EIN: 566000343
UEI: YLN4BFCJCP39
Data as of August 19, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on July 23, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by January 23, 2027 (156 days from today).
What is a management decision? →Criteria: In accordance with the Division of Social Services Fiscal Manual, DSS employees should control physical access to the state network terminals or personal computers that are connected to the state mainframe. Condition: Upon surprise inspection, one unattended workstation of a DSS employee was logged onto the state network, without anyone attending the workstation. Effect: Unauthorized access to the state system could be obtained due to the unattended logged into the system throughout the DSS building. Cause: Lack of proper internal controls over data security. Questioned Costs: None. The finding represents an internal control issue; therefore, no questioned costs Recommendation: Require the County Data Processing Department to implement procedures to require logout of workstations where access to the state DSS system is granted. The control procedures should include random verification of logout in instances where offices are unattended. Name of Contact Person: Nathaneal Carver, Director of Information Technology Views of Responsible Officials and Planned Corrective Actions: The County agrees with this finding and will adhere to the Corrective Action Plan in this audit report.
Name of Contact Person: Nathanael Carver Management Response: In FY24, the County’s Information Technology Department implemented enhanced procedures under the Computer and Internet Use Policy to strengthen the security of County and State data. These updates include restricting unused network ports, limiting network access by non-County devices, enforcing stronger password requirements, and requiring all IT-related support requests to be submitted through a centralized ticketing system. Automatic time-out procedures were implemented across all County workstations. In addition, staff were reminded of their responsibility to secure workstations when unattended. Compliance is reinforced through random verification checks conducted by DSS supervisors and IT staff to confirm users have properly logged out of their workstations. Further review identified that the specific instance in question involved a workstation assigned to a contracted worker. In response, targeted training was provided to both the contractor and the contracting organization to ensure a clear understanding of County security expectations and procedures. These actions demonstrate the County’s commitment to strengthening controls, addressing identified gaps, and maintaining ongoing compliance with data security requirements. Proposed Completion Date: Immediately
Criteria: In accordance with Title 2 CFR 200.512(a)(1), Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), auditees are required to submit the data collection form and the reporting package to the Federal Audit Clearinghouse within the earlier of 30 calendar days after receipt of the auditor’s report or nine months after the end of the audit period. For any 2025 submissions with fiscal periods ending between January 1, 2025 and September 30, 2025, requirement 2 CFR 200.512(1) stating that single audits are due to the Federal Audit Clearinghouse 30 days after receipt of the auditor’s report(s), is waived. These audits will be considered on time if they are submitted within nine months after their fiscal period end date. Condition: The County’s data collection form and reporting package for the year ended June 30, 2025, were not submitted to the Federal Audit Clearinghouse (FAC) within a timely manner. Context: This requirement applies to all auditees subject to the Single Audit Act. Effect: The County’s data collection form and reporting package were not submitted, as required under Title 2 CFR 200.512(a)(1), Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Cause: Due to a delay in the audit, the timing of the Uniform Guidance audit was delayed. The County did not submit the data collection form to the Federal Audit Clearinghouse (FAC) on time. Identification of a Repeat Finding: This is a repeat finding from the immediate previous audit, 2024-004. Questioned Costs: None. The finding represents a reporting issue; therefore, no questioned costs are applicable. Recommendation: Measures should be taken to ensure the audit package and the data collection form are submitted within 30 days after receipt of the auditor’s report or nine months after the end of the fiscal year end date, whichever comes first. Name of Contact Person: Meagan O’Neal, Finance Director Views of Responsible Officials and Planned Corrective Action: Management concurs with the condition noted above. Please refer to the Corrective Action Plan of this report.
Name of Contact Person: Meagan O’Neal Management Response: As covered in 2025-001, several years of late audits have inevitably created a lag. With the challenges of a new finance director, Hurricane Helene, 600+ acres of wildfire due to blowdown from Helene, County staff across all departments have been maxed out, including Finance staff trying to balance regular duties, audit fieldwork and disaster related responsibilities. 180 Corrective Action Plan (continued) We completed the FY24 audit at the end of September 2025 and immediately began the FY25 process. With systems implemented over the last two years, we were able to complete all year-end reconciliations and FY25 audit fieldwork in approximately seven months. This has been the most efficient completion of an audit for Transylvania since FY19, reflecting the effectiveness of these changes. Procedures to reconcile subsidiary ledgers monthly have been implemented as an ongoing responsibility of the Finance Director and Accountant to minimize year-end adjustments. The Finance Director has also completed over 50 hours of CPE through the School of Government to support continued process improvement. Communication between the auditor and the County has remained open throughout this period of transition and disaster management. Proposed Completion Date: Immediately.
2024-004
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on October 9, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by April 9, 2026, which was (133 days ago).
What is a management decision? →Significant Deficiency Non-Compliance Finding 2024-004 Criteria: In accordance with Title 2 CFR 200.512(a)(1), Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), auditees are required to submit the data collection form and the reporting package to the Federal Audit Clearinghouse within the earlier of 30 calendar days after receipt of the auditor’s report or nine months after the end of the audit period. For any 2024 submissions with fiscal periods ending between January 1, 2024 and September 30, 2024, requirement 2 CFR 200.512(1) stating that single audits are due to the Federal Audit Clearinghouse 30 days after receipt of the auditor’s report(s), is waived. These audits will be considered on time if they are submitted within nine months after their fiscal period end date. Condition: The County’s data collection form and reporting package for the year ended June 30, 2024, were not submitted to the Federal Audit Clearinghouse (FAC) within a timely manner. Context: This requirement applies to all auditees subject to the Single Audit Act. Effect: The County’s data collection form and reporting package were not submitted, as required under Title 2 CFR 200.512(a)(1), Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Cause: Due to a delay in the audit, the timing of the Uniform Guidance audit was delayed. The County did not submit the data collection form to the Federal Audit Clearinghouse (FAC) on time. Identification of a Repeat Finding: This is a repeat finding from the immediate previous audit, 2023- 003. Questioned Costs: None. The finding represents a reporting issue; therefore, no questioned costs are applicable. Recommendation: Measures should be taken to ensure the audit package and the data collection form are submitted within 30 days after receipt of the auditor’s report or nine months after the end of the fiscal year end date, whichever comes first. Name of Contact Person: Meagan O’Neal, Finance Director Views of Responsible Officials and Planned Corrective Action: Management concurs with the condition noted above. Please refer to the Corrective Action Plan of this report. 177
Finding 2024-004: Name of Contact Person: Meagan O’Neal Management Response: The new Finance Director, hired in October 2023, immediately began reviewing staff assignments to analyze for improvements in efficiency while keeping separation of duties secure, while also completing the FY23 audit. This review allowed restructuring tasks to improve efficiency and the ability to set up new processes. The finance director has utilized help from NC Association of County Commissioner staff as well as UNC School of Government courses to continue to update processes and improve upon the quality of data provided. The occurrence of Hurricane Helene and the Spring wildfires in Transylvania County impacted staff capacity to complete the FY24 audit however now that it is complete we will be diligently working to have FY25 information submitted quickly. Notes have been added to the process documents to ensure all steps are taken when submitting the data collection form to the Federal Audit Clearinghouse once future audits are completed by the firm. Proposed Completion Date: Immediately.
2023-003
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on October 24, 2024. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by April 24, 2025, which was (483 days ago).
What is a management decision? →Significant Deficiency Non-Compliance Finding 2023-003 Criteria: In accordance with Title 2 CFR 200.512(a)(1), Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance), auditees are required to submit the data collection form and the reporting package to the GAC within the earlier of 30 calendar days after receipt of the auditor’s report or nine months after the end of the audit period. For any 2023 submissions with fiscal periods ending between January 1, 2023 and September 30, 2023, requirement 2 CFR 200.512(1) stating that single audits are due to the Federal Audit Clearinghouse 30 days after receipt of the auditor’s report(s), is waived. These audits will be considered on time if they are submitted within nine months after their fiscal period end date. Condition: The County’s data collection form and reporting package for the year ended June 30, 2023, were not submitted to the Federal Audit Clearinghouse (FAC) within a timely manner. Effect: The County’s data collection form and reporting package were not submitted, as required under Title 2 CFR 200.512(a)(1), Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance). Cause: Due to a delay in the audit, the timing of the Uniform Guidance audit was delayed. The County did not submit the data collection form to the Federal Audit Clearinghouse (FAC) on time. Questioned Costs: None. The finding represents a reporting issue; therefore, no questioned costs are applicable. Recommendation: Measures should be taken to ensure the audit package and the data collection form are submitted within 30 days after receipt of the auditor’s report or nine months after the end of the fiscal year end date, whichever comes first. Name of Contact Person: Meagan O’Neal, Finance Director Views of Responsible Officials and Planned Corrective Action: Management concurs with the condition noted above. Please refer to the Corrective Action Plan of this report.
Finding 2023-003: Name of Contact Person: Meagan O’Neal Management Response: The assessment of all finance staff duties has provided a clearer understanding of how the audit package can be timely moving forward. Processes have been put in place for reviewing accounts, budgets and reports more often to prevent a year end rush to collect data. Proposed Completion Date: Immediately.
U.S. Department of Health and Human Services Passed through the N.C. Dept. of Health and Human Services Program Name: Medical Assistance Program AL# 93.778 Grant Number: XIX-MAP23 Significant Deficiency Finding 2023-004 Criteria: In accordance with the Division of Social Services Fiscal Manual, DSS employees should control physical access to the state network terminals or personal computers that are connected to the state mainframe. Condition: Upon surprise inspection, one unattended workstation of a DSS employee was logged onto the state network. Context: While performing testing of internal control over compliance related to the Division of Social Services, we noted the above condition. Effect: Unauthorized access to the state system could be obtained due to the unattended logon to the system throughout the DSS building. Cause: Lack of proper internal controls over data security. Questioned Costs: None. The finding represents an internal control issue; therefore, no questioned costs are applicable. Recommendation: Require the County Data Processing Department to implement procedures to require logout of workstations where access to the state DSS system is granted. The control procedures should include random verification of logout in instances where offices are unattended. Name of Contact Person: Meagan O’Neal, Finance Director. Views of Responsible Officials and Planned Corrective Actions: Management concurs with this finding and will adhere to the Corrective Action Plan in this audit report.
Finding 2023-004: Name of Contact Person: Nathanael Carver Management Response: Information Technology implemented a new procedure related to the County’s Computer and Internet Use Policy to ensure County and State data is always secure and safe. This new procedure includes restrictions on non-used network ports, non-county technology devices accessing the network, new password requirements and a ticketing system for all IT related support. Staff were also reminded of the importance of securing workstations during their absence. Random verification of logout confirmation occurs by DSS supervisors as well as IT staff to ensure procedures are being followed. Proposed Completion Date: Immediately.
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on December 17, 2017. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by June 17, 2018, which was (2986 days ago).
What is a management decision? →GSA_MIGRATION
GSA_MIGRATION
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.