Holy Names University

EIN: 941358307

UEI: FVJMAY9HM3A5

8
Audit Years
19
Total Findings
8
Repeat Findings

FY 2023-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on December 24, 2024. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by June 24, 2025, which was (421 days ago).

What is a management decision? →
2023-002
Special Tests & Provisions
Condition

Criteria According to 34 CFR 668. 164(h)(2), A Title IV, HEA credit balance must be paid directly to the student or parent as soon as possible, but no later than- (i) Fourteen (14) days after the balance occurred if the credit balance occurred after the first day of class of a payment period; or (ii) Fourteen (14) days after the first day of class of a payment period if the credit balance occurred on or before the first day of class of that payment period. Condition The University's refunded credit balances later than fourteen days after the date the credit balance occurred. Cause Noncompliance was caused by an oversight by the responsible department and changes to the refund process. Effect Credit balances were refunded more than fourteen days after the credit balance occurred. Questioned Cost There is no questioned cost related to this finding. Context During review of the University's refund of credit balances, we noted that 4 out of 40 students selected for testing had credit balances refunded later than fourteen days after the date of the credit balance occurred. After further review by the University, it was identified that a total of 32 students had credit balances refunded later than fourteen days after the date the credit balance occurred. All late payments of credit balances identified by the University occurred within the same three week period as the 4 identified from the testing selection. Recommendation We recommend the University take appropriate steps to ensure all credit balances are refunded within the required fourteen days. Views of Responsible Officials We agree with the recommendation.

Corrective Action Plan

We agree with the recommendation. A full-time staff position "Student Scholarship Accounting & Compliance Officer" is filled and a component of this role is to disburse credit balances within 14 days, should there be a need. However no Federal financial assistance funds were awarded after June 30, 2023 as the University ceased academic operations and degree granting in May 2023 upon completion of spring semester.

About Special Tests and Provisions →
2023-003
Special Tests & Provisions
REPEAT
Condition

Criteria Under the University’s Program Participation Agreement and the Gramm-Leach-Bliley Act (GLBA), schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid. According to 16 CFR 314.4(b), a school must identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: Employee training and management; Information systems, including network and software design, as well as information processing, storage, transmission, and disposal; and Detecting, preventing, and responding to attacks, intrusions, or other systems failures. Condition Although the University has documented various IT policies around access, they are not comprehensive enough to cover the Gramm-Leach-Bliley Act requirements with respect to the process of identifying the internal and external risks to data security. Cause The University has not conducted a formal risk assessment since January 2021. Effect Student information may be at risk of unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information. Questioned Costs There were no questioned costs related to this finding. Context During our review of the University’s Information Technology system, we noted through inquiry that a formal risk assessment of the University’s documented safeguards had not been performed since January 2021. Identification as a Repeat Finding This finding is a repeat of finding 2022-002 in the immediately prior audit. Recommendation We recommend that the University re-engage the outside resource to independently perform and develop a formal risk assessment, along with recommendations for remediation of any open items and/or deficiencies. Views of Responsible Officials We agree with the recommendation.

Corrective Action Plan

Under the University’s Program Participation Agreement and the Gramm-Leach-Bliley Act (GLBA), schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid. According to 16 CFR 314.4(b), a school must identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: Employee training and management; Information systems, including network and software design, as well as information processing, storage, transmission, and disposal; and Detecting, preventing, and responding to attacks, intrusions, or other systems failures. Condition Although the University has documented various IT policies around access, they are not comprehensive enough to cover the Gramm-Leach-Bliley Act requirements around the process of identifying the internal and external risks to data security. Cause The University has not conducted a formal risk assessment since January 2021. Effect Student information may be at risk of unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information. Questioned Costs There were no questioned costs related to this finding. Context During our review of the University’s Information Technology system, we noted through inquiry that a formal risk assessment of the University’s documented safeguards had not been performed since January 2021. Recommendation We recommend that the University re-engage the outside resource to independently perform and develop a formal risk assessment, along with recommendations for remediation of any open items and/or deficiencies. Corrective Action Planned The organization has engaged an outside IT consultant to manage the organization’s IT needs moving forward. Responsible PersonnelDouglas Burnet Chief Financial OfficerPhone: 415-425-0666 Burnet@hnu.edu

Prior Finding References

2022-002

About Special Tests and Provisions →
2023-004
Reporting
Condition

Criteria According to 34 CFR 673.3(a}, to participate in the Federal Perkins Loan, FWS, or FSEOG programs, an institution shall file an application before the deadline date established annually by the Secretary through publication of a notice in the Federal Register. Condition The University submitted the report after the reporting deadline of October 1, 2023. Cause Noncompliance with the requirement occurred due to an oversight by the responsible department. Effect The Fiscal Operations Report and Application to Participate report was submitted late. Questioned Cost There is no questioned cost related to this finding. Context During review of the University's Fiscal Operations Report and Application to Participate report for the year ended June 30, 2023, we noted that the report was submitted after the required reporting deadline of October 1, 2023. Recommendation We recommend the University take appropriate steps to ensure the Fiscal Operations Report and Application to Participate report is submitted in a timely manner prior to the reporting deadline. Views of Responsible Officials We agree with the recommendation. There is no questioned cost related to this finding.

Corrective Action Plan

Given staff & contract staff turnover during the year, required financial aid reporting requirements were late, this will not be an issue moving forward as the University ceased participation in all federal financial aid programs and is expected to fully transition to a scholarship granting organization.

About Reporting →

FY 2022-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on July 17, 2023. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by January 17, 2024, which was (945 days ago).

What is a management decision? →
2022-001
Special Tests & Provisions
REPEAT
Condition

2022 ? 001 Financial Responsibility Ratio (Student Financial Aid Cluster ? All programs) Criteria According to 34 CFR 668. 171(b)(1), an institution is considered to be financially responsible if the institution?s Equity, Primary Reserve, and Net Income ratios yield a composite score of at least 1.5. Condition The University?s composite score as of June 30, 2022 was below 1.5. Cause Noncompliance was caused by the University?s financial condition. Effect The University is not considered to be financially responsible. Questioned Cost There is no questioned cost related to this finding. Context During review of the University?s financial responsibility ratio calculation, we noted that it?s composite score as of June 30, 2022 was below 1.5. Identification as a Repeat Finding This finding is a repeat of finding 2021-001 and 2020-001 in the immediately prior two audits. Recommendation We recommend the University take appropriate steps to improve its financial condition to be compliant. Views of Responsible Officials We agree with the recommendation.

Corrective Action Plan

Corrective Action Plan For the Year Ended June 30, 2022 Findings for the Year Ended June 30, 2022 2022 ? 001 Financial Responsibility Ratio (Student Financial Aid Cluster ? All programs) Criteria According to 34 CFR 668. 171(b)(1), an institution is considered to be financially responsible if the institution?s Equity, Primary Reserve, and Net Income ratios yield a composite score of at least 1.5. Condition The University?s composite score as of June 30, 2022 was below 1.5. Cause Noncompliance was caused by the University?s financial condition. Effect The University is not considered to be financially responsible. Questioned Cost There is no questioned cost related to this finding. Context During review of the University?s financial responsibility ratio calculation, we noted that its composite score as of June 30, 2022 was below 1.5. Recommendation We recommend the University take appropriate steps to improve its financial condition to be compliant. Corrective Action Planned In September 2019, the University secured long-term bond financing. The long-term financing allowed the implementation of the 5-Year Strategic Business Plan, repayment of the Presidio Bank operating line of credit, new program investments of $9.65 million, and provided additional operating cash needed during the strategic plan implementation. The goals of the 5-Year Strategic Business Plan are to develop new academic programs, increase enrollment, expand our advancement team and major donor programs, all of which will improve the financial position of the University. In addition, for the 2022-2023, the University reduced its budget by over $3.5 million. The Board of Trustees announced in December 2022, plans to cease academic operations and degree granting in May 2023 after the completion of the spring semester. In spring 2022, Holy Names University was seeking a partner institution to keep the university functioning and continue the mission of our founders, SNJM. While the University had interest in long-term collaboration from potential partners, the University was not able to reach closure in a way that would allow it to continue offering programs and services. The ongoing impact of COVID-19 enrollment declines were especially significant, particularly for fall term 2022. In addition, the University experienced rising operational costs and student retention issues. In January 2023, the University declared financial exigency, which gave the University greater flexibility to allocate its remaining resources to deliver spring term academic and athletic programs and support the transition of continuing students to other institutions. The University initiated layoffs beginning February 3, 2023 and continues to reduce expenses, funding only the most critical instructional and health and safety expenses. In February 2023, The University bondholder filed a notice of default based on noncompliance with the prior period operating ratio covenant. In March 2023 the University began marketing efforts to support the sale of the 60-acre campus. In April 2023 the University sold the residence, formerly occupied the University's President, for $3 million. The net proceeds to the University were $1.2 million after expenses and after a repayment of a $1.6 million loan on the property drawn in 2023. The net book value of the property at June 30, 2022 was $1.2 million. Responsible Personnel Jeanine Hawk, EdD, MBA Vice-President, Finance and Administration Mobile: 408-590-5834 hawk@ndnu.edu

Prior Finding References

2021-001

About Special Tests and Provisions →
2022-002
Special Tests & Provisions
Condition

2022 ? 002 Gramm-Leach-Bliley Act (Student Financial Aid Cluster ? All programs) Criteria Under the University?s Program Participation Agreement and the Gramm-Leach-Bliley Act (GLBA), schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid. According to 16 CFR 314.4(b), a school must identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: 1. Employee training and management; 2. Information systems, including network and software design, as well as information processing, storage, transmission, and disposal; and 3. Detecting, preventing, and responding to attacks, intrusions, or other systems failures. Condition Although the University has documented various IT policies around access, they are not comprehensive enough to cover the Gramm-Leach-Bliley Act requirements around the process of identifying the internal and external risks to data security. Cause The University has not conducted a formal risk assessment since January 2021. Effect Student information may be at risk of unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information. Questioned Costs There were no questioned costs related to this finding. Context During our review of the University?s Information Technology system, we noted through inquiry that a formal risk assessment of the University?s documented safeguards had not been performed since January 2021. Recommendation We recommend that the University re-engage the outside resource to independently perform and develop a formal risk assessment, along with recommendations for remediation of any open items and/or deficiencies. Views of Responsible Officials We agree with the recommendation.

Corrective Action Plan

Corrective Action Plan For the Year Ended June 30, 2022 2022 ? 002 Gramm-Leach-Bliley Act (Student Financial Aid Cluster ? All programs) Criteria Under the University?s Program Participation Agreement and the Gramm-Leach-Bliley Act (GLBA), schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid. According to 16 CFR 314.4(b), a school must identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: 1. Employee training and management; 2. Information systems, including network and software design, as well as information processing, storage, transmission, and disposal; and 3. Detecting, preventing, and responding to attacks, intrusions, or other systems failures. Condition Although the University has documented various IT policies around access, they are not comprehensive enough to cover the Gramm-Leach-Bliley Act requirements around the process of identifying the internal and external risks to data security. Cause The University has not conducted a formal risk assessment since January 2021. Effect Student information may be at risk of unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information. Questioned Costs There were no questioned costs related to this finding. Context During our review of the University?s Information Technology system, we noted through inquiry that a formal risk assessment of the University?s documented safeguards had not been performed since January 2021. Recommendation We recommend that the University re-engage the outside resource to independently perform and develop a formal risk assessment, along with recommendations for remediation of any open items and/or deficiencies. Corrective Action Planned The Board of Trustees announced in December 2022, plans to cease academic operations and degree granting in May 2023 after the completion of the spring semester. In spring 2022, Holy Names University was seeking a partner institution to keep the university functioning and continue the mission of our founders, SNJM. While the University had interest in long-term collaboration from potential partners, the University was not able to reach closure in a way that would allow it to continue offering programs and services. The ongoing impact of COVID-19 enrollment declines were especially significant, particularly for fall term 2022. In addition, the University experienced rising operational costs and student retention issues. In January 2023, the University declared financial exigency, which gave the University greater flexibility to allocate its remaining resources to deliver spring term academic and athletic programs and support the transition of continuing students to other institutions. The University initiated layoffs beginning February 3, 2023 and continues to reduce expenses, funding only the most critical instructional and health and safety expenses. In February 2023, The University bondholder filed a notice of default based on noncompliance with the prior period operating ratio covenant. In March 2023 the University began marketing efforts to support the sale of the 60-acre campus. In April 2023 the University sold the residence, formerly occupied the University's President, for $3 million. The net proceeds to the University were $1.2 million after expenses and after a repayment of a $1.6 million loan on the property drawn in 2023. The net book value of the property at June 30, 2022 was $1.2 million. Responsible Personnel Jeanine Hawk, EdD, MBA Vice-President, Finance and Administration Mobile: 408-590-5834 hawk@ndnu.edu

About Special Tests and Provisions →

FY 2021-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on September 28, 2022. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by March 28, 2023, which was (1240 days ago).

What is a management decision? →
2021-001
Special Tests & Provisions
REPEATMATERIAL WEAKNESS
Condition

2021 ? 001 Financial Responsibility Ratio (Student Financial Aid Cluster ? All programs) Criteria According to 34 CFR 668. 171(b)(1), an institution is considered to be financially responsible if the institution?s Equity, Primary Reserve, and Net Income ratios yield a composite score of at least 1.5. Condition The University?s composite score as of June 30, 2021 is below 1.5. Cause Noncompliance was caused by the University?s financial condition. Effect The University is not considered to be financially responsible. Questioned Cost There is no questioned cost related to this finding. Context During review of the University?s financial responsibility ratio calculation, we noted that it?s composite score as of June 30, 2020 is below 1.5. Identification as a Repeat Finding This finding is a repeat of finding 2020-001 in the immediately prior audit. Recommendation We recommend the University take appropriate steps to improve its financial condition to be compliant. Views of Responsible Officials We agree with the recommendation.

Corrective Action Plan

2021 ? 001 Financial Responsibility Ratio (Student Financial Aid Cluster ? All programs) Criteria According to 34 CFR 668. 171(b)(1), an institution is considered to be financially responsible if the institution?s Equity, Primary Reserve, and Net Income ratios yield a composite score of at least 1.5. Condition The University?s composite score as of June 30, 2021 is below 1.5. Cause Noncompliance was caused by the University?s financial condition. Effect The University is not considered to be financially responsible. Questioned Cost There is no questioned cost related to this finding. Context During review of the University?s financial responsibility ratio calculation, we noted that it?s composite score as of June 30, 2021 is below 1.5. Recommendation We recommend the University take appropriate steps to improve its financial condition to be compliant. Corrective Action Planned In September 2019, the University secured long-term bond financing. The long-term financing allowed the implementation of the 5-Year Strategic Business Plan, repayment of the Presidio Bank operating line of credit, new program investments of $9.65 million, and provided additional operating cash needed during the strategic plan implementation. The goals of the 5-Year Strategic Business Plan are to develop new academic programs, increase enrollment, expand our advancement team and major donor programs, all of which will improve the financial position of the University. We are continuing to do everything possible to improve operations so that we will be profitable within the next few years. Responsible Personnel Jeanine Hawk, EdD, MBA Vice-President, Finance and Administration Mobile: 408-590-5834 hawk@ndnu.eduAnticipated Completion Date June 30, 2021

Prior Finding References

2020-001

About Special Tests and Provisions →

FY 2020-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on August 24, 2021. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by February 24, 2022, which was (1637 days ago).

What is a management decision? →
2020-001
Special Tests & Provisions
REPEAT
Condition

2020 ? 001 Financial Responsibility Ratio (Student Financial Aid Cluster ? All programs) Criteria According to 34 CFR 668. 171(b)(1), an institution is considered to be financially responsible if the institution?s Equity, Primary Reserve, and Net Income ratios yield a composite score of at least 1.5. Condition The University?s composite score as of June 30, 2020 is below 1.5. Cause Noncompliance was caused by the University?s financial condition. Effect The University is not considered to be financially responsible. Questioned Cost There is no questioned cost related to this finding. Context During review of the University?s financial responsibility ratio calculation, we noted that it?s composite score as of June 30, 2020 is below 1.5. Identification as a Repeat Finding This finding is a repeat of finding 2019-003 in the immediately prior audit. Recommendation We recommend the University take appropriate steps to improve its financial condition to be compliant. Views of Responsible Officials We agree with the recommendation.

Corrective Action Plan

2020 ? 001 Financial Responsibility Ratio (Student Financial Aid Cluster ? All programs) Criteria According to 34 CFR 668. 171(b)(1), an institution is considered to be financially responsible if the institution?s Equity, Primary Reserve, and Net Income ratios yield a composite score of at least 1.5. Condition The University?s composite score as of June 30, 2020 is below 1.5. Cause Noncompliance was caused by the University?s financial condition. Effect The University is not considered to be financially responsible. Questioned Cost There is no questioned cost related to this finding. Context During review of the University?s financial responsibility ratio calculation, we noted that it?s composite score as of June 30, 2020 is below 1.5. Recommendation We recommend the University take appropriate steps to improve its financial condition to be compliant. Corrective Action Planned In September 2019, the University secured long-term bond financing. The long-term financing allowed the implementation of the 5-Year Strategic Business Plan, repayment of the Presidio Bank operating line of credit, new program investments of $9.65 million, and provided additional operating cash needed during the strategic plan implementation. The goals of the 5-Year Strategic Business Plan are to develop new academic programs, increase enrollment, expand our advancement team and major donor programs, all of which will improve the financial position of the University. We are continuing to do everything possible to improve operations so that we will be profitable within the next few years. Responsible Personnel Rob Kinnard, Vice President for Finance and Administration kinnard@hnu.edu 510-436-1035 Anticipated Completion Date June 30, 2021.

Prior Finding References

2019-003

About Special Tests and Provisions →
2020-002
Special Tests & Provisions
REPEAT
Condition

2020 ? 002 Gramm-Leach-Bliley Act (Student Financial Aid Cluster ? All programs) Criteria Under the University?s Program Participation Agreement and the Gramm-Leach-Bliley Act (GLBA), schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid. According to 16 CFR 314.4(b), a school must identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: 1. Employee training and management; 2. Information systems, including network and software design, as well as information processing, storage, transmission, and disposal; and 3. Detecting, preventing, and responding to attacks, intrusions, or other systems failures. Condition Although the University has documented a safeguard for certain risk area, the University has not performed a formal risk assessment to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of student information and assess the sufficiency of these safeguards. Cause The University had not scheduled a formal risk assessment until after the June 30, 2020 school year. Effect Student information may be at risk of unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information. Questioned Costs There were no questioned costs related to this finding. Context During our review of the University's Information Technology system, we noted through inquiry that a formal risk assessment of the University's documented safeguards had not been performed. Identification as a Repeat Finding This finding is a repeat of finding 2019-004 in the immediately prior audit. Recommendation We recommend that the University consider bringing in an outside resource to independently evaluate and develop a formal risk assessment, along with recommendations for remediation of any open items and/or deficiencies. Otherwise, we recommend the University form a risk assessment group of members of management to schedule at least annual risk assessments. Views of Responsible Officials We agree with the recommendation

Corrective Action Plan

2020 ? 002 Gramm-Leach-Bliley Act (Student Financial Aid Cluster ? All programs) Criteria Under the University?s Program Participation Agreement and the Gramm-Leach-Bliley Act (GLBA), schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid. According to 16 CFR 314.4(b), a school must identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: 1. Employee training and management; 2. Information systems, including network and software design, as well as information processing, storage, transmission, and disposal; and 3. Detecting, preventing, and responding to attacks, intrusions, or other systems failures. Condition Although the University has documented a safeguard for certain risk area, the University has not performed a formal risk assessment to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of student information and assess the sufficiency of these safeguards. Context During our review of the University's Information Technology system, we noted through inquiry that a formal risk assessment of the University's documented safeguards had not been performed. Questioned Costs There were no questioned costs related to this finding. Cause The University had not scheduled a formal risk assessment until after the June 30, 2019 school year. Recommendation We recommend that the University consider bringing in an outside resource to independently evaluate and develop a formal risk assessment, along with recommendations for remediation of any open items and/or deficiencies. Otherwise, we recommend the University form a risk assessment group of members of management to schedule at least annual risk assessments. Corrective Action Planned The University?s Chief Technology Officer (CTO) and the Information Technology (I.T.) team are in the process of documenting our internal and external risks to student information, which includes an assessment of the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. The CTO and I.T. team do not foresee any problems with compliance and expect to have documented the internal and external risks, controls, and systems in place during the subsequent fiscal year. The risk assessment was completed subsequent to year end. Illumant (a consulting company) conducted a Risk Assessment in January of 2021 which resulted in Holy Names University having a rating of Average Risk. We have appropriate safeguards in place to mitigate identified risks related to all areas in the Risk Assessment. Responsible Personnel William Wanker, Chief Technology Officer wanker@hnu.edu (510) 436-1372 Anticipated Completion Date January 2021.

Prior Finding References

2019-004

About Special Tests and Provisions →

FY 2019-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 29, 2020. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 29, 2020, which was (2150 days ago).

What is a management decision? →
2019-001
Special Tests & Provisions
Condition

2019 ? 001 Return of Title IV Testing (Student Financial Aid Cluster ? All Programs) Criteria According to 34 CFR 685.309(b), (1) Upon receipt of an enrollment report from the Secretary, a University must update all information included in the report and return the report to the Secretary? (i) In the manner and format prescribed by the Secretary; and (ii) Within the timeframe prescribed by the Secretary. (2) Unless it expects to submit its next updated enrollment report to the Secretary within the next 60 days, a University must notify the Secretary within 30 days after the date the University discovers that - (i) A loan under title IV of the Act was made to or on behalf of a student who was enrolled or accepted for enrollment at the University, and the student has ceased to be enrolled on at least a half-time basis or failed to enroll on at least a half-time basis for the period for which the loan was intended; or (ii) A student who is enrolled at the University and who received a loan under title IV of the Act has changed his or her permanent address. Condition The University did not notify the Secretary of the student?s enrollment change within the timeframe. In addition, the University did not accurately report the last date of attendance for the students who withdrew from the University. Cause Noncompliance was caused by a lack of a procedure to consistently report on the change in student enrollment status for students that had Return of Title IV. Effect Noncompliance may cause a delay in the loan repayment process for the student borrowers that withdrew from the University. Questioned Cost There was no questioned cost. Context During our testing of Return of Title IV, out of 6 students tested, we noted 1 instance where the University notified the Secretary after the 60-day allowable time frame. Recommendation We recommend the University implement a process to consistently and accurately report on the changes in student enrollment status once the University determines a student withdrew from the University. View of Responsible Officials We acknowledge the Registrar?s Office procedures of students withdrawing after the spring semester need to be updated.

Corrective Action Plan

2019 ? 001 Return of Title IV Testing (Student Financial Aid Cluster ? All Programs) Criteria According to 34 CFR 685.309(b), (1) Upon receipt of an enrollment report from the Secretary, a University must update all information included in the report and return the report to the Secretary - (i) In the manner and format prescribed by the Secretary; and (ii) Within the timeframe prescribed by the Secretary. (2) Unless it expects to submit its next updated enrollment report to the Secretary within the next 60 days, a University must notify the Secretary within 30 days after the date the University discovers that - (i) A loan under title IV of the Act was made to or on behalf of a student who was enrolled or accepted for enrollment at the University, and the student has ceased to be enrolled on at least a half-time basis or failed to enroll on at least a half-time basis for the period for which the loan was intended; or (ii) A student who is enrolled at the University and who received a loan under title IV of the Act has changed his or her permanent address. Condition The University did not notify the Secretary of the student?s enrollment change within the timeframe. In addition, the University did not accurately report the last date of attendance for the students who withdrew from the University. Context During our testing of Return of Title IV, out of 6 students tested, we noted 1 instance where the University notified the Secretary after the 60-day allowable time frame. Questioned Cost There was no questioned cost. Cause Noncompliance was caused by a lack of a procedure to consistently report on the change in student enrollment status for students that had Return of Title IV. Effect Noncompliance may cause a delay in the loan repayment process for the student borrowers that withdrew from the University. Recommendation We recommend the University implement a process to consistently and accurately report on the changes in student enrollment status once the University determines a student withdrew from the University. Corrective Actions Planned The Registrar?s Office reporting practices did not identify students that withdrew after the spring semester as needing to be reported as a result of being unclear about the summer reporting requirements. Having identified this issue through the audit, the Registrar?s Office has updated the procedures of students withdrawing after the spring semester. The individuals responsible for processing the withdrawal/leave of absence forms will update the student information system and National Student Clearinghouse records to reflect the status/effective date for the student. This will ensure compliance with the reporting regulations. Additionally, the Registrar?s Office is coordinating with the IT department to update the SIS-generated, standard enrollment report to NSLC to capture these students in the end-of term spring report and the first-of-term summer report.

About Special Tests and Provisions →
2019-002
Special Tests & Provisions
QUESTIONED COSTS
Condition

2019 ? 002 Need Analysis (Student Financial Aid Cluster ? All Programs) Criteria According to Volume 3 Chapter 7 of the SFA handbook, the general rule in packaging is that the student?s total financial aid and other estimated financial assistance must not exceed the student?s financial need. Condition Cost of attendance calculation during packaging. Cause The University failed to recognize the adjustment to the student?s award for summer classes. Effect Noncompliance may result in an over award to the student. Questioned Cost The student?s tuition was not adjusted to $19,400 in the summer, due to the student being enrolled in nursing. Context During our testing of Need Analysis, we noted that 1 out of the 40 students tested, whose COA was not calculated correctly. Recommendation We recommend that the University address the issues with the packaging software to ensure that funds awarded to the students are in compliance with award limits and that their total award does not exceed their need or cost of attendance. View of Responsible Officials We acknowledge the finding and before each disbursement periods, budgets will be checked prior to releasing funds to Student Accounts.

Corrective Action Plan

2019 ? 002 Need Analysis Criteria According to Volume 3 Chapter 7 of the SFA handbook, the general rule in packaging is that the student?s total financial aid and other estimated financial assistance must not exceed the student?s financial need. Condition Cost of attendance calculation during packaging. Context During our testing of Need Analysis, we noted that 1 out of the 40 students tested, whose COA was not calculated correctly. Questioned Cost The student?s tuition was not adjusted to $19,400 in the summer, due to the student being enrolled in nursing. Cause The University failed to recognize the adjustment to the student?s award for summer classes. Recommendation We recommend that the University address the issues with the packaging software to ensure that funds awarded to the students are in compliance with award limits and that their total award does not exceed their need or cost of attendance. Corrective Actions Planned Financial aid administrators are re-trained to ensure summer budgets in the packaging software are adjusted to match that of the fall and spring budgets for students with full time, year-round programs (such as the nursing undergraduate program). We checked all nursing students with a summer enrollment and found all were in compliance and there were no under awarding or over awarding of financial aid. As a precaution, before each disbursement periods, budgets will be checked prior to releasing funds to Student Accounts.

About Special Tests and Provisions →
2019-003
Special Tests & Provisions
QUESTIONED COSTS
Condition

2019 ? 003 Financial Responsibility Ratio (Student Financial Aid Cluster ? All programs) Criteria According to 34 CFR 668. 171(b)(1), an institution is considered to be financially responsible if the institution?s Equity, Primary Reserve, and Net Income ratios yield a composite score of at least 1.5. Condition The University?s composite score as of June 30, 2019 is 0.96, below 1.5. Cause Noncompliance was caused by the University?s financial condition. Effect The School is not considered to be financially responsible. Questioned Cost There is no questioned cost related to this finding. Context During review of the University?s financial responsibility ratio calculation, we noted that their composite score as of June 30, 2019 is below 1.5. Recommendation We recommend the University take appropriate steps to improve its financial condition to be compliant. View of Responsible Officials We agree with the recommendation.

Corrective Action Plan

2019 ? 003 Financial Responsibility Ratio (Student Financial Aid Cluster ? All programs) Criteria According to 34 CFR 668. 171(b)(1), an institution is considered to be financially responsible if the institution?s Equity, Primary Reserve, and Net Income ratios yield a composite score of at least 1.5. Condition The University?s composite score as of June 30, 2019 is 0.96, below 1.5. Context During review of the University?s financial responsibility ratio calculation, we noted that their composite score as of June 30, 2019 is below 1.5. Questioned Cost There is no questioned cost related to this finding. Cause Noncompliance was caused by the University?s financial condition. Recommendation We recommend the University take appropriate steps to improve its financial condition to be compliant. Corrective Actions Planned On September 2019, the University secured long-term bond financing. The Long-term financing will allow the implementation of the 5-Year Strategic Business Plan. The Plan includes repayment of the Presidio Bank operating line of credit, new program investments of $9.65 million, and providing additional operating cash needed during the strategic plan implementation. The goals of the 5-Year Strategic Business Plan is to develop new academic programs, increase enrollment, expand our advancement team and major donor programs, all of which will improve the financial position of the university.

About Special Tests and Provisions →
2019-004
Special Tests & Provisions
Condition

2019 ? 004 Gramm-Leach-Bliley Act (Student Financial Aid Cluster ? All programs) Criteria Under the University?s Program Participation Agreement and the Gramm-Leach-Bliley Act (GLBA), schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid. According to 16 CFR 314.4(b), a school must identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: 1. Employee training and management; 2. Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and 3. Detecting, preventing and responding to attacks, intrusions, or other systems failures. Condition Although the University has documented a safeguard for certain risk area, the University has not performed a formal risk assessment to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of student information and assess the sufficiency of these safeguards. Cause The University had not scheduled a formal risk assessment until after the June 30, 2019 school year. Effect Student information may be at risk of unauthorized disclosure, misuse, alteration, destruction or other compromise of such information. Questioned Costs There were no questioned costs related to this finding. Context During our review of the University's Information Technology system, we noted through inquiry that a formal risk assessment of the University's documented safeguards had not been performed. Recommendation We recommend that the University consider bringing in an outside resource to independently evaluate and develop a formal risk assessment, along with recommendations for remediation of any open items and/or deficiencies. Otherwise, we recommend the University form a risk assessment group of members of management to schedule at least annual risk assessments. View of Responsible Officials We agree with the recommendation.

Corrective Action Plan

2019 ? 004 Gramm-Leach-Bliley Act (Student Financial Aid Cluster ? All programs) Criteria Under the University?s Program Participation Agreement and the Gramm-Leach-Bliley Act (GLBA), schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid. According to 16 CFR 314.4(b), a school must identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including: 1. Employee training and management; 2. Information systems, including network and software design, as well as information processing, storage, transmission and disposal; and 3. Detecting, preventing and responding to attacks, intrusions, or other systems failures. Condition Although the University has documented a safeguard for certain risk area, the University has not performed a formal risk assessment to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of student information and assess the sufficiency of these safeguards. Context During our review of the University's Information Technology system, we noted through inquiry that a formal risk assessment of the University's documented safeguards had not been performed. Questioned Costs There were no questioned costs related to this finding. Cause The University had not scheduled a formal risk assessment until after the June 30, 2019 school year. Recommendation We recommend that the University consider bringing in an outside resource to independently evaluate and develop a formal risk assessment, along with recommendations for remediation of any open items and/or deficiencies. Otherwise, we recommend the University form a risk assessment group of members of management to schedule at least annual risk assessments. Corrective Actions Planned The University?s Chief Technology Officer (CTO) and the Information Technology (I.T.) team are in the process of documenting our internal and external risks to student information. Which includes an assessment of the security, confidentiality, and integrity of student information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. The CTO and I.T. team do not foresee any problems with compliance and expect to have documented the internal and external risks, controls and systems in place during the subsequent fiscal year.

About Special Tests and Provisions →

FY 2018-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 25, 2019. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 25, 2019, which was (2520 days ago).

What is a management decision? →
2018-001
Special Tests & Provisions
QUESTIONED COSTS
Condition

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →
2018-002
Special Tests & Provisions
Condition

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →

FY 2016-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on March 16, 2017. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 16, 2017, which was (3259 days ago).

What is a management decision? →
2016-001
Special Tests & Provisions
Condition

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →
2016-002
Special Tests & Provisions
MATERIAL WEAKNESS
Condition

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

About Special Tests and Provisions →
2016-003
Special Tests & Provisions
REPEAT
Condition

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-004

About Special Tests and Provisions →
2016-004
Special Tests & Provisions
REPEAT
Condition

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-005

About Special Tests and Provisions →
2016-005
Special Tests & Provisions
REPEAT
Condition

GSA_MIGRATION

Corrective Action Plan

GSA_MIGRATION

Prior Finding References

2015-005

About Special Tests and Provisions →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and compliance status.

Start monitoring →

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.