COMMONWEALTH OF VIRGINIA SINGLE AUDIT REPORT FOR THE YEAR ENDED JUNE 30, 2019 Auditor of Public Accounts Martha S. Mavredes, CPA www.apa.virginia.gov (804) 225-3350 - T A B L E O F C O N T E N T S - Page AUDITOR’S SECTION 1-135 EXECUTIVE SUMMARY 2 INTRODUCTION LETTER 3-5 - INDEPENDENT AUDITOR’S REPORTS: 6-13 Independent Auditor’s Report on Internal Control over Financial Reporting and on Compliance and Other Matters based on an Audit of Financial Statements Performed in Accordance with Government Auditing Standards 6-9 Independent Auditor’s Report on Compliance for Each Major Federal Program; Report on Internal Control over Compliance; and Report on Schedule of Expenditures of Federal Awards Required by the Uniform Guidance 10-13 SCHEDULE OF FINDINGS AND QUESTIONED COSTS: 14-135 Section 1: Summary of Auditor’s Results 14-15 Section 2: Financial Statement Findings 16-124 Section 3: Federal Award Findings and Questioned Costs: 124-135 U.S. Department of Health and Human Services 124-129 U.S. Department of Education 129-132 U.S. Department of Education and Social Security Administration 132-135 U.S. Department of Transportation 135 U.S. Department of Agriculture 135 U.S. Department of Labor 135 MANAGEMENT’S SECTION 136-243 SUMMARY SCHEDULE OF PRIOR AUDIT FINDINGS 137-182 SCHEDULE OF EXPENDITURES OF FEDERAL AWARDS: 183-243 Schedule of Expenditures of Federal Awards 183-236 Notes to the Schedule of Expenditures of Federal Awards 237-243 APPENDICES: 244-255 Appendix I: Listing of Findings: 245-250 Grouped by Topic 245-247 Grouped by Applicable Entity 248-250 Appendix II: Applicable Management Contacts for Findings and Questioned Costs 251-253 Appendix III: Acronyms for Auditor’s Section 254-255 AUDITOR’S SECTION FISCAL YEAR 2019 AUDITOR'S SECTION | 1 EXECUTIVE SUMMARY The results of our financial statement audit of the Commonwealth of Virginia for the year ended June 30, 2019, are summarized as follows: • we issued an unmodified opinion on the basic financial statements; • we found certain matters that we consider to be material weaknesses or significant deficiencies in internal control over financial reporting; and • we identified instances of noncompliance or other matters required to be reported under Government Auditing Standards related to the basic financial statements. The results of our single audit of the Commonwealth of Virginia for the year ended June 30, 2019, are summarized as follows: • we issued an unmodified opinion on the Commonwealth’s compliance with requirements applicable to each major federal program; • we found certain matters and instances of noncompliance with selected provisions, which are required to be reported in accordance with the Uniform Guidance, 2 C.F.R. Part 200; • we did not identify any matters that we consider to be material weaknesses in internal control over compliance; • we found certain matters that we consider to be significant deficiencies in internal control over compliance; and • the Schedule of Expenditures of Federal Awards is fairly stated in all material respects in relation to the financial statements as a whole. Our audit findings, along with a summary of the views of officials, are reported in the accompanying “Schedule of Findings and Questioned Costs.” Consistent with prior years, unabridged views of responsible officials concerning audit findings are in the report related to their agency, which can be found at www.apa.virginia.gov. Management’s Corrective Action Plan will be available from the Federal Audit Clearinghouse web site and the Virginia Department of Accounts’ web site at www.doa.virginia.gov. FISCAL YEAR 2019 AUDITOR'S SECTION | 2 February 7, 2020 The Honorable Ralph S. Northam The Honorable Thomas K. Norment, Jr. Governor of Virginia Chairman, Joint Legislative Audit and Review Commission We are pleased to submit the Commonwealth of Virginia Single Audit Report for the fiscal year ended June 30, 2019. This report contains our: • report on internal control over financial reporting and compliance; • report on compliance for each major federal program; • report on internal control over compliance; • report on the Schedule of Expenditures of Federal Awards; and • resulting Schedule of Findings and Questioned Costs. Additionally, this report contains management's: • Summary Schedule of Prior Audit Findings; and • Schedule of Expenditures of Federal Awards, with footnotes. The Commonwealth’s Comprehensive Annual Financial Report for the year ended June 30, 2019, and our report thereon have been issued under separate cover. As in previous years, we included two listings of all findings in Appendix I of this report. The first list organizes all findings by topical area and the second list organizes all findings by the applicable entity. Additionally, because information security findings are a substantial number of the Commonwealth’s findings, we continue to provide additional information about these findings. The Commonwealth of Virginia’s Information Security Standard, SEC 501 (Security Standard) adopts the Information System Security Control Families (families) from the National Institute of Standards and Technology (NIST). The Security Standard uses these families to organize the controls that the Commonwealth is required to apply to its information systems. According to NIST, a family “contains security controls related to the general security topic of the family. Security controls may involve aspects of policy, oversight, supervision, manual processes, actions by individuals, or automated mechanisms implemented by information systems and devices.” Chart 1 on the next page shows the categories for all non-information system security findings and Chart 2 shows the control families impacted by the issues reported in the information system security findings. FISCAL YEAR 2019 AUDITOR'S SECTION | 3 Non-Information System Security Findings Chart 1 Financial Accounting and Reporting 7 Human Resources and Payroll 13 5 Other Grants Management and Federal Award and Questioned Costs Statement of Economic 6 Interests 11 Retirement System Member Data 11 Miscellaneous Of the 53 findings above in Chart 1, four represent weaknesses that are material to the Commonwealth’s Comprehensive Annual Financial Report. Additionally, there are 55 information system security findings represented in Chart 2 below. Consistent with recent years, access control represents approximately one third of the weaknesses related to information system security. Information System Security Findings by Control Families Chart 2 Access Control 12 Contingency Planning Configuration Management 26 5 Audit and Accountability 5 System and Communications Protection 5 System and Information Integrity 7 9 System and Services 8 Acquisition Six Other Control Families Note: Twelve findings reported deficiencies with multiple control families. For this graph, these deficiencies are broken-out and included to the total of each control family impacted. FISCAL YEAR 2019 AUDITOR'S SECTION | 4 We would like to express our appreciation to the many individuals whose efforts assisted in preparing this report and recognize the Commonwealth’s management and federal program and financial staff for their cooperation and assistance in resolving single audit issues. Martha S. Mavredes AUDITOR OF PUBLIC ACCOUNTS GDS/clj FISCAL YEAR 2019 AUDITOR'S SECTION | 5 INDEPENDENT AUDITOR’S REPORT ON INTERNAL CONTROL OVER FINANCIAL REPORTING AND ON COMPLIANCE AND OTHER MATTERS BASED ON AN AUDIT OF FINANCIAL STATEMENTS PERFORMED IN ACCORDANCE WITH GOVERNMENT AUDITING STANDARDS We have audited, in accordance with the auditing standards generally accepted in the United States of America and the standards applicable to financial audits contained in Government Auditing Standards issued by the Comptroller General of the United States, the financial statements of the governmental activities, the business-type activities, the aggregate discretely presented component units, each major fund, and the aggregate remaining fund information of the Commonwealth of Virginia, as of and for the year ended June 30, 2019, and the related notes to the financial statements, which collectively comprise the Commonwealth's basic financial statements, and have issued our report thereon dated December 13, 2019. Our report includes a reference to other auditors who audited the financial statements of the Virginia College Savings Plan (major fund and private purpose trust fund), which is discussed on pages 53 and 262 of the financial statements, and certain blended and discretely presented component units of the Commonwealth, as described in our report on the Commonwealth’s financial statements and Note 1.B. of the financial statements. This report does not include the results of the other auditors’ testing of internal control over financial reporting or compliance and other matters that are reported on separately by those auditors. The financial statements of the Science Museum of Virginia Foundation, Virginia Museum of Fine Arts Foundation, Library of Virginia Foundation, and Danville Science Center, Inc, which were audited by other auditors upon whose reports we are relying, were audited in accordance with auditing standards generally accepted in the United States of America, but not in accordance with Government Auditing Standards. Internal Control Over Financial Reporting In planning and performing our audit of the financial statements, we considered the Commonwealth's internal control over financial reporting (internal control) to determine the audit procedures that
