EIN: 610444780
UEI: J3KPEDNN74R6
Data as of August 21, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 26, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 26, 2025 (329 days ago).
What is a management decision? →During our testing of unofficial withdrawals and student status changes for graduates, we selected four and 22 samples, respectively, and we noted one instance in each testing section where a students status change was not timely reported to the National Student Loan Database System (NSLDS). Cause: The University did not have controls in place to ensure students' classification were being properly reported to the NSLDS. Effect: Student status changes were not reported within the required timeframe under federal regulations. The provisions of 34 CFR Section 685.309(b) were not followed and thus two students were not reported timely and subsequently not placed into loan repayment status in a timely manner. Questioned Costs: There were no questioned costs associated with this finding. Recommendation: We recommend that the University implement a control to ensure data is being reviewed for accuracy by the appropriate personnel before roster files are submitted to the NSLDS. In addition, we recommend that the University submit roster files on a regular basis. Views of responsible officials and planned corrective actions: Regarding the status change for the identified graduate, management implemented a new process for reporting student enrollments. The Office of Institutional Research reviews the specifications for reporting from the National Student Clearinghouse (NSC) and National Student Loan Data System (NSLDS) to ensure that the proper data is being reported. Reports are generated by Institutional Research and upon approval of the Registrar submitted to the NSC. Any errors are remediated by the Registrar. And the Financial Aid Office verifies that reports sent to the National Student Clearinghouse are accurately reported to the National Student Loan Data System, by auditing both systems with assistance from the Office of institutional Research and Office of the Registrar. This process was implemented in February 2023. However, the timing of that fix occurred after the student in question had already graduated, meaning they were not included in the corrective measures. For the Return of Title IV (R2T4) calculation process, management has updated our procedures to ensure that student enrollment status is promptly updated when an R2T4 is completed. Specifically, a required step was added in the R2T4 process where a designated box is checked in the system, flagging the student’s account for withdrawal status reporting. This change helps ensure timely and accurate reporting of enrollment status to NSLDS. Completion Date: October 1, 2024 Responsible Official: Robert Giesting, Executive Director of Institutional Assessment and Learning
Show full finding ▾Hide full finding ▴Finding 2024-002 Federal Program: U.S. Department of Education - Student Financial Aid Cluster: Federal Direct Loan Program, 84.268 Criteria: The University is required to comply with 36 CFR Section 685.309(b). Condition: During our testing of unofficial withdrawals and student status changes for graduates, we selected four and 22 samples, respectively, and we noted one instance in each testing section where a students status change was not timely reported to the National Student Loan Database System (NSLDS). Cause: The University did not have controls in place to ensure students' classification were being properly reported to the NSLDS. Effect: Student status changes were not reported within the required timeframe under federal regulations. The provisions of 34 CFR Section 685.309(b) were not followed and thus two students were not reported timely and subsequently not placed into loan repayment status in a timely manner. Questioned Costs: There were no questioned costs associated with this finding. Recommendation: We recommend that the University implement a control to ensure data is being reviewed for accuracy by the appropriate personnel before roster files are submitted to the NSLDS. In addition, we recommend that the University submit roster files on a regular basis. Views of responsible officials and planned corrective actions: Regarding the status change for the identified graduate, management implemented a new process for reporting student enrollments. The Office of Institutional Research reviews the specifications for reporting from the National Student Clearinghouse (NSC) and National Student Loan Data System (NSLDS) to ensure that the proper data is being reported. Reports are generated by Institutional Research and upon approval of the Registrar submitted to the NSC. Any errors are remediated by the Registrar. And the Financial Aid Office verifies that reports sent to the National Student Clearinghouse are accurately reported to the National Student Loan Data System, by auditing both systems with assistance from the Office of institutional Research and Office of the Registrar. This process was implemented in February 2023. However, the timing of that fix occurred after the student in question had already graduated, meaning they were not included in the corrective measures. For the Return of Title IV (R2T4) calculation process, management has updated our procedures to ensure that student enrollment status is promptly updated when an R2T4 is completed. Specifically, a required step was added in the R2T4 process where a designated box is checked in the system, flagging the student’s account for withdrawal status reporting. This change helps ensure timely and accurate reporting of enrollment status to NSLDS. Completion Date: October 1, 2024 Responsible Official: Robert Giesting, Executive Director of Institutional Assessment and Learning
Identifying Number: 2024-002 Finding: Federal Program: U.S. Department of Education - Student Financial Aid Cluster: Federal Direct Loan Program, 84.268 Criteria: The University is required to comply with 36 CFR Section 685.309(b). Condition: During our testing of unofficial withdrawals and student status changes for graduates, we selected four and 22 samples, respectively, and we noted one instance in each testing section where a student’s status change was not timely reported to the National Student Loan Database System (NSLDS). Cause: The University did not have controls in place to ensure students' classification were being properly reported to the NSLDS. Effect: Student status changes were not reported within the required timeframe under federal regulations. The provisions of 34 CFR Section 685.309(b) were not followed and thus two students were not reported timely and subsequently not placed into loan repayment status in a timely manner. Questioned Costs: There were no questioned costs associated with this finding. Recommendation: We recommend that the University implement a control to ensure data is being reviewed for accuracy by the appropriate personnel before roster files are submitted to the NSLDS. In addition, we recommend that the University submit roster files on a regular basis. Corrective Actions Taken or Planned: Regarding the status change for the identified graduate, management implemented a new process for reporting student enrollments. The Office of Institutional Research reviews the specifications for reporting from the National Student Clearinghouse (NSC) and National Student Loan Data System (NSLDS) to ensure that the proper data is being reported. Reports are generated by Institutional Research and upon approval of the Registrar submitted to the NSC. Any errors are remediated by the Registrar. And the Financial Aid Office verifies that reports sent to the National Student Clearinghouse are accurately reported to the National Student Loan Data System, by auditing both systems with assistance from the Office of institutional Research and Office of the Registrar. This process was implemented in February 2023. However, the timing of that fix occurred after the student in question had already graduated, meaning they were not included in the corrective measures. For the Return of Title IV (R2T4) calculation process, management has updated our procedures to ensure that student enrollment status is promptly updated when an R2T4 is completed. Specifically, a required step was added in the R2T4 process where a designated box is checked in the system, flagging the student’s account for withdrawal status reporting. This change helps ensure timely and accurate reporting of enrollment status to NSLDS. Completion Date: October 1, 2024 Responsible Official: Robert Giesting, Executive Director of Institutional Assessment and Learning
FAC accepted this audit on February 8, 2024 — management decision was due August 8, 2024.
During our audit procedures, we noted that a GLBA compliance risk assessment was not performed within the last fiscal year. Various vulnerability assessments have been conducted since 2020, however updated GLBA compliance guidance has more specific requirements for what must be performed as part of an IT risk assessment in order to identify reasonable, foreseeable internal and external risks to the security, confidentiality, and integrity of student information that addresses the following areas: a. Information systems, including network and software design, as well as information processing, storage, transmission and disposal. b. Detecting, preventing and responding to attacks, intrusions, or other systems failures. c. Documented safeguards for each identified risk. d. Appropriate mitigated risk levels for each identified risk. Updated GLBA guidance requires that a Qualified Individual who oversees the Information Security Program makes a written report to the Board of Trustees on the status of the Information Security Program at least annually. Lastly, in reviewing the University's Information Security Program and IT policies, it was noted that four attributes were not appropriately documented for GLBA compliance: a. Conduct a periodic inventory of data, noting where its collected, stored, or transmitted. b. Encrypt customer information on the University's system and when it's in transit. c. Assess apps developed by the University. d. Implement multi-factor authentication for anyone accessing customer information on the University's system. Cause: The University did not have controls in place to ensure all GLBA requirements were met. Effect: The University is not in compliance with GLBA requirements. Recommendation: We recommend the following to ensure compliance with GLBA requirements: a. The University conduct an annual IT risk assessment that includes all components required by GLBA and periodically update the Information Security Program in response to identified risks. b. Ensure the status of the University's Information Security Program is reported, in writing, to the Board of Trustees at least annually and that the Qualified Individual signs off on this report. c. Update the policy library to ensure that the policies are appropriately documented to reduce the risk of GLBA noncompliance. Views of responsible officials and planned corrective actions: The University agrees that GLBA requirements are to be implemented and has taken steps to change the process. See corrective action plan.
Show full finding ▾Hide full finding ▴Finding 2023-001 Federal Program: U.S. Department of Education - Student Financial Aid Cluster: Federal Pell Grant, 84.063 Federal Supplemental Education Opportunity Grant, 84.007 Federal Work Study Program, 84.033 Federal Perkins Loan Program, 84.038 Federal Direct Loan Program, 84.268 Nursing Student Loan Program, 93.364 Scholarships for Disadvantaged Students, 93.925 Criteria: The University is required to comply with the Gramm-Leach-Bliley Act (GLBA) section 16 CFR 314.4(b). Condition: During our audit procedures, we noted that a GLBA compliance risk assessment was not performed within the last fiscal year. Various vulnerability assessments have been conducted since 2020, however updated GLBA compliance guidance has more specific requirements for what must be performed as part of an IT risk assessment in order to identify reasonable, foreseeable internal and external risks to the security, confidentiality, and integrity of student information that addresses the following areas: a. Information systems, including network and software design, as well as information processing, storage, transmission and disposal. b. Detecting, preventing and responding to attacks, intrusions, or other systems failures. c. Documented safeguards for each identified risk. d. Appropriate mitigated risk levels for each identified risk. Updated GLBA guidance requires that a Qualified Individual who oversees the Information Security Program makes a written report to the Board of Trustees on the status of the Information Security Program at least annually. Lastly, in reviewing the University's Information Security Program and IT policies, it was noted that four attributes were not appropriately documented for GLBA compliance: a. Conduct a periodic inventory of data, noting where its collected, stored, or transmitted. b. Encrypt customer information on the University's system and when it's in transit. c. Assess apps developed by the University. d. Implement multi-factor authentication for anyone accessing customer information on the University's system. Cause: The University did not have controls in place to ensure all GLBA requirements were met. Effect: The University is not in compliance with GLBA requirements. Recommendation: We recommend the following to ensure compliance with GLBA requirements: a. The University conduct an annual IT risk assessment that includes all components required by GLBA and periodically update the Information Security Program in response to identified risks. b. Ensure the status of the University's Information Security Program is reported, in writing, to the Board of Trustees at least annually and that the Qualified Individual signs off on this report. c. Update the policy library to ensure that the policies are appropriately documented to reduce the risk of GLBA noncompliance. Views of responsible officials and planned corrective actions: The University agrees that GLBA requirements are to be implemented and has taken steps to change the process. See corrective action plan.
Criteria: The University is required to comply with the Gramm-Leach-Bliley Act (GLBA) section 16 CFR 314.4(b). Condition: A GLBA compliance risk assessment was not performed within the last fiscal year. Various vulnerability assessments have been conducted since 2020, however updated GLBA compliance guidance has more specific requirements for what must be performed as part of an IT risk assessment in order to identify reasonable, foreseeable internal and external risks to the security, confidentiality, and integrity of student information that addresses the following areas: a. Information systems, including network and software design, as well as information processing, storage, transmission and disposal. b. Detecting, preventing and responding to attacks, intrusions, or other systems failures. c. Documented safeguards for each identified risk. d. Appropriate mitigated risk levels for each identified risk. Updated GLBA guidance requires that a Qualified Individual who oversees the Information Security Program makes a written report to the Board of Trustees on the status of the Information Security Program at least annually. The University's Information Security Program and IT policies has four attributes that were not appropriately documented for GLBA compliance: a. Conduct a periodic inventory of data, noting where its collected, stored, or transmitted. b. Encrypt customer information on the University's system and when it's in transit. c. Assess apps developed by the University. d. Implement multi-factor authentication for anyone accessing customer information on the University's system. Cause: The University did not have controls in place to ensure all GLBA requirements were met. Effect: The University is not in compliance with GLBA requirements. Corrective Actions Taken or Planned: Items that have been resolved: a. Customer data, and backups of customer data, is now encrypted at rest and in transit. b. All users with access to customer data are required to use multi-factor authentication.c. The University password policy has been updated to strengthen passwords and increase minimum length to 12 characters with complexity. The University has also implemented a tool to block the reuse of compromised passwords from the HIBP database. Items to be resolved: a. An update on the University’s information security program draft has been shared with the Board of Trustees and a final report will be issued by February 1, 2024. b. The University has begun an inventory of customer data and systems storing customer data. The University does not have any University developed apps that handle or store customer data (this will be documented in the customer data inventory). This inventory will be completed by April 15, 2024. c. The University is evaluating proposals for an assessment to include a risk assessment and internal and external vulnerability scans. The IT risk assessment is planned to be completed by June 1, 2024. d. Updated GLBA policies, including a disaster recovery policy, will be completed by June 1, 2024 Person Responsible for Implementing Correction Action: Ezra Krumhansl, Chief Financial Officer Implementation Date: Through June 1, 2024
FAC accepted this audit on January 5, 2023 — management decision was due July 5, 2023.
Reference Number: 2022-001 Federal Agency: Department of Education Program Name (AL #): Student Financial Aid Cluster (AL No. Various) Federal Award Year: July 1, 2021 to June 30, 2022 Federal Award Number: P268K221492, P268K231492, P063P201492, P063P211492 Compliance Requirement: Enrollment Reporting Criteria: Per 34 CFR 690.83(b)(2) and 34 CFR 685.309, Institutions are required to report enrollment information under the Pell grant and the Direct loan programs via the National Student Loan Data System (NSLDS) (OMB No. 1845-0035). Institutions must review, update, and verify student enrollment statuses, program information, and effective dates that appear on the Enrollment Reporting Roster file or on the Enrollment Maintenance page of the NSLDS Professional Access (NSLDSFAP) website which the financial aid administrator can access for the auditor. Cause: The University?s monitoring control over enrollment reporting was not operating effectively during fiscal year 2022. Context: For 5 out of 25 students tested for NSLDS reporting, it was noted that these students were not reported within 60 days as required for all schools participating in Title IV aid. Crowe had management perform an independent analysis in order to quantify the total number of students with enrollment reporting issues due to the 5 identified as part of our testing. Through further testing procedures performed and analysis performed by management it was noted that a total of 38 students were not reported timely to the NSLDS. Effect or Potential Effect: The administration of the Title IV programs depends heavily on the accuracy and timeliness of the enrollment information reported by institutions. Inaccurate reporting or not timely reporting student status changes to NSLDS will have an impact on the timeliness of the student entering repayment. Recommendation: We recommend that the University enhance its review and monitoring of the enrollment reporting to NSLDS to ascertain accuracy and timeliness of the submission. We recommend management perform a review of the students after being reported to NSLDS to ensure that were accurately and timely reporting as well as implement a monitoring control internally to ensure all students who changed stated are properly identified and reported to the NSLDS. Views of Responsible Officials and Planned Corrective Actions: The University agrees that accurate enrollment reporting is required and has taken steps to change the process. See corrective action plan.
Show full finding ▾Hide full finding ▴Reference Number: 2022-001 Federal Agency: Department of Education Program Name (AL #): Student Financial Aid Cluster (AL No. Various) Federal Award Year: July 1, 2021 to June 30, 2022 Federal Award Number: P268K221492, P268K231492, P063P201492, P063P211492 Compliance Requirement: Enrollment Reporting Criteria: Per 34 CFR 690.83(b)(2) and 34 CFR 685.309, Institutions are required to report enrollment information under the Pell grant and the Direct loan programs via the National Student Loan Data System (NSLDS) (OMB No. 1845-0035). Institutions must review, update, and verify student enrollment statuses, program information, and effective dates that appear on the Enrollment Reporting Roster file or on the Enrollment Maintenance page of the NSLDS Professional Access (NSLDSFAP) website which the financial aid administrator can access for the auditor. Cause: The University?s monitoring control over enrollment reporting was not operating effectively during fiscal year 2022. Context: For 5 out of 25 students tested for NSLDS reporting, it was noted that these students were not reported within 60 days as required for all schools participating in Title IV aid. Crowe had management perform an independent analysis in order to quantify the total number of students with enrollment reporting issues due to the 5 identified as part of our testing. Through further testing procedures performed and analysis performed by management it was noted that a total of 38 students were not reported timely to the NSLDS. Effect or Potential Effect: The administration of the Title IV programs depends heavily on the accuracy and timeliness of the enrollment information reported by institutions. Inaccurate reporting or not timely reporting student status changes to NSLDS will have an impact on the timeliness of the student entering repayment. Recommendation: We recommend that the University enhance its review and monitoring of the enrollment reporting to NSLDS to ascertain accuracy and timeliness of the submission. We recommend management perform a review of the students after being reported to NSLDS to ensure that were accurately and timely reporting as well as implement a monitoring control internally to ensure all students who changed stated are properly identified and reported to the NSLDS. Views of Responsible Officials and Planned Corrective Actions: The University agrees that accurate enrollment reporting is required and has taken steps to change the process. See corrective action plan.
Finding 2022-001: Enrollment reporting Condition: For 5 out of 25 students tested for NSLDS reporting, it was noted that these students were not reported within 60 days as required for all schools participating in Title IV aid. Crowe had management perform an independent analysis in order to quantify the total number of students with enrollment reporting issues due to the 5 identified as part of our testing. Through further testing procedures performed and analysis performed by management it was noted that a total of 38 students were not reported timely to the NSLDS. Recommendation: We recommend that the University enhance its review and monitoring of the enrollment reporting to NSLDS to ascertain accuracy and timeliness of the submission. Views of Responsible Officials Management agrees with the finding related to enrollment reporting. Management has taken steps to change the process, adding review of filings by the Office of the Registrar, Financial aid, and Institutional Research. Additionally, a calendar has been created for future reporting dates of enrollment reports and degree conferral reports to be filed with the National Student Clearinghouse. Corrective Action Plan Management is developing a new process for reporting student enrollments. The Office of Institutional Research will review the specifications for reporting from the National Student Clearinghouse (NSC) and National Student Loan Data System (NSLDS) to ensure that the proper data is being reported. The Office of the Registrar will develop an annual calendar of filing dates for enrollment and graduation reports. Reports will be generated by Institutional Research and upon approval of the Registrar submitted to the NSC. Any errors in reporting will be remediated by the Registrar. And the Financial Aid Office will verify that reports sent to the National Student Clearinghouse are accurately reported to the National Student Loan Data System, by auditing both systems with assistance from the Office of institutional Research and Office of the Registrar. This process will be in place by February 2023.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.