EIN: 660191965
UEI: FGNMYHB9WBN4
Audited by: KPMG LLP
Cognizant agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of August 28, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 28, 2024. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 28, 2024 (701 days ago).
What is a management decision? →Criteria (A)Per 16 CFR 314.3 the institutions with 5,000 or more customers must stablish written information securityprogram to include nine elements. The elements that an institution must address in its written informationsecurity program are at 16 CFR 314.4. At a minimum, an institution’s written information security programshould include: 1.Designates a qualified individual responsible for overseeing and implementing the institutions or servicer’sinformation security program and enforcing the information security program (16 C.F.R. 314.4(a)). 2.Provides for the information security program to be based on a risk assessment that identifies reasonablyforeseeable internal and external risks to the security, confidentiality, and integrity of customer information(as the term customer information applies to the institution or servicer) that could result in the unauthorizeddisclosure, misuse, alteration, destruction, or other compromise of such information, and assesses thesufficiency of any safeguards in place to control these risks (16 C.F.R. 314.4(b)). 3.Provides for the design and implementation of safeguards to control the risks the institution or serviceridentifies through its risk assessment (16 C.F.R. 314.4(c)). At a minimum, the written information securityprogram must address the implementation of the minimum safeguards identified in 16 C.F.R. 314.4(c)(1)through (8). 4.Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it hasimplemented (16 CFR 314.4(d)). 5.Provides for the implementation of policies and procedures to ensure that personnel are able to enact theinformation security program (16 C.F.R. 314.4(e)). 6.Addresses how the institution will oversee its information system service providers (16 C.F.R. 314.4(f)). 7.Provides for the evaluation and adjustment of its information security program in light of the results of therequired testing and monitoring; any material changes to its operations or business arrangements; theresults of the required risk assessments; or any other circumstances that it knows or has reason to knowmay have a material impact the information security program (16 C.F.R. 314.4(g)). 8.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses theestablishment of an incident response plan (16 C.F.R. 314.4(h)). 9.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses therequirement for its Qualified Individual to report regularly and at least annually to those with control over theinstitution on the institution’s information security program (16 C.F.R. 314.4(i)). (B)Per 2 CFR 200.303, a non-federal entity mush establish and maintain internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations and the terms and conditions of the federal award.Condition and ContextDuring our audit of the internal controls over compliance and compliance requirements, we noted that the University did not have written procedures or formal policies to ensure compliance with all the elements included in the criteria. We were no able to identify formal written procedures for the elements: 4,5,7 and 9.
Show full finding ▾Hide full finding ▴Criteria (A)Per 16 CFR 314.3 the institutions with 5,000 or more customers must stablish written information securityprogram to include nine elements. The elements that an institution must address in its written informationsecurity program are at 16 CFR 314.4. At a minimum, an institution’s written information security programshould include: 1.Designates a qualified individual responsible for overseeing and implementing the institutions or servicer’sinformation security program and enforcing the information security program (16 C.F.R. 314.4(a)). 2.Provides for the information security program to be based on a risk assessment that identifies reasonablyforeseeable internal and external risks to the security, confidentiality, and integrity of customer information(as the term customer information applies to the institution or servicer) that could result in the unauthorizeddisclosure, misuse, alteration, destruction, or other compromise of such information, and assesses thesufficiency of any safeguards in place to control these risks (16 C.F.R. 314.4(b)). 3.Provides for the design and implementation of safeguards to control the risks the institution or serviceridentifies through its risk assessment (16 C.F.R. 314.4(c)). At a minimum, the written information securityprogram must address the implementation of the minimum safeguards identified in 16 C.F.R. 314.4(c)(1)through (8). 4.Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it hasimplemented (16 CFR 314.4(d)). 5.Provides for the implementation of policies and procedures to ensure that personnel are able to enact theinformation security program (16 C.F.R. 314.4(e)). 6.Addresses how the institution will oversee its information system service providers (16 C.F.R. 314.4(f)). 7.Provides for the evaluation and adjustment of its information security program in light of the results of therequired testing and monitoring; any material changes to its operations or business arrangements; theresults of the required risk assessments; or any other circumstances that it knows or has reason to knowmay have a material impact the information security program (16 C.F.R. 314.4(g)). 8.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses theestablishment of an incident response plan (16 C.F.R. 314.4(h)). 9.For an institution or servicer maintaining student information on 5,000 or more consumers, addresses therequirement for its Qualified Individual to report regularly and at least annually to those with control over theinstitution on the institution’s information security program (16 C.F.R. 314.4(i)). (B)Per 2 CFR 200.303, a non-federal entity mush establish and maintain internal control over the federal award that provides reasonable assurance that the non-federal entity is managing the federal award in compliance with federal statutes, regulations and the terms and conditions of the federal award.Condition and ContextDuring our audit of the internal controls over compliance and compliance requirements, we noted that the University did not have written procedures or formal policies to ensure compliance with all the elements included in the criteria. We were no able to identify formal written procedures for the elements: 4,5,7 and 9.
Management has already written the basic Security of Information Plan as required by 16 C.F.R. 313.3 and 313.4. A framework for personnel training is being developed, as well as a reporting dateto the Board of Trustees has been set before the end of the current fiscal year. A risk assessment plan isbeing developed and the University is in the process of contracting an independent third party to conductmonitoring and risk assessment of the data security plan, reporting at least four times per year. Correctionsor modifications to the plan or the established safeguards will be implemented based in said monitoring processes. The person designated to be in charge is Dr. Edgardo Aviles Garay, director of the Information Tecnologies and Telecomunications Department, under the guidance of the Vicepresident of Administrative Affairs. The corrective plan should be completed by June 30, 2024.
FAC accepted this audit on March 30, 2023 — management decision was due September 30, 2023.
FAC accepted this audit on August 15, 2022 — management decision was due February 15, 2023.
FAC accepted this audit on June 24, 2021 — management decision was due December 24, 2021.
FAC accepted this audit on March 29, 2020 — management decision was due September 29, 2020.
FAC accepted this audit on February 19, 2019 — management decision was due August 19, 2019.
FAC accepted this audit on March 27, 2018 — management decision was due September 27, 2018.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
FAC accepted this audit on March 29, 2017 — management decision was due September 29, 2017.
GSA_MIGRATION
Show full finding ▾Hide full finding ▴GSA_MIGRATION
GSA_MIGRATION
2015-002
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in Puerto Rico →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.