Milwaukee Institue of Art and Design

EIN: 391201561

UEI: JQSDRGK2M9S3

Data as of August 27, 2026

Milwaukee Institue of Art and Design11 audit years8 findings2 repeat
11
Audit Years
8
Total Findings
2
Repeat Findings

FY 2025-05-31

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on February 26, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by August 26, 2026 (1 day ago).

What is a management decision? →
2025-001
Special Tests & Provisions
REPEAT

Management implemented controls that specifically addressed some of the circumstances surrounding prior year finding 2024-001. Management's review of the enrollment reporting did not detect that the Institute was not timely reporting certain student Campus-Level and Program-Level data elements. Student records within the NSLDS was identified with non-timely Campus-Level and Program-Level data elements. Questioned Costs: There were no questioned costs. Context: In the sample selected, 4 students that withdrew during the 2024-2025 school year were identified with non-timely Campus-Level and Program-Level reported data elements out of a total of 30 students with status changes tested. We identified one error out of an initial sample of 25 students tested. Based on additional procedures, students that withdrew between June 4, 2024 and July 3, 2024 would not have been timely reported and would not have been detected or prevented by the Institute’s internal controls. There were a total of 4 students that withdrew in that date range and all were not timely reported. Cause: The Institute’s internal control over compliance did not detect and correct the errors. The preparer did not timely report withdrawal statuses impacting the student's effective date and status during submission process to NSLDS resulting in over 90 day certification in Campus and Program-Level enrollment data elements that ED considers high risk. The Institute’s internal control over compliance did not detect and correct the error within the 60 day initial window or additional 10-day correction window. Effect: The Institute did not timely report certain Campus-Level and Program-Level records in NSLDS which is information that ED considers high risk. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the timeliness of Campus-Level and Program-Level data elements reported to ED. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy and timing of enrollment reporting. Management’s Response: Management agrees with the finding. To resolve this issue, when a student formally withdraws or is academically dismissed in summer, the student information will be manually added to the next National Student Clearinghouse (NSC) upload file, submitted once a month, and marked as “Withdrawn” with an effective status date of the withdrawn date of determination. This complies with NSC processes detailed here: https://help.studentclearinghouse.org/compliancecentral/knowledge-base/enrollment-reporting-for-summer-and-other-non-required-terms/.

Show full finding ▾
Full finding narrative

Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (ED), Student financial assistance cluster. Finding Type: Noncompliance and significant deficiency in internal control over compliance relating to special tests of enrollment reporting. Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for accurately and timely reporting significant data elements under the Campus-Level and Program-Level records within the National Student Loan Data System (NSLDS) that ED considers high risk. Statement of Condition: Management implemented controls that specifically addressed some of the circumstances surrounding prior year finding 2024-001. Management's review of the enrollment reporting did not detect that the Institute was not timely reporting certain student Campus-Level and Program-Level data elements. Student records within the NSLDS was identified with non-timely Campus-Level and Program-Level data elements. Questioned Costs: There were no questioned costs. Context: In the sample selected, 4 students that withdrew during the 2024-2025 school year were identified with non-timely Campus-Level and Program-Level reported data elements out of a total of 30 students with status changes tested. We identified one error out of an initial sample of 25 students tested. Based on additional procedures, students that withdrew between June 4, 2024 and July 3, 2024 would not have been timely reported and would not have been detected or prevented by the Institute’s internal controls. There were a total of 4 students that withdrew in that date range and all were not timely reported. Cause: The Institute’s internal control over compliance did not detect and correct the errors. The preparer did not timely report withdrawal statuses impacting the student's effective date and status during submission process to NSLDS resulting in over 90 day certification in Campus and Program-Level enrollment data elements that ED considers high risk. The Institute’s internal control over compliance did not detect and correct the error within the 60 day initial window or additional 10-day correction window. Effect: The Institute did not timely report certain Campus-Level and Program-Level records in NSLDS which is information that ED considers high risk. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the timeliness of Campus-Level and Program-Level data elements reported to ED. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy and timing of enrollment reporting. Management’s Response: Management agrees with the finding. To resolve this issue, when a student formally withdraws or is academically dismissed in summer, the student information will be manually added to the next National Student Clearinghouse (NSC) upload file, submitted once a month, and marked as “Withdrawn” with an effective status date of the withdrawn date of determination. This complies with NSC processes detailed here: https://help.studentclearinghouse.org/compliancecentral/knowledge-base/enrollment-reporting-for-summer-and-other-non-required-terms/.

Corrective Action Plan

Finding 2025-001 Condition Management implemented controls that specifically addressed some of the circumstances surrounding prior year finding 2024-001. Management's review of the enrollment reporting did not timely report certain student Campus-Level and Program-Level data elements. Student records within the NSLDS was identified with non-timely Campus-Level and Program-Level data elements. Corrective Action Plan Corrective Action Planned: Management agrees with the finding. To resolve this issue, when a student formally withdraws or is academically dismissed in summer, the student information will be manually added to the next National Student Clearinghouse (NSC) upload file, submitted once a month, and marked as “Withdrawn” with an effective status date of the withdrawn date of determination. This complies with NSC processes detailed here: https://help.studentclearinghouse.org/compliancecentral/knowledge-base/enrollment-reporting-for-summer-and-other-non-required-terms/. Name of Contact Person Responsible for Corrective Action: Mark Fetherston, Vice President for Enrollment Management Anticipated Completion Date: Process and procedures will be updated in February 2026, with first implementation in May 2026 (as part of the Summer 2026 submission process).

Prior Finding References

2024-001

About Special Tests and Provisions →

FY 2024-05-31

FAC accepted this audit on January 29, 2025 — management decision was due July 29, 2025.

2024-001
Special Tests & Provisions
MATERIAL WEAKNESSREPEAT

Management implemented controls that specifically addressed some of the circumstances surrounding prior year finding 2023-001. Management's review of the enrollment reporting did not detect errors on certain student Program-Level data elements or timely reporting. Certain student records within the NSLDS were identified with inaccurate Program-Level data elements and not timely reported. Questioned Costs: There were no questioned costs. Context: 9 students were identified with inaccurate Program-Level data elements and not timely reported out of a total of 27 student statuses tested. The Campus-Level data elements were accurately and timely reported. Cause: The Institute’s internal control over compliance did not detect and correct the errors. The preparer incorrectly reported graduate file impacting the student's effective dates and statuses during submission process to NSLDS resulting in inaccuracies in significant Program-Level enrollment data elements that ED considers high risk. The Institute’s internal control over compliance did not detect and correct the error. Effect: The Institute incorrectly reported certain Program-Level records in NSLDS which is information that DOE considers high risk and the Institute’s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of Program-Level data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Management’s Response: Management agrees with the finding. Through internal investigation, it was determined that the date field issues found in 2023 also impacted “special” files, which include graduate data files and are processed differently in-house. This error has been fixed so that both fields will always be the same and accurate using the same corrective method as the 2023-001 finding. The registrar will now confirm both the student-level and program-level data fields upon submission to NSC.

Show full finding ▾
Full finding narrative

2024-001 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and material weakness in internal control over compliance relating to special tests. Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for accurately and timely reporting significant data elements under the Campus-Level and Program-Level records within the National Student Loan Data System (NSLDS) that DOE considers high risk. Statement of Condition: Management implemented controls that specifically addressed some of the circumstances surrounding prior year finding 2023-001. Management's review of the enrollment reporting did not detect errors on certain student Program-Level data elements or timely reporting. Certain student records within the NSLDS were identified with inaccurate Program-Level data elements and not timely reported. Questioned Costs: There were no questioned costs. Context: 9 students were identified with inaccurate Program-Level data elements and not timely reported out of a total of 27 student statuses tested. The Campus-Level data elements were accurately and timely reported. Cause: The Institute’s internal control over compliance did not detect and correct the errors. The preparer incorrectly reported graduate file impacting the student's effective dates and statuses during submission process to NSLDS resulting in inaccuracies in significant Program-Level enrollment data elements that ED considers high risk. The Institute’s internal control over compliance did not detect and correct the error. Effect: The Institute incorrectly reported certain Program-Level records in NSLDS which is information that DOE considers high risk and the Institute’s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of Program-Level data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Management’s Response: Management agrees with the finding. Through internal investigation, it was determined that the date field issues found in 2023 also impacted “special” files, which include graduate data files and are processed differently in-house. This error has been fixed so that both fields will always be the same and accurate using the same corrective method as the 2023-001 finding. The registrar will now confirm both the student-level and program-level data fields upon submission to NSC.

Corrective Action Plan

2024-001 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and material weakness in internal control over compliance relating to special tests. Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for accurately and timely reporting significant data elements under the Campus-Level and Program-Level records within the National Student Loan Data System (NSLDS) that DOE considers high risk. Statement of Condition: Management implemented controls that specifically addressed the some of the circumstances surrounding prior year finding 2023-001. Management's review of the enrollment reporting did not detect errors on certain student Program-Level data elements or timely reporting. Certain student records within the NSLDS were identified with inaccurate Program-Level data elements and not timely reported. Questioned Costs: There were no questioned costs. Context: 9 students were identified with inaccurate Program-Level data elements and not timely reported out of a total of 27 student statuses tested. The Campus-Level data elements were accurately and timely reported. Cause: The Institute’s internal control over compliance did not detect and correct the errors. The preparer incorrectly reported graduate file impacting the student's effective dates and statuses during submission process to NSLDS resulting in inaccuracies in significant Program-Level enrollment data elements that ED considers high risk. The Institute’s internal control over compliance did not detect and correct the error. Effect: The Institute incorrectly reported certain Program-Level records in NSLDS which is information that DOE considers high risk and the Institute’s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of Program-Level data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Management’s Response: Management agrees with the finding. Through internal investigation, it was determined that the date field issues found in 2023 also impacted “special” files, which include graduate data files and are processed differently in-house. This error has been fixed so that both fields will always be the same and accurate using the same method as the 2023-001 finding. The registrar will now confirm both the student-level and program-level data fields upon submission to NSC. Status: Completed January 2024 Contact: Mark Fetherston Vice President for Enrollment Management 414-847-3215 markfetherston@miad.edu

Prior Finding References

2023-001

About Special Tests and Provisions →

FY 2023-05-31

FAC accepted this audit on February 29, 2024 — management decision was due August 29, 2024.

2023-001
Special Tests & Provisions
MATERIAL WEAKNESS

Management implemented controls that specifically addressed the circumstances surrounding prior year finding 2022-001. Management's review of the enrollment reporting did not detect other errors on certain student data elements or timely reporting. Certain student records within the NSLDS were identified with inaccurate data elements and not timely reported. Questioned Costs: Questioned costs could not be determined. Context: 10 students were identified with inaccurate data elements and not timely reported out of a total of 25 students tested. Cause: The Institute’s internal control over compliance did not detect and correct the errors. The preparer incorrectly input the student's effective date and status into NSLDS resulting in inaccuracies in significant Campus-Level and Program-Level enrollment data elements that DOE considers high risk. Effect: The Institute incorrectly reported certain Campus-Level and Program-Level records in NSLDS which is information that DOE considers high risk and the Institute’s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Management’s Response: Management agrees with the finding. Through internal investigation, it was determined that there was a procedural issue with the manual entry of two date fields which both need to be the same when submitted to National Student Clearinghouse (NSC). Human error during these manual checks caused one data field to be correct, and the other incorrect. This error has been fixed so that both fields will always be the same and accurate. The Institute has also updated our enrollment reporting procedures to have the registrar log into NSLDS monthly to confirm that the prior month NSC status changes are properly recorded in NSLDS.

Show full finding ▾
Full finding narrative

2023-001 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and material weakness in internal control over compliance relating to special tests. Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for accurately and timely reporting significant data elements under the Campus-Level and Program-Level records within the National Student Loan Data System (NSLDS) that DOE considers high risk. Statement of Condition: Management implemented controls that specifically addressed the circumstances surrounding prior year finding 2022-001. Management's review of the enrollment reporting did not detect other errors on certain student data elements or timely reporting. Certain student records within the NSLDS were identified with inaccurate data elements and not timely reported. Questioned Costs: Questioned costs could not be determined. Context: 10 students were identified with inaccurate data elements and not timely reported out of a total of 25 students tested. Cause: The Institute’s internal control over compliance did not detect and correct the errors. The preparer incorrectly input the student's effective date and status into NSLDS resulting in inaccuracies in significant Campus-Level and Program-Level enrollment data elements that DOE considers high risk. Effect: The Institute incorrectly reported certain Campus-Level and Program-Level records in NSLDS which is information that DOE considers high risk and the Institute’s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Management’s Response: Management agrees with the finding. Through internal investigation, it was determined that there was a procedural issue with the manual entry of two date fields which both need to be the same when submitted to National Student Clearinghouse (NSC). Human error during these manual checks caused one data field to be correct, and the other incorrect. This error has been fixed so that both fields will always be the same and accurate. The Institute has also updated our enrollment reporting procedures to have the registrar log into NSLDS monthly to confirm that the prior month NSC status changes are properly recorded in NSLDS.

Corrective Action Plan

Corrective Action Plan For the Year Ended May 31, 2023 Finding 2023-001 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and material weakness in internal control over compliance relating to special tests. Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for accurately and timely reporting significant data elements under the Campus- Level and Program-Level records within the National Student Loan Data System (NSLDS) that DOE considers high risk. Statement of Condition: Management implemented controls that specifically addressed the circumstances surrounding prior year finding 2022-001. Management's review of the enrollment reporting did not detect other errors on certain student data elements or timely reporting. Certain student records within the NSLDS were identified with inaccurate data elements and not timely reported. Questioned Costs: Questioned costs could not be determined. Context: 10 students were identified with inaccurate data elements and not timely reported out of a total of 25 students tested. Cause: The Institute’s internal control over compliance did not detect and correct the errors. The preparer incorrectly input the student's effective date and status into NSLDS resulting in inaccuracies in significant Campus- Level and Program-Level enrollment data elements that DOE considers high risk. Effect: The Institute incorrectly reported certain Campus-Level and Program-Level records in NSLDS which is information that DOE considers high risk and the Institute’s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Status: Completed February 2024 Corrective Action: Management agrees with the finding. Through internal investigation, it was determined that there was a procedural issue with the manual entry of two date fields which both need to be the same when submitted to National Student Clearinghouse (NSC). Human error during these manual checks caused one data field to be correct, and the other incorrect. This error has been fixed so that both fields will always be the same and accurate. We have also updated our enrollment reporting procedures to have the registrar log into NSLDS monthly to confirm that the prior month NSC status changes are properly recorded in NSLDS. Contact Jean Weimer Registrar 414-847-3272 jeanweimer@miad.edu Submitted Feb 23, 2024

About Special Tests and Provisions →
2023-001
Special Tests & Provisions
MATERIAL WEAKNESS

Management implemented controls that specifically addressed the circumstances surrounding prior year finding 2022-001. Management's review of the enrollment reporting did not detect other errors on certain student data elements or timely reporting. Certain student records within the NSLDS were identified with inaccurate data elements and not timely reported. Questioned Costs: Questioned costs could not be determined. Context: 10 students were identified with inaccurate data elements and not timely reported out of a total of 25 students tested. Cause: The Institute’s internal control over compliance did not detect and correct the errors. The preparer incorrectly input the student's effective date and status into NSLDS resulting in inaccuracies in significant Campus-Level and Program-Level enrollment data elements that DOE considers high risk. Effect: The Institute incorrectly reported certain Campus-Level and Program-Level records in NSLDS which is information that DOE considers high risk and the Institute’s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Management’s Response: Management agrees with the finding. Through internal investigation, it was determined that there was a procedural issue with the manual entry of two date fields which both need to be the same when submitted to National Student Clearinghouse (NSC). Human error during these manual checks caused one data field to be correct, and the other incorrect. This error has been fixed so that both fields will always be the same and accurate. The Institute has also updated our enrollment reporting procedures to have the registrar log into NSLDS monthly to confirm that the prior month NSC status changes are properly recorded in NSLDS.

Show full finding ▾
Full finding narrative

2023-001 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and material weakness in internal control over compliance relating to special tests. Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for accurately and timely reporting significant data elements under the Campus-Level and Program-Level records within the National Student Loan Data System (NSLDS) that DOE considers high risk. Statement of Condition: Management implemented controls that specifically addressed the circumstances surrounding prior year finding 2022-001. Management's review of the enrollment reporting did not detect other errors on certain student data elements or timely reporting. Certain student records within the NSLDS were identified with inaccurate data elements and not timely reported. Questioned Costs: Questioned costs could not be determined. Context: 10 students were identified with inaccurate data elements and not timely reported out of a total of 25 students tested. Cause: The Institute’s internal control over compliance did not detect and correct the errors. The preparer incorrectly input the student's effective date and status into NSLDS resulting in inaccuracies in significant Campus-Level and Program-Level enrollment data elements that DOE considers high risk. Effect: The Institute incorrectly reported certain Campus-Level and Program-Level records in NSLDS which is information that DOE considers high risk and the Institute’s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Management’s Response: Management agrees with the finding. Through internal investigation, it was determined that there was a procedural issue with the manual entry of two date fields which both need to be the same when submitted to National Student Clearinghouse (NSC). Human error during these manual checks caused one data field to be correct, and the other incorrect. This error has been fixed so that both fields will always be the same and accurate. The Institute has also updated our enrollment reporting procedures to have the registrar log into NSLDS monthly to confirm that the prior month NSC status changes are properly recorded in NSLDS.

Corrective Action Plan

Corrective Action Plan For the Year Ended May 31, 2023 Finding 2023-001 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and material weakness in internal control over compliance relating to special tests. Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for accurately and timely reporting significant data elements under the Campus- Level and Program-Level records within the National Student Loan Data System (NSLDS) that DOE considers high risk. Statement of Condition: Management implemented controls that specifically addressed the circumstances surrounding prior year finding 2022-001. Management's review of the enrollment reporting did not detect other errors on certain student data elements or timely reporting. Certain student records within the NSLDS were identified with inaccurate data elements and not timely reported. Questioned Costs: Questioned costs could not be determined. Context: 10 students were identified with inaccurate data elements and not timely reported out of a total of 25 students tested. Cause: The Institute’s internal control over compliance did not detect and correct the errors. The preparer incorrectly input the student's effective date and status into NSLDS resulting in inaccuracies in significant Campus- Level and Program-Level enrollment data elements that DOE considers high risk. Effect: The Institute incorrectly reported certain Campus-Level and Program-Level records in NSLDS which is information that DOE considers high risk and the Institute’s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Status: Completed February 2024 Corrective Action: Management agrees with the finding. Through internal investigation, it was determined that there was a procedural issue with the manual entry of two date fields which both need to be the same when submitted to National Student Clearinghouse (NSC). Human error during these manual checks caused one data field to be correct, and the other incorrect. This error has been fixed so that both fields will always be the same and accurate. We have also updated our enrollment reporting procedures to have the registrar log into NSLDS monthly to confirm that the prior month NSC status changes are properly recorded in NSLDS. Contact Jean Weimer Registrar 414-847-3272 jeanweimer@miad.edu Submitted Feb 23, 2024

About Special Tests and Provisions →
2023-002
Special Tests & Provisions

The Institute performed a risk assessment however the safeguards for the risks identified were not formally documented through a policy. A formal policy was not reviewed in fiscal year 2023 which would have addressed required areas noted in 16 CFR 314.4 (b). Questioned Costs: Questioned costs could not be determined. Context: A policy and documentation linking the safeguards to the risk assessment was not formally written. The internal controls over compliance at the Institute did not identify the noncompliance. However, the Institute performed risk assessments and has appropriate safeguards for each area identified within 16 CFR 314.4(b). Cause: The Institute did not have internal controls in place to identify the need for the policy documenting the safeguards required by the Gramm-Leach-Bliley Act. Effect: The Institute has no documented policy and the related safeguards for each risk identified. Recommendation: We recommend management review 16 CFR 314.4 (b) to create a policy that addresses the three required areas, which are (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures. This policy should be formalized and reviewed annually. We recommend that the Institute document the approval and acceptance of the policy. In addition, we recommend management review internal control processes for special tests and provisions on an annual basis. Management’s Response: Management agrees with the finding. The Institute is currently developing a comprehensive cyber-security policy to address 16 CFR 314.4 (b), which will be formalized, approved by Senior Staff, and reviewed annually. The Institute is now conducting annual penetration tests, the most recent in December 2023, to address internal control processes. The Institute has contracted with a planning team at CDW to determine best practices and perform training. The Institute has begun providing a quarterly GLBA Compliance update to our board, with an annual comprehensive GLBA review to the board.

Show full finding ▾
Full finding narrative

2023-002 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and significant deficiency in control over compliance relating to special tests. Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for safeguarding sensitive data under the Gramm-Leach-Bliley Act, including performing an annual risk assessment that addresses three required areas noted in 16 Code of Federal Regulations (CFR) 314.4 (b). Statement of Condition: The Institute performed a risk assessment however the safeguards for the risks identified were not formally documented through a policy. A formal policy was not reviewed in fiscal year 2023 which would have addressed required areas noted in 16 CFR 314.4 (b). Questioned Costs: Questioned costs could not be determined. Context: A policy and documentation linking the safeguards to the risk assessment was not formally written. The internal controls over compliance at the Institute did not identify the noncompliance. However, the Institute performed risk assessments and has appropriate safeguards for each area identified within 16 CFR 314.4(b). Cause: The Institute did not have internal controls in place to identify the need for the policy documenting the safeguards required by the Gramm-Leach-Bliley Act. Effect: The Institute has no documented policy and the related safeguards for each risk identified. Recommendation: We recommend management review 16 CFR 314.4 (b) to create a policy that addresses the three required areas, which are (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures. This policy should be formalized and reviewed annually. We recommend that the Institute document the approval and acceptance of the policy. In addition, we recommend management review internal control processes for special tests and provisions on an annual basis. Management’s Response: Management agrees with the finding. The Institute is currently developing a comprehensive cyber-security policy to address 16 CFR 314.4 (b), which will be formalized, approved by Senior Staff, and reviewed annually. The Institute is now conducting annual penetration tests, the most recent in December 2023, to address internal control processes. The Institute has contracted with a planning team at CDW to determine best practices and perform training. The Institute has begun providing a quarterly GLBA Compliance update to our board, with an annual comprehensive GLBA review to the board.

Corrective Action Plan

Corrective Action Plan For the Year Ended May 31, 2023 Finding 2023-002 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and significant deficiency in control over compliance relating to special tests. Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for safeguarding sensitive data under the Gramm-Leach-Bliley Act, including performing an annual risk assessment that addresses three required areas noted in 16 Code of Federal Regulations (CFR) 314.4 (b). Statement of Condition: The Institute performed a risk assessment however the safeguards for the risks identified were not formally documented through a policy. A formal policy was not reviewed in fiscal year 2023 which would have addressed required areas noted in 16 CFR 314.4 (b). Questioned Costs: Questioned costs could not be determined. Context: A policy and documentation linking the safeguards to the risk assessment was not formally written. The internal controls over compliance at the Institute did not identify the noncompliance. However, the Institute performed risk assessments and has appropriate safeguards for each area identified within 16 CFR 314.4(b). Cause: The Institute did not have internal controls in place to identify the need for the policy documenting the safeguards required by the Gramm-Leach-Bliley Act. Effect: The Institute has no verifiable evidence of the policy and the related safeguards for each risk identified. Recommendation: We recommend management review 16 CFR 314.4 (b) to create a policy that addresses the three required areas, which are (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures. This policy should be formalized and reviewed annually. We recommend that the Institute document the approval and acceptance of the policy. In addition, we recommend management review internal control processes for special tests and provisions on an annual basis. Status: In progress, anticipated completion September 2024 Corrective Action: Management agrees with the finding. We are currently developing a comprehensive cybersecurity policy to address 16 CFR 314.4 (b), which will be formalized, approved by Senior Staff, and reviewed annually. We are now conducting annual penetration tests, the most recent in December 2023, to address internal control processes. We have contracted with a planning team at CDW to determine best practices and perform training. We have begun providing a quarterly GLBA Compliance update to our board, with an annual comprehensive GLBA review to the board. Contact Matt Ogden Director of Technology 414.847.3223 mattogden@miad.edu Submitted Feb 23, 2024

About Special Tests and Provisions →
2023-002
Special Tests & Provisions

The Institute performed a risk assessment however the safeguards for the risks identified were not formally documented through a policy. A formal policy was not reviewed in fiscal year 2023 which would have addressed required areas noted in 16 CFR 314.4 (b). Questioned Costs: Questioned costs could not be determined. Context: A policy and documentation linking the safeguards to the risk assessment was not formally written. The internal controls over compliance at the Institute did not identify the noncompliance. However, the Institute performed risk assessments and has appropriate safeguards for each area identified within 16 CFR 314.4(b). Cause: The Institute did not have internal controls in place to identify the need for the policy documenting the safeguards required by the Gramm-Leach-Bliley Act. Effect: The Institute has no documented policy and the related safeguards for each risk identified. Recommendation: We recommend management review 16 CFR 314.4 (b) to create a policy that addresses the three required areas, which are (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures. This policy should be formalized and reviewed annually. We recommend that the Institute document the approval and acceptance of the policy. In addition, we recommend management review internal control processes for special tests and provisions on an annual basis. Management’s Response: Management agrees with the finding. The Institute is currently developing a comprehensive cyber-security policy to address 16 CFR 314.4 (b), which will be formalized, approved by Senior Staff, and reviewed annually. The Institute is now conducting annual penetration tests, the most recent in December 2023, to address internal control processes. The Institute has contracted with a planning team at CDW to determine best practices and perform training. The Institute has begun providing a quarterly GLBA Compliance update to our board, with an annual comprehensive GLBA review to the board.

Show full finding ▾
Full finding narrative

2023-002 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and significant deficiency in control over compliance relating to special tests. Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for safeguarding sensitive data under the Gramm-Leach-Bliley Act, including performing an annual risk assessment that addresses three required areas noted in 16 Code of Federal Regulations (CFR) 314.4 (b). Statement of Condition: The Institute performed a risk assessment however the safeguards for the risks identified were not formally documented through a policy. A formal policy was not reviewed in fiscal year 2023 which would have addressed required areas noted in 16 CFR 314.4 (b). Questioned Costs: Questioned costs could not be determined. Context: A policy and documentation linking the safeguards to the risk assessment was not formally written. The internal controls over compliance at the Institute did not identify the noncompliance. However, the Institute performed risk assessments and has appropriate safeguards for each area identified within 16 CFR 314.4(b). Cause: The Institute did not have internal controls in place to identify the need for the policy documenting the safeguards required by the Gramm-Leach-Bliley Act. Effect: The Institute has no documented policy and the related safeguards for each risk identified. Recommendation: We recommend management review 16 CFR 314.4 (b) to create a policy that addresses the three required areas, which are (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures. This policy should be formalized and reviewed annually. We recommend that the Institute document the approval and acceptance of the policy. In addition, we recommend management review internal control processes for special tests and provisions on an annual basis. Management’s Response: Management agrees with the finding. The Institute is currently developing a comprehensive cyber-security policy to address 16 CFR 314.4 (b), which will be formalized, approved by Senior Staff, and reviewed annually. The Institute is now conducting annual penetration tests, the most recent in December 2023, to address internal control processes. The Institute has contracted with a planning team at CDW to determine best practices and perform training. The Institute has begun providing a quarterly GLBA Compliance update to our board, with an annual comprehensive GLBA review to the board.

Corrective Action Plan

Corrective Action Plan For the Year Ended May 31, 2023 Finding 2023-002 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and significant deficiency in control over compliance relating to special tests. Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for safeguarding sensitive data under the Gramm-Leach-Bliley Act, including performing an annual risk assessment that addresses three required areas noted in 16 Code of Federal Regulations (CFR) 314.4 (b). Statement of Condition: The Institute performed a risk assessment however the safeguards for the risks identified were not formally documented through a policy. A formal policy was not reviewed in fiscal year 2023 which would have addressed required areas noted in 16 CFR 314.4 (b). Questioned Costs: Questioned costs could not be determined. Context: A policy and documentation linking the safeguards to the risk assessment was not formally written. The internal controls over compliance at the Institute did not identify the noncompliance. However, the Institute performed risk assessments and has appropriate safeguards for each area identified within 16 CFR 314.4(b). Cause: The Institute did not have internal controls in place to identify the need for the policy documenting the safeguards required by the Gramm-Leach-Bliley Act. Effect: The Institute has no verifiable evidence of the policy and the related safeguards for each risk identified. Recommendation: We recommend management review 16 CFR 314.4 (b) to create a policy that addresses the three required areas, which are (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures. This policy should be formalized and reviewed annually. We recommend that the Institute document the approval and acceptance of the policy. In addition, we recommend management review internal control processes for special tests and provisions on an annual basis. Status: In progress, anticipated completion September 2024 Corrective Action: Management agrees with the finding. We are currently developing a comprehensive cybersecurity policy to address 16 CFR 314.4 (b), which will be formalized, approved by Senior Staff, and reviewed annually. We are now conducting annual penetration tests, the most recent in December 2023, to address internal control processes. We have contracted with a planning team at CDW to determine best practices and perform training. We have begun providing a quarterly GLBA Compliance update to our board, with an annual comprehensive GLBA review to the board. Contact Matt Ogden Director of Technology 414.847.3223 mattogden@miad.edu Submitted Feb 23, 2024

About Special Tests and Provisions →

FY 2022-05-31

FAC accepted this audit on February 27, 2023 — management decision was due August 27, 2023.

2022-001
Special Tests & Provisions

Management's review of the enrollment reporting did not detect errors on certain student data elements. Certain student records within the NSLDS were identified with inaccurate data elements. Questioned Costs: Questioned costs could not be determined. Context: Five students were identified with inaccurate data elements reported out of a total of 40 students tested. Cause: The Institute?s internal control over compliance did not detect and correct the errors. The preparer incorrectly input the student's status into NSLDS resulting in inaccuracies in significant Campus-Level and Program-Level enrollment data elements that DOE considers high risk. Effect: The Institute incorrectly reported certain Campus-Level and Program-Level records in NSLDS which is information that DOE considers high risk and the Institute?s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Management?s Response: Management agrees with the finding. Through internal investigation, it was determined that the issue arose through National Student Clearinghouse (NSC), which reports the Institute?s data to NSLDS. Management will work with NSC to assure graduates are accurately reported as soon as possible within existing external systems. The changes to management?s enrollment reporting procedures will be added to the Institute?s NSC submissions procedure documentation.

Show full finding ▾
Full finding narrative

2022-001 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and significant deficiency in internal control over compliance relating to special tests Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for accurately reporting significant data elements under the Campus-Level and Program-Level records within the National Student Loan Data System (NSLDS) that DOE considers high risk. Statement of Condition: Management's review of the enrollment reporting did not detect errors on certain student data elements. Certain student records within the NSLDS were identified with inaccurate data elements. Questioned Costs: Questioned costs could not be determined. Context: Five students were identified with inaccurate data elements reported out of a total of 40 students tested. Cause: The Institute?s internal control over compliance did not detect and correct the errors. The preparer incorrectly input the student's status into NSLDS resulting in inaccuracies in significant Campus-Level and Program-Level enrollment data elements that DOE considers high risk. Effect: The Institute incorrectly reported certain Campus-Level and Program-Level records in NSLDS which is information that DOE considers high risk and the Institute?s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Management?s Response: Management agrees with the finding. Through internal investigation, it was determined that the issue arose through National Student Clearinghouse (NSC), which reports the Institute?s data to NSLDS. Management will work with NSC to assure graduates are accurately reported as soon as possible within existing external systems. The changes to management?s enrollment reporting procedures will be added to the Institute?s NSC submissions procedure documentation.

Corrective Action Plan

Corrective Action Plan For the Year Ended May 31, 2022 Finding 2022-001 Assistance listing number(s), federal agency, and program name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial aid cluster. Finding type: Noncompliance and significant deficiency in internal control over compliance Statement of condition: Certain student records within the National Student Loan Data System (NSLDS) were identified with inaccurate data elements. Management's review of the enrollment reporting did not detect errors on certain student data elements. Context: Five students were identified with inaccurate data elements reported out of a total of 40 students tested. Cause: The preparer incorrectly input the student's status into NSLDS resulting in inaccuracies in significant Campus-Level and Program-Level enrollment data elements that ED considers high risk. The Institute?s internal control over compliance did not detect and correct the error. Effect: The Institute incorrectly reported certain Campus-Level and Program-Level records in NSLDS which is information that DOE considers high risk and the Institute?s internal controls over compliance did not detect and correct the errors. Recommendation: We recommend management review policies and procedures surrounding enrollment reporting submissions to ensure the accuracy of data elements reported to DOE. A review performed by an appropriate individual separate from the preparer prior to the submission of the enrollment reports to NSLDS may improve the accuracy of enrollment reporting. Status completed Corrective Action Management agrees with the finding. Through internal investigation, it was determined that the issue arose through National Student Clearinghouse (NSC), which reports the Institute?s data to NSLDS. Management will work with NSC to assure graduates are accurately reported as soon as possible within existing external systems. The changes to management?s enrollment reporting procedures will be added to the Institute?s NSC submissions procedure documentation. Contact Jean Weimer Registrar 414-847-3272 jeanweimer@miad.edu submitted 2/23/2023

About Special Tests and Provisions →
2022-002
Special Tests & Provisions

A formal risk assessment was not completed and documented in fiscal 2022 which would have addressed required areas noted in 16 CFR 314.4 (b). Questioned Costs: Questioned costs could not be determined. Context: The internal controls over compliance at the Institute did not identify that a risk assessment in compliance with the Gramm-Leach-Bliley Act was not completed and that the Institute did not comply with the compliance requirement. However, the Institute has safeguards for each area identified within 16 CFR 314.4 (b). Cause: The Institute did not have internal controls in place to identify the need for the risk assessment required by the Gramm-Leach-Bliley Act. Effect: The Institute has no verifiable evidence of the risk assessment performed and the related safeguards for each risk identified. Recommendation: We recommend management review 16 CFR 314.4 (b) to perform a risk assessment that addresses the three required areas, which are (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures. This risk assessment should be documented and we recommend that the Institute document the approval and acceptance of the risk assessment. In addition, we recommend management review internal control processes for special tests and provisions on an annual basis. Management?s Response: Management agrees with the finding. The Institute will review 16 CFR 314.4 (b) and develop a written Information Security Plan (ISP) that outlines the procedures and practices to protect non-public personal information (NPI) and manage information security risks. The Institute will provide routinely scheduled training to all current and new employees on the importance of protecting NPI and the procedures they must follow to ensure that employees are up-to-date with the latest information security best practices. The Institute will continue to conduct regular risk assessments to identify potential security vulnerabilities, both internal and external, to evaluate the effectiveness of the ISP. The Institute will develop a plan to investigate and respond to security incidents that may compromise NPI. If an incident occurs the Institute will follow the ISP to remedy the incident, and revise the ISP as needed.

Show full finding ▾
Full finding narrative

2022-002 Assistance Listing Number(s), Federal Agency and Program Name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial assistance cluster. Finding Type: Noncompliance and significant deficiency in control over compliance relating to special tests Criteria: The Institute is responsible for designing, implementing, and maintaining internal control over compliance for special tests and provisions and for safeguarding sensitive data under the Gramm-Leach-Bliley Act, including performing an annual risk assessment that addresses three required areas noted in 16 Code of Federal Regulations (CFR) 314.4 (b). Statement of Condition: A formal risk assessment was not completed and documented in fiscal 2022 which would have addressed required areas noted in 16 CFR 314.4 (b). Questioned Costs: Questioned costs could not be determined. Context: The internal controls over compliance at the Institute did not identify that a risk assessment in compliance with the Gramm-Leach-Bliley Act was not completed and that the Institute did not comply with the compliance requirement. However, the Institute has safeguards for each area identified within 16 CFR 314.4 (b). Cause: The Institute did not have internal controls in place to identify the need for the risk assessment required by the Gramm-Leach-Bliley Act. Effect: The Institute has no verifiable evidence of the risk assessment performed and the related safeguards for each risk identified. Recommendation: We recommend management review 16 CFR 314.4 (b) to perform a risk assessment that addresses the three required areas, which are (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures. This risk assessment should be documented and we recommend that the Institute document the approval and acceptance of the risk assessment. In addition, we recommend management review internal control processes for special tests and provisions on an annual basis. Management?s Response: Management agrees with the finding. The Institute will review 16 CFR 314.4 (b) and develop a written Information Security Plan (ISP) that outlines the procedures and practices to protect non-public personal information (NPI) and manage information security risks. The Institute will provide routinely scheduled training to all current and new employees on the importance of protecting NPI and the procedures they must follow to ensure that employees are up-to-date with the latest information security best practices. The Institute will continue to conduct regular risk assessments to identify potential security vulnerabilities, both internal and external, to evaluate the effectiveness of the ISP. The Institute will develop a plan to investigate and respond to security incidents that may compromise NPI. If an incident occurs the Institute will follow the ISP to remedy the incident, and revise the ISP as needed.

Corrective Action Plan

Action Plan For the Year Ended May 31, 2022 Finding 2022-002 Section III ? Federal and State Awards Findings and Questioned Costs Assistance listing number(s), federal agency, and program name: 84.063, 84.007, 84.033, and 84.268; United States Department of Education (DOE), Student financial aid cluster. Finding type: Noncompliance Criteria: The Institute is responsible for safeguarding sensitive data under the Gramm-Leach-Bliley Act, including performing a risk assessment that addresses three required areas noted in 16 CFR 314.4 (b). Statement of condition: A formal risk assessment is not documented which addresses required areas noted in 16 CFR 314.4 (b). Questioned costs: Questioned costs could not be determined. Context: The Institute has safeguards for each area identified within 16 CFR 314.4 (b) in place; however a formal risk assessment and documentation of the relevant safeguards implemented by the Institute to address the risks is not documented. Cause: There is no formal risk assessment documented. Effect: The Institute has no verifiable evidence of the risk assessment performed and the related safeguard for each risk identified. Recommendation: We recommend management review 16 CFR 314.4 (b) to perform a risk assessment that addresses the three required areas, which are (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions, or other systems failures. Management?s Response: Management agrees with the finding. Corrective Action: MIAD will review 16 CFR 314.4 (b) and develop a written Information Security Plan (ISP) that outlines the procedures and practices to protect non-public personal information (NPI) and manage information security risks. MIAD will provide routinely scheduled training to all current and new employees on the importance of protecting NPI and the procedures they must follow, to ensure that employees are up-to-date with the latest information security best practices. MIAD will continue to conduct regular risk assessments to identify potential security vulnerabilities, both internal and external, to evaluate the effectiveness of the ISP. MIAD will develop a plan to investigate and respond to security incidents that may compromise NPI. If an incident occurs MIAD will follow the ISP to remedy the incident, and revise the ISP as needed. Matt Ogden Director of Technology 414.847.3223 mattogden@miad.edu February 14th 2023

About Special Tests and Provisions →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and compliance status.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.