BlackLeafwatch the watchmen
FDIC contract oversight of its Infrastructure Support Services IT contract, audited by the FDIC Office of Inspector General

FDIC Can't Account For $6.6M on a $300M IT Contract

Summary

A Federal Deposit Insurance Corporation inspector general audit of the agency's $300 million Infrastructure Support Services contract found FDIC could not verify $4.6 million in resource-unit charges the contractor invoiced, and had left $2 million in service-level credits owed back to it uncollected. The same audit found a contractor employee emailed an internal planning document outside FDIC's network without the incident being reported, and two of the contractor's staff got privileged network access before finishing required security training. FDIC's own senior management asked the inspector general to redact the report when it was first issued in January 2026; the OIG reissued it in June, unredacting the dollar figures because federal law required disclosure. FDIC has given itself until July 31, 2026 to decide whether the $4.6 million was properly spent, and until December 31, 2026 to try to recover the $2 million.

By Frontinus · July 21, 2026

The signed a $300 million contract in January 2021 to run the day-to-day IT operations behind its own systems -- the Infrastructure Support Services (ISS) agreement, split across seven service categories and more than 42 billing lines a month. A January 30, 2026 audit by the 's own inspector general found the agency couldn't verify $4.6 million of what the contractor invoiced under it, and had left $2 million in credits the contractor owed back to it sitting uncollected. has given itself until July 31, 2026 to decide whether the $4.6 million was properly spent, and until December 31, 2026 to try to recover the $2 million.

A contract too complex to check

's findings on invoice oversight center on two failures: the didn't consistently enforce the contractor's obligation to hand over the data needed to verify service-level performance, and it didn't consistently review or retain the backup for what it was billed. Key contract personnel told auditors the contract's own complexity was part of the problem -- monthly invoices span more than 42 resource-unit categories across seven service towers, and understanding the methodology behind pass/fail performance calculations was, in their own words, difficult. tested this directly: it pulled a judgmental sample of invoices from February 2023 through December 2024, the period following an earlier corrective action plan on the same contract, and still found charges it couldn't trace back to supporting records.

Two different problems, both worth millions
The two dollar figures FDIC's inspector general attached to the ISS contract audit
Questioned costs (unsupported invoice charges)
4,629,334
Funds to be put to better use (uncollected credits)
2,000,375
Source: FDIC OIG, AUD-26-02, Results (p.8) and Recommendations 2 and 6 (p.13, 20)
View data as table
Neither figure is a finding of theft or fraud. 'Questioned costs' is an audit term for spending the FDIC could not document as allowable -- the money may turn out to be fine, once the FDIC produces the records. 'Funds to be put to better use' is money the contract already entitles the FDIC to collect from the contractor but hasn't.
Questioned costs$4,629,334
Funds to be put to better use$2,000,375
Combined$6,629,709

What 'questioned' and 'better use' actually mean

The two dollar figures describe different problems, not one. "Questioned costs" is audit vocabulary for spending the couldn't document as allowable -- not a finding that the $4.6 million was misspent, but that the agency couldn't produce the paperwork to show it wasn't. Recommendation 6 gives the until July 31, 2026 to go find that paperwork and determine whether the charges were supported and allowable. "Funds put to better use" is the opposite kind of problem: the contract already entitles the to $2,000,375 in credits for service the contractor didn't deliver, and the agency simply hasn't collected it. Recommendation 2 gives the until December 31, 2026 to recover that money or explain in writing why it can't.

ISS contract ceiling
$300M
A Basic Ordering Agreement FDIC awarded in January 2021 for day-to-day IT support across seven service towers and 42-plus invoice categories
Questioned costs OIG found
$4.63M
Unsupported invoice charges -- FDIC has until July 31, 2026 to determine whether they were allowable
Uncollected credits OIG found
$2.0M
Service-level credits owed to FDIC that it hasn't recovered -- due by December 31, 2026
$6.6 million against a $300 million ceiling
The audit's combined monetary findings, scaled against the ISS contract's total ordering ceiling
ISS contract ceiling (Basic Ordering Agreement, awarded Jan. 2021)
300,000,000
Combined questioned costs + uncollected credits
6,629,709
Source: FDIC OIG, AUD-26-02, Executive Summary (p.1) and Results (p.8)
View data as table
The $6.6 million is small next to the $300 million ceiling, but it's also not the full picture: OIG sampled invoices judgmentally, not a full audit of every dollar billed under the contract, so the two figures describe what turned up in a sample, not a ceiling on what might be found.
ISS contract ceiling (Basic Ordering Agreement, awarded Jan. 2021)300,000,000Not all of it has been spent -- this is the contract vehicle's ordering ceiling, not a confirmed total spend.
Combined questioned costs + uncollected credits6,629,709About 2.2% of the ceiling -- concentrated in the years covered by OIG's invoice sample, February 2023 through December 2024.

Data that left the building

A third finding has nothing to do with invoices. A contractor employee overseeing one of the seven service towers emailed an internal planning document -- one that laid out the ISS program's operating model, tools, and organization chart -- to two colleagues' company email accounts outside 's own network. One of them downloaded it before finishing required cybersecurity training or even receiving an -issued laptop, and the contractor never self-reported the incident to 's security team, as its contract requires. Separately, sampled 15 contractor employees to check training compliance and found that two had been granted privileged access to 's network and systems before completing the security training that access requires.

Redacted, then required by law to unredact

issued this report on January 30, 2026 with sections blacked out at the request of 's own senior management, who wanted the agency's information kept confidential. It reissued the report on June 1, 2026, unredacting specifically the $4.6 million and $2 million figures -- not because the agreed to release them, but because federal law requires inspectors general to publicly disclose the monetary benefits of their audits. Everything else 's management asked to keep confidential, including the contractor's identity, remains blacked out in the public version.

  • Two different problems total $6.6 million, not one. $4.6 million is money can't yet prove was properly spent; $2 million is money is owed and hasn't collected. Conflating them into a single 'waste' number would misstate what the audit actually found.
  • Both have real deadlines, not vague ones. committed to resolving the $4.6 million question by July 31, 2026 and the $2 million recovery by December 31, 2026 -- dates the agency itself proposed in response to the audit, now on the record.
  • The public only has the dollar figures because the law forced it. 's own leadership wanted this report kept confidential; the numbers are public today because an inspector general's statutory disclosure duty overrode that request.

The contractor holding the ISS agreement is not named anywhere in the public report -- redacted its identity along with other agency-requested material, and this piece does not attempt to identify it. No or contractor employee is named; the report itself refers to contractor staff only by role ("a service tower lead," "two Contractor employees"). "Questioned costs" and "funds to be put to better use" are standard federal audit terms, not findings of fraud or theft -- see the explainer above. The $300 million figure is the contract's ordering ceiling, not a confirmed total of dollars spent to date, so the $6.6 million in findings should be read against a sample reviewed, not audited spending across the full life of the contract.

Sources(2) ▾
  • Federal Deposit Insurance Corporation, Office of Inspector General, Oversight of the Infrastructure Support Services Contract (AUD-26-02) (2026-01-30)The primary document -- a 37-page performance audit of the agency's oversight of its Infrastructure Support Services (ISS) contract. Read in full: the cover Notice (explaining the report's redaction and June 1, 2026 reissuance), the Executive Summary (What We Did/Found/Recommended), the full Results narrative, Findings 1-3 (service level monitoring, invoice review, data protection/training), all eight numbered Recommendations with 's stated corrective actions, Appendix 1 (Objective, Scope, and Methodology), and Appendix 3 (Summary of the 's Corrective Actions, the table of expected completion dates and monetary benefits). Retrieved and hash-sealed directly from the 's own domain. fdicoig.gov · original document
  • Federal Deposit Insurance Corporation, Office of Inspector General, Report Waste, Fraud, & Abuse -- FDIC OIG Hotline (2026-07-21)The 's own public hotline page, fetched this iteration to source the call-to-action: phone number, mailing address, and online reporting portal for reporting fraud, waste, abuse, or mismanagement in programs and contractor operations -- the same office that produced AUD-26-02. fdicoig.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account