EIN: 946135772
UEI: L2RJLUHMBY16
Audited by: BPM LLP
Oversight agency: 59 [Small Business Administration]
View federal awards & risk assessment →
Data as of September 7, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on February 26, 2023. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by August 26, 2023 (1114 days ago).
What is a management decision? →FAC accepted this audit on March 25, 2021 — management decision was due September 25, 2021.
A.C.T. does not have documented evidence of regular testing performed over safeguards. Effect: Safeguards in place to mitigate risks over Student Information Security may not be operating effectively. Context: During testing of Gramm-Leach-Bliley Act and review of management assessment, it was determined evidence of testing performed over safeguards in place are not documented. Cause: Transitions in both systems and personnel due to remote working environment necessitated by COVID-19. Questioned Costs: None noted Repeat Finding: No Recommendation: We recommend A.C.T. to regular perform and properly document testing over safeguards.
Show full finding ▾Hide full finding ▴Federal Program: Student Financial Assistance Cluster Federal Agency: U.S. Department of Education CFDA Title and Number: Federal Direct Loan Program 84.268, Federal Work Study 84.033, Federal Pell Grant Program 84.063, Federal Perkins Loan Program 84.038 Award Year: July 1, 2019 ? June 30, 2020 Criteria or Specific Requirement: Special Tests and Provisions - Gramm-Leach-Bliley Act - Student Information Security - The Gramm-Leach-Bliley Act (Public Law 106-102) requires financial institutions to explain their information sharing-practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV eligible institutions that participate in Title IV Educational Assistance Programs as ?financial institutions? and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(iv)). Under an institution?s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act, institutions must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal financial aid programs. Institutions are required to designate an individual to coordinate the information security program and perform a risk assessment that addresses (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission and disposal; and (3) detecting, preventing, and responding to attacks, intrusions or other systems failures. Institutions are also required to document the safeguards in place and perform regular testing of safeguards to address each of the risk identified in the areas listed above. Condition: A.C.T. does not have documented evidence of regular testing performed over safeguards. Effect: Safeguards in place to mitigate risks over Student Information Security may not be operating effectively. Context: During testing of Gramm-Leach-Bliley Act and review of management assessment, it was determined evidence of testing performed over safeguards in place are not documented. Cause: Transitions in both systems and personnel due to remote working environment necessitated by COVID-19. Questioned Costs: None noted Repeat Finding: No Recommendation: We recommend A.C.T. to regular perform and properly document testing over safeguards.
WhileA.C.T.performsregulartestingoftheeffectivenessofpoliciesandprocedures intended to safeguard its information systems, A.C.T. will implement formal processes to document the testing procedures performed and the results.
FAC accepted this audit on January 2, 2020 — management decision was due July 2, 2020.
FAC accepted this audit on March 29, 2018 — management decision was due September 29, 2018.
FAC accepted this audit on January 11, 2017 — management decision was due July 11, 2017.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Browse other Single Audit organizations in California →
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Add it to a monitored group and get alerted when a new audit, finding, repeat finding, or management-decision deadline shows up — instead of checking back.
Checking several at once? Portfolio view →
© 2026 Single Audit Intelligence. All data is public domain.