GAO

Fraud in Federal Programs: Limited Beneficial Ownership Information Available on Awardees

What GAO Found Illicit actors hide their beneficial ownership in multiple ways to fraudulently access federal awards, such as contracts, grants, and Medicare payments, and to evade payment on taxes. GAO’s review of federal cases highlights tactics illicit actors have used, such as using stolen identities, shell companies, professional enablers, and pass-through billing schemes to hide ownership. For example, from July 2019 through January 2023, three purported hospice owners stole identities to register shell companies and defrauded Medicare for nearly $16 million. In another example, from June 2018 through September 2018, a foreign-based scam ring, with U.S. based conspirators, directed legitimate federal contractors to a fake government website. This pass-through billing scam caused the government to misdirect $23.5 million to the fraudsters. Pass-Through Billing Scam The federal award process requires recipients to disclose some information on company owners and relationships, but it generally does not require disclosure of beneficial owner information. For example, names of corporate officers and directors may be collected, but these individuals may not be the beneficial owners or exercise substantial control over the entity. Beneficial ownership information is available to a limited extent in data sources such as the Department of the Treasury’s Financial Crimes Enforcement Network’s (FinCEN) company registry, the General Services Administration’s (GSA) System for Award Management, and state incorporation registries. Changes in the scope of reporting requirements now exempt domestic entities from reporting beneficial ownership information in the FinCEN registry. This exemption removed about 99 percent of entities previously required to report. The National Defense Authorization Act for Fiscal Year 2021 includes a provision for the GSA to maintain a database that contains beneficial ownership information for federal contractors. A Federal Acquisition Regulation (FAR) case was opened in 2021 to implement this and other related provisions, but the FAR Council deadline to draft a proposed rule has been extended until at least September 2026. GSA had considered using FinCEN’s beneficial ownership registry to develop the database, but that source is now of limited use. GAO will continue to monitor progress on GSA’s efforts to implement the statutory provision. GAO’s analysis of federal award data highlights the hundreds of billions of dollars vulnerable to beneficial ownership-related fraud risks. Awards, such as contracts awarded to foreign businesses, are among those categories that are vulnerable to beneficial ownership fraud risks. Why GAO Did This Study Beneficial ownership information identifies the individuals who ultimately benefit or control a company. While individuals listed as company owners in state incorporation records may indeed be the beneficial owner, this is not always the case. GAO was asked to provide insights on what information is available from various federal, state, and commercial data sources to identify beneficial owners, and the related fraud risks to federal awards. GAO reviewed relevant fraud cases from various sources such as Department of Justice press releases; reviewed federal regulations on beneficial ownership reporting requirements; analyzed federal award data to assess potential financial impacts of beneficial ownership fraud in federal awards; and examined the nature of company ownership information collected in relevant federal datasets and state corporate registries. For more information, contact Rebecca Shea at SheaR@gao.gov.

Categories -

Supplemental Material for GAO-25-107721: Summary of Key Changes in the 2025 Green Book Revision

This is a supplement to GAO’s 2025 revision of the Standards for Internal Control in the Federal Government, known as the Green Book, GAO-25-107721. The 2025 revision contained changes from, and supersedes, the 2014 revision of the Green Book, GAO-14-704G. The purpose of this supplement is to present the key changes to the 2025 revision of the Green Book. Resources For more information or for technical assistance regarding the Green Book, please call (202) 512-9535 or e-mail greenbook@gao.gov. Visit GAO’s Green Book website for more information on applicable updates and alerts. To receive updates and information related to standards, send an email with the subject “Subscribe” to TheStandardsTeam@gao.gov.

Categories -

Director of National Intelligence: Status of Open GAO Recommendations

What GAO Found GAO has made 139 recommendations to the Director of National Intelligence (DNI) from July 2011 through September 15, 2026. These recommendations address issues with intelligence enterprise management, infrastructure and facilities, workforce management, and personnel vetting. As of September 15, 2026, the Office of the DNI (ODNI) has implemented 76 recommendations, or 55 percent. GAO closed six additional recommendations for various other reasons, such as a program having terminated or changed. By fully implementing the 57 remaining open recommendations, ODNI could improve the efficiency and effectiveness of its intelligence management and oversight. In July 2026, GAO identified six of these 57 as recommendations that ODNI should prioritize to improve intelligence operations and address high-risk issues. Why GAO Did This Study The James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 includes a provision for the Comptroller General to submit a list to the Congressional Intelligence Committees and to the DNI of all GAO recommendations made to the DNI as of September 30, 2023, that had not been fully implemented, and annually thereafter through 2028. This letter and its enclosures is GAO’s fourth submission, which formally transmits and communicates the results of its work. For more information, contact Alissa Czyz at czyza@gao.gov.

Categories -

VA Health Care: Prevalence Information Needed to Better Understand and Address Harassment Involving Veterans

What GAO Found The Department of Veterans Affairs (VA) has a policy to end harassment-related behaviors—including harassment of a non-sexual nature, sexual harassment, and sexual assault—at its VA medical centers. The policy gives certain VA medical center staff responsibility for managing reported incidents of these behaviors involving veterans. GAO’s analysis of VA data found there were over 31,000 reported incidents from fiscal years 2020 through 2025. Most involved veterans (or other patients) who engaged in these behaviors against staff. Number of Reported Incidents of Harassment-Related Behaviors Involving Veterans at VA Medical Centers, Fiscal Years 2020-2025 However, the data on reported incidents likely do not capture all incidents of harassment-related behaviors. According to reports by stakeholders, most individuals who experience such behaviors do not notify the institutions at which the incidents occur. For example, several studies found that just 2 to 7 percent of individuals formally notify someone about experiencing sexual harassment. Individuals’ unwillingness to report is attributed to causes such as fear of retaliation. As a result, stakeholders have indicated the importance of identifying the prevalence of these behaviors, or their occurrence regardless of whether individuals notify someone, to better understand their potential within organizations. This can be done through anonymous or confidential surveys. VA officials said they collect information on veteran experiences with certain harassment-related behaviors at a subset of VA medical centers to inform policies and practices. However, VA has not implemented any effort to identify the systemwide prevalence of these behaviors. Implementing a means to do so, such as through a survey, would better allow VA to know whether increases in reported incidents reflect greater willingness to notify staff or an actual increase in these behaviors. It also would help VA more effectively direct resources toward prevention and mitigation efforts to reach those most at risk. Why GAO Did This Study Harassment-related behaviors within the VA health care system may put veterans at risk and compromise care. For example, researchers have found that veterans who experience these behaviors may avoid needed care. Further, staff who experience such behaviors may rush care in response. In 2022, VA established a policy aimed at ending harassment-related behaviors, but reported incidents of these behaviors have since generally increased. GAO was asked to review VA processes for responding to harassment-related behaviors. This report describes data on reported incidents of these behaviors involving veterans at VA medical centers and examines VA’s efforts to identify the prevalence of these behaviors. GAO analyzed available VA data on reported incidents of harassment-related behaviors from fiscal year 2020 through fiscal year 2025; reviewed relevant VA policies; interviewed VA officials responsible for harassment-related matters; reviewed reports by and interviewed stakeholders, including officials from the National Academies of Sciences, Engineering, and Medicine and RAND, on their published work related to identifying the prevalence of these behaviors; and reviewed relevant publications from VA researchers.

Categories -

Internet of Things: OMB Action Needed to Ensure Agencies Secure Their Networked Devices

What GAO Found The nation’s infrastructure relies on information systems to support its varied functions. This includes the networked Internet of Things (IoT) and operational technology (OT) devices that interact with the physical world, including in building maintenance systems and specialized equipment in hospitals and laboratories. Responsible federal agencies have issued guidance, best practices, and requirements to help agencies securely procure such devices. For example, the Office of Management and Budget (OMB) has issued requirements to ensure that agencies establish and maintain inventories of their networked devices and process IoT cybersecurity waivers. However, most agencies have not fully addressed OMB’s networked device requirements, which were established in December 2023 and updated in January 2025. Specifically, agencies’ initial inventories were required to be completed by September 2024. However, as of September 2026, of the 22 civilian Chief Financial Officer (CFO) Act agencies in GAO’s review, 15 had established an inventory, 11 were maintaining their inventories, and 10 had included all required information (such as asset description and software version) for each device. Overall, only seven agencies had fully addressed all three of OMB’s requirements. Further, no agencies had reported an IoT cybersecurity waiver. Status of 22 Agency Networked Device Inventories, as of September 2026 Agencies cited a variety of reasons for not having completed or maintained inventories with required information, including technical and resource constraints and competing priorities. However, OMB has yet to issue updated guidance to agencies that covers fiscal year 2026, leaving agencies without a clear imperative to prioritize implementation of the requirements and a timeline for doing so. Until OMB issues this guidance, agencies will lack appropriate direction on how and when to complete their device inventories. In the absence of inventories, agencies may lack awareness of the number and type of connected devices in their systems and be at risk of not protecting those systems from cyberattacks. Further, without updated guidance and oversight of agencies’ implementation of inventory requirements, agencies may continue to struggle to apply appropriate security controls to vulnerable systems—potentially compromising highly sensitive data and systems. Why GAO Did This Study Networked technologies and devices are facing increasing cyber threats from around the globe. For example, in July 2026, cyber threat actors disrupted operations in the water sector by modifying passwords to disconnect networked programmable logic controllers, which are a type of OT. Moreover, emerging technologies such as artificial intelligence can compound risks faced by these technologies and devices. The IoT Cybersecurity Improvement Act of 2020 includes provisions for OMB and civilian CFO Act agencies to identify and protect networked devices. The act also includes provisions for GAO to report every 2 years on IoT guidance and the waiver process through 2026. This final report in a series of three (1) describes guidance and best practices for procuring secure networked devices; and (2) evaluates agencies’ progress in addressing networked device cybersecurity. GAO identified federal agencies with cybersecurity or acquisition responsibilities and described guidance and best practices developed by those agencies for procuring secure networked devices. GAO compared 22 civilian CFO Act agencies’ inventory implementation efforts to OMB’s requirements. GAO also interviewed relevant agency officials to obtain their views and verify the information provided.

Categories -

Foreign Assistance: Agencies Made Broad Changes, but State Lacked Guidance for Decisions

What GAO Found In response to multiple executive orders issued beginning in January 2025, selected agencies have made changes, some significant, to their foreign assistance programming and staffing. Eight of the nine agencies included in GAO’s review decreased funding (e.g., obligations) for foreign assistance awards. One agency did not decrease the number of awards but has been unable to disburse funds to awardees since January 2025. Most notably, the U.S. Agency for International Development (USAID) terminated approximately 6,780 of 7,510 awards between January 2025 and March 2026, according to State data. The value of obligations of the terminated awards from their beginning until March 2026 was $79.1 billion. The remaining active awards, now managed by State, represented about $52.1 billion as of March 2026. The Europe and Eurasia region had the highest dollar value of terminated awards but still has the highest dollar value of remaining active USAID awards. (see figure) State announced that USAID ceased administering foreign assistance awards as of July 1, 2025. Value of USAID Terminated and Active Awards by Region, March 2026 Note: Funding represents cumulative obligations from 2015 through March 2026 or the award termination date. All nine agencies decreased staff, including both headquarters and overseas personnel, from January 2025 up to May 2026. The most significant change occurred at USAID which decreased from about 13,600 staff worldwide in January 2025 to 241 staff in April 2026, according to USAID and government-wide data. State is now the primary provider of foreign assistance, but the full range of its workforce reductions is unknown because State was unable to produce data on its staffing levels during the eleven months that GAO requested it. Without readily available staffing data, State cannot effectively plan for operational requirements, respond to risks posed by its staffing changes, or address oversight needs. State also could not provide evidence of its guidance to staff including standards for making foreign assistance changes. Without documented guidance, officials responsible for foreign assistance programming may make inconsistent, ad hoc, or inefficient decisions that could waste taxpayer money. For example, State officials may make incorrect assumptions about desired program changes that could lead to legal dispute or the retraction of terminated awards. Why GAO Did This Study The U.S. government uses foreign assistance to aid strategically important countries, countries in conflict, and populations in need. In January 2025, the President issued an executive order pausing U.S. foreign development assistance programs to assess them for programmatic efficiencies and consistency with U.S. foreign policy. Subsequent orders led to decreases in staff and reorganizations at agencies that carry out foreign assistance programming. GAO examined changes to foreign assistance programming and staffing in nine selected agencies from January 2025 up to May 2026, and the extent to which these agencies developed and documented processes to inform their foreign assistance reviews. GAO selected nine agencies, including State and USAID, based on agencies identified within appropriations legislation for the Department of State, foreign operations, and related programs, as well as agencies impacted by certain executive orders. GAO reviewed data, documents, and guidance from agencies and interviewed agency officials regarding their foreign assistance programming, funding, and staffing, as well as processes for decision-making.

Categories -

Disaster Assistance: FEMA Actions Needed to Better Support People with Disabilities in Disasters

What GAO Found The Federal Emergency Management Agency (FEMA) has made guidance, grants, and specialized staff available to state and local governments and other organizations that support disaster survivors, including people with disabilities. FEMA has some guidance for state and local partners on incorporating the needs of people with disabilities into disaster planning and response. FEMA has also offered training for its partners on including people with disabilities in disaster operations but removed this training from its curriculum in 2025 to ensure compliance with various Executive Orders, according to officials. It has now been over a year since the training was offered. Without this training, FEMA’s state and local partners risk not being able to effectively assist people with disabilities. FEMA also has regional staff who can coordinate with state and local partners to support people with disabilities, which state and local officials said was beneficial. However, this coordination has been inconsistent across regions, and this role is not standardized. Clearly documenting a responsibility for disability specialists to coordinate with state and local partners would help ensure equitable access to assistance for people with disabilities when a disaster happens. FEMA also makes information, grants, and staff support directly available to survivors with disabilities. For example: FEMA publishes disaster planning and recovery guidance for people with disabilities and caregivers on its website. FEMA’s individual assistance grants can provide financial assistance to replace assistive devices and medically required equipment, among other things. FEMA provides specialized services to help people with disabilities apply for grants, such as providing sign language interpretation via video. It also has staff who investigate complaints of discrimination based on disability. However, some people with disabilities may face obstacles when applying for grant assistance, according to stakeholders GAO interviewed. These obstacles include unclear application questions and eligibility letters written at a grade 12 reading level. FEMA has not solicited feedback from people with disabilities on its overall grant application process, limiting its ability to ensure accessibility. Being able to more easily navigate the application process could help ensure people with disabilities receive assistance after a disaster. GAO’s analysis shows that 4 percentage points fewer applicants with disabilities were approved than those without disabilities from 2022 through 2025. FEMA Disaster Assistance Applications Received and Approved in 2022–2025 Why GAO Did This Study People with disabilities are far more likely than people without disabilities to face hardship due to a major disaster, according to the National Council on Disability. FEMA plays a role in helping state and local governments, nonprofits, and others support survivors after a disaster. It also provides grants to states to help rebuild infrastructure and financial assistance to disaster survivors. The Think Differently About Emergencies Act included a provision for GAO to review the assistance FEMA provides to help people with disabilities. This report examines the extent to which FEMA (1) works with state and local governments and others to support people with disabilities in disasters and (2) directly helps people with disabilities and their families. GAO analyzed data from 2022 through 2025 on FEMA’s grants to disaster survivors and reviewed relevant federal laws and agency policy. GAO also interviewed FEMA officials; officials at organizations that support people with disabilities; and state and local officials and organizations in Hawaii, Louisiana, and Kentucky, which experienced different types of disasters in separate FEMA regions from 2023 through 2025.

Categories -

Combatting Illicit Drugs: DOJ and DHS Must Resolve Uncertainties Around Collaboration to Ensure Effective Counternarcotics Investigations

What GAO Found The Drug Enforcement Administration (DEA) and U.S. Immigration and Customs Enforcement (ICE) have entered into longstanding formal agreements to enhance their collaboration on counternarcotics investigations, including a June 2009 interagency cooperation agreement and a January 2021 joint letter. These agreements describe how DEA and ICE’s Homeland Security Investigations (HSI) are to coordinate on investigations. They establish requirements for DEA to cross-designate (or allow) HSI special agents to engage in counternarcotics investigations under the Controlled Substances Act and for both agencies to deconflict case information and engage in joint training, among other things. More recently, GAO found that the Department of Justice (DOJ) issued two new documents since 2021 that relate to DEA and HSI collaboration on counternarcotics investigations—a January 2025 DOJ Office of Legal Counsel opinion and a May 2026 memorandum from the Acting Attorney General. DOJ Documents Issued Since 2021 Related to DEA and ICE Collaboration Prior to the issuance of the May 2026 memorandum, GAO found that DEA and ICE’s collaboration generally addressed four out of eight leading collaboration practices, including defining common outcomes and clarifying roles and responsibilities. The four leading practices that DEA and ICE had not fully addressed (ensuring accountability, sustaining leadership, bridging organizational cultures, and updating agreements) involve activities required by the agreements. For example, DEA and ICE never fully sustained a functioning Headquarters Review Team, nor had they fully implemented joint training, which were required by the 2009 and 2021 agreements respectively to address collaboration challenges. As of June 2026, DOJ officials told GAO they were still determining how the May 2026 memorandum will impact existing requirements in the 2009 and 2021 collaboration agreements, including establishing the Headquarters Review Team and implementing the joint training. By clarifying the status of the requirements within DEA and ICE’s agreements, DOJ and DHS would provide DEA and ICE the necessary direction about the activities they should conduct to ensure effective collaboration on counternarcotics investigations. Why GAO Did This Study The U.S. faces multiple challenges related to illicit drugs, including the opioid epidemic, which has been a national public health emergency since October 2017. To combat this crisis, the federal government has tasked DEA with leading U.S. efforts against illicit drug trafficking. In this role, DEA works with ICE’s HSI, within the Department of Homeland Security (DHS), to investigate illicit drug activity with a connection to U.S. borders. GAO was asked to examine how DEA and ICE coordinate on counternarcotics investigations. This report addresses (1) new DOJ and DHS documents since 2021 that address how DEA and ICE collaborate and (2) the extent to which DEA and ICE agreements and activities related to counternarcotics investigations have been aligned with leading practices for collaboration. To do this work, GAO analyzed DEA and HSI agreements and policies and interviewed relevant headquarters officials. GAO also conducted site visits with a nongeneralizable sample of nine DEA and HSI field offices to interview staff about their collaboration experiences. GAO selected this sample to reflect a variety of geographic regions and quantities of DEA and HSI drug seizures over an 8 ½ -year period. GAO also compared DEA and ICE’s collaboration activities against leading interagency collaboration practices and DOJ legal requirements.

Categories -

Child Labor: DOL Action Needed to Better Protect Working Children

What GAO Found An estimated 2.8 million children worked in the U.S. in 2023, according to GAO’s analysis. The Department of Labor (DOL) publishes statistical data that provide information on working children’s fatalities, injuries, and illnesses. These data are used to develop workplace safety strategies and policies, but data limitations and discontinued data sets have contributed to information gaps. For example: In DOL’s dataset on workplace fatalities, some data on the cause of death or industry in which the child worked are not publicly available. DOL changed how it collects data on working children’s injuries and illnesses, so data since 2021 cannot be compared to earlier years. Between 2015 and 2023, one DOL survey and two other federal datasets that contained child labor injury data ended. By mitigating child labor data gaps, DOL would be better positioned to identify and respond to dangerous working conditions for children. Since fiscal year 2015, the number of annual child labor violations that DOL cited and the number of children affected by their employers’ violations has generally increased, according to GAO’s analysis (see figure). Examples of violations include children working later than allowed or doing hazardous work such as operating meat processing machines. Cited Child Labor Violations and Children Affected, Fiscal Years 2015−2025 DOL recently launched an initiative to enhance its enforcement of child labor laws, but it faces some challenges. For example: DOL regional and district officials expressed concern with the data DOL recommended for targeting egregious child labor violations, including that the data were not detailed enough to provide useful investigation leads. DOL does not have a process to identify and evaluate additional data sources. DOL officials described persistent knowledge gaps among employers and the public on child labor laws. DOL implemented a communications strategy to raise awareness, but taking steps to measure and assess its outreach would help DOL understand whether its efforts are achieving its goals. In 2023 and 2024, DOL’s interagency collaboration on child labor did not fully follow leading collaboration practices, according to GAO’s analysis. Although DOL works with other agencies to protect children, it discontinued its interagency task force in 2025. Strengthening future collaboration and ensuring key information is shared could enhance DOL’s efforts to protect working children. Why GAO Did This Study The Fair Labor Standards Act of 1938 included provisions to protect the safety and health of working children under 18. Almost 90 years later, DOL continues to find numerous child labor law violations. GAO was asked to review child labor data and enforcement. Among other things, this report addresses (1) information gaps in data about fatalities, injuries, and illnesses among working children; (2) trends in child labor violations; (3) recent changes DOL has made in its child labor enforcement practices, and how DOL has addressed related challenges; and (4) the extent to which DOL has collaborated with other federal agencies on child labor. GAO analyzed federal data on working children from 2023; child labor fatalities, injuries, and illnesses since 2013; and cited child labor violations from 2015 to 2025 (the most recent data available). GAO reviewed relevant federal laws, regulations, and agency documentation on enforcement and collaboration. To gather information on enforcement and challenges, GAO interviewed officials at DOL’s Wage and Hour Division, including at five regional and six district offices selected to capture a variety of enforcement experiences. GAO also analyzed information from DOL and seven other agencies on child labor collaboration.

Categories -

VA Health Care: Action Needed to Improve Fertility Care Communications and Eligibility Determination Process

What GAO Found Within the Department of Veterans Affairs (VA), the Veterans Health Administration (VHA) is responsible for providing enrolled veterans access to reproductive health care, including fertility care. From fiscal years 2022 through 2025, VHA data show that approximately 8 million veterans used some type of VHA health care. Around 30,000 veterans had an infertility diagnosis in fiscal year 2025, an increase from the approximately 19,000 veterans with an infertility diagnosis in fiscal year 2022. VHA officials said there may be several reasons for the increase, such as expansions VHA made to eligibility for fertility care in 2024. Number of Veterans with an Infertility Diagnosis, Fiscal Years 2022-2025 VHA’s Office of Women’s Health communicates about available fertility care through various methods, such as a fertility webpage and brochures. GAO found some interested veterans may be unaware of VHA’s fertility care. For example, stakeholders said male veterans may not seek out or may find it difficult to seek out eligibility information because it comes from Office of Women’s Health. GAO determined that VHA has not implemented key performance practices related to its communication. By implementing such practices, VHA could better assess progress towards its communication goals and increase the effectiveness of its outreach to veterans about fertility care. This would allow VHA to identify and make any needed adjustments to better ensure its efforts reach veterans who may need fertility care. VHA changed its process for determining veterans’ eligibility for fertility care in October 2024. Under the change, VA medical center fertility teams are responsible for making these decisions instead of VHA at the national level. However, GAO identified challenges with the process after October 2024. For example, GAO found fertility team composition and skill level varied at selected facilities. VHA officials from these facilities said that it can be challenging to determine veterans’ eligibility, which can affect the care they receive. GAO also found that teams at two facilities did not consistently provide written notifications of eligibility decisions to veterans as required. Federal standards for internal control state that agencies are to identify, analyze, and respond to change as part of their risk assessment efforts. Assessing the changes it made to its eligibility determination process would allow VHA to determine whether the process is working as intended or whether adjustments are needed, in turn, ensuring it is best serving veterans. Why GAO Did This Study Infertility—the inability to conceive or sustain a pregnancy—can affect both men and women. Research suggests veterans may experience infertility for a variety of reasons including injuries in combat, environmental exposures, or trauma sustained during military service, which impacts treatment options. To be eligible to receive certain fertility care, such as in vitro fertilization, a veteran’s infertility must be causally related to a service-connected disability—an injury or illness incurred or aggravated during military service—or to the treatment of one. GAO was asked to review issues related to infertility among veterans. This report, among other objectives, describes (1) available data on infertility among veterans for fiscal years 2022 through 2025; examines (2) VHA’s efforts to provide information to veterans and providers about available fertility care; and (3) VHA’s eligibility determination process for fertility care. GAO reviewed VHA documentation and data for fiscal years 2022 through 2025; interviewed VHA officials, staff involved with fertility care at four VA medical centers, and four veterans integrated service networks (selected based on presence of fertility staff, geography, and facility complexity); and interviewed eight veterans, six veterans service organizations, and two national organizations (selected based on focus on infertility and national reach).

Categories -

Small Business Research Programs: Better Data Could Improve Insight into Companies’ Success

What GAO Found In fiscal year (FY) 2024, the most recent data available at the time of review, 11 federal agencies issued $4.4 billion in Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) awards, split almost equally between open and conventional topics. For open topics, agencies define broad areas of interest, and small businesses submit proposals defining potential agency needs and solutions. In contrast, for conventional topics, agencies define specific problems, and small businesses submit proposals that address those needs. One goal of SBIR and STTR is to increase commercialization of federally funded research and development (R&D), such as by selling to private industry or to federal agencies. To help achieve this goal, Congress began requiring the Department of Defense (DOD) to release open topic solicitations in FY 2023. Open Topic Awards in the Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) Programs, Fiscal Years 2019–2024 Incomplete data prevent agencies from evaluating commercialization outcomes for open and conventional topic awards. At specific milestones, small businesses are required to report to the Small Business Administration (SBA) on commercial activity resulting from past awards. SBA maintains this information in a statutorily required database. However, GAO’s review of FY 2019 through FY 2024 awards showed small businesses submitted required data for less than half of their prior awards. Not all agencies communicate reporting requirements to applicants or ensure that applicants submitted required reports. Better conveying requirements to small businesses and ensuring compliance with these requirements could improve the completeness of the commercialization database. Even if the share of companies submitting information increased, SBA officials said that they would not view the commercialization data as sufficiently reliable without validation and verification. They identified options to increase data reliability, such as incorporating information from other sources (like the Internal Revenue Service’s revenue data) or obtaining additional resources to validate the data. Statutory changes would be needed to change the commercialization data SBA collects. Reliable data would potentially enable SBA to provide decision makers with clearer insights into the different outcomes for open and conventional topic awards and the overall economic return on federal R&D. Why GAO Did This Study To help drive economic growth, 11 participating agencies provide SBIR and STTR funding to support small businesses that might otherwise face difficulties securing capital for R&D. SBA oversees the programs, including issuing guidance and reporting to Congress. In connection with requirements for DOD to release open topics, the SBIR and STTR Extension Act of 2022 included a provision for GAO to review open topics in the programs. This fourth report examines FY 2024 awards, how open and conventional topic awards differ in terms of small businesses’ commercialization outcomes, and other objectives. GAO analyzed data from the 11 participating agencies and SBA for over 6,000 awards issued in FY 2024. GAO examined SBA’s commercialization database for awards issued in FY 2019 through FY 2024. GAO reviewed statutory requirements and interviewed officials from SBA and participating agencies, as well as representatives from 20 randomly selected small businesses that received SBIR or STTR awards.

Categories -

DOGE: Congress and the Public Lack Assurance That Systems and Data Were Protected at Multiple Agencies

What GAO Found Four agencies in GAO’s review—the Consumer Financial Protection Bureau (CFPB), Department of Education, National Oceanic and Atmospheric Administration (NOAA), and Securities and Exchange Commission (SEC)—established Department of Government Efficiency (DOGE) teams and collectively reported that those teams had access to more than 23 systems. These systems were used to manage contracts, grants, human resources, and finances and contained sensitive information, including personally identifiable information (PII). However, whether DOGE team members had specific system permissions or were allowed certain actions (e.g., view PII or modify data) could not be determined based on the information provided. The other two agencies in GAO’s review—Small Business Administration (SBA) and the Department of Veterans Affairs (VA)—did not respond to requests for information to which systems DOGE team members had access to. CFPB, Education, and SEC provided limited documentation related to the extent to which they implemented controls for ensuring adherence to their IT security rules and their DOGE team members followed the rules. For example, CFPB demonstrated that six DOGE team members received a privacy briefing and four completed security training. Such training is important for ensuring that system users are aware of their responsibilities for addressing cyber and privacy risks. However, the bureau did not provide evidence that the remaining team members completed the necessary training. Education provided IT system rules of behavior documents signed by five of the six DOGE team members. Acknowledgment of these documents is key to holding system users accountable for not following IT security rules. However, the department did not respond to GAO’s repeated requests for the document signed by the remaining team member. SEC demonstrated that a background check was underway for one team member and had been conducted for another team member in 2017. These investigations are important for ensuring that system users can be trusted with sensitive information. However, the agency did not respond to GAO’s requests to confirm that the 2017 investigation was favorably adjudicated. In addition, NOAA, SBA, and VA did not respond to requests for information on whether they implemented controls for ensuring adherence to the IT security rules and their DOGE team members followed those rules. Without the ability to examine the requested information, Congress and the public lack assurance that the six reviewed agencies implemented controls needed to ensure DOGE team members appropriately secured information. GAO has ample statutory authority to both conduct this work and obtain the information in support of Congress. Despite this clear authority, the agencies did not respond to GAO’s requests for the information needed to fully answer the questions posed by members of Congress. Agencies cited various reasons for not fully responding to GAO’s requests, but their stated reasons do not alter or diminish GAO’s statutory right of access to this information. Why GAO Did This Study The United States DOGE Service (USDS) was created by executive order to maximize government efficiency by modernizing technology. The order also called for the heads of executive branch agencies to establish DOGE teams that work with USDS. GAO was asked to review efforts to ensure that agency DOGE teams appropriately protected the systems and information they accessed at multiple agencies. The objectives of this review were to (1) describe the systems to which the DOGE teams at six agencies had been provided access and (2) evaluate the extent to which these agencies implemented controls to ensure that the DOGE team followed the agency’s IT security rules and the DOGE team followed those rules. This report focuses on the following agencies: Education, VA, CFPB, NOAA, SEC, and SBA. GAO analyzed documentation related to DOGE access to agency systems, IT security rules, security and privacy training, and background investigations. GAO provided a draft of this report to the six agencies for review and comment. Education, NOAA, SBA, SEC, and VA stated that they did not have any comments. CFPB expressed concerns with the accuracy of the report. GAO stands by the accuracy of the facts presented in the report. For more information, contact Nick Marinos at marinosn@gao.gov.

Categories -

Coast Guard: Additional Action Needed to Address Marine Firefighting Challenges

What GAO Found Fires on vessels are among the most dangerous and challenging incidents to which firefighters can respond. Vessels may also carry hazardous cargo, like lithium-ion batteries, further complicating marine firefighting responses. According to U.S. Coast Guard data, there were 886 nearshore marine fires that occurred between 2015 and 2025. About one quarter (206) of these resulted in either death, injury, over $200,000 in damage, or a total loss of the vessel. The U.S. Coast Guard is the principal federal agency responsible for overseeing marine safety. For marine firefighting, the Coast Guard plays a coordinating role while land-based fire departments extinguish fires. Following a marine fire that resulted in two firefighter deaths in 2023, the Coast Guard established a task force to address various marine firefighting challenges. The task force has taken several steps to address them but gaps remain. Examples of Firefighting Challenges, Coast Guard Actions, and Gaps Designating consistent Coast Guard field personnel to lead coordination before marine fires occur, facilitating more hands-on training for firefighters on vessels, and establishing an information sharing mechanism would help ensure firefighters have the knowledge and skills necessary to safely and effectively extinguish vessel fires. Further, developing guidance on what warrants vessel response plan activation would help ensure resources are quickly mobilized and better ensure the safety of firefighters. The number of vessels that use alternative fuels continues to grow. However, legal limitations prevent the Coast Guard from requiring nontank vessels that use alternative fuels—such as ferries powered by lithium-ion batteries—to have vessel response plans related to hazardous substance discharges. These limitations predate the widespread use of alternative fuels. Having that authority would empower the Coast Guard to better ensure vessels and firefighters can quickly receive assistance in the event of a fire. Why GAO Did This Study The Coast Guard has issued regulations requiring certain vessels to have response plans that identify the resources that would respond to marine fires related to oil discharges. The National Defense Authorization Act for Fiscal Year 2026 includes a provision for GAO to review, among other things, the Coast Guard’s efforts related to marine firefighting. This report examines (1) how frequently nearshore marine fires occur and the characteristics of those fires and (2) what challenges exist in marine firefighting and how the Coast Guard is addressing them. GAO analyzed Coast Guard data for 2015 through 2025; reviewed Coast Guard guidance and investigative reports; and interviewed Coast Guard officials, fire chiefs based in seven Coast Guard sectors, and representatives from maritime and firefighting stakeholder associations.

Categories -

Cybersecurity Regulations: Industry Panelists Identify Duplication and Conflicts and Ways to Address Them

What GAO Found GAO convened a panel discussion to gather industry perspectives on potential duplication or conflict among federal cybersecurity regulations affecting selected critical infrastructure sectors. The industry participants identified multiple federal cybersecurity regulations within their sectors as duplicative or conflicting with other regulations (see figure below). In such cases, participants said it could be difficult to fully satisfy all reporting requirements while remediating cyber threats. Number of Duplicative or Conflicting Federal Cybersecurity Regulations Identified by Selected Industry Sector Representatives For example, participants in all three sectors noted that the Department of Homeland Security’s proposed rule for cyber incident reporting or the Securities and Exchange Commission’s cybersecurity disclosure rules were duplicative and in conflict with their own sector’s regulations. Participants also identified duplication or conflict in sector-specific cybersecurity reporting requirements. While participants in all three sectors noted that progress in harmonizing federal cybersecurity regulations has been made over the past year—such as federal agencies providing increased regulatory guidance for financial institutions—half the participants agreed that this progress was limited. Participants also identified several opportunities for harmonizing federal cybersecurity regulations, including those related to cybersecurity incident reporting. Participants stated that defining reporting timeframes and thresholds in consistent ways could streamline requirements and reduce duplication. Participants also stated that having a lead agency to coordinate and receive incident reports would increase collaboration between government agencies and industry. Why GAO Did This Study Nearly all the nation’s critical infrastructure is supported by computer-based information systems. Because this infrastructure is mostly owned by the private sector, having the public and private sectors work together to protect the information systems is vital. Cognizant federal agencies have issued numerous regulations to help protect health data and ensure smooth operation of financial systems, among other things. However, according to the Office of the National Cyber Director, when critical infrastructure sectors are subject to multiple cybersecurity regulations, it can lead to conflicting guidance, inconsistencies, increased compliance costs, and redundancies for regulated entities. GAO was asked to gather perspectives of industry participants on the progress that federal agencies are making to harmonize cybersecurity regulations. This report summarizes industry views from selected sectors on duplication or conflicts among federal cybersecurity regulations that affect critical infrastructure sectors. GAO convened a panel discussion on July 16, 2026. The panel included six representatives from different industry organizations within three critical infrastructure sectors that GAO’s prior work has identified as subject to a significant number of cybersecurity regulations: energy, financial services, and healthcare and public health. The representatives included chief and senior executives overseeing cybersecurity, medical, and industry operations, as well as regulatory affairs and legal specialists. For more information, contact David B. Hinchman at HinchmanD@gao.gov.

Categories -

Criminal Justice: Data on Noncitizen Incarcerations, Convictions, Removals, and Costs

What GAO Found The average number of noncitizens incarcerated by the Federal Bureau of Prisons (BOP) each year decreased 44 percent from fiscal year 2017 (approximately 36,300) through fiscal year 2024 (approximately 20,300). This includes noncitizens with lawful immigration status. During this time, noncitizens, as a proportion of all BOP-incarcerated individuals, also decreased. Immigration-related offenses accounted for more than half of the offenses for which BOP-incarcerated noncitizens were convicted; another 30 percent were drug-related. U.S. Immigration and Customs Enforcement removed approximately 84,800 (76 percent) of the 111,200 noncitizens who completed, at least one term of BOP incarceration from fiscal years 2017 through 2024, as of December 2025. Individuals Incarcerated by the Federal Bureau of Prisons by U.S. Citizenship Status, Fiscal Years 2017 – 2024 There are no reliable comprehensive data on all noncitizens incarcerated by states and localities. GAO analyzed data from the State Criminal Alien Assistance Program (SCAAP). SCAAP is a Department of Justice (DOJ) program that reimburses jurisdictions for a portion of the eligible costs attributable to incarcerating noncitizens who meet program requirements. Though SCAAP data represent only a portion of all noncitizens incarcerated by states and localities, it provides valuable insights. In state fiscal year 2022, there were a total of approximately 73,500 SCAAP-eligible incarcerations, a decrease of 43 percent from state fiscal year 2016 when there were approximately 128,000 such incarcerations. SCAAP-eligible noncitizens incarcerated by the five state prison systems with the greatest number of SCAAP-eligible incarcerations were convicted of various offenses, including sex crimes, homicide, and drug offenses. DOJ spent more than $9 billion incarcerating noncitizens from fiscal years 2016 through 2023 (the most recent cost information available at the time of our audit work). This includes approximately $8 billion for BOP’s incarceration of noncitizens from fiscal year 2016 through fiscal year 2023 and approximately $1.44 billion for SCAAP reimbursements to states and localities for incarcerations in state fiscal years 2016 through 2022. This does not reflect costs paid by state and localities that were not reimbursed by the federal government. Why GAO Did This Study Depending on the nature of the offense, noncitizens who are arrested and convicted of crimes may be incarcerated by federal, state, or local authorities. These entities each bear the costs of incarcerating them. Following their incarceration, noncitizens may be subject to removal from the U.S. Since 2005, GAO has periodically reported available information on noncitizens incarcerated in the U.S. GAO was asked to update its body of work on this topic (including, GAO-18-433). This report addresses, among other things, the number and citizenship of noncitizens incarcerated in the U.S., and the cost of incarcerating them. Noncitizens, in the context of this report, refers to all individuals who are not U.S. citizens, regardless of their immigration status. GAO analyzed data separately for noncitizens incarcerated by BOP and for SCAAP-eligible noncitizens incarcerated by states and localities. GAO analyzed the most recent data available for each group at the time of our audit work. Generally, analyses of BOP-incarcerated noncitizens span fiscal years 2017 through 2024; analyses of SCAAP-eligible noncitizens incarcerated by states and localities span state fiscal years 2016 through 2022. To calculate the costs of incarcerating noncitizens, GAO analyzed BOP data and information on the annual per person cost of incarcerating an individual in various types of BOP facilities. GAO also analyzed data from the Bureau of Justice Assistance and information collected directly from selected states and localities. For more information, contact Gretta L. Goodwin at GoodwinG@gao.gov.

Categories -

Firearms Trafficking to Mexico: Better Data and Performance Monitoring Would Help Agencies Direct Resources to Counter Cartels

What GAO Found Transnational criminal organizations (TCO) in Mexico seek to acquire semi-automatic firearms—AR-15s, AK-47s, and .50-caliber rifles—which they often convert to fully automatic firearms, according to agency officials. Armed with these weapons, TCOs pose a serious threat to Mexican law enforcement and military. TCOs acquire firearms from the U.S. primarily through straw purchasers—third parties who buy them on the TCOs’ behalf—and middlemen who smuggle the firearms through ports of entry on the border. U.S. agencies collect data on trafficked firearms, but some data have limitations that limit their utility. The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) reported that 68 percent (82,785) of firearms recovered in Mexico and traced from January 2020 to December 2024 had a U.S. source. Department of Homeland Security (DHS) U.S. Customs and Border Protection (CBP) data show that CBP seized 4,944 firearms bound for Mexico at land ports of entry on the border from January 2020 through December 2025. However, CBP’s data system does not consistently capture information on the semi-automatic rifles sought by TCOs, and some officers may have difficulty identifying specific types. Improved data on these types of rifles would strengthen federal agencies’ ability to generate intelligence to combat firearms trafficking from the U.S. to Mexico. U.S. agencies conduct various efforts to combat firearms trafficking but do not assess effectiveness. For example, in the U.S., CBP conducts targeted outbound inspections along the U.S.–Mexican border and DHS’s Homeland Security Investigations and ATF seek to disrupt firearms trafficking along the border. In Mexico, ATF helps Mexican authorities conduct investigations and trace firearms. The Department of State’s Bureau of International Narcotics and Law Enforcement Affairs (INL) provides security assistance to Mexican authorities to combat firearms trafficking. In fiscal years 2020–2025, ATF and INL provided about $126 million for these efforts. But DHS has not established goals, desired outcomes, or performance measures that include baselines and targets for its efforts. ATF also lacks performance measures, after discontinuing measures it established in fiscal year 2023, and INL lacks baselines, targets, and results for some of its measures. As a result, the agencies do not know the extent to which their efforts are meeting objectives and cannot determine whether they are directing resources to the most effective programs. This could lead to waste and, potentially, missed opportunities to more effectively counter firearms trafficking. Vehicle Inspected, Hidden Compartment, and Firearms Seized at U.S.–Mexican Border Why GAO Did This Study Estimates indicate that hundreds of thousands of firearms are trafficked from the U.S. into Mexico each year, presenting a serious threat to Mexican and U.S. security. TCOs in Mexico use increasingly deadly firearms as well as technology and drones. In February 2025, State designated six Mexican cartels as foreign terrorist organizations and as specially designated global terrorists. GAO was asked to review U.S. efforts to combat firearms trafficking to Mexico. This report examines (1) the types of firearms TCOs in Mexico seek in the U.S. and the methods they use to illegally acquire and transport them into Mexico; (2) data U.S. agencies have collected on Mexico-bound firearms seized in the U.S. and on U.S.-sourced firearms recovered in Mexico, as well as the agencies’ uses of these data; and (3) efforts that U.S. agencies have made to combat firearms trafficking to Mexico, as well as the extent to which they have monitored these efforts’ performance. GAO reviewed agency documents and interviewed U.S. officials in Washington, D.C.; El Paso, Dallas, and Houston, Texas; and Nogales, Tucson, and Phoenix, Arizona. GAO also interviewed U.S. and Mexican officials at the U.S. embassy in Mexico City. GAO analyzed CBP data on seizures of southbound firearms at the U.S.–Mexican border in 2020–2025 as well as ATF data on firearms recovered in Mexico and submitted to ATF for tracing in 2020–2024.

Categories -

Nuclear Power: Actions Needed to Improve NRC’s Assessment of Its Workforce Needs

What GAO Found The U.S. Nuclear Regulatory Commission (NRC) has faced longstanding challenges in hiring and retaining adequate staff. NRC officials and most of the stakeholders GAO interviewed stated that increased attrition and industry competition have affected NRC’s workforce more in recent years. GAO found that from July 2024 through June 2026, NRC lost, on net, about 500 staff in various positions, most of which were due to voluntary retirements. This loss of staff has increased concerns about the stability of NRC’s workforce. Total Number of NRC Employees from July 2024 Through June 2026 In July 2024, the Accelerating Deployment of Versatile, Advanced Nuclear for Clean Energy Act of 2024 (ADVANCE Act), was enacted, granting NRC three enhanced authorities to support its workforce: (1) direct hire, (2) compensation flexibility, and (3) bonuses for hiring and performance. Between July 2024 and July 2026, NRC used the authority to award a total of $335,000 in performance bonuses to 18 staff but had not used the other two authorities. NRC officials cited various reasons for not using all of the authorities, including a recently completed agency reorganization and the need to conduct a comprehensive workforce evaluation and inventory to identify current workforce, project critical staffing needs, and forecast agency performance using its new strategic workforce planning tool. According to officials, the results can clarify the agency’s current and future workforce needs to effectively carry out licensing and oversight activities. However, NRC’s time frame for finalizing the tool has been delayed multiple times and is now planned for the first quarter of fiscal year 2027. Until it is finalized, NRC may not be able to effectively conduct strategic workforce management and planning to best use the ADVANCE Act authorities to enhance its workforce going forward. NRC officials and most of the stakeholders GAO interviewed agreed that the ADVANCE Act authorities offer NRC additional flexibilities to better meet agency needs in the future. However, they were unsure if these authorities are enough to fully address NRC’s significant workforce challenges and gaps. As of July 2026, NRC had developed a plan to use the authorities but had not established metrics to measure or assess the effectiveness of the ADVANCE Act authorities in supporting hiring and retention. Doing so could provide NRC with data to evaluate whether its workforce authorities adequately address its identified workforce needs. Why GAO Did This Study NRC is responsible for regulating civilian use of nuclear materials in the U.S., carrying out licensing activities, and conducting inspections and oversight. Policymakers’ interest in strengthening U.S. nuclear energy capacity has increased in recent years. In addition, NRC anticipates an increase in applications for new nuclear reactor licenses. In section 502 of the ADVANCE Act of 2024, Congress granted NRC additional authorities to enhance its recruitment and retention of specialized staff. The act also included a provision for GAO to evaluate the extent to which NRC has used the workforce authorities. This report examines the extent to which NRC has used the ADVANCE Act authorities and describes challenges NRC officials and stakeholders identified related to NRC’s workforce. GAO reviewed the ADVANCE Act, other relevant laws, policy, and agency documents; analyzed agency workforce data; and interviewed NRC officials and representatives from a nongeneralizable sample of 10 nuclear industry and policy organizations.

Categories -

Nonimmigrant Visas: State Should Consistently Conduct Global Staffing Needs Assessments to Help Balance Workloads and Address Long Wait Times

What GAO Found Visitor visa adjudications, which account for most nonimmigrant visas (NIV), have surpassed pre-COVID numbers. The Department of State adjudicated 9.2 million visitor visas pre-COVID in fiscal year (FY) 2019. That number dropped to 1.5 million in FY 2021. By FY 2025, the number of adjudications surpassed pre-pandemic levels, reaching 11.7 million. The average wait time to obtain an interview for a visitor visa was almost 8 times higher than before the pandemic, increasing from 26 days in FY 2019 to 201 days in FY 2025. In addition, the number of consular officers working on NIVs almost recovered from a COVID-era low of 1,104 in FY 2021 to pre-pandemic levels in FY 2024, reaching 1,342, but dropped to 904 in FY 2025 due to hiring freezes and attrition. State officials in Brazil, China, India, and Mexico—the countries GAO selected for more in-depth analysis—identified low staffing levels relative to demand for visitor visas as the main factor, among others, contributing to wait times to obtain an interview. According to data provided by State, wait times to obtain an interview in Mexico and India are longer than in China and Brazil, in part because they have fewer staff working on NIVs relative to the number of applications they receive (see table). Nonimmigrant Visa (NIV) Applications, CA Officers working on NIVs, NIV Applications per CA Officer, and Weighted Average Interview Wait Times to Obtain an Interview by Selected Countries, Fiscal Year 2025 Country NIV applications CA officers working on NIVs NIV applications per CA officer Weighted average wait times, in days Brazil 1,141,235 87 13,118 32 China 1,206,011 119 10,135 34 India 1,455,255 68 21,401 346 Mexico 2,658,627 124 21,441 283 Source: GAO analysis of Department of State data. | GAO-26-107902 Since FY 2019, State has conducted and implemented one Global Repositioning Exercise (GREX), which provides information used to bring consular staffing levels into alignment with workloads, according to State officials. Although the GREX is not required by policy, State officials said that the exercise is designed to be conducted annually. However, officials said they did not conduct the exercise in FY 2021 and FY 2022 because of issues related to COVID and in FY 2024 and FY 2025 because of changing policy priorities. Having a mechanism to require the exercise would help ensure State consistently and fully assesses workloads and NIV demand at posts and adequately addresses its staffing needs, particularly in years when significant changes are affecting workload. Why GAO Did This Study Millions of travelers to the U.S. apply for NIVs each year, which include visitor visas for tourism and business purposes, as well as visas for foreign students, diplomats, and temporary workers. According to the U.S. Travel Association, international travel and tourism contributed $176 billion to the U.S. economy in 2025. In adjudicating visas, State must balance speed and efficiency with national security concerns. One key issue that can affect efficiency is long wait times for an interview, which is required in most cases to obtain a visa. A House Committee on Appropriations report and the explanatory statement accompanying legislation that became the Further Consolidated Appropriations Act, 2024 includes a provision for GAO to examine the efficiency of consular operations, including visa processing times. This report examines (1) trends in the number of applications and adjudications for NIVs, associated wait times to obtain an interview, and staffing levels from FY 2019 through FY 2025; and (2) how staffing levels affect wait times and to what extent State determines posts’ staffing needs; among other objectives. GAO analyzed State’s data for NIVs and interviewed State officials in Washington, D.C. GAO also conducted interviews and discussion groups with consular officers and management in Brazil, China, India, and Mexico, the countries with the highest demand for NIVs in FY 2025.

Categories -

IT Systems Annual Assessment: DOD Should Improve IT Fraud Risk Management Practices

What GAO Found To meet its mission to protect the security of our nation and provide warfighters the assets they need, the Department of Defense (DOD) relies heavily on the use of information technology (IT). According to DOD’s Office of the Chief Information Officer (OCIO), the department planned to spend $10.3 billion on the 18 major IT business programs from fiscal years (FY) 2024 through 2026. The four largest programs account for 50 percent of the planned spending (see figure). The Department of Defense’s (DOD) Planned Costs for the Four Largest Information Technology (IT) Business Programs Compared to the Remaining 14 Selected Programs from Fiscal Year (FY) 2024 through FY 2026 To help determine whether operational programs are meeting their business or mission purpose, programs are required by the General Services Administration to identify and track a minimum of five performance metrics across the categories of customer satisfaction, strategic and business results, financial performance, and innovation. Of the 18 programs, 17 were operational. Of these, 15 identified the minimum required number of performance metrics in each category. However, the remaining two did not. Accordingly, the extent to which these two programs were improving customer satisfaction, increasing financial performance, and delivering innovative approaches is unknown. GAO has previously reported on DOD IT business programs not fully reporting performance metric data and made recommendations to the department to do so (see GAO-22-105330 and GAO-25-107649). Regarding achieving performance goals, of the 17 programs that identified metrics, six programs met all performance targets, 10 programs met more than one target but not all, and one program met no targets. The IT programs demonstrated mixed progress in implementing key practices for fraud risk awareness, software development, and key cybersecurity initiatives. Developing fraud risk awareness—particularly in staff who manage key IT programs—is an important step toward maturing DOD in fraud risk management. Of the 18 programs, seven programs reported via GAO’s questionnaire that program staff were either unaware of or did not receive training to recognize and report signs of fraud or tampering in IT systems (see table). In response, DOD officials indicated that the department does not currently require training to recognize and report signs of fraud in IT systems, rather that personnel receive mandatory, general fraud awareness training. While these broad efforts are important, programs’ reported lack of awareness of training to manage or report fraud can increase the risk of software development- and cybersecurity-related fraud within IT programs, making them vulnerable to exploitation. Department of Defense (DOD) Major Information Technology (IT) Business Programs Reporting Fraud Risk Awareness Fraud risk awareness practice Number of programs that reported practice Receiving training or knowing about available training over the past two years to recognize and report signs of fraud in IT systems 11 of 18 Assessing fraud risks facing the program 10 of 18 Source: GAO analysis of DOD program questionnaire responses as of April 2026. | GAO-26-108596 Further, 10 of the 18 DOD IT business programs reported actively developing software using recommended Agile and iterative software development approaches and practices. However, in areas related to tracking customer satisfaction and progress of software development, eight of the 10 programs did not report or demonstrate using required metrics and management tools. GAO previously recommended that DOD address this issue. Additionally, six of the 18 programs had not developed plans to implement zero trust in their cybersecurity frameworks by DOD’s 2027 deadline (see table). In addition, while five programs reported using artificial intelligence (AI) tools to secure their systems, three programs did not have an approved cybersecurity strategy. GAO has previously recommended that all programs develop one (see GAO-22-105330). Department of Defense (DOD) Major Information Technology (IT) Business Programs That Reported Having an Approved Cybersecurity Strategy or Implementing Zero Trust Architecture Development approach or practice Number of programs that reported using each approach or practice Having a DOD approved cybersecurity strategy 15 of 18 Implementing zero trust architecture as part of the security framework 12 of 18 Source: GAO analysis of DOD program questionnaire responses as of April 2026. | GAO-26-108596 DOD continues to make efforts to improve its management of IT investments as a result of legislative and policy changes. These efforts include revising its business systems investment management guidance, modernizing its business enterprise architecture, adopting a zero trust cybersecurity strategy, developing AI acquisition guidance, updating its agency strategic plan, and implementing cost efficiency initiatives. GAO will continue to monitor DOD’s efforts to improve how the department manages its IT investments. Why GAO Did This Study IT is critical to the success of DOD’s major business functions. These functions include such areas as health care, human capital, financial management, logistics, and contracting. The National Defense Authorization Act for FY 2019, as amended, includes a provision for GAO to conduct assessments of selected DOD IT programs annually through March 2029. GAO’s objectives for this seventh review were to (1) examine what progress selected DOD IT business programs have made on cost, schedule, and performance; (2) assess the extent to which DOD has implemented key fraud risk management, software development, and cybersecurity practices for selected programs; and (3) describe actions DOD has taken to implement legislative and policy changes that could affect its IT acquisitions. To address the first objective, GAO selected the 18 IT business programs listed as DOD’s major IT investments in its FY 2026 submission to the Federal IT Dashboard. GAO analyzed data from DOD’s OCIO to examine DOD’s planned expenditures for these programs from FY 2024 through FY 2026. GAO also administered a questionnaire to the 18 program offices to obtain and analyze information about cost and schedule changes that the programs reported experiencing since January 2024. Further, GAO compared programs’ performance metrics data provided by DOD’s OCIO to guidance from the Office of Management and Budget. To address the second objective, the questionnaire also sought information about the selected programs’ practices in fraud risk management, software development, and cybersecurity. GAO compared the responses and documentation against relevantguidance and leading practices to identify gaps and risks. For programs that did not demonstrate having documentation or strategies, GAO followed up with DOD officials for clarification. For the third objective, GAO reviewed and summarized (1) policy, plans, and guidance associated with the department’s efforts to implement changes to its defense business systems investment management guidance and business enterprise architecture and (2) efforts to adopt zero trust cybersecurity principles, develop AI acquisition guidance, update its strategic plan, and implement cost efficiency initiatives. GAO also met with DOD OCIO officials to discuss their efforts in these areas.

Categories -

Acquisition Management: Opportunities Exist for GAO to Strengthen Its Policies and Procedures

What the OIG Found Proper contract administration is critical to ensure GAO complies with contract terms and conditions. In FY 2019, GAO entered into a blanket purchase agreement for commercial facility maintenance (the BPA), which it awarded under the General Services Administration (GSA) Schedule program. After subsequent modification, the BPA’s maximum value was about $119 million. Although the contractor submitted adjusted labor rates from a collective bargaining agreement, GAO did not modify the BPA and associated time-and-materials orders to reflect these higher rates before payment. As a result, the agency paid about $94,000 more than the previously negotiated rates during the second option year. GAO was unable to explain why the BPA and the associated orders were not modified prior to payment. The OIG also observed that GAO’s standard operating procedures for procurements did not provide clear guidance on evaluating a contractor’s charges for indirect costs or profit on work performed by a subcontractor when the contractor adds no or only negligible value (excessive pass-through charges). The OIG also found that GAO could clarify its policies and procedures regarding the applicability of federal regulations for contracting by negotiation to GSA schedule procurements. The lack of clarity could result in procurement staff taking unnecessary steps. The agency indicated it had updated its procedures regarding subcontracting and was in the process of updating its policies for GSA schedule procurements. By enhancing its oversight of contract modifications and invoice approvals, GAO could ensure that payments are consistent with negotiated rates. Further, GAO’s updated policies and procedures regarding excessive pass-through charges and future updates to the applicable procurement processes when using the GSA schedule could strengthen GAO’s acquisition program and improve efficiencies for procurement staff. Why the OIG Did This Audit Careful contract administration, especially concerning invoice review and approval, is critical to ensure GAO pays the correct labor rates for time-and-materials orders. The OIG conducted this audit to assess time-and-materials orders issued under the BPA.

Categories -

Pages