APERS Skipped Its Own Monthly Check -- Then a Software Bug Hit
Summary
A January 6, 2026 audit from Arkansas Legislative Audit found the Arkansas Public Employees Retirement System self-reported $261,993 in FY2025 benefit overpayments from mis-set calculations, then let a pension-software defect overpay five more retirees a further $95,264 -- a defect the agency's own monthly safeguard, built in 2022 after a prior audit finding, was not being reviewed to catch. A separate, unrelated incident left $2,692 in redirected benefits unrecovered.
A breach nobody has gotten back
In December 2024, an employee in APERS's call center reset Member Self Service account credentials twice without verifying the caller was the account holder, granting an unauthorized user access to a retiree's account. Before APERS revoked the access, that user redirected one month's benefit payment: $2,692. As of the audit's January 2026 report date, the funds had not been recovered. In its written response, APERS said it has since added two-factor authentication to the Member Self Service portal and now blocks online banking changes to institutions frequently used by fraudsters, requiring a notarized application to change to one of those instead.
View data as table
| Unrecovered breach (2025-1) | 2,692 | One month's benefit payment, redirected after an unverified account-credential reset |
|---|---|---|
| Self-reported overpayments (2025-2) | 261,993 | FY2025 total, reported by APERS to ALA as required by state law |
| Software-bug overpayments (2025-3) | 95,264 | Found only after ALA's own sample testing traced one error to a system defect |
$261,993 in overpayments, self-reported
Arkansas law requires state agencies to report apparent losses of state funds to the legislative auditor. Under that rule, APERS reported $261,993 in overpayments to retirees and beneficiaries for the year ending June 30, 2025 -- money paid out because benefits were calculated wrong when a member's payments were first set up, not because of any one system failure. The audit names two of the larger errors: APERS overpaid one public-employees-plan member about $42,317 by failing to recognize reciprocal service as concurrent service, letting that member retire under full benefits instead of the reduced early-retirement rate they actually qualified for. Separately, it overpaid a judicial-plan member about $46,764 by calculating their benefit under the state's more generous Tier II provisions instead of the Tier I provisions that applied to them -- and then miscalculating even the Tier II rate.
The bug the agency's own safeguard didn't catch
Separately from what APERS reported on its own, Arkansas Legislative Audit ran its own test: a sample of 60 members added to the benefit rolls in FY2025 who retired or moved through the state's deferred retirement option program (DROP). Two showed discrepancies. One was a simple data error. The other traced to something structural: APERS's pension-administration software, COMPASS, had erroneously erased an internal flag marking a member's monthly benefit as capped under the IRS's Section 415 limit when that member exited DROP, producing a $1,264 overpayment. That single hit in a 60-person sample was enough to make APERS check its full membership for the same defect -- and it found four more retirees affected, adding roughly $94,000 more.
View data as table
| Found in the 60-member sample (1 retiree) | 1,264 |
|---|---|
| Found once APERS queried all members (4 more retirees) | 94,000 |
The part that makes this a control story, not just a software story: APERS had already built a safeguard meant to catch exactly this kind of error. In January 2022, responding to a prior audit finding about benefit overpayments, APERS started generating a monthly Benefit Reconciliation Audit Report designed to flag mismatches between a retiree's calculation factors and what they're actually being paid. When ALA sampled two months of FY2025 to confirm the report was being reviewed, APERS could not produce evidence that it had been -- telling auditors the agency was still working to identify an experienced team to review it monthly.
APERS's own response adds a caveat worth taking at face value rather than dismissing as an excuse: even reviewed on schedule, the report would not have caught this specific bug, since a missing software flag doesn't show up as a calculation mismatch. The agency says it's now working with the COMPASS vendor on a system-level fix, and negotiated a service credit -- expected in the first quarter of 2026 -- to cover the $95,264 rather than pursue the five retirees for repayment.
- Three FY2025 findings, three different failure modes, $359,949 combined. An unverified caller redirected $2,692 that's still unrecovered; mis-set benefit calculations produced $261,993 in self-reported overpayments; a software defect added $95,264 more once a small sample test led to a full-membership check.
- A safeguard built after a 2022 audit finding wasn't being run. APERS's monthly Benefit Reconciliation Audit Report exists specifically to catch benefit-calculation errors, but auditors found no evidence it was reviewed in the two FY2025 months they sampled -- though APERS itself notes that report wouldn't have caught this particular software bug anyway.
- A 60-member sample surfaced a problem affecting at least five. ALA's routine testing found one overpaid retiree; only a full-membership query, prompted by that single hit, turned up four more -- a reminder that compliance samples can confirm a defect exists without measuring how far it reaches.
All figures in this piece come from Arkansas Legislative Audit's Report SA1037025, the FY2025 annual financial-statement audit of APERS, fetched directly from arklegaudit.gov (the report is a routine annual audit, not a special investigation). Arkansas Legislative Audit classified the two benefit-calculation findings (2025-2 and 2025-3) as significant deficiencies in internal control, not material weaknesses, and cautioned that its audit procedures are not designed to catch every deficiency that might exist -- meaning these three findings should be read as what one year's testing surfaced, not a complete accounting of every error in APERS's benefit payments. No individual employee or retiree named in the underlying report is identified here; all are described by role only, consistent with how the report itself withholds their names. The $359,949 combined across all three findings is a small fraction -- about 0.00265% -- of the $13.57 billion in assets APERS held as of June 30, 2025; the story here is about whether a specific control was operating, not about the fund's solvency.
Sources(1) ▾
- Arkansas Legislative Audit, Arkansas Public Employees Retirement System, Annual Financial Report, For the Year Ended June 30, 2025 (Report SA1037025) (2026-01-06) — Arkansas Legislative Audit's annual financial-statement audit of the Arkansas Public Employees Retirement System (APERS) -- the state's pension system for public employees, state police, and judicial retirees -- for the year ended June 30, 2025, issued to the Legislative Joint Auditing Committee. Fetched and read in full (49-page PDF) directly from the issuer's own domain. Used for every dollar figure and finding cited here: the auditor's opinion and internal-control report (pp.1-6), the Schedule of Findings and Responses (2025-1, 2025-2, 2025-3, pp.4-6) including APERS's own written management responses, the Statement of Fiduciary Net Position (Exhibit A, p.8), Note 1's plan-membership table (p.10), Note 3's net pension liability table (p.31), and the Schedule of Selected Information (Schedule 10, p.45). A Wayback Save Page Now request was made at read time but had not completed indexing as of this writing; capture points to the same direct arklegaudit.gov URL used as url, which serves the report with no login required. arklegaudit.gov · original document
Comments
Always open. Logged-in readers can annotate paragraphs in place.
The Arkansas Public Employees Retirement System (APERS) manages $13.57 billion in assets for 104,051 active members, retirees, and beneficiaries across the state's public-employee, state-police, and judicial pension plans. Arkansas Legislative Audit⧉ -- the independent, legislative-branch office that audits every Arkansas state agency -- reviewed that fund's FY2025 books and issued its report January 6, 2026, finding three unrelated control failures: an unverified caller redirected a retiree's benefit payment that remains unrecovered, the agency self-reported $261,993 in benefit overpayments from calculations set wrong at retirement, and a pension-software defect quietly overpaid five more retirees -- a defect the agency's own monthly safeguard report, built specifically to catch this kind of error, was not being reviewed to find.