EIN: 340737794
UEI: DW9MU2VQBAJ5
Audited by: Forvis Mazars, LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of September 2, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on December 31, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by July 1, 2026 (67 days ago).
What is a management decision? →FAC accepted this audit on December 16, 2024 — management decision was due June 16, 2025.
FAC accepted this audit on December 13, 2023 — management decision was due June 13, 2024.
FAC accepted this audit on October 30, 2022 — management decision was due April 30, 2023.
FAC accepted this audit on October 18, 2021 — management decision was due April 18, 2022.
FAC accepted this audit on April 8, 2021 — management decision was due October 8, 2021.
FAC accepted this audit on January 5, 2020 — management decision was due July 5, 2020.
Malone University did not have a risk assessment performed in compliance with the Gramm-Leach-Bliley Act. (Significant Deficiency and Other Noncompliance) Questioned Costs: None noted Effect: Potential risks as it pertains to Student Information Security are not identified and/or addressed. Cause: Turnover in University management personnel diverted focus from obtaining an outside firm to perform a risk assessment. Repeat Finding: No Recommendation: We recommend Malone University have a risk assessment in compliance with Gramm-Leach-Bliley Act performed. Views of Responsible Officials and Planned Corrective Action: The University will have a risk assessment performed prior to June 30, 2020.
Show full finding ▾Hide full finding ▴Federal Program: Student Financial Assistance Cluster Federal Agency: U.S. Department of Education CFDA Title and Number: Federal Direct Loan Program 84.268, Federal Pell Grant Program 84.063, Federal Supplemental Educational Opportunities Grant 84.007, Federal Work Study 84.033, Federal Perkins Loan Program 84.038, Federal TEACH Grant Program 84.379 Award Year: July 1, 2018 - June 30, 2019 Criteria or Specific Requirement: Special Tests and Provisions - Gramm-Leach-Bliley Act - Student Information Security - The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information sharing-practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as ?financial institutions? and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(iv)). Under an institution?s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, institutions must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal financial aid programs. Institutions are required to designate an individual to coordinate the information security program and perform a risk assessment that addresses (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions or other systems failures. Condition: Malone University did not have a risk assessment performed in compliance with the Gramm-Leach-Bliley Act. (Significant Deficiency and Other Noncompliance) Questioned Costs: None noted Effect: Potential risks as it pertains to Student Information Security are not identified and/or addressed. Cause: Turnover in University management personnel diverted focus from obtaining an outside firm to perform a risk assessment. Repeat Finding: No Recommendation: We recommend Malone University have a risk assessment in compliance with Gramm-Leach-Bliley Act performed. Views of Responsible Officials and Planned Corrective Action: The University will have a risk assessment performed prior to June 30, 2020.
Reference: 2019-002 Corrective Action: Special Tests ? Gramm-Leach-Bliley Act ? The following steps have been taken and will be taken to address Finding 2019-002: Views of Responsible Officials and Planned Corrective Action: The University will have a risk assessment performed prior to June 30, 2020. Anticipated Completion Date: June 30, 2020 Responsible party: Adam Klemann, Chief Information Officer 330.471.8138
FAC accepted this audit on June 2, 2019 — management decision was due December 2, 2019.
FAC accepted this audit on March 11, 2018 — management decision was due September 11, 2018.
FAC accepted this audit on January 19, 2017 — management decision was due July 19, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in Ohio →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Add it to a monitored group and get alerted when a new audit, finding, repeat finding, or management-decision deadline shows up — instead of checking back.
Checking several at once? Portfolio view →
© 2026 Single Audit Intelligence. All data is public domain.