FDIC Can't Account For $6.6M on a $300M IT Contract
Summary
A Federal Deposit Insurance Corporation inspector general audit of the agency's $300 million Infrastructure Support Services contract found FDIC could not verify $4.6 million in resource-unit charges the contractor invoiced, and had left $2 million in service-level credits owed back to it uncollected. The same audit found a contractor employee emailed an internal planning document outside FDIC's network without the incident being reported, and two of the contractor's staff got privileged network access before finishing required security training. FDIC's own senior management asked the inspector general to redact the report when it was first issued in January 2026; the OIG reissued it in June, unredacting the dollar figures because federal law required disclosure. FDIC has given itself until July 31, 2026 to decide whether the $4.6 million was properly spent, and until December 31, 2026 to try to recover the $2 million.
A contract too complex to check
's findings on invoice oversight⧉ center on two failures: the didn't consistently enforce the contractor's obligation to hand over the data needed to verify service-level performance, and it didn't consistently review or retain the backup for what it was billed. Key contract personnel told auditors the contract's own complexity was part of the problem -- monthly invoices span more than 42 resource-unit categories across seven service towers, and understanding the methodology behind pass/fail performance calculations was, in their own words, difficult. tested this directly: it pulled a judgmental sample of invoices from February 2023 through December 2024, the period following an earlier corrective action plan on the same contract, and still found charges it couldn't trace back to supporting records.
View data as table
| Questioned costs | $4,629,334 |
|---|---|
| Funds to be put to better use | $2,000,375 |
| Combined | $6,629,709 |
What 'questioned' and 'better use' actually mean
The two dollar figures describe different problems, not one. "Questioned costs" is audit vocabulary for spending the couldn't document as allowable -- not a finding that the $4.6 million was misspent, but that the agency couldn't produce the paperwork to show it wasn't⧉. Recommendation 6 gives the until July 31, 2026 to go find that paperwork and determine whether the charges were supported and allowable. "Funds put to better use" is the opposite kind of problem: the contract already entitles the to $2,000,375 in credits for service the contractor didn't deliver, and the agency simply hasn't collected it. Recommendation 2 gives the until December 31, 2026 to recover that money or explain in writing why it can't.
View data as table
| ISS contract ceiling (Basic Ordering Agreement, awarded Jan. 2021) | 300,000,000 | Not all of it has been spent -- this is the contract vehicle's ordering ceiling, not a confirmed total spend. |
|---|---|---|
| Combined questioned costs + uncollected credits | 6,629,709 | About 2.2% of the ceiling -- concentrated in the years covered by OIG's invoice sample, February 2023 through December 2024. |
Data that left the building
A third finding has nothing to do with invoices. A contractor employee overseeing one of the seven service towers emailed an internal planning document⧉ -- one that laid out the ISS program's operating model, tools, and organization chart -- to two colleagues' company email accounts outside 's own network. One of them downloaded it before finishing required cybersecurity training or even receiving an -issued laptop, and the contractor never self-reported the incident to 's security team, as its contract requires. Separately, sampled 15 contractor employees to check training compliance and found that two had been granted privileged access to 's network and systems before completing the security training that access requires.
Redacted, then required by law to unredact
issued this report on January 30, 2026 with sections blacked out at the request of 's own senior management, who wanted the agency's information kept confidential. It reissued the report on June 1, 2026⧉, unredacting specifically the $4.6 million and $2 million figures -- not because the agreed to release them, but because federal law requires inspectors general to publicly disclose the monetary benefits of their audits. Everything else 's management asked to keep confidential, including the contractor's identity, remains blacked out in the public version.
- Two different problems total $6.6 million, not one. $4.6 million is money can't yet prove was properly spent; $2 million is money is owed and hasn't collected. Conflating them into a single 'waste' number would misstate what the audit actually found.
- Both have real deadlines, not vague ones. committed to resolving the $4.6 million question by July 31, 2026 and the $2 million recovery by December 31, 2026 -- dates the agency itself proposed in response to the audit, now on the record.
- The public only has the dollar figures because the law forced it. 's own leadership wanted this report kept confidential; the numbers are public today because an inspector general's statutory disclosure duty overrode that request.
The contractor holding the ISS agreement is not named anywhere in the public report -- redacted its identity along with other agency-requested material, and this piece does not attempt to identify it. No or contractor employee is named; the report itself refers to contractor staff only by role ("a service tower lead," "two Contractor employees"). "Questioned costs" and "funds to be put to better use" are standard federal audit terms, not findings of fraud or theft -- see the explainer above. The $300 million figure is the contract's ordering ceiling, not a confirmed total of dollars spent to date, so the $6.6 million in findings should be read against a sample reviewed, not audited spending across the full life of the contract.
Sources(2) ▾
- Federal Deposit Insurance Corporation, Office of Inspector General, Oversight of the Infrastructure Support Services Contract (AUD-26-02) (2026-01-30) — The primary document -- a 37-page performance audit of the agency's oversight of its Infrastructure Support Services (ISS) contract. Read in full: the cover Notice (explaining the report's redaction and June 1, 2026 reissuance), the Executive Summary (What We Did/Found/Recommended), the full Results narrative, Findings 1-3 (service level monitoring, invoice review, data protection/training), all eight numbered Recommendations with 's stated corrective actions, Appendix 1 (Objective, Scope, and Methodology), and Appendix 3 (Summary of the 's Corrective Actions, the table of expected completion dates and monetary benefits). Retrieved and hash-sealed directly from the 's own domain. fdicoig.gov · original document
- Federal Deposit Insurance Corporation, Office of Inspector General, Report Waste, Fraud, & Abuse -- FDIC OIG Hotline (2026-07-21) — The 's own public hotline page, fetched this iteration to source the call-to-action: phone number, mailing address, and online reporting portal for reporting fraud, waste, abuse, or mismanagement in programs and contractor operations -- the same office that produced AUD-26-02. fdicoig.gov · original document
Comments
Always open. Logged-in readers can annotate paragraphs in place.
The signed a $300 million contract in January 2021⧉ to run the day-to-day IT operations behind its own systems -- the Infrastructure Support Services (ISS) agreement, split across seven service categories and more than 42 billing lines a month. A January 30, 2026 audit by the 's own inspector general found the agency couldn't verify $4.6 million of what the contractor invoiced under it, and had left $2 million in credits the contractor owed back to it sitting uncollected. has given itself until July 31, 2026 to decide whether the $4.6 million was properly spent, and until December 31, 2026 to try to recover the $2 million.