Anne Arundel Community College

EIN: 520905706

UEI: CYN8HKRHAQF9

Data as of August 24, 2026

Anne Arundel Community College10 audit years4 findings
10
Audit Years
4
Total Findings
0
Repeat Findings

FY 2024-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on November 5, 2024. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by May 5, 2025 (477 days ago).

What is a management decision? →
2024-001
Special Tests & Provisions

During testing of the enrollment status reporting, we noted that the incorrect enrollment status and effective date was reported in NSLDS. Questioned costs: None Context: The enrollment data was incorrectly reported for 1 out of 60 students. Cause: The student’s enrollment status update was delayed due to the sequence of file submissions by the college. Although the college transmitted accurate information with each Spring 2024 enrollment file, the initial sequencing of the Fall 2023 graduation file led to a delay in updating the student’s enrollment status and effective date in NSLDS until Fall 2024. Effect: Student enrollment status was not reported accurately in NSLDS. Repeat Finding: No Recommendation: The institution should evaluate their procedures and policies related to reporting status changes and effective dates to NSLDS and enhance as deemed necessary to ensure that accurate information is reported to NSLDS. Views of responsible officials: There is no disagreement with the audit finding.

Show full finding ▾
Full finding narrative

2024 – 001: Special Tests and Provisions – NSLDS Enrollment Reporting Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Aid Cluster Assistance Listing Number: 84.063, 84.268 Federal Award Identification Number: P063P231544, P268K241544 Award Period: July 1, 2023 – June 30, 2024 Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Criteria or specific requirement: Internal Control – Per 2 CFR section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non-Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Compliance – The Code of Federal Regulations, 34 CFR 685.309(b), states that: Institutions must have some arrangement to report student enrollment data to NSLDS through an enrollment roster file. The institution is required to report changes in the enrollment status, the effective date of the status, and an anticipated completion date. Also, the Code of Federal Regulations, 34 CFR 682.610, states that institutions must report accurately the enrollment status of all students regardless if they receive aid from the institution or not. Condition: During testing of the enrollment status reporting, we noted that the incorrect enrollment status and effective date was reported in NSLDS. Questioned costs: None Context: The enrollment data was incorrectly reported for 1 out of 60 students. Cause: The student’s enrollment status update was delayed due to the sequence of file submissions by the college. Although the college transmitted accurate information with each Spring 2024 enrollment file, the initial sequencing of the Fall 2023 graduation file led to a delay in updating the student’s enrollment status and effective date in NSLDS until Fall 2024. Effect: Student enrollment status was not reported accurately in NSLDS. Repeat Finding: No Recommendation: The institution should evaluate their procedures and policies related to reporting status changes and effective dates to NSLDS and enhance as deemed necessary to ensure that accurate information is reported to NSLDS. Views of responsible officials: There is no disagreement with the audit finding.

Corrective Action Plan

MANAGEMENT RESPONSE AND CORRECTIVE ACTION PLAN U.S. Department of Education Audit period: July 1, 2023 – June 30, 2024 The findings from the schedule of findings and questioned costs are discussed below. The findings are numbered consistently with the numbers assigned in the schedule. FINDINGS—FEDERAL AWARD PROGRAMS AUDITS U.S. Department of Education 2024-01: Special Tests and Provisions – NSLDS Enrollment Reporting Student Financial Aid Cluster – Assistance Listing No. 84.063, 84.268 Condition: During testing of the enrollment status reporting, we noted that the incorrect enrollment status and effective date was included in NSLDS. Recommendation: The institution should evaluate their procedures and policies related to reporting status changes and effective dates to NSLDS and enhance as deemed necessary to ensure that accurate information is reported to NSLDS. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: The college has reviewed and updated procedures to ensure that graduation and enrollment files are submitted in the necessary sequence to reflect the appropriate enrollment status and effective dates. Name(s) of the contact person(s) responsible for corrective action: Nanci A. Beier, Registrar Planned completion date for corrective action plan: Completed

About Special Tests and Provisions →

FY 2023-06-30

FAC accepted this audit on January 19, 2024 — management decision was due July 19, 2024.

2023-001
Special Tests & Provisions

Certain elements of the College’s information security program were not maintained in written form. Questioned costs: None Context: The College’s written information security program did not cover the following requirements as of the required deadline in June 2023: Conduct a periodic inventory of data, noting where it's collected, stored or transmitted. Encrypt customer information on the institution's system and when it's in transit; Implement multi-factor authentication for anyone accessing customer information on the institution's system; Maintain a log of authorized users' activity and keep an eye out for unauthorized access; and, Provides for the institution to regularly test or otherwise monitor effectiveness of the safeguards it has implemented (16 CFR 314.4(d)) Cause: The College engaged an external consultant to aid in the development of comprehensive written information security program, but the resulting written policies and procedures were not complete as of the June 2023 deadline. However the College had implemented the required actions under the requirements, and was actively managing information security within the intent of the requirements. The program was later written to codify College process. Effect: Information security management may not be optimized and responses delayed without the written plan. Repeat Finding: No Recommendation: We recommend the College ensure its written information security program addresses the required minimum elements as outlined in 16 CFR 314.4. Views of responsible officials: Management acknowledges that the policy components were not in a written comprehensive format, however the College was and continues to conduct those actions required in a written plan, and subsequent to the deadline has created the written documents to satisfy the requirements without compromise to any student information

Show full finding ▾
Full finding narrative

2023-001: Gramm-Leach-Bliley Act Federal Agency: U.S. Department of Education Federal Program Name: Student Finacial Aid Cluster Assistance Listing Number: 84.063, 84.268, 84.007, 84.033 Federal Award Identification Number: P007A221715, P033A221715, Po63P221544, P268K231544 Award Period: July 1, 2022 - June 30, 2023 Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Criteria or specific requirement: Internal Control - Per 2 CFR section 200.303(a), a non-Federal entity must Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non- Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Compliance – The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi). Institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The regulations require the written information security program to include nine elements for institutions with 5,000 or more customers, (16 CFR 314.3(a)). The elements that an institution must address in its written information security program are at 16 CFR 314.4. Condition: Certain elements of the College’s information security program were not maintained in written form. Questioned costs: None Context: The College’s written information security program did not cover the following requirements as of the required deadline in June 2023: Conduct a periodic inventory of data, noting where it's collected, stored or transmitted. Encrypt customer information on the institution's system and when it's in transit; Implement multi-factor authentication for anyone accessing customer information on the institution's system; Maintain a log of authorized users' activity and keep an eye out for unauthorized access; and, Provides for the institution to regularly test or otherwise monitor effectiveness of the safeguards it has implemented (16 CFR 314.4(d)) Cause: The College engaged an external consultant to aid in the development of comprehensive written information security program, but the resulting written policies and procedures were not complete as of the June 2023 deadline. However the College had implemented the required actions under the requirements, and was actively managing information security within the intent of the requirements. The program was later written to codify College process. Effect: Information security management may not be optimized and responses delayed without the written plan. Repeat Finding: No Recommendation: We recommend the College ensure its written information security program addresses the required minimum elements as outlined in 16 CFR 314.4. Views of responsible officials: Management acknowledges that the policy components were not in a written comprehensive format, however the College was and continues to conduct those actions required in a written plan, and subsequent to the deadline has created the written documents to satisfy the requirements without compromise to any student information

Corrective Action Plan

2023-001: Gramm-Leach-Bliley Act Student Financial Aid Cluster – Assistance Listing No. 84.063, 84.268, 84.007, 84.033 Condition: Certain elements of the College’s information security program were not maintained in written form. Recommendation: We recommend the College ensure its written information security program addresses the required minimum elements as outlined in 16 CFR 314.4. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: Prior to the conclusion of our audit the College documented in writing the required minimum elements. Name(s) of the contact person(s) responsible for corrective action: Dr. Richard C. Kralevich, Vice President, Information and Instructional Technology Planned completion date for corrective action plan: Completed

About Special Tests and Provisions →
2023-002
Special Tests & Provisions

The associate degree programs were not reported as two years per the recommendation in the NSLDS enrollment reporting guide. Questioned costs: None Context: The condition occurred for 38 out of the 40 students tested Cause: The program length reported to NSLDS for associate degree programs is maintained in the College ERP system based on program length in months and was not converted to years as recommended in the NSLDS enrollment reporting guide. Effect: The NSLDS system calculated the program length at 2.678 years. Repeat Finding: No Recommendation: We recommend the College report associate degree program length to NSLDS as two years. Views of responsible officials: There is no disagreement with the audit finding.

Show full finding ▾
Full finding narrative

2023-002: Special Tests and Provisions - NSLDS Program - Level Reporting Federal Agency: U.S. Department of Education Federal Program Name: Student Financial Aid Cluster Assistance Listing Number: 84.063, 84.268 Federal Award Identification Number: P063P221544, P268K231544 Award Period: July 1, 2022 - June 30, 2023 Type of Finding: Significant Deficiency in Internal Control over Compliance, Other Matters Criteria or Specific requirement: Internal Control – Per 2 CFR section 200.303(a), a non-Federal entity must: Establish and maintain effective internal control over the Federal award that provides reasonable assurance that the non- Federal entity is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should be in compliance with guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control Integrated Framework”, issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO). Compliance – Per the NSLDS Enrollment Reporting Guide, Published Program Length should be reported to NSLDS based on the definition of “normal time” to completion in the regulations at 34 CFR 668.41(a), as follows: If the school has published, in it's catalog, on it's website, or in any promotional materials, the length of the program in weeks, months, or years, the program length reported must be the same as the program length that the school published. If the school has not published a program length and the program is an associate or bachelor's degree program, the program length to be reported should be two years (associate) or four years (bachelor), respectively, unless the academic design of the program makes it longer or shorter than typical. For all other programs for which the school has not published a program length, the program length is based on the school's determination of how long, in weeks, months, or years, the program is designed for a full-time student to complete. Condition: The associate degree programs were not reported as two years per the recommendation in the NSLDS enrollment reporting guide. Questioned costs: None Context: The condition occurred for 38 out of the 40 students tested Cause: The program length reported to NSLDS for associate degree programs is maintained in the College ERP system based on program length in months and was not converted to years as recommended in the NSLDS enrollment reporting guide. Effect: The NSLDS system calculated the program length at 2.678 years. Repeat Finding: No Recommendation: We recommend the College report associate degree program length to NSLDS as two years. Views of responsible officials: There is no disagreement with the audit finding.

Corrective Action Plan

2023-002: Special Tests and Provisions – NSLDS Program-Level Reporting Student Financial Aid Cluster – Assistance Listing No. 84.063, 84.268 Condition: The associate degree programs were not reported as two years per the recommendation in the NSLDS enrollment reporting guide. Recommendation: We recommend the College report associate degree program length to NSLDS at two years. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: Currently investigating ERP system configuration changes necessary to report associate degree program length to NSLDS at two years. Name(s) of the contact person(s) responsible for corrective action: Nanci A. Beier, Registrar Planned completion date for corrective action plan: Spring 2024

About Special Tests and Provisions →

FY 2017-06-30

FAC accepted this audit on November 13, 2017 — management decision was due May 13, 2018.

2017-001
Special Tests & Provisions

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and compliance status.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.