COVENANT COLLEGE, INC. AND SUPPORTING FOUNDATION

EIN: 430719506

UEI: L5MMBAMNPNS7

Data as of August 26, 2026

COVENANT COLLEGE, INC. AND SUPPORTING FOUNDATION10 audit years2 findings
10
Audit Years
2
Total Findings
0
Repeat Findings

FY 2023-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on October 24, 2023. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by April 24, 2024 (855 days ago).

What is a management decision? →
2023-001
Special Tests & Provisions

The College did not sufficiently comply with the updated requirements of GLBA. Criteria: 16 CFR 314.4 Questioned Costs: $0 Context: The College has not: • Implemented multi-factor authentication on systems containing personally identifiable information (PII) • Implemented continuous monitoring, such as penetration testing and vulnerability scanning • Implemented sufficient vendor management policies and reviews • Provided a written, annual report to the board Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA. Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks. Identification as repeat finding, if applicable: Not applicable. Recommendation: We recommend the College allocate sufficient resources to address all requirements of GLBA. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.

Show full finding ▾
Full finding narrative

Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency DEPARTMENT OF EDUCATION ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, and 84.379 Federal Award Identification #: 2022-2023 Financial Aid Year Condition: The College did not sufficiently comply with the updated requirements of GLBA. Criteria: 16 CFR 314.4 Questioned Costs: $0 Context: The College has not: • Implemented multi-factor authentication on systems containing personally identifiable information (PII) • Implemented continuous monitoring, such as penetration testing and vulnerability scanning • Implemented sufficient vendor management policies and reviews • Provided a written, annual report to the board Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA. Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks. Identification as repeat finding, if applicable: Not applicable. Recommendation: We recommend the College allocate sufficient resources to address all requirements of GLBA. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.

Corrective Action Plan

Gramm-Leach-Bliley Act (GLBA) Compliance Planned Corrective Action: 1) Written Annual report to the Board of Directors on the overall status of ISP and GLBA compliance does not address risk management and control decisions, results of testing, security events or violations and management's response to each, and recommendations for changes in the Program. A report was submitted to the Board of Trustees in September 2023 for their review at the October meeting on campus. The Board will meet on campus again in March 2024 should any additional information or changes be needed. 2) MFA is not enabled for Banner by Ellucian and National Student Clearinghouse - § 314.4(c)(5) of the GLBA. This is in progress. Technical specifications for MFA in Banner have been reviewed. Testing of three possible options should be started in October 2023. Our Registrar has contacted the NSC and requested MFA on our accounts. 3) No annual penetration testing of information systems. This is in progress. As of September 2023 five vendors were being reviewed and evaluated for this engagement. 4) Vendors are only evaluated at contract initiation. This is in progress. Review of templates and approval needed has already started. Person Responsible for Corrective Action Plan: Dr. H. Collin Messer, Vice President for Academic Affairs Anticipated Date of Completion: May 1, 2024

About Special Tests and Provisions →

FY 2021-06-30

FAC accepted this audit on October 18, 2021 — management decision was due April 18, 2022.

2021-001
Reporting

The Organization did not post the required Education Stabilization Fund Higher Education Emergency Relief Fund (HEERF) reports to their website as required for the Coronavirus Response and Relief Supplemental Appropriations Act (CRRSAA) institutional and student portions expended. Criteria: 86 FR 26213 The Organization was required to post the Institutional Quarterly Report to their website within 10 days of the end of the quarter in which the funds were spent. Additionally, for each student grant disbursement made, the Organization is required to report quarterly to their website a summary of how the funds were allocated and disbursed. Questioned Costs: None. Context: During the audit, it was noted that while the Organization had appropriately disclosed the required CARES Act reporting for HEERF funds, neither the CRRSAA Institutional Quarterly report or the student emergency grant disbursement report for the quarter ending June 30, 2021, were completed and disclosed on their website. The Organization corrected immediately, and reports were posted to the website before the audit was finalized. Cause: There was a transition in key management positions during the year that led to a gap in understanding of the requirements of the HEERF reporting. Effect: The Organization was not in compliance with the reporting requirements of HEERF. Identification as repeat finding, if applicable: Not applicable. Recommendation: We recommend that before any additional funds are spent, that the Organization appoints a group of individuals to review the requirements for HEERF to ensure future compliance is maintained. Additionally, we recommend that the Organization utilize these individuals to stay informed of any new requirements as they are released going forward. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.

Show full finding ▾
Full finding narrative

2021-001 Higher Education Stabilization Fund Reporting Other Matter DEPARTMENT OF EDUCATION CFDA #: 84.425E and 84.425F Federal Award Identification #: P425E201437 and P425F200003 Condition: The Organization did not post the required Education Stabilization Fund Higher Education Emergency Relief Fund (HEERF) reports to their website as required for the Coronavirus Response and Relief Supplemental Appropriations Act (CRRSAA) institutional and student portions expended. Criteria: 86 FR 26213 The Organization was required to post the Institutional Quarterly Report to their website within 10 days of the end of the quarter in which the funds were spent. Additionally, for each student grant disbursement made, the Organization is required to report quarterly to their website a summary of how the funds were allocated and disbursed. Questioned Costs: None. Context: During the audit, it was noted that while the Organization had appropriately disclosed the required CARES Act reporting for HEERF funds, neither the CRRSAA Institutional Quarterly report or the student emergency grant disbursement report for the quarter ending June 30, 2021, were completed and disclosed on their website. The Organization corrected immediately, and reports were posted to the website before the audit was finalized. Cause: There was a transition in key management positions during the year that led to a gap in understanding of the requirements of the HEERF reporting. Effect: The Organization was not in compliance with the reporting requirements of HEERF. Identification as repeat finding, if applicable: Not applicable. Recommendation: We recommend that before any additional funds are spent, that the Organization appoints a group of individuals to review the requirements for HEERF to ensure future compliance is maintained. Additionally, we recommend that the Organization utilize these individuals to stay informed of any new requirements as they are released going forward. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.

Corrective Action Plan

Covenant College Auditee Corrective Action Plan October 13, 2021 Finding Number: 2021-001 Planned Corrective Action: We received notice of our reporting discrepancy from Capin Crouse. To conect this, Matthew Bazzel completed the report which was posted to the Covenant College website on September 29, 2021. Moving fo1ward we have created an official HEERF team comprised of Matthew Bazzel (Director of Financial Aid), Fred Verwoerd (VP for Finance), Brad Tomas (Assistant VP for Enrollment Management), and Jennifer Black-Patel (Controller) to ensure appropriate and compliant actions are taken on all HEERF expectations and guidance. Matthew will be the point person for this team. He will be responsible for alerting the other team members of new guidance, deadlines, and rep01ting expectations . To ensure compliance, Matthew has subscribed to all FSA, NASFAA, and various other resources detailing the HEERF guidance. This information will come directly to Matthew which he can then act on appropriately. Person Responsible for Corrective Action Plan: Matthew Bazzel Director of Financial Aid Covenant College Anticipated Date of Completion: We corrected the reporting on the Covenant website o September 29, 2021, and have updated the roles of the staff for HEERF allocation, repo1ting, and guidance review on October 13, 2021.

About Reporting →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and compliance status.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.