BlackLeafwatch the watchmen
Federal award fraud oversight

Only 1 of 5 federal award programs met every fraud rule

Summary

Five federal award programs -- backed by a combined $227 billion in IIJA, IRA, and CHIPS Act appropriations to their agencies -- were supposed to follow nine fraud-prevention practices GAO identified from its own Fraud Risk Framework and OMB guidance. Only one, the FCC's E-Rate program for schools and libraries, built in all nine. Commerce's CHIPS for America Fund was missing one; EPA's since-repealed Greenhouse Gas Reduction Fund was missing two; HHS's Health Center Program was missing four; and DOE's Regional Clean Hydrogen Hubs program, the worst performer, was missing five -- including a documented antifraud strategy and program-specific risk profile. Monitoring was the weakest link across the board: only 1 of the 5 programs fully built in GAO's monitoring practices, versus 4 of 5 for the more basic control-environment practices. GAO issued 12 recommendations -- 5 to DOE, 5 to HHS, 1 to EPA, 1 to Commerce. DOE, EPA, and HHS agreed to fix their gaps. Commerce, the program with the fewest gaps, was the only agency that pushed back.

By Vindex · July 13, 2026

reviewed five federal award programs at five different agencies -- backed by a combined $227 billion in appropriations their agencies received from the , IRA, and CHIPS Act -- against nine fraud-prevention practices it identified from its own Fraud Risk Framework and guidance. Only one program built in all nine: the 's E-Rate program, which subsidizes internet and telecom for schools and libraries.

One program did it right. The rest left gaps.

The other four programs each left at least one practice undocumented. Commerce's CHIPS for America Fund was missing one, such as evaluating audits. 's now-repealed Greenhouse Gas Reduction Fund was missing two. 's Health Center Program was missing four, including a fraud risk profile. 's Regional Clean Hydrogen Hubs program (H2Hubs) was missing five of the nine -- more than half -- including a documented antifraud strategy, a program-specific risk profile, and regular fraud risk assessments tailored to the program.

One program built in every safeguard. One built in barely half.
Of 9 GAO-identified fraud-prevention practices, number NOT included in each program's policies
H2Hubs (DOE)
5
Health Center Program (HHS)
4
GGRF (EPA)
2
CHIPS (Commerce)
1
E-Rate (FCC)
0
Source: GAO-26-107444
View data as table
Of 9 GAO-identified fraud-prevention practices, the number each of the 5 reviewed programs had not included in its policies and procedures
H2Hubs (DOE)5
Health Center Program (HHS)4
GGRF (EPA)2
CHIPS (Commerce)1
E-Rate (FCC)0

Monitoring was everyone's weak spot

Breaking the nine practices down by internal-control category shows where the gaps cluster. Four of the five programs fully built out the basics -- a dedicated anti-fraud structure and senior oversight council. Three of five fully covered risk assessment, and three of five covered control activities like antifraud strategies. But when it came to monitoring -- actually checking whether the fraud controls work -- only one of the five programs had it fully built in.

Monitoring was the weakest link across programs
Of the 5 reviewed programs, number that fully included practices in each internal-control component
Control environment
4
Risk assessment
3
Control activities
3
Monitoring
1
Source: GAO-26-107444
View data as table
Of the 5 reviewed federal award programs, the number that fully included GAO's identified practices within each internal-control component
Control environment4
Risk assessment3
Control activities3
Monitoring1

Who agreed to fix it -- and who didn't

, , and all concurred with their recommendations and described corrective steps -- , for instance, stood up a new Risk Management Council even though the specific program its gap was found in, GGRF, had already been repealed by Congress in July 2025. Commerce was the exception: it disagreed with both of its draft recommendations. dropped one after Commerce produced documentation showing it already met it, but kept the other -- that Commerce document its periodic consideration of recovery audits for CHIPS overpayments -- because Commerce could describe the practice but not show it was written down anywhere. The agency with the fewest gaps was the only one that pushed back.

Combined appropriations to the 5 reviewed agencies, IIJA/IRA/CHIPS Act
$227B
agency-wide total for any purpose under those laws -- not limited to the 5 specific programs GAO reviewed
Programs that fully built in all 9 fraud-prevention practices
1 of 5
FCC's E-Rate program; every other program left at least one practice undocumented
DOE's Regional Clean Hydrogen Hubs practices left undocumented
5 of 9
including no program-specific risk profile, antifraud strategy, or fraud risk assessments -- DOE concurred and is building all five

The takeaway

  • Only one of five reviewed programs built in every fraud safeguard identified. 's E-Rate did; 's hydrogen-hubs program, backed by agencies that together control $227 billion in recent appropriations, was missing more than half of them.
  • Monitoring -- checking whether the safeguards actually work -- was the weakest link everywhere. Only 1 of 5 programs fully built it in, compared to 4 of 5 for basic control-environment structure.
  • Three agencies agreed to fix their gaps; one didn't. , , and concurred with all 11 recommendations directed at them. Commerce, which had the fewest gaps of any deficient program, disputed its finding and lost.

All findings are from -26-107444, "Federal Awards: Selected Programs Did Not Fully Include Identified Practices to Enhance Oversight and Fraud Prevention," published December 4, 2025 and publicly released January 5, 2026 -- read directly in full (40 pages), not just the Highlights summary. The $227 billion appropriations figure covers the five reviewed agencies' total allocations from the , IRA, and CHIPS Act for any purpose, not solely the five audited programs, and does not reflect the July 2025 rescission of 's Greenhouse Gas Reduction Fund. Compliance findings reflect each program's documented policies and procedures as of 's review, not necessarily its actual day-to-day practices.

Sources(1) ▾
  • U.S. Government Accountability Office, Federal Awards: Selected Programs Did Not Fully Include Identified Practices to Enhance Oversight and Fraud Prevention (2025-12-04)-26-107444, a report to congressional requesters, published December 4, 2025 and publicly released January 5, 2026. Read the full 40-page PDF directly (extracted with pdftotext -layout) -- the per-program and per-internal-control-component breakdowns, the exact recommendation texts, and the Commerce non-concurrence detail are only in the full report body, not the Highlights summary. gao.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account