← Back to home

Bethany Lutheran College, Inc.Higher Education

EIN: 410747065

UEI: M9RHPYRK2YF9

Audited by: Baker Tilly US, LLP

Oversight agency: 84 [Department of Education]

View federal awards & risk assessment →

Data as of August 28, 2026

Bethany Lutheran College, Inc.3 audit years7 findings3 repeat
3
Audit Years
7
Total Findings
3
Repeat Findings
$4.2M
Federal Awards Expended (FY 2025)

FY 2025-06-30

$4,159,128 federal awards expended

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on December 19, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by June 19, 2026 (72 days ago).

What is a management decision? →
2025-003
Special Tests & Provisions
SIGNIFICANT DEFICIENCYREPEAT OF 2024-003OTHER MATTERS

Finding 2025-003: Significant Deficiency – GLBA Security Policy Repeat Finding 2024-003 Federal Program – Student Financial Assistance Cluster Federal Agency – U.S. Department of Education Pass-Through Entity – Not Applicable Assistance Listing Number – Various Federal Award Year – June 30, 2025 Criteria: The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their informationsharing practices to their customers and to safeguard sensitive data (16 CFR 314). institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The regulations require the written information security program to include nine elements for institutions with 5,000 or more customers, (16 CFR 314.3(a)). The written information security program (WISP) for institutions with few that 5,000 customers must address seven elements (16 CFR 314.3(a) and 16 CFR 314.6). The elements that an institution must address in its written information security program are at 16 CFR 314.4. At a minimum, the institution's written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8) including: assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16CFR 314.4(d)). Condition/Context: Under the Corporation's Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S Department of Education or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned Costs: Not applicable. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The Corporation's students' personal information could be vulnerable. Recommendation: We recommend the Corporation review each element of GLBA to ensure compliance with all necessary requirements. Management's Response: To ensure continued compliance with GLBA requirements, the Corporation engaged FRSecure to perform a comprehensive risk assessment and develop a security roadmap. As part of their work, FRSecure conducted system scans to identify potential vulnerabilities and interviewed key personnel across IT, HR, Finance and other departments to evaluate the current state of the Corporation’s information security system. GLBA compliance was included in the scope of their review. FRSecure issued a “Roadmap Plan,” which the department is reviewing and will implement as feasible.

Show full finding ▾
Full finding narrative

Finding 2025-003: Significant Deficiency – GLBA Security Policy Repeat Finding 2024-003 Federal Program – Student Financial Assistance Cluster Federal Agency – U.S. Department of Education Pass-Through Entity – Not Applicable Assistance Listing Number – Various Federal Award Year – June 30, 2025 Criteria: The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their informationsharing practices to their customers and to safeguard sensitive data (16 CFR 314). institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The regulations require the written information security program to include nine elements for institutions with 5,000 or more customers, (16 CFR 314.3(a)). The written information security program (WISP) for institutions with few that 5,000 customers must address seven elements (16 CFR 314.3(a) and 16 CFR 314.6). The elements that an institution must address in its written information security program are at 16 CFR 314.4. At a minimum, the institution's written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8) including: assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16CFR 314.4(d)). Condition/Context: Under the Corporation's Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the U.S Department of Education or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned Costs: Not applicable. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The Corporation's students' personal information could be vulnerable. Recommendation: We recommend the Corporation review each element of GLBA to ensure compliance with all necessary requirements. Management's Response: To ensure continued compliance with GLBA requirements, the Corporation engaged FRSecure to perform a comprehensive risk assessment and develop a security roadmap. As part of their work, FRSecure conducted system scans to identify potential vulnerabilities and interviewed key personnel across IT, HR, Finance and other departments to evaluate the current state of the Corporation’s information security system. GLBA compliance was included in the scope of their review. FRSecure issued a “Roadmap Plan,” which the department is reviewing and will implement as feasible.

Corrective Action Plan

Finding 2025-003: GLBA Repeat Finding 2024-003 Federal Program - Student Financial Assistance Cluster Federal Agency- U.S. Department of Education Pass-Through Entity- Not Applicable Assistance Listing Number - 84.007 - Federal Supplemental Education Opportunity Grants 84.033 - Federal Work-Study Program 84.038 - Federal Perkins Loan Program 84.063 - Federal Pell Grant Program 84.268 - Federal Direct Student Loans Criteria: The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their informationsharing practices to their customers and to safeguard sensitive data (16 CFR 314). institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The regulations require the written information security program to include nine elements for institutions with 5,000 or more customers, (16 CFR 314.3(a)). The written information security program (WISP) for institutions with few that 5,000 customers must address seven elements (16 CFR 314.3(a) and 16 CFR 314.6). The elements that an institution must address in its written information security program are at 16 CFR 314.4. At a minimum, the institution's written information security program must address the implementation ofthe minimum safeguards identified in 16 CFR 314.4(c)(l) through (8) including: assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16CFR 314.4(d)). Condition/Context: Under a college's Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned Costs: Not applicable. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The Corporation's students' personal information could be vulnerable. Recommendation: We recommend the Corporation review each element of GLBA to ensure compliance with all necessary requirements. Corrective Action Plan: Corrective Action Planned: To ensure continued GLBA compliance the Corporation contracted with FRSecure to develop a risk assessment and roadmap which did a system scan for issues, an assessor interviewed staff including IT, HR, Finance Leaders and others to learn more about the current state of overall security program. Compliance with GLBA was part of their review. FRSecure issued an assessment 'Roadmap Plan' for the department to review and the Corporation will implement the results as feasible. Name of the contact person responsible for corrective action: John Sehloff, Director of Information Technology Anticipated Completion Date: June 30, 2026

Prior Finding References

2024-003

About Special Tests and Provisions →

FY 2024-06-30

$4,047,208 federal awards expended

FAC accepted this audit on March 31, 2025 — management decision was due October 1, 2025.

2024-002
Special Tests & Provisions
SIGNIFICANT DEFICIENCYREPEAT OF 2023-002OTHER MATTERS

During our testing, we noted 2 of the 40 students tested, the students’ program begin date per the institution's records did not match what was reported to NSLDS. Questioned Costs: None Context: During our testing, it was noted the Corporation does not have a process in place to ensure the accuracy of NSLDS reporting, specifically as it relates to the program begin date per the Program-Level Records. Cause: The Corporation’s processes and controls did not ensure that students’ program begin dates were accurately reported to NSLDS. Effect: The Corporation did not comply with Department of Education (ED) regulations. Repeat Finding: Yes Auditors’ Recommendation We recommend the Corporation review its reporting procedures to ensure that student information is reported accurately and timely to NSLDS as required by regulations. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Show full finding ▾
Full finding narrative

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 – Federal Supplemental Educational Opportunity Grants 84.033 – Federal Work-Study Program 84.038 – Federal Perkins Loan Program 84.063 – Federal Pell Grant Program 84.268 – Federal Direct Student Loans Award Period: July 1, 2023 to June 30, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or Specific Requirement: The Code of Federal Regulations, 34 CFR 685.309 requires that enrollment status changes for students be reported to NSLDS within 30 days or within 60 days if the student with the status change will be reported on a scheduled transmission within 60 days of the change in status. Regulations require the status include an accurate effective date. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that do not pass the NSLDS enrollment reporting edits. Condition: During our testing, we noted 2 of the 40 students tested, the students’ program begin date per the institution's records did not match what was reported to NSLDS. Questioned Costs: None Context: During our testing, it was noted the Corporation does not have a process in place to ensure the accuracy of NSLDS reporting, specifically as it relates to the program begin date per the Program-Level Records. Cause: The Corporation’s processes and controls did not ensure that students’ program begin dates were accurately reported to NSLDS. Effect: The Corporation did not comply with Department of Education (ED) regulations. Repeat Finding: Yes Auditors’ Recommendation We recommend the Corporation review its reporting procedures to ensure that student information is reported accurately and timely to NSLDS as required by regulations. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Corrective Action Plan

Title: Student Financial Assistance Cluster – Assistance Listing Nos. 84.038, 84.268, 84.033, 84.007, 84.063 Recommendation: We recommend the Corporation review its reporting procedures to ensure that students’ statuses are accurately and timely reported to NSLDS as required by regulations. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: While this is classified as a repeat finding as it involves enrollment reporting, it is a different type of issue than prior year, which involved withdrawal date reporting. The College will implement a process to ensure that the beginning term date matches the enrollment record. The College will make sure that the campus enrollment date will not be affected by change of major date going forward and will make sure that correct dates are coming across and being correctly populated from the Admissions Department. Name of the contact person responsible for corrective action: Jeff Younge, Director of Financial Aid Planned completion date for corrective action plan: Fiscal Year 2025

Prior Finding References

2023-002

About Special Tests and Provisions →
2024-003
Special Tests & Provisions
SIGNIFICANT DEFICIENCYREPEAT OF 2023-005OTHER MATTERS

Under a college’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned Costs: None Context: During our audit procedures, it was noted that the Corporation did not have documented in its Written Information Security Program a description of the use of a data inventory that includes how is the Corporation identifies and manages data, personnel, devices, systems and facilities. In addition, there was no evidence that a multi-factor authentication process was used for individuals accessing sensitive information across systems. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The Corporation’s students’ personal information could be vulnerable. Repeat Finding: Yes Auditor’s Recommendation: We recommend that the Corporation review each element of GLBA to ensure compliance with all necessary requirements. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Show full finding ▾
Full finding narrative

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 – Federal Supplemental Educational Opportunity Grants 84.033 – Federal Work-Study Program 84.038 – Federal Perkins Loan Program 84.063 – Federal Pell Grant Program 84.268 – Federal Direct Student Loans Award Period: July 1, 2023 to June 30, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or Specific Requirement: The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). Institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The regulations require the written information security program to include nine elements for institutions with 5,000 or more customers, (16 CFR 314.3(a)). The written information security program (WISP) for institutions with fewer than 5,000 customers must address seven elements (16 CFR 314.3(a) and 16 CFR 314.6). The elements that an institution must address in its written information security program are at 16 CFR 314.4. At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8) including: Assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). Condition: Under a college’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned Costs: None Context: During our audit procedures, it was noted that the Corporation did not have documented in its Written Information Security Program a description of the use of a data inventory that includes how is the Corporation identifies and manages data, personnel, devices, systems and facilities. In addition, there was no evidence that a multi-factor authentication process was used for individuals accessing sensitive information across systems. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The Corporation’s students’ personal information could be vulnerable. Repeat Finding: Yes Auditor’s Recommendation: We recommend that the Corporation review each element of GLBA to ensure compliance with all necessary requirements. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Corrective Action Plan

Title: Student Financial Assistance Cluster – Assistance Listing Nos. 84.038, 84.268, 84.033, 84.007, 84.063 Recommendation: We recommend that the Corporation review each element of GLBA to ensure compliance with all necessary requirements. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The College will update its Written Information Security Program to include a description of the use of a data inventory that includes how we identify and manage data, personnel, devices and facilities. Some of these items can be found in the other documents submitted but we will merge them into our WISP. Multi-factor authentication is in use for individuals accessing sensitive information but that also was not clearly identified in the WISP and will be added. To ensure GLBA compliance going forward, the College has contracted FRSecure to develop a risk assessment and roadmap which will do system scan for issues, an assessor will interview staff including IT, HR, Finance Leaders and others to learn more about the currentstate of overall security program. Compliance with GLBA will be part of their review. Finally,FRSecure will issue an assessment ‘Roadmap Plan’ for the department to review andpending results, implement as feasible.

Prior Finding References

2023-005

About Special Tests and Provisions →

FY 2023-06-30

LOW-RISK AUDITEE$3,545,432 federal awards expended

FAC accepted this audit on April 1, 2024 — management decision was due October 1, 2024.

2023-002
Reporting
SIGNIFICANT DEFICIENCYOTHER MATTERS

During our testing, we noted 2 out of the 9 students tested where the student was not reported in a timely manner after the school determined the students change in status. Questioned Costs: N/A Context: Updates to NSLDS were not completed in a timely manner. Cause: The College did not have a process in place to ensure the student who graduated or withdrew were reported timely. Effect: The College did not comply with Department of Education (ED) regulations by reporting student enrollment status changes timely. Repeat Finding: No Auditors’ Recommendation We recommend the College review its reporting procedures to ensure that students’ statuses are accurately and timely reported to NSLDS as required by regulations. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Show full finding ▾
Full finding narrative

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 – Federal Supplemental Educational Opportunity Grants 84.033 – Federal Work-Study Program 84.038 – Federal Perkins Loan Program 84.063 – Federal Pell Grant Program 84.268 – Federal Direct Student Loans Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or Specific Requirement: The Code of Federal Regulations, 34 CFR 685.309 requires that enrollment status changes for students be reported to NSLDS within 30 days or within 60 days if the student with the status change will be reported on a scheduled transmission within 60 days of the change in status. Regulations require the status include an accurate effective date. In addition, regulations require that an institution make necessary corrections and return the records within 10 days for any roster files that don’t pass the NSLDS enrollment reporting edits. Condition: During our testing, we noted 2 out of the 9 students tested where the student was not reported in a timely manner after the school determined the students change in status. Questioned Costs: N/A Context: Updates to NSLDS were not completed in a timely manner. Cause: The College did not have a process in place to ensure the student who graduated or withdrew were reported timely. Effect: The College did not comply with Department of Education (ED) regulations by reporting student enrollment status changes timely. Repeat Finding: No Auditors’ Recommendation We recommend the College review its reporting procedures to ensure that students’ statuses are accurately and timely reported to NSLDS as required by regulations. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Corrective Action Plan

Title: Student Financial Assistance Cluster – Assistance Listing Nos. 84.038, 84.268, 84.033, 84.007, 84.063 Recommendation: We recommend the College review its reporting procedures to ensure that students’ statuses are accurately and timely reported to NSLDS as required by regulations. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: Issue: Taylor Theiste began official withdrawal process on 1/31/23. This date was used in Return of Title IV calculations, and entered into PowerFAIDS system. Student was asked to unenroll from the courses by the Registrar, which she did, but not until 2 days later. Resolution: Jeff Younge (Director of Financial Aid) met with Sergio Salgado (Registrar) and Lisa Shubert (Manager of Administrative Computing and Institutional Reporting) on 11/29/23. Going forward, when student indicates intent to withdraw, Registrar will unenroll the student from courses using the withdrawal date used for Title IV purposes. This will ensure that the correct date is reported to Clearinghouse, and then to NSLDS. Issue: Ben Draper began official withdrawal process on 1/20/23. Since this was the 10th day of class, he was not included in the Census Report that was run at the end of the day (although correct date was used for Return of Title IV calculations, and transcript shows Ws). Consequently, he was treated for reporting purposes as if he did not return for spring semester, and withdrawal date sent to Clearinghouse, and then on to NSLDS, reverted to last day of the previous fall semester, which was 12/15/22. Resolution: On December 20, 2023, meeting was held in Luther Hall that included the following: (Stacey Dawley, Jeff Lemke, Jason Lowrey, Ted Manthe, Daniel Mundahl, Sergio Salgado, Lisa Shubert, Renee Tatge, Estelle Vlieger, Jeff Younge) Proposal was made (and accepted by this group, and later the President) that stated the following: 1. Add/Drop period is day 1-5 of fall and spring semester. During this time, classes can be added, and dropped courses disappear from student schedule/transcript, as if student did not begin the class. Courses withdrawn from after 5th day result in a grade on the transcript (W, WP/WF, or F, depending on the timing of the withdrawal). This is the current policy, not a proposed change. 2. Change wording of refund policy, so that instead of Week 1, Week 2, Week 3...it is worded as Day 1-5, Day 6-10, Day 11-15... (This solves the issue of 1st week being only 4 days in the fall, but 5 days in the spring, and the day after Labor Day being the 10th day of class, but 3rd week of the semester). 3. Change Census report figures from being (10th day) to (end of 5th day). That does not mean census report is available on the 5th day, but just that the information is “locked” as of that day for reporting purposes. Name of the contact person responsible for corrective action: Jeff Younge, Director of Financial Aid Planned completion date for corrective action plan: 3/26/2024

About Reporting →
2023-003
Eligibility
SIGNIFICANT DEFICIENCYQUESTIONED COSTSOTHER MATTERS

During our testing, we noted for 2 out of 40 students tested, there was an under award of need-based aid in the amount of $2,062 as total aid paid was lower than it should have been relating to the student's total need in the 2022-23 academic year. Questioned Costs: $2,062 Context: Two students aid should have been repackaged after the College accepted their transfer credits, thus causing an under award in need-based aid. Cause: Management incorrectly awarded these students based on their transfer credits and financial need. Effect: The College is not in compliance with Department of Education requirements. Repeat Finding: No Auditor’s Recommendation: We recommend the College implements policies to review all student award packages at the start of the academic year to ensure no over awards exist. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Show full finding ▾
Full finding narrative

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 – Federal Supplemental Educational Opportunity Grants 84.033 – Federal Work-Study Program 84.038 – Federal Perkins Loan Program 84.063 – Federal Pell Grant Program 84.268 – Federal Direct Student Loans Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or Specific Requirement: Per the Code of Federal Regulations, 34 CFR 673.5, students may not be under awarded need-based aid in excess of their calculated need. In addition, 34 CFR 685.203(j) states that in no case may a loan amount exceed the student’s estimated cost of attendance for the period of enrollment for which the loan is intended less the student’s estimated financial assistance for that period and in the case of Direct Subsidized Loans, the borrower’s expected family contribution for that period. Condition: During our testing, we noted for 2 out of 40 students tested, there was an under award of need-based aid in the amount of $2,062 as total aid paid was lower than it should have been relating to the student's total need in the 2022-23 academic year. Questioned Costs: $2,062 Context: Two students aid should have been repackaged after the College accepted their transfer credits, thus causing an under award in need-based aid. Cause: Management incorrectly awarded these students based on their transfer credits and financial need. Effect: The College is not in compliance with Department of Education requirements. Repeat Finding: No Auditor’s Recommendation: We recommend the College implements policies to review all student award packages at the start of the academic year to ensure no over awards exist. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Corrective Action Plan

Title: Student Financial Assistance Cluster – Assistance Listing Nos. 84.038, 84.268, 84.033, 84.007, 84.063 Recommendation: We recommend the College implements policies to review all student award packages at the start of the academic year to ensure no over awards exist. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The Financial Aid Office looks for over award situations throughout the academic year, as changes to Cost of Attendance and financial aid (Scholarships/Grants, Loans, and Work- Study earnings) can change throughout the year. That said, Financial Aid Staff (Jeff Younge and/or Sally Sorensen) will review every student for potential over awards during the 1st two weeks of fall semester (beginning August 20, 2024), to catch any over awards that may have been created between the time of packaging, and beginning of the academic year. Name of the contact person responsible for corrective action: Jeff Younge, Director of Financial Aid Planned completion date for corrective action plan: 3/26/2024

About Eligibility →
2023-004
Special Tests & Provisions
SIGNIFICANT DEFICIENCYOTHER MATTERS

During testing we noted there is no formalized process of Federal Work Study, Supplemental Education Opportunity Grants, and Perkins reconciliations. Questioned Costs: None Context: During our testing, it was noted there is no formalized process of Federal Work Study, Supplemental Education Opportunity Grants, and Perkins reconciliations. Cause: Management could incorrectly have amounts of their Federal Work Study, Supplemental Education Opportunity Grants, and Perkins at year-end. Effect: The College is not in compliance with Department of Education requirements. Repeat Finding: No Auditor’s Recommendation: We recommend the College implements a formalized yearly reconciliation of Federal Work Study, Perkins, and Supplemental Education Opportunity Grants. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Show full finding ▾
Full finding narrative

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number 84.007 – Federal Supplemental Educational Opportunity Grants 84.033 – Federal Work-Study Program 84.038 – Federal Perkins Loan Program Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or Specific Requirement: No documentation of review as it relates to Federal Work Study, Perkins, and Supplemental Education Opportunity Grants. Condition: During testing we noted there is no formalized process of Federal Work Study, Supplemental Education Opportunity Grants, and Perkins reconciliations. Questioned Costs: None Context: During our testing, it was noted there is no formalized process of Federal Work Study, Supplemental Education Opportunity Grants, and Perkins reconciliations. Cause: Management could incorrectly have amounts of their Federal Work Study, Supplemental Education Opportunity Grants, and Perkins at year-end. Effect: The College is not in compliance with Department of Education requirements. Repeat Finding: No Auditor’s Recommendation: We recommend the College implements a formalized yearly reconciliation of Federal Work Study, Perkins, and Supplemental Education Opportunity Grants. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Corrective Action Plan

Title: Student Financial Assistance Cluster – Assistance Listing Nos. 84.038, 84.033, 84.007 Recommendation: We recommend the College implements a formalized yearly reconciliation of Federal Work Study, Perkins, and Supplemental Education Opportunity Grants. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: FWS: Jeff Younge, Director of Financial Aid, directs Business Office on when to pull funds. Reconciliation between financial aid system and payroll system is done annually, prior to end of fiscal year by Director of Financial Aid. Piece we will add is for Director of Financial Aid to verify amounts requested to be pulled actually got pulled by Business Office. This has not been a problem, but additional step will serve as an extra safeguard so that all stays in balance. Perkins: No new Perkins loans are being made. Annual FISAP serves as reconciliation for this program. SEOG: Jeff Younge, Director of Financial Aid, directs Business Office on when to pull funds at time of disbursement. Piece we will add is for Director of Financial Aid to verify amounts requested to be pulled actually got pulled by Business Office. This has not been a problem, but additional step will serve as an extra safeguard so that all stays in balance. Name of the contact person responsible for corrective action: Jeff Younge, Director of Financial Aid Planned completion date for corrective action plan: 3/26/2024

About Special Tests and Provisions →
2023-005
Special Tests & Provisions
SIGNIFICANT DEFICIENCYOTHER MATTERS

There are missing items from the Written Information Security Program. Questioned Costs: N/A Context: These new GLBA requirements were applicable beginning on June 9, 2023, and there are a few elements missing from the WISP. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The College’s students’ personal information could be vulnerable. Repeat Finding: No Auditor’s Recommendation: We recommend that the College review the updated GLBA requirements and ensure their WISP includes all required elements. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Show full finding ▾
Full finding narrative

Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Assistance Cluster Assistance Listing Number: 84.007 – Federal Supplemental Educational Opportunity Grants 84.033 – Federal Work-Study Program 84.038 – Federal Perkins Loan Program 84.063 – Federal Pell Grant Program 84.268 – Federal Direct Student Loans Award Period: July 1, 2022 to June 30, 2023 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or Specific Requirement: The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The first element that an institution’s written information security program must address is the designation of an individual with responsibility for implementing and enforcing an institution’s written information security program. The regulations refer to this individual as the Qualified Individual. If an institution has not designated a Qualified Individual, it is not in compliance with the GLBA requirements. The Qualified Individual has ultimate responsibility and accountability for implementing and enforcing the institution’s information security program (16 CFR 314.4(a)). The first element that an institution’s written information security program must address is the designation of an individual with responsibility for implementing and enforcing an institution’s written information security program. The regulations refer to this individual as the Qualified Individual. If an institution has not designated a Qualified Individual, it is not in compliance with the GLBA requirements. The Qualified Individual has ultimate responsibility and accountability for implementing and enforcing the institution’s information security program (16 CFR 314.4(a)). Provides for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). Provides for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted and Encrypt customer information on the institution’s system and when it’s in transit. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. Dispose of customer information securely. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. Criteria or Specific Requirement (Continued): Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). Provides for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). Addresses how the institution will oversee its information system service providers (16 CFR 314.4(f)). Provides for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Condition: There are missing items from the Written Information Security Program. Questioned Costs: N/A Context: These new GLBA requirements were applicable beginning on June 9, 2023, and there are a few elements missing from the WISP. Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance. Effect: The College’s students’ personal information could be vulnerable. Repeat Finding: No Auditor’s Recommendation: We recommend that the College review the updated GLBA requirements and ensure their WISP includes all required elements. Views of Responsible Officials and Planned Corrective Actions: There is no disagreement with the audit finding.

Corrective Action Plan

Title: Student Financial Assistance Cluster – Assistance Listing Nos. 84.038, 84.268, 84.033, 84.007, 84.063 Recommendation: We recommend that the College review the updated GLBA requirements and ensure their WISP includes all required elements. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The College will review the updated GLBA requirements to ensure Bethany is compliant with all the WISP required elements. Name of the contact person responsible for corrective action: John Sehloff, Director of Information Technology Planned completion date for corrective action plan: June 30, 2024

About Special Tests and Provisions →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and filing records.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.