← Back to home

Winthrop UniversityHigher Education

EIN: 576001204

UEI: N3KZE4TMNUM4

Audited by: Kochenower Blake Blake Arango & Co., PA

Oversight agency: 84 [Department of Education]

View federal awards & risk assessment →

Data as of September 2, 2026

Winthrop University10 audit years3 findings2 repeat
10
Audit Years
3
Total Findings
2
Repeat Findings
$47.4M
Federal Awards Expended (FY 2025)

FY 2025-06-30

LOW-RISK AUDITEE$47,383,948 federal awards expendedNo findings recorded this year

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on January 2, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by July 2, 2026 (64 days ago).

What is a management decision? →

FY 2024-06-30

LOW-RISK AUDITEE$46,886,193 federal awards expendedNo findings recorded this year

FAC accepted this audit on October 29, 2024 — management decision was due April 29, 2025.

FY 2023-06-30

LOW-RISK AUDITEE$46,267,793 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 26, 2024 — management decision was due August 26, 2024.

FY 2022-06-30

LOW-RISK AUDITEE$66,730,751 federal awards expendedNo findings recorded this year

FAC accepted this audit on November 10, 2022 — management decision was due May 10, 2023.

FY 2021-06-30

MATERIAL NONCOMPLIANCE DISCLOSEDLOW-RISK AUDITEE$69,272,869 federal awards expended

FAC accepted this audit on October 27, 2021 — management decision was due April 27, 2022.

2021-001
Special Tests & Provisions
REPEAT OF 2020-001OTHER MATTERS

The University has designated an individual to coordinate its information security system, has developed its Information Security Implementation Plan, and has yet to complete a risk assessment that addresses the three required areas noted in 16 CFR 314.4(b). [Repeat] Criteria: The Gramm-Leach-Bliley Act requires the University to explain their information-sharing practices to their customers and to safeguard sensitive data. Cause: An Information Security Implementation Plan has not been fully implemented. Effect: The University is not currently in full compliance with its Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act. They have not begun the process of regularly testing and monitoring the effectiveness of their designed safeguards. Recommendation: We recommend that the University complete the implementation of its Information Security Implementation Plan to address the regular, systematic testing, monitoring and documenting of the safeguards' key controls, systems and procedures for each risk identified. Identification of a Repeat Finding: This is a repeat finding from the immediate previous audit, 2020-001. Corrective Action Plan: The University agrees with this finding and adheres to the corrective action plan on page 90 in this audit report.

Show full finding ▾
Full finding narrative

DEPARTMENT OF EDUCATION Finding 2021-001 Gramm-Leach-Bliley Act-Student Information Security-Student Financial Aid Cluster. Condition: The University has designated an individual to coordinate its information security system, has developed its Information Security Implementation Plan, and has yet to complete a risk assessment that addresses the three required areas noted in 16 CFR 314.4(b). [Repeat] Criteria: The Gramm-Leach-Bliley Act requires the University to explain their information-sharing practices to their customers and to safeguard sensitive data. Cause: An Information Security Implementation Plan has not been fully implemented. Effect: The University is not currently in full compliance with its Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act. They have not begun the process of regularly testing and monitoring the effectiveness of their designed safeguards. Recommendation: We recommend that the University complete the implementation of its Information Security Implementation Plan to address the regular, systematic testing, monitoring and documenting of the safeguards' key controls, systems and procedures for each risk identified. Identification of a Repeat Finding: This is a repeat finding from the immediate previous audit, 2020-001. Corrective Action Plan: The University agrees with this finding and adheres to the corrective action plan on page 90 in this audit report.

Corrective Action Plan

Findings and Questioned Costs Relating to Federal Awards, Department of Education, Finding 2021-001 Gramm-Leach-Bliley Act-Student Information Security-Student Financial Aid Cluster. Condition: The University has designated an individual to coordinate its information security system, has developed its Information Security Implementation Plan, and has yet to complete a risk assessment that addresses the three required areas noted in 16 CFR 314.4(b). Contact Persons: Jeremy Whitaker, Associate VP for Finance and Business, and Justin Oates, Vice President for Finance and Business Affairs. FY 2021 Corrective Action Taken: Since the original finding, Winthrop has worked to come into compliance with GLBA. On October 25, 2019, the Board of Trustees adopted a resolution authorizing the implementation of a Comprehensive Information Security Plan. In March 2020, the Coronavirus pandemic hit and unfortunately, this delayed progress on this implementation plan while the University had to spend most of its resources in addressing the pandemic issues and concerns. In December 2020, after the initial hit of the pandemic was over, the University's President and executive leadership approved an Information Security Implementation Plan that addressed compliance with the Gramm-Leach-Bliley Act. The University is committed to full implementation of this plan. The University has and will continue to provide adequate resources toward accomplishing this objective. During Fall 2020, the University had a failed solicitation to acquire software to be used to systematically test and monitor, on a routine basis, the effectiveness of our safeguards' key controls. During the fiscal year, the University experienced a significant decline in administrative personnel campus-wide, but especially in the Finance and Business Affairs division. In early Spring 2021, there was complete turnover in the Procurement Office. Due to budgetary constraints as well as the current market situation, the University was unable to remedy this staffing situation until June 2021. In the prior year Corrective Action response, the University stated that the remaining component of this plan is scheduled to be completed by September 30, 2021. During the summer, a successful solicitation was completed and a contract was awarded. As of the date of this letter, the software has been procured, installed, and has started logging data.

Prior Finding References

2020-001

About Special Tests and Provisions →

FY 2020-06-30

MATERIAL NONCOMPLIANCE DISCLOSEDLOW-RISK AUDITEE$58,031,615 federal awards expended

FAC accepted this audit on June 27, 2021 — management decision was due December 27, 2021.

2020-001
Special Tests & Provisions
REPEAT OF 2019-001OTHER MATTERS

The University has designated an individual to coordinate its information security system, has developed its Information Security Implementation Plan, and has yet to complete a risk assessment that addresses the three required areas noted in 16 CFR 314.4(b).[Repeat] Criteria: The Gramm-Leach-Bliley Act requires the University to explain their information-sharing practices to their customers and to safeguard sensitive data. Cause: An Information Security Implementation Plan has not been fully implemented. Effect: The University is not currently in full compliance with its Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act. Recommendation: We recommend that the University complete the implementation of its Information Security Implementation Plan. Corrective Action Plan: See attached corrective plan.

Show full finding ▾
Full finding narrative

DEPARTMENT OF EDUCATION Finding 2019-001 Gramm-Leach-Bliley Act-Student Information Security-Student Financial Aid Cluster. Condition: The University has designated an individual to coordinate its information security system, has developed its Information Security Implementation Plan, and has yet to complete a risk assessment that addresses the three required areas noted in 16 CFR 314.4(b).[Repeat] Criteria: The Gramm-Leach-Bliley Act requires the University to explain their information-sharing practices to their customers and to safeguard sensitive data. Cause: An Information Security Implementation Plan has not been fully implemented. Effect: The University is not currently in full compliance with its Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act. Recommendation: We recommend that the University complete the implementation of its Information Security Implementation Plan. Corrective Action Plan: See attached corrective plan.

Corrective Action Plan

FY 2019 Findings and Questions Costs Relating to Federal Awards, Department of Education, Finding 2019-001 Gramm-Leach-Bliley Act-Student Information Security-Student Financial Aid Cluster Condition: The University has designated an individual to coordinate its information security system, has developed its Information Security Implementation Plan, and has yet to complete a risk assessment that addresses the three required areas noted in 16 CFR 314.4(b). Contact Persons: Craig Sauvigne, Information Security Analyst, and Justin Oates, Vice President for Finance and Business Affairs FY2020 Corrective Action Taken: Since the original finding the University has worked to come into compliance with GLBA. On October 25, 2019, The Board of Trustees adopted a resolution authorizing the Implementation of a Comprehensive Information Security Plan. In December 2020, the University's President and executive leadership approved an Information Security Implementation Plan that includes completing a comprehensive risk assessment covering all three required areas noted in 16 CFR 314.4(b). The University is committed to full implementation of this plan and will provide adequate resources toward accomplishing this objective. The remaining component is scheduled to be completed by September 30, 2021. 314.4(a) Winthrop has a personnel role charged with developing and ensuring compliance with information security for the University. This role reports outside of the information technology chain of command as is best practice and mandated by South Carolina Division of Information Security. (b) Winthrop University has completed a full risk assessment of both internal and external risks related to the information systems and the data stored thereon. The first risk assessment was completed at the end of 2019 and will be reviewed annually. The most recent review was completed at the end of 2020. This risk assessment reviews controls related to 314.4(b) subsections (1)-(3). (c) Winthrop University is in the continual process of designing and implementing information safeguards to control the risks identified through risk assessment. The Risk Management Office is still waiting on the University Procurement Office to publish an appropriate solicitation related to regularly testing or otherwise monitoring the effectiveness of the safeguards' key controls, systems, and procedures. (d) Winthrop oversees service providers and/or third-party contractors, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; and (2) Requiring University service provides by contract to implement and maintain such safeguards. (3) Reviewing data sharing and protection agreements along with the SC Materials Management Office. (e) The Information security office continues to evaluate and adjust the Winthrop information security program in light of the University environment or any other circumstances that are known or have reason to be known which may have a material impact on the information security program. However, the Risk Management Office is still waiting on the University Procurement Office to publish an appropriate solicitation related to the testing and monitoring required by paragraph (c) of this section.

Prior Finding References

2019-001

About Special Tests and Provisions →

FY 2019-06-30

MATERIAL NONCOMPLIANCE DISCLOSEDLOW-RISK AUDITEE$53,308,281 federal awards expended

FAC accepted this audit on November 5, 2019 — management decision was due May 5, 2020.

2019-001
Special Tests & Provisions
OTHER MATTERS

The University has designated an individual to coordinate its information security system, has developed its Information Security Implementation Plan, and has yet to complete a risk assessment that addresses the three required areas noted in 16 CFR 314.4(b). Criteria: The Gramm-Leach-Bliley Act requires the University to explain their information-sharing practices to their customers and to safeguard sensitive data. Cause: An Information Security Implementation Plan has not been fully implemented. Effect: The University is not currently in full compliance with its Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act. Recommendation: We recommend that the University complete the implementation of its Information Security Implementation Plan.

Show full finding ▾
Full finding narrative

DEPARTMENT OF EDUCATION Finding 2019-001 Gramm-Leach-Bliley Act-Student Information Security-Student Financial Aid Cluster. Condition: The University has designated an individual to coordinate its information security system, has developed its Information Security Implementation Plan, and has yet to complete a risk assessment that addresses the three required areas noted in 16 CFR 314.4(b). Criteria: The Gramm-Leach-Bliley Act requires the University to explain their information-sharing practices to their customers and to safeguard sensitive data. Cause: An Information Security Implementation Plan has not been fully implemented. Effect: The University is not currently in full compliance with its Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act. Recommendation: We recommend that the University complete the implementation of its Information Security Implementation Plan.

Corrective Action Plan

Response to 2018-19 Audit Finding Regarding Gramm-Leach-Bliley Act-Student Information Security to the Department of Education. Winthrop agrees that it is not currently in full compliance with some of the components of the Gramm-Leach-Bliley Act. Winthrop further agrees with the recommendation that the University complete the components of the Information Security Implementation Plan. After multiple failed searches, Winthrop did fill an information security position on June 1, 2019 as a new role charged with developing a mature information security plan for the University. Winthrop University does comply with 314.4(b)(1) by mandating annual security training for all employees. Winthrop University reviews all agreements with third party contractors on numerous facets to include data protection and security standards as required under 314.4(d). Corrective Action The University's President has approved an Information Security Implementation Plan that includes completing a comprehensive risk assessment covering all three required areas noted in 16 CFR 314.4(b). The University is committed to full implementation of this plan and will provide adequate resources toward accomplishing this objective.

About Special Tests and Provisions →

FY 2018-06-30

LOW-RISK AUDITEE$54,232,307 federal awards expendedNo findings recorded this year

FAC accepted this audit on October 28, 2018 — management decision was due April 28, 2019.

FY 2017-06-30

LOW-RISK AUDITEE$55,289,265 federal awards expendedNo findings recorded this year

FAC accepted this audit on October 25, 2017 — management decision was due April 25, 2018.

FY 2016-06-30

LOW-RISK AUDITEE$54,647,336 federal awards expendedNo findings recorded this year

FAC accepted this audit on November 2, 2016 — management decision was due May 2, 2017.

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Browse other Single Audit organizations in South Carolina

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Add it to a monitored group and get alerted when a new audit, finding, repeat finding, or management-decision deadline shows up — instead of checking back.

Checking several at once? Portfolio view →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.