision was due September 27, 2025.
FAC accepted this audit on March 27, 2024 — management decision was due September 27, 2024.
The Gramm-Leach-Bliley Act (Public Law 106-102) (“GLBA”) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (“16 CFR 314”). Under 16 CFR 314 f(d), the University should regularly test or otherwise monitor the effectiveness of the safeguards it has implemented. Under 16 CFR 314.4 (e)(1), the University should implement policies and procedures to ensure that personnel are able to enact the information security program. The University does not have a formalized information security program to document the policies and procedures relevant with respect to requirements under 16 CFR 314.4(e)(1). The University does not regularly conduct vulnerability assessments, penetration testing, or other procedures to monitor its implemented safeguards as required under 16 CFR 314 f(d). Without a formalized policy in place surrounding its information security program, the University is not able to fully determine its compliance under the GLBA requirements, including the requirement to regularly test or otherwise monitor the effectiveness of its safeguards. Lack of regular testing or monitoring the effectiveness of the safeguards established could lead to the lack of timely identification of ineffectiveness or missing safeguards that could help detect or prevent breaches or other similar issues.
Show full finding ▾Hide full finding ▴The Gramm-Leach-Bliley Act (Public Law 106-102) (“GLBA”) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (“16 CFR 314”). Under 16 CFR 314 f(d), the University should regularly test or otherwise monitor the effectiveness of the safeguards it has implemented. Under 16 CFR 314.4 (e)(1), the University should implement policies and procedures to ensure that personnel are able to enact the information security program. The University does not have a formalized information security program to document the policies and procedures relevant with respect to requirements under 16 CFR 314.4(e)(1). The University does not regularly conduct vulnerability assessments, penetration testing, or other procedures to monitor its implemented safeguards as required under 16 CFR 314 f(d). Without a formalized policy in place surrounding its information security program, the University is not able to fully determine its compliance under the GLBA requirements, including the requirement to regularly test or otherwise monitor the effectiveness of its safeguards. Lack of regular testing or monitoring the effectiveness of the safeguards established could lead to the lack of timely identification of ineffectiveness or missing safeguards that could help detect or prevent breaches or other similar issues.
The University is employing internal and external resources to finalize and implement a security program that includes development of formal policies and procedures and consideration of regular tests or assessments of the policies and associated safeguards. The policies will be developed and implemented beginning in fiscal year 2024 and will be finalized prior to the completion of next year's audit period.
FAC accepted this audit on January 12, 2023 — management decision was due July 12, 2023.
FAC accepted this audit on March 13, 2022 — management decision was due September 13, 2022.
FAC accepted this audit on June 28, 2021 — management decision was due December 28, 2021.
FAC accepted this audit on November 6, 2019 — management decision was due May 6, 2020.
The University disbursed financial aid to individuals whose Institutional Student Information Record (ISIR) contained a flag that should have been resolved prior to the award being made. Cause: The University changed the manner in which ISIR data was reviewed for flags or others indicators that would impact the awarding of financial aid, and the University?s manual and automated controls did not prevent the awarding prior to ISIR flags being resolved. Effect or Potential Effect: Since ISIR flags were not identified and resolved prior to awarding, it resulted in improper financial aid being applied to student accounts. Questioned Costs: $13,675 Context: In a sample of 60 students who were tested, four were identified whose ISIR contained flags that were not resolved prior to awarding. Two of those individuals should not have been awarded aid for the 2018-2019 federal award year. Two other individuals were awarded excess funding for the 2018-2019 federal award year. A further analysis by management of the University of the remaining population of ISIRs that contained a flag, yielded no additional exceptions. Identification as a Repeat Finding: This is not a repeat finding. Recommendation: We recommend the University review all ISIRs prior to awarding financial aid to ensure that all records with flags are resolved prior to the awards being applied to the student account and the manual and automated controls be enhanced to detect and prevent future errors. View of Responsible Officials: Management concurs with this finding. See separate corrective action plan document.
Show full finding ▾Hide full finding ▴Finding 2019-001 Student Financial Assistance - Cluster, Department of Education Programs Program Names: 84.007 - Federal Supplemental Educational Opportunity Grants, 84.063 - Federal Pell Grant Program, 84.268 - Federal Direct Student Loans Criteria or Specific Requirement: Prior to disbursing of financial aid, institutions are expected to consider the requirements under 34 CFR 668.32 - Student eligibility - general, to ensure individuals are eligible. Condition: The University disbursed financial aid to individuals whose Institutional Student Information Record (ISIR) contained a flag that should have been resolved prior to the award being made. Cause: The University changed the manner in which ISIR data was reviewed for flags or others indicators that would impact the awarding of financial aid, and the University?s manual and automated controls did not prevent the awarding prior to ISIR flags being resolved. Effect or Potential Effect: Since ISIR flags were not identified and resolved prior to awarding, it resulted in improper financial aid being applied to student accounts. Questioned Costs: $13,675 Context: In a sample of 60 students who were tested, four were identified whose ISIR contained flags that were not resolved prior to awarding. Two of those individuals should not have been awarded aid for the 2018-2019 federal award year. Two other individuals were awarded excess funding for the 2018-2019 federal award year. A further analysis by management of the University of the remaining population of ISIRs that contained a flag, yielded no additional exceptions. Identification as a Repeat Finding: This is not a repeat finding. Recommendation: We recommend the University review all ISIRs prior to awarding financial aid to ensure that all records with flags are resolved prior to the awards being applied to the student account and the manual and automated controls be enhanced to detect and prevent future errors. View of Responsible Officials: Management concurs with this finding. See separate corrective action plan document.
Identifying Number: 2019-001 Issue: During the audit of the 2018-19 Financial Aid Award Year it was found that the Student Financial Services staff failed to resolve ISIR flags for four students prior to awarding financial aid. A review of the remaining population of ISIRs found no additional errors. Two of the students were in default and should not have received the Federal Supplemental Educational Opportunity Grant, Federal Pell Grant or Federal Direct Loans. The other two students received Federal Direct Subsidized Loans in excess of aggregate limits. Cause: The reason for the errors was a change in the way that ISIR data is reviewed. In previous years the ISIR was printed and the paper ISIR records was reviewed for flags prior to awarding. For 2018-19 the Student Financial Services staff moved to a paperless review of ISIRs. The counselors were adjusting to the new way of viewing ISIR data electronically and did not detect the relevant ISIR flags as part of the awarding procedures. Correctives Action Taken or Planned: Federal Financial Aid for the 4 students has been cancelled and returned through COD. The University has increased its manual and automated controls to prevent future occurrences. Counselors have been retrained regarding the need to check for ISIR flags as part of the awarding process. Counselors are now required to check to see if there is a "Y" in the SAR C box on NASU. The counselors review the comments associated with the flag and act to resolve the flag prior to any awarding for the students with those flags. The University has contracted with its software vendor Ellucian for consulting to implement Auto Packaging. The use of Auto Packaging will prevent students with flags from being offered a financial aid award package prior to their flags being cleared. Consulting is taking place in November of 2019 so that the improvements can be implemented for the 2020-21 Federal Award Year. In the meantime, the University has created a flag report that pulls all ISIRS with a flag and the associated comment code. A counselor other than the awarding counselor reviews the flags to confirm that they are resolved prior to awarding.
The University did not have written documentation to demonstrate its compliance with the requirements of 16 CFR 314. Cause: The University has not updated its student financial aid security program since its adoption in 2007. Effect or potential effect: If the University does not have a current risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and documented safeguards for identified risks, there may be inadequate safeguards of student financial aid information. Questioned Costs: None noted. Context: We were unable to verify whether the University had recently performed a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and documented safeguards for identified risks, based upon the University?s current operations and environment. Identification as a Repeat Finding: This is not a repeat finding. Recommendation: We recommend that the University perform an update to its risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and document safeguards for identified risks. Views of Responsible Officials: Management concurs with this finding. See separate corrective action plan document.
Show full finding ▾Hide full finding ▴Finding 2019-002 Student Financial Assistance - Cluster, Department of Education Programs Program Names: 84.007 - Federal Supplemental Educational Opportunity Grants, 84.033 - Federal Work-Study Program, 84.038 - Federal Perkins Loan, 84.063 - Federal Pell Grant Program, 84.268 - Federal Direct Student Loans, 84.379 - Teacher Education Assistance for College and Higher Education Grants (TEACH Grants) Criteria or Specific Requirement: Under an institution?s Program Participation Agreement with the Department of Education (Department) and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. (16 CFR 314.3; HEA 483(a)(3)(E) and HEA 485B(d)(2)) Condition: The University did not have written documentation to demonstrate its compliance with the requirements of 16 CFR 314. Cause: The University has not updated its student financial aid security program since its adoption in 2007. Effect or potential effect: If the University does not have a current risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and documented safeguards for identified risks, there may be inadequate safeguards of student financial aid information. Questioned Costs: None noted. Context: We were unable to verify whether the University had recently performed a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and documented safeguards for identified risks, based upon the University?s current operations and environment. Identification as a Repeat Finding: This is not a repeat finding. Recommendation: We recommend that the University perform an update to its risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and document safeguards for identified risks. Views of Responsible Officials: Management concurs with this finding. See separate corrective action plan document.
Identifying Number: 2019-002 Issue and Cause: Under an institution's Program Participation Agreement with the Department of Education (Department) and the Gramm-Leach-Bliley Act (GLBA), they are required to protect the information of those who are receiving student financial aid, with paiticular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of federal student financial aid programs. The University has not updated its student financial aid security program since its adoption in 2007 and has not documented its risk assessment to address the areas in GLBA and safeguards for identified risks. Corrective Actions Taken or Planned: Management concurs with the condition, cause and the recommendation as stated in the accompanying schedule of findings and questioned costs. The University, subsequent to June 30, 2019, is implementing the following processes to prevent this finding from occurring in the future, which will be completed by December 31, 2019. The University will update its risk assessment associated with GLBA and document the safeguards for identified risks. This plan will be monitored by the University's Director of Institutional Research and updated annually.
FAC accepted this audit on November 1, 2018 — management decision was due May 1, 2019.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴FAC accepted this audit on November 26, 2017 — management decision was due May 26, 2018.
FAC accepted this audit on February 11, 2017 — management decision was due August 11, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in Ohio →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.