Fiscal Year 2022 Federal Information Security Modernization Act of 2014 Penetration Test and Vulnerability Assessment
The Federal Information Security Modernization Act of 2014 (FISMA) requires all Federal agencies to conduct independent penetration tests and vulnerability assessments on a sampling of information systems annually. In conjunction with our fiscal year 2022 FISMA evaluation (2022-OE-0001), we conducted a targeted penetration test and vulnerability assessment of sample systems that resulted in a Topic Brief. The objective of this…
December 14, 2022
Report
#2022-OE-0001a
Audit of HUD’s Fiscal Years 2022 and 2021 Financial Statements
We contracted with the independent public accounting firm of CliftonLarsonAllen LLP (CLA) to audit the financial statements of HUD as of and for the fiscal years ended September 30, 2022 and 2021, and to provide reports on HUD’s 1) internal control over financial reporting; and 2) compliance with laws, regulations, contracts, and grant agreements and other matters, including whether financial management systems complied substantially with the…
November 17, 2022
Report
#2023-FO-0004
Audit of FHA’s Fiscal Years 2022 and 2021 Financial Statements
We contracted with the independent public accounting firm of CliftonLarsonAllen LLP (CLA) to audit the financial statements of FHA as of and for the fiscal years ended September 30, 2022 and 2021, and to provide reports on FHA’s 1) internal control over financial reporting; and 2) compliance with laws, regulations, contracts, and grant agreements and other matters. Our contract with CLA required that the audit be performed in accordance…
November 16, 2022
Report
#2023-FO-0003
Government National Mortgage Association Audit of Fiscal Years 2022 and 2021 Financial Statements
We contracted with the independent public accounting firm of CliftonLarsonAllen LLP (CLA) to audit the financial statements of Ginnie Mae as of and for the fiscal years ended September 30, 2022 and 2021, and to provide reports on Ginnie Mae’s 1) internal control over financial reporting; and 2) compliance with laws, regulations, contracts, and grant agreements and other matters. Our contract with CLA required that the audit be performed in…
November 14, 2022
Report
#2023-FO-0002
Geospatial Data Act of 2018, Fiscal Year 2022
We audited the U.S. Department of Housing and Urban Development’s (HUD) efforts to meet the Geospatial Data Act of 2018 (the Act).
Our audit objective was to determine whether HUD met the 13 responsibilities stated in the Act with regard to its collection, production, acquisition, maintenance, distribution, use, and preservation of geospatial data. The Act also generally requires covered agencies provide access to geospatial data and…
September 30, 2022
Report
#2022-LA-0004
HUD FY 2022 Federal Information Security Modernization Act (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to assess…
September 30, 2022
Report
#2022-OE-0001
Fraud Risk Inventory for the Tenant- and Project-Based Rental Assistance, HOME, and Operating Fund Programs’ CARES and ARP Act Funds
In coordination with the Pandemic Response Accountability Committee, we conducted an audit to identify potential fraud schemes that could affect HUD’s pandemic funds. We reviewed the funds appropriated by the Coronavirus Aid, Relief, and Economic Security (CARES) Act and the American Rescue Plan (ARP) Act for the Tenant-Based Rental Assistance (TBRA), Project-Based Rental Assistance (PBRA), HOME Investment Partnerships, and Public Housing…
September 29, 2022
Report
#2022-FO-0007
Community Development Block Grant CARES Act Implementation Challenges
We audited the U.S. Department of Housing and Urban Development’s (HUD) Community Development Block Grant Coronavirus Aid, Relief, and Economic Security (CARES) Act program.
Our audit objective was to determine what challenges grantees faced in using program funds for activities that prepare for, prevent, or respond to the coronavirus and its impact. We used a survey questionnaire to gather feedback and insight directly from 1,047 program…
September 28, 2022
Report
#2022-LA-0003
Corrective Action Verification Government Purchase Card Program and Government Travel Card Program Audit Recommendations
We completed a corrective action verification (CAV) of recommendations from prior Office of Inspector General (OIG) audit reports on the U.S. Department of Housing and Urban Development’s (HUD) government purchase cards and government travel cards, both issued January 31, 2020. During our CAV, we followed up on all 10 recommendations from OIG audit report 2020-KC-0001 and all 13 recommendations from OIG audit report 2020-KC-0002. Our CAV…
August 24, 2022
Report
#2022-FO-0006
HUD Did Not Implement Adequate Grant Closeout and Reporting Processes To Ensure Consistent Application of GONE Act Requirements
We audited the U.S. Department of Housing and Urban Development’s (HUD) grant closeout processes and compliance with the Grants Oversight and New Efficiency (GONE) Act. The GONE Act required that we conduct a risk assessment to determine whether an audit of HUD’s grant closeout process was warranted. We initiated this review based on the results of our risk assessment conducted in fiscal year 2018, which found that an audit was…
March 09, 2022
Report
#2022-NY-0001
Fiscal Year 2021 Federal Information Security Modernization Act (FISMA) Evaluation Report
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to assess…
February 17, 2022
Report
#2021-OE-0001
Fiscal Year 2021 Federal Information Security Modernization Act (FISMA) Evaluation Security Technical Testing Topic Brief
The Federal Information Security Modernization Act of 2014 (FISMA) requires all federal agencies to conduct independent security technical verification testing on a sampling of information systems annually. In conjunction with our fiscal year 2021 FISMA evaluation (2021-OE-0001), we conducted a targeted security testing assessment of sample systems that resulted in a Topic Brief. The objective of this application vulnerability…
February 15, 2022
Topic brief
#2021-OE-0001a
HUD Did Not Always Comply With Its Internal Guide When Transitioning Offices From Mandatory to Maximum Telework During the COVID-19 Pandemic
We audited the U.S. Department of Housing and Urban Development’s (HUD) transitioning of offices from mandatory to maximum telework during the coronavirus disease 2019 (COVID-19) pandemic, based on a request from Representative Gerald Connolly, to review whether HUD was employing best practices and existing guidance when deciding whether or when to require Federal employees to return to their offices. Transitioning an office to maximum…
February 15, 2022
Report
#2022-CH-0002
Audit of HUD’s Fiscal Years 2021 and 2020 Consolidated Financial Statements
We contracted with the independent public accounting firm of CliftonLarsonAllen LLP (CLA) to audit the financial statements of HUD as of and for the fiscal years ended September 30, 2021 and 2020,1 and to provide reports on HUD’s 1) internal control over financial reporting; and 2) compliance with laws, regulations, contracts, and grant agreements and other matters, including whether financial management systems complied substantially with the…
December 09, 2021
Report
#2022-FO-0004
Audit of FHA’s Fiscal Years 2021 and 2020 Consolidated Financial Statements
We contracted with the independent public accounting firm of CliftonLarsonAllen LLP (CLA) to audit the financial statements of FHA as of and for the fiscal years ended September 30, 2021 and 2020, and to provide reports on FHA’s 1) internal control over financial reporting; and 2) compliance with laws, regulations, contracts, and grant agreements in its financial reporting. Our contract with CLA required that the audit be performed in…
December 09, 2021
Report
#2022-FO-0003
Delays in Federal Housing Administration Catalyst’s Development
In February 2021, the Office of the Chief Information Officer (OCIO) identified funding risks with the development contract under which HUD contracted for Federal Housing Administration (FHA) Catalyst’s development. In response, HUD officials took steps to slow FHA Catalyst spending on the contract while awaiting approval for additional contract funds. Despite efforts to slow project spending, it was not enough to prevent funding…
November 17, 2021
Memorandum
#2021-OE-0003a
HUD’s Processes for Managing IT Acquisitions
We reviewed the U.S. Department of Housing and Urban Development’s (HUD) ability to effectively complete information technology (IT) acquisitions. HUD’s IT systems and its modernization plans depend heavily on contractors, yet HUD has historically faced significant challenges with implementing effective acquisition processes. Therefore, HUD’s acquisition capacity represents a key potential risk within HUD’s IT environment. We found that a…
November 17, 2021
Report
#2020-OE-0004
DATA Act Compliance Audit of the U.S. Department of Housing and Urban Development, Office of the Chief Financial Officer
In accordance with the statutory requirements of the Digital Accountability and Transparency Act of 2014 (DATA Act) and standards established by the Office of Management and Budget (OMB) and the U.S. Department of the Treasury, we audited the U.S. Department of Housing and Urban Development (HUD), Office of the Chief Financial Officer’s (OCFO) compliance with the DATA Act for the third quarter of fiscal year 2020. The audit was statutorily…
November 08, 2021
Report
#2022-FO-0001
Fraud Risk Inventory for the CDBG and ESG CARES Act Funds
We conducted this engagement in coordination with the Pandemic Response Accountability Committee (PRAC) to gain an understanding of the U.S. Department of Housing and Urban Development’s (HUD) fraud risk management practices and develop an inventory of fraud risks that HUD had not already identified for the funds appropriated by the Coronavirus Aid, Relief, and Economic Security (CARES) Act for the Community Development Block Grant (CDBG) and…
October 12, 2021
Report
#2022-FO-0801
2021 Persistent IT Challenges and Issues Facing HUD
The brief provides an update to the original 2018 topic brief, and highlights key challenges faced by HUD in managing and improving its IT program. The brief is not based on new work, but is a summary of 83 reports and 788 recommendations from past HUD OIG and GAO reports. It discusses the present IT environment at HUD, previously identified and new IT-related challenges, and HUD’s efforts and progress in addressing these challenges.…
August 09, 2021
Topic brief
#2021-OE-0004