EIN: 581126894
UEI: UK1FK45FAUY3
Audited by: THOMAS & COMPANY CPA PA
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of September 2, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on February 23, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by August 23, 2026 (11 days ago).
What is a management decision? →FAC accepted this audit on January 16, 2025 — management decision was due July 16, 2025.
FAC accepted this audit on January 9, 2024 — management decision was due July 9, 2024.
FAC accepted this audit on January 18, 2023 — management decision was due July 18, 2023.
FAC accepted this audit on January 27, 2022 — management decision was due July 27, 2022.
FAC accepted this audit on January 27, 2021 — management decision was due July 27, 2021.
PROGRAM NAME: Student Financial Assistance Cluster CFDA#: 84.063/84.268 FEDERAL AWARDING AGENCY: Department of Education Type of Finding: Noncompliance Compliance Requirement: Special Tests and Provisions FINDING (2020-001): INEFFICIENCIES IN IT INTERNAL CONTROL SYSTEM CRITERIA: 16 CFR ?314.4 provides that Institutions ?shall (A) designate an employee or employees to coordinate your information security program. (B) Identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: 1.) Employee training and management. 2.) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and 3.) Detecting, preventing and responding to attacks, intrusions, or other systems failures. (C) Design and implement information safeguards to control the risks you identify through risk assessment, and regularly test or otherwise monitor the effectiveness of the safeguards' key controls, systems, and procedures. CAUSE: The Institution is required to conduct routine monitoring and regularly test the effectiveness of the safeguards of key IT Controls. When inquiring of management, management did not conduct periodic risk assessment of the IT environment periodically. CONDITION: When reviewing the information, processing and storage IT system, there were inefficiencies with the IT environment and application of IT controls. Additionally, employee training and management was conducted but not documented. EFFECT: Inefficiencies in the IT Control environment could lead to internal and external risks to security, confidentiality and integrity of confidential data. Proper Management training should be documented to verify occurrence of training. Periodic Risk assessments of IT Control need to be conducted routinely to assess and respond to potential threats. QUESTIONED COSTS: N/A VIEWS OF RESPONSIBLE OFFICIALS & CORRECTIVE ACTION PLAN: Management is in the process of implementing a new, robust IT environment which will correct the inefficiencies noted.
Show full finding ▾Hide full finding ▴PROGRAM NAME: Student Financial Assistance Cluster CFDA#: 84.063/84.268 FEDERAL AWARDING AGENCY: Department of Education Type of Finding: Noncompliance Compliance Requirement: Special Tests and Provisions FINDING (2020-001): INEFFICIENCIES IN IT INTERNAL CONTROL SYSTEM CRITERIA: 16 CFR ?314.4 provides that Institutions ?shall (A) designate an employee or employees to coordinate your information security program. (B) Identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: 1.) Employee training and management. 2.) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and 3.) Detecting, preventing and responding to attacks, intrusions, or other systems failures. (C) Design and implement information safeguards to control the risks you identify through risk assessment, and regularly test or otherwise monitor the effectiveness of the safeguards' key controls, systems, and procedures. CAUSE: The Institution is required to conduct routine monitoring and regularly test the effectiveness of the safeguards of key IT Controls. When inquiring of management, management did not conduct periodic risk assessment of the IT environment periodically. CONDITION: When reviewing the information, processing and storage IT system, there were inefficiencies with the IT environment and application of IT controls. Additionally, employee training and management was conducted but not documented. EFFECT: Inefficiencies in the IT Control environment could lead to internal and external risks to security, confidentiality and integrity of confidential data. Proper Management training should be documented to verify occurrence of training. Periodic Risk assessments of IT Control need to be conducted routinely to assess and respond to potential threats. QUESTIONED COSTS: N/A VIEWS OF RESPONSIBLE OFFICIALS & CORRECTIVE ACTION PLAN: Management is in the process of implementing a new, robust IT environment which will correct the inefficiencies noted.
The Institution will implement a robust IT system which will encompass all of the security issues mentioned. For example, the Institution is currently undergoing a shift of data from local servers to the Cloud. This will ensure that backups are external are conducted routinely. The institution also has purchased a new security program to protect client data. The new security program is considered to be more thorough in data protection, storage and routine scans. Additionally, management will conduct monthly employee trainings and test the IT controls to certain risks to be able to adapt to any potential threats. Although management has been conducting this assessment routinely, an increased effort will be made to conduct this assessment more frequently (monthly) and all documentation will be kept of the trainings including the safeguards to assessed risks and updates in security.
FAC accepted this audit on February 23, 2020 — management decision was due August 23, 2020.
FAC accepted this audit on February 4, 2019 — management decision was due August 4, 2019.
FAC accepted this audit on March 27, 2018 — management decision was due September 27, 2018.
FAC accepted this audit on May 12, 2019 — management decision was due November 12, 2019.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
FAC accepted this audit on February 20, 2017 — management decision was due August 20, 2017.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in Florida →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.