← Back to home

Asbury UniversityHigher Education

EIN: 610458355

UEI: CXWFKSLNBE16

Audited by: Forvis Mazars, LLP

Oversight agency: 84 [Department of Education]

View federal awards & risk assessment →

Data as of September 2, 2026

Asbury University10 audit years8 findings1 repeat
10
Audit Years
8
Total Findings
1
Repeat Findings
$13M
Federal Awards Expended (FY 2025)

FY 2025-06-30

$12,988,474 federal awards expendedNo findings recorded this year

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 30, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 30, 2026 (26 days from today).

What is a management decision? →

FY 2024-06-30

LOW-RISK AUDITEE$11,447,465 federal awards expendedNo findings recorded this year

FAC accepted this audit on November 1, 2024 — management decision was due May 1, 2025.

FY 2023-06-30

$9,777,150 federal awards expended

FAC accepted this audit on November 27, 2023 — management decision was due May 27, 2024.

2023-002
Special Tests & Provisions
SIGNIFICANT DEFICIENCYOTHER MATTERS

During our testing of eligibility, we noted 5 TEACH Grant recipients of 5 sampled did not have the proper time of disbursement reported on COD. The students were also not notified of their right to cancel. Cause: 5 students disbursement dates were improperly report to COD and were not notified of their right to cancel. Effect: The provisions of 36 Section 686.37(a) and 36 CFR Section 686.31(e) were not followed and thus 5 students TEACH disbursements were not properly reported to COD and were not notified of their right to cancel. Recommendation: We recommend the University report to COD monthly the disbursement dates of grants, as well as update their notification to students to include wording about the students right to cancel. Views of Responsible Officials: The financial aid office has had turnover in positions. Submitting a disbursement date adjustment file for TEACH Grant disbursements was missed in training the new employee. This has been corrected and a disbursement date adjustment file is sent after each TEACH Grant disbursement is made to a student's ledger. We have manually reviewed TEACH Grant recipients for the 2022-2023 at COD to insure that our ledger and COD are in agreement. Personnel responsible: Leslie Kurtz, Director of Financial Aid, with appropriate staff.

Show full finding ▾
Full finding narrative

Finding 2023-002 Federal Program: U.S. Department of Education: TEACH Grant Criteria: The University must comply with 36 Section 686.37(a) and 36 CFR Section 686.31(e). Condition: During our testing of eligibility, we noted 5 TEACH Grant recipients of 5 sampled did not have the proper time of disbursement reported on COD. The students were also not notified of their right to cancel. Cause: 5 students disbursement dates were improperly report to COD and were not notified of their right to cancel. Effect: The provisions of 36 Section 686.37(a) and 36 CFR Section 686.31(e) were not followed and thus 5 students TEACH disbursements were not properly reported to COD and were not notified of their right to cancel. Recommendation: We recommend the University report to COD monthly the disbursement dates of grants, as well as update their notification to students to include wording about the students right to cancel. Views of Responsible Officials: The financial aid office has had turnover in positions. Submitting a disbursement date adjustment file for TEACH Grant disbursements was missed in training the new employee. This has been corrected and a disbursement date adjustment file is sent after each TEACH Grant disbursement is made to a student's ledger. We have manually reviewed TEACH Grant recipients for the 2022-2023 at COD to insure that our ledger and COD are in agreement. Personnel responsible: Leslie Kurtz, Director of Financial Aid, with appropriate staff.

Corrective Action Plan

Asbury University's Financial Aid office has had a turnover in positions. Submitting a disbursement date adjustment file for TEACH Grant disbursements was missed in training Dawn Hopkins the new Financial Aid Specialist. Leslie Kurtz (Director of Financial Aid) has shown Ms. Hopkins how to create and transmit a TEACH Grant adjustment file to COD. Ms. Hopkins sent a file to correct the 22-23 disbursement dates on July 14, 2023. Ms. Hopkins also updated her desk manual on July 14, 2023, adding the steps to create and submit a disbursement date adjustment file after each TEACH Grant is disbursed to a student's ledger. Leslie Kurtz and Dawn Hopkins have manually reviewed TEACH Grant recipients for the 22-23 at COD to ensure that our ledger and COD are in agreement. On July 14, 2023, Leslie Kurtz modified the receipt that is sent to students to indicate that they have the right to cancel the TEACH Grant by notifying our office.

About Special Tests and Provisions →

FY 2022-06-30

LOW-RISK AUDITEE$12,958,813 federal awards expendedNo findings recorded this year

FAC accepted this audit on May 30, 2023 — management decision was due November 30, 2023.

FY 2021-06-30

LOW-RISK AUDITEE$12,521,955 federal awards expendedNo findings recorded this year

FAC accepted this audit on November 28, 2021 — management decision was due May 28, 2022.

FY 2020-06-30

LOW-RISK AUDITEE$12,904,978 federal awards expendedNo findings recorded this year

FAC accepted this audit on August 8, 2021 — management decision was due February 8, 2022.

FY 2019-06-30

$11,860,021 federal awards expended

FAC accepted this audit on November 19, 2019 — management decision was due May 19, 2020.

2019-001
Special Tests & Provisions
SIGNIFICANT DEFICIENCY

During our audit procedures, we noted the following conditions: - The University's IT risk assessment did not address information processing. The University should identify risks and safeguards associated with information processing. -The risks and safeguards with the University's risk assessment does not have a risk level assigned to any of the risks. Each risk should be assigned a risk level (high, medium, or low) to determine if the risk has been mitigated to an acceptable level. Cause: The University has not included all necessary required parts of a risk assessment. Effect: - If the University's risk assessment does not include information processing risks and safeguards, then the University will not meet the GLBA compliance standard thus impacting their security maturity level. - If risks are not assigned a risk level, the University will not be able to determine vulnerabilities that need to be mitigated. Recommendation: We have the following recommendations: - The University should update the IT risk assessment to ensure it includes risks and corresponding safeguards as it relates to information processing. -All risks that are identified within the IT risk assessment should be assigned a risk level to determine if they have been mitigated to an acceptable level. If a risk is not mitigated to an acceptable level, then either an action item should be documented or a conclusion should be made that the risk has been accepted and will be reevaluated annually. View of Responsible Officials: We agree with this finding and recommendation. Refer to Corrective Action Plan for planned response.

Show full finding ▾
Full finding narrative

Finding 2019-001 Federal Program: U.S. Department of Education - Student Financial Aid - Cluster Criteria: The University must comply with Gramm-Leach-Bliley Act (GLBA) section 16 CRF 314.4(b) Condition: During our audit procedures, we noted the following conditions: - The University's IT risk assessment did not address information processing. The University should identify risks and safeguards associated with information processing. -The risks and safeguards with the University's risk assessment does not have a risk level assigned to any of the risks. Each risk should be assigned a risk level (high, medium, or low) to determine if the risk has been mitigated to an acceptable level. Cause: The University has not included all necessary required parts of a risk assessment. Effect: - If the University's risk assessment does not include information processing risks and safeguards, then the University will not meet the GLBA compliance standard thus impacting their security maturity level. - If risks are not assigned a risk level, the University will not be able to determine vulnerabilities that need to be mitigated. Recommendation: We have the following recommendations: - The University should update the IT risk assessment to ensure it includes risks and corresponding safeguards as it relates to information processing. -All risks that are identified within the IT risk assessment should be assigned a risk level to determine if they have been mitigated to an acceptable level. If a risk is not mitigated to an acceptable level, then either an action item should be documented or a conclusion should be made that the risk has been accepted and will be reevaluated annually. View of Responsible Officials: We agree with this finding and recommendation. Refer to Corrective Action Plan for planned response.

Corrective Action Plan

Identifying Number: 2019-001 Finding: During our audit procedures, we noted the following conditions: ? The University's IT risk assessment did not address information processing. The University should identify risks and safeguards associated with information processing. ? The risks and safeguards with the University's risk assessment does not have a risk level assigned to any of the risks. Each risk should be assigned a risk level (high, medium, or low) to determine if the risk has been mitigated to an acceptable level. Corrective Actions Taken or Planned: On September 13, 2019, the Assistant VP of Information Technology updated the Risk Assessment document, adding a specific item for Information Processing in the Information Systems section. The September 13, 2019 updated document included a risk level (high, medium, or low) for each risk pre-mitigation, a description of mitigation activity, and a risk level (high, medium or low) for each risk post-mitigation. The VP for Business Affairs approved the updated document on October 11, 2019. This document will be reviewed and updated annually, as part of the IT Risk Assessment process that takes place at the end of each fiscal year. Name of Responsible Person: Paul Dupree ?AVP for Information Technology Services Implementation Date: October 11, 2019

About Special Tests and Provisions →

FY 2018-06-30

$13,370,004 federal awards expendedNo findings recorded this year

FAC accepted this audit on November 14, 2018 — management decision was due May 14, 2019.

FY 2017-06-30

LOW-RISK AUDITEE$13,531,485 federal awards expendedNo findings recorded this year

FAC accepted this audit on January 22, 2018 — management decision was due July 22, 2018.

FY 2016-06-30

LOW-RISK AUDITEE$15,667,466 federal awards expended

FAC accepted this audit on January 24, 2017 — management decision was due July 24, 2017.

2016-001
Special Tests & Provisions
REPEAT OF 2015-001OTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-001

About Special Tests and Provisions →
2016-002
Special Tests & Provisions
OTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →
2016-003
Special Tests & Provisions
OTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →
2016-004
Reporting
OTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Reporting →
2016-005
Special Tests & Provisions
OTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →
2016-006
Cash Management
OTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Cash Management →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Browse other Single Audit organizations in Kentucky

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Add it to a monitored group and get alerted when a new audit, finding, repeat finding, or management-decision deadline shows up — instead of checking back.

Checking several at once? Portfolio view →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.