← Back to home

Martin Luther CollegeHigher Education

EIN: 410695520

UEI: QY6ZHNKREKS3

Audited by: Baker Tilly US, LLP

Oversight agency: 84 [Department of Education]

View federal awards & risk assessment →

Data as of August 28, 2026

Martin Luther College10 audit years2 findings
10
Audit Years
2
Total Findings
0
Repeat Findings
$3.6M
Federal Awards Expended (FY 2025)

FY 2025-06-30

LOW-RISK AUDITEE$3,556,478 federal awards expendedNo findings recorded this year

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on December 17, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by June 17, 2026 (75 days ago).

What is a management decision? →

FY 2024-06-30

LOW-RISK AUDITEE$2,666,725 federal awards expendedNo findings recorded this year

FAC accepted this audit on January 10, 2025 — management decision was due July 10, 2025.

FY 2023-06-30

LOW-RISK AUDITEE$2,856,910 federal awards expended

FAC accepted this audit on March 20, 2024 — management decision was due September 20, 2024.

2023-001
Special Tests & Provisions
OTHER MATTERS

Criteria The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition The College does not have a written information security program that addresses all elements that apply. Cause The College did not have procedures and processes in place specific to GLBA and therefore, did not have written documentation of all required elements. Effect Failure to comply with the requirements of GLBA standards puts the College at risk of compromising consumer, nonpublic personal information. Questioned Costs Not applicable. Context Not applicable. Recommendation The College should perform and document an annual risk assessment to determine the College’s specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the College should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management’s Response The cause of the reported issue stems from the lack of written documentation of policies and procedures specific to GLBA requirements. The issue is being addressed by the Director of Information Technology and a campus-wide committee overseeing information security. The documented information security program has been drafted and will address the GLBA cybersecurity requirements.

Show full finding ▾
Full finding narrative

Criteria The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). In 2021, the Federal Trade Commission issued final regulations that altered the current required elements of an information security program and added several new elements. Under the regulations, institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The written information security program for institutions must address all elements that apply. The elements for the information security programs set forth in this section 16 CFR 314.4 are high-level principles that set forth basic issues the programs must address, and do not prescribe how they will be addressed. Condition The College does not have a written information security program that addresses all elements that apply. Cause The College did not have procedures and processes in place specific to GLBA and therefore, did not have written documentation of all required elements. Effect Failure to comply with the requirements of GLBA standards puts the College at risk of compromising consumer, nonpublic personal information. Questioned Costs Not applicable. Context Not applicable. Recommendation The College should perform and document an annual risk assessment to determine the College’s specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the College should address each of the required minimum elements noted in the GLBA regulations (16 CFR 314.4). Management’s Response The cause of the reported issue stems from the lack of written documentation of policies and procedures specific to GLBA requirements. The issue is being addressed by the Director of Information Technology and a campus-wide committee overseeing information security. The documented information security program has been drafted and will address the GLBA cybersecurity requirements.

Corrective Action Plan

The lack of written documentation of policies and procedures specific to GLBA requirements is being addressed by the Director of Information Technology and a campus-wide committee overseeing information security. The documented information security program has been drafted and will address the required elements of GLBA . Final policies will be reviewed and approved by the Administrative Council, or president’s cabinet. The College is also planning to increase assurance procedures related to the GLBA requirements, with a mid-year review of the information security program as well as enhanced procedures during the interim audit.

About Special Tests and Provisions →

FY 2022-06-30

LOW-RISK AUDITEE$3,712,494 federal awards expendedNo findings recorded this year

FAC accepted this audit on October 30, 2022 — management decision was due April 30, 2023.

FY 2021-06-30

LOW-RISK AUDITEE$5,695,216 federal awards expendedNo findings recorded this year

FAC accepted this audit on October 10, 2021 — management decision was due April 10, 2022.

FY 2020-06-30

LOW-RISK AUDITEE$4,819,568 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 15, 2021 — management decision was due August 15, 2021.

FY 2019-06-30

LOW-RISK AUDITEE$4,930,053 federal awards expendedNo findings recorded this year

FAC accepted this audit on September 29, 2019 — management decision was due March 29, 2020.

FY 2018-06-30

LOW-RISK AUDITEE$5,090,833 federal awards expended

FAC accepted this audit on October 1, 2018 — management decision was due April 1, 2019.

2018-001
Special Tests & Provisions
SIGNIFICANT DEFICIENCYOTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →

FY 2017-06-30

LOW-RISK AUDITEE$4,700,161 federal awards expendedNo findings recorded this year

FAC accepted this audit on October 1, 2017 — management decision was due April 1, 2018.

FY 2016-06-30

LOW-RISK AUDITEE$4,526,130 federal awards expendedNo findings recorded this year

FAC accepted this audit on October 31, 2016 — management decision was due May 1, 2017.

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Browse other Single Audit organizations in Minnesota

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and filing records.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.