← Back to home

Universidad Central de Bayamon, Inc.Higher Education

EIN: 660259904

UEI: JFA4KNMF5AM3

Audited by: Galindez, LLC

Oversight agency: 84 [Department of Education]

View federal awards & risk assessment →

Data as of August 28, 2026

Universidad Central de Bayamon, Inc.8 audit years14 findings3 repeat
8
Audit Years
14
Total Findings
3
Repeat Findings
$6.6M
Federal Awards Expended (FY 2024)

FY 2024-06-30

$6,590,908 federal awards expended

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 31, 2025. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by October 1, 2025 (334 days ago).

What is a management decision? →
2024-001
Special Tests & Provisions
OTHER MATTERS

Finding No. 2024–001 – Special Tests and Provisions – Return of Title IV Funds - Timing of Return of Title IV Funds. Federal Program Name Student Financial Assistance Programs Cluster – Federal Pell Grant Program (PELL) Assistance Listing 84.063 Name of Federal Agency U.S. Department of Education (USDE) Category Internal Control/Compliance Compliance Requirement Special Tests and Provisions Criteria 34 CFR Section 668.173 (b) states that an institution returns unearned Title IV, HEA program funds timely if; (1) the institution deposits or transfers the funds into the bank account it maintains under §668.163 no later than forty-five (45) days after the date it determines that the student withdrew; (2) the institution initiates an electronic fund transfer (EFT) no later than forty-five (45) days after the date it determines that the student withdrew; (3) the institution initiates an electronic transaction, no later than forty five (45) days after the date it determines that the student withdrew, that informs a FFEL lender to adjust the borrower's loan account for the amount returned; or (4) the institution issues a check no later than forty-five (45) days after the date it determines that the student withdrew. Condition In testing compliance with the Return of Title IV funds requirements, we noted one (1) instance, which based on the regulation previously indicated, the return of Title IV funds as calculated by the Institution was performed after the required 45 days. (Table) Cause In November 2023, the University reported that the information technology systems had been the target of an external cyber-attack, which caused various disruptions in the operations. The delay in returning the funds within the time prescribed by the regulations was due to the disruptions caused by such event. Effect As a result of this instance of noncompliance, the USDE may issue warnings and/or impose penalties on the University. Also, the delay in the returning of Title IV funds could limit the students’ future eligibility to Title IV funds. Context Of the sixty-four (64) cases of withdrawal, we examined twenty-five (25) and determined that one (1) case that the Return of Title IV was returned late.Following is a description of the sample that included the finding identified and the population from which the sample was drawn for students that received Pell funds: (Table) Following is a description of the sample that included the finding identified and the population from which the sample was drawn for students that received Direct Loans: (Table) Identification of a repeat finding This is not a repeat finding from the immediate previous audit. Questioned cost None Recommendation The University should reinforce its internal control and procedures to ensure the return of Title IV funds in the required time frame. Views of Responsible Officials and Planned Corrective Actions Management of the University agrees with this finding. Please refer to the corrective action plan on pages 61-63.

Show full finding ▾
Full finding narrative

Finding No. 2024–001 – Special Tests and Provisions – Return of Title IV Funds - Timing of Return of Title IV Funds. Federal Program Name Student Financial Assistance Programs Cluster – Federal Pell Grant Program (PELL) Assistance Listing 84.063 Name of Federal Agency U.S. Department of Education (USDE) Category Internal Control/Compliance Compliance Requirement Special Tests and Provisions Criteria 34 CFR Section 668.173 (b) states that an institution returns unearned Title IV, HEA program funds timely if; (1) the institution deposits or transfers the funds into the bank account it maintains under §668.163 no later than forty-five (45) days after the date it determines that the student withdrew; (2) the institution initiates an electronic fund transfer (EFT) no later than forty-five (45) days after the date it determines that the student withdrew; (3) the institution initiates an electronic transaction, no later than forty five (45) days after the date it determines that the student withdrew, that informs a FFEL lender to adjust the borrower's loan account for the amount returned; or (4) the institution issues a check no later than forty-five (45) days after the date it determines that the student withdrew. Condition In testing compliance with the Return of Title IV funds requirements, we noted one (1) instance, which based on the regulation previously indicated, the return of Title IV funds as calculated by the Institution was performed after the required 45 days. (Table) Cause In November 2023, the University reported that the information technology systems had been the target of an external cyber-attack, which caused various disruptions in the operations. The delay in returning the funds within the time prescribed by the regulations was due to the disruptions caused by such event. Effect As a result of this instance of noncompliance, the USDE may issue warnings and/or impose penalties on the University. Also, the delay in the returning of Title IV funds could limit the students’ future eligibility to Title IV funds. Context Of the sixty-four (64) cases of withdrawal, we examined twenty-five (25) and determined that one (1) case that the Return of Title IV was returned late.Following is a description of the sample that included the finding identified and the population from which the sample was drawn for students that received Pell funds: (Table) Following is a description of the sample that included the finding identified and the population from which the sample was drawn for students that received Direct Loans: (Table) Identification of a repeat finding This is not a repeat finding from the immediate previous audit. Questioned cost None Recommendation The University should reinforce its internal control and procedures to ensure the return of Title IV funds in the required time frame. Views of Responsible Officials and Planned Corrective Actions Management of the University agrees with this finding. Please refer to the corrective action plan on pages 61-63.

Corrective Action Plan

The University afirms its understanding of its obligation to submit disbursement according to 34 CFR Section 668.173 (b) states that an institution returns unearned Title IV, HEA program funds timely if; (1) the institution deposits or transfers the funds into the bank account it maintains under §668.163 no later than forty-five (45) days after the date it determines that the student withdrew; (2) the institution initiates an electronic fund transfer (EFT) no later than forty-five (45) days after the date it determines that the student withdrew; (3) the institution initiates an electronic transaction, no later than forty five (45) days after the date it determines that the student withdrew, that informs a FFEL lender to adjust the borrower's loan account for the amount returned; or (4) the institution issues a check no later than forty-five (45) days after the date it determines that the student withdrew. Due to an information technology systems external cybernetic attack that caused various disruptions in the operations, a delay in returning of funds within the time prescribed by the regulation was caused, even when the institution does everything to perform manually all transaction in order to avoid any noncompliance of the regulation. UCB will reinforce their processes and procedures to satisfy all applicable requirements specified in 668.173 (b) and do a doble verification to make sure every return of funds is made no later than 45 days required by the regulation. Anticipated completion date: Immediately.

About Special Tests and Provisions →
2024-002
Special Tests & Provisions
REPEAT OF 2023-002OTHER MATTERS

Finding No. 2024–002 – Special Tests and Provisions – Enrollment Reporting Federal Program Name Student Financial Assistance Programs Cluster – Federal Pell Grant Program (PELL) Assistance Listing 84.063 Federal Direct Student Loan Program (DL) Assistance Listing 84.268 Name of Federal Agency U.S. Department of Education (USDE) Category Internal Control/Compliance Compliance Requirement Special Tests and ProvisionsCriteria 34 CFR 685.309 (b)(2)(ii) states that unless it expects to submit its next updated enrollment report to the Secretary within the next 60 days, a school must notify the Secretary within 30 days after the date the school discovers that; a loan under title IV of the Act was made to or on behalf of a student who was enrolled or accepted for enrollment at the school, and the student has ceased to be enrolled on at least a half-time basis or failed to enroll on at least a half-time basis for the period for which the loan was intended; or a student who is enrolled at the school and who received a loan under title IV of the Act has changed his or her permanent address. The National Student Loan Data System (NSLDS) is the U.S. Department of Education’s central database for federal student aid disbursed under Title IV of the Higher Education Act of 1965 (HEA), as amended. Among other things, NSLDS monitors the programs of attendance and the enrollment status of Title IV aid recipients. The institution determines how often it receives the Enrollment Reporting roster file with the default set at a minimum of every 60 days. Once received, the institution must update for changes in student status, report the date the enrollment status was effective, enter the new anticipated completion date, and submit the changes electronically through the batch method or the NSLDS website, as stated in 34 CFR 690.83 (b) (2) for Federal Pell Grant Program and 34 CFR section 685.309 for Federal Direct Student Loan Program. A student’s enrollment status determines eligibility for in-school status, deferment, and grace periods, as well as for the payment of interest subsidies to FFEL Program loan holders by USDE. Enrollment Reporting in a timely and accurate manner is critical for effective management of the programs. Enrollment information must be reported within 30 days whenever attendance changes for students, unless a roster will be submitted within 60 days. These changes include reductions or increases in attendance levels, withdrawals, graduations, or approved leaves-of- absence. Condition In testing compliance with the enrollment reporting requirements, from twenty-five (25) cases of students examined, we found that in one (1) instance, the University did not report to the National Student Loan Data System (NSLDS) the change in status of the student within the required 60 days period. Cause Despite having sent the file on time, the Registrar’s Office did not verify that it was transmitted correctly. Subsequently, while reviewing the file, it was identified that the system did not recognized the status change of “official withdrawal” instead, the status was changed to “Three- Quarter”. The file was submitted again with the correction, untimely, therefore, the University did not comply with the enrollment reporting requirements. Effect As a result of this condition, the USDE was prevented the use of accurate reporting data, which is critical for the effective administration of the Direct Loan Program and for USDE budgetary policy analysis. Identification of a Repeat Finding This is a repeat finding from the immediate previous audit. Finding 2023-002. Questioned Cost None Context Of the one hundred and ninety-eight (198) status changes for 2024, we selected twenty-five (25) students for testing and noted one (1) instance in which the University did not comply with the enrollment reporting requirements. Recommendation Management should reinforce its monitoring of the services provided by the National Student Clearinghouse to ensure they comply with the agreed upon reporting timeframe. The University should enhance both electronic and manual procedures to ensure enrollment status changes are timely and accurately reported to NSDLS. Views of Responsible Officials and Planned Corrective Actions Management of the University agrees with this finding. Please refer to the corrective action plan on pages 61-63.

Show full finding ▾
Full finding narrative

Finding No. 2024–002 – Special Tests and Provisions – Enrollment Reporting Federal Program Name Student Financial Assistance Programs Cluster – Federal Pell Grant Program (PELL) Assistance Listing 84.063 Federal Direct Student Loan Program (DL) Assistance Listing 84.268 Name of Federal Agency U.S. Department of Education (USDE) Category Internal Control/Compliance Compliance Requirement Special Tests and ProvisionsCriteria 34 CFR 685.309 (b)(2)(ii) states that unless it expects to submit its next updated enrollment report to the Secretary within the next 60 days, a school must notify the Secretary within 30 days after the date the school discovers that; a loan under title IV of the Act was made to or on behalf of a student who was enrolled or accepted for enrollment at the school, and the student has ceased to be enrolled on at least a half-time basis or failed to enroll on at least a half-time basis for the period for which the loan was intended; or a student who is enrolled at the school and who received a loan under title IV of the Act has changed his or her permanent address. The National Student Loan Data System (NSLDS) is the U.S. Department of Education’s central database for federal student aid disbursed under Title IV of the Higher Education Act of 1965 (HEA), as amended. Among other things, NSLDS monitors the programs of attendance and the enrollment status of Title IV aid recipients. The institution determines how often it receives the Enrollment Reporting roster file with the default set at a minimum of every 60 days. Once received, the institution must update for changes in student status, report the date the enrollment status was effective, enter the new anticipated completion date, and submit the changes electronically through the batch method or the NSLDS website, as stated in 34 CFR 690.83 (b) (2) for Federal Pell Grant Program and 34 CFR section 685.309 for Federal Direct Student Loan Program. A student’s enrollment status determines eligibility for in-school status, deferment, and grace periods, as well as for the payment of interest subsidies to FFEL Program loan holders by USDE. Enrollment Reporting in a timely and accurate manner is critical for effective management of the programs. Enrollment information must be reported within 30 days whenever attendance changes for students, unless a roster will be submitted within 60 days. These changes include reductions or increases in attendance levels, withdrawals, graduations, or approved leaves-of- absence. Condition In testing compliance with the enrollment reporting requirements, from twenty-five (25) cases of students examined, we found that in one (1) instance, the University did not report to the National Student Loan Data System (NSLDS) the change in status of the student within the required 60 days period. Cause Despite having sent the file on time, the Registrar’s Office did not verify that it was transmitted correctly. Subsequently, while reviewing the file, it was identified that the system did not recognized the status change of “official withdrawal” instead, the status was changed to “Three- Quarter”. The file was submitted again with the correction, untimely, therefore, the University did not comply with the enrollment reporting requirements. Effect As a result of this condition, the USDE was prevented the use of accurate reporting data, which is critical for the effective administration of the Direct Loan Program and for USDE budgetary policy analysis. Identification of a Repeat Finding This is a repeat finding from the immediate previous audit. Finding 2023-002. Questioned Cost None Context Of the one hundred and ninety-eight (198) status changes for 2024, we selected twenty-five (25) students for testing and noted one (1) instance in which the University did not comply with the enrollment reporting requirements. Recommendation Management should reinforce its monitoring of the services provided by the National Student Clearinghouse to ensure they comply with the agreed upon reporting timeframe. The University should enhance both electronic and manual procedures to ensure enrollment status changes are timely and accurately reported to NSDLS. Views of Responsible Officials and Planned Corrective Actions Management of the University agrees with this finding. Please refer to the corrective action plan on pages 61-63.

Corrective Action Plan

UCB recognizes its obligation to report enrollment data to the National Student Loan Data System (NSLDS) at least every 60 days. The Registrar's Office reports enrollment data to NSLDS on a monthly basis. To ensure that the University complies with the 60-day requirement, we have established an additional notification procedure. The Financial Aid Office will forward a report of all Title IV student recipients classified as withdrawn to the Registrar's Office, this process consists of a reconciliation of the data. The Registrar's Office will report the enrollment change of these cases to NSLDS within 60 days required. Anticipated completion date: Immediately.

Prior Finding References

2023-002

About Special Tests and Provisions →
2024-003
Special Tests & Provisions
SIGNIFICANT DEFICIENCYOTHER MATTERS

Finding No. 2024-003 – Special Tests and Provisions - Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency Teacher Education Assistance for College and Higher Education Grants (TEACH Grants) U.S. Department of Education (USDE) Type of Finding Internal Control/Compliance Category Significant deficiency Compliance Requirement Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provide for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provide for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). e) Provide for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Address how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provide for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Vulnerability test 2. Penetration test 3. No backup test was performed during year ended June 30, 2024. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the University’s information cyber-security program. As a result, some of the procedures and policies established in the information cyber-security program risk assessment have not been consistently or continuously maintained, accordingly, the student personal information could be at risk. In addition, the USDE has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received, they will refer the audit to the Federal Trade Commission (FTC). Effect Once the finding is referred to the FTC, that finding will be considered closed for the USDE audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding. Identification of a repeat finding This is not a repeat finding from the immediate previous audit. Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Recommendation We recommend that the University addresses the cause for the high turnover in the position of the qualified individual responsible for overseeing the implementation of policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of Responsible Officials and Planned Corrective Actions Management of the University agrees with this finding. Please refer to the corrective action plan on pages 61-63.

Show full finding ▾
Full finding narrative

Finding No. 2024-003 – Special Tests and Provisions - Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency Teacher Education Assistance for College and Higher Education Grants (TEACH Grants) U.S. Department of Education (USDE) Type of Finding Internal Control/Compliance Category Significant deficiency Compliance Requirement Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designate a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provide for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provide for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provide for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). e) Provide for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Address how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provide for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Vulnerability test 2. Penetration test 3. No backup test was performed during year ended June 30, 2024. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the University’s information cyber-security program. As a result, some of the procedures and policies established in the information cyber-security program risk assessment have not been consistently or continuously maintained, accordingly, the student personal information could be at risk. In addition, the USDE has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received, they will refer the audit to the Federal Trade Commission (FTC). Effect Once the finding is referred to the FTC, that finding will be considered closed for the USDE audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding. Identification of a repeat finding This is not a repeat finding from the immediate previous audit. Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Recommendation We recommend that the University addresses the cause for the high turnover in the position of the qualified individual responsible for overseeing the implementation of policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of Responsible Officials and Planned Corrective Actions Management of the University agrees with this finding. Please refer to the corrective action plan on pages 61-63.

Corrective Action Plan

UCB recognizes its obligation under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in supportof the administration of the federal student financial aid programs. The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). To ensure that the University complies with the requirement, during this year that ends at June 30, 2025, University risk assessment addressed the elements required by (16 CFR 314.4). Accordingly, for this year UCB already performed the following: 1. Vulnerability test 2. Penetration test 3. Backup test was performed during year ended June 30, 2025. Anticipated completion date: Immediately.

About Special Tests and Provisions →

FY 2022-06-30

$11,916,790 federal awards expended

FAC accepted this audit on March 12, 2023 — management decision was due September 12, 2023.

2022-001
Special Tests & Provisions
OTHER MATTERS

Finding No. 2022?001 ? Special Tests and Provisions ? Return of Title IV Funds Federal Program ALN 84.063, Federal Pell Grant Program (PELL), Student Financial Assistance Programs Name of Federal Agency U.S. Department of Education (USDE) Category Internal Control/Compliance Compliance Requirement Special Tests and Provisions Criteria 34 CFR Section 668.173 (b) states that an institution returns unearned Title IV, HEA program funds timely if; (1) the institution deposits or transfers the funds into the bank account it maintains under ?668.163 no later than forty-five (45) days after the date it determines that the student withdrew; (2) the institution initiates an electronic fund transfer (EFT) no later than forty five (45) days after the date it determines that the student withdrew; (3) the institution initiates an electronic transaction, no later than forty five (45) days after the date it determines that the student withdrew, that informs a Federal Family Education Loan (FFEL) lender to adjust the borrower's loan account for the amount returned; or (4) the institution issues a check no later than forty-five (45) days after the date it determines that the student withdrew. Universidad Central de Bayamon, Inc. Condition The return of Title IV funds as calculated by the University was performed after the required 45 days, in the following case: Finding Number Student Identifier OPEID Pell Disbursed ($) Pell Under- Payment ($) Pell Over- Payment ($) Direct Loan Disbursed ($) Direct Loan Under- Payment ($) Direct Loan Over- Payment ($) 2022-001 Student 1 502200 $ 2,436 * $ - $ - $ - $ - $ - * There was no under-payment or over-payment of Title IV funds. Cause In this case, the disbursement of Title IV funds was processed at the same date and time of the R2T4. This action caused the process of R2T4 to be interrupted and the personnel become aware of the issue several days later. Effect As a result of these conditions, the U.S. Department of Education may impose penalties to the University or issue a warning as to incur in a probation status. It also could deprive other needy students of federal funds. Context Of the 116 cases of withdrawal, we examined forty (40) participants and determined that in one (1) case the Return of Title IV funds was performed late. The composition of the audit samples for the Pell grant and direct loans programs and the population from which the samples were drawn were as follows: i. Pell Grant Program: Sample Description Related Compliance Requirement OPEID Student Receiving Pell (#) Pell Disbursed ($) Students Receiving Pell (#) Pell Disbursed ($) Elegibility Sample Eligibility; and, Special Tests and Provisions - Verification and Disbursements to or on Behalf of Student 00502200 36 $ 194,814 728 $ 3,575,369 Return of Title IV Funds Sample Special Tests and Provisions - Return of Title IV Funds 00502200 29 $ 74,690 75 $ 205,924 Sample and Population Overlap 2 $ 74,690 75 $ 205,924 Population from which the Sample Sample was drawn ii. Direct Loans Program: Sample Description Related Compliance Requirement OPEID Student Receiving Direct Loans (#) Direct Loans Disbursed ($) Students Receiving Direct Loans (#) Direct Loans Disbursed ($) Elegibility Sample Eligibility; and, Special Test and Provisions - Verification and Disbursement to or on Behalf of Student 00502200 5 $ 30,250 370 $ 1,751,670 Return of Title IV Funds Sample Special Test and Provisions - Return of Title IV Funds 00502200 14 $ 48,370 11 $ 32,086 Sample and Population Overlap - $ - 11 $ 32,086 Population from which the Sample Sample was drawn Identification of a repeat finding No Questioned costs None Recommendation The University management should reinforce its procedures to ensure that disbursement of Title IV funds and R2T4 process are running separately and that each process be revise to make sure it was completed. Also, management should continue to improve its processes including the communications between departments to ensure that return of Title IV funds is made within the prescribed period of time. Views of responsible officials and planned corrective actions The University management agrees with this finding. Please refer to the corrective action plan on page 52.

Show full finding ▾
Full finding narrative

Finding No. 2022?001 ? Special Tests and Provisions ? Return of Title IV Funds Federal Program ALN 84.063, Federal Pell Grant Program (PELL), Student Financial Assistance Programs Name of Federal Agency U.S. Department of Education (USDE) Category Internal Control/Compliance Compliance Requirement Special Tests and Provisions Criteria 34 CFR Section 668.173 (b) states that an institution returns unearned Title IV, HEA program funds timely if; (1) the institution deposits or transfers the funds into the bank account it maintains under ?668.163 no later than forty-five (45) days after the date it determines that the student withdrew; (2) the institution initiates an electronic fund transfer (EFT) no later than forty five (45) days after the date it determines that the student withdrew; (3) the institution initiates an electronic transaction, no later than forty five (45) days after the date it determines that the student withdrew, that informs a Federal Family Education Loan (FFEL) lender to adjust the borrower's loan account for the amount returned; or (4) the institution issues a check no later than forty-five (45) days after the date it determines that the student withdrew. Universidad Central de Bayamon, Inc. Condition The return of Title IV funds as calculated by the University was performed after the required 45 days, in the following case: Finding Number Student Identifier OPEID Pell Disbursed ($) Pell Under- Payment ($) Pell Over- Payment ($) Direct Loan Disbursed ($) Direct Loan Under- Payment ($) Direct Loan Over- Payment ($) 2022-001 Student 1 502200 $ 2,436 * $ - $ - $ - $ - $ - * There was no under-payment or over-payment of Title IV funds. Cause In this case, the disbursement of Title IV funds was processed at the same date and time of the R2T4. This action caused the process of R2T4 to be interrupted and the personnel become aware of the issue several days later. Effect As a result of these conditions, the U.S. Department of Education may impose penalties to the University or issue a warning as to incur in a probation status. It also could deprive other needy students of federal funds. Context Of the 116 cases of withdrawal, we examined forty (40) participants and determined that in one (1) case the Return of Title IV funds was performed late. The composition of the audit samples for the Pell grant and direct loans programs and the population from which the samples were drawn were as follows: i. Pell Grant Program: Sample Description Related Compliance Requirement OPEID Student Receiving Pell (#) Pell Disbursed ($) Students Receiving Pell (#) Pell Disbursed ($) Elegibility Sample Eligibility; and, Special Tests and Provisions - Verification and Disbursements to or on Behalf of Student 00502200 36 $ 194,814 728 $ 3,575,369 Return of Title IV Funds Sample Special Tests and Provisions - Return of Title IV Funds 00502200 29 $ 74,690 75 $ 205,924 Sample and Population Overlap 2 $ 74,690 75 $ 205,924 Population from which the Sample Sample was drawn ii. Direct Loans Program: Sample Description Related Compliance Requirement OPEID Student Receiving Direct Loans (#) Direct Loans Disbursed ($) Students Receiving Direct Loans (#) Direct Loans Disbursed ($) Elegibility Sample Eligibility; and, Special Test and Provisions - Verification and Disbursement to or on Behalf of Student 00502200 5 $ 30,250 370 $ 1,751,670 Return of Title IV Funds Sample Special Test and Provisions - Return of Title IV Funds 00502200 14 $ 48,370 11 $ 32,086 Sample and Population Overlap - $ - 11 $ 32,086 Population from which the Sample Sample was drawn Identification of a repeat finding No Questioned costs None Recommendation The University management should reinforce its procedures to ensure that disbursement of Title IV funds and R2T4 process are running separately and that each process be revise to make sure it was completed. Also, management should continue to improve its processes including the communications between departments to ensure that return of Title IV funds is made within the prescribed period of time. Views of responsible officials and planned corrective actions The University management agrees with this finding. Please refer to the corrective action plan on page 52.

Corrective Action Plan

Finding No. 2022?001 ? Special Tests and Provisions ? Return of Title IV Funds Condition found. The return of Title IV funds as calculated by the University was performed after the required 45 days, in the following case: Student Id. No. Determination date Refund date 92710 6/24/2022 8/24/2022 Management Response The University agrees with the finding. Corrective Action Plan The University affirms its understanding of its obligation to submit the return of Title IV funds due to a total withdrawal to the Department of Education no later than 45 days after the determination date, the date that the school became aware that the student withdrew. In this case, the disbursement of Title IV funds was posted at the same date and time the R2T4 was processed, and one process blocked the other. To avoid this issue, officials must be aware that process that involve return of funds should be processed on different days than the disbursement of Title IV funds are processed. Name of the Contact Person Responsible for Corrective Action Elaine Nu?ez, Financial Aid Office Director Anticipated Completion Date During fiscal year 2022-2023

About Special Tests and Provisions →

FY 2021-06-30

$9,919,658 federal awards expended

FAC accepted this audit on October 10, 2022 — management decision was due April 10, 2023.

2021-001
Special Tests & Provisions
OTHER MATTERS

Criteria The National Student Loan Data System (NSLDS) is the U.S. Department of Education?s central database for federal student aid disbursed under Title IV of the Higher Education Act of 1965 (HEA), as amended. Among other things, NSLDS monitors the programs of attendance and the enrollment status of Title IV aid recipients. The institution determines how often it receives the Enrollment Reporting roster file with the default set at a minimum of every 60 days. Once received, the institution must update for changes in student status, report the date the enrollment status was effective, enter the new anticipated completion date, and submit the changes electronically through the batch method or the NSLDS website, as stated in 34 CFR 690.83 (b) (2) for Federal Pell Grant Program and 34 CFR section 685.309 for Federal Direct Student Loan Program. A student?s enrollment status determines eligibility for in-school status, deferment, and grace periods, as well as for the payment of interest subsidies to FFEL Program loan holders by USDE.Enrollment Reporting in a timely and accurate manner is critical for effective management of the programs. Enrollment information must be reported within 30 days whenever attendance changes for students, unless a roster will be submitted within 60 days. These changes include reductions or increases in attendance levels, withdrawals, graduations, or approved leaves-of- absence. Condition During our examination of the enrollment reporting test, from twenty five (25) cases of students examined, we found that in one (1) case, the University did not report to the National Student Loan Data System (NSLDS) the change in status of the students within the required 60 days? period. Cause The registrar reported the student graduated status within the required time frame to the National Student Clearinghouse (NSC), but the NSC exceeded the timeframe agreed with the University to report the student status changes to the NSDLS. Effect As a result, the USDE was prevented the use of accurate reporting data, which is critical for the effective administration of the Direct Loan Program and for USDE budgetary policy analysis. Questioned Cost None Context Of the 215 students changes for 2021, we selected 25 students for testing and noted 1 instance in which the University did not comply with the enrollment reporting requirement submission limit of 60 days. Recommendation Management should keep improving the Roster File Update policies and procedures and should reinforce its monitoring of NSC in order to ensure that enrollment reporting is completed in a timely and accurate manner.Views of responsible officials and planned corrective actions The University management agrees with this finding. Please refer to the corrective action plan on page 53.

Show full finding ▾
Full finding narrative

Criteria The National Student Loan Data System (NSLDS) is the U.S. Department of Education?s central database for federal student aid disbursed under Title IV of the Higher Education Act of 1965 (HEA), as amended. Among other things, NSLDS monitors the programs of attendance and the enrollment status of Title IV aid recipients. The institution determines how often it receives the Enrollment Reporting roster file with the default set at a minimum of every 60 days. Once received, the institution must update for changes in student status, report the date the enrollment status was effective, enter the new anticipated completion date, and submit the changes electronically through the batch method or the NSLDS website, as stated in 34 CFR 690.83 (b) (2) for Federal Pell Grant Program and 34 CFR section 685.309 for Federal Direct Student Loan Program. A student?s enrollment status determines eligibility for in-school status, deferment, and grace periods, as well as for the payment of interest subsidies to FFEL Program loan holders by USDE.Enrollment Reporting in a timely and accurate manner is critical for effective management of the programs. Enrollment information must be reported within 30 days whenever attendance changes for students, unless a roster will be submitted within 60 days. These changes include reductions or increases in attendance levels, withdrawals, graduations, or approved leaves-of- absence. Condition During our examination of the enrollment reporting test, from twenty five (25) cases of students examined, we found that in one (1) case, the University did not report to the National Student Loan Data System (NSLDS) the change in status of the students within the required 60 days? period. Cause The registrar reported the student graduated status within the required time frame to the National Student Clearinghouse (NSC), but the NSC exceeded the timeframe agreed with the University to report the student status changes to the NSDLS. Effect As a result, the USDE was prevented the use of accurate reporting data, which is critical for the effective administration of the Direct Loan Program and for USDE budgetary policy analysis. Questioned Cost None Context Of the 215 students changes for 2021, we selected 25 students for testing and noted 1 instance in which the University did not comply with the enrollment reporting requirement submission limit of 60 days. Recommendation Management should keep improving the Roster File Update policies and procedures and should reinforce its monitoring of NSC in order to ensure that enrollment reporting is completed in a timely and accurate manner.Views of responsible officials and planned corrective actions The University management agrees with this finding. Please refer to the corrective action plan on page 53.

Corrective Action Plan

The University affirms its understanding of its obligation to report enrollment data to the National Student Loan Data System (NSLDS) at least every 60 days. Due to a miscommunication within institutional officials in charge of managing this process, three student?s status were not submitted on a timely basis. Fiscal year 2020-2021 was an unusual year due to the COVID-19 pandemic which caused significant disruptions of normal operating procedures; principally due to the fact that operations were carried must of the time on-line with no physical presence at the University?s premises, as required by the Governor?s executive orders. The Registrar?s Office will be submitting an enrollment file containing only students who completed the coursework for a degree. Additionally, in each term students who complete their coursework for a degree will be reported to NSLDS, no later than 60 days after having conferred the degree.

About Special Tests and Provisions →
2021-002
Special Tests & Provisions
OTHER MATTERS

Criteria A school must submit Federal Pell Grant, TEACH Grant, and Direct Loan disbursement records no later than 15 days after making a disbursement or becoming aware of the need to adjust a student?s disbursement. Condition During our examination of the disbursement of Pell to students, from thirty-two (32) cases of students examined, we found that in three (3) cases, the University did not submit the disbursement record within the required 15 days? period.Cause Due to a miscommunication within institutional officials in charge of managing this process, three disbursements were not submitted on a timely basis. Fiscal year 2020-2021 was an unusual year due to the COVID-19 pandemic which caused significant disruptions of normal operating procedures; principally due to the fact that operations were carried most of the time on-line with no physical presence at the University?s premises, as required by the Governor?s executive orders. Effect A school?s failure to submit disbursement records within the required time frame may result in an audit or program review finding. In addition, the Department may initiate an adverse action, such as a fine or other penalty for such failure Questioned Cost None Context Of the 40 students examined on the eligibility sample, 32 received Pell. We used those 32 students for testing and noted 3 instances in which the University did not comply with the Submitting Disbursement Records requirement submission limit of 15 days. Recommendation Management should keep improving the Submitting Disbursement Record policies and procedures and should reinforce its monitoring in order to ensure that the process is completed in a timely and accurate manner. Views of responsible officials and planned corrective actions The University management agrees with this finding. Please refer to the corrective action plan on page 53.

Show full finding ▾
Full finding narrative

Criteria A school must submit Federal Pell Grant, TEACH Grant, and Direct Loan disbursement records no later than 15 days after making a disbursement or becoming aware of the need to adjust a student?s disbursement. Condition During our examination of the disbursement of Pell to students, from thirty-two (32) cases of students examined, we found that in three (3) cases, the University did not submit the disbursement record within the required 15 days? period.Cause Due to a miscommunication within institutional officials in charge of managing this process, three disbursements were not submitted on a timely basis. Fiscal year 2020-2021 was an unusual year due to the COVID-19 pandemic which caused significant disruptions of normal operating procedures; principally due to the fact that operations were carried most of the time on-line with no physical presence at the University?s premises, as required by the Governor?s executive orders. Effect A school?s failure to submit disbursement records within the required time frame may result in an audit or program review finding. In addition, the Department may initiate an adverse action, such as a fine or other penalty for such failure Questioned Cost None Context Of the 40 students examined on the eligibility sample, 32 received Pell. We used those 32 students for testing and noted 3 instances in which the University did not comply with the Submitting Disbursement Records requirement submission limit of 15 days. Recommendation Management should keep improving the Submitting Disbursement Record policies and procedures and should reinforce its monitoring in order to ensure that the process is completed in a timely and accurate manner. Views of responsible officials and planned corrective actions The University management agrees with this finding. Please refer to the corrective action plan on page 53.

Corrective Action Plan

The University affirms its understanding of its obligation to submit disbursement record of a FSA payment to a student no later than 15 days after making a disbursement or becoming aware of the need too adjust a student?s disbursement. Due to a miscommunication within institutional officials in charge of managing this process, three disbursements was not submitted on a timely basis. Fiscal year 2020-2021 was an unusual year due to the COVID-19 pandemic which caused significant disruptions of normal operating procedures; principally due to the fact that operations were carried must of the time on-line with no physical presence at the University?s premises, as required by the Governor?s executive orders. As of the date of the auditors? report, the University request all of the institution?s officials to work in the school premises and the communication between officials has been improve, making more easy the tracking of the disbursements on a timely basis to students.

About Special Tests and Provisions →

FY 2020-06-30

$11,351,906 federal awards expended

FAC accepted this audit on June 29, 2021 — management decision was due December 29, 2021.

2020-001
Equipment & Real Property
OTHER MATTERS

Finding No. 2020?001 ? STEM II ? Physical Inventory of Equipment Federal Program Name Developing Hispanic ? Serving Institutions STEM Program (CFDA No. 84.031C) Name of Federal Agency U.S. Department of Education Pass-through Entity N/A Criteria As required by Uniform Guidance - 2 CFR, 200.313-Equipment - equipment must be used in the program for which it was acquired or, when appropriate, other Federal programs with a proper authorization. Equipment records shall be maintained, a physical inventory of equipment shall be taken at least once every 2 years and reconciled to the equipment records, an appropriate control system shall be used to safeguard equipment, and equipment shall be adequately maintained. Condition In testing compliance with the Equipment and real property requirement of STEM II Program, we noted the entity did not perform the physical inventory count required at least once every 2 years. Cause Due to the COVID-9 pandemic effect on the entity and the several lockdowns faced in Puerto Rico this year, the personnel in charge of making the physical inventory count was not able to take it.Effect This condition could result in the misappropriation of the assets that had not been properly inventoried. Questioned Costs None. Context No physical inventory count has been taken for more than two years. Identification of a Repeat Finding This finding was not included in the previous audit. Recommendation The University management should reinforce its procedures to ensure that the physical inventory count of equipment purchased with federal fund is taken every two years. Alternative plans and procedures should be developed to handle unexpected situations during the year the physical inventory count should be taken. Views of Responsible Officials and Planned Corrective Actions The University management agrees with this finding. Refer to the corrective action plan on page 53.

Show full finding ▾
Full finding narrative

Finding No. 2020?001 ? STEM II ? Physical Inventory of Equipment Federal Program Name Developing Hispanic ? Serving Institutions STEM Program (CFDA No. 84.031C) Name of Federal Agency U.S. Department of Education Pass-through Entity N/A Criteria As required by Uniform Guidance - 2 CFR, 200.313-Equipment - equipment must be used in the program for which it was acquired or, when appropriate, other Federal programs with a proper authorization. Equipment records shall be maintained, a physical inventory of equipment shall be taken at least once every 2 years and reconciled to the equipment records, an appropriate control system shall be used to safeguard equipment, and equipment shall be adequately maintained. Condition In testing compliance with the Equipment and real property requirement of STEM II Program, we noted the entity did not perform the physical inventory count required at least once every 2 years. Cause Due to the COVID-9 pandemic effect on the entity and the several lockdowns faced in Puerto Rico this year, the personnel in charge of making the physical inventory count was not able to take it.Effect This condition could result in the misappropriation of the assets that had not been properly inventoried. Questioned Costs None. Context No physical inventory count has been taken for more than two years. Identification of a Repeat Finding This finding was not included in the previous audit. Recommendation The University management should reinforce its procedures to ensure that the physical inventory count of equipment purchased with federal fund is taken every two years. Alternative plans and procedures should be developed to handle unexpected situations during the year the physical inventory count should be taken. Views of Responsible Officials and Planned Corrective Actions The University management agrees with this finding. Refer to the corrective action plan on page 53.

Corrective Action Plan

Finding No. 2020?001 ? STEM II ? Physical Inventory of Equipment Name of Contact Person: Juan Jose Garcia-Rodriguez, CPA Dean of Administration and Finance Corrective Action Plan The University affirms its understanding of its obligation to perform physical inventory counts of equipment acquired with Federal funds every two years. Fiscal year 2019-2020 was an unusual year due to the COVID-19 pandemic which caused significant disruptions of normal operating procedures; principally due to the fact that operations were carried on-line with no physical presence at the University?s premises, as required by the Governor?s executive orders. As of the date of the auditors? report, the University has completed the physical inventory of all equipment acquired with Federal funds and taken action in order to avoid any recurrence or violation with the provisions of the Uniform Guidance ? 2 CFR, 200.313 ? Equipment.

About Equipment and Real Property Management →
2020-002
Reporting
OTHER MATTERS

Finding No. 2020?002 ? Emergency Assistance ? Reporting Federal Program Name Hurricane Education Recovery (CFDA No. 84.938) Name of Federal Agency U.S. Department of Education Pass-through Entity N/A Criteria As required by Uniform Guidance ? 2 CFR, 200.328 ? Financial reporting - Unless otherwise approved by OMB, the Federal awarding agency must solicit only the OMB - approved governmentwide data elements for collection of financial information (at time of publication the Federal Financial Report or such future, OMB-approved, governmentwide data elements available from the OMB-designated standards lead. This information must be collected with the frequency required by the terms and conditions of the Federal award, but no less frequently than annually nor more frequently than quarterly except in unusual circumstances, for example where more frequent reporting is necessary for the effective monitoring of the Federal award or could significantly affect program outcomes, and preferably in coordination with performance reporting. The Federal awarding agency must use OMB-approved common information collections, as applicable, when providing financial and performance reporting information. Condition In testing compliance with the Reporting Requirement of Emergency Assistance Program, as required by Uniform Guidance ? 2 CFR, 200.328 ? Financial reporting, due to the entity received the grant on December 18, 2018, it was required to submit its performance report no later than December 18, 2019, but it was submitted by management on March 31, 2020. Cause During October 2019, the University received a reminder from the agency related to the delay of the report due on July 31, 2019. This communication was not shared in a timely basis with the staff in charge of managing program funds.Effect The University did not comply with the requirements to report the status of the projects carried out with the allocated funds, which does not allow the agency to effectively monitor the assigned projects in the awarding of the funds. Questioned Costs None. Context Performance reporting was not submitted at least annually as required by Uniform Guidance ? 2 CFR, 200.328 ? Reporting. Identification of a Repeat Finding This finding was not included in the previous audit. Recommendation The University management should reinforce its procedures to ensure that the required reports related to federal grants are submitted on time. Alternative plans and procedures should be developed to handle unexpected situations close to the due date of the report.Views of Responsible Officials and Planned Corrective Actions The University management agrees with this finding. Refer to the corrective action plan on page 53.

Show full finding ▾
Full finding narrative

Finding No. 2020?002 ? Emergency Assistance ? Reporting Federal Program Name Hurricane Education Recovery (CFDA No. 84.938) Name of Federal Agency U.S. Department of Education Pass-through Entity N/A Criteria As required by Uniform Guidance ? 2 CFR, 200.328 ? Financial reporting - Unless otherwise approved by OMB, the Federal awarding agency must solicit only the OMB - approved governmentwide data elements for collection of financial information (at time of publication the Federal Financial Report or such future, OMB-approved, governmentwide data elements available from the OMB-designated standards lead. This information must be collected with the frequency required by the terms and conditions of the Federal award, but no less frequently than annually nor more frequently than quarterly except in unusual circumstances, for example where more frequent reporting is necessary for the effective monitoring of the Federal award or could significantly affect program outcomes, and preferably in coordination with performance reporting. The Federal awarding agency must use OMB-approved common information collections, as applicable, when providing financial and performance reporting information. Condition In testing compliance with the Reporting Requirement of Emergency Assistance Program, as required by Uniform Guidance ? 2 CFR, 200.328 ? Financial reporting, due to the entity received the grant on December 18, 2018, it was required to submit its performance report no later than December 18, 2019, but it was submitted by management on March 31, 2020. Cause During October 2019, the University received a reminder from the agency related to the delay of the report due on July 31, 2019. This communication was not shared in a timely basis with the staff in charge of managing program funds.Effect The University did not comply with the requirements to report the status of the projects carried out with the allocated funds, which does not allow the agency to effectively monitor the assigned projects in the awarding of the funds. Questioned Costs None. Context Performance reporting was not submitted at least annually as required by Uniform Guidance ? 2 CFR, 200.328 ? Reporting. Identification of a Repeat Finding This finding was not included in the previous audit. Recommendation The University management should reinforce its procedures to ensure that the required reports related to federal grants are submitted on time. Alternative plans and procedures should be developed to handle unexpected situations close to the due date of the report.Views of Responsible Officials and Planned Corrective Actions The University management agrees with this finding. Refer to the corrective action plan on page 53.

Corrective Action Plan

Finding No. 2020?002 ? Emergency Assistance Reporting Name of Contact Person: Elaine Nu?ez Compliance Officer Corrective Action Plan The University affirms its understanding of its obligation to perform the Reporting requirement of Emergency Assistance Program. Due to a miscommunication, the Annual reporting was not submitted on a timely basis. Fiscal year 2019-2020 was an unusual year due to the COVID-19 pandemic which caused significant disruptions of normal operating procedures; principally due to the fact that operations were carried on-line with no physical presence at the University?s premises, as required by the Governor?s executive orders. As of the date of the auditors? report, the University completed and submitted the Annual Performance Report for the FY 2020 in a timely basis when requested by the Department and evidence was submitted to the auditors, taking action in order to avoid any recurrence or violation with the provisions of the Uniform Guidance ? 2 CFR, 200.328 ? Financial Reporting.

About Reporting →

FY 2019-06-30

$11,728,146 federal awards expended

FAC accepted this audit on July 25, 2020 — management decision was due January 25, 2021.

2019-001
Special Tests & Provisions
OTHER MATTERS

Criteria Under the provisions of 16 CFR 314.3 schools shall develop, implement and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards, listed on 16 CFR 314.4, that are appropriate to the University?s size and complexity. Information security program shall be reasonably designed to achieve their objectives, as follows: (1) insure the security and confidentiality of customer information; (2) protect against any anticipated threats or hazards to the security or integrity of such information; and (3) protect against unauthorized access to or used of such information that could result in substantial harm of inconvenience to any customer. Condition During our review of the Information System structure we identified that the University has not developed, implemented or maintained a formal Information Security Program which includes all elements required in the three main areas as required by 16 CFR 314.4. Although we observed that significant effort has been taken by the University to implement practices for complying and being on par with security best practice frameworks and the desire to act in order to ensure the security of Personally Identifiable Information (?PII?), the implemented framework does not address the main areas included in the Gramm-Leach-Bliley Act (Public Law 106-102). Cause The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as "financial institutions" and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi). Under an institution's Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Review and inquiry procedures disclosed that the University has not developed, implemented or maintained a formal Information Security Program which includes: a designated employee or employee to coordinate your information security program; a risk assessment that addresses the three required areas noted in 16 CFR 314.4; detection, preventing and responding to attacks, intrusion, or other systems failures; and oversee service providers. Although a significant effort has been taken by the University to implement practices for complying and meet the security best practice frameworks, procedures and manuals, an Information System Security Program has not been formally developed and implemented due to the departure of the Information System and Telecommunications Director.Questioned Costs None Effect Information security is the process by which institutions protects the creation, collection, storage, use, transmission, and disposal of sensitive information, including the protection of hardware and infrastructure used to store and transmit such information. Information security promotes the commonly accepted objectives of confidentiality, integrity, and availability of information and is essential to the overall safety and soundness of an institution. Information security exists to provide protection from malicious and non- malicious actions that increase the risk of adverse effects on earnings, capital, or enterprise value. The potential adverse effects that can arise from not having a proper Information Security Program include disclosure of information to unauthorized individuals, unavailability or degradation of services, modification or destruction of systems or information as well as possible critical data losses which can lead to fines, sanctions, and reputational damage.Context From an interview that our consulting department and personnel, including professionals with CISA certification, with the IT personnel of the entity, we determined that, according to client responses, the entity has not developed, implemented or maintained a formal Information Security Program. Recommendation The University must develop and maintain an effective information security program commensurate with its operational complexities. The information security programs should have strong board and senior management support, promote integration of security activities and controls throughout the institution?s business processes, and establish clear accountability for carrying out security responsibilities. In addition, because of the frequency and severity of cyber-attacks, the institution should place an increasing focus on cybersecurity controls, a key component of information security. To comply with corresponding regulation (16 CFR 314), the University must develop or contract external resources to help develop, implement, and maintain its information security program that must include the following: a) Designate an employee or employees to coordinate the information security program. (b) Identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other systems failures. (b) Design and implement information safeguards to control the risks identified through the risk assessment, and regularly test or otherwise monitor the effectiveness of the safeguards' key controls, systems, and procedures.(c) Oversee service providers, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; and (2) Requiring service providers by contract to implement and maintain such safeguards. a. Evaluate and adjust the information security program in light of the results of the testing and monitoring required by paragraph (c) of this section; any material changes to the operations or business arrangements; or any other circumstances that you know or have reason to know may have a material impact on your information security program.Views of responsible officials and planned corrective actions The University management agrees with this finding. Please refer to the corrective action plan on pages 46.

Show full finding ▾
Full finding narrative

Criteria Under the provisions of 16 CFR 314.3 schools shall develop, implement and maintain a comprehensive information security program that is written in one or more readily accessible parts and contains administrative, technical, and physical safeguards, listed on 16 CFR 314.4, that are appropriate to the University?s size and complexity. Information security program shall be reasonably designed to achieve their objectives, as follows: (1) insure the security and confidentiality of customer information; (2) protect against any anticipated threats or hazards to the security or integrity of such information; and (3) protect against unauthorized access to or used of such information that could result in substantial harm of inconvenience to any customer. Condition During our review of the Information System structure we identified that the University has not developed, implemented or maintained a formal Information Security Program which includes all elements required in the three main areas as required by 16 CFR 314.4. Although we observed that significant effort has been taken by the University to implement practices for complying and being on par with security best practice frameworks and the desire to act in order to ensure the security of Personally Identifiable Information (?PII?), the implemented framework does not address the main areas included in the Gramm-Leach-Bliley Act (Public Law 106-102). Cause The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as "financial institutions" and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi). Under an institution's Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Review and inquiry procedures disclosed that the University has not developed, implemented or maintained a formal Information Security Program which includes: a designated employee or employee to coordinate your information security program; a risk assessment that addresses the three required areas noted in 16 CFR 314.4; detection, preventing and responding to attacks, intrusion, or other systems failures; and oversee service providers. Although a significant effort has been taken by the University to implement practices for complying and meet the security best practice frameworks, procedures and manuals, an Information System Security Program has not been formally developed and implemented due to the departure of the Information System and Telecommunications Director.Questioned Costs None Effect Information security is the process by which institutions protects the creation, collection, storage, use, transmission, and disposal of sensitive information, including the protection of hardware and infrastructure used to store and transmit such information. Information security promotes the commonly accepted objectives of confidentiality, integrity, and availability of information and is essential to the overall safety and soundness of an institution. Information security exists to provide protection from malicious and non- malicious actions that increase the risk of adverse effects on earnings, capital, or enterprise value. The potential adverse effects that can arise from not having a proper Information Security Program include disclosure of information to unauthorized individuals, unavailability or degradation of services, modification or destruction of systems or information as well as possible critical data losses which can lead to fines, sanctions, and reputational damage.Context From an interview that our consulting department and personnel, including professionals with CISA certification, with the IT personnel of the entity, we determined that, according to client responses, the entity has not developed, implemented or maintained a formal Information Security Program. Recommendation The University must develop and maintain an effective information security program commensurate with its operational complexities. The information security programs should have strong board and senior management support, promote integration of security activities and controls throughout the institution?s business processes, and establish clear accountability for carrying out security responsibilities. In addition, because of the frequency and severity of cyber-attacks, the institution should place an increasing focus on cybersecurity controls, a key component of information security. To comply with corresponding regulation (16 CFR 314), the University must develop or contract external resources to help develop, implement, and maintain its information security program that must include the following: a) Designate an employee or employees to coordinate the information security program. (b) Identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other systems failures. (b) Design and implement information safeguards to control the risks identified through the risk assessment, and regularly test or otherwise monitor the effectiveness of the safeguards' key controls, systems, and procedures.(c) Oversee service providers, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; and (2) Requiring service providers by contract to implement and maintain such safeguards. a. Evaluate and adjust the information security program in light of the results of the testing and monitoring required by paragraph (c) of this section; any material changes to the operations or business arrangements; or any other circumstances that you know or have reason to know may have a material impact on your information security program.Views of responsible officials and planned corrective actions The University management agrees with this finding. Please refer to the corrective action plan on pages 46.

Corrective Action Plan

Finding No. 2019-001 ? Special Test and Provisions ? Gramm Leach Bliley Act ? Student Information Security Name of contact Person: Mr. Jose Rodriguez Information System and Telecommunications Specialist Corrective Action Plan: Universidad Central de Bayamon (the University) affirms that is in complete understanding of its obligation related to the Information Security Program that protects the creation, collection, storage, use, transmission, and disposal of sensitive information, including the protection of hardware and infrastructure used to store and transmit such information. In addition, the University is taking all necessary corrective actions and procedures to avoid any recurrence or violation to this regulation 16 CFR 314.3, 16 CFR 314.4 and the Gramm Leach Bliley Act. The University accepted the auditor?s recommendations. The University is developing an effective information security program commensurate with its operational complexities. The information security program will have strong board and senior management support, promote integration of security activities and controls throughout the institution?s business processes, and establish clear accountability for carrying out security responsibilities. In addition, because of the frequency and severity of cyber-attacks, the institution is focusing its efforts on the cybersecurity controls, a key component of information security. This will help de Institution to avoid cyber-attacks and breach of information. The University, in its best interest to comply with the implementation of an information security program, 16 CFR 314.3, 16 CFR 314.4 and the Gramm Leach Bliley Act has: (a) Designated an employee to coordinate the information security program and a committee that will observe and assess the efficiency of all institutional policies and procedures. (b) Identified reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assessed the sufficiency of any safeguards in place to control these risks. The risk assessment includes consideration of risks in each relevant area of operations, including:(1) Employee training and management to teach them how to identify a possible cyber security threat and how to prevent them; (2) Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) Detecting, preventing and responding to attacks, intrusions, or other systems failures and ensure that all new threats will be addressed as soon as possible. (c) Design and implement information safeguards to control the risks identified through the risk assessment, and regularly test or otherwise monitor the effectiveness of the safeguards' key controls, systems, and procedures. (d) Oversee service providers, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue and ensure that their security standards comply with federal, state, local and institutional requirements; and (2) Requiring service providers by contract to implement and maintain such safeguards. In addition, the institutional risk assessment will evaluate and adjust the information security program considering the results of the testing and monitoring required by paragraph (c) of this section; any material changes to the operations or business arrangements; or any other circumstances that could represent a material impact on the institutional information security program. To ensure the effectiveness of cyber security and to prevent possible cyber-attacks and the breach of information the institution has in place the following resources: (1)To ensure the security and confidentiality of users data: (a) Policy to address situations of cyber security, information protection and identity theft. (b) Web use policy and standards. (c) Standards and procedures to address situations of cyber security and mitigation of information system failures. (d) Design and implementation of a strong Web. (e) Information System database architecture manual. (2) To ensure detection and prevention of cyber-attacks to institutional hardware the institution has: (a) Palo Alto Network Firewall & Content manager that filter, monitor and register every input and output of data in the web. (b) ELFIQ load balancer help us detect a possible treat of cyber-attack. (3) To ensure software and data protection the institution has the following measures: (a) The use a unique web domain that limit the user?s access to institutional resources. (b) The Active Directory platform to manage user accounts and control the access users have to institutional resources.(c) The use of a unique Students Information Systems that controls the student?s database and user?s privileges. (d) The use of domain controlled Windows Defender that incorporates the firewall, anti-malware antivirus. (e) The use Microsoft Windows Server Update Services. (f) Windows System Center Data Protection Manager and VEEAM backup and replication. (g) The use of external web servers to maintain online services outside the local web system, none of the external servers has personal identifiable data from users (employees or students). (h) The institutional and academic email system is in the Cloud Office 365, managed and secured by Microsoft. (i) An implemented and updated Windows 10 Professional at institutional level. (j) Microsoft is doing an assessment of institutional infrastructure, workstations, servers, networks and security tools and procedures to ensure their efficiency.

About Special Tests and Provisions →

FY 2018-06-30

$12,204,142 federal awards expended

FAC accepted this audit on March 28, 2019 — management decision was due September 28, 2019.

2018-001
Special Tests & Provisions
REPEAT OF 2017-001QUESTIONED COSTSOTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2017-001

About Special Tests and Provisions →

FY 2017-06-30

$12,483,099 federal awards expended

FAC accepted this audit on March 22, 2018 — management decision was due September 22, 2018.

2017-001
Special Tests & Provisions
QUESTIONED COSTSOTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →
2017-002
Special Tests & Provisions
REPEAT OF 2016-001OTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-001

About Special Tests and Provisions →

FY 2016-06-30

$12,607,308 federal awards expended

FAC accepted this audit on March 29, 2017 — management decision was due September 29, 2017.

2016-001
Special Tests & Provisions
OTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →
2016-002
Special Tests & Provisions
QUESTIONED COSTSOTHER MATTERS

GSA_MIGRATION

Show full finding ▾
Full finding narrative

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Browse other Single Audit organizations in Puerto Rico

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and filing records.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.