Audit of AmeriCorps' FY2025 Trust Financial Statements
Open Recommendations
We recommend that the AmeriCorps Chief Information Security Officer, in coordination with the eSPAN and Momentum system owners, implement processes to:
a. ensure user access is documented and approved; and
b. validate that the monthly eSPAN and Momentum recertifications are completed and documented.
We recommend that the eSPAN System Owner ensure eSPAN accounts are disabled for separated personnel within one working day following termination actions as required by AmeriCorps’ policy.