EIN: 860277526
UEI: UN7XD37BMGY5
Audited by: CliftonLarsonAllen LLP
Oversight agency: 84 [Department of Education]
View federal awards & risk assessment →
Data as of September 7, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 31, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by October 1, 2026 (22 days from today).
What is a management decision? →The District’s written information security program does not include a vendor due diligence program as required by the Gramm-Leach-Bliley Act (GLBA) 16 CFR 314.4(f). Questioned Costs: None Cause: The District’s written information security program did not include established policies and standards specifically addressing vendor risk management. Effect: The District is exposed to loss of revenue, reputation damage, disclosure of non-public data, loss of technology assets as a result of the following: • Potential security breaches due to insufficient evaluation and monitoring of vendors who interact with sensitive data. • Inadequate assessment of risks associated with outsourcing services or managing services through vendors. • Establishing relationships with vendors that do not support the District’s strategic objectives, lack financial stability, or have inadequate controls. This absence makes it difficult to ensure that vendors who interact with sensitive data are properly evaluated, selected, and monitored, potentially leading to security breaches and noncompliance with regulatory requirements. Repeat Finding: Yes; 2024-004 Recommendation: The District should ensure that the written information security program includes a vendor due diligence program. This program should include: • Standards for evaluating and selecting vendors who interact with sensitive data. • Contract provisions that require third-party vendors to maintain safeguards. • Ongoing monitoring based on the risk the vendor presents. Also, appropriate policy and standards documentation should be established to support the vendor management program. View of responsible official: The District agrees with the finding, see the Corrective Action Plan.
Show full finding ▾Hide full finding ▴Criteria: Establishing a process for managing risk that follows a credible industry source, such as the National Institute of Standards and Technology, helps the District to effectively manage risk related to IT systems and data. CFR Guidance (Based on GLBA 16 CFR – 314.4) – Addresses how the institution will oversee its information system service providers (16 CFR 314.4(f)). Condition: The District’s written information security program does not include a vendor due diligence program as required by the Gramm-Leach-Bliley Act (GLBA) 16 CFR 314.4(f). Questioned Costs: None Cause: The District’s written information security program did not include established policies and standards specifically addressing vendor risk management. Effect: The District is exposed to loss of revenue, reputation damage, disclosure of non-public data, loss of technology assets as a result of the following: • Potential security breaches due to insufficient evaluation and monitoring of vendors who interact with sensitive data. • Inadequate assessment of risks associated with outsourcing services or managing services through vendors. • Establishing relationships with vendors that do not support the District’s strategic objectives, lack financial stability, or have inadequate controls. This absence makes it difficult to ensure that vendors who interact with sensitive data are properly evaluated, selected, and monitored, potentially leading to security breaches and noncompliance with regulatory requirements. Repeat Finding: Yes; 2024-004 Recommendation: The District should ensure that the written information security program includes a vendor due diligence program. This program should include: • Standards for evaluating and selecting vendors who interact with sensitive data. • Contract provisions that require third-party vendors to maintain safeguards. • Ongoing monitoring based on the risk the vendor presents. Also, appropriate policy and standards documentation should be established to support the vendor management program. View of responsible official: The District agrees with the finding, see the Corrective Action Plan.
The District’s written information security program does not include a vendor due diligence program as required by the Gramm-Leach Bliley Act (Pub. L. No. 106-102)(GLBA) 16 CFR 314.4(f). Responsible Official: Michael Jacob, Associate Vice President Chief Information Officer Anticipated Completion Date: June 30, 2026 The District will take the following actions to address the identified concerns: • The Information Security Group (ISG) was reactivated to strengthen oversight and align practices with industry standards and audit recommendations. The group developed a standardized Vendor Evaluation Checklist, now used prior to signing contracts with any vendor that stores student, employee, or financial data. It also proposed updates to internal procedures to reflect current practices, including the addition of data protection provisions in new vendor contracts when appropriate. While not all proposed changes have been formally approved, they represent the direction the District is actively pursuing. The ISG meets every two months and convenes annually in December to review vendor contracts and assess their security posture. These efforts demonstrate the District’s ongoing commitment to improving vendor management and safeguarding sensitive data through sustained oversight.
2024-004
We found that the District did not report enrollment status changes to the NSLDS by the required federal deadlines for 40 of the 40 (100 percent) students we tested. Questioned Costs: None Cause: The District did not have adequate internal controls in place to ensure that it fully complied with federal student enrollment reporting requirements for the Title IV Student Financial Assistance program. Effect: Enrollment reporting is a critical compliance requirement for institutions participating in the federal Student Financial Assistance program. For recipients of Pell Grants, timely enrollment reporting by institutions assists with their eligibility, future disbursement amounts, and continued access to Student Financial Assistance. Failure to meet the required enrollment status change reporting timeliness increases the District’s risk of material noncompliance with federal Student Financial Assistance program requirements. Repeat Finding: No Recommendation: We recommend that the District strengthen its internal controls over reporting student enrollment changes to NSLDS to ensure that enrollment effective dates are reported to NSLDS within 60 days of an enrollment status change occurring. Views of Responsible Officials: The District agrees with the finding, see the Corrective Action Plan.
Show full finding ▾Hide full finding ▴Criteria: Per 34 CFR 690.83(b)(2), an institution must report any enrollment status changes, including the date of the change per the institution’s reporting system, to the National Student Loan Data System (NSLDS) for participating students within 60 days of the change. Condition: We found that the District did not report enrollment status changes to the NSLDS by the required federal deadlines for 40 of the 40 (100 percent) students we tested. Questioned Costs: None Cause: The District did not have adequate internal controls in place to ensure that it fully complied with federal student enrollment reporting requirements for the Title IV Student Financial Assistance program. Effect: Enrollment reporting is a critical compliance requirement for institutions participating in the federal Student Financial Assistance program. For recipients of Pell Grants, timely enrollment reporting by institutions assists with their eligibility, future disbursement amounts, and continued access to Student Financial Assistance. Failure to meet the required enrollment status change reporting timeliness increases the District’s risk of material noncompliance with federal Student Financial Assistance program requirements. Repeat Finding: No Recommendation: We recommend that the District strengthen its internal controls over reporting student enrollment changes to NSLDS to ensure that enrollment effective dates are reported to NSLDS within 60 days of an enrollment status change occurring. Views of Responsible Officials: The District agrees with the finding, see the Corrective Action Plan.
We found that the District did not report enrollment status changes to the NSLDS by the required federal deadlines for 40 of the 40 (100 percent) students we tested. Responsible Official: Jennifer Dobell, Director of Financial Aid Anticipated Completion Date: 6/30/2026 The District will take the following actions to address the identified concerns: • Management will implement a tracking mechanism to document the receipt, review, and submission of each NSLDS enrollment reporting roster. This tracking log will be reviewed on a periodic basis to verify that all required submissions are completed within the 60‑day reporting window. These efforts demonstrate the District’s ongoing commitment to improving reporting requirements through sustained oversight.
FAC accepted this audit on February 19, 2025 — management decision was due August 19, 2025.
FAC accepted this audit on March 13, 2024 — management decision was due September 13, 2024.
FAC accepted this audit on March 27, 2023 — management decision was due September 27, 2023.
Assistance Listings number and name: 84.425E COVID-19 - Education Stabilization Fund?Higher Education Emergency Relief Fund (HEERF) Student Portion Award numbers and years: P425E201812, April 24, 2020 through June 30, 2023 Federal agency: U.S. Department of Education Compliance requirement: Activities allowed or unallowed and allowable costs/cost principles Questioned costs: None Condition?Contrary to federal guidance, the District used emergency financial assistance monies to satisfy the student?s outstanding account balance without obtaining the student?s prior consent to do so for 3 of 30 emergency financial assistance transactions we tested. Specifically, the District misapplied $500 of program monies, for a total of $1,500, to discharge each of these student?s outstanding account balance with the District rather than directly disbursing these monies to the students. However, we noted no questioned costs as a result of this noncompliance since the students were eligible to receive financial assistance monies. Effect?By the District not obtaining a student?s prior consent to discharge their outstanding account balance rather than disbursing the monies directly to the student, the program?s objective to provide students with emergency financial assistance that may be used at the student?s discretion to help defray costs for food, housing, health care, or childcare?in addition to tuition costs?may not be met. Further, the student could face undue financial hardship. Cause?The District did not have a documented process in place to ensure that it obtained a student?s prior consent for applying emergency financial assistance to the student?s outstanding account balance. Criteria?Federal guidance requires the District to obtain a student?s prior written or electronic consent prior to applying emergency financial assistance to discharge the student?s outstanding account balance with the District.1 In addition, the District must establish and maintain effective internal control over federal awards that provides reasonable assurance that it administers federal programs in compliance with all applicable laws, regulations, and award terms (2 Code of Federal Regulations [CFR] ?200.303). Recommendations?The District should: 1. Develop and implement written policies and procedures to ensure the District obtains each student?s written or electronic consent prior to applying any emergency financial assistance to the student?s outstanding account balance. 2. For those instances in which the District misapplied emergency financial assistance to students? outstanding account balances, determine if the students agree with the discharge of the outstanding account balances or want direct payment of those monies and make any necessary adjustments. The District?s corrective action plan at the end of this report includes the views and planned corrective action of its responsible officials. We are not required to and have not audited these responses and planned corrective actions and therefore provide no assurances as to their accuracy. 1 U.S. Department of Education. (2021). Higher Education Emergency Relief Fund III, Frequently Asked Questions, Question 11. https://www2.ed.gov/about/offices/list/ope/arpfaq.pdf
Show full finding ▾Hide full finding ▴Assistance Listings number and name: 84.425E COVID-19 - Education Stabilization Fund?Higher Education Emergency Relief Fund (HEERF) Student Portion Award numbers and years: P425E201812, April 24, 2020 through June 30, 2023 Federal agency: U.S. Department of Education Compliance requirement: Activities allowed or unallowed and allowable costs/cost principles Questioned costs: None Condition?Contrary to federal guidance, the District used emergency financial assistance monies to satisfy the student?s outstanding account balance without obtaining the student?s prior consent to do so for 3 of 30 emergency financial assistance transactions we tested. Specifically, the District misapplied $500 of program monies, for a total of $1,500, to discharge each of these student?s outstanding account balance with the District rather than directly disbursing these monies to the students. However, we noted no questioned costs as a result of this noncompliance since the students were eligible to receive financial assistance monies. Effect?By the District not obtaining a student?s prior consent to discharge their outstanding account balance rather than disbursing the monies directly to the student, the program?s objective to provide students with emergency financial assistance that may be used at the student?s discretion to help defray costs for food, housing, health care, or childcare?in addition to tuition costs?may not be met. Further, the student could face undue financial hardship. Cause?The District did not have a documented process in place to ensure that it obtained a student?s prior consent for applying emergency financial assistance to the student?s outstanding account balance. Criteria?Federal guidance requires the District to obtain a student?s prior written or electronic consent prior to applying emergency financial assistance to discharge the student?s outstanding account balance with the District.1 In addition, the District must establish and maintain effective internal control over federal awards that provides reasonable assurance that it administers federal programs in compliance with all applicable laws, regulations, and award terms (2 Code of Federal Regulations [CFR] ?200.303). Recommendations?The District should: 1. Develop and implement written policies and procedures to ensure the District obtains each student?s written or electronic consent prior to applying any emergency financial assistance to the student?s outstanding account balance. 2. For those instances in which the District misapplied emergency financial assistance to students? outstanding account balances, determine if the students agree with the discharge of the outstanding account balances or want direct payment of those monies and make any necessary adjustments. The District?s corrective action plan at the end of this report includes the views and planned corrective action of its responsible officials. We are not required to and have not audited these responses and planned corrective actions and therefore provide no assurances as to their accuracy. 1 U.S. Department of Education. (2021). Higher Education Emergency Relief Fund III, Frequently Asked Questions, Question 11. https://www2.ed.gov/about/offices/list/ope/arpfaq.pdf
Maderia Ellison, Vice President for Administrative Services/CFO Jeremy Raisor, Dean of Career & Technical Education Anticipated completion date: June 30, 2023 Corrective Action Plan: The District has been made aware of the issues related to the federal awards and concurs with the finding and recommendations. The District will develop and implement student refund procedures to ensure that written or electronic consent is received from students before applying emergency financial assistance to the student?s outstanding account balance, and that if the consent cannot be obtained within the appropriate time period funds will be released to the student. The district will also make any necessary adjustments on the three accounts where emergency financial assistance was misapplied.
FAC accepted this audit on December 6, 2021 — management decision was due June 6, 2022.
FAC accepted this audit on December 2, 2020 — management decision was due June 2, 2021.
Cluster name: Student Financial Assistance Cluster Assistance Listings numbers and names: 84.007 Federal Supplemental Educational Opportunity Grants 84.033 Federal Work-Study Program 84.063 Federal Pell Grant Program Award numbers and years: P007A180127; P033A180127; P063P183482; July 1, 2019 through June 30, 2020 Federal agency: U.S. Department of Education (U.S. ED) Compliance requirement: Special tests and provisions Questioned costs: N/A Condition?The District did not document that it identified reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of its student financial aid information and that it implemented safeguards for each risk identified. Effect?Without correcting these deficiencies, the District?s administration and information technology (IT) management may put the District?s operations and IT systems and data, including student financial aid information, at unintended and unnecessary risk. Cause?The District designated an individual to coordinate its information security program over its student financial aid information but relied on an informal and undocumented process to manage, assess, and respond to IT risks. Criteria?The District?s Program Participation Agreement with the U.S. ED requires the District to protect student financial aid information by designating an employee to coordinate its information security program. The District must also perform a risk assessment and document a safeguard for each risk identified. (Title 16 U.S. Code of Federal Regulations, Parts 313 and 314, as required by the Gramm-Leach-Bliley Act, P.L. 106-102) Recommendations?To help ensure that the District protects student financial aid information, the District should: 1. Develop, document, and implement entity-wide risk assessment written policies and procedures. 2. Perform a risk assessment to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of student financial aid information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information. The risk assessment should consider risks related to: o Employee training and management. o Information systems, including network and software design, as well as information processing, storage, transmission, and disposal. o Detecting, preventing, and responding to attacks, intrusions, or other system failures. 3. Document and implement a safeguard for each risk identified. The District?s responsible officials? views and planned corrective action are in its corrective action plan at the end of this report. This finding is similar to prior-year finding 2019-101.
Show full finding ▾Hide full finding ▴Cluster name: Student Financial Assistance Cluster Assistance Listings numbers and names: 84.007 Federal Supplemental Educational Opportunity Grants 84.033 Federal Work-Study Program 84.063 Federal Pell Grant Program Award numbers and years: P007A180127; P033A180127; P063P183482; July 1, 2019 through June 30, 2020 Federal agency: U.S. Department of Education (U.S. ED) Compliance requirement: Special tests and provisions Questioned costs: N/A Condition?The District did not document that it identified reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of its student financial aid information and that it implemented safeguards for each risk identified. Effect?Without correcting these deficiencies, the District?s administration and information technology (IT) management may put the District?s operations and IT systems and data, including student financial aid information, at unintended and unnecessary risk. Cause?The District designated an individual to coordinate its information security program over its student financial aid information but relied on an informal and undocumented process to manage, assess, and respond to IT risks. Criteria?The District?s Program Participation Agreement with the U.S. ED requires the District to protect student financial aid information by designating an employee to coordinate its information security program. The District must also perform a risk assessment and document a safeguard for each risk identified. (Title 16 U.S. Code of Federal Regulations, Parts 313 and 314, as required by the Gramm-Leach-Bliley Act, P.L. 106-102) Recommendations?To help ensure that the District protects student financial aid information, the District should: 1. Develop, document, and implement entity-wide risk assessment written policies and procedures. 2. Perform a risk assessment to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of student financial aid information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information. The risk assessment should consider risks related to: o Employee training and management. o Information systems, including network and software design, as well as information processing, storage, transmission, and disposal. o Detecting, preventing, and responding to attacks, intrusions, or other system failures. 3. Document and implement a safeguard for each risk identified. The District?s responsible officials? views and planned corrective action are in its corrective action plan at the end of this report. This finding is similar to prior-year finding 2019-101.
Cluster name: Student Financial Assistance Cluster CFDA numbers and names: 84.007 Federal Supplemental Educational Opportunity Grants 84.033 Federal Work-Study Program 84.063 Federal Pell Grant Program Award numbers and years: P007A180127; P033A180127; P063P183482; July 1, 2019 through June 30, 2020 Federal agency: U.S. Department of Education Compliance requirement: Special tests and provisions Questioned costs: N/A Maderia Ellison, Associate Vice President and Chief Business Officer Henry Scott Estes, Chief Information Officer Anticipated completion date: June 30, 2021 The District will make the necessary changes to improve existing security over information technology resources; specifically, it will ensure that the District protects student financial aid information in accordance with the Gramm-Leach-Bliley Act and specifically, will: ?Designate an employee to coordinate the information security program. ?Perform an annual risk assessment of its maintained student financial aid information toidentify, analyze and respond to IT risks related to its employee training andmanagement; IT systems and data; and detecting, preventing, and responding toattacks, intrusions, or other systems failures. ?Document a safeguard for each risk identified. ?Monitor the effectiveness of the safeguards? key controls, systems, and procedures on aperiodic basis. ?Evaluate and adjust the information security program in light of the results of the testingand monitoring any material changes to the District?s operations or businessarrangements; or any other circumstances that may have a material impact on theinformation security program.
2019-101
FAC accepted this audit on November 19, 2019 — management decision was due May 19, 2020.
2019-101 Cluster name: Student Financial Assistance Cluster CFDA numbers and names: 84.007 Federal Supplemental Educational Opportunity Grants 84.033 Federal Work-Study Program 84.063 Federal Pell Grant Program Award numbers and years: P007A180127; P033A180127; P063P183482; July 1, 2018 through June 30, 2019 Federal agency: U.S. Department of Education Compliance requirement: Special tests and provisions Questioned costs: N/A Condition and context?The District had no evidence that it had performed the required risk assessment and documented safeguards of the student financial aid information it maintains. Criteria?The District?s agreement with the U.S. Department of Education requires the District to protect student financial aid information by designating an employee to coordinate its information security program. The District must also perform a risk assessment and document a safeguard for each risk identified. (Gramm-Leach-Bliley Act, Title 16 U.S. Code of Federal Regulations, Part 314). Effect?Without correcting these deficiencies, the District?s administration and information technology (IT) management may put the District?s operations and IT systems and data, including student financial aid information, at unintended and unnecessary risk. Cause?The District designated an individual to coordinate its information security program over its student financial aid information but relied on an informal and undocumented process to manage, assess, and respond to IT risks. Recommendation?To help ensure that the District protects student financial aid information, the District should: ? Perform a risk assessment to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of student financial aid information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information. The risk assessment should consider risks related to: o Employee training and management. o Information systems, including network and software design, as well as information processing, storage, transmission and disposal. o Detecting, preventing and responding to attacks, intrusions, or other system failures. ? Document and implement a safeguard for each risk identified. ? Monitor the effectiveness of the safeguards? key controls, systems, and procedures on a periodic basis. ? Evaluate and adjust the information security program in light of the testing and monitoring results, any significant changes to the District?s operations or business arrangements, and any other circumstances that may have a significant impact on the information security program. The District?s responsible officials? views and planned corrective action are in its corrective action plan at the end of this report.
Show full finding ▾Hide full finding ▴2019-101 Cluster name: Student Financial Assistance Cluster CFDA numbers and names: 84.007 Federal Supplemental Educational Opportunity Grants 84.033 Federal Work-Study Program 84.063 Federal Pell Grant Program Award numbers and years: P007A180127; P033A180127; P063P183482; July 1, 2018 through June 30, 2019 Federal agency: U.S. Department of Education Compliance requirement: Special tests and provisions Questioned costs: N/A Condition and context?The District had no evidence that it had performed the required risk assessment and documented safeguards of the student financial aid information it maintains. Criteria?The District?s agreement with the U.S. Department of Education requires the District to protect student financial aid information by designating an employee to coordinate its information security program. The District must also perform a risk assessment and document a safeguard for each risk identified. (Gramm-Leach-Bliley Act, Title 16 U.S. Code of Federal Regulations, Part 314). Effect?Without correcting these deficiencies, the District?s administration and information technology (IT) management may put the District?s operations and IT systems and data, including student financial aid information, at unintended and unnecessary risk. Cause?The District designated an individual to coordinate its information security program over its student financial aid information but relied on an informal and undocumented process to manage, assess, and respond to IT risks. Recommendation?To help ensure that the District protects student financial aid information, the District should: ? Perform a risk assessment to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of student financial aid information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information. The risk assessment should consider risks related to: o Employee training and management. o Information systems, including network and software design, as well as information processing, storage, transmission and disposal. o Detecting, preventing and responding to attacks, intrusions, or other system failures. ? Document and implement a safeguard for each risk identified. ? Monitor the effectiveness of the safeguards? key controls, systems, and procedures on a periodic basis. ? Evaluate and adjust the information security program in light of the testing and monitoring results, any significant changes to the District?s operations or business arrangements, and any other circumstances that may have a significant impact on the information security program. The District?s responsible officials? views and planned corrective action are in its corrective action plan at the end of this report.
2019-101 Cluster name: Student Financial Assistance Cluster CFDA numbers and names: 84.007 Federal Supplemental Educational Opportunity Grants 84.033 Federal Work-Study Program 84.063 Federal Pell Grant Program Award numbers and years: P007A180127; P033A180127; P063P183482; July 1, 2018 through June 30, 2019 Federal agency: U.S. Department of Education Compliance requirement: Special tests and provisions Questioned costs: N/A Maderia Ellison, Associate Vice President and Chief Business Officer Ernest Hess, Network Administrator Anticipated completion date: June 30, 2020 The District will make the necessary changes to improve existing security over information technology resources; specifically, it will ensure that the District protects student financial aid information in accordance with the Gramm-Leach-Bliley Act and specifically, will: ? Designate an employee to coordinate the information security program. ? Perform an annual risk assessment of its maintained student financial aid information to identify, analyze and respond to IT risks related to its employee training and management; IT systems and data; and detecting, preventing, and responding to attacks, intrusions, or other systems failures. ? Document a safeguard for each risk identified. ? Monitor the effectiveness of the safeguards? key controls, systems, and procedures on a periodic basis. ? Evaluate and adjust the information security program in light of the results of the testing and monitoring any material changes to the District?s operations or business arrangements; or any other circumstances that may have a material impact on the information security program.
FAC accepted this audit on December 13, 2018 — management decision was due June 13, 2019.
FAC accepted this audit on November 30, 2017 — management decision was due May 30, 2018.
FAC accepted this audit on December 12, 2016 — management decision was due June 12, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in Arizona →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Add it to a monitored group and get alerted when a new audit, finding, repeat finding, or management-decision deadline shows up — instead of checking back.
Checking several at once? Portfolio view →
© 2026 Single Audit Intelligence. All data is public domain.