EIN: 383336473
UEI: XGLQDT9J9C15
Data as of August 22, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 2, 2022. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 2, 2022 (1450 days ago).
What is a management decision? →During our compliance testing, we determined that the College does not have a written procurement policy in place. While the College does have general controls in place to cover these areas, there are no formal written policies covering payments, procurement, allowability of costs, compensation, and travel costs in accordance with the Uniform Guidance. Cause: The College was not aware of the requirements to have a written procurement policy. Effect: As a result of this condition, the College was exposed to increased risk that grant requirements under 2 CFR 200 would not be followed. Questioned Costs: None Context/Sampling: No sampling was used; this requirement was tested in its entirety.
Show full finding ▾Hide full finding ▴2021-001 ? Education Stabilization Fund - Procurement Federal Agency: Department of Education Program: 84.425 Higher Education Emergency Relief Fund Criteria: 2 CFR 200.318 ? The non-Federal entity must have and use documented procurement procedures, consistent with State, local, and tribal laws and regulations and the standards of this section, for the acquisition of property or services required under a Federal award or sub-award. The non-Federal entity?s documented procurement procedures must conform to the procurement standards identified in 2 CFR 200.317 through 200.327. Per 2 CFR 200.320, the non-Federal entity may use informal procurement methods for the procurement of property or services at or below the simplified acquisition threshold as defined in 2 CFR 200.1, including micro-purchases or small purchases. When the value of the procurement for property or services exceeds the simplified acquisition threshold, formal procurement methods are required, including sealed bids, proposals or noncompetitive procurement. Condition: During our compliance testing, we determined that the College does not have a written procurement policy in place. While the College does have general controls in place to cover these areas, there are no formal written policies covering payments, procurement, allowability of costs, compensation, and travel costs in accordance with the Uniform Guidance. Cause: The College was not aware of the requirements to have a written procurement policy. Effect: As a result of this condition, the College was exposed to increased risk that grant requirements under 2 CFR 200 would not be followed. Questioned Costs: None Context/Sampling: No sampling was used; this requirement was tested in its entirety.
2021-001 Higher Education Emergency Relief Fund Recommendation: Compass College of Cinematic Arts should develop and implement the required written procurement policies as soon as practical. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action Taken or to Be Taken: Management will take the necessary steps to create and implement a written procurement policy to meet the requirements under Federal Guidance. Anticipated Completion Date: 06/30/2022 People responsible for Corrective Action: Fred Kooistra, Jay Greer
FAC accepted this audit on January 14, 2020 — management decision was due July 14, 2020.
The College does not have procedures in place to address all required elements under GLBA. While the College does have general IT controls in place to safeguard personally identifiable information and other sensitive or proprietary information and has performed general IT risk assessments in the past, there was no formal information security program established to address GLBA, no employee or group of employees designated to coordinate an information security program specific to GLBA, and no formal risk assessment has been completed by the College that would address all required elements under GLBA. Cause: The College was not aware of the requirements under the Gramm-Leach-Bliley Act. Effect: The College?s information security program may not be as robust and secure as it could be. Because compliance with GLBA is a provision of the College?s Program Participation Agreement with the Department of Education, failure to comply with the requirements of the GLBA may impact the College?s eligibility for Title IV funding. Questioned Costs: None Context/Sampling: No sampling was used; this requirement was tested in its entirety. Recommendation: We recommend that Compass College of Cinematic Arts designate and appropriate individual to establish and maintain an information security program and develop the program to meet all required elements under GLBA. The college should also ensure the information security program includes provisions to maintain adequate documentation of all required elements under GLBA. View of Management and Planned Corrective Actions: Management is in agreement with the above audit finding and condition. Management?s Views and Corrective Action Plan is included at the end of this report after the Summary Schedule of Prior Audit Findings.
Show full finding ▾Hide full finding ▴2019-001 ? Gramm-Leach-Bliley Act Federal Agency: Department of Education Program: Student Financial Assistance Cluster Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Education Assistance Programs as ?financial institutions? and subject to the Gram-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi). Under an institution?s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act (GLBA), schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. (16 CFR 314.3; HEA 483(a)(3)(E) and HEA 485B(d)(2). GLBA requires institutions to develop, implement, and maintain and information security program which includes the elements described in 16 CFR 314.4, listed below: 1) Designate an employee or employees to coordinate the information security program. 2) Identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At minimum, such a risk assessment should include consideration of risks in each relevant area of the entity?s operations, including: a) Employee training and management; b) Information systems, including network and software design, as well as information processing, storage, transmission, and disposal; and c) Detecting, preventing and responding to attacks, intrusions, or other systems failures. 3) Design and implement information safeguards to control the risks the entity identified through risk assessment, and regularly test or otherwise monitor the effectiveness of the safeguards? key controls, systems, and procedures. Condition: The College does not have procedures in place to address all required elements under GLBA. While the College does have general IT controls in place to safeguard personally identifiable information and other sensitive or proprietary information and has performed general IT risk assessments in the past, there was no formal information security program established to address GLBA, no employee or group of employees designated to coordinate an information security program specific to GLBA, and no formal risk assessment has been completed by the College that would address all required elements under GLBA. Cause: The College was not aware of the requirements under the Gramm-Leach-Bliley Act. Effect: The College?s information security program may not be as robust and secure as it could be. Because compliance with GLBA is a provision of the College?s Program Participation Agreement with the Department of Education, failure to comply with the requirements of the GLBA may impact the College?s eligibility for Title IV funding. Questioned Costs: None Context/Sampling: No sampling was used; this requirement was tested in its entirety. Recommendation: We recommend that Compass College of Cinematic Arts designate and appropriate individual to establish and maintain an information security program and develop the program to meet all required elements under GLBA. The college should also ensure the information security program includes provisions to maintain adequate documentation of all required elements under GLBA. View of Management and Planned Corrective Actions: Management is in agreement with the above audit finding and condition. Management?s Views and Corrective Action Plan is included at the end of this report after the Summary Schedule of Prior Audit Findings.
U.S. Department of Education 2019-001 Gramm-Leach-Bliley Act Recommendation: Compass College of Cinematic Arts should designate an appropriate individual to establish and maintain an information security program and develop the program to meet all required elements under GLBA. The college should also ensure the information security program includes provisions to maintain adequate documentation of all required elements under GLBA. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action Taken or to Be Taken: Management will take the necessary steps to create a comprehensive information security program beginning with developing, implementing and maintaining a comprehensive written plan containing administrative, technical and physical safeguards. The plan will include the following important features: designated employees to coordinate the program; reasonably foreseeable internal and external risks to security, confidentiality and integrity of customer information; design and implement information safeguards to control identified risk and regularly test; oversee service providers; and periodically re-evaluate the plan. Additionally, Compass College will create a clear incident response plan and educate employees on GLBA compliance. Anticipated Completion Date: 03/31/2020 People responsible for Corrective Action: Ken Boersma, Laura Coulier, Lynne Heerema
During our audit, we identified 5 out of the 12 months that did not have roster distributions that were responded to within the required 15 days. Cause: The College?s processes and controls did not ensure that the roster file submissions were responded to within a timely manner and within the required timeframe. Effect: As a result of this condition, the College?s roster file submissions, and therefore student status changes, were not reported timely. The effective administration of Title IV programs could be impacted when changes in students? status are not reported timely and accurately. The accuracy of enrollment information is important as student?s enrollment status determines eligibility for in-school status, deferment, grace periods, and repayments, as well as the Government?s payment of interest subsidies. Questioned Costs: None Context/Sampling: No sampling was used; this requirement was tested in its entirety. Recommendation: We recommend that Compass College of Cinematic Arts review its reporting procedures to ensure that roster file submissions are reported timely and accurately. View of Management and Planned Corrective Actions: The College is in agreement with the above audit finding and condition. Management?s Views and Corrective Action Plan is included as the end of this report after the Summary Schedule of Prior Audit Findings.
Show full finding ▾Hide full finding ▴2019-002 ? Enrollment Reporting Federal Agency: Department of Education Program: Student Financial Assistance Cluster Criteria: Under the Federal Direct Student Loan, and Federal Pell Grant programs, institutions must complete and return within 15 day the Enrollment Reporting roster file placed in their Student Aid Internet Gateway mailboxes sent by the Department of Education via National Student Loan Data System (NSLDS). The institution determines how often it receives the Enrollment Reporting roster file with the default set at every two months, but the minimum is twice a year. Once received, the institution must update for changes in student status, report the date the enrollment status was effective, enter the new anticipated completion date, and submit the changes electronically through the batch method or the NSLDS website. Unless the school expects to complete its next roster within 60 days, the school must notify the lender or guaranty agency within 15 days, if it discovers a student who received a loan either did not enroll or ceased to be enrolled on at least a half-time basis (34 CFR 685.309(b) and 674.33(g)). Condition: During our audit, we identified 5 out of the 12 months that did not have roster distributions that were responded to within the required 15 days. Cause: The College?s processes and controls did not ensure that the roster file submissions were responded to within a timely manner and within the required timeframe. Effect: As a result of this condition, the College?s roster file submissions, and therefore student status changes, were not reported timely. The effective administration of Title IV programs could be impacted when changes in students? status are not reported timely and accurately. The accuracy of enrollment information is important as student?s enrollment status determines eligibility for in-school status, deferment, grace periods, and repayments, as well as the Government?s payment of interest subsidies. Questioned Costs: None Context/Sampling: No sampling was used; this requirement was tested in its entirety. Recommendation: We recommend that Compass College of Cinematic Arts review its reporting procedures to ensure that roster file submissions are reported timely and accurately. View of Management and Planned Corrective Actions: The College is in agreement with the above audit finding and condition. Management?s Views and Corrective Action Plan is included as the end of this report after the Summary Schedule of Prior Audit Findings.
2019-002 Student Financial Assistance Cluster Recommendation: Compass College of Cinematic Arts should review its reporting procedures to ensure that roster file submissions are reported timely and accurately. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: Due to being a new hire, the Financial Aid Manager was not initially aware of this requirement and of the timeliness of this requirement. The lack of Microsoft Excel at the time also hindered the process, as it was difficult to get the report in a usable format. Policies and procedures have now been put in place to ensure accurate and timely reporting. Microsoft Excel is also now accessible so the report can be accessed in a user-friendly format. The Financial Aid Manager will ensure that the corrective action plan is being followed and will make any adjustments, as needed. Person responsible for corrective action: Lynne Heerema
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.