HUD OCIO should update its enterprisewide business impact prioritization analysis procedures to include system dependencies and the characterization of system components (IG FISMA metric 61).
2023-OE-0001 | Enero 29, 2024
HUD FY 2023 Federal Information Security Modernization Act (FISMA) Evaluation Report
Chief Information Officer
2023-OE-0001-23
2024-IG-0001 | Enero 23, 2024
Management Alert: Action Is Needed From HUD Leadership To Resolve Systemic Challenges With Improper Payments
Deputy Secretary
2024-IG-0001-001-A
PrioridadPriorityWe believe these open recommendations, if implemented, will have the greatest impact on helping HUD achieve its mission to create strong, sustainable, inclusive communities and quality affordable homes for all.
We recommend that the Deputy Secretary Develop and execute a detailed plan and timeline for both testing and reporting estimates of improper payments in the PIH-TBRA and PBRA programs in compliance with Federal law and OMB guidance.
Status
In response to the Management Alert, the Deputy Secretary stated that she would provide a plan in 30 days. On April 10, 2024, the Chief Financial Officer, Assistant Secretary for Housing, and Principal Deputy Assistant Secretary for Public and Indian Housing (PIH) stated their respective executives have been working together to develop a plan to accelerate HUD’s ability to produce statistically valid estimates. With respect to project-based rental assistance (PBRA), HUD plans to use ongoing data collection for fiscal year (FY) 2023 tier 1 and tier 2 payments to develop a statistical estimate in FY 2024. With respect to PIH-TBRA, in lieu of pursuing an estimate for the FY 2024 reporting cycle, PIH will focus on “its existing efforts to enhance PIH [IT] systems”, which HUD considers to be a more strategic use of resources. It is not clear from HUD’s response what PIH will do differently than it already had planned prior to the management alert as HUD did not provide a detailed plan or timeline for OIG review. As of June 21, 2024, a detailed plan or timeline has not been provided.
Analysis
As of June 21, 2024, HUD has not provided a detailed plan or timeline for OIG review. It remains unclear how HUD will produce an estimate in the PBRA programs in 2024 and when it will be able to produce an estimate for PIH-TBRA.
For HUD to close this recommendation, it must finish testing the full life cycle of payments in these programs and publicly report estimates of the improper payments in them. Merely producing a plan with future action target dates is not sufficient to meet the spirit of this recommendation.
PBRA and PIH-TBRA are the two largest program expenditures in HUD's portfolio, totaling $45.3 billion in FY 23, or 67.5 percent of HUD's total expenditures. HUD has been challenged with developing a compliant sampling methodology that can test the full payment cycle and that can be executed within the required timeframes. HUD’s sampling methodology did not test the full payment cycle. Further, the associated sample testing and statistical estimation of improper payments could not be completed in time for the required annual reporting of improper payment estimates in the Agency Financial Report (AFR), normally issued in November. To fully address this recommendation, the sampling methodology should test the full payment cycle, and the associated sample testing and statistical estimation must be completed in time to be included in the AFR.
Implementation of this recommendation will result in HUD better safeguarding taxpayer dollars and decrease improper payments.
2022-OE-0008 | Enero 19, 2024
U.S. Department of Housing and Urban Development Employee Retention
Office of Chief Human Capital Officer
2022-OE-0008-04
Develop guidance for program offices to develop program office-specific action plans to address any causes found for high attrition rates in governmentwide high-risk MCOs and field offices in large cities.
2022-OE-0008-05
Create a single, unified agency-specific MCO list updated to reflect current progress toward closing skills gaps.
2023-OE-0001a | Diciembre 20, 2023
Fiscal Year 2023 Federal Information Security Modernization Act of 2014 Penetration Test Evaluation Report
Policy Development & Research
2023-OE-0001a-04
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
Chief Information Officer
2023-OE-0001a-01
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2023-OE-0001a-02
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2023-OE-0001a-03
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2023-OE-0001a-05
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2023-OE-0001a-06
SensitiveSensitiveSensitive information refers to information that could have a damaging import if released to the public and, therefore, must be restricted from public disclosure.
The OIG has determined that the contents of this recommendation would not be appropriate for public disclosure and has therefore limited its distribution to selected officials.
2024-FW-1001 | Octubre 27, 2023
The Puerto Rico Department of Housing Should Enhance Its Fraud Risk Management Practices
Community Planning and Development
2024-FW-1001-001-A
We recommend that the Deputy Assistant Secretary instruct PRDOH to implement a process to regularly conduct fraud risk assessments and determine a fraud risk profile. The fraud risk profile should include key findings and conclusions from the risk assessment, including the analysis of the types of fraud risks, their perceived likelihood and impact, risk tolerance, and the prioritization of risks.
2024-FW-1001-001-C
We recommend that the Deputy Assistant Secretary for Grant Programs evaluate PRDOH’s risk exposure and tolerance as part of HUD’s program-specific fraud risk assessment for disaster grant programs.
2024-FW-1001-001-D
We recommend that the Deputy Assistant Secretary for Grant Programs coordinate with HUD’s Chief Risk Officer to (1) provide training and technical assistance to PRDOH with a focus on the design, implementation, and performance of fraud risk assessments, and (2) establish a fraud risk management framework for the organization.
2024-FW-1001-001-E
We recommend that the Deputy Assistant Secretary for Grant Programs assess whether grantees have mature fraud risk management programs within the disaster recovery and mitigation programs.
2024-FW-1001-001-F
We recommend that the Deputy Assistant Secretary for Grant Programs determine the fraud risk exposure in HUD's disaster recovery and mitigation programs and work with grantees to implement appropriate fraud mitigation activities.
2024-FW-0001 | Octubre 24, 2023
Preventing Duplication of Benefits When Using Community Development Block Grant Disaster Recover and Mitigation Funds
Community Planning and Development
2024-FW-0001-001-A
We recommend that the Director, Office of Disaster Recovery, perform monitoring of or otherwise review grantees’ detailed procedures for preventing duplication of benefits for each grant activity within the first year after HUD signs the grant agreement or before grantees process applications for assistance, whichever occurs first.
2024-FW-0001-001-B
We recommend that the Director, Office of Disaster Recovery, develop and implement a process to review grantees’ detailed procedures for preventing duplication of benefits and require grantees to correct any deficiencies identified in the review before grantees process applications for assistance.
2023-FW-0003 | Julio 21, 2023
Disaster Recovery Data Portal
Policy Development & Research
2023-FW-0003-001-A
We recommend that the General Deputy Assistant Secretary, Office of Policy Development and Research, and the Deputy Chief Information Officer, Office of the Chief Information Officer develop the project management documents, as required by HUD’s Project Planning and Management Life Cycle V2.0 policy, including obtaining required approvals and ensuring that an adequate project risk management process is established for identifying, analyzing, and responding to project risks.
2023-FW-0003-002-A
We recommend that the General Deputy Assistant Secretary, Office of Policy Development and Research; the Deputy Chief Information Officer; and the Director, Office of Disaster Recovery, identify and incorporate at least one additional data source into the Disaster Recovery Data Portal to further assist grantees with duplication of benefits assessments.
2023-KC-0005 | Junio 13, 2023
Servicers Generally Did Not Meet HUD Requirements When Providing Loss Mitigation Assistance to Borrowers With Delinquent FHA-Insured Loans
Housing
2023-KC-0005-001-C
Provide additional guidance and training to servicers to address common loss mitigation issues found during this audit.