EIN: 626001104
UEI: SBRWLVZNE847
Data as of August 22, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on January 6, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by July 6, 2025 (413 days ago).
What is a management decision? →During the audit, it was noted that the University’s Gramm-Leach-Bliley Act Policy did not fully address all of the requirements as described by 16 CFR 314.4. In addition, the application of the comprehensive information security program was not effectively administered by the University during the 2024 year. An updated policy was put into place in July 2024, which addressed several of the deficiencies noted in the existing policy, but not all. The seven required elements for the GLBA policy are as follows, along with the status within each of the University’s policies in place during the year: 1. The policy designates a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance. Both the existing policy and the newly implemented sufficiently address this attribute. Luke Edwards, IT director, and Tim Fisher, IT Systems Analyst, work together to oversee the information security program and implementation of additional facets. 2. The policy provides for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. This attribute was addressed in the existing policy but was not considered to be sufficient; the newly implemented policy does sufficiently address this requirement. Additional risk assessments are planned to be performed every 2 years to reexamine reasonably foreseeable risks and to account for changes in cybersecurity controls. The next risk assessment shall be completed by December 31, 2025. 3. The policy provides for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8), which are detailed as follows: 3.1. Implement and periodically review access controls. This attribute was not addressed in the existing policy; the newly implemented policy does address this requirement, instituting a continuous monitoring process undertaken at periodic intervals. The University has contracted with a new software to assist with this, which is expected to be live by December 31, 2024. 3.2. Conduct a periodic inventory of data, noting where it is collected, stored or transmitted. Both the existing policy and the newly implemented policy are silent on this requirement. Resolution to this matter is expected to be addressed and incorporated into the policy by December 31, 2024. 3.3. Encrypt customer information on the institution’s system and when it is in transit. This attribute was not addressed in the existing policy; the newly implemented policy does address this requirement. The University has had encryption in transit for several years but has not had encryption at rest. In October 2023, the University purchased licenses to enable encryption at rest and most virtual machines containing sensitive data were fully encrypted by April 30, 2024. The remaining virtual machines are planned to be encrypted by December 31, 2024. 3.4. Assess applications developed by the institution. Both the existing policy and the newly implemented policy are silent on this requirement. However, the University does not develop in-house applications for transmitting, accessing, or storing customer information. 3.5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. Both the existing policy and the newly implemented policy are silent on this requirement. However, the University utilizes multi-factor authentication on all connections to the server where student information system is accessed, as well as administrative and financial applications. 3.6. Dispose of customer information securely. Both the existing policy and the newly implemented policy are silent on this requirement. Evaluation of organizational data retention policies for effectiveness is ongoing and expected to be completed by December 31, 2024. Future evaluations for the effectiveness of data retention policies will take place every other year in a joint venture with the Finance and IT Departments. 3.7. Anticipate and evaluate changes to the information system or network. This attribute was not addressed in the existing policy; the newly implemented policy does address this requirement. Official policies should be in place by December 31, 2024. 3.8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. Both the existing policy and the newly implemented policy are silent on this requirement. Office 365 user logging has been in place; sign-ins to on-premises resources was implemented in March 2024. IT has processes in place for addressing suspicious activity. 4. The policy provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented. This attribute was addressed in the existing policy but was not considered to be sufficient; the newly implemented policy does sufficiently address this requirement. 5. The policy provides for the implementation of policies and procedures to ensure that personnel are able to enact the information security program. Both the existing policy and the newly implemented sufficiently address this attribute. Software has been purchased and implemented for continuous monitoring of vulnerabilities within organizational software. 6. The policy addresses how the institution will oversee its information system service providers. This attribute was addressed in the existing policy but was not considered to be sufficient; the newly implemented policy does sufficiently address this requirement. Collection of SOC2 security reports from vendors that have access to systems with student information is in progress. The collection and analysis of these reports is expected to be completed by December 31, 2024. Review of these reports is planned to be conducted annually, with requests for updated security reports every 3 years. 7. The policy provides for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program. Both the existing policy and the newly implemented sufficiently address this attribute. Status reports regarding facets of the information security policy are provided to senior leadership team members and to the board at least annually at their regularly scheduled meetings. Questioned Costs: Such information is not applicable for this finding since it is nonmonetary in nature. Perspective Information: The 2024 audit included testing of the University’s Gramm-Leach-Bliley Act Policy as outlined in Part 5 of the Compliance Supplement including the application of this program for the year. Cause and Effect: During the current year, the responsible parties began putting procedures into place and drafted an updated policy to ensure deficiencies in the information security policy are addressed. As this process requires the coordination of multiple individuals, software systems, and approvals, the updates were unable to be completed by June 30, 2024. Recommendation: The University should continue to update their Gramm-Leach-Bliley Act Policy to be in accordance with the requirements and put in place effective controls and practices to ensure the policy is monitored in a way to ensure it is administered effectively and timely. View of Responsible Officials: The Johnson University IT Department has consistently worked to improve compliance with GLBA regulations since July 2023. The leadership of Johnson University has taken a proactive and measured approach to GLBA compliance that ensures a balance between reaching compliance quickly and reaching compliance with long-term strategic planning. This has led to a GLBA implementation that will take 2 or more years but will set up the university for long-term excellence in compliance and security. The University understands the importance of GLBA requirements and is committed to ensuring student data is protected from all foreseeable threats. It will continue to iterate on its GLBA corrective action plan to ensure proper compliance for long-term security.
Show full finding ▾Hide full finding ▴2024-001 Significant Deficiency: Gramm-Leach-Bliley Act (GLBA) (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268) (Repeat Finding: 2023-001) Criteria: In accordance with 16 CFR 314.4, a University shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards that are appropriate to your size and complexity, the nature and scope of your activities, and the sensitivity of any customer information at issue and must contain all of the elements that are further described in 16 CFR 314.4. Statement of Condition: During the audit, it was noted that the University’s Gramm-Leach-Bliley Act Policy did not fully address all of the requirements as described by 16 CFR 314.4. In addition, the application of the comprehensive information security program was not effectively administered by the University during the 2024 year. An updated policy was put into place in July 2024, which addressed several of the deficiencies noted in the existing policy, but not all. The seven required elements for the GLBA policy are as follows, along with the status within each of the University’s policies in place during the year: 1. The policy designates a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance. Both the existing policy and the newly implemented sufficiently address this attribute. Luke Edwards, IT director, and Tim Fisher, IT Systems Analyst, work together to oversee the information security program and implementation of additional facets. 2. The policy provides for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. This attribute was addressed in the existing policy but was not considered to be sufficient; the newly implemented policy does sufficiently address this requirement. Additional risk assessments are planned to be performed every 2 years to reexamine reasonably foreseeable risks and to account for changes in cybersecurity controls. The next risk assessment shall be completed by December 31, 2025. 3. The policy provides for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8), which are detailed as follows: 3.1. Implement and periodically review access controls. This attribute was not addressed in the existing policy; the newly implemented policy does address this requirement, instituting a continuous monitoring process undertaken at periodic intervals. The University has contracted with a new software to assist with this, which is expected to be live by December 31, 2024. 3.2. Conduct a periodic inventory of data, noting where it is collected, stored or transmitted. Both the existing policy and the newly implemented policy are silent on this requirement. Resolution to this matter is expected to be addressed and incorporated into the policy by December 31, 2024. 3.3. Encrypt customer information on the institution’s system and when it is in transit. This attribute was not addressed in the existing policy; the newly implemented policy does address this requirement. The University has had encryption in transit for several years but has not had encryption at rest. In October 2023, the University purchased licenses to enable encryption at rest and most virtual machines containing sensitive data were fully encrypted by April 30, 2024. The remaining virtual machines are planned to be encrypted by December 31, 2024. 3.4. Assess applications developed by the institution. Both the existing policy and the newly implemented policy are silent on this requirement. However, the University does not develop in-house applications for transmitting, accessing, or storing customer information. 3.5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. Both the existing policy and the newly implemented policy are silent on this requirement. However, the University utilizes multi-factor authentication on all connections to the server where student information system is accessed, as well as administrative and financial applications. 3.6. Dispose of customer information securely. Both the existing policy and the newly implemented policy are silent on this requirement. Evaluation of organizational data retention policies for effectiveness is ongoing and expected to be completed by December 31, 2024. Future evaluations for the effectiveness of data retention policies will take place every other year in a joint venture with the Finance and IT Departments. 3.7. Anticipate and evaluate changes to the information system or network. This attribute was not addressed in the existing policy; the newly implemented policy does address this requirement. Official policies should be in place by December 31, 2024. 3.8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. Both the existing policy and the newly implemented policy are silent on this requirement. Office 365 user logging has been in place; sign-ins to on-premises resources was implemented in March 2024. IT has processes in place for addressing suspicious activity. 4. The policy provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented. This attribute was addressed in the existing policy but was not considered to be sufficient; the newly implemented policy does sufficiently address this requirement. 5. The policy provides for the implementation of policies and procedures to ensure that personnel are able to enact the information security program. Both the existing policy and the newly implemented sufficiently address this attribute. Software has been purchased and implemented for continuous monitoring of vulnerabilities within organizational software. 6. The policy addresses how the institution will oversee its information system service providers. This attribute was addressed in the existing policy but was not considered to be sufficient; the newly implemented policy does sufficiently address this requirement. Collection of SOC2 security reports from vendors that have access to systems with student information is in progress. The collection and analysis of these reports is expected to be completed by December 31, 2024. Review of these reports is planned to be conducted annually, with requests for updated security reports every 3 years. 7. The policy provides for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program. Both the existing policy and the newly implemented sufficiently address this attribute. Status reports regarding facets of the information security policy are provided to senior leadership team members and to the board at least annually at their regularly scheduled meetings. Questioned Costs: Such information is not applicable for this finding since it is nonmonetary in nature. Perspective Information: The 2024 audit included testing of the University’s Gramm-Leach-Bliley Act Policy as outlined in Part 5 of the Compliance Supplement including the application of this program for the year. Cause and Effect: During the current year, the responsible parties began putting procedures into place and drafted an updated policy to ensure deficiencies in the information security policy are addressed. As this process requires the coordination of multiple individuals, software systems, and approvals, the updates were unable to be completed by June 30, 2024. Recommendation: The University should continue to update their Gramm-Leach-Bliley Act Policy to be in accordance with the requirements and put in place effective controls and practices to ensure the policy is monitored in a way to ensure it is administered effectively and timely. View of Responsible Officials: The Johnson University IT Department has consistently worked to improve compliance with GLBA regulations since July 2023. The leadership of Johnson University has taken a proactive and measured approach to GLBA compliance that ensures a balance between reaching compliance quickly and reaching compliance with long-term strategic planning. This has led to a GLBA implementation that will take 2 or more years but will set up the university for long-term excellence in compliance and security. The University understands the importance of GLBA requirements and is committed to ensuring student data is protected from all foreseeable threats. It will continue to iterate on its GLBA corrective action plan to ensure proper compliance for long-term security.
Finding Reference Number: 2024-001 Initial Fiscal Year: 2023 Summary of Finding: Significant Deficiency: Gramm-Leach-Bliley Act (GLBA) (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268) (Repeat Finding: 2023-001) In accordance with 16 CFR 314.4, a University shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards that are appropriate to your size and complexity, the nature and scope of your activities, and the sensitivity of any customer information at issue and must contain all of the elements that are further described in 16 CFR 314.4 During the audit, it was noted that the University’s Gramm-Leach-Bliley Act Policy did not fully address all of the requirements as described by 16 CFR 314.4. In addition, the application of the comprehensive information security program was not effectively administered by the University during the 2024 year. An updated policy was put into place in July 2024, which addressed several of the deficiencies noted in the existing policy, but not all. The University should continue to update their Gramm-Leach-Bliley Act Policy to be in accordance with the requirements and put in place effective controls and practices to ensure the policy is monitored in a way to ensure it is administered effectively and timely. Entity’s Corrective Action Plan: The Johnson University IT Department has consistently worked to improve compliance with GLBA regulations since July 2023. The leadership of Johnson University has taken a proactive and measured approach to GLBA compliance that ensures a balance between reaching compliance quickly and reaching compliance with long-term strategic planning. This has led to a GLBA implementation that will take 2 or more years but will set up the university for long-term excellence in compliance and security. The University understands the importance of GLBA requirements and is committed to ensuring student data is protected from all foreseeable threats. It will continue to iterate on its GLBA corrective action plan to ensure proper compliance for long-term security. The Johnson University IT Department has developed a plan to address deficiencies in GLBA compliance in each of the following areas: Requirement 1 - Qualified Individual: 16 CFR 314.4(a) Johnson University has designated Tim Fisher as our Qualified Individual. Tim Fisher is an employee of Johnson University, serving in the IT Systems Analyst role, and will work alongside Johnson University’s IT Director to oversee the information security program and its implementation. While Tim has over 15 years of on-the-job cybersecurity experience, additional training resources have already been provided to Tim Fisher to pursue the CompTIA Security+ certification. Tim Fisher expects to complete the training and gain the certification by the end of 2025. This was deemed sufficient for GLBA compliance in the audit report provided by Blackburn, Childers & Steagall, PLC dated November 6, 2024. Note from 2024 audit report: “Both the existing policy and the newly implemented sufficiently address this attribute.” Requirement 2 - Risk Assessment: 16 CFR 314.4(b) Johnson University partnered with HORNE, a cybersecurity company, to conduct a risk assessment in November 2023. The assessment covered several topics and recorded inherent risk levels, existing mitigating controls, and the residual risk levels of each topic covered. Residual risk levels, the level of risk existing despite the existing controls, were found to be considered high in termination procedures and review of security logs. GLBA policy development and implementation decisions were based heavily on this initial risk assessment. A more comprehensive cybersecurity company with experience serving customers in Higher Education, DeapSeas, has been selected for ongoing cybersecurity assistance and will be conducting future risk assessments. Additional risk assessments are planned to be performed every 2 years to reexamine reasonably foreseeable risks and to account for changes in cybersecurity controls. The next risk assessment shall be completed by the end of 2025. Note from 2024 audit report: “This attribute was addressed in the existing policy but was not considered to be sufficient; the newly implemented policy does sufficiently address this requirement. Requirement 3.1 - Access Controls: 16 CFR 314.4(c)(1) Johnson University policy ensures that employee supervisors dictate appropriate access for each employee to the IT Department when they are hired or change positions. Supervisors are responsible for ensuring employees have appropriate access to locations where sensitive information is stored, such as file servers and Jenzabar (Student Information System) software access. The IT Department processes permission changes and does not provide permissions without explicit request from the employee supervisor. Auditing existing permissions is a weak spot that has, in the past, taken hours of manual work. We have purchased software, AD Manager, to assist with access reviews. We expect this software to be ready to audit necessary permission groups by the end of 2024. This should significantly reduce the time it takes to audit permissions through additional reporting and easy remediation features. Note from 2024 audit report: “This attribute was not addressed in the existing policy; the newly implemented policy does address this requirement, instituting a continuous monitoring process undertaken at periodic intervals. The University has contracted with a new software to assist with this, which is expected to be live by December 31, 2024. Note from JU IT: Requirement 3.1, access control reviews, is complicated as each department supervisor is responsible for setting access permissions. The IT Department will need to engage department supervisors for review and approval. Due to the transition in the I.T. Director position, the expectation to be live should be adjusted to March 31, 2025. Requirement 3.2 – Data Identification: 16 CFR 314.4(c)(2) Informal identification has been completed by the IT Department through generalized asset inventory procedures. DeapSeas, our selected cybersecurity vendor, has been contracted to conduct a more formal data identification procedure in early 2025. This will identify critical items and analyze risks and responsibilities associated with each party. This procedure will take place through scanning the corporate network and interviewing departments on their data storage procedures. Note from 2024 audit report: “Both the existing policy and the newly implemented policy are silent on this requirement. Resolution to this matter is expected to be addressed and incorporated into the policy by December 31, 2024.” Note from JU IT: For requirement 3.2, data inventory, we’re already under contract with DeapSeas to do this. It will be completed by March 31, 2025. Requirement 3.3 – Encryption: 16 CFR 314.4(c)(3) Johnson University has had encryption in transit for several years but has not had encryption at rest. Johnson University purchased licenses to enable encryption at rest in October 2023 and finished a project to encrypt most virtual machines containing sensitive data using AES-256 and XTS-AES-256 encryption on April 29, 2024. The remaining virtual machines are planned to be encrypted before the end of 2024. Note from 2024 audit report: “This attribute was not addressed in the existing policy; the newly implemented policy does address this requirement.” Requirement 3.4 – Secure Development: 16 CFR 314.4(c)(4) Johnson University does not develop in-house applications for transmitting, accessing, or storing customer information. A combination of the risk assessment, vendor analysis, and penetration testing will assess the security of externally developed applications. The risk assessment has already been completed, but further vendor analysis and penetration testing are planned to be completed by the end of June 2025. Note from 2024 audit report: “Both the existing policy and the newly implemented policy are silent on this requirement. However, the University does not develop in-house applications for transmitting, accessing, or storing customer information.” Requirement 3.5 – Multi-factor Authentication: 16 CFR 314.4(c)(5) Johnson University has enabled multi-factor authentication on all connections to the server where our student information system (Jenzabar One) is accessed. Multi-factor authentication is also enabled for all logins to Office 365 and integrated applications, such as Zoom videoconferencing, our student/employee portal, Jenzabar Financial Aid (financial aid management system), and Jenzabar Recruitment (admissions software). Multi-factor authentication is also enabled on connections to our administrative systems, such as our network firewall, hypervisor, door access control, and security camera management systems. With multi-factor authentication requirements for all these systems, we believe that multi-factor authentication is enabled on all critical systems to protect student information. Evaluation of low-risk systems, such as our classroom audiovisual systems, for feasibility of multi-factor authentication are ongoing and expect to be completed by the end of 2024. Note from 2024 audit report: “Both the existing policy and the newly implemented policy are silent on this requirement. However, the University utilizes multi-factor authentication on all connections to the server where student information system is accessed, as well as administrative and financial applications.” Requirement 3.6 – Data Retention: 16 CFR 314.4(c)(6) Organizational data retention policies, developed by the Finance Department, are currently in effect. These policies were originally written for other means but have some overlap with GLBA regulations. Evaluation of these policies for effectiveness is ongoing and expected to be completed by the end of 2024. Future evaluations for the effectiveness of data retention policies will take place every other year in a joint venture with the Finance and IT Departments. Note from 2024 audit report: “Both the existing policy and the newly implemented policy are silent on this requirement. Evaluation of organizational data retention policies for effectiveness is ongoing and expected to be completed by December 31, 2024. Note from JU IT: Requirement 3.6, data retention policies, will require collaboration between Finance and IT. Finance’s existing policies on data retention need to be enhanced. This just takes time and decisions from the CFO (how long to retain and when to delete – IT will be enforcing the policy technically). Evaluation will be completed by June 30, 2025. Requirement 3.7 – Change Management: 16 CFR 314.4(c)(7) Change management procedures have been discussed and official policies are being developed. Evaluation of security risk and risk of downtime or other degradation of service are being considered in change management procedures. Official policies should be in place in 2025. Note from 2024 audit report: “This attribute was not addressed in the existing policy; the newly implemented policy does address this requirement. Official policies should be in place by December 31, 2024. Note from JU IT: A change management plan will be completed by March 31, 2025. Requirement 3.8 – User Logging: 16 CFR 314.4(c)(8) User logging is in place for all log-ins to Office 365 log-ins to its services and integrated applications. Microsoft Entra sign-in risk and user-risk policies are in place to enforce stronger security measures during sign-in, force password resets, or deny sign-ins altogether based on risk analysis. Sign-ins to on-premises resources are logged through new software, Log360, implemented in March 2024. Log360 analyses log-ins and sends notifications to IT Department technicians via email for suspicious activity. IT will then process these reports to take appropriate action to resolve the threat unless there is sufficient evidence of a false positive. Note from 2024 audit report: “Both the existing policy and the newly implemented policy are silent on this requirement. Office 365 user logging has been in place; sign-ins to on-premises resources was implemented in March 2024. IT has processes in place for addressing suspicious activity.” Requirement 4 – Security Assessment: 16 CFR 314.4(d)(1) DeapSeas, a cybersecurity vendor, has been chosen to conduct security assessments. A security assessment is planned for early 2025. Ongoing, internal security assessments are planned on an annual basis to be conducted by the IT Department. These assessments will assist in evaluating the effectiveness of existing controls and the ongoing development of the security program. Software has also been purchased and implemented for continuous monitoring of vulnerabilities within organizational software. The software, Vulnerability Manager, provides notice of known vulnerabilities and available patches for software installed on devices within our organization. These notifications are distributed through the software and through email. Automated and semi-automated patches are available through the software to be deployed to organizational devices over the internet. Patching known vulnerabilities within our software portfolio is a priority for us. This system should reduce overall risk and patch effectiveness will be verified with penetration testing. Our first annual penetration test is planned for early 2025. Note from 2024 audit report: “This attribute was addressed in the existing policy but was not considered to be sufficient; the newly implemented policy does sufficiently address this requirement. Requirement 5 – Security Training: 16 CFR 314.4(e) Security training has been made mandatory for all employees beginning in Fall 2024. Security training is done through our online video training platform, KnowBe4. This system allows for video, quizzes, and other learning material to be presented to the employees. KnowBe4 develops this content and ensures accuracy and appropriateness. Johnson University IT Department selects available materials and assigns them to employees. Security training was last updated after the initial risk assessment and will be reviewed every 6 months. Note from 2024 audit report: “Both the existing policy and the newly implemented sufficiently address this attribute.” Requirement 6 – Service Providers: 16 CFR 314.4(f) Collection of SOC2 security reports from vendors that have access to systems with student information is in progress. The collection and analysis of these reports is expected to be completed by the end of 2024. Review of these reports is planned to be conducted annually, with requests for updated security reports every 3 years. \ Note from 2024 audit report: “This attribute was addressed in the existing policy but was not considered to be sufficient; the newly implemented policy does sufficiently address this requirement. Requirement 7 – Security Control Monitoring: 16 CFR 314.4(g) Security controls are being monitored using Log360 wherever possible. Continuous evaluation of these controls is underway and adjustments will be made to security controls as needed. New change management policies and penetration testing will influence the way we evaluate these controls and will likely include changes to monitoring systems and evaluation methods. Note from 2024 audit report: “Both the existing policy and the newly implemented sufficiently address this attribute.” Anticipated Completion Date: Fall 2026 Name and Title of Responsible Person: Luke Edwards, Director of IT.
2023-001
During the audit, it was noted that the University used the incorrect number of completed days in the payment period or period of enrollment in calculating the percentage of the Title IV aid earned. Questioned Costs: This finding is monetary in nature. In the instances noted in testing, the total error identified is $1,992 in over-award. Extrapolation of this monetary error was not necessary as the 5 withdrawal students tested as part of the 2024 audit constitute the entire withdrawal population for the period under audit. This does not exceed the $25,000 reporting threshold for monetary error within Federal Award Programs. Perspective Information: The audit included a detailed testing of 5 withdrawal student files, of which this significant deficiency applies to 1, indicating an error rate of 20.0%. This does exceed the reporting threshold of 10% for Federal Award Programs. Cause and Effect: For one withdrawal calculation performed, the day count for days completed by the student was not performed per the instructions described in the Student Financial Aid Handbook. The student identified was enrolled in multiple modules within the same term. The individual withdrew from all classes enrolled in the earlier module, returned at the start of the second module, and then withdrew from the latter module and therefore, the University. At this time, an R2T4 was completed and in calculating completed days for the student, the University did not reduce the calculation of calendar days completed for the break between the withdrawal from the first module and the beginning of the second module. The use of an incorrect number of completed calendar days results in a miscalculation of percentage of Title IV aid earned and may additionally result in monetary error. Recommendation: The University should ensure that the number of completed days in the payment period or period of enrollment are counted correctly utilizing the guidance provided by the Compliance Supplement and the Student Financial Aid Handbook. View of Responsible Officials: The University has determined that this matter constitutes a unique training situation involving the application of procedures related to the Return of Title IV funds. In particular, the University recognizes the need for enhanced training concerning the accurate counting of days when a student withdraws, provides written notification of their intent to attend a future module within the same term, and subsequently withdraws from that second module. The error in question arose from the miscalculation of days, where the University inadvertently counted all days in the initial module rather than counting only the days leading up to the student's initial withdrawal prior to the final withdrawal from the second module. This oversight was attributed to an individual employee, and the University has proactively implemented comprehensive training and procedural safeguards to prevent similar occurrences in the future.
Show full finding ▾Hide full finding ▴2024-002 Significant Deficiency: Return to Title IV Funds (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268; Federal Pell Grant Program, ALN #84.063) Criteria: In accordance with 34 CFR 668.22(f), in the calculation of the percentage of payment period and/or period of enrollment completed, the total number of calendar days in a payment and/or enrollment period includes all days within the period, except that institutionally scheduled breaks of at least 5 consecutive calendar days and days in which the student was on an approved leave of absence are excluded from the total number of calendar days in a payment period and/or period of enrollment. Statement of Condition: During the audit, it was noted that the University used the incorrect number of completed days in the payment period or period of enrollment in calculating the percentage of the Title IV aid earned. Questioned Costs: This finding is monetary in nature. In the instances noted in testing, the total error identified is $1,992 in over-award. Extrapolation of this monetary error was not necessary as the 5 withdrawal students tested as part of the 2024 audit constitute the entire withdrawal population for the period under audit. This does not exceed the $25,000 reporting threshold for monetary error within Federal Award Programs. Perspective Information: The audit included a detailed testing of 5 withdrawal student files, of which this significant deficiency applies to 1, indicating an error rate of 20.0%. This does exceed the reporting threshold of 10% for Federal Award Programs. Cause and Effect: For one withdrawal calculation performed, the day count for days completed by the student was not performed per the instructions described in the Student Financial Aid Handbook. The student identified was enrolled in multiple modules within the same term. The individual withdrew from all classes enrolled in the earlier module, returned at the start of the second module, and then withdrew from the latter module and therefore, the University. At this time, an R2T4 was completed and in calculating completed days for the student, the University did not reduce the calculation of calendar days completed for the break between the withdrawal from the first module and the beginning of the second module. The use of an incorrect number of completed calendar days results in a miscalculation of percentage of Title IV aid earned and may additionally result in monetary error. Recommendation: The University should ensure that the number of completed days in the payment period or period of enrollment are counted correctly utilizing the guidance provided by the Compliance Supplement and the Student Financial Aid Handbook. View of Responsible Officials: The University has determined that this matter constitutes a unique training situation involving the application of procedures related to the Return of Title IV funds. In particular, the University recognizes the need for enhanced training concerning the accurate counting of days when a student withdraws, provides written notification of their intent to attend a future module within the same term, and subsequently withdraws from that second module. The error in question arose from the miscalculation of days, where the University inadvertently counted all days in the initial module rather than counting only the days leading up to the student's initial withdrawal prior to the final withdrawal from the second module. This oversight was attributed to an individual employee, and the University has proactively implemented comprehensive training and procedural safeguards to prevent similar occurrences in the future.
Finding Reference Number: 2024-002 Initial Fiscal Year: 2024 Summary of Finding: 2024-002 Significant Deficiency: Return to Title IV Funds (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268; Federal Pell Grant Program, ALN #84.063) In accordance with 34 CFR 668.22(f), in the calculation of the percentage of payment period and/or period of enrollment completed, the total number of calendar days in a payment and/or enrollment period includes all days within the period, except that institutionally scheduled breaks of at least 5 consecutive calendar days and days in which the student was on an approved leave of absence are excluded from the total number of calendar days in a payment period and/or period of enrollment. During the audit, it was noted that the University used the incorrect number of completed days in the payment period or period of enrollment in calculating the percentage of the Title IV aid earned. The audit included a detailed testing of 5 withdrawal student files, of which this significant deficiency applies to 1, indicating an error rate of 20.0%. This finding is monetary in nature. In the instances noted in testing, the total error identified is $1,992 in over-award. Extrapolation of this monetary error was not necessary as the 5 withdrawal students tested as part of the 2024 audit constitute the entire withdrawal population for the period under audit. The University should ensure that the number of completed days in the payment period or period of enrollment are counted correctly utilizing the guidance provided by the Compliance Supplement and the Student Financial Aid Handbook. Entity’s Corrective Action Plan: Corrective Action Plan Summary: The University has determined that this matter constitutes a unique training situation involving the application of procedures related to the Return of Title IV funds. In particular, the University recognizes the need for enhanced training concerning the accurate counting of days when a student withdraws, provides written notification of their intent to attend a future module within the same term, and subsequently withdraws from that second module. The error in question arose from the miscalculation of days, where the University inadvertently counted all days in the initial module rather than counting only the days leading up to the student's initial withdrawal prior to the final withdrawal from the second module. This oversight was attributed to an individual employee, and the University has proactively implemented comprehensive training and procedural safeguards to prevent similar occurrences in the future. Anticipated Completion Date: August 01, 2024 The corrective action plan has been implemented to resolve the prior year finding, helping to ensure that future dates are accurate. Name and Title of Responsible Person: Rocky Christensen, Director of Financial Aid.
During the audit, it was noted that the University did not fulfill maximum award of students’ Direct Subsidized Loan eligibility prior to awarding Unsubsidized Direct Loans. Questioned Costs: This finding is monetary in nature. In the instances noted in testing, the total error is $5,983 in under-award. Extrapolation of this monetary error estimates a total potential error of $54,614. This exceeds the $25,000 reporting threshold for monetary error within Federal Award Programs. Perspective Information: The audit included a detailed testing of 32 files for undergraduate students who had received Unsubsidized Direct Loans, of which this significant deficiency applies to 3, indicating an error rate of 9.4%. This does not exceed the reporting threshold of 10% for Federal Award Programs. Recommendation: The University should institute processes and controls to ensure that the student eligibility is assessed properly based upon grade level progression and that maximum Subsidized Direct Loans are awarded prior to Unsubsidized Direct Loans, as this practice is more beneficial for the student. Cause and Effect: For one of the three students identified, the student was a transfer into the University from another institution for the 2023-24 school year. The student’s transcript was not received prior to awarding, so the student was awarded as a first-year student; once received, the award was not adjusted to reflect the credit hours previously earned by the student. Since the handbook states that the student eligibility must match the credit hours recognized academically by the receiving institution, this resulted in an under-award of Subsidized Direct Loans. For another of the three students identified, a system error resulted in an under-award. The error was not noticed by the responsible parties, so correction was not made, resulting in an under-award of Subsidized Direct Loans. For the final of the three students identified, the student received the full amount of aggregate annual Direct Loan eligibility as Unsubsidized Direct Loans. The student was a first-year student with adequate calculated need to receive the maximum Direct Subsidized Loans. This oversight results in an under-award of Subsidized Direct Loan, which should have been reclassified from Unsubsidized Direct Loans. View of Responsible Officials: The University has determined that this finding was caused by a deficiency in the software’s calculation of the subsidized award. Specifically, the software failed to update the student’s records following changes in circumstances that impacted the calculation of financial need. In response, the University has conducted a thorough evaluation and implemented new software designed to address this issue and ensure accurate calculations in future cases.
Show full finding ▾Hide full finding ▴2024-003 Significant Deficiency: Direct Loan Limits (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268) Criteria: In accordance with the Federal Student Aid Handbook, Volume 3, Chapter 3, you must determine an undergraduate student’s Pell Grant eligibility before originating a Direct Subsidized or Unsubsidized Loan for that student, and you must package Campus-Based funds and Direct Subsidized Loans before Direct Unsubsidized Loans. In addition, you must determine an undergraduate student’s maximum Direct Subsidized Loan eligibility before originating a Direct Unsubsidized Loan for the student. The student’s maximum annual loan limit increases as the student progresses to higher grade levels. Statement of Condition: During the audit, it was noted that the University did not fulfill maximum award of students’ Direct Subsidized Loan eligibility prior to awarding Unsubsidized Direct Loans. Questioned Costs: This finding is monetary in nature. In the instances noted in testing, the total error is $5,983 in under-award. Extrapolation of this monetary error estimates a total potential error of $54,614. This exceeds the $25,000 reporting threshold for monetary error within Federal Award Programs. Perspective Information: The audit included a detailed testing of 32 files for undergraduate students who had received Unsubsidized Direct Loans, of which this significant deficiency applies to 3, indicating an error rate of 9.4%. This does not exceed the reporting threshold of 10% for Federal Award Programs. Recommendation: The University should institute processes and controls to ensure that the student eligibility is assessed properly based upon grade level progression and that maximum Subsidized Direct Loans are awarded prior to Unsubsidized Direct Loans, as this practice is more beneficial for the student. Cause and Effect: For one of the three students identified, the student was a transfer into the University from another institution for the 2023-24 school year. The student’s transcript was not received prior to awarding, so the student was awarded as a first-year student; once received, the award was not adjusted to reflect the credit hours previously earned by the student. Since the handbook states that the student eligibility must match the credit hours recognized academically by the receiving institution, this resulted in an under-award of Subsidized Direct Loans. For another of the three students identified, a system error resulted in an under-award. The error was not noticed by the responsible parties, so correction was not made, resulting in an under-award of Subsidized Direct Loans. For the final of the three students identified, the student received the full amount of aggregate annual Direct Loan eligibility as Unsubsidized Direct Loans. The student was a first-year student with adequate calculated need to receive the maximum Direct Subsidized Loans. This oversight results in an under-award of Subsidized Direct Loan, which should have been reclassified from Unsubsidized Direct Loans. View of Responsible Officials: The University has determined that this finding was caused by a deficiency in the software’s calculation of the subsidized award. Specifically, the software failed to update the student’s records following changes in circumstances that impacted the calculation of financial need. In response, the University has conducted a thorough evaluation and implemented new software designed to address this issue and ensure accurate calculations in future cases.
Finding Reference Number: 2024-003 Initial Fiscal Year: 2024 Summary of Finding: 2024-003 Significant Deficiency: Direct Loan Limits (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268) In accordance with the Federal Student Aid Handbook, Volume 3, Chapter 3, you must determine an undergraduate student’s Pell Grant eligibility before originating a Direct Subsidized or Unsubsidized Loan for that student, and you must package Campus-Based funds and Direct Subsidized Loans before Direct Unsubsidized Loans. In addition, you must determine an undergraduate student’s maximum Direct Subsidized Loan eligibility before originating a Direct Unsubsidized Loan for the student. The student’s maximum annual loan limit increases as the student progresses to higher grade levels. During the audit, it was noted that the University did not fulfill maximum award of students’ Direct Subsidized Loan eligibility prior to awarding Unsubsidized Direct Loans for 3 of the 32 applicable students tested, which is a 9.4% error rate. This finding is monetary in nature. In the instances noted in testing, the total error is $5,983 in under-award. Extrapolation of this monetary error estimates a total potential error of $54,614. The University should institute processes and controls to ensure that the student eligibility is assessed properly based upon grade level progression and that maximum Subsidized Direct Loans are awarded prior to Unsubsidized Direct Loans, as this practice is more beneficial for the student. Entity’s Corrective Action Plan: Corrective Action Plan Summary: The University has determined that this finding was caused by a deficiency in the software’s calculation of the subsidized award. Specifically, the software failed to update the student’s records following changes in circumstances that impacted the calculation of financial need. In response, the University has conducted a thorough evaluation and implemented new software designed to address this issue and ensure accurate calculations in future cases. Anticipated Completion Date: November 1, 2024 The corrective action plan has been implemented to resolve the prior year finding, helping to ensure that future dates are accurate. Name and Title of Responsible Person: Rocky Christensen, Director of Financial Aid.
During the 2024 audit, it was noted that certain students who had received Direct Loan funds and/or TEACH grant funds did not receive disbursement notifications. Questioned Costs: Such information is not applicable for this finding since it is nonmonetary in nature. Perspective Information: The 2024 audit included a detailed testing of 38 applicable student files, of which this significant deficiency applies to 13, indicating an error rate of 34.2%. Cause and Effect: Due to a system failure during the Spring semester, many students did not receive notification from the University of Direct Loan or TEACH Grant disbursements made to their account. This glitch was not recognized by the responsible parties in a timely manner to manually create and disburse such notification. The purpose of disbursement notifications is to provide information to students and parents regarding their accounts and options they may have concerning Title IV aid. Neglecting to provide the disbursement notifications may result in students or parents making uninformed decisions. Recommendation: The University should ensure system functionality periodically, specifically entering periods in which disbursements are concentrated, such as the beginning of the semester, to prevent lapses in mass. The University should also create a process to verify that disbursement notifications have been distributed as intended, so that any missed notices can be remedied timely. View of Responsible Officials: The University has taken a comprehensive and proactive approach to address this issue through two key initiatives. First, we have instituted a robust audit process designed to ensure the integrity and functionality of the system responsible for documenting sent emails. This process enables us to systematically verify that the system is operating as intended. Second, we have deployed advanced software solutions that serve to mitigate the risk of similar issues arising in the future. These combined measures reflect our commitment to ensuring operational reliability and preventing recurrence.
Show full finding ▾Hide full finding ▴2024-004 Significant Deficiency: Disbursement Notifications (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268; U.S. Department of Education, Teacher Education Assistance for College and Higher Education Grants, ALN #84.379) (Repeat Finding: 2023-005) Criteria: In accordance with 34 CFR 668.165(a)(2), when a University credits a student’s account, the University must notify the student or parent of (i) the anticipated date and amount of the disbursement, (ii) the student’s or parent’s rights to cancel all or a portion of that loan or disbursement, and (iii) the procedures and time by which the student or parent must notify the University that he or she wishes to cancel the loan or disbursement. This communication must occur no earlier than 30 days before, and no later than seven days after, crediting the student’s ledger account at the institution if the institution does not obtain affirmative confirmation from the student. Statement of Condition: During the 2024 audit, it was noted that certain students who had received Direct Loan funds and/or TEACH grant funds did not receive disbursement notifications. Questioned Costs: Such information is not applicable for this finding since it is nonmonetary in nature. Perspective Information: The 2024 audit included a detailed testing of 38 applicable student files, of which this significant deficiency applies to 13, indicating an error rate of 34.2%. Cause and Effect: Due to a system failure during the Spring semester, many students did not receive notification from the University of Direct Loan or TEACH Grant disbursements made to their account. This glitch was not recognized by the responsible parties in a timely manner to manually create and disburse such notification. The purpose of disbursement notifications is to provide information to students and parents regarding their accounts and options they may have concerning Title IV aid. Neglecting to provide the disbursement notifications may result in students or parents making uninformed decisions. Recommendation: The University should ensure system functionality periodically, specifically entering periods in which disbursements are concentrated, such as the beginning of the semester, to prevent lapses in mass. The University should also create a process to verify that disbursement notifications have been distributed as intended, so that any missed notices can be remedied timely. View of Responsible Officials: The University has taken a comprehensive and proactive approach to address this issue through two key initiatives. First, we have instituted a robust audit process designed to ensure the integrity and functionality of the system responsible for documenting sent emails. This process enables us to systematically verify that the system is operating as intended. Second, we have deployed advanced software solutions that serve to mitigate the risk of similar issues arising in the future. These combined measures reflect our commitment to ensuring operational reliability and preventing recurrence.
Finding Reference Number: 2024-004 Initial Fiscal Year: 2023 Summary of Finding: Significant Deficiency: Disbursement Notifications (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268; U.S. Department of Education, Teacher Education Assistance for College and Higher Education Grants, ALN #84.379) (Repeat Finding: 2023-005) In accordance with 34 CFR 668.165(a)(2), when a University credits a student’s account, the University must notify the student or parent of (i) the anticipated date and amount of the disbursement, (ii) the student’s or parent’s rights to cancel all or a portion of that loan or disbursement, and (iii) the procedures and time by which the student or parent must notify the University that he or she wishes to cancel the loan or disbursement. This communication must occur no earlier than 30 days before, and no later than seven days after, crediting the student’s ledger account at the institution if the institution does not obtain affirmative confirmation from the student. During the 2024 audit, it was noted that 13 of 38 students, or 34.2%, who had received Direct Loan funds and/or TEACH grant funds did not receive disbursement notifications due to a system failure. The failure was not noticed to be able to remedy the situation timely. The University should ensure system functionality periodically, specifically entering periods in which disbursements are concentrated, such as the beginning of the semester, to prevent lapses in mass. The University should also create a process to verify that disbursement notifications have been distributed as intended, so that any missed notices can be remedied timely. Entity’s Corrective Action Plan Corrective Action Plan Summary: The University has taken a comprehensive and proactive approach to address this issue through two key initiatives. First, we have instituted a robust audit process designed to ensure the integrity and functionality of the system responsible for documenting sent emails. This process enables us to systematically verify that the system is operating as intended. Second, we have deployed advanced software solutions that serve to mitigate the risk of similar issues arising in the future. These combined measures reflect our commitment to ensuring operational reliability and preventing recurrence. Anticipated Completion Date: October 1, 2024 The corrective action plan has been implemented to resolve the prior year finding, helping to ensure that future dates are accurate. Name and Title of Responsible Person: Rocky Christensen, Director of Financial Aid
2023-005
FAC accepted this audit on January 10, 2024 — management decision was due July 10, 2024.
During the 2023 audit, it was noted that the University’s Gramm-Leach-Bliley Act Policy did not fully address all of the requirements as described by 16 CFR 314.4. In addition, the application of the comprehensive information security program was not effectively administered by the University for the 2023 year. Questioned Costs: Such information is not applicable for this finding since it is nonmonetary in nature. Perspective Information: The 2023 audit included testing of the University’s Gramm-Leach-Bliley Act Policy as outlined in Part 5 of the Compliance Supplement including the application of this program for the year. Cause and Effect: Due to oversight by the director of the program, the GLBA policy was not reviewed and updated for changes to the program as required by the Compliance Supplement. Recommendation: The University should update their Gramm-Leach-Bliley Act Policy to be in accordance with the requirements and put in place effective controls and practices to ensure the policy is monitored in a way to ensure it is administered effectively. View of Responsible Officials: Due to turnover within the IT Department, GLBA requirements were not communicated well to incoming staff or to the organization. Once GLBA requirements were discovered, a plan was developed to begin implementing GLBA controls and revise our security plan. The plan to bring the organization into GLBA compliance was developed for the 2023-2024 school year and was not in effect before this audit. The IT Department, and key stakeholders within the organization, are working to ensure GLBA compliance within the next year.
Show full finding ▾Hide full finding ▴2023-001 Material Weakness: Gramm-Leach-Bliley Act (GLBA) (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268) Criteria: In accordance with 16 CFR 314.4, a University shall develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards that are appropriate to your size and complexity, the nature and scope of your activities, and the sensitivity of any customer information at issue and must contain all of the elements that are further described in 16 CFR 314.4. Statement of Condition: During the 2023 audit, it was noted that the University’s Gramm-Leach-Bliley Act Policy did not fully address all of the requirements as described by 16 CFR 314.4. In addition, the application of the comprehensive information security program was not effectively administered by the University for the 2023 year. Questioned Costs: Such information is not applicable for this finding since it is nonmonetary in nature. Perspective Information: The 2023 audit included testing of the University’s Gramm-Leach-Bliley Act Policy as outlined in Part 5 of the Compliance Supplement including the application of this program for the year. Cause and Effect: Due to oversight by the director of the program, the GLBA policy was not reviewed and updated for changes to the program as required by the Compliance Supplement. Recommendation: The University should update their Gramm-Leach-Bliley Act Policy to be in accordance with the requirements and put in place effective controls and practices to ensure the policy is monitored in a way to ensure it is administered effectively. View of Responsible Officials: Due to turnover within the IT Department, GLBA requirements were not communicated well to incoming staff or to the organization. Once GLBA requirements were discovered, a plan was developed to begin implementing GLBA controls and revise our security plan. The plan to bring the organization into GLBA compliance was developed for the 2023-2024 school year and was not in effect before this audit. The IT Department, and key stakeholders within the organization, are working to ensure GLBA compliance within the next year.
Finding Reference Number: 2023-001 Initial Fiscal Year: 2023 Summary of Finding: Material Weakness: Gramm-Leach-Bliley Act (GLBA) (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268) Entity’s Corrective Action Plan Due to turnover within the IT Department, GLBA requirements were not communicated well to incoming staff or to the organization. Once GLBA requirements were discovered, a plan was developed to begin implementing GLBA controls and revise our security plan. The plan to bring the organization into GLBA compliance was developed for the 2023-2024 school year and was not in effect before this audit. The IT Department, and key stakeholders within the organization, are working to ensure GLBA compliance within the next year.. Anticipated Completion Date: September 21, 2023 Name and Title of Responsible Person: Luke Edwards, Director of IT.
During the 2023 audit, it was noted that the University was unable to provide supporting documentation detailing the student was offered a post-withdrawal disbursement. Questioned Costs: This finding is monetary in nature. In the instances noted in testing, the total error identified is $736 in under-award. Extrapolation of this monetary error was not necessary as the 11 withdrawal students tested as part of the 2023 audit were the entire withdrawal population for the period under audit. Perspective Information: The 2023 audit included a detailed testing of 11 withdrawal student files, of which this significant deficiency applies to 3, indicating an error rate of 27.3%. Cause and Effect: Due to the University’s lack of retention of appropriate documentation, we were unable to determine or test the post-withdrawal disbursements were appropriately offered to the affected students resulting in the inability to appropriately review the documentation to satisfy testing requirements. Recommendation: The University should maintain documentation of sending the student, or parent when applicable, notification regarding their eligibility for a post-withdrawal disbursement. View of Responsible Officials: While the University was completing this process the lack of documentation has been addressed. The University now has the student verify receipt of this information on the withdrawal form itself and has other notification procedures in place to ensure that this is completed.
Show full finding ▾Hide full finding ▴2023-002 Significant Deficiency: Documentation Regarding Offer of a Post-Withdrawal Disbursement (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268; Federal Pell Grant Program, ALN #84.063) Criteria: In accordance with 34 CFR 668.22(a)(6), a post-withdrawal disbursement must be made to the student for any grant funds they are eligible for within 45 days of the date of determination. Moreover, the University must offer to disburse directly to a student, or parent in the case of a parent PLUS loan, any amount of a post-withdrawal disbursement of loan funds that is not credited to the student’s account. The disbursement of loan funds must occur after the University received confirmation from the student’s or parent’s intentions, respectively. Statement of Condition: During the 2023 audit, it was noted that the University was unable to provide supporting documentation detailing the student was offered a post-withdrawal disbursement. Questioned Costs: This finding is monetary in nature. In the instances noted in testing, the total error identified is $736 in under-award. Extrapolation of this monetary error was not necessary as the 11 withdrawal students tested as part of the 2023 audit were the entire withdrawal population for the period under audit. Perspective Information: The 2023 audit included a detailed testing of 11 withdrawal student files, of which this significant deficiency applies to 3, indicating an error rate of 27.3%. Cause and Effect: Due to the University’s lack of retention of appropriate documentation, we were unable to determine or test the post-withdrawal disbursements were appropriately offered to the affected students resulting in the inability to appropriately review the documentation to satisfy testing requirements. Recommendation: The University should maintain documentation of sending the student, or parent when applicable, notification regarding their eligibility for a post-withdrawal disbursement. View of Responsible Officials: While the University was completing this process the lack of documentation has been addressed. The University now has the student verify receipt of this information on the withdrawal form itself and has other notification procedures in place to ensure that this is completed.
Finding Reference Number: 2023-002 Initial Fiscal Year: 2023 Summary of Finding: Significant Deficiency: Documentation Regarding Offer of a Post- Withdrawal Disbursement (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268; Federal Pell Grant Program, ALN #84.063) Entity’s Corrective Action Plan Corrective Action Plan Summary: The university was not documenting the PWD notification that happens with students as part of our exit process. While the university was completing this the lack of documentation has been addressed. The university now has the student verify receipt of this information on the withdrawal form. Anticipated Completion Date: September 21, 2023 Name and Title of Responsible Person: Rocky Christensen, Director of Financial Aid.
During the audit, it was noted that the University used the incorrect number of total days in the payment period or period of enrollment in calculating the percentage of payment period and/or period of enrollment completed for the Fall 2022 semester. Questioned Costs: This finding is monetary in nature. In the instances noted in testing, the total error identified is $116 in under-award. Extrapolation of this monetary error was not necessary as the 11 withdrawal students tested as part of the 2023 audit were the entire withdrawal population for the period under audit. Perspective Information: The audit included a detailed testing of 11 withdrawal student files, of which this significant deficiency applies to 6, indicating an error rate of 54.6%. Cause and Effect: For withdrawal calculations performed in the fall semester, the total day count was not performed per the instructions described in the Student Financial Aid Handbook. The University calculated using 109 days, while the actual number was 107 days. The use of an incorrect total number of calendar days will result in a miscalculation of percentage of Title IV aid earned and may additionally result in monetary error. Recommendation: The University should ensure that the total number of calendar days in the payment period or period of enrollment are counted correctly utilizing the guidance provided by the Compliance Supplement and the Student Financial Aid Handbook. View of Responsible Officials: When setting the R2T4 dates in the system the University had failed to count the Saturday and Sunday preceding the break period of five days or more. The University has addressed the issue for the future POE periods and implemented a three-step verification process moving forward. The three-step verification involves two additional staff verifying the dates in the system to ensure accuracy.
Show full finding ▾Hide full finding ▴2023-003 Significant Deficiency: Return to Title IV Funds (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268; Federal Pell Grant Program, ALN #84.063) Criteria: In accordance with 34 CFR 668.22(f), in the calculation of the percentage of payment period and/or period of enrollment completed, the total number of calendar days in a payment and/or enrollment period includes all days within the period, except that institutionally scheduled breaks of at least 5 consecutive calendar days and days in which the student was on an approved leave of absence are excluded from the total number of calendar days in a payment period and/or period of enrollment. Statement of Condition: During the audit, it was noted that the University used the incorrect number of total days in the payment period or period of enrollment in calculating the percentage of payment period and/or period of enrollment completed for the Fall 2022 semester. Questioned Costs: This finding is monetary in nature. In the instances noted in testing, the total error identified is $116 in under-award. Extrapolation of this monetary error was not necessary as the 11 withdrawal students tested as part of the 2023 audit were the entire withdrawal population for the period under audit. Perspective Information: The audit included a detailed testing of 11 withdrawal student files, of which this significant deficiency applies to 6, indicating an error rate of 54.6%. Cause and Effect: For withdrawal calculations performed in the fall semester, the total day count was not performed per the instructions described in the Student Financial Aid Handbook. The University calculated using 109 days, while the actual number was 107 days. The use of an incorrect total number of calendar days will result in a miscalculation of percentage of Title IV aid earned and may additionally result in monetary error. Recommendation: The University should ensure that the total number of calendar days in the payment period or period of enrollment are counted correctly utilizing the guidance provided by the Compliance Supplement and the Student Financial Aid Handbook. View of Responsible Officials: When setting the R2T4 dates in the system the University had failed to count the Saturday and Sunday preceding the break period of five days or more. The University has addressed the issue for the future POE periods and implemented a three-step verification process moving forward. The three-step verification involves two additional staff verifying the dates in the system to ensure accuracy.
Finding Reference Number: 2023-003 Initial Fiscal Year: 2023 Summary of Finding: Significant Deficiency: Return to Title IV Funds (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268; Federal Pell Grant Program, ALN #84.063) Entity’s Corrective Action Plan Corrective Action Plan Summary: When setting the R2T4 dates in the system we had failed to count the Saturday and Sunday preceding the break period of five days or more. The university has addressed the issue for the future POE periods and implemented a three step verification process moving forward. The three step verification involves two additional staff verifying the dates in the system to ensure accuracy. Anticipated Completion Date: September 21, 2023 Explanation: The corrective action plan was taken to resolve the prior year finding, helping to ensure that future dates are accurate. Name and Title of Responsible Person: Rocky Christensen, Director of Financial Aid.
During the audit, it was noted that the University did not complete an R2T4 for unofficial withdrawal students in the Spring semester until during the audit and therefore did not calculate the percentage of aid that was earned by the student. Questioned Costs: This finding is monetary in nature. In the instances noted in testing, the total error is $1,851 in over-award. Extrapolation of this monetary error was not necessary as the 11 withdrawal students tested as part of the 2023 audit were the entire withdrawal population for the period under audit. Perspective Information: The audit included a detailed testing of 11 withdrawal student files, of which this significant deficiency applies to 3, indicating an error rate of 27.3%. Cause and Effect: For unofficial withdrawals, an R2T4 was not performed per the instructions described in the Student Financial Aid Handbook in certain instances due to lack of oversight by the director. By not performing an R2T4, the University did not compute the percentage of aid that was earned by the student and this may result in monetary error. Recommendation: The University should ensure that the R2T4 calculations are being completed timely. View of Responsible Officials: When processing the R2T4s for these three students the Director looked at the current date on the form and processed them according to the current date and not the date of withdrawal. For these students due to the date difference went from being in the greater than 60% category where a R2T4 was not necessary to now needing one processed. The University has implemented an audit process whereby the date entered can be more easily verified to ensure accuracy. This date and the withdrawal date or LDA are now added to a withdrawal form that is shared between departments so that any variance will be easily identified.
Show full finding ▾Hide full finding ▴2023-004 Significant Deficiency: The University Did Not Timely Complete Return to Title IV Funds (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268; Federal Pell Grant Program, ALN #84.063) Criteria: In accordance with 34 CFR 668.22(e), the amount of title IV grant or loan assistance that is earned by the student is calculated by (i) determining the percentage of title IV grant or loan assistance that has been earned by the student and (ii) applying the percentage of the total amount of title IV grant or loan assistance that was disbursed and could have been disbursed to the student, or on the student’s behalf for the payment period or period of enrollment as of the student’s withdrawal date. Statement of Condition: During the audit, it was noted that the University did not complete an R2T4 for unofficial withdrawal students in the Spring semester until during the audit and therefore did not calculate the percentage of aid that was earned by the student. Questioned Costs: This finding is monetary in nature. In the instances noted in testing, the total error is $1,851 in over-award. Extrapolation of this monetary error was not necessary as the 11 withdrawal students tested as part of the 2023 audit were the entire withdrawal population for the period under audit. Perspective Information: The audit included a detailed testing of 11 withdrawal student files, of which this significant deficiency applies to 3, indicating an error rate of 27.3%. Cause and Effect: For unofficial withdrawals, an R2T4 was not performed per the instructions described in the Student Financial Aid Handbook in certain instances due to lack of oversight by the director. By not performing an R2T4, the University did not compute the percentage of aid that was earned by the student and this may result in monetary error. Recommendation: The University should ensure that the R2T4 calculations are being completed timely. View of Responsible Officials: When processing the R2T4s for these three students the Director looked at the current date on the form and processed them according to the current date and not the date of withdrawal. For these students due to the date difference went from being in the greater than 60% category where a R2T4 was not necessary to now needing one processed. The University has implemented an audit process whereby the date entered can be more easily verified to ensure accuracy. This date and the withdrawal date or LDA are now added to a withdrawal form that is shared between departments so that any variance will be easily identified.
Finding Reference Number: 2023-004 Initial Fiscal Year: 2023 Summary of Finding: Significant Deficiency: The University Did Not Timely Complete Return to Title IV Funds (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268, Federal Pell Grant Program, ALN #84.063) Entity’s Corrective Action Plan Corrective Action Plan Summary: When processing the R2T4s for these three students the Director looked at the current date on the form and processed them according to the current date and not the date of withdrawal. For these students due to the date difference went from being in the greater than 60% category where a R2T4 was not necessary to now needing one processed. The university has implemented an audit process where by the date entered can be more easily verified to ensure accuracy. This date and the withdrawal date or LDA are now added to a withdrawal form that is shared between departments so that any variance will be easily identified. Anticipated Completion Date: September 21, 2023 Explanation: The corrective action plan was taken to resolve the prior year finding, helping to ensure that future dates are accurate. Name and Title of Responsible Person: Rocky Christensen, Director of Financial Aid.
During the 2023 audit, it was noted that certain students who had received Direct Loan funds did not receive disbursement notifications. Questioned Costs: Such information is not applicable for this finding since it is nonmonetary in nature. Perspective Information: The 2023 audit included a detailed testing of 40 student files, of which this significant deficiency applies to 5, indicating an error rate of 12.5%. Cause and Effect: Due to the University’s lack of retention of the appropriate documentation, we were unable to determine or test the disbursement notifications for Direct Loans were made to affected students resulting in the inability to appropriately review the documentation to satisfy testing requirements. Recommendation: The University should verify and retain documentation that appropriate communication is made to students receiving Direct Loan funds. View of Responsible Officials: Once IT was made aware of the issues, we implemented changes to the process. The action code was discontinued, and our database administrator developed a custom database table used only for tracking Financial Aid communications. This custom table tracks the student’s organizational ID number, email address, communication code (MAND for mandatory loan emails), date/time the email was processed, and the status returned by the process used to send emails. Please note that this status only checks whether the process succeeded, it does not check whether the email was successfully sent. The Financial Aid Department is still copied in all emails sent at their main email address (currently FinancialAidTN@Johnsonu.edu). The Financial Aid Department has the responsibility to alert the IT Department if they are not receiving emails as expected. Once the IT Department has been alerted of an issue, the IT Department can start working to resolve the issue. For long-term reliability of communications, Johnson University has purchased and is implementing a new Financial Aid software platform. This will give us an opportunity to work towards reliable communications, not just reliable logging of process failures or successes.
Show full finding ▾Hide full finding ▴2023-005 Significant Deficiency: Disbursement Notifications (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268) Criteria: In accordance with 34 CFR 668.165(a)(2), when a University credits a student’s account, the University must notify the student or parent of (i) the anticipated date and amount of the disbursement, (ii) the student’s or parent’s rights to cancel all or a portion of that loan or disbursement, and (iii) the procedures and time by which the student or parent must notify the University that he or she wishes to cancel the loan or disbursement. This communication must occur no earlier than 30 days before, and no later than seven days after, crediting the student’s ledger account at the institution if the institution does not obtain affirmative confirmation from the student. Statement of Condition: During the 2023 audit, it was noted that certain students who had received Direct Loan funds did not receive disbursement notifications. Questioned Costs: Such information is not applicable for this finding since it is nonmonetary in nature. Perspective Information: The 2023 audit included a detailed testing of 40 student files, of which this significant deficiency applies to 5, indicating an error rate of 12.5%. Cause and Effect: Due to the University’s lack of retention of the appropriate documentation, we were unable to determine or test the disbursement notifications for Direct Loans were made to affected students resulting in the inability to appropriately review the documentation to satisfy testing requirements. Recommendation: The University should verify and retain documentation that appropriate communication is made to students receiving Direct Loan funds. View of Responsible Officials: Once IT was made aware of the issues, we implemented changes to the process. The action code was discontinued, and our database administrator developed a custom database table used only for tracking Financial Aid communications. This custom table tracks the student’s organizational ID number, email address, communication code (MAND for mandatory loan emails), date/time the email was processed, and the status returned by the process used to send emails. Please note that this status only checks whether the process succeeded, it does not check whether the email was successfully sent. The Financial Aid Department is still copied in all emails sent at their main email address (currently FinancialAidTN@Johnsonu.edu). The Financial Aid Department has the responsibility to alert the IT Department if they are not receiving emails as expected. Once the IT Department has been alerted of an issue, the IT Department can start working to resolve the issue. For long-term reliability of communications, Johnson University has purchased and is implementing a new Financial Aid software platform. This will give us an opportunity to work towards reliable communications, not just reliable logging of process failures or successes.
Finding Reference Number: 2023-005 Initial Fiscal Year: 2023 Summary of Finding: Significant Deficiency: Disbursement Notifications (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268) Entity’s Corrective Action Plan Corrective Action Plan Summary: Once IT was made aware of the issues, we implemented changes to the process. The action code was discontinued, and our database administrator developed a custom database table used only for tracking Financial Aid communications. This custom table tracks the student’s organizational ID number, email address, communication code (MAND for mandatory loan emails), date/time the email was processed, and the status returned by the process used to send emails. Please note that this status only checks whether the process succeeded, it does not check whether the email was successfully sent. The Financial Aid Department is still copied in all emails sent at their main email address (currently FinancialAidTN@Johnsonu.edu). The Financial Aid Department has the responsibility to alert the IT Department if they are not receiving emails as expected. Once the IT Department has been alerted of an issue, the IT Department can start working to resolve the issue. For long-term reliability of communications, Johnson University has purchased and is implementing a new Financial Aid software platform. This will give us an opportunity to work towards reliable communications, not just reliable logging of process failures or successes. Anticipated Completion Date: September 21, 2023 Explanation: The corrective action plan was taken to resolve the prior year finding, helping to ensure that future dates are accurate. Name and Title of Responsible Person: Luke Edwards, Director of IT.
During the 2023 audit, it was noted that certain students who had dropped below half-time enrollment or who had left the University were not provided with exit counseling in relation to outstanding federal direct loan balances. Questioned Costs: Such information is not applicable for this finding since it is nonmonetary in nature. Perspective Information: The 2023 audit included a detailed testing of 40 student files, of which this significant deficiency applies to 9, indicating an error rate of 22.5%. Cause and Effect: Due to an internal information technology error, the University was not able to maintain documentation showing that exit counseling information was sent to the affected students. Recommendation: The University should verify that appropriate communication is made to students leaving the University or lowering enrollment to less than half time, who also have outstanding federal direct loans balances, to provide each with the exit counseling resource. View of Responsible Officials: Once IT was made aware of the issues, we implemented changes to the process. The action code was discontinued, and our database administrator developed a custom database table used only for tracking Financial Aid communications. This custom table tracks the student’s organizational ID number, email address, communication code (EXIT for exit counseling emails), date/time the email was processed, and the status returned by the process used to send emails. Please note that this status only checks whether the process succeeded, it does not check whether the email was successfully sent. The Financial Aid Department is still copied in all emails sent at their main email address (currently FinancialAidTN@Johnsonu.edu). The Financial Aid Department has the responsibility to alert the IT Department if they are not receiving emails as expected. Once the IT Department has been alerted of an issue, the IT Department can start working to resolve the issue. For long-term reliability of communications, Johnson University has purchased and is implementing a new Financial Aid software platform. This will give us an opportunity to work towards reliable communications, not just reliable logging of process failures or successes.
Show full finding ▾Hide full finding ▴2023-006 Significant Deficiency: Exit Counseling (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268) Criteria: In accordance with 34 CFR 682.604(a)(1), a school must ensure that exit counseling is conducted with each borrower either in person, by audiovisual presentation, or by interactive electronic means. In each case, the school must ensure that this counseling is provided or conducted within 30 days after learning that the student borrower has withdrawn from school or dropped below half-time enrollment. Statement of Condition: During the 2023 audit, it was noted that certain students who had dropped below half-time enrollment or who had left the University were not provided with exit counseling in relation to outstanding federal direct loan balances. Questioned Costs: Such information is not applicable for this finding since it is nonmonetary in nature. Perspective Information: The 2023 audit included a detailed testing of 40 student files, of which this significant deficiency applies to 9, indicating an error rate of 22.5%. Cause and Effect: Due to an internal information technology error, the University was not able to maintain documentation showing that exit counseling information was sent to the affected students. Recommendation: The University should verify that appropriate communication is made to students leaving the University or lowering enrollment to less than half time, who also have outstanding federal direct loans balances, to provide each with the exit counseling resource. View of Responsible Officials: Once IT was made aware of the issues, we implemented changes to the process. The action code was discontinued, and our database administrator developed a custom database table used only for tracking Financial Aid communications. This custom table tracks the student’s organizational ID number, email address, communication code (EXIT for exit counseling emails), date/time the email was processed, and the status returned by the process used to send emails. Please note that this status only checks whether the process succeeded, it does not check whether the email was successfully sent. The Financial Aid Department is still copied in all emails sent at their main email address (currently FinancialAidTN@Johnsonu.edu). The Financial Aid Department has the responsibility to alert the IT Department if they are not receiving emails as expected. Once the IT Department has been alerted of an issue, the IT Department can start working to resolve the issue. For long-term reliability of communications, Johnson University has purchased and is implementing a new Financial Aid software platform. This will give us an opportunity to work towards reliable communications, not just reliable logging of process failures or successes.
Finding Reference Number: 2023-006 Initial Fiscal Year: 2023 Summary of Finding: Significant Deficiency: Exit Counseling (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268) Entity’s Corrective Action Plan Corrective Action Plan Summary: Once IT was made aware of the issues, we implemented changes to the process. The action code was discontinued, and our database administrator developed a custom database table used only for tracking Financial Aid communications. This custom table tracks the student’s organizational ID number, email address, communication code (EXIT for exit counseling emails), date/time the email was processed, and the status returned by the process used to send emails. Please note that this status only checks whether the process succeeded, it does not check whether the email was successfully sent. The Financial Aid Department is still copied in all emails sent at their main email address (currently FinancialAidTN@Johnsonu.edu). The Financial Aid Department has the responsibility to alert the IT Department if they are not receiving emails as expected. Once the IT Department has been alerted of an issue, the IT Department can start working to resolve the issue. For long-term reliability of communications, Johnson University has purchased and is implementing a new Financial Aid software platform. This will give us an opportunity to work towards reliable communications, not just reliable logging of process failures or successes. Anticipated Completion Date: September 21, 2023 Explanation: The corrective action plan was taken to resolve the prior year finding, helping to ensure that future dates are accurate. Name and Title of Responsible Person: Luke Edwards, Director of IT.
FAC accepted this audit on November 4, 2021 — management decision was due May 4, 2022.
During the audit, it was noted that the University used the incorrect number of total days in the payment period or period of enrollment in calculating the percentage of payment period or period of enrollment completed. Questioned Costs: Such information is not applicable for this finding, due to the fact that it is nonmonetary in nature. Perspective Information: The audit included a detailed testing of 40 student files, of which this significant deficiency applies to 4, indicating an error rate of 10.00%. Cause and Effect: When setting the return to Title IV dates in the system, the University used the term end date from the catalog instead of the last class date which would be the last day of finals. Recommendation: The University should ensure that the total number of calendar days in the payment period or period of enrollment is counted correctly.View of Responsible Officials: The University agrees with this finding. This was an oversight and the correct dates were verified as correct for the 2021-22 award year already. The University has procedures in place to have these dates evaluated each year when the system is transitioned over to each new award year.
Show full finding ▾Hide full finding ▴2021-001 Significant Deficiency: Return to Title IV Funds (U.S. Department of Education, William D. Ford Direct Loan Program, CFDA #84.268; Federal Pell Grant Program, CFDA #84.063; Federal Supplemental Opportunity Grant Program, CFA #84.007; and TEACH Grant Program, CFDA #84.379) Criteria: In accordance with 34 CFR 668.22(f), in the calculation of the percentage of payment period or period of enrollment completed, the total number of calendar days in a payment or enrollment period includes all days within the period, except that institutionally scheduled breaks of at least 5 consecutive calendar days and days in which the student was on an approved leave of absence are excluded from the total number of calendar days in a payment period or period of enrollment. Statement of Condition: During the audit, it was noted that the University used the incorrect number of total days in the payment period or period of enrollment in calculating the percentage of payment period or period of enrollment completed. Questioned Costs: Such information is not applicable for this finding, due to the fact that it is nonmonetary in nature. Perspective Information: The audit included a detailed testing of 40 student files, of which this significant deficiency applies to 4, indicating an error rate of 10.00%. Cause and Effect: When setting the return to Title IV dates in the system, the University used the term end date from the catalog instead of the last class date which would be the last day of finals. Recommendation: The University should ensure that the total number of calendar days in the payment period or period of enrollment is counted correctly.View of Responsible Officials: The University agrees with this finding. This was an oversight and the correct dates were verified as correct for the 2021-22 award year already. The University has procedures in place to have these dates evaluated each year when the system is transitioned over to each new award year.
Corrective Action Plan Summary: When setting the R2T4 dates in the system we had used the "term end date" from the college catalog instead of the last class date which would be the last day of finals. This was an oversight and the correct dates were verified as correct for the 2021-22 award year already. We have a procedure in place to have these dates evaluated each year when the system is transitioned over to each new award year.
During the audit, it was noted that the University was unable to provide documentation of Direct Loan disbursement notifications being provided to the student. Questioned Costs: Such information is not applicable for this finding, due to the fact that it is nonmonetary in nature. Perspective Information: The audit included a detailed testing of 40 student files, of which this significant deficiency applies to 5, indicating an error rate of 12.50%. Cause and Effect: It appears this finding was caused by the University switching to a new notifications system which purges data every 120 days. Recommendation: We recommend that the University ensure that documentation is retained of Direct Loan notifications. View of Responsible Officials: The University agrees with this finding. The University has switched to a new notification system that makes this process more streamlined. The system purged the data verifying the notifications sent to the student every 120 days, so the University did not have documentation related to the students in question. The University has worked with its IT department to ensure that they have a longer retention period where the verification of notification can be retained.
Show full finding ▾Hide full finding ▴2021-002 Significant Deficiency: Federal Direct Loan Disbursement Notifications (William D. Ford Federal Direct Loan Program, CFDA #84.268) Criteria: In accordance with 34 CFR 668.165(a), if an institution credits a student ledger account with Direct Loan program funds, the institution must notify the student or parent of (1) the anticipated date and amount of the disbursement; (2) the student?s or parent?s right to cancel all or a portion of that loan or loan disbursement and have the loan proceeds returned to the Secretary; and (3) the procedures and time by which the student or parent must notify the institution that he or she wishes to cancel the loan or loan disbursement. The institution must provide the notice no earlier than 30 days before and no later than 30 days after crediting the student?s ledger account at the institution. Statement of Condition: During the audit, it was noted that the University was unable to provide documentation of Direct Loan disbursement notifications being provided to the student. Questioned Costs: Such information is not applicable for this finding, due to the fact that it is nonmonetary in nature. Perspective Information: The audit included a detailed testing of 40 student files, of which this significant deficiency applies to 5, indicating an error rate of 12.50%. Cause and Effect: It appears this finding was caused by the University switching to a new notifications system which purges data every 120 days. Recommendation: We recommend that the University ensure that documentation is retained of Direct Loan notifications. View of Responsible Officials: The University agrees with this finding. The University has switched to a new notification system that makes this process more streamlined. The system purged the data verifying the notifications sent to the student every 120 days, so the University did not have documentation related to the students in question. The University has worked with its IT department to ensure that they have a longer retention period where the verification of notification can be retained.
Corrective Action Plan Summary: We switch to a new notification system that makes this process more streamlined. It has worked well both for our students and the school. However, the systems purged the data verifying the process was done and sent to the stydent every 120 days, so we did not have documentation related to the students in question. We have already worked with our IT department to ensure that we have a longer retention period where the verification of notification can be retained.
FAC accepted this audit on May 10, 2021 — management decision was due November 10, 2021.
During the audit, it was noted that significant elements of the program level data, including credentialing level, published program length, program begin date, program enrollment status, and program enrollment effective date, were incorrectly reported to NSLDS. Questioned Costs: Such information is not applicable for this finding, due to the fact that it is nonmonetary in nature. Perspective Information: The audit included a detailed testing of 40 student files, of which this significant deficiency applies to 10, indicating an error rate of 25.00%. Cause and Effect: It appears this finding was caused by the system pulling incorrect data to be reported to NSLDS. Recommendation: The University should ensure that the correct data is submitted to the NSLDS in accordance with the Department of Education and that proper policies and internal controls are in place regarding the enrollment reporting process. View of Responsible Officials: The University agrees with this finding and has implemented new policies and procedures to ensure that future program level data are correctly reported via submissions to the NSC and NSLDS. Additional quality checks have been added into the review process of all reports before submission.
Show full finding ▾Hide full finding ▴2020-001 Significant Deficiency: National Student Loan Data System (NSLDS) Report (William D. Ford Direct Loan Program, CFDA #84.268 and Federal Pell Grant Program, CFDA #84.063) Criteria: In accordance with 34 CFR 685.309 and 34 CFR section 690.83(b)(2), for Direct Loans and Pell grants, respectively, the institution must ensure that the reports on student enrollment submitted to NSLDS are accurate. Statement of Condition: During the audit, it was noted that significant elements of the program level data, including credentialing level, published program length, program begin date, program enrollment status, and program enrollment effective date, were incorrectly reported to NSLDS. Questioned Costs: Such information is not applicable for this finding, due to the fact that it is nonmonetary in nature. Perspective Information: The audit included a detailed testing of 40 student files, of which this significant deficiency applies to 10, indicating an error rate of 25.00%. Cause and Effect: It appears this finding was caused by the system pulling incorrect data to be reported to NSLDS. Recommendation: The University should ensure that the correct data is submitted to the NSLDS in accordance with the Department of Education and that proper policies and internal controls are in place regarding the enrollment reporting process. View of Responsible Officials: The University agrees with this finding and has implemented new policies and procedures to ensure that future program level data are correctly reported via submissions to the NSC and NSLDS. Additional quality checks have been added into the review process of all reports before submission.
Johnson University Corrective Action Plan April 7, 2021 Finding Reference Number: 2020-001 Initial Fiscal Year: 2020 Summary of Finding: Program level data discrepancies Entity?s Corrective Action Plan Name and Title of Responsible Contact: Dr. Andrew M. Frazier, University Registrar Corrective Action Plan Summary: The University agrees with this finding and has implemented new policies and procedures to ensure that future program level data are correctly reported via submissions to the NSC and NSLDS. Additional quality checks have been added into the review process of all program level data in NSC reports before submission. Further, as new programs are created and implemented at the University, correct credential levels and program length will be reviewed and verified when entered into the system. Anticipated Completion Date: April 7, 2021 Andrew M. Frazier, Ed.D.University Registrar
FAC accepted this audit on October 20, 2019 — management decision was due April 20, 2020.
During the audit, it was noted that the University awarded one student Direct Subsidized Loan without the student having the need to receive such aid. Questioned Costs: The known monetary error was $1,550, which resulted in an extrapolated error of $40,812. Perspective Information: The audit included a detailed testing of 40 student files, of which this material weakness applies to 1, indicating an error rate of 2.50%. The relevant population in which this error was extrapolated consisted of all students who received Direct Subsidized Loans in the 2018-2019 aid year. We consider both of these samples to be statistically valid. Cause and Effect: This issue was caused by grant funds for the student being increased after the student accepted their Subsidized Direct Loan. Recommendation: The University should ensure that students are awarded Subsidized Loans in accordance with their need.
Show full finding ▾Hide full finding ▴2019-001 Material Weakness: Direct Subsidized Loans were Awarded without Adequate Need (U.S Department of Education, William D. Ford Direct Loan Program, CFDA #84.268) Criteria: In accordance with 34 CFR 685.200(a)(2)(i)(A), a Direct Subsidized Loan borrower must demonstrate financial need. Statement of Condition: During the audit, it was noted that the University awarded one student Direct Subsidized Loan without the student having the need to receive such aid. Questioned Costs: The known monetary error was $1,550, which resulted in an extrapolated error of $40,812. Perspective Information: The audit included a detailed testing of 40 student files, of which this material weakness applies to 1, indicating an error rate of 2.50%. The relevant population in which this error was extrapolated consisted of all students who received Direct Subsidized Loans in the 2018-2019 aid year. We consider both of these samples to be statistically valid. Cause and Effect: This issue was caused by grant funds for the student being increased after the student accepted their Subsidized Direct Loan. Recommendation: The University should ensure that students are awarded Subsidized Loans in accordance with their need.
Johnson University Corrective Action Plan June 30, 2019 Finding Reference Number: 2019-001 Initial Fiscal Year: 2019 Summary of Finding: Need-based Aid Over-award Entity?s Corrective Action Plan Name and Title of Responsible Contact: Dr. Brittany Debity-Barker, Interim Director of Financial Aid Corrective Action Plan Summary: The University agrees with this finding and has implemented a new procedure to ensure students are reviewed each term, prior to disbursement and at the conclusion of the term, to ensure need-based aid awarded does not exceed eligibility. Anticipated Completion Date: June 30, 2019 Brittany Debity-Barker, Ed.D. Interim Director of Financial Aid
FAC accepted this audit on October 29, 2018 — management decision was due April 29, 2019.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2017-002
FAC accepted this audit on October 30, 2017 — management decision was due April 30, 2018.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2016-001
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
FAC accepted this audit on December 9, 2016 — management decision was due June 9, 2017.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
Show full finding ▾Hide full finding ▴Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.