EIN: 516000297
UEI: T72NHKM259N3
Data as of August 24, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on September 1, 2022. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by March 1, 2023 (1272 days ago).
What is a management decision? →Finding 2021-001: Reporting Federal Program COVID-19 Higher Education Emergency Relief Fund (ALN: 84.425) Federal Agency U.S. Department of Education Federal Award Year July 1, 2020 through June 30, 2021 Criteria or Requirement The objective of the Higher Education Emergency Relief Fund (HEERF) program is to use HEERF grant funds to ?prevent, prepare for, and respond to coronavirus? through grants to eligible institutions. There are three components to reporting for HEERF: (1) public reporting on the (a)(1) Student Aid Portion;(2) public reporting on the (a)(1) Institutional Portion, (a)(2) and (a)(3) programs, as applicable; and the (3) the annual report. Beginning on May 6, 2020, ED required institutions that received a HEERF 18004(a)(1) Student Aid Portion award to publicly post certain information on their website no later than 30 days after award, and update that information every 45 days thereafter (by posting a new report). This was announced through an electronic announcement (EA). On August 31, 2020, ED revised the EA by decreasing the frequency of reporting after the initial 30-day period from every 45 days thereafter to every calendar quarter. Grantees posting a 45-day report on or after August 31, 2020, should instead post a report every calendar quarter, with the first calendar quarter report due by October 10, 2020, and covering the period from after their last 45-day or 30-day report through the end of the calendar quarter on September 30, 2020. Sections 18004(a)(1) Institutional Portion, (a)(2), and (a)(3) Quarterly Public Reporting must be conspicuously posted on the institution?s primary website on the same page the reports of the Institution of Higher Education (IHE)?s activities as to the emergency financial aid grants to students made with funds from the IHE?s allocation under Section 18004(a)(1) of the CARES Act (Student Aid Portion) are posted. A new, separate form must be posted covering each quarterly reporting period (September 30, December 31, March 31, June 30), concluding after either (1) posting the quarterly report ending September 30, 2022, or (2) when an institution has expended and liquidated all (a)(1) Institutional Portion, (a)(2), and (a)(3) funds and checks the ?final report? box. IHEs must post this quarterly report form no later than 10 days after the end of each calendar quarter (October 10, January 10, April 10, July 10) apart from the first report, which is due October 30, 2020. Condition Found, Including Perspective In the review of the quarterly reporting requirement for the institutional portion, we noted the University did not post their quarterly reports for March 31, 2021 and June 30, 2021 within the 10 day after each quarter end requirement. These reports were posted on October 10, 2021. In the review of the quarterly reporting requirement for the student portion, we noted the University did not modify its student portion reporting to the quarterly requirement, but rather the University provided updates every 45 days from the date of the first student award made. Possible Cause and Effect Management?s review control over its reporting requirements for HEERF institutional and student was not operating effectively to ensure compliance with the requirements. While management?s reporting in connection with the institutional portion was accurate, it was not posted timely. While management?s reporting in connection with the student portion was more frequent than required, it was not in accordance with quarterly requirement. Questioned Costs None identified. Statistical Validity The sample was not intended to be, and was not, a statistically valid sample. Repeat Finding in the Prior Year No. Recommendation Given the nature of the pandemic funding, and the evolving guidance of the compliance requirements, we recommend management enhance its process level controls over reporting requirements for HEERF to ensure timely and accurate reporting in accordance with the stated reporting requirements. View of Responsible Officials The University agrees with the finding. The HEERF reporting guidelines were in flux throughout the 2021 fiscal year. Final changes required schools to change student reporting from the 15/30 day requirement to quarterly reporting. The University continued to report on a more frequent basis for the student reporting. The University will create and post the quarterly student reports. The institutional reporting has been posted. Controls over reporting requirements will be enhanced.
Show full finding ▾Hide full finding ▴Finding 2021-001: Reporting Federal Program COVID-19 Higher Education Emergency Relief Fund (ALN: 84.425) Federal Agency U.S. Department of Education Federal Award Year July 1, 2020 through June 30, 2021 Criteria or Requirement The objective of the Higher Education Emergency Relief Fund (HEERF) program is to use HEERF grant funds to ?prevent, prepare for, and respond to coronavirus? through grants to eligible institutions. There are three components to reporting for HEERF: (1) public reporting on the (a)(1) Student Aid Portion;(2) public reporting on the (a)(1) Institutional Portion, (a)(2) and (a)(3) programs, as applicable; and the (3) the annual report. Beginning on May 6, 2020, ED required institutions that received a HEERF 18004(a)(1) Student Aid Portion award to publicly post certain information on their website no later than 30 days after award, and update that information every 45 days thereafter (by posting a new report). This was announced through an electronic announcement (EA). On August 31, 2020, ED revised the EA by decreasing the frequency of reporting after the initial 30-day period from every 45 days thereafter to every calendar quarter. Grantees posting a 45-day report on or after August 31, 2020, should instead post a report every calendar quarter, with the first calendar quarter report due by October 10, 2020, and covering the period from after their last 45-day or 30-day report through the end of the calendar quarter on September 30, 2020. Sections 18004(a)(1) Institutional Portion, (a)(2), and (a)(3) Quarterly Public Reporting must be conspicuously posted on the institution?s primary website on the same page the reports of the Institution of Higher Education (IHE)?s activities as to the emergency financial aid grants to students made with funds from the IHE?s allocation under Section 18004(a)(1) of the CARES Act (Student Aid Portion) are posted. A new, separate form must be posted covering each quarterly reporting period (September 30, December 31, March 31, June 30), concluding after either (1) posting the quarterly report ending September 30, 2022, or (2) when an institution has expended and liquidated all (a)(1) Institutional Portion, (a)(2), and (a)(3) funds and checks the ?final report? box. IHEs must post this quarterly report form no later than 10 days after the end of each calendar quarter (October 10, January 10, April 10, July 10) apart from the first report, which is due October 30, 2020. Condition Found, Including Perspective In the review of the quarterly reporting requirement for the institutional portion, we noted the University did not post their quarterly reports for March 31, 2021 and June 30, 2021 within the 10 day after each quarter end requirement. These reports were posted on October 10, 2021. In the review of the quarterly reporting requirement for the student portion, we noted the University did not modify its student portion reporting to the quarterly requirement, but rather the University provided updates every 45 days from the date of the first student award made. Possible Cause and Effect Management?s review control over its reporting requirements for HEERF institutional and student was not operating effectively to ensure compliance with the requirements. While management?s reporting in connection with the institutional portion was accurate, it was not posted timely. While management?s reporting in connection with the student portion was more frequent than required, it was not in accordance with quarterly requirement. Questioned Costs None identified. Statistical Validity The sample was not intended to be, and was not, a statistically valid sample. Repeat Finding in the Prior Year No. Recommendation Given the nature of the pandemic funding, and the evolving guidance of the compliance requirements, we recommend management enhance its process level controls over reporting requirements for HEERF to ensure timely and accurate reporting in accordance with the stated reporting requirements. View of Responsible Officials The University agrees with the finding. The HEERF reporting guidelines were in flux throughout the 2021 fiscal year. Final changes required schools to change student reporting from the 15/30 day requirement to quarterly reporting. The University continued to report on a more frequent basis for the student reporting. The University will create and post the quarterly student reports. The institutional reporting has been posted. Controls over reporting requirements will be enhanced.
Finding 2021-001: HEERF Reporting Condition Found: In the review of the quarterly reporting requirement for the institutional portion, the auditors noted the University did not post their quarterly reports for March 31, 2021 and June 30, 2021 within the 10-day requirement after each quarter end. These reports were posted on October 10, 2021. In the review of the quarterly reporting requirement for the student portion, the auditors noted the University did not modify its student portion reporting to the quarterly requirement, but rather provided updates every 45 days from the date the first student award was made. Recommendation: Given the nature of the pandemic funding, and the evolving guidance of the compliance requirements, the auditors recommended management enhance its process level controls over reporting requirements for HEERF to ensure timely and accurate reporting in accordance with the stated reporting requirements. University of Delaware Corrective Action Plan: The University of Delaware (UD or the University) agrees that the evolving guidance created challenges in maintaining compliance. Controls over reporting requirements are expected to function effectively now that the reporting requirements are finalized. The HEERF reporting guidelines were in flux throughout the 2021 fiscal year. Final changes required schools to change student reporting from the 15/30-day requirement to quarterly reporting. UD continued to report on a more frequent basis for the student reporting. Having conferred with the Department of Education contact, UD is required to go back and add the quarterly reports. The institutional reporting always required a quarterly reporting cycle even if no transactions occurred. During staff transition, two reporting quarters were missed. This oversight was identified by the University in October 2021 and corrective action was taken at that time to update the reporting. Responsible parties have been identified to ensure reports are submitted on time. Anticipated Completion Date: HEERF Student Reporting: August 2022 HEERF Institutional Reporting: Completed October 2021 Contact Person: Mary Booker, Executive Director, Student Financial Services
Finding 2021-002: Gramm-Leach-Bliley Act ? Student Information Security Federal Program Student Financial Assistance Cluster (ALN: 93.364, 84.268, 84.063, 84.038, 84.033, 84.007) Federal Agency U.S. Department of Education Federal Award Year July 1, 2020, through June 30, 2021 Criteria or Requirement The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as `financial institutions? and subject to the Gramm-Leach-Bliley Act because they appear to be significantly engaged in wiring funds to consumers (16 CFR 313.3(k)(2)(vi)). Under an institution?s Program Participation Agreement with ED and the Gramm-Leach-Bliley Act, institutions must protect student financial aid information, with particular attention to information provided to institutions by ED or otherwise obtained in support of the administration of the federal student financial aid programs. (16 CFR 314.3; HEA 483(a)(3)(E) and HEA 485B(d)(2)) ED provides additional information about cybersecurity requirements at https://ifap.ed.gov/fsa-cybersecurity-compliance. Among the requirements, institutions must: (a) designate an individual to coordinate the information security program; (b) perform a risk assessment that addresses the three required areas noted in 16 CFR 314.4(b), which are (1) employee training and management; (2) information systems, including network and software design as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions or other systems failures; and (c) document a safeguard for each risk identified. Condition Found, Including Perspective In the review of GLBA compliance requirements, we noted the University had performed a formal risk assessment in 2017, however, has not updated the risk assessment annually in accordance with 16 CFR 314.4(b), nor has it updated its safeguard response. Possible Cause and Effect Management?s control over its compliance with GLBA risk assessment and responses was not operating effectively to ensure compliance with the requirements. Therefore, changes to the operating environment that could impact information technology risks may not have been identified and/or safeguard responses may not have been put into place or are not operating effectively. Questioned Costs None identified. Statistical Validity The sample was not intended to be, and was not, a statistically valid sample. Repeat Finding in the Prior Year No. Recommendation Given the nature of the finding, and the evolving information security environments and compliance requirements, we recommend management enhance its controls over GLBA risk assessment, which should include an annual review of risks and responses that is reviewed by senior management and discussed with the appropriate board committee. View of Responsible Officials The University agrees with the finding. The University is engaging an independent qualified consultant to conduct the risk assessment and to prepare the risk management plan for GLBA related data, including responses to risks identified. Controls over the annual risk assessment will be enhanced.
Show full finding ▾Hide full finding ▴Finding 2021-002: Gramm-Leach-Bliley Act ? Student Information Security Federal Program Student Financial Assistance Cluster (ALN: 93.364, 84.268, 84.063, 84.038, 84.033, 84.007) Federal Agency U.S. Department of Education Federal Award Year July 1, 2020, through June 30, 2021 Criteria or Requirement The Gramm-Leach-Bliley Act (Pub. L. No. 106-102) (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as `financial institutions? and subject to the Gramm-Leach-Bliley Act because they appear to be significantly engaged in wiring funds to consumers (16 CFR 313.3(k)(2)(vi)). Under an institution?s Program Participation Agreement with ED and the Gramm-Leach-Bliley Act, institutions must protect student financial aid information, with particular attention to information provided to institutions by ED or otherwise obtained in support of the administration of the federal student financial aid programs. (16 CFR 314.3; HEA 483(a)(3)(E) and HEA 485B(d)(2)) ED provides additional information about cybersecurity requirements at https://ifap.ed.gov/fsa-cybersecurity-compliance. Among the requirements, institutions must: (a) designate an individual to coordinate the information security program; (b) perform a risk assessment that addresses the three required areas noted in 16 CFR 314.4(b), which are (1) employee training and management; (2) information systems, including network and software design as well as information processing, storage, transmission and disposal; and (3) detecting, preventing and responding to attacks, intrusions or other systems failures; and (c) document a safeguard for each risk identified. Condition Found, Including Perspective In the review of GLBA compliance requirements, we noted the University had performed a formal risk assessment in 2017, however, has not updated the risk assessment annually in accordance with 16 CFR 314.4(b), nor has it updated its safeguard response. Possible Cause and Effect Management?s control over its compliance with GLBA risk assessment and responses was not operating effectively to ensure compliance with the requirements. Therefore, changes to the operating environment that could impact information technology risks may not have been identified and/or safeguard responses may not have been put into place or are not operating effectively. Questioned Costs None identified. Statistical Validity The sample was not intended to be, and was not, a statistically valid sample. Repeat Finding in the Prior Year No. Recommendation Given the nature of the finding, and the evolving information security environments and compliance requirements, we recommend management enhance its controls over GLBA risk assessment, which should include an annual review of risks and responses that is reviewed by senior management and discussed with the appropriate board committee. View of Responsible Officials The University agrees with the finding. The University is engaging an independent qualified consultant to conduct the risk assessment and to prepare the risk management plan for GLBA related data, including responses to risks identified. Controls over the annual risk assessment will be enhanced.
Finding 2021-002: Gramm-Leach-Bliley Act ? Student Information Security Condition Found: In the review of GLBA compliance requirements, the auditors? noted the University had performed a risk assessment in 2017; however, it has not updated the risk assessment annually in accordance with 16 CFR 314.4(b), nor has it updated its safeguard response. Recommendation: Given the nature of the finding, and the evolving information security environments and compliance requirements, we recommend management enhance its controls over the GLBA risk assessment, which should include an annual review of risks and responses that is reviewed by senior management and discussed with the appropriate board committee. University of Delaware Corrective Action Plan: The University agrees that it should conduct a risk assessment for GLBA related data and review outcomes with senior management and the appropriate board committee. The University is engaging an independent qualified consultant to conduct the risk assessment and to prepare the risk management plan for GLBA related data, including responses to risks identified. The University has strengthened its controls by designating the Chief Information Security Officer (CISO) as the qualified individual to oversee and implement the information security program for GLBA. The CISO, with cooperation from senior management of the designated GLBA components, will annually (i) review the identified risks and the management plan; and (ii) in conjunction with the Chief Privacy Officer, report to the board of trustees and senior management regarding compliance with GLBA security requirements. Anticipated Completion Date: Risk assessment and risk management plan: December 2022 Contact Person: Andy Weisskopf, Chief Information Security Officer, IT-Information Security Patricia Shea, Associate General Counsel and Chief Privacy Officer
FAC accepted this audit on March 24, 2019 — management decision was due September 24, 2019.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴FAC accepted this audit on February 25, 2018 — management decision was due August 25, 2018.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.