EIN: 381381271
UEI: YBR2AJ9X4BK9
Audited by: PLANTE & MORAN, PLLC
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of August 31, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 5, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 5, 2026 (3 days from today).
What is a management decision? →FAC accepted this audit on March 24, 2025 — management decision was due September 24, 2025.
FAC accepted this audit on March 27, 2024 — management decision was due September 27, 2024.
FAC accepted this audit on March 26, 2023 — management decision was due September 26, 2023.
FAC accepted this audit on May 9, 2022 — management decision was due November 9, 2022.
FAC accepted this audit on June 3, 2021 — management decision was due December 3, 2021.
FAC accepted this audit on January 19, 2020 — management decision was due July 19, 2020.
CFDA Number, Federal Agency, and Program Name Student Financial Assistance Cluster Department of Education Federal Direct Loan Program (CFDA #84.268), Federal Pell Grant Program (CFDA #84.063), Federal Work Study Program (CFDA #84.033), Federal Supplemental Educational Opportunity Grant (CFDA #84.007), Federal Perkins Loan Program (CFDA #84.038), Federal TEACH Grant (CFDA #84.379) Federal Award Identification Number and Year 2019 001 Pass through Entity None Finding Type Significant deficiency Repeat Finding No Criteria In accordance with the Gramm Leach Bliley Act (16 CFR 313.3(k)(2)(vi)), an institution must explain their information sharing practices to their customers and safeguard sensitive data by designating an individual to coordinate the information security program, perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and document safeguards for identified risks. Condition The College did not designate an individual to coordinate the information security program, perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), or document safeguards for identified risks. Questioned Costs None Context The requirements of the Gramm Leach Bliley Act (16 CFR 313.3(k)(2)(vi)) do not include testing of a sample and apply to the total population of students receiving federal financial aid. Cause and Effect There were no instances of compromised sensitive data under the Gramm Leach Bliley Act (16 CFR 313.3(k)(2)(vi)). Recommendation The College should designate an individual to be responsible for coordinating the information security program to protect sensitive data. The College should also perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b) and also document safeguards for identified risks. Views of Responsible Officials and Corrective Action Plan The College concurs with the finding and is in the process of developing a team to be responsible for complying with the provisions of the Gramm Leach Bliley Act (16 CFR 313.3(k)(2)(vi)), including identifying an individual to be responsible for coordinating the information security program to protect sensitive data, performing a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and documenting safeguards for identified risks.
Show full finding ▾Hide full finding ▴CFDA Number, Federal Agency, and Program Name Student Financial Assistance Cluster Department of Education Federal Direct Loan Program (CFDA #84.268), Federal Pell Grant Program (CFDA #84.063), Federal Work Study Program (CFDA #84.033), Federal Supplemental Educational Opportunity Grant (CFDA #84.007), Federal Perkins Loan Program (CFDA #84.038), Federal TEACH Grant (CFDA #84.379) Federal Award Identification Number and Year 2019 001 Pass through Entity None Finding Type Significant deficiency Repeat Finding No Criteria In accordance with the Gramm Leach Bliley Act (16 CFR 313.3(k)(2)(vi)), an institution must explain their information sharing practices to their customers and safeguard sensitive data by designating an individual to coordinate the information security program, perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and document safeguards for identified risks. Condition The College did not designate an individual to coordinate the information security program, perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), or document safeguards for identified risks. Questioned Costs None Context The requirements of the Gramm Leach Bliley Act (16 CFR 313.3(k)(2)(vi)) do not include testing of a sample and apply to the total population of students receiving federal financial aid. Cause and Effect There were no instances of compromised sensitive data under the Gramm Leach Bliley Act (16 CFR 313.3(k)(2)(vi)). Recommendation The College should designate an individual to be responsible for coordinating the information security program to protect sensitive data. The College should also perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b) and also document safeguards for identified risks. Views of Responsible Officials and Corrective Action Plan The College concurs with the finding and is in the process of developing a team to be responsible for complying with the provisions of the Gramm Leach Bliley Act (16 CFR 313.3(k)(2)(vi)), including identifying an individual to be responsible for coordinating the information security program to protect sensitive data, performing a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b), and documenting safeguards for identified risks.
Finding Number: 2019-001 Condition: The College did not designate an individual to coordinate the information security program, perform a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b) or document safeguards for identified risks. Planned Corrective Action: The College concurs with the finding and is in the process of developing a team to be responsible for complying with the provisions of the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi), including identifying an individual to be responsible for coordinating the information security program to protect sensitive data, performing a risk assessment that addresses the three areas noted in 16 CFR 314.4 (b) and documenting safeguards for identified risks. Contact person responsible for corrective action: Doug VanDyken Anticipated Completion Date: December 2019
FAC accepted this audit on November 12, 2018 — management decision was due May 12, 2019.
FAC accepted this audit on October 30, 2017 — management decision was due April 30, 2018.
FAC accepted this audit on February 1, 2017 — management decision was due August 1, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in Michigan →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.