EIN: 560532297
UEI: LTJAP519MKA6
Audited by: Cherry Bekaert LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of August 28, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on September 25, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by March 25, 2026 (159 days ago).
What is a management decision? →FAC accepted this audit on September 26, 2024 — management decision was due March 26, 2025.
FAC accepted this audit on October 6, 2023 — management decision was due April 6, 2024.
FAC accepted this audit on November 4, 2022 — management decision was due May 4, 2023.
The College sent 10 changes related to withdrawn students to the National Student Loan Data System (?NSLDS?) after 60 days and did not send status changes related to 11 withdrawn students to the NSLDS for the year ended May 31, 2022 of which 14 students received direct loans. Criteria: The College is required to send changes in attendance levels, graduated, withdrew, dropped out, or enrolled changes to the NSLDS within 60 days of the change. Cause: The College had not reported changes of withdrawn students to the NSLDS as required under the Uniform Grant Guidance for the year ended May 31, 2022. The College had a system upgrade in the Fall of 2021 and did not realize there was a bug in the system that did not properly report withdrawn students on one of the standard reports produced by the system. The College did not have another monitoring mechanism in place that would have alerted them to this deficiency in the automated system reporting. Context: The College is required to send changes in attendance levels, graduated, withdrew, dropped out, or enrolled changes to the NSLDS within 60 days of the change. Effect: The College did not report withdraw changes to the NSLDS timely. Recommendation: The College should put in place a process to timely capture withdrawn student changes so that they can be reported to the NSLDS. Management Response: The College concurs with this finding. Corrective Action Plan: See attached management?s corrective action plan.
Show full finding ▾Hide full finding ▴Finding 2022-001 - Student Financial Aid Cluster, CFDA# 84.007, 84.033, 84.038, 84.063, 84.268 Compliance Requirement: Special Test and Provisions - Enrollment Reporting Condition: The College sent 10 changes related to withdrawn students to the National Student Loan Data System (?NSLDS?) after 60 days and did not send status changes related to 11 withdrawn students to the NSLDS for the year ended May 31, 2022 of which 14 students received direct loans. Criteria: The College is required to send changes in attendance levels, graduated, withdrew, dropped out, or enrolled changes to the NSLDS within 60 days of the change. Cause: The College had not reported changes of withdrawn students to the NSLDS as required under the Uniform Grant Guidance for the year ended May 31, 2022. The College had a system upgrade in the Fall of 2021 and did not realize there was a bug in the system that did not properly report withdrawn students on one of the standard reports produced by the system. The College did not have another monitoring mechanism in place that would have alerted them to this deficiency in the automated system reporting. Context: The College is required to send changes in attendance levels, graduated, withdrew, dropped out, or enrolled changes to the NSLDS within 60 days of the change. Effect: The College did not report withdraw changes to the NSLDS timely. Recommendation: The College should put in place a process to timely capture withdrawn student changes so that they can be reported to the NSLDS. Management Response: The College concurs with this finding. Corrective Action Plan: See attached management?s corrective action plan.
Reference No. 2022-001 Explanation: The College had not reported changes of withdrawn students to the NSLDS as required under the Uniform Grant Guidance for the year ended May 31, 2022. The College had a system upgrade in the Fall of 2021 and did not realize there was a bug in the system that did not properly report withdrawn students on one of the standard reports produced by the system. The College did not have another monitoring mechanism in place that would have alerted them to this deficiency in the automated system reporting. Corrective Action Plan: The Registrar's Office will change their enrollment status and dates in National Student Clearinghouse to reflect accurate information and contact NSLDS to report the issue. To ensure this doesn't happen in the future, these steps will be taken: ? IT will report the bug to Jenzabar. ? Registrar will manually create a new row in the Registration Transaction table anytime a student fully withdraws from a term. ? IT will create a report that flags any inconsistencies in hours in Student Registration vs. NSC status.
FAC accepted this audit on October 26, 2021 — management decision was due April 26, 2022.
FAC accepted this audit on April 29, 2021 — management decision was due October 29, 2021.
The College had not performed a risk assessment as of May 31, 2020. Criteria: The College is required to complete a risk assessment that addresses the three required areas noted in 16 CFR 314.4 (b). Cause: The College had not performed its risk assessment as required under the Uniform Grant Guidance as of May 31, 2020. The College had scheduled a system upgrade in the Fall of 2020 and a risk assessment had been planned for that time. Context: The College is required to perform this risk assessment, document risks and document safeguards to protect against those risks. Effect: The College could have risks associated with the safeguarding of sensitive information it is not aware of or does not protect against. Recommendation: The College should complete its risk assessment and document any risks identified and safeguards put in place to protect against such risk as soon as possible. Management Response: The College concurs with this finding. Corrective Action Plan: See attached management?s corrective action plan.
Show full finding ▾Hide full finding ▴Finding 2020-001 - Student Financial Aid Cluster, CFDA# 84.007, 84.033, 84.0383, 84.063, 84.268 Compliance Requirement: Gramm-Leach-Bliley Act Condition: The College had not performed a risk assessment as of May 31, 2020. Criteria: The College is required to complete a risk assessment that addresses the three required areas noted in 16 CFR 314.4 (b). Cause: The College had not performed its risk assessment as required under the Uniform Grant Guidance as of May 31, 2020. The College had scheduled a system upgrade in the Fall of 2020 and a risk assessment had been planned for that time. Context: The College is required to perform this risk assessment, document risks and document safeguards to protect against those risks. Effect: The College could have risks associated with the safeguarding of sensitive information it is not aware of or does not protect against. Recommendation: The College should complete its risk assessment and document any risks identified and safeguards put in place to protect against such risk as soon as possible. Management Response: The College concurs with this finding. Corrective Action Plan: See attached management?s corrective action plan.
April 5, 2021 MANAGEMENT?S CORRECTIVE ACTION PLAN Finding 2020-000 ? Student Financial Aid Cluster, CFDA #84.007, 84.033, 84.063, 84.268 Compliance Requirement: Gramm-Leach-Bliley Act Criteria: The College is required to complete a risk assessment that addresses the three required areas noted in 16 CFR 314.4 (b). Cause: The College had not performed its risk assessment as required under the Uniform Grant Guidance as of May 31, 2020. The College had scheduled a system upgrade in the Fall of 2020 and a risk assessment had been planned for that time. Context: The College is required to perform this risk assessment, document risks and document safeguards to protect against those risks. Effect: The College could have risks associated with the safeguarding of sensitive information it is not aware of or does not protect against. Recommendation: The College should complete its risk assessment and document any risks identified and safeguards put in place to protect against such risk as soon as possible. Management Response: The College concurs with this finding. Corrective Action Plan: Management performed the required risk assessment in Fall 2020, which included employee training through various informative emails regarding cyber security and its impact on safeguarding of sensitive data. Upon the new Director of Information Services, William DeWitt?s, arrival, he initiated an assessment of the information systems, including network and software design, as well as information processing, storage, transmission and disposal. As a result of this assessment, the following improvements were made: ? Cyber Security Awareness Program o Cyber Security Incident Response Team o Cyber Security Campaign will kick off October 1st 2021 ? Security Awareness Program using KnowBe4 as the application platform o Campaigns will begin Summer of 2021 o Employee Security Awareness will begin prior to Fall 2021 ? Wireless network will be evaluated Summer 2021 to create a 2nd VLAN to support student access ? Use of NAC portal to scan, verify updates, operating systems, and patches prior to devices being on-boarded onto Brevard College wireless network ? Cloud-based backups with encryption during transit and at rest Information Services also evaluated the Ccollege?s process of detecting, preventing, and responding to attacks, intrusions, or other systems failures. As a result of this assessment: ? All endpoint anti-virus applications are up to date with monitoring enabled ? Firewall software is updated on a regular basis to keep up with current IPS and IDS protections ? PRTG monitoring software is installed on all Brevard College infrastructure devices The risks discovered have been documented, as well as safeguards to protect against those risks.
FAC accepted this audit on November 19, 2019 — management decision was due May 19, 2020.
FAC accepted this audit on January 8, 2019 — management decision was due July 8, 2019.
FAC accepted this audit on October 24, 2017 — management decision was due April 24, 2018.
FAC accepted this audit on November 20, 2016 — management decision was due May 20, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in North Carolina →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.