← Back to home

Pontifical Catholic University of Puerto RicoHigher Education

EIN: 660191965

UEI: FGNMYHB9WBN4

Audited by: KPMG LLP

Cognizant agency: 84 [Department of Education]

View federal awards & risk assessment →

Data as of August 28, 2026

Pontifical Catholic University of Puerto Rico8 audit years3 findings1 repeat
8
Audit Years
3
Total Findings
1
Repeat Findings
$85M
Federal Awards Expended (FY 2023)

FY 2023-06-30

LOW-RISK AUDITEE$85,020,230 federal awards expended

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 28, 2024. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 28, 2024 (701 days ago).

What is a management decision? →
2023-001
Special Tests & Provisions
SIGNIFICANT DEFICIENCY

Criteria (A)Per 16 CFR 314.3 the institutions with 5,000 or more customers must stablish written information securityprogram to include nine elements. The elements that an institution must address in its written informationsecurity program are at 16 CFR 314.4. At a minimum, an institution’s written information security programshould include: 1.Designates a qualified individual responsible for overseeing and implementing the institutions or servicer’sinformation security program and enforcing the information security program (16 C.F.R. 314.4(a)). 2.Provides for the information security program to be based on a risk assessment that identifies reasonablyforeseeable internal and external risks to the security, confidentiality, and integrity of customer information(as the term customer information applies to the institution or servicer) that could result in the unauthorizeddisclosure, misuse, alteration, destruction, or other compromise of such information, and assesses thesufficiency of any safeguards in place to control these risks (16 C.F.R. 314.4(b)). 3.Provides for the design and implementation of safeguards to control the risks the institution or serviceridentifies through its risk assessment (16 C.F.R. 314.4(c)). At a minimum, the written information securityprogram must address the implementation of the minimum safeguards identified in 16 C.F.R. 314.4(c)(1)through (8). 4.Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it hasimplemented (16 CFR 314.4(d)). 5.Provides for the implementation of policies and procedures to ensure that personnel are able to enact theinformation security program (16 C.F.R. 314.4(e)). 6.Addresses how the institution will oversee its information system service providers (16 C.F.R. 314.4(f)). 7.Provides for the evaluation and adjustment of its information security program in light of the results of therequired testing and monitoring; any material changes to its operations or business arrangements; theresults of the required risk assessments; or any other circumstances that it knows or has reason to knowmay have a material impact the information security program (16 C.F.R. 314.4(g)). 8.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses theestablishment of an incident response plan (16 C.F.R. 314.4(h)). 9.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses therequirement for its Qualified Individual to report regularly and at least annually to those with control over theinstitution on the institution’s information security program (16 C.F.R. 314.4(i)). (B)Per 2 CFR 200.303, a non-federal entity mush establish and maintain internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations and the terms and conditions of the federal award.Condition and ContextDuring our audit of the internal controls over compliance and compliance requirements, we noted that the University did not have written procedures or formal policies to ensure compliance with all the elements included in the criteria. We were no able to identify formal written procedures for the elements: 4,5,7 and 9.

Show full finding ▾
Full finding narrative

Criteria (A)Per 16 CFR 314.3 the institutions with 5,000 or more customers must stablish written information securityprogram to include nine elements. The elements that an institution must address in its written informationsecurity program are at 16 CFR 314.4. At a minimum, an institution’s written information security programshould include: 1.Designates a qualified individual responsible for overseeing and implementing the institutions or servicer’sinformation security program and enforcing the information security program (16 C.F.R. 314.4(a)). 2.Provides for the information security program to be based on a risk assessment that identifies reasonablyforeseeable internal and external risks to the security, confidentiality, and integrity of customer information(as the term customer information applies to the institution or servicer) that could result in the unauthorizeddisclosure, misuse, alteration, destruction, or other compromise of such information, and assesses thesufficiency of any safeguards in place to control these risks (16 C.F.R. 314.4(b)). 3.Provides for the design and implementation of safeguards to control the risks the institution or serviceridentifies through its risk assessment (16 C.F.R. 314.4(c)). At a minimum, the written information securityprogram must address the implementation of the minimum safeguards identified in 16 C.F.R. 314.4(c)(1)through (8). 4.Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it hasimplemented (16 CFR 314.4(d)). 5.Provides for the implementation of policies and procedures to ensure that personnel are able to enact theinformation security program (16 C.F.R. 314.4(e)). 6.Addresses how the institution will oversee its information system service providers (16 C.F.R. 314.4(f)). 7.Provides for the evaluation and adjustment of its information security program in light of the results of therequired testing and monitoring; any material changes to its operations or business arrangements; theresults of the required risk assessments; or any other circumstances that it knows or has reason to knowmay have a material impact the information security program (16 C.F.R. 314.4(g)). 8.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses theestablishment of an incident response plan (16 C.F.R. 314.4(h)). 9.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses therequirement for its Qualified Individual to report regularly and at least annually to those with control over theinstitution on the institution’s information security program (16 C.F.R. 314.4(i)). (B)Per 2 CFR 200.303, a non-federal entity mush establish and maintain internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations and the terms and conditions of the federal award.Condition and ContextDuring our audit of the internal controls over compliance and compliance requirements, we noted that the University did not have written procedures or formal policies to ensure compliance with all the elements included in the criteria. We were no able to identify formal written procedures for the elements: 4,5,7 and 9.

Corrective Action Plan

Management has already written the basic Security of Information Plan as required by 16 C.F.R. 313.3 and 313.4. A framework for personnel training is being developed, as well as a reporting dateto the Board of Trustees has been set before the end of the current fiscal year. A risk assessment plan isbeing developed and the University is in the process of contracting an independent third party to conductmonitoring and risk assessment of the data security plan, reporting at least four times per year. Correctionsor modifications to the plan or the established safeguards will be implemented based in said monitoring processes. The person designated to be in charge is Dr. Edgardo Aviles Garay, director of the Information Tecnologies and Telecomunications Department, under the guidance of the Vicepresident of Administrative Affairs. The corrective plan should be completed by June 30, 2024.

About Special Tests and Provisions →

FY 2022-06-30

LOW-RISK AUDITEE$95,265,257 federal awards expendedNo findings recorded this year

FAC accepted this audit on March 30, 2023 — management decision was due September 30, 2023.

FY 2021-06-30

$98,554,572 federal awards expendedNo findings recorded this year

FAC accepted this audit on August 15, 2022 — management decision was due February 15, 2023.

FY 2020-06-30

$104,491,085 federal awards expendedNo findings recorded this year

FAC accepted this audit on June 24, 2021 — management decision was due December 24, 2021.

FY 2019-06-30

LOW-RISK AUDITEE$98,762,510 federal awards expendedNo findings recorded this year

FAC accepted this audit on March 29, 2020 — management decision was due September 29, 2020.

FY 2018-06-30

LOW-RISK AUDITEE$102,449,097 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 19, 2019 — management decision was due August 19, 2019.

FY 2017-06-30

MATERIAL NONCOMPLIANCE DISCLOSED$105,244,395 federal awards expended

FAC accepted this audit on March 27, 2018 — management decision was due September 27, 2018.

2017-001
Special Tests & Provisions
SIGNIFICANT DEFICIENCYOTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →

FY 2016-06-30

MATERIAL NONCOMPLIANCE DISCLOSED$102,464,899 federal awards expended

FAC accepted this audit on March 29, 2017 — management decision was due September 29, 2017.

2016-001
Special Tests & Provisions
SIGNIFICANT DEFICIENCYREPEAT OF 2015-002OTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-002

About Special Tests and Provisions →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Browse other Single Audit organizations in Puerto Rico

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and filing records.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.