EIN: 610458355
UEI: CXWFKSLNBE16
Audited by: Forvis Mazars, LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of September 2, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 30, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 30, 2026 (26 days from today).
What is a management decision? →FAC accepted this audit on November 1, 2024 — management decision was due May 1, 2025.
FAC accepted this audit on November 27, 2023 — management decision was due May 27, 2024.
During our testing of eligibility, we noted 5 TEACH Grant recipients of 5 sampled did not have the proper time of disbursement reported on COD. The students were also not notified of their right to cancel. Cause: 5 students disbursement dates were improperly report to COD and were not notified of their right to cancel. Effect: The provisions of 36 Section 686.37(a) and 36 CFR Section 686.31(e) were not followed and thus 5 students TEACH disbursements were not properly reported to COD and were not notified of their right to cancel. Recommendation: We recommend the University report to COD monthly the disbursement dates of grants, as well as update their notification to students to include wording about the students right to cancel. Views of Responsible Officials: The financial aid office has had turnover in positions. Submitting a disbursement date adjustment file for TEACH Grant disbursements was missed in training the new employee. This has been corrected and a disbursement date adjustment file is sent after each TEACH Grant disbursement is made to a student's ledger. We have manually reviewed TEACH Grant recipients for the 2022-2023 at COD to insure that our ledger and COD are in agreement. Personnel responsible: Leslie Kurtz, Director of Financial Aid, with appropriate staff.
Show full finding ▾Hide full finding ▴Finding 2023-002 Federal Program: U.S. Department of Education: TEACH Grant Criteria: The University must comply with 36 Section 686.37(a) and 36 CFR Section 686.31(e). Condition: During our testing of eligibility, we noted 5 TEACH Grant recipients of 5 sampled did not have the proper time of disbursement reported on COD. The students were also not notified of their right to cancel. Cause: 5 students disbursement dates were improperly report to COD and were not notified of their right to cancel. Effect: The provisions of 36 Section 686.37(a) and 36 CFR Section 686.31(e) were not followed and thus 5 students TEACH disbursements were not properly reported to COD and were not notified of their right to cancel. Recommendation: We recommend the University report to COD monthly the disbursement dates of grants, as well as update their notification to students to include wording about the students right to cancel. Views of Responsible Officials: The financial aid office has had turnover in positions. Submitting a disbursement date adjustment file for TEACH Grant disbursements was missed in training the new employee. This has been corrected and a disbursement date adjustment file is sent after each TEACH Grant disbursement is made to a student's ledger. We have manually reviewed TEACH Grant recipients for the 2022-2023 at COD to insure that our ledger and COD are in agreement. Personnel responsible: Leslie Kurtz, Director of Financial Aid, with appropriate staff.
Asbury University's Financial Aid office has had a turnover in positions. Submitting a disbursement date adjustment file for TEACH Grant disbursements was missed in training Dawn Hopkins the new Financial Aid Specialist. Leslie Kurtz (Director of Financial Aid) has shown Ms. Hopkins how to create and transmit a TEACH Grant adjustment file to COD. Ms. Hopkins sent a file to correct the 22-23 disbursement dates on July 14, 2023. Ms. Hopkins also updated her desk manual on July 14, 2023, adding the steps to create and submit a disbursement date adjustment file after each TEACH Grant is disbursed to a student's ledger. Leslie Kurtz and Dawn Hopkins have manually reviewed TEACH Grant recipients for the 22-23 at COD to ensure that our ledger and COD are in agreement. On July 14, 2023, Leslie Kurtz modified the receipt that is sent to students to indicate that they have the right to cancel the TEACH Grant by notifying our office.
FAC accepted this audit on May 30, 2023 — management decision was due November 30, 2023.
FAC accepted this audit on November 28, 2021 — management decision was due May 28, 2022.
FAC accepted this audit on August 8, 2021 — management decision was due February 8, 2022.
FAC accepted this audit on November 19, 2019 — management decision was due May 19, 2020.
During our audit procedures, we noted the following conditions: - The University's IT risk assessment did not address information processing. The University should identify risks and safeguards associated with information processing. -The risks and safeguards with the University's risk assessment does not have a risk level assigned to any of the risks. Each risk should be assigned a risk level (high, medium, or low) to determine if the risk has been mitigated to an acceptable level. Cause: The University has not included all necessary required parts of a risk assessment. Effect: - If the University's risk assessment does not include information processing risks and safeguards, then the University will not meet the GLBA compliance standard thus impacting their security maturity level. - If risks are not assigned a risk level, the University will not be able to determine vulnerabilities that need to be mitigated. Recommendation: We have the following recommendations: - The University should update the IT risk assessment to ensure it includes risks and corresponding safeguards as it relates to information processing. -All risks that are identified within the IT risk assessment should be assigned a risk level to determine if they have been mitigated to an acceptable level. If a risk is not mitigated to an acceptable level, then either an action item should be documented or a conclusion should be made that the risk has been accepted and will be reevaluated annually. View of Responsible Officials: We agree with this finding and recommendation. Refer to Corrective Action Plan for planned response.
Show full finding ▾Hide full finding ▴Finding 2019-001 Federal Program: U.S. Department of Education - Student Financial Aid - Cluster Criteria: The University must comply with Gramm-Leach-Bliley Act (GLBA) section 16 CRF 314.4(b) Condition: During our audit procedures, we noted the following conditions: - The University's IT risk assessment did not address information processing. The University should identify risks and safeguards associated with information processing. -The risks and safeguards with the University's risk assessment does not have a risk level assigned to any of the risks. Each risk should be assigned a risk level (high, medium, or low) to determine if the risk has been mitigated to an acceptable level. Cause: The University has not included all necessary required parts of a risk assessment. Effect: - If the University's risk assessment does not include information processing risks and safeguards, then the University will not meet the GLBA compliance standard thus impacting their security maturity level. - If risks are not assigned a risk level, the University will not be able to determine vulnerabilities that need to be mitigated. Recommendation: We have the following recommendations: - The University should update the IT risk assessment to ensure it includes risks and corresponding safeguards as it relates to information processing. -All risks that are identified within the IT risk assessment should be assigned a risk level to determine if they have been mitigated to an acceptable level. If a risk is not mitigated to an acceptable level, then either an action item should be documented or a conclusion should be made that the risk has been accepted and will be reevaluated annually. View of Responsible Officials: We agree with this finding and recommendation. Refer to Corrective Action Plan for planned response.
Identifying Number: 2019-001 Finding: During our audit procedures, we noted the following conditions: ? The University's IT risk assessment did not address information processing. The University should identify risks and safeguards associated with information processing. ? The risks and safeguards with the University's risk assessment does not have a risk level assigned to any of the risks. Each risk should be assigned a risk level (high, medium, or low) to determine if the risk has been mitigated to an acceptable level. Corrective Actions Taken or Planned: On September 13, 2019, the Assistant VP of Information Technology updated the Risk Assessment document, adding a specific item for Information Processing in the Information Systems section. The September 13, 2019 updated document included a risk level (high, medium, or low) for each risk pre-mitigation, a description of mitigation activity, and a risk level (high, medium or low) for each risk post-mitigation. The VP for Business Affairs approved the updated document on October 11, 2019. This document will be reviewed and updated annually, as part of the IT Risk Assessment process that takes place at the end of each fiscal year. Name of Responsible Person: Paul Dupree ?AVP for Information Technology Services Implementation Date: October 11, 2019
FAC accepted this audit on November 14, 2018 — management decision was due May 14, 2019.
FAC accepted this audit on January 22, 2018 — management decision was due July 22, 2018.
FAC accepted this audit on January 24, 2017 — management decision was due July 24, 2017.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-001
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in Kentucky →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Add it to a monitored group and get alerted when a new audit, finding, repeat finding, or management-decision deadline shows up — instead of checking back.
Checking several at once? Portfolio view →
© 2026 Single Audit Intelligence. All data is public domain.