• Skip to primary navigation
  • Skip to main content
Dean Dorton – CPAs and Advisors
  • Services
        • Audit & Assurance
          • Audits, Reviews & Compilations
          • ESG Programs & Reporting
          • Internal Audit
          • International Financial Reporting
          • Lease Accounting Managed Services
          • Peer Review Services
          • SOC Reporting
        • Family Office
        • Consulting & Advisory
          • Business Valuation Services
          • Forensic Accounting
          • Fractional CFO
          • Litigation Support
          • Matrimonial Dissolution
          • Merger & Acquisition
          • SEC Services
          • Succession Planning
          • Transaction Advisory Services
          • Whistleblower Hotline
        • Outsourced Accounting
        • Private Wealth
        • Healthcare Consulting
          • Finance
          • Health Systems Operational Transformation
          • Medical Billing and Credentialing
          • Risk Management & Compliance
          • Strategic Growth for Private Practices
          • Strategy and Strategy Implementation
          • Technology & Data Analytics
        • Tax
          • Business Tax
          • Cost Segregation Studies
          • Credits and Incentives
          • Estates and Trusts
          • Individual Tax
          • International Tax
          • SEC Provision and Compliance
          • State and Local Tax
        • Technology & Cybersecurity
          • Accounting Software
          • Cybersecurity, IT Audit, & Compliance
            • Cybersecurity Assessments
            • Cybersecurity Maturity Model Certification (CMMC)
            • Cybersecurity Scorecard Assessment
            • Data Privacy Laws
            • Security Awareness Training
            • SOC Reporting
            • Virtual Information Security Office
          • Data Analytics & AI
          • IT Infrastructure & Cloud Solutions
            • Automation
            • Backup and Disaster Recovery
            • Cloud Strategy
            • Data Center
            • Enterprise Network
            • Network Security
            • Phone and Video Conferencing
            • User Identity Management Solutions
            • Webex
          • Managed IT Services
  • Industries
        • Construction
        • Distilleries and Craft Breweries
        • Energy and Natural Resources
        • Equine
        • Financial Institutions
        • Government
        • Healthcare
        • Higher Education
        • Life Sciences
        • Manufacturing and Distribution
        • Nonprofit
        • Real Estate
  • Insights
    • Articles
    • Guides
    • Case Studies
  • Events
  • Company
        • News
        • Our Team
        • Experiences
        • Careers
          • College Students
          • Experienced Professionals
        • Locations
        • Lexington, KY

          250 West Main Street
          Suite 1400
          Lexington, KY 40507
          859-255-2341

        • Louisville, KY

          435 North Whittington Parkway
          Suite 400
          Louisville, KY 40222
          502-589-6050

        • Louisville, KY

          700 North Hurstbourne Parkway
          Suite 115
          Louisville, KY 40222
          502-589-6050

        • Ft. Wright, KY

          810 Wright’s Summit Parkway
          Suite 300
          Fort Wright, KY 41011
          859-331-3300

        • Cincinnati, OH

          312 Walnut Street
          Suite 3330
          Cincinnati, OH 45202
          859-331-3300

        • Blue Ash, OH

          9987 Carver Rd
          Suite 120
          Blue Ash, OH 45242
          513-891-5911

        • West Chester, OH

          9025 Centre Pointe Drive
          Suite 310
          West Chester, OH 45069
          513-985-6240

        • Indianapolis, IN

          5975 Castle Crk Pkwy Dr N
          Suite 400
          Indianapolis, IN 46250
          317-469-0169

        • Raleigh, NC

          4130 Parklake Avenue
          Suite 400
          Raleigh, NC 27612
          919-782-9265

  • Contact Us

Higher Education

Article 05.11.2026 Dean Dorton

May is Internal Audit Awareness Month, a timely reminder of the important role internal audit and risk assessment play in helping institutions navigate growing complexity and uncertainty.

Higher education is operating with a tighter margin for error than it has in years financially, operationally, and reputationally. Enrollment swings, rising compliance expectations, and cyber risk are hitting at once. When risk assessment and internal audit are positioned well, they give leadership early visibility into what could disrupt the mission, and practical steps to reduce surprises.

The Expanding Risk Landscape

In higher education, the risk environment is uniquely complex, spanning academics, operations, finances, and reputation. In our work with colleges and universities, the pressure points most campuses are managing typically include:

  • Cybersecurity & data privacy: Sensitive student, research, and financial data; evolving threats
  • Regulatory compliance: Title IV, Clery, FERPA, grant requirements
  • Financial sustainability: Enrollment volatility, tuition dependence, declining state support, endowment pressure
  • Research integrity & funding oversight: Federal scrutiny; controls that stand up to review
  • Operational complexity: Decentralization, inconsistent processes, control gaps

When the top risks aren’t clearly prioritized, campuses end up reacting after the fact. A structured risk assessment helps leaders focus early and stay ahead of issues before they become findings, headlines, or budget surprises.

Why the Margin for Error Is Shrinking (Public and Private)

Many institutions feel this, public and private alike. Whether the driver is enrollment volatility, pricing and discounting, endowment performance, or new compliance demands, the margin for surprises is shrinking.

For public institutions, uncertainty in state support can tighten that margin even further. When baseline funding is unpredictable, control breakdowns, delayed reporting, or weak oversight can turn into real budget surprises faster, and with fewer options to absorb them.

The Role of Risk Assessment

A good risk assessment gives leadership a clear, practical view of what could most disrupt the mission and how the institution is responding.

When it’s done well, the risk assessment:

  • Surfaces the highest-impact risks (and separates what’s urgent from what’s just noise)
  • Connects risk to strategy, so priorities reflect where the institution is going, not just where it’s been
  • Calls out gaps in controls, ownership, and governance before they become findings
  • Sets the direction for the audit plan and the work that will move the needle

In our experience, the best risk assessments include a broad mix of voices (academic leadership, finance, IT, compliance, and research administration). That’s how leadership gets a view of risk that matches how the campus actually runs, not just how the organizational chart says it runs.

Internal Audit as a Strategic Partner

Internal audit still gets pegged as a backward-looking function, where someone shows up after the fact and writes a report. That’s not how the strongest teams operate. Modern internal audit helps leadership get ahead of risk, strengthen operations, and build confidence in how things work day to day.

For example, instead of reviewing a process after a breakdown, leading teams are assessing new system implementations, research programs, or third-party relationships early, before risks materialize.

That can look like a quick pre-go-live review of an ERP or student information system change, a readiness check for a new research center, or due diligence around a key vendor before contracts are signed.

In practice, that shows up in a few ways:

  • Independent assurance: pressure-testing whether controls are designed well and operating as intended
  • Advisory support: helping process owners make improvements and think through emerging risks
  • Risk alignment: making sure the audit plan tracks to today’s priorities, not last year’s cycle
  • Governance support: equipping boards and audit committees with the visibility they need for effective oversight

When it’s positioned well, internal audit has a seat at the leadership table, engaged early to shape decisions, while still maintaining the independence and objectivity leaders rely on.

Common Gaps We See

Across higher ed, a few recurring issues tend to get in the way of a strong risk and audit function:

  • Risk assessments that happen too infrequently (or become a one-and-done exercise)
  • Audit plans driven by historical cycles instead of current risk priorities
  • Compliance, risk management, and internal audit operating in silos
  • Teams that are lean relative to the risk profile, especially in technical areas like IT security and research compliance
  • Inconsistent documentation of processes and controls across departments

Closing these gaps doesn’t always require a major investment. Most of the time it starts with clearer ownership, better alignment, and more discipline around prioritization. For smaller audit teams, it can also mean rethinking the delivery model, such as co-sourcing or targeted specialists, so the highest-risk areas get real coverage.

Practical Steps to Strengthen Your Approach

If you want to strengthen your internal audit and risk assessment approach, these are practical moves that tend to pay off. If you do only a few things, start with the “Do now” list, then move to “Do next” as you build momentum.

Do now (next 30 to 60 days)

  1. Confirm the current risk assessment is less than 12 months old; if not, refresh it.
  2. Gather executive and board/audit committee input on what should rise to the top.
  3. Map planned audits to top risks and identify gaps or low-value carryovers.
  4. Identify 2–3 high-risk areas where analytics could add immediate value.
  5. Assess where your team lacks depth (especially cybersecurity, grants management, and research compliance).
  6. Clarify risk ownership and expectations for process owners (what “good controls” looks like).
  7. Identify technical areas where coverage is needed but capacity is limited.

Do next (this year)

  1. Set a cadence (at least annually) and trigger updates when the institution changes (new systems, new programs, major leadership shifts).
  2. Build a repeatable leadership input process (interviews, surveys, workshops) to refresh priorities.
  3. Reallocate limited resources to where coverage will matter most (highest impact, weakest controls, greatest change).
  4. Build repeatable analytics to surface trends, anomalies, and control breakdowns faster than interviews alone.
  5. Line up SMEs (internal or external) for targeted reviews, planning support, or technical testing.
  6. Embed risk thinking into how departments operate (check-ins, metrics, onboarding), not a separate annual exercise.
  7. Use co-sourcing to expand coverage in specialized areas without building permanent fixed costs.

Make Internal Audit Accessible Across Campuses

For decentralized institutions, internal audit is most effective when it’s visible, approachable, and easy to engage. A few moves that can help:

  • Predictable touch points: Virtual office hours and periodic on-site days
  • Campus liaisons: One point of contact per campus/area to coordinate and escalate
  • Simple intake: One clear pathway (advisory request, concern, training) and response times
  • Short learning sessions: 30-minute, role-based webinars on common pain points
  • Plain-language tools: One-page checklists and “what good looks like” examples
  • Feedback loop: Quick post-engagement input to improve timing, communication, and deliverables

If you’re not sure where to start, pilot two or three of these steps at one campus this quarter, then scale what works across the system.

The Bottom Line

Higher education can’t eliminate risk, but it can be managed far more intentionally. A thoughtful risk assessment paired with a well-positioned internal audit function gives leaders visibility, strengthens controls, and supports confident decision-making.

When resources are tight and expectations keep rising, that kind of clarity isn’t a nice to have. It’s what keeps surprises from becoming crises.

If you’re reassessing your approach, consider benchmarking your current audit plan against today’s risk profile, then selecting one “Do now” action to tackle in the next 30 to 60 days. Contact the Dean Dorton team to discuss how we can help support your internal audit and risk assessment efforts.

Filed Under: Higher Education Tagged With: Higher Education, Internal Audit

Article 05.8.2026 Dean Dorton

A recent cybersecurity incident involving Instructure (parent company of Canvas LMS) highlights the scale and complexity of today’s threat landscape, with potential data exposure impacting thousands of institutions globally. Following unauthorized access identified on April 29, 2026, Instructure announced additional unauthorized activity on May 7 tied to the same incident, temporarily placing Canvas into maintenance mode while additional safeguards were implemented.

Instructure has since confirmed the activity was linked to a vulnerability involving its Free-For-Teacher accounts, which have been temporarily shut down during ongoing remediation efforts. The threat actor group ShinyHunters has claimed responsibility for the incident and alleges the theft of approximately 275–280 million records across more than 8,800 educational institutions globally.

Data confirmed or believed to be exposed includes:
• Full names
• Email addresses
• Student ID numbers
• Private messages between Canvas users

While the platform remains operational, events like this serve as an important reminder: even widely trusted third-party systems can introduce risk.

For colleges and universities, the stakes are especially high—sensitive student, faculty, and institutional data must be protected, and disruptions can directly impact learning environments.

At Dean Dorton, we work alongside Higher Education institutions to bring awareness to evolving cyber risks and help leaders think proactively about:
• Third-party risk exposure
• Data governance and protection
• Incident response preparedness
• Ongoing monitoring and compliance

Cybersecurity isn’t just an IT issue—it’s an institutional priority.

Staying informed is the first step toward staying protected.

If your institution would like to discuss cybersecurity preparedness, third-party risk management, or incident response planning, contact the Dean Dorton team.

Filed Under: Higher Education Tagged With: Cybersecurity, Higher Education

Article 05.13.2025 Autumn Hines

On May 12, 2025, the House Ways and Means Committee released its long-awaited draft of proposed tax legislation. If enacted, this could have the most significant impact on tax-exempt organizations since the Tax Cuts and Jobs Act. Below is a summary of highlights in the proposed legislation.

Increase in Rate of Tax on Net Investment Income of Certain Private Foundations

The draft bill proposes an increased excise tax on private foundations’ net investment income, which could impact grantmaking and the execution of exempt purpose activities.

  • 1.39% in the case of a private foundation with assets of less than $50,000,000
  • 2.78% in the case of a private foundation with assets of at least $50,000,000 and less than $250,000,000
  • 5% in the case of a private foundation with assets of at least $250,000,000 and less than $5,000,000,000, and
  • 10% in the case of a private foundation with assets of at least $5,000,000,000

Modification of Excise Tax on Investment Income of Certain Private Colleges and Universities

A tax would be imposed on the net investment income of an “applicable educational institution”:

  • 1.4% in the case of an institution with a student endowment in excess of $500,000 and less than $750,000
  • 7% in the case of an institution with a student endowment in excess of $750,000 and less than $1,250,000
  • 14% in the case of an institution with a student endowment in excess of $1,250,000 and less than $2,000,000, and
  • 21% in the case of an institution with a student endowment in excess of $2,000,000

See our article on how this proposed tax bill could impact colleges and universities for a more in-depth explanation of terms.

Unrelated Business Income Increased by the Amount of Certain Fringe Benefit Expenses for Which Deduction is Disallowed

The proposed bill would include qualified transportation fringe benefits and parking facilities disallowed under IRC section 274 in an organization’s unrelated business income for the year. This provision was initially included in the Tax Cuts and Jobs Act and was subsequently repealed.

Name and Logo Royalties Treated as Unrelated Business Taxable Income

The proposed bill would include the sale or licensing of an organization’s name or logo as an unrelated trade or business regularly carried on by the organization.

1% Floor on Deduction of Charitable Contributions Made by Corporations

The proposed bill would include a 1% floor on corporate charitable deductions and allow corporations to carry the unused tax benefit forward 5 years, which could help increase charitable giving.

Reinstatement of Partial Deduction for Charitable Contributions of Individuals Who Do Not Elect to Itemize

While the standard deduction was increased, which could impact individuals’ ability to deduct charitable contributions, the proposed bill reinstates the deduction for those who do not itemize. The deduction would be reduced from $600 to $300 ($150 for married filing separate and single filers).

Termination of Tax-Exempt Status of Terrorist-Supporting Organizations

This provision would allow the Treasury to revoke the exempt status of organizations deemed to provide “material support or resources” that support terrorist activities.

While the above provisions are just some highlights, there is other proposed legislation that may impact tax-exempt organizations, such as an extension of excise tax on executive compensation for employees earning over $1 million, changes to the excess business holdings rule for private foundations, updates to the exclusion for publicly available research income, termination of certain energy credits, and other individual and business income tax provisions.

Although the bill is in draft format, we will watch closely as it moves through Congress. If you have any questions about how the proposed legislation may impact your organization, please contact your trusted Dean Dorton advisor.

Filed Under: Accounting & Tax, Higher Education, Nonprofit & Government Tagged With: Higher Education, nonprofit, Tax

Article 05.13.2025 Autumn Hines

The recently released draft of the House Ways and Means Committee’s proposed tax bill included a significant impact on colleges and universities. The 2017 Tax Cuts and Jobs Act imposed a 1.4% excise tax on the investment income of an “applicable educational institution.” The proposed bill expands the excise tax, as detailed below.

  • 1.4% in the case of an institution with a student endowment in excess of $500,000 and less than $750,000
  • 7% in the case of an institution with a student endowment in excess of $750,000 and less than $1,250,000
  • 14% in the case of an institution with a student endowment in excess of $1,250,000 and less than $2,000,000, and
  • 21% in the case of an institution with a student endowment in excess of $2,000,000

Applicable Educational Institution

An “applicable educational institution” is described as an eligible educational institution (as defined in IRC section 25A(f)(2)):

  • Which had at least 500 tuition-paying students during the preceding tax year,
  • More than 50% of the tuition-paying students of which are located in the U.S.,
  • Which is not a state college or university or a qualified religious institution, and
  • The “student adjusted endowment” of which is at least $500,000.

Student Adjusted Endowment

“Student adjusted endowment” means the aggregate fair market value of the institution’s assets (determined as of the end of the preceding tax year, other than those assets used directly in carrying out the institution’s exempt purpose) divided by the number of eligible students of the institution. An eligible student meets the requirements under Section 484(a)(5) of the Higher Education Act of 1965.

The institution’s net investment income is determined under rules similar to the rules of IRC section 4940(c).

The proposed bill also includes the aggregation of related organizations. A related organization is defined as any organization that:

  • Controls, or is controlled by, such institution,
  • Is controlled by one or more persons who also control such institution, or
  • A supported organization (as defined in IRC section 509(f)(3)) or an organization described under IRC section 509(a)(3).

Although the bill is in draft format, we will watch closely as it moves through Congress. If you have any questions about how the proposed legislation may impact your organization, please contact your trusted Dean Dorton advisor.

Filed Under: Accounting & Tax, Higher Education, Nonprofit & Government Tagged With: Higher Education, nonprofit, Tax

Article 03.3.2025 Autumn Hines

On February 14, 2025, the U.S. Department of Education Office for Civil Rights (the Department) released a Dear Colleague Letter (DCL) notifying institutions that they should stop using race preferences and stereotypes as factors in admissions, hiring, promotion, compensation, financial aid, scholarships, prizes, administrative support, discipline, housing, graduation ceremonies, and all other aspects of student, academic, and campus life. The letter also advised that institutions should:  

“(1) ensure that their policies and actions comply with existing civil rights law; (2) cease all efforts to circumvent prohibitions on the use of race by relying on proxies or other indirect means to accomplish such ends; and (3) cease all reliance on third-party contractors, clearinghouses, or aggregators that are being used by institutions in an effort to circumvent prohibited uses of race.”  

If institutions do not comply, they risk losing federal funding. Read the full letter here. 

On February 28, 2025, the Department released a Frequently Asked Questions (FAQ) as a follow-up to the DCL. The FAQ is meant to provide more detail about how the “Students for Fair Admissions, Inc. v. President & Fellows of Harvard College, 600 U.S. 181 (2023) (“Students v. Harvard” or “SFFA”) decision applies to applies to racial classifications, racial preferences, and racial stereotypes as well as how the Department will interpret the ruling in its enforcement of Title VI of the Civil Rights Act of 1964 and its implementing regulations.”

The FAQ covers questions from the admissions process to investigation and non-compliance with regulations. The FAQ will continue to be updated as questions arise.  

As the Department continues to provide updates and clarification on these policies, it is important for institutions to stay informed and ensure compliance with evolving regulations. The team at Dean Dorton will continue to monitor the situation and share relevant updates as they become available. If you have any questions or need guidance on how these changes may impact your institution, please don’t hesitate to contact Megan Crane. 

Read the FAQ here. 

Filed Under: Higher Education Tagged With: DEI, Higher Education

Article 02.13.2025 Autumn Hines

On February 12, 2025, the U.S. Department of Education’s Office for Civil Rights (OCR) announced the rescission of guidance issued in the final days of the Biden administration concerning Name, Image, and Likeness (NIL) compensation for student-athletes. The Biden administration guidance had interpreted NIL agreements between schools and student-athletes as a form of financial aid, necessitating proportional distribution between male and female athletes under Title IX.  

We previously covered the Biden administration guidance here.  

This policy reversal has significant implications for collegiate athletics: 

  • Potential for Increased Gender Disparities: Without the requirement for proportional distribution, there is concern that NIL compensation may become concentrated in male-dominated sports, such as football and men’s basketball.  
  • Impact on Revenue-Sharing Models: The rescission may influence how institutions design their revenue-sharing frameworks, possibly leading to models that favor revenue-generating sports without mandated considerations for gender equity.  
  • Legal and Compliance Considerations: Institutions may need to reassess their Title IX compliance strategies, as the rescission alters the regulatory landscape regarding NIL compensation and its distribution. 

For questions or further inquiries, please contact Megan Crane.  

Filed Under: Higher Education Tagged With: Higher Education, NIL, Title IX

  • Page 1
  • Page 2
  • Page 3
  • Interim pages omitted …
  • Page 5
  • Go to Next Page »
  • Services
    • Outsourced Accounting
    • Audit & Assurance
    • Tax
    • Consulting & Advisory
    • Technology & Cybersecurity
    • Family Office
    • Wealth Management
  • Industries
  • Company
  • Locations
  • Careers
  • Insights
  • Events
  • Contact Us
facebook Dean Dorton - CPAs And Advisors On Facebook twitter twitter linkedin Dean Dorton - CPAs And Advisors On LinkedIn youtube Dean Dorton - CPAs And Advisors On YouTube

The matters discussed on this website provide general information only. The information is neither tax nor legal advice. You should consult with a qualified professional advisor about your specific situation before undertaking any action.

© 2026 Dean Dorton Allen Ford, PLLC. All Rights Reserved