Dewey University, Inc.

EIN: 660498051

UEI: LFHNRRX5ZRK5

Data as of August 21, 2026

10
Audit Years
12
Total Findings
2
Repeat Findings

FY 2025-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 31, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by October 1, 2026 (41 days from today).

What is a management decision? →
2025-001
Cost Allowability / Cash Management
QUESTIONED COSTS
Condition

Unallowable Cost and Improper Cash Drawdown Federal Program ALN 84.031M Promoting Postbaccalaureate Opportunities for Hispanic Americans Program (PPOHA) Name of Federal Agency U.S. Department of Education Compliance Requirement Allowable Cost/Cost Principles Cash Management Type of Finding: Non-compliance / Internal Control over Compliance Category Significant Deficiency Criteria: In accordance with 2 CFR Part 200 Subpart E – Cost Principles, federal awards may only be used to reimburse allowable costs that have been properly incurred and supported, reimbursement requests must be based on actual expenditures. Additionally, per 2 CFR §200.305, Cash Management, payments must be limited to the minimum amounts needed and timed in accordance with the actual, immediate cash requirements of the entity. Condition: We noted that the University requested reimbursement for a cost that had not been incurred at the time of the request. Therefore, the reimbursement request was not supported by actual expenditures. Cause The condition was due to inadequate internal controls over the review and approval of reimbursement requests, including lack of verification that costs were incurred prior to submission. Effect Federal funds were drawn in excess of allowable amounts, resulting in noncompliance with cash management and allowable expenditures requirements. This increases the risk of excess cash on hand and may require repayment of funds to the grantor. Questioned Costs Known questioned costs of $610 were identified, representing the amount requested for reimbursement that was not incurred. Subsequent to year-end and prior to the issuance of the report, the University returned the full amount to the grantor. Context Total federal expenditures for the program during the audit period were $753,300. During the same period, the program processed a total of twenty-six (26) reimbursement petitions, comprising salaries, equipment, supplies, and scholarships. Within the equipment and supplies categories, there were sixty-seven (67) individual transactions totaling $254,931. The unallowable cost identified in this finding was included within these equipment and supplies transactions. Recommendation We recommend that management strengthen controls over reimbursement requests by ensuring all reimbursement requests are supported by incurred and documented expenditures. Implement a review process to verify allowability and timing of costs prior to submission. Provide training to personnel responsible for grant compliance. Identification of a repeat finding This is not a repeat finding. Views of Responsible Officials Management of the University agrees with this finding. Please refer to the corrective action plan on pages 45-51.

Corrective Action Plan

Statement of Concurrence and Technical Clarification The University concurs with the finding. It was identified that, due to an arithmetic calculation error in the fund request worksheet (Drawdown Worksheet), $610.00 was over-requested through the G5 system during fiscal year 2024. Mitigation Clarification This error was administrative and arithmetic in nature (“clerical error”). It does not represent a failure in the eligibility of PPOHA program expenses nor a misuse of funds. The excess amount remained identified in the accounting records and was not disbursed for purposes unrelated to the program. To rectify the excess funds and comply with cash management regulations (2 CFR § 200.305), the University has implemented the following:  Refund of Excess Funds: The University has proceeded with the return of the $610.00 to the Department of Education. (G5 transaction reference R2603185111, March 18, 2026.)  Standardized Calculation Template: A new protected Excel template has been created that automatically totals expenses from the General Ledger (GL), eliminating the possibility of manual calculation errors in reimbursement requests.  Secondary Review Requirement: Effective immediately, all fund requests (drawdowns) must be prepared by the Comptroller and reviewed by the Director of Finance before being processed in the G5 system. This segregation of duties ensures that a second official verifies the mathematical accuracy of the amount.  Monthly Reconciliation: A monthly reconciliation will be conducted between the expenses reported by the PPOHA Program Director and the fund requests processed by the Finance Department to ensure a zero balance at the close of each period.  With the establishment of new policies, processes, and supporting documentation, staff involved in the certification and drawdown process will receive training. Responsible Official:  Name: Yelitza Feliciano  Title: Executive Vice President  Email: Yelitza.feliciano@dewey.edu Timeline for Implementation:  Return of $610.00: Completed on March 18, 2026  Staff Training: April 1, 2026  Implementation of New Policies and Procedures: Effective April 1, 2026

About Allowable Costs / Cost Principles, Cash Management →
2025-002
Procurement & Suspension/Debarment
Condition

Failure to comply with Procurement and Suspension and Debarment requirements Federal Program ALN 84.031M Promoting Postbaccalaureate Opportunities for Hispanic Americans Program (PPOHA) Name of Federal Agency U.S. Department of Education Pass-through Entity N/A Compliance Requirement Procurement and Suspension and Debarment Type of Finding: Non-compliance / Internal Control over Compliance Category Significant Deficiency Criteria In accordance with 2 CFR §§200.318–200.327, non-federal entities are required to maintain effective internal controls over procurement processes, including proper documentation such as purchase orders, receiving reports, and evidence of price or rate quotations, as applicable. Additionally, pursuant to 2 CFR §180.220, non-Federal entities are prohibited from contracting with or making subawards to parties that are suspended or debarred and must verify that vendors are not excluded from participating in Federal programs. Further, in accordance with the University’s procurement policy, which establishes the policies, norms, and procedures for the acquisition of materials, equipment, and non-personal services, the entity is required to ensure that purchases are properly authorized, documented, and executed in accordance with established procedures. The policy outlines requirements including the use of purchase requisitions and purchase orders, verification of budget availability, obtaining required price quotations based on purchase thresholds, and appropriate approval processes prior to procurement. Condition As part of our tests of compliance with allowable costs and cost principles, we noted instances where key procurement and disbursement controls were not followed. Specifically, transactions lacked supporting documentation such as approved purchase orders, receiving reports, and/or evidence of required price quotations. In addition, for some transactions, procedures to verify that vendors were not suspended or debarred were not performed. Cause The condition was due to inadequate implementation and monitoring of procurement and disbursement controls, including lack of enforcement of established purchasing procedures and insufficient review to ensure required documentation and vendor eligibility verification were performed. Effect Goods and services that are not properly authorized, received, or competitively procured, increased risk of noncompliance with federal procurement requirements, and reduced ability to ensure costs charged to federal programs are reasonable and allowable. Not having the complete documentation at the time of recognition of an expenditure or when executing a payment may lead to inadequate recording, duplicity in recording or in payment, recording invalid transactions or unauthorized purchases. Questioned Cost None. Context Of the sixty-seven (67) disbursements, we selected fourteen (14) transactions for testing and noted the following instances of noncompliance: • Eight (8) transactions lacked supporting documentation such as approved purchase orders, receiving reports, and/or evidence of required price quotations. • Three (3) transactions Suspension and Debarment verification weren’t performed Recommendation We recommend that management enforce compliance with procurement policies and procedures. Ensure all purchases are supported by approved purchase orders, receiving documentation, and required quotations. Implement monitoring controls to ensure consistent application of procurement requirements. Provide training for personnel involved in purchasing and disbursement processes. Also, management should evaluate and revise the procurement policy, as necessary, to ensure thresholds and requirements are practical, risk-based, and aligned with the nature and volume of transactions. Identification of a Repeat Finding This is not a repeat finding from the immediate previous audit. Views of Responsible Officials: Management of the University agrees with this finding. Please refer to the corrective action plan on pages 45-51.

Corrective Action Plan

Strengthening of Procurement Controls  Implementation of a mandatory checklist prior to payment approval, which includes: o Approved purchase order o Evidence of required quotations identifying the selected quote o Receiving report o Vendor verification (not excluded/suspended)  The Title V Project Director will submit the required documentation to the Procurement Officer. The Procurement Officer will prepare the checklist, which must be signed by both officials.  Once it has been verified and certified that all procurement requirements have been met, the purchase will be completed.  Controls have been configured in the financial system to prevent payments without complete documentation. Page 4 of 7 Implementation of Vendor Verification Process  The formal procedure for validating vendors has been strengthened against: o SAM.gov  Documented evidence (screenshot or certification) is required before processing the purchase.  Evidence of the verification process in SAM.gov has been incorporated into the checklist included in the procurement process.  No payment will be processed for purchases that do not comply with the new requirements, policies, and implemented procedures. Staff Training Staff are being trained on the new standards, policies, and required documentation for the procurement process. Monitoring and Internal Audit  Quarterly reviews of procurement samples will be implemented to validate: o Complete documentation o Compliance with quotation requirements o Vendor verification  Results will be documented, and additional corrective actions will be taken if necessary. Responsible Official:  Name: Yelitza Feliciano  Title: Executive Vice President  Email: Yelitza.feliciano@dewey.edu Timeline for Implementation:  Staff Training: April 1, 2026  Implementation of New Policies and Procedures: Effective April 1, 2026 Expected Outcome: Once these actions are implemented:  100% of purchases will comply with documentation requirements  All vendors will be verified prior to contracting  The risk of unallowable costs will be significantly reduced

About Procurement and Suspension and Debarment →
2025-003
Special Tests & Provisions
Condition

Gramm-Leach-Bliley Act–Student Information Security Federal Program Students Financial Assistance Programs Cluster: ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency U.S. Department of Education Pass-through Entity N/A Type of Finding Non-compliance / Internal Control over Compliance Category Significant deficiency Compliance Requirement Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Condition During our audit procedures, we noted that the University’s information security program did not fully address all elements required by 16 CFR §314.4. Specifically, the following deficiencies were identified: • The risk assessment did not fully address all required components of the GLBA Safeguards Rule. • The University did not obtain or review security reports (e.g., SOC 1/2 Type II or equivalent third-party security certifications ) for critical IT vendors in accordance with CFR 314.4(f). • Backup and recovery tests were not performed or documented during the audit period. • Physical access controls over the datacenter were not adequate, including lack of visitor logs and unrestricted/shared access. Cause The condition was due to inadequate implementation and monitoring of the information security program, including lack of formalized processes and oversight to ensure compliance with GLBA requirements. Effect Sensitive student financial aid information may be exposed to unauthorized access, loss, or disruption. In addition, the lack of adequate safeguards over system availability and third-party service providers increases the risk of data compromise or operational interruptions. Noncompliance with GLBA requirements may also result in regulatory scrutiny, as the Department of Education may refer such findings to the Federal Trade Commission (FTC) for further evaluation and potential enforcement actions. Questioned cost None. Context The Gramm-Leach-Bliley Act (GLBA) requires institutions participating in federal student aid programs to implement administrative, technical, and physical safeguards to protect student information. These requirements are enforced by the Federal Trade Commission under 16 CFR Part 314 and are incorporated into the institution’s Program Participation Agreement with the Department of Education. Recommendation We recommend that management strengthen its information security program to ensure compliance with 16 CFR §314.4 by: • Performing a comprehensive risk assessment that addresses all relevant risks to the confidentiality, integrity, and availability of student information. • Establishing formal processes for obtaining, reviewing, and documenting security reports for critical IT vendors. • Implementing and documenting periodic backup and recovery testing to ensure system availability and data recoverability. • Strengthening physical access controls over IT infrastructure, including restricting access and maintaining visitor logs. • Evaluating and enhancing safeguards over systems and infrastructure supporting financial aid data to ensure adequate protection. Identification of a repeat finding This is not a repeat finding from the immediate previous audit. Views of Responsible Officials Management of the University agrees with this finding. Please refer to the corrective action plan on pages 45-51.

Corrective Action Plan

Statement of Concurrence and Technical Clarification The University concurs with the finding related to compliance with the Gramm-Leach-Bliley Act, specifically with the requirements of the Safeguards Rule (16 CFR Part 314). Management acknowledges that certain components of the information security program were not fully implemented or documented during the audit period, including risk assessment, vendor management, backup testing, and physical access controls. However, no evidence of security breaches or unauthorized access to confidential information was identified during the period under review. The finding is related to deficiencies in the formalization, documentation, and monitoring of existing controls. Actions Enhancement of Risk Assessment Process  A comprehensive risk assessment will be developed and documented, including all components required by GLBA, such as: o Information systems security o Risks associated with third-party vendors o System availability and disaster recovery o Physical controls  For the current fiscal year 2025–2026, a full risk assessment has already been completed. However, the University will perform an additional assessment to ensure full compliance with the requirement. Vendor Risk Management (CFR § 314.4(f)  A formal process for managing critical vendors will be implemented, including: o Annual collection and review of security reports  Mandatory training will be provided to relevant staff (IT, Finance, Compliance) on: o GLBA requirements o Newly implemented procedures o Secure handling of confidential information Responsible Official  Name: Marcos Cruz  Title: Information Systems Coordinator  Email: marcos.cruz1@dewey.edu Timeline for Implementation  Staff Training: April 15, 2026  Full Program Implementation: All actions, including construction to restrict access to the physical information systems area, will be completed by June 30, 2026. Expected Outcome Once these actions are implemented:  Full compliance with the GLBA Safeguards Rule requirements  Effective management of risks associated with third-party vendors  Increased operational resilience through recovery testing  Enhanced protection of confidential information  Significant reduction in the risk of regulatory noncompliance and exposure to sanctions from entities such as the Federal Trade Commission o Development of a vendor security questionnaire o Evaluation of third-party security controls prior to engagement o Inclusion of contractual security and confidentiality clauses  Documented evidence of the review and approval of each vendor will be maintained. Backup and Recovery Testing  A formal procedure will be established to: o Perform periodic backup and recovery testing (at least annually) Document results, findings, and corrective actions  A testing schedule will be implemented, and specific responsibility will be assigned for execution and validation. Physical Security Controls – Data Center  Physical access controls will be strengthened through: o Implementation of mandatory visitor logs o Restricting access to authorized personnel only o Elimination of shared or generic access  Periodic access reviews will be conducted to validate appropriateness.  The University has already obtained quotes and is in the process of contracting a company that will perform construction work to ensure the physical security of the information systems facilities. Monitoring and Oversight  A continuous monitoring process for the information security program will be established, including: o Quarterly GLBA compliance reviews o Documentation of evidence of implemented controls o Periodic reporting to senior management

About Special Tests and Provisions →

FY 2023-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 28, 2024. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 28, 2024, which was (692 days ago).

What is a management decision? →
2023-001
Special Tests & Provisions
Condition

Finding No. 2023-001 Gramm-Leach-Bliley Act–Student Information Security Federal Program ALN 84.007 Federal Supplemental Educational Opportunity Grant Program ALN 84.033 Federal Work-Study Program ALN 84.063 Federal Pell Grant Program ALN 84.268 Federal Direct Student Loan Program Name of Federal Agency U.S. Department of Education Pass-through Entity N/A Type of Finding Compliance Internal of Control Category Significant deficiency Compliance Requirement N. Special Tests and Provisions Criteria Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs.The Gramm-Leach-Bliley Act (GLBA) (Pub. L. No. 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). The Standards for Safeguarding Customer Information, required by the GLBA (16 CFR §314.4) requires the University to: a) Designates a qualified individual responsible for overseeing and implementing the institution’s information security program and enforcing the information security program in compliance (16 CFR 314.4(a)). b) Provides for the information security program to be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information (as the term customer information applies to the institution) that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks (16 CFR 314.4(b)). c) Provides for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The eight minimum safeguards that the written information security program must address are summarized as follows: 1. Implement and periodically review access controls. 2. Conduct a periodic inventory of data, noting where it’s collected, stored, or transmitted. 3. Encrypt customer information on the institution’s system and when it’s in transit. 4. Assess apps developed by the institution. 5. Implement multi-factor authentication for anyone accessing customer information on the institution’s system. 6. Dispose of customer information securely. 7. Anticipate and evaluate changes to the information system or network. 8. Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. d) Provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)).Criteria – (continued) e) Provides for the implementation of policies and procedures to ensure that personnel are able to enact the information security program (16 CFR 314.4(e)(1)). f) Addresses how the institution will oversee its information system service providers (16 CFR 314.4(f)). g) Provides for the evaluation and adjustment of its information security program in light of the results of the required testing and monitoring; any material changes to its operations or business arrangements; the results of the required risk assessments; or any other circumstances that it knows or has reason to know may have a material impact the institution’s information security program (16 CFR 314.4(g)). Additionally, the Uniform Guidance (2 CFR 200.303(a)) requires nonfederal entities receiving federal awards to establish and maintain effective internal controls designed to reasonably ensure compliance with Federal laws, statutes, regulations, and the terms and conditions of the Federal award. Furthermore, generally accepted information technology guidance endorses the implementation of a process to identify risk and ensure appropriate safeguards are in place to protect information technology systems and data. Condition During our audit procedures, we noted that the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Evidence of annual security report to those charge with governance 2. Vulnerability test 3. Disaster recovery plan 4. No backup test was performed during year ended June 30, 2023. Cause In the past years there’s been a high turnover in the position of the qualified individual responsible for overseeing and implementing the institution’s information security program. As a result, some of the procedures and policies established in the information security program risk assessment have not been consistently or continuously maintained. Effect The student personal information could be vulnerable. In addition, the Department of Education (DE) has informed through electronic announcements (EA), that “when an audit report that includes a GLBA audit finding is received by the Department, they will refer the audit to the Federal Trade Commission (FTC). Once the finding is referred to the FTC, that finding will be considered closed for the Department’s audit tracking purposes. The FTC will determine what action may be needed as a result of the GLBA audit finding.” Questioned cost N/A Context The Gramm-Leach-Bliley Act (GLBA) created a requirement that financial institutions must have certain information privacy protections and safeguards in place. The Federal Trade Commission (FTC) has enforcement authority for the requirements and has determined that institutions of higher education (institutions) are financial institutions under GLBA. Each institution has agreed to comply with GLBA in its Program Participation Agreement with the Department. In addition, as a condition of accessing the Department’s systems, each institution and servicer must sign the Student Aid Internet Gateway (SAIG) Enrollment Agreement, which states that the institution must ensure that all federal student aid applicant information is protected from access by or disclosure to unauthorized personnel. Institutions and third-party servicers are also required to demonstrate administrative capability in accordance with 34 C.F.R. § 668.16, including the maintenance of adequate checks and balances in their systems of internal control. An institution or servicer that does not maintain adequate internal controls over the security of student information may not be considered administratively capable. Identification of a repeat finding This is not a repeat finding. Recommendation We recommend that management implement policies and procedures, including internal controls, to ensure that they are in compliance with 16 CFR 314.4(b) and (c). Views of responsible officials and planned corrective actions The University’s management agrees with this finding. Please refer to the corrective action plan on pages 47-48.

Corrective Action Plan

Finding No. 2023-001 Gramm-Leach-Bliley Act–Student Information Security Condition During audit procedures, the auditor has noted the University risk assessment did not fully addressed all the elements required by (16 CFR 314.4). Accordingly, the following elements were missing: 1. Evidence of annual security report to those charges with governance The Qualified Individual (MIS Director) which is responsible for overseeing, implementing and enforcing the Information Security Program, will submit a written report. This report will include any recommended changes, material matters, security events or violations and management responses. This report is submitted to President of the institution including the Board of Trustees at least annually on a fiscal year basis commencing with the first report due by June 30, 2024. 2. Vulnerability test Vulnerability assessments of the institution information system will include systemic scans or reviews designed to identify publicly known security vulnerabilities, at least every six months; and/or whenever there are material changes or circumstances that may have a material impact on the information security program. In addition, the institution is evaluating the possibility a network scout services (a subscription base service), which runs a daily host discovery scan across the network to detect any unauthorized devices or changes. 3. Disaster recovery plan The institution will expand the disaster recovery plan to include the following:  The main datacenters have heat and humidity detection systems as well as a fire suppression system, alarms with motion detectors, security cameras set to 24 hours recording.  The University take reasonable steps to select and retain Service Providers who will maintain safeguards to protect Covered Data in compliance with GLBA.  Disaster Recovery Teams organized to respond to disasters of various type, size, and location. These teams will mobilized depending on the parameters of the disaster. It is the responsibility of the MIS Director to determine which Disaster Recover Teams to mobilize, following the declaration of a disaster. Each team will utilize their respective procedures, technical expertise, and recovery tools to return the information systems to operational status. The datacenter and network/telecommunications infrastructure will be a highest priority. 4. No backup test was performed to assure data accuracy during year ended June 30, 2023. The Datacenter department runs a daily basis backup on a secure server, but in order to assure the store data is accurate the institution is analyzing to implement a third party Backup Verification Application. The backup application offers a verification process, which includes:  Verifying the files' integrity/they have no corruption  Monitor for ransomware traces  Making sure the file system is stable  Checks to make sure a restore will work properly, if needed Anticipated completion date: June 30, 2024.

About Special Tests and Provisions →

FY 2021-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 30, 2022. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 30, 2022, which was (1421 days ago).

What is a management decision? →
2021-002
Special Tests & Provisions
Condition

During our evaluation of compliance with this requirement, we noted one (1) instance, or two percent (2%) of the sample selected, in which the University make the corresponding reporting in the 76th day failing to report such disbursement on COD no later than 15 days as required.

Corrective Action Plan

The incident noted by the external auditors were due to staff turnover during the Covid-19 pandemic, resulting in an inconsistent reporting during an isolated timeframe. The Financial Aid Administrator have reinforced to the corresponding personnel, the importance of timely review procedures and have established reporting timeframes within the corresponding separate offices. Such timeframe was set at least every two weeks for reviewing origination and disbursement reports and the Common Origination and Disbursement website.

About Special Tests and Provisions →

FY 2019-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on May 4, 2020. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by November 4, 2020, which was (2116 days ago).

What is a management decision? →
2019-001
Special Tests & Provisions
Condition

Condition Found During our evaluation of compliance with these requirements, we noted one (1) instance, or two percent (2%) of the sample selected, in which the University failed to return the corresponding refund within the 14 days time frame from the date the University determined that the student had a Federal Student Aid credit balance. Such instance corresponded to a credit balance amounting to $493 for the Fall 2018 academic period which was in excess of the required time frame by one (1) day. Cause The University?s Business Office submitted the approved credit balance check to the Bursar Officer during the require fourteen (14) days period. The Bursar Office is in charge of delivering the check directly to the student or by mail. Unfortunately, the check was misplaced and mailed one (1) day after the required deadline. Context In testing compliance with the requirements for disbursements under the Federal Pell Grant Program, we selected forty (40) participants, from a total population of one thousand three hundred and sixty (1,360) students, who received Pell Grant funds for the audit period and found one (1) instance of noncompliance. Following is a description of the sample and the population from which the samples were drawn for students that received Direct Loans funds for the year ended June 30, 2019: See Schedule of Findings and Questioned Costs for chart/table.

Corrective Action Plan

Based on other similar transactions managed without incidents and with no prior findings related to this issue, we consider this event as an isolated case. Nevertheless, the University has taken a proactive step to straighten its internal controls related to this matter to assure the Bursar Office returns the corresponding refunds to students during the required fourteen (14) days period. After refund checks are prepared and sent to the Bursar Officer in order to assure compliance, the Bursar Officer must submit twice a week to the Finance Department staff the evidence of the postal office stamp validation sheet so it can be corroborated and verified that all students refunds were sent by mail within the required time frame. This additional procedure enhances the monitoring controls and process of verification. Also, to mitigate this matter the University, in accordance with required federal regulations, is considering adopting the direct deposit process to disburse refunds to students.

About Special Tests and Provisions →
2019-002
Special Tests & Provisions
QUESTIONED COSTS
Condition

Condition Found When auditing the cash area, we became aware that the student refunds cash account has forty-six (46) students outstanding checks in excess of two hundred and forty (240) days of the issued date year. The checks amounted to $543.77 in the aggregate. As of the date of this report, these funds have not been returned to the USDE. Cause Due to a reorganization in the Business Department, the reconciliation process and follow up procedures for monitoring outstanding checks was assigned to a staff not familiarized with the procedure, who inadvertently during the last month of the year did not review the process according to the above deadline requirement. Context As of June 30, 2019, the Student Refunds cash account had two hundred sixty-six (266) outstanding checks totaling $89,077.26. From this amount, forty-six (46) outstanding checks, totaling $543.77, where in excess of two hundred and forty (240) days after the date the check was issued. Also, as part of our Disbursements to or on behalf of Students Special Test, we verified this compliance for a sample of fifty-four (54) Pell Grant and Federal Supplemental Educational Opportunity Grants disbursements out of a sample of forty (40) students. We verified that the funds were returned no later than two hundred and forty (240) days from the date of the issued check, if they were not cashed. No exceptions were noted on this particular test.

Corrective Action Plan

This condition was subsequently corrected as the University returned the funds to the corresponding federal programs on March 12, 2020 through the G-5 computerized system. Also, to avoid this issue, the University has established the following additional procedures to comply with the two hundred and forty (240) days requirement regulation for outstanding checks. The Business Officer in charge of the monthly bank reconciliations is required to provide a semi-monthly aging of the student?s refunds checks issued. He is also required to identify any outstanding check aged with a one hundred and eighty (180) days aging benchmark. After identifying which students are in the benchmark, a list of such cases will be prepared and submitted to the Finance Director including the Financial Aid Office. After the review and authorization of the list by both officers, the Business Officer will be instructed to cancel the checks and submit the proper refund to the USDE via electronic refund. Note that if the University is unable to locate the student (or parent) to whom a Title IV credit balance continues to be outstanding after one hundred and eighty 180 days of the date the check was issued, the Business Office will proceed to cancel the outstanding check and the corresponding funds will be returned to the USDE. Such refund will be sent through the G-5 System to the corresponding grant. This is not a recurring finding and this occurrence was caused by the resignation of the former officer in charge of the student check reconciliation process and the challenge it has represented the recruiting of a replacement of this position.

About Special Tests and Provisions →
2019-003
Special Tests & Provisions
Condition

Condition Under an institution?s Program Participation Agreement with the U.S. Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to the University by the USDE or otherwise obtained in support of the administration of the federal student financial aid programs. Review and inquiry procedures disclosed that the University has not developed, implemented or maintained a formal Information Security Program as required by the newly released Compliance Supplement (2019), since no formal Information Security Risk Assessment has been performed to sustain actual control environment. Cause As part of the development, implementation and maintenance of an information security program, the University must have designated an employee to coordinate the program. However, the key project personnel in charge resigned and the University could not replace this position in a short time. Context During year ended June 30, 2019, Dewey University had an enrollment of three thousand four hundred sixty-two (3,462) students. Financial aid information of this students, particularly information provided to the University by the USDE, could be compromised if the appropriate safeguards are not implemented. The Gramm?Leach?Bliley Act (GLBA) was enacted in 1999. GLBA requires financial institutions and institutions of higher education to explain their information-sharing practices to their customers and to safeguard sensitive data.

Corrective Action Plan

The University agrees with the recommendations presented recognizing the role of implementing the IT security program in order to preserve the confidentiality, integrity, availability, intended use and value of electronically stored, processed or transmitted information. The University has appointed a full-time project manager to continue with the development and implementation of an effective information security program. A detail implementation schedule is as follows: See Corrective Action Plan for chart/table

About Special Tests and Provisions →

FY 2018-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 28, 2019. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 28, 2019, which was (2519 days ago).

What is a management decision? →
2018-001
Special Tests & Provisions
Condition

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →
2018-002
Cost Allowability
QUESTIONED COSTS
Condition

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Allowable Costs / Cost Principles →

FY 2017-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 26, 2018. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 26, 2018, which was (2886 days ago).

What is a management decision? →
2017-001
Special Tests & Provisions
REPEAT
Condition

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2016-001

About Special Tests and Provisions →

FY 2016-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 23, 2017. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 23, 2017, which was (3254 days ago).

What is a management decision? →
2016-001
Special Tests & Provisions
REPEAT
Condition

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-002

About Special Tests and Provisions →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and compliance status.

Start monitoring →

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.