EIN: 680278640
UEI: KH5EABLM5LL7
Audited by: Nigro & Nigro, PC
Oversight agency: 16 [Department of Justice]
View federal awards & risk assessment →
Data as of August 31, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on February 26, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by August 26, 2026 (6 days ago).
What is a management decision? →FAC accepted this audit on February 7, 2025 — management decision was due August 7, 2025.
FAC accepted this audit on March 29, 2024 — management decision was due September 29, 2024.
FAC accepted this audit on March 29, 2023 — management decision was due September 29, 2023.
FAC accepted this audit on March 23, 2021 — management decision was due September 23, 2021.
The Project entered into a procurement contract for software of $49,538 but did not have documentation of three written quotes. Questioned Cost: The total purchase price of the software was $49,538. CalOES did approve a budget modification to include the cost of this software prior to its purchase. Context: N/A Effect: Failure to retain documentation of quotes and procurement procedures could lead to a lack of control over or transparency surrounding procurement transactions. Cause: The Project suffered a malware attack which caused them to lose certain electronically stored documentation and records. The Project indicated that the required quotes were obtained, however, the records of these quotes were lost, and therefore could not be verified during the audit process. Recommendation: We recommend that the Project retain all documentation related to procurement transactions. Views of Responsible Officials: In response to Audit Finding 2020-01 CFDA #16.575, Mendocino County Youth Project acknowledges the agency?s failure to provide appropriate documentation of purchase consistent with guidelines established within the current Procurement Policy. The inability to produce required documentation was due to loss of records caused by widespread malware attack on the agency?s computer system, incapacitating the system?s server including the entirety of all back up files. This malware attack did not pose any risk or data breach, only encryption/corruption of all system files and processing ability. Documentation provided by tech company states the diagnostic analysis conducted on the malware virus proved no compromise of client or employee data (see attached letter, name of tech company has been redacted for anonymity). Through this event, deficiencies were revealed within the services provided by said tech company; this information was previously unknown to the agency?s executive and management team. Therefore, in response to this massive failure of the agency?s computer security system, MCYP terminated it?s working relationship and service contract with the tech company who had been responsible for maintaining the agency?s computer system. The agency entered into an updated and expanded contract with alternate tech company on December 28, 2020. Contract with new tech company is extensive in its services to be provided to the agency with substantial improvements specific to system security components. To date the newly contracted tech company has installed all new computer system hardware and software. A stringent, multilevel, system server backup processes has been established which will guarantee full security of system server with corruption or loss unable to occur. The new security process includes generation of backup files on an hourly basis 24 hours a day, 7 days a week including an offsite, cloud based file save location. The agency will continue maintenance of these heightened system security processes to guarantee protection of all files. These implemented computer system improvements will ensure the agency?s ability to remain in compliance of record retention requirements going forward.
Show full finding ▾Hide full finding ▴Finding 2020-001: Procurement CFDA #16.575 ? U.S. Department of Justice, California Governor's Office of Emergency Services, Crime Victim Assistance Cluster Criteria: Non-Federal entities other than States, including those operating Federal programs as subrecipients of States, must follow the procurement standards set out at 2 CFR sections 200.318 through 200.326. They must use their own documented procurement procedures, which reflect applicable state and local laws and regulations, provided that the procurements conform to applicable Federal statutes and the procurement requirements identified in 2 CFR part 200. Additionally, per the California Governor's Office of Emergency Services Subrecipient Handbook, ?Contracts and procurements in the amount of $10,001 to $50,000 do not require formal advertising. However, it is required that a minimum of three quotes are obtained.? The Project?s own policies require that ?purchase decisions exceeding $25,000 for labor, equipment, supplies or services purchased, leased or contracted for shall be made only after receiving whenever possible, written quotations from at least three vendors.? Condition: The Project entered into a procurement contract for software of $49,538 but did not have documentation of three written quotes. Questioned Cost: The total purchase price of the software was $49,538. CalOES did approve a budget modification to include the cost of this software prior to its purchase. Context: N/A Effect: Failure to retain documentation of quotes and procurement procedures could lead to a lack of control over or transparency surrounding procurement transactions. Cause: The Project suffered a malware attack which caused them to lose certain electronically stored documentation and records. The Project indicated that the required quotes were obtained, however, the records of these quotes were lost, and therefore could not be verified during the audit process. Recommendation: We recommend that the Project retain all documentation related to procurement transactions. Views of Responsible Officials: In response to Audit Finding 2020-01 CFDA #16.575, Mendocino County Youth Project acknowledges the agency?s failure to provide appropriate documentation of purchase consistent with guidelines established within the current Procurement Policy. The inability to produce required documentation was due to loss of records caused by widespread malware attack on the agency?s computer system, incapacitating the system?s server including the entirety of all back up files. This malware attack did not pose any risk or data breach, only encryption/corruption of all system files and processing ability. Documentation provided by tech company states the diagnostic analysis conducted on the malware virus proved no compromise of client or employee data (see attached letter, name of tech company has been redacted for anonymity). Through this event, deficiencies were revealed within the services provided by said tech company; this information was previously unknown to the agency?s executive and management team. Therefore, in response to this massive failure of the agency?s computer security system, MCYP terminated it?s working relationship and service contract with the tech company who had been responsible for maintaining the agency?s computer system. The agency entered into an updated and expanded contract with alternate tech company on December 28, 2020. Contract with new tech company is extensive in its services to be provided to the agency with substantial improvements specific to system security components. To date the newly contracted tech company has installed all new computer system hardware and software. A stringent, multilevel, system server backup processes has been established which will guarantee full security of system server with corruption or loss unable to occur. The new security process includes generation of backup files on an hourly basis 24 hours a day, 7 days a week including an offsite, cloud based file save location. The agency will continue maintenance of these heightened system security processes to guarantee protection of all files. These implemented computer system improvements will ensure the agency?s ability to remain in compliance of record retention requirements going forward.
Finding 2020-001: Procurement Contact persons responsible: Joanna Olson, Amanda Archer CFDA #16.575 ? U.S. Department of Justice, California Governor's Office of Emergency Services, Crime Victim Assistance Cluster Criteria: Non-Federal entities other than States, including those operating Federal programs as subrecipients of States, must follow the procurement standards set out at 2 CFR sections 200.318 through 200.326. They must use their own documented procurement procedures, which reflect applicable state and local laws and regulations, provided that the procurements conform to applicable Federal statutes and the procurement requirements identified in 2 CFR part 200. Additionally, per the California Governor's Office of Emergency Services Subrecipient Handbook, ?Contracts and procurements in the amount of $10,001 to $50,000 do not require formal advertising. However, it is required that a minimum of three quotes are obtained.? The Project?s own policies require that ?purchase decisions exceeding $25,000 for labor, equipment, supplies or services purchased, leased or contracted for shall be made only after receiving whenever possible, written quotations from at least three vendors.? Condition: The Project entered into a procurement contract for software of $49,538 but did not have documentation of three written quotes. Questioned Cost: The total purchase price of the software was $49,538. CalOES did approve a budget modification to include the cost of this software prior to its purchase. Context: N/A Effect: Failure to retain documentation of quotes and procurement procedures could lead to a lack of control over or transparency surrounding procurement transactions. Cause: The Project suffered a malware attack which caused them to lose certain electronically stored documentation and records. The Project indicated that the required quotes were obtained, however, the records of these quotes were lost, and therefore could not be verified during the audit process. Auditor Recommendation: We recommend that the Project retain all documentation related to procurement transactions. ? Corrective Action Plan: In response to Audit Finding 2020-01 CFDA #16.575, Mendocino County Youth Project acknowledges the agency?s failure to provide appropriate documentation of purchase consistent with guidelines established within the current Procurement Policy. The inability to produce required documentation was due to loss of records caused by widespread malware attack on the agency?s computer system, incapacitating the system?s server including the entirety of all back up files. This malware attack did not pose any risk or data breach, only encryption/corruption of all system files and processing ability. Documentation provided by tech company states the diagnostic analysis conducted on the malware virus proved no compromise of client or employee data (see attached letter, name of tech company has been redacted for anonymity). Through this event, deficiencies were revealed within the services provided by said tech company; this information was previously unknown to the agency?s executive and management team. Therefore, in response to this massive failure of the agency?s computer security system, MCYP terminated it?s working relationship and service contract with the tech company who had been responsible for maintaining the agency?s computer system. The agency entered into an updated and expanded contract with alternate tech company on December 28, 2020 (see attached contract). Contract with new tech company is extensive in its services to be provided to the agency with substantial improvements specific to system security components. To date the newly contracted tech company has installed all new computer system hardware and software. A stringent, multilevel, system server backup processes has been established which will guarantee full security of system server with corruption or loss unable to occur. The new security process includes generation of backup files on an hourly basis 24 hours a day, 7 days a week including an offsite, cloud based file save location. The agency will continue maintenance of these heightened system security processes to guarantee protection of all files. These implemented computer system improvements will ensure the agency?s ability to remain in compliance of record retention requirements going forward.
FAC accepted this audit on March 30, 2020 — management decision was due September 30, 2020.
The Project 's written procurement and purchasing procedures and board policies do not reflect the requirements identified in the CalOES Subrecipient Handbook. Questioned Cost: N/A Context: N/A Effect: Failure to adopt a clear written policy that conforms to applicable Federal statutes and the procurement requirements could lead to a lack of control over procurement transactions. Cause: The Project did not update its documented policy to conform to applicable Federal statutes and the procurement requirement thresholds identified by CalOES. Recommendation: We recommend that the Project update its written policy to reflect applicable state, local, and Federal statutes and the procurement requirements identified in 2 CFR part 200 and in the CalOES Subrecipient Handbook. In addition, it is recommended that the Project maintain a detailed administrative regulation or procedures manual addressing the mandated components. Views of Responsible Officials: The Project is in the process of updating its written procurement and purchasing policy to reflect the most current CalOES guidelines.
Show full finding ▾Hide full finding ▴Finding 2019-001: Procurement Policy (30000, 50000) CFDA #16.575 ? U.S. Department of Justice, California Governor's Office of Emergency Services, Crime Victim Assistance Cluster Criteria: Non-Federal entities other than States, including those operating Federal programs as subrecipients of States, must follow the procurement standards set out at 2 CFR sections 200.318 through 200.326. They must use their own documented procurement procedures, which reflect applicable state and local laws and regulations, provided that the procurements conform to applicable Federal statutes and the procurement requirements identified in 2 CFR part 200. Additionally, per the California Governor's Office of Emergency Services Subrecipient Handbook, ?audits in which CalOES is identified as a major program must consider the provisions contained in the terms of the program and the CalOES Subrecipient Handbook.? Condition: The Project 's written procurement and purchasing procedures and board policies do not reflect the requirements identified in the CalOES Subrecipient Handbook. Questioned Cost: N/A Context: N/A Effect: Failure to adopt a clear written policy that conforms to applicable Federal statutes and the procurement requirements could lead to a lack of control over procurement transactions. Cause: The Project did not update its documented policy to conform to applicable Federal statutes and the procurement requirement thresholds identified by CalOES. Recommendation: We recommend that the Project update its written policy to reflect applicable state, local, and Federal statutes and the procurement requirements identified in 2 CFR part 200 and in the CalOES Subrecipient Handbook. In addition, it is recommended that the Project maintain a detailed administrative regulation or procedures manual addressing the mandated components. Views of Responsible Officials: The Project is in the process of updating its written procurement and purchasing policy to reflect the most current CalOES guidelines.
Mendocino County Youth Project Corrective Action Plan ? Finding 2019-001: Procurement Policy (30000, 50000) ? Contact persons responsible: Joanna Olson, Mimine Ambrois, Amanda Archer ? Corrective Action Plan: In response to Audit Finding 2019-00, Mendocino County Youth Project acknowledges the agency?s current Procurement Policy does not meet the min/max guidelines outlined in CalOES Subrecipient Handbook. While MCYP?s existing active CalOES subawards do not necessitate the use of procurement procedures, we understand a policy must be in place and must adhere to the latest guidelines posted. To correct, MCYP will update the agency?s Procurement Policy to reflect the most up-to-date and accurate requirements as outlined in the CalOES Subrecipient Handbook. In addition, MCYP will implement an annual review of all agency policies. This annual review will include a verification process to crosscheck requirements and standards with all available resources ensuring the most current requirements are incorporated to agency policies. ? Estimated completion of updated Procurement Policy: By 4/30/2020
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in California →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and filing records.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.