EIN: 941698615
UEI: C7QMA7H9WN88
Data as of August 21, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 29, 2022. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 29, 2022 (1422 days ago).
What is a management decision? →FINDING NO. 2021-001: CARES Act ? Significant Deficiency in Internal Control and Instance of Non-Compliance Federal Program: Higher Education Emergency Relief Fund (HEERF) Grant Program Federal Agency: U. S. Department of Education Award Year: 2020-21 Statement of Condition The Institution did not accurately complete and submit to U.S.D.E. all quarterly reports as required. Criteria The CARES Act requires that institutions complete and submit all quarterly reports, student and institutional, within 10 days from the end of each calendar quarter. Q1 covers January-March and is due April 10, Q2 covers April-June and is due July 10, Q3 covers July-September and is due October 10, and Q4 covers October-December and is due January 10 (CARES Act Section 18004(a)(1)). Effect Of the 4 quarterly reports due during the audit period, the Institution submitted only the report for the quarter ended September 30, 2020 and reported cumulative totals rather than amounts specific to the quarter as required. Additionally, the Institution did not submit a quarterly report for the quarter ended June 30, 2020 during which it incurred a large amount of COVID-19 pandemic-related expenditures and received $177,436 HEERF I funds. Cause The Institution immediately implemented its plan to allow its students and instructors to work remotely when the COVID-19 pandemic triggered a national emergency announced on March 13, 2020. Students living in dormitories were separated and many returned to their parents? homes, resulting in transportation costs and dormitory refunds. Primarily in the quarters ended June 30, 2020 and September 30, 2020, the Institution incurred $1.2 million in COVID-19 pandemic-related costs. The Institution reported these costs in its report for the quarter ended September 30, 2020 although certain costs reported were not incurred during that quarter. Recommendation The Institution should adhere to its procedures and seek guidance if necessary to fully understand regulatory requirements with respect to CARES Act reporting. Additional Information Upon learning of this finding, the Institution promptly completed, provided to the auditors, and submitted revised reports based on U.S.D.E. guidance issued in November 2021. We reviewed the revised reports and found that the Institution properly reported its HEERF receipts and expenditures. Institution Comments The Institution, upon learning of this finding, promptly completed, provided to the auditors, and submitted to U.S.D.E. revised reports based on U.S.D.E. guidance issued in November 2021. Going forward, the Institution will timely and accurately report to U.S.D.E. any future receipts and expenditures of federal funds.
Show full finding ▾Hide full finding ▴FINDING NO. 2021-001: CARES Act ? Significant Deficiency in Internal Control and Instance of Non-Compliance Federal Program: Higher Education Emergency Relief Fund (HEERF) Grant Program Federal Agency: U. S. Department of Education Award Year: 2020-21 Statement of Condition The Institution did not accurately complete and submit to U.S.D.E. all quarterly reports as required. Criteria The CARES Act requires that institutions complete and submit all quarterly reports, student and institutional, within 10 days from the end of each calendar quarter. Q1 covers January-March and is due April 10, Q2 covers April-June and is due July 10, Q3 covers July-September and is due October 10, and Q4 covers October-December and is due January 10 (CARES Act Section 18004(a)(1)). Effect Of the 4 quarterly reports due during the audit period, the Institution submitted only the report for the quarter ended September 30, 2020 and reported cumulative totals rather than amounts specific to the quarter as required. Additionally, the Institution did not submit a quarterly report for the quarter ended June 30, 2020 during which it incurred a large amount of COVID-19 pandemic-related expenditures and received $177,436 HEERF I funds. Cause The Institution immediately implemented its plan to allow its students and instructors to work remotely when the COVID-19 pandemic triggered a national emergency announced on March 13, 2020. Students living in dormitories were separated and many returned to their parents? homes, resulting in transportation costs and dormitory refunds. Primarily in the quarters ended June 30, 2020 and September 30, 2020, the Institution incurred $1.2 million in COVID-19 pandemic-related costs. The Institution reported these costs in its report for the quarter ended September 30, 2020 although certain costs reported were not incurred during that quarter. Recommendation The Institution should adhere to its procedures and seek guidance if necessary to fully understand regulatory requirements with respect to CARES Act reporting. Additional Information Upon learning of this finding, the Institution promptly completed, provided to the auditors, and submitted revised reports based on U.S.D.E. guidance issued in November 2021. We reviewed the revised reports and found that the Institution properly reported its HEERF receipts and expenditures. Institution Comments The Institution, upon learning of this finding, promptly completed, provided to the auditors, and submitted to U.S.D.E. revised reports based on U.S.D.E. guidance issued in November 2021. Going forward, the Institution will timely and accurately report to U.S.D.E. any future receipts and expenditures of federal funds.
The Institution, upon learning of this finding, promptly completed, provided to the auditors, and submitted to U.S.D.E. revised reports based on U.S.D.E. guidance issued in November 2021. Going forward, the Institution will timely and accurately report to U.S.D.E. any future receipts and expenditures of federal funds.
FAC accepted this audit on February 19, 2020 — management decision was due August 19, 2020.
Statement of Condition The Institution did not comply with provisions contained in the Gramm-Leach-Bliley Act (GLBA). Criteria The GLBA (16 CFR 314.4 (b)) includes specific compliance requirements designed to enhance the security of student information maintained electronically by institutions of higher education, as well as third party servicers and other vendors who may require sensitive student information to perform their duties. The compliance requirements include the designation of an individual to coordinate the information security program, periodic risk assessment in three specific areas, and designing and documenting safeguards for identified risks. Effect The Institution was unable to demonstrate compliance with the GLBA, specifically by identifying an individual responsible for coordinating the information security program or performing a risk assessment during the audit period that addressed the three required areas described in 16 CFR 314.4 (b). The three areas are: Employee training and management; information systems, including network and software design, as well as information processing, storage, transmission and disposal; and, detecting, preventing and responding to attacks, intrusions, or other systems failures. The Institution?s internal control over the related compliance requirement did not function as designed and was not effective in detecting this instance of non-compliance. Therefore, this finding represents a significant deficiency in internal control. Cause While the Institution has in place information systems security protocols and personnel, the Institution had not implemented the specific requirements contained in the GLBA. Additional Information The Institution, upon learning of this finding, promptly designed and implemented a periodic risk assessment process in the three areas described in 16 CFR 314.4 (b), created and documented safeguards for identified risks, and designated an individual responsible for coordinating the Institution?s information security program. We reviewed the Institution?s documentation and determined that it satisfies the GLBA requirements. Recommendation The Institution needs to follow its policy and procedures to ensure that GLBA requirements are consistently applied. Institution Comments The Institution concurs with the finding and has procedures in place to ensure compliance with the requirements. Details are included in the Corrective Action Plan.
Show full finding ▾Hide full finding ▴Statement of Condition The Institution did not comply with provisions contained in the Gramm-Leach-Bliley Act (GLBA). Criteria The GLBA (16 CFR 314.4 (b)) includes specific compliance requirements designed to enhance the security of student information maintained electronically by institutions of higher education, as well as third party servicers and other vendors who may require sensitive student information to perform their duties. The compliance requirements include the designation of an individual to coordinate the information security program, periodic risk assessment in three specific areas, and designing and documenting safeguards for identified risks. Effect The Institution was unable to demonstrate compliance with the GLBA, specifically by identifying an individual responsible for coordinating the information security program or performing a risk assessment during the audit period that addressed the three required areas described in 16 CFR 314.4 (b). The three areas are: Employee training and management; information systems, including network and software design, as well as information processing, storage, transmission and disposal; and, detecting, preventing and responding to attacks, intrusions, or other systems failures. The Institution?s internal control over the related compliance requirement did not function as designed and was not effective in detecting this instance of non-compliance. Therefore, this finding represents a significant deficiency in internal control. Cause While the Institution has in place information systems security protocols and personnel, the Institution had not implemented the specific requirements contained in the GLBA. Additional Information The Institution, upon learning of this finding, promptly designed and implemented a periodic risk assessment process in the three areas described in 16 CFR 314.4 (b), created and documented safeguards for identified risks, and designated an individual responsible for coordinating the Institution?s information security program. We reviewed the Institution?s documentation and determined that it satisfies the GLBA requirements. Recommendation The Institution needs to follow its policy and procedures to ensure that GLBA requirements are consistently applied. Institution Comments The Institution concurs with the finding and has procedures in place to ensure compliance with the requirements. Details are included in the Corrective Action Plan.
Thomas Aquinas College, upon learning of this finding, promptly designed and implemented a periodic risk assessment process in the three areas describe in 16 CFR 3 l 4.4(b), created and documented safeguards for the identified risks, and designated an individual responsible for coordinating the Institution's information security program. The following actions have been taken : ? An Information Security Policy (GLBA) has been written. It was written by: o Mr. Dennis McCarthy, Vice President for Finance o Mr. Gregory Becher, Director of Financial Aid o Mr. Patrick Nichols, Network Administrator ? Mr. Dennis McCarthy, Vice President for Finance, has been designated to coordinate the information security program. ? A log is being maintained by Mr. McCarthy of the ongoing risk assessments, the corresponding safeguards implemented to mitigate those risks, and the testing/monitoring of the effectiveness of those safeguards. ? Mr. McCarthy is overseeing the College's service providers to ensure those service providers maintain adequate data safeguards. ? ? In light of the results from the aforementioned testing and monitoring, Mr. McCarthy is evaluating and adjusting the school's information security program on an ongoing basis.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.