What GAO Found
In 2014, the Financial Crimes Enforcement Network (FinCEN)—a federal agency that helps combat financial crimes—issued guidance on how financial institutions can serve cannabis-related businesses (CRB) while complying with Bank Secrecy Act (BSA) requirements. This guidance instructs institutions to gather thorough information on CRB customers and file suspicious activity reports for certain transactions involving CRBs. Federal banking regulators help oversee institutions’ compliance with these requirements through BSA examinations.
Financial institutions consider various factors when deciding whether to serve CRBs, according to GAO’s focus groups and interviews. Factors dissuading institutions from serving CRBs include potential legal and regulatory sanctions and the costs of complying with BSA requirements. Conversely, some institutions decide to serve CRBs to meet community needs or as a business opportunity.
According to FinCEN data, the number of financial institutions that reported providing services to CRBs increased from 2015 to 2019 and then remained relatively steady through 2024. FinCEN requires institutions to include specific terms when filing suspicious activity reports on transactions involving CRBs. FinCEN data indicate that about 1,000 banks and credit unions filed such reports in 2024. These data do not identify how many institutions accept CRBs as ongoing customers as institutions may not report or may not know they are providing services to CRBs, or they may report providing services to a CRB in an occasional transaction but not accept CRBs as ongoing customers. In addition, some institutions filing these reports may only serve ancillary businesses, not plant-touching businesses that directly grow, manufacture, or sell cannabis.
FinCEN Analysis of Numbers of Banks and Credit Unions Filing Selected Suspicious Activity Reports, Fiscal Years 2015–2024
Obtaining and maintaining financial services remain difficult for CRBs, according to CRB owners and managers. For example, CRBs may experience bank account closures, high fees for bank accounts, and high interest rates for business loans. Further, accepting customer payments is difficult largely because two major credit card companies prohibit cannabis purchases. In addition, CRB owners and managers reported that they and their employees face challenges accessing personal financial services due to their work in the cannabis industry.
Why GAO Did This Study
CRBs include state-licensed businesses that grow, manufacture, or sell cannabis products (plant-touching businesses), as well as businesses that support those operations, such as suppliers of growing equipment or providers of legal services (ancillary businesses). Financial institutions may be reluctant to serve CRBs because, with certain exceptions, cannabis is a controlled substance under federal law. As a result, serving these businesses poses legal risks and triggers ongoing BSA compliance obligations.
GAO was asked to review issues related to financial institutions serving CRBs. This report examines (1) the guidance and oversight federal agencies provide to financial institutions on serving state-sanctioned CRBs, (2) factors that affect financial institutions’ decisions about serving CRBs, and (3) challenges CRBs and their employees face in accessing financial services.
GAO reviewed relevant agency guidance and documents, obtained FinCEN’s analysis of data on suspicious activity reports for CRB-related transactions filed from 2015 through 2024, and reviewed literature on CRBs’ access to banking. GAO also conducted nine focus groups and 11 interviews involving a total of 74 financial institutions (selected to represent different asset sizes, institution types, and policies on serving CRBs). Participants were the BSA officer or cannabis banking program manager for each institution. GAO also conducted eight focus groups with owners and managers from 51 CRBs (selected to represent different business sizes and types). Finally, GAO interviewed agency officials, financial and cannabis industry associations, and other interest groups (selected for their expertise or public comments on banking CRBs).
For more information, contact Courtney LaFountain at lafountainc@gao.gov.
What GAO Found
The Department of Homeland Security’s (DHS) Cybersecurity and Infrastructure Security Agency (CISA) is the sector risk management agency (SRMA) for the U.S. chemical sector, responsible for implementing programs to assist facility owners and operators in identifying and mitigating security risks. In 2007, DHS established a regulatory program to mitigate security risks for high-risk chemical facilities. As part of this program, CISA required facilities to vet their personnel and certain unescorted visitors for terrorist ties against the U.S. government’s terrorist watchlist. Vetting against the U.S. terrorist watchlist is an inherently governmental function that the private sector cannot perform on its own; therefore, CISA set up a process with options facilities could use for such vetting. Authorization for the regulatory program lapsed in July 2023. The program, including personnel vetting, was discontinued. High-risk chemical facilities are now responsible for identifying and mitigating their own security risks.
According to CISA officials and selected private sector stakeholders GAO interviewed, losing access to the terrorist vetting process is the most significant challenge high-risk facility owners and operators have faced since the discontinuation of CISA’s regulatory program and it has left a gap in chemical facility security that poses substantial risks. The statutory authority that establishes SRMA responsibilities specifies that SRMAs are to implement security programs to assist stakeholders in identifying and mitigating risks to their assets and systems. As of May 2026, CISA said it was exploring whether the agency’s SRMA authority could be used to set up a vetting process. Without federal options for the terrorist vetting of personnel, facility owners and operators lack a critical tool to protect their facilities from an insider terrorist attack and from potential disruptions to critical national supply chains.
From fiscal years 2024 to 2025, the number of CISA active personnel dedicated to chemical sector activities declined from 214 (96 percent of authorized positions) to 52 (25 percent of authorized positions). The active personnel did not include full-time personnel scheduled to separate from CISA by the end of calendar year 2025 through deferred resignations programs. CISA said the reductions have necessitated reducing or eliminating services, such as most on-site facility assessments, but also said the agency continues to offer other services, such as security training and cybersecurity guidance. Selected private sector stakeholders told GAO that CISA’s personnel reductions and the loss of experienced staff have reduced their contact with CISA regarding facility security vulnerabilities.
Chemical Facility Warehouse and Operations
Why GAO Did This Study
According to DHS, as of 2025, more than 89 million people lived or worked within 2 miles of a U.S. facility using high-risk chemicals. DHS estimates that should high-risk chemicals be weaponized, it could cause significant harm to surrounding populations, from fatalities within the facility to the equivalent impact of a nuclear explosion.
GAO was asked to examine DHS’s efforts to mitigate security risks to the U.S. chemical sector. This report addresses, among other issues, CISA and sector stakeholder assessments of sector security following the discontinuation of a facility regulatory program, effects of the lack of a federal terrorist vetting process for chemical facility personnel, and effects of fiscal year 2025 reductions in CISA personnel on sector support services.
GAO reviewed relevant statutes, CISA guidelines and procedures, and CISA data on full-time authorized positions and active agency personnel for fiscal years 2024 and 2025. GAO interviewed CISA officials; conducted site visits to five chemical facilities; and interviewed private sector stakeholders, including representatives from the private sector coordinating council, three industry associations, and six chemical companies.
What GAO Found
In April 2025, GAO identified 13 priority recommendations for the Department of State. Since then, State has implemented six of those recommendations, and GAO removed the priority status from two recommendations.
In September 2026, GAO identified an additional four priority recommendations, bringing the total to nine. GAO is highlighting the following two areas that warrant timely and focused attention:
Managing fraud risks, and
Strengthening oversight of U.S. security assistance.
Addressing GAO’s recommendations in these areas would help determine whether Ukraine used direct budget support funding as intended and support Congressional oversight of U.S. security assistance. Taking action to implement all of GAO’s open priority recommendations would help enhance the efficiency and effectiveness of operations across State.
Why GAO Did This Study
Priority open recommendations are the GAO recommendations that warrant priority attention from heads of key departments or agencies because their implementation could save large amounts of money; improve congressional or executive branch decision-making on major issues; eliminate mismanagement, fraud, and abuse; or make progress toward addressing a high risk or duplication issue, among other benefits.
Since 2015, GAO has sent letters to selected agencies to highlight the importance of implementing such recommendations.
For more information, contact Kimberly Gianopoulos at gianopoulosk@gao.gov.
What GAO Found
During the rulemaking process, agencies are generally required to issue a notice of proposed rulemaking (NPRM) and seek public comment before issuing a final rule. They can expedite the process and forgo this requirement when they find good cause that the process would be impracticable, unnecessary, or contrary to the public interest. This can occur, for example, when agencies are responding to natural disasters or public health emergencies. Agencies cited good cause reasons for expedited rulemaking for about 71 percent of major interim final rules GAO reviewed and that agencies published between January 20, 2013, and January 20, 2025. This is consistent with GAO’s 2012 report, which found that 77 percent of major rules issued without an NPRM cited good cause for doing so.
GAO found that the use of expedited rulemaking increased during the peak of the COVID-19 pandemic in 2020 and 2021. There was little variation in use during non-pandemic years from January 20, 2013, through January 20, 2025, as agencies issued between two and 10 major rules without an NPRM per year. During the pandemic agencies expedited the issuance of 55 rules in response to COVID-19. Agencies cited good cause for 41 of these rules.
Number of COVID-19 and Non-COVID-19 Major Rules Reviewed Using Expedited Rulemaking, by Year, Jan. 20, 2013–Jan. 20, 2025
Agencies reported on the economic effects of 66 percent of the rules that GAO reviewed. COVID-19 related rules were less likely to include this information due to the emergency nature of the rules. Agencies requested public comments for 99 percent of the interim final rules that GAO reviewed and received comments on 94 percent of these rules. This is an increase from GAO’s 2012 report which found agencies requested comments for 63 percent of major rules issued without an NPRM.
Why GAO Did This Study
On average, agencies publish over 2,000 final regulations each year to achieve goals such as ensuring access to food and healthcare services and addressing national emergencies. The Administrative Procedure Act establishes the basic procedural requirements agencies generally must follow when issuing regulations, including providing the public with an opportunity to comment on proposed rules. Public participation can improve the quality of rules, ensure fair treatment, and promote accountability. However, providing for public participation might not be appropriate in every situation before issuing a final rule and agencies may find good cause that notice-and-comment procedures are impracticable, unnecessary, or contrary to the public interest.
GAO was asked to provide information on the frequency, reasons, and trends for agencies issuing final rules without an NPRM. This report addresses (1) how frequently agencies found good cause to issue rules without an NPRM; (2) the extent to which the effect of the COVID-19 pandemic led to changes in issuing rules without prior notice-and-comment; and (3) the extent to which agencies assessed the rules’ economic benefits, among other things.
GAO reviewed 116 major interim final and 12 direct final rules published between January 20, 2013, and January 20, 2025. GAO also reviewed associated documents for the rules, relevant laws, executive orders, and guidance related to waiving notice-and-comment, and agencies’ use of regulatory flexibility during the pandemic.
For more information, contact Lisa Van Arsdale at vanarsdalel@gao.gov.
What GAO Found
The Secret Service protects the President, Vice President, visiting foreign dignitaries, and others. From fiscal year 2015 through fiscal year 2025, the Secret Service’s budget increased while the number of its protectees fluctuated, particularly around changes in presidential administrations. During this time, there were 83 security incidents. The Secret Service updated its protection policies in response to 25 of them.
Secret Service Policy Changes in Response to Incidents, Fiscal Years 2015–2025
Secret Service policy does not require that personnel document their rationale when they determine an incident does not warrant a protection policy update. However, Secret Service officials told GAO that doing so would be important because it shows an incident was fully reviewed. In the absence of this information, it is sometimes unclear why the Secret Service maintained the status quo. For example, the Secret Service encountered drone incidents from 2015 to 2021, but did not update its policies to address civilian use of drones prior to July 2024, when a shooter used a drone in an assassination attempt of then-former President Trump. Revising its policy to require personnel to document the rationale for not making policy changes after incidents would provide the Secret Service with more complete information when considering protection policy updates to mitigate future threats.
Further, the Secret Service has not reviewed and updated protection policies in a timely manner. These policies are to be reviewed and updated within 4 years of issuance, but the Secret Service has not reviewed or updated eight of 22 protection policies within the required time frame. Secret Service officials said they try to make timely updates but are not always able to identify personnel available to do so. Revising its policy to assign responsibility to specific positions for updating protection policies within required time frames could help the Secret Service incorporate the most current techniques into advance planning.
Finally, since 1991, the Secret Service and Diplomatic Security Service, the protective division within the Department of State, have not updated a key memorandum of understanding that delineates the two entities’ roles and responsibilities for securing the President and others traveling abroad, and foreign dignitaries traveling to the United States. Much has changed over the intervening years, such as the emergence of drone threats, and updating the memorandum would provide the two entities an opportunity to respond to evolving roles, responsibilities, and advance techniques.
Why GAO Did This Study
Recent attacks and threats of violence against Secret Service protectees highlight the importance of the Secret Service’s protective mission. These incidents include the July 2024 assassination attempt of then-former President Trump, the alleged assassination attempt of President Trump at the April 2026 White House Correspondents’ Dinner, and the shooting near Vice President Vance’s motorcade in May 2026.
GAO was asked to examine the Secret Service’s protection policies. This report addresses, among other things, (1) how the Secret Service protection budget and number of protectees changed from fiscal year 2015 through fiscal year 2025; and (2) the extent to which the Secret Service has updated its protection policies.
GAO analyzed data and reviewed documentation related to protection policies for the Secret Service and Diplomatic Security Service from fiscal year 2015 through fiscal year 2025. GAO also conducted interviews with officials from the Secret Service and Diplomatic Security Service, as well as eight other selected federal, state, and local entities with protection responsibilities.
What GAO Found
The Department of Defense (DOD) has not recently met statutory requirements to review and report on the efficiency and effectiveness of its defense agencies and DOD field activities (DAFA). Between April 2023 and September 2024, DOD conducted a review of four DAFAs. However, the department did not finalize the reports based on its reviews or submit the reports to Congress as required. DOD did not have formalized guidance, such as an instruction, in place when conducting these four DAFA reviews. In May 2026, DOD issued a memorandum for future DAFA reviews that includes responsibilities and deadlines. While this is a positive step, DOD previously issued a memorandum for this effort that did not ensure the completion of the reviews. Formalizing guidance for the process would better position DOD to meet its reporting requirements and would provide Congress with better information to inform decision-making related to DOD’s efficiency and effectiveness.
Timeline of Defense Agency and DOD Field Activity Reviews Since 2018
DOD has not assessed the efficiency and effectiveness of its DAFAs, including the Defense Human Resources Agency (DHRA), because the department did not clearly define measures to be used for its most recent DAFA reviews. In its May 2026 memorandum, DOD included standard measures for efficiency and effectiveness, but the memorandum lacks detail on these measures. Moreover, the measures are not clearly defined or established in formalized guidance. Clearly defining how to assess efficiency and effectiveness in formalized guidance for the DAFA reviews would enable DOD to more comprehensively assess DHRA and the other DAFAs’ performance.
As part of its DAFA reviews, DOD is statutorily required to identify each activity of a DAFA that is substantially similar to, or duplicative of, an activity carried out by another organization within DOD. GAO found overlap in two training areas within the DAFAs: (1) the leader development programs at DHRA, the Defense Logistics Agency, and the Washington Headquarters Services; and (2) the sexual assault prevention and response training directed by DOD and developed by the military services. However, DOD has not assessed if there are negative effects on efficiency or effectiveness resulting from this overlap. If DOD were to evaluate these training programs, it may find opportunities to streamline them and reduce any inefficient overlap.
Why GAO Did This Study
DOD’s 27 DAFAs play a critical role in supporting the department’s business operations. For example, DHRA—which DOD renamed the Personnel Readiness Management Agency in June 2026—is a DOD field activity with a stated mission of enhancing the operational efficiency and effectiveness of diverse programs supporting DOD. DOD is required to conduct reviews of each DAFA’s efficiency and effectiveness at least once every 4 years.
The House report accompanying a bill for the Department of Defense Appropriations Act for fiscal year 2024 includes a provision for GAO to evaluate DOD’s DAFA reviews, with a focus on DHRA. This report examines the extent to which (1) DOD is reviewing and reporting on the DAFAs as required by law; (2) DOD has assessed the efficiency and effectiveness of DHRA as part of these reviews; and (3) DHRA provides training services that are duplicative, overlapping, or fragmented with other select DAFAs and the military services.
GAO reviewed DOD guidance, reports, and relevant statutory requirements and interviewed DOD officials.
What GAO Found
Congress and the Securities and Exchange Commission (SEC) require public companies to disclose information that investors would find important when making investment decisions. Disclosures include an annual audited financial statement and a description of risk factors and financial performance. Accounting firms that audit public companies must register with the nonprofit Public Company Accounting Oversight Board (PCAOB), which Congress created in 2002 to focus on audit quality. Certain auditor responsibilities—such as evaluating a company’s accounting estimates and ability to continue as a going concern—can be particularly challenging in bank audits, according to PCAOB staff, auditors, and others.
SEC is required by law to review public companies’ disclosures. However, 11 public banks—including two with more than $80 billion in assets—are not subject to SEC review because they operate without a corporate parent known as a bank holding company. (Two of the three banks that failed in spring 2023 operated without a holding company. Shareholders lost more than $29 billion in investments in these two banks between the end of 2022 and May 2023.) For those banks, Congress charged banking regulators with certain functions and duties of SEC. However, GAO found that banking regulators’ review processes, unlike SEC’s, do not assess disclosures for investors’ benefit. Reassessing disclosure review authority could help Congress determine whether changes are needed to strengthen investor protection.
Comparison of Federal Regulators’ Processes for Annual Disclosure Reviews
Note: Annual disclosures include details on a company’s business, its risks, and operating and financial results.
GAO reviewed 2021 and 2022 disclosures for the three banks that failed in spring 2023 to analyze the information they provided about interest rate and liquidity risks. GAO and banking regulators previously found that weak management of these risks contributed to the banks’ failures. Although each bank described setting thresholds for interest rate or liquidity risk, they did not disclose when thresholds were breached or how they addressed the breaches. SEC also identified other banks whose disclosures on these risk topics could be improved. However, SEC staff have not provided public guidance on how companies could assess whether breaches of interest rate or liquidity risk tolerances are material to investors. Such guidance could help companies assess the materiality of these details and may provide investors with the information they need to make informed decisions.
Why GAO Did This Study
The Securities Exchange Act of 1934 and federal regulations require public companies to provide investors with periodic disclosures about business risks and financial results. Three of the 30 largest U.S. banks failed in spring 2023, shortly after their financial statement audits were completed. Some observers raised questions about whether auditors had properly fulfilled their roles and whether the banks had clearly disclosed material information.
GAO was asked to review oversight of bank financial disclosures and external audits. Among other objectives, this report examines auditing standards relevant for bank audits; oversight of audit quality; SEC and banking regulators’ reviews of public companies’ annual disclosures; and the failed banks’ disclosures about selected risks before they failed.
GAO reviewed PCAOB auditing standards, SEC and banking regulators’ disclosure review processes, SEC public comments to bank holding companies, and the failed banks’ annual disclosures. GAO also interviewed staff from SEC, banking regulators, PCAOB, and accounting firms, among others.
What GAO Found
The Federal Aviation Administration (FAA) uses the National Simulator Program (NSP) to evaluate and oversee an increasing number of flight simulators. NSP’s oversight ensures that simulators accurately replicate the aircraft they simulate. From 1990 to 2025, the number of simulators increased by more than 500 percent, while the number of NSP staff remained steady. From 2019 through 2024, the number and type of simulator evaluations that NSP conducted remained relatively steady, as NSP implemented the Extended Evaluation Interval (EEI) program, among other strategies, to oversee the growing number of simulators. This program allows FAA to extend intervals between evaluations—from the standard 12 months up to 36 months—for simulators that demonstrate consistent, high-quality performance.
Trends in the Number of Simulators Under Federal Aviation Administration Oversight and National Simulator Program Staff, 1990–2025
However, GAO found that NSP has not communicated with simulator sponsors about its process for determining simulators’ eligibility for the EEI program and the intervals between evaluations of simulators in the program. Six of 10 selected sponsors raised concerns about communication, including insufficient opportunity to provide information that could help improve EEI determinations. For example, two sponsors cited potential safety issues that could result from extending the intervals between evaluations. Communicating with sponsors could help NSP make more informed decisions about eligibility and evaluation intervals, and identify and address risks associated with those determinations.
GAO found that NSP has identified staffing and skills gaps but has not addressed all mission-critical skills gaps, including in standards development. Developing and implementing a process to address all identified mission-critical skills gaps would help NSP ensure its staff has the requisite skills to keep pace with evolving technology while handling an increased oversight workload.
Why GAO Did This Study
NSP plays a critical role in aviation safety, as it oversees the flight simulators that airlines and flight schools use to train pilots to operate aircraft in a variety of situations.
The FAA Reauthorization Act of 2024 includes a provision for GAO to review FAA’s oversight of simulators. This report examines, among other objectives, how the number and type of simulator evaluations NSP conducts annually has changed in recent years, and how NSP has addressed increased demand; the extent to which NSP has communicated with sponsors in its process for making EEI program determinations; and the extent to which NSP has identified and addressed gaps in staffing levels and staff skill sets.
GAO reviewed FAA policies, guidance, and data, as well as relevant federal laws and regulations. GAO also interviewed FAA officials and simulator sponsors, such as major and regional airlines. For these interviews, GAO selected a nongeneralizable sample of 10 sponsors that own or operate over 62 percent of all flight simulators. In addition, GAO conducted two site visits to observe simulators managed by a flight simulator manufacturer and a flight training organization.
What GAO Found
The Federal Emergency Management Agency (FEMA) and the Army Corps of Engineers have key responsibilities for disaster response and recovery activities. Contracting with local businesses—those that reside or primarily do business in declared major disaster areas—is one way to fulfill their responsibilities. Both have policies and guidance to promote local vendor use, but they do not monitor associated data on this use. As a result, they do not know the extent to which they are using local vendors or helping jump-start the local economy.
Further, the contracting officers that GAO interviewed were not always aware of how to identify the local disaster area. Under federal regulations, a major disaster area is generally defined in the official presidential disaster declaration. However, some contracting officers identified the local area incorrectly or did not understand how to do so. For example:
FEMA. One contracting officer stated that they identified the entire state of Tennessee as the local area instead of staying within the declared disaster area in anticipation that other parts of the state might be added later.
Corps. One contracting officer responsible for four contracts for the Maui Wildfires stated that there was not an official way to identify a local area.
Example of a Contracting Officer Incorrectly Identifying the Local Disaster Area
The Corps has taken efforts to ensure that its contracting officers correctly identify the local area, but FEMA has yet to fully address the issue. For example, its three contracting officers who identified the local area incorrectly had received training on local vendor use. This indicates a need for additional action. Until FEMA takes additional steps to ensure that its contracting officers correctly identify the local area, it could miss opportunities to both award contracts to local vendors and help communities jump-start economic recovery after a disaster.
Additionally, all the selected Corps’s contracts were missing documents related to the use of local vendors. Federal regulations require contracting officers who award a post-disaster contract to a nonlocal vendor to document their justification in the contract file. Without these justifications, the Corps lacks assurance its contracting officers are making an effort to use local vendors as appropriate. Ensuring that contracting officers fully comply with federal regulations can provide the Corps with greater certainty that it is succeeding in its efforts to contract with local vendors and assist with the economic recovery of a local area.
Why GAO Did This Study
U.S. communities devastated by natural disasters often rely on federal aid for their recovery. To meet their disaster response and recovery responsibilities, FEMA and the Corps contract with businesses to obtain some of the goods and services needed for these recovery activities. Under federal law, they are required to provide a preference for contracting with businesses defined by regulation as local—relative to the declared disaster area—to the extent feasible and practicable. This preference may help jump-start the local economy.
The American Relief Act of 2025 includes a provision for GAO to conduct work related to certain natural disasters. GAO’s report assesses the extent to which (1) FEMA and the Corps promote and monitor the use of local vendors for disaster response, and (2) contracting officers followed requirements for local vendor use for selected contracts.
GAO selected three major disasters: Hurricane Helene, the Maui wildfires, and Hurricane Ian; collected, analyzed, and confirmed the reliability of relevant data; reviewed laws, regulations, policies, and guidance; interviewed agency officials and contracting officers; and assessed a nongeneralizable sample of contracts from the three selected disasters.
What GAO Found
In the first half of 2025, the President issued a series of executive orders directing federal agency heads—in consultation with the United States DOGE Service (also known as the Department of Government Efficiency) agency team leads—to review and terminate contracts in order to reduce federal spending, among other things.
In response, the Department of Homeland Security (DHS) conducted a department-wide review of over 17,000 contracts to assess their level of importance to the agency’s mission. This assessment resulted in DHS components completely or partially terminating contracts for cost savings. In addition, in March 2025, DHS began requiring approval by the Deputy Secretary for all contract terminations regardless of value and for awards of any contracts worth $25 million or more. The requirement for Deputy Secretary approval of contract terminations was rescinded in April 2026.
GAO analysis shows that from January 20, 2025, through September 30, 2025, DHS completely or partially terminated 438 contracts for convenience—meaning that termination of work under the contracts was determined to be in the federal government’s interest. DHS had obligated over $1.6 billion for these contracts prior to termination. Since these contracts were terminated, GAO analysis shows that DHS deobligated a net total of over $92 million on these contracts. These funds represent cost savings in that they reduce federal obligations and may be available for other purposes. However, if DHS should subsequently obligate additional funds to perform similar work associated with terminated contracts, the amount of cost savings or avoidance would be further diminshed.
DHS publicly reported on its website that its contract terminations over this time frame could allow the department to potentially avoid over $10.5 billion in costs. However, this overstates actual costs avoided for two reasons.
First, it represents the maximum that could be obligated on these contracts, not how much would have actually been obligated.
Second, if DHS continues to need the goods and services covered by those contracts and meets those needs through other contracts, then those costs would not be avoided but incurred through those contracts.
In fact, GAO found that 95 percent of DHS’s reported $10.5 billion in potential cost avoidance was attributable to 30 terminated indefinite delivery/indefinite-quantity contracts in place for DHS to meet information technology requirements. These contracts had a 10-year period of performance, from fiscal years 2025 through 2034. According to DHS, the agency obligated over $1.7 billion in fiscal year 2025 through existing government-wide contracts to meet those requirements. Thus, $1.7 billion in costs were not avoided but were incurred through other contracts. Additionally, any future obligations for the same requirements against the government-wide contracts in future years, through fiscal year 2034, would further reduce actual cost avoidance. As a result, DHS will not fully achieve the amount of reported potential cost avoidance.
Why GAO Did This Study
In early 2025, the President directed the heads of federal agencies to implement a series of initiatives to reform government operations, including reviewing federal contracts and grants for termination or modification to potentially save costs. To advance these initiatives, the President established the United States DOGE Service and directed agencies to establish DOGE teams to assist in carrying out administration priorities.
GAO was asked to review DHS and DOGE efforts to terminate contracts and grant awards and make reductions to its workforce in 2025. This report, the first in a series, provides information on DHS actions to review and terminate contracts from January through September 2025, and the number and value of contracts terminated.
GAO reviewed and analyzed documents such as executive orders directing federal agencies to review and terminate contracts and agency documents directing components on how to conduct these efforts. GAO analyzed federal procurement data to determine the number of contracts terminated by DHS and dollar amounts obligated or deobligated on those contracts. GAO also interviewed officials with DHS’s Offices of the Chief Procurement Officer and Chief Financial Officer about these efforts.
For more information, contact Chris Currie at CurrieC@gao.gov.
Recent comments