The Offices of Audit and Evaluation supervise and conduct independent and objective audits, evaluations, and other reviews of U.S. Department of Housing and Urban Development (HUD] programs and activities to ensure they operate economically, efficiently, and effectively. This page contains links to our audit and evaluation reports and memoranda.
Public and Indian Housing (PIH) Information Technology (IT) Modernization Resourcing Evaluation
The OIG Office of Evaluation is initiating an evaluation of the U.S. Department of Housing and Urban Development’s (HUD) Public and Indian Housing (PIH) Information Technology (IT) Modernization program. The objectives are to assess the IT Modernization process for Enterprise Voucher Management System (EVMS) and Housing Information Portal (HIP) systems that support key PIH programs.
Marzo 31, 2025
Work Start Notification
#2025-OE-0007
Operational Effectiveness of IT Security Controls
To assess the operational effectiveness of security controls for selected HUD IT systems or functions.
Marzo 31, 2025
Work Start Notification
#2025-OE-0006
U.S. Department of Housing and Urban Development Personally Identifiable Information Risk Management in a Zero Trust Environment (2023-OE-0007) Evaluation Report
The OIG evaluated the U.S. Department of Housing and Urban Development’s (HUD) progress in applying zero trust security principles to protect personally identifiable information (PII). HUD maintained a significant number of records that contain PII with limited zero trust controls in place to secure these data. In FY 2022, HUD established a zero trust implementation plan to help the agency address the five zero trust...
Diciembre 12, 2024
Report
#2023-OE-0007
Fiscal Year (FY) 2025 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation
HUD OIG is conducting the Fiscal Year (FY) 2025 evaluation of the HUD's information security (InfoSec) program and practices, as required by the Federal Information Security Modernization Act of 2014 (FISMA). The objectives are to (1) perform an independent evaluation of the effectiveness of HUD’s InfoSec program and practices as required by FISMA; (2) test the effectiveness of HUD’s InfoSec policies, procedures, and practices through...
Noviembre 01, 2024
Work Start Notification
#2025-OE-0001
FHA Catalyst Personally Identifiable Information Risk Management in a Zero Trust Environment (2023-OE-0007a) Interim Evaluation Report
The OIG evaluated the U.S. Department of Housing and Urban Development (HUD) Office of Housing’s (Housing) progress in applying zero trust security principles to protect personally identifiable information (PII) within the Federal Housing Administration (FHA) Catalyst system.HUD was in the beginning stages of implementing zero trust requirements for the data and identity pillars. HUD Office of Housing systems, including FHA Catalyst,...
Octubre 31, 2024
Report
#2023-OE-0007a
HUD FY 2024 Federal Information Security Modernization Act (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to...
Octubre 29, 2024
Report
#2024-OE-0002
HUD Has Met the Responsibilities of the Geospatial Data Act of 2018 During the Implementation Phase
The Geospatial Data of 2018 (the Act) governs the collection, production, acquisition, maintenance, distribution, use, and preservation of geospatial data of covered agencies, including the U.S. Department of Housing and Urban Development (HUD). We audited the U.S. Department of Housing and Urban Development’s (HUD) efforts to meet the geospatial data requirements stated in the Act. The Act requires the Inspector...
Septiembre 20, 2024
Report
#2024-LA-0002
HUD FY 2023 Federal Information Security Modernization Act (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to...
Enero 29, 2024
Report
#2023-OE-0001
HUD Personal Identifiable Information Risk Management in a Zero Trust Environment
HUD OIG is performing this evaluation to assess HUD’s capability to meet privacy and data protection requirements and provide appropriate stakeholders with an understanding of any related potential risks to HUD’s data and the operational mission. The evaluation will also provide HUD an independent assessment of the level of maturity it has reached in developing the data and identify pillars of CISA's zero-trust architecture. The...
Enero 01, 2024
Work Start Notification
#2023-OE-0007
Fiscal Year (FY) 2024 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation
HUD OIG is conducting the Fiscal Year (FY) 2024 evaluation of the HUD's information security program and practices, as required by the Federal Information Security Modernization Act of 2014 (FISMA). The objectives are to (1) assess the maturity level of HUD’s InfoSec program and practices based on the annual IG FISMA reporting metrics. The assessment will include 20 core IG metrics that are evaluated annually and group 2 of the...
Diciembre 01, 2023
Work Start Notification
#2024-OE-0002
HUD’s Assistance and Grantee Challenges With the Office of Native American Programs’ COVID-19 Recovery Programs
We audited the U.S. Department of Housing and Urban Development (HUD), Office of Native American Programs’ (ONAP) coronavirus disease of 2019 (COVID-19) recovery programs. We performed this audit to provide HUD with insight and a nationwide perspective on the challenges that grantees experienced with those programs. Our audit objectives were to identify 1) the information, guidance, and training HUD provided to the...
Julio 28, 2023
Report
#2023-LA-0005
HUD’s Robotic Process Automation Program Was Not Efficient or Effective
We conducted this evaluation to assess the maturity of HUD’s Robotic process automation (RPA) activities and determine whether HUD had implemented related controls to address technology and program management risks. RPA is a software technology used to emulate human actions on a computer. RPA software programs, referred to as “bots,” can complete repetitive tasks quickly and consistently, freeing up employees to work on...
Febrero 17, 2023
Report
#2021-OE-0007
Assessment of HUD’s IT Infrastructure To Support Extensive Telework
We audited the U.S. Department of Housing and Urban Development’s (HUD) information technology (IT) infrastructure to support mandatory telework. During mandatory telework, more employees simultaneously needed remote access to HUD’s network and agency resources for an extended period, which presented unique risks and security requirements. While HUD is no longer operating under mandatory telework, understanding the challenges it faced...
Enero 24, 2023
Report
#2023-FO-0008
Review of Drawdown Levels and Publicly Available Information on the Office of Native American Programs’ CARES Act and ARP Act Block Grants
We audited the U.S. Department of Housing and Urban Development (HUD), Office of Native American Programs’ (ONAP) Coronavirus Aid, Relief, and Economic Security (CARES) Act and American Rescue Plan (ARP) Act to identify drawdown levels for its block grant programs and assessed information ONAP made publicly available.
As of October 4, 2022, grantees had drawn $231.6 million of the $300 million in CARES Act block grant funds and $135....
Enero 20, 2023
Report
#2023-LA-0003
Fiscal Year 2023 Federal Information Security Modernization Act of 2014 (FISMA) Evaluation
HUD OIG is conducting the Fiscal Year (FY) 2023 evaluation of the HUD's information security program and practices, as required by the Federal Information Security Modernization Act of 2014 (FISMA). The objectives are to (1) assess the maturity level of HUD’s IS programs and practices based on the annual IG FISMA reporting metrics. The assessment will include 20 core IG metrics that are evaluated annually and group 1 of the...
Diciembre 01, 2022
Work Start Notification
#2023-OE-0001
HUD FY 2022 Federal Information Security Modernization Act (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation...
Septiembre 30, 2022
Report
#2022-OE-0001
Geospatial Data Act of 2018, Fiscal Year 2022
We audited the U.S. Department of Housing and Urban Development’s (HUD) efforts to meet the Geospatial Data Act of 2018 (the Act).Our audit objective was to determine whether HUD met the 13 responsibilities stated in the Act with regard to its collection, production, acquisition, maintenance, distribution, use, and preservation of geospatial data. The Act also generally requires covered agencies provide access to geospatial data...
Septiembre 30, 2022
Report
#2022-LA-0004
Fraud Risk Inventory for the Tenant- and Project-Based Rental Assistance, HOME, and Operating Fund Programs’ CARES and ARP Act Funds
In coordination with the Pandemic Response Accountability Committee, we conducted an audit to identify potential fraud schemes that could affect HUD’s pandemic funds. We reviewed the funds appropriated by the Coronavirus Aid, Relief, and Economic Security (CARES) Act and the American Rescue Plan (ARP) Act for the Tenant-Based Rental Assistance (TBRA), Project-Based Rental Assistance (PBRA), HOME Investment Partnerships, and...
Septiembre 29, 2022
Report
#2022-FO-0007
Community Development Block Grant CARES Act Implementation Challenges
We audited the U.S. Department of Housing and Urban Development’s (HUD) Community Development Block Grant Coronavirus Aid, Relief, and Economic Security (CARES) Act program.Our audit objective was to determine what challenges grantees faced in using program funds for activities that prepare for, prevent, or respond to the coronavirus and its impact. We used a survey questionnaire to gather feedback and insight directly from 1,...
Septiembre 28, 2022
Report
#2022-LA-0003
PRAC COVID-19 Pandemic Impact Project
HUD OIG is one of 10 OIGs participating in this PRAC-led COVID 19 Pandemic Impact Project. The OIGs will conduct the review and provide the results to the PRAC for the final consolidated work products. The objective is to identify the federal pandemic response program funds provided to select geographic areas and the purpose of those funds, and to determine whether the federal program spending aligned with the intended goals and...
Abril 01, 2022
Work Start Notification
#LA 23 0020