Yosemite Community College District

EIN: 521566989

UEI: DLVKVBMZME64

Data as of August 26, 2026

Yosemite Community College District10 audit years3 findings1 repeat
10
Audit Years
3
Total Findings
1
Repeat Findings

FY 2025-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on January 22, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by July 22, 2026 (35 days ago).

What is a management decision? →
2025-001
Special Tests & Provisions

For two of the forty students selected for testing, the District performed an R2T4 calculation even though the students had completed more than 60% of the payment period and had earned their full Title IV awards. Cause: The District’s internal controls over the identification and review of withdrawal dates and completion percentages were not properly designed, resulting in R2T4 calculations being performed when they were not required. Effect: The District performed R2T4 calculations for two students who had completed more than 60% of the payment period and had earned 100% of their Title IV funds. As a result, Title IV funds were inappropriately returned to the Department of Education for these students, resulting in the unnecessary return of federal student financial aid and noncompliance with R2T4 requirements. Fiscal Impact: Audit testing identified an over return of approximately $674 in Title IV funds related to the two students with deviations noted in the sample. The total fiscal impact could not be determined. Identification as a Repeat Finding: Not applicable. Recommendation: We recommend the District strengthen internal controls over the R2T4 process to ensure calculations are performed only for students who withdraw prior to completing 60% of the payment period. This includes implementing procedures to verify completion percentages prior to initiating an R2T4 calculation and performing supervisory reviews to ensure compliance with federal requirements. Views of Responsible Officials and Planned Corrective Action: See corrective action plan.

Show full finding ▾
Full finding narrative

FINDING 2025-001 – SIGNIFICANT DEFIENCY – FEDERAL COMPLIANCE – STUDENT FINANCIAL ASSISTANCE CLUSTER Federal Department: Department of Education AL Number(s): 84.007, 84.033, 84.063, 84.268, 93.364 Program Name(s): Student Financial Assistance Cluster Questioned Costs: Not determined. Criteria: In accordance with 34 CFR § 668.22, an institution must calculate and return Title IV funds when a student withdraws from a Title IV eligible program prior to completing more than 60% of the payment period or period of enrollment. Once a student has completed more than 60% of the payment period, the student is considered to have earned their entire Title IV award, and no Return of Title IV (R2T4) calculation is required. Institutions are required to establish and maintain effective internal controls to ensure R2T4 calculations are performed accurately and only when required. Condition: For two of the forty students selected for testing, the District performed an R2T4 calculation even though the students had completed more than 60% of the payment period and had earned their full Title IV awards. Cause: The District’s internal controls over the identification and review of withdrawal dates and completion percentages were not properly designed, resulting in R2T4 calculations being performed when they were not required. Effect: The District performed R2T4 calculations for two students who had completed more than 60% of the payment period and had earned 100% of their Title IV funds. As a result, Title IV funds were inappropriately returned to the Department of Education for these students, resulting in the unnecessary return of federal student financial aid and noncompliance with R2T4 requirements. Fiscal Impact: Audit testing identified an over return of approximately $674 in Title IV funds related to the two students with deviations noted in the sample. The total fiscal impact could not be determined. Identification as a Repeat Finding: Not applicable. Recommendation: We recommend the District strengthen internal controls over the R2T4 process to ensure calculations are performed only for students who withdraw prior to completing 60% of the payment period. This includes implementing procedures to verify completion percentages prior to initiating an R2T4 calculation and performing supervisory reviews to ensure compliance with federal requirements. Views of Responsible Officials and Planned Corrective Action: See corrective action plan.

Corrective Action Plan

Corrective action taken or planned: Management concurs with the finding and the auditor's recommendation. The District will continue to provide targeted training and perform ongoing monitoring of staff responsible for the preparation and review of R2T4 calculations. In addition, the campus will create internal procedures for the new FAFSA simplification calculations. District will strengthen internal controls over the R2T4 process by implementing an additional level of supervisory review and approval to ensure calculations are performed accurately and in accordance with applicable federal regulations. Anticipated completion date: June 30, 2026 Contact person responsible: Melissa Raby Vice President, Student Services Columbia College

About Special Tests and Provisions →

FY 2024-06-30

FAC accepted this audit on December 13, 2024 — management decision was due June 13, 2025.

2024-001
Special Tests & Provisions
REPEAT

FINDING 2024-001 – Controls and Noncompliance Related to Student Information Security Federal Department: Department of Education AL Number(s): 84,003, 84.063, 84.007, 84.268, 93.364 Program Name(s): Student Financial Aid Cluster Questioned Costs: None Criteria Special Tests and Provisions - Gramm-Leach-Bliley Act -Student Information Security - The Gramm-Leach- Bliley Act (“GLBA”) (Public Law 106-102) requires financial institutions to explain their information sharingpractices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to GLBA (16 CFR 313.3(k)(2)(iv)). Under an institution’s Program Participation Agreement with the Department of Education and the GLBA, institutions must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal financial aid programs. Institutions are required to designate a qualified individual responsible for implementing and monitoring the institution's information and security program. Additionally, the District is required to maintain written security program that addresses the minimum elements required by GLBA. Condition Yosemite Community College District (the “District”) did not have a written security program in place that addresses the minimum required elements under GLBA. Questioned Costs None noted. Context During inquiries with management, management established that there is not currently a written security program in place that addresses the minimum required elements under GLBA. However, management indicated that there were no known data breaches or instances of the District’s information systems being compromised during the audit period. Effect Risks pertaining to Student Information Security may not be identified and/or addressed. Cause Insufficient time to implement a security program that addresses the minimum elements required by GLBA due to a vacancy in the Information Systems department that was filled during 2024. The vacant role caused a lack of available resources for purposes of implementing GLBA compliant policies and procedures. Identification as a Repeat Finding, if Applicable Partial repeat finding of 2023-001. Recommendation We recommend that the District to develop and maintain written security program that addresses the minimum elements required by GLBA. Views of Responsible Officials and Planned Corrective Actions See Corrective Action Plan

Show full finding ▾
Full finding narrative

FINDING 2024-001 – Controls and Noncompliance Related to Student Information Security Federal Department: Department of Education AL Number(s): 84,003, 84.063, 84.007, 84.268, 93.364 Program Name(s): Student Financial Aid Cluster Questioned Costs: None Criteria Special Tests and Provisions - Gramm-Leach-Bliley Act -Student Information Security - The Gramm-Leach- Bliley Act (“GLBA”) (Public Law 106-102) requires financial institutions to explain their information sharingpractices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to GLBA (16 CFR 313.3(k)(2)(iv)). Under an institution’s Program Participation Agreement with the Department of Education and the GLBA, institutions must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal financial aid programs. Institutions are required to designate a qualified individual responsible for implementing and monitoring the institution's information and security program. Additionally, the District is required to maintain written security program that addresses the minimum elements required by GLBA. Condition Yosemite Community College District (the “District”) did not have a written security program in place that addresses the minimum required elements under GLBA. Questioned Costs None noted. Context During inquiries with management, management established that there is not currently a written security program in place that addresses the minimum required elements under GLBA. However, management indicated that there were no known data breaches or instances of the District’s information systems being compromised during the audit period. Effect Risks pertaining to Student Information Security may not be identified and/or addressed. Cause Insufficient time to implement a security program that addresses the minimum elements required by GLBA due to a vacancy in the Information Systems department that was filled during 2024. The vacant role caused a lack of available resources for purposes of implementing GLBA compliant policies and procedures. Identification as a Repeat Finding, if Applicable Partial repeat finding of 2023-001. Recommendation We recommend that the District to develop and maintain written security program that addresses the minimum elements required by GLBA. Views of Responsible Officials and Planned Corrective Actions See Corrective Action Plan

Corrective Action Plan

Controller's Office Yosemite Community College District P.O. Box 4065 / Modesto, CA 95352 / 2201 Blue Gum Avenue 95358 Phone (209) 575-6527 / FAX (209) 575-6562 CORRECTIVE ACTION PLAN YEAR ENDED JUNE 30, 2024 Identifying number: 2024-001 Finding: Special Tests and Provisions - Gramm-Leach-Bliley Act (GLBA) - Student Information Security - Yosemite Community College District (the "District") did not have a written security program in place that addresses the minimum required elements as required under GLBA. Corrective action taken or planned: The District has begun preparing risk assessments that meet the requirements of 16 CFR 314.4(b). Once the risk assessment has been completed, safeguards will be implemented to meet the GLBA requirements, and will serve as a comprehensive information security program for the District. Anticipated completion date: June 30, 2025 Contact person responsible: Brandon Ellenburg Director of Information Security

Prior Finding References

2023-001

About Special Tests and Provisions →

FY 2023-06-30

FAC accepted this audit on December 19, 2023 — management decision was due June 19, 2024.

2023-001
Other

FINDING 2023-001 – Controls and Noncompliance Related to Student Information Security Federal Department: Department of Education CFDA Number(s): 84,003, 84.063, 84.007, 84.268, 93.364 Program Name(s): Student Financial Aid Cluster Questioned Costs: None Criteria Special Tests and Provisions - Gramm-Leach-Bliley Act -Student Information Security - The Gramm-Leach- Bliley Act (“GLBA”) (Public Law 106-102) requires financial institutions to explain their information sharingpractices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to GLBA (16 CFR 313.3(k)(2)(iv)). Under an institution’s Program Participation Agreement with the Department of Education and the GLBA, institutions must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal financial aid programs. Institutions are required to designate a qualified individual responsible for implementing and monitoring the institution's information and security program. Additionally, the District is required to maintain written security program that addresses the minimum elements required by GLBA. Condition Yosemite Community College District (the “District”) did not have a designated individual responsible for implementing and monitoring the institution’s information and security program and did not have a written security program in place that addresses the minimum required elements under GLBA. Questioned Costs None noted. Context During inquiries with management, management established that there was not a designated individual responsible for implementing and monitoring the institutions information and security program, and there is not currently a written security program in place that addresses the minimum required elements under GLBA. However, management indicated that there were no data breaches or instances of the District’s information systems being compromised during the audit period. Effect Risks pertaining to Student Information Security may not be identified and/or addressed. Cause Turnover in the Information Systems department and a vacant role have caused a lack of available resources for purposes of appointing a designated individual and implementing GLBA compliant policies and procedures. Identification as a Repeat Finding, if Applicable Not applicable Recommendation We recommend that the District designate a qualified individual responsible for implementing and monitoring the institution's information and security program, and to develop and maintain written security program that addresses the minimum elements required by GLBA. Views of Responsible Officials and Planned Corrective Actions See Corrective Action Plan.

Show full finding ▾
Full finding narrative

FINDING 2023-001 – Controls and Noncompliance Related to Student Information Security Federal Department: Department of Education CFDA Number(s): 84,003, 84.063, 84.007, 84.268, 93.364 Program Name(s): Student Financial Aid Cluster Questioned Costs: None Criteria Special Tests and Provisions - Gramm-Leach-Bliley Act -Student Information Security - The Gramm-Leach- Bliley Act (“GLBA”) (Public Law 106-102) requires financial institutions to explain their information sharingpractices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to GLBA (16 CFR 313.3(k)(2)(iv)). Under an institution’s Program Participation Agreement with the Department of Education and the GLBA, institutions must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal financial aid programs. Institutions are required to designate a qualified individual responsible for implementing and monitoring the institution's information and security program. Additionally, the District is required to maintain written security program that addresses the minimum elements required by GLBA. Condition Yosemite Community College District (the “District”) did not have a designated individual responsible for implementing and monitoring the institution’s information and security program and did not have a written security program in place that addresses the minimum required elements under GLBA. Questioned Costs None noted. Context During inquiries with management, management established that there was not a designated individual responsible for implementing and monitoring the institutions information and security program, and there is not currently a written security program in place that addresses the minimum required elements under GLBA. However, management indicated that there were no data breaches or instances of the District’s information systems being compromised during the audit period. Effect Risks pertaining to Student Information Security may not be identified and/or addressed. Cause Turnover in the Information Systems department and a vacant role have caused a lack of available resources for purposes of appointing a designated individual and implementing GLBA compliant policies and procedures. Identification as a Repeat Finding, if Applicable Not applicable Recommendation We recommend that the District designate a qualified individual responsible for implementing and monitoring the institution's information and security program, and to develop and maintain written security program that addresses the minimum elements required by GLBA. Views of Responsible Officials and Planned Corrective Actions See Corrective Action Plan.

Corrective Action Plan

CORRECTIVE ACTION PLAN YEAR ENDED JUNE 30, 2023 Finding: Special Tests and Provisions - Gramm-Leach-Bliley Act (GLBA) -Student Information Security - Yosemite Community College District (the "District") did not have a designated individual responsible for implementing and monitoring the institution's information and security program and did not have a written security program in place that addresses the minimum required elements as required under GLBA. Corrective actions taken or planned: The District has started the process of developing a job description for the creation of a position expected to be called the Chief Information Security Officer. The individual hired for this position will be directly responsible for coordinating the information security program, preparing a risk assessment that meets the requirements of 16 CFR 314.4{b), and document a safeguard for each risk identified. Anticipated completion date: June 30, 2024 Contact person responsible: Vice Chancellor of District Administrative Services Columbia

About Other →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and compliance status.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.