Only 1 of 5 federal award programs met every fraud rule
Summary
Five federal award programs -- backed by a combined $227 billion in IIJA, IRA, and CHIPS Act appropriations to their agencies -- were supposed to follow nine fraud-prevention practices GAO identified from its own Fraud Risk Framework and OMB guidance. Only one, the FCC's E-Rate program for schools and libraries, built in all nine. Commerce's CHIPS for America Fund was missing one; EPA's since-repealed Greenhouse Gas Reduction Fund was missing two; HHS's Health Center Program was missing four; and DOE's Regional Clean Hydrogen Hubs program, the worst performer, was missing five -- including a documented antifraud strategy and program-specific risk profile. Monitoring was the weakest link across the board: only 1 of the 5 programs fully built in GAO's monitoring practices, versus 4 of 5 for the more basic control-environment practices. GAO issued 12 recommendations -- 5 to DOE, 5 to HHS, 1 to EPA, 1 to Commerce. DOE, EPA, and HHS agreed to fix their gaps. Commerce, the program with the fewest gaps, was the only agency that pushed back.
One program did it right. The rest left gaps.
The other four programs each left at least one practice undocumented⧉. Commerce's CHIPS for America Fund was missing one, such as evaluating audits. 's now-repealed Greenhouse Gas Reduction Fund was missing two. 's Health Center Program was missing four, including a fraud risk profile. 's Regional Clean Hydrogen Hubs program (H2Hubs) was missing five of the nine -- more than half -- including a documented antifraud strategy, a program-specific risk profile, and regular fraud risk assessments tailored to the program.
View data as table
| H2Hubs (DOE) | 5 |
|---|---|
| Health Center Program (HHS) | 4 |
| GGRF (EPA) | 2 |
| CHIPS (Commerce) | 1 |
| E-Rate (FCC) | 0 |
Monitoring was everyone's weak spot
Breaking the nine practices down by internal-control category shows where the gaps cluster. Four of the five programs⧉ fully built out the basics -- a dedicated anti-fraud structure and senior oversight council. Three of five fully covered risk assessment, and three of five covered control activities like antifraud strategies. But when it came to monitoring -- actually checking whether the fraud controls work -- only one of the five programs had it fully built in.
View data as table
| Control environment | 4 |
|---|---|
| Risk assessment | 3 |
| Control activities | 3 |
| Monitoring | 1 |
Who agreed to fix it -- and who didn't
, , and all concurred with their recommendations⧉ and described corrective steps -- , for instance, stood up a new Risk Management Council even though the specific program its gap was found in, GGRF, had already been repealed by Congress in July 2025. Commerce was the exception: it disagreed with both of its draft recommendations. dropped one after Commerce produced documentation showing it already met it, but kept the other -- that Commerce document its periodic consideration of recovery audits for CHIPS overpayments -- because Commerce could describe the practice but not show it was written down anywhere. The agency with the fewest gaps was the only one that pushed back.
The takeaway
- Only one of five reviewed programs built in every fraud safeguard identified. 's E-Rate did; 's hydrogen-hubs program, backed by agencies that together control $227 billion in recent appropriations, was missing more than half of them.
- Monitoring -- checking whether the safeguards actually work -- was the weakest link everywhere. Only 1 of 5 programs fully built it in, compared to 4 of 5 for basic control-environment structure.
- Three agencies agreed to fix their gaps; one didn't. , , and concurred with all 11 recommendations directed at them. Commerce, which had the fewest gaps of any deficient program, disputed its finding and lost.
All findings are from -26-107444, "Federal Awards: Selected Programs Did Not Fully Include Identified Practices to Enhance Oversight and Fraud Prevention," published December 4, 2025 and publicly released January 5, 2026 -- read directly in full (40 pages), not just the Highlights summary. The $227 billion appropriations figure covers the five reviewed agencies' total allocations from the , IRA, and CHIPS Act for any purpose, not solely the five audited programs, and does not reflect the July 2025 rescission of 's Greenhouse Gas Reduction Fund. Compliance findings reflect each program's documented policies and procedures as of 's review, not necessarily its actual day-to-day practices.
Sources(1) ▾
- U.S. Government Accountability Office, Federal Awards: Selected Programs Did Not Fully Include Identified Practices to Enhance Oversight and Fraud Prevention (2025-12-04) — -26-107444, a report to congressional requesters, published December 4, 2025 and publicly released January 5, 2026. Read the full 40-page PDF directly (extracted with pdftotext -layout) -- the per-program and per-internal-control-component breakdowns, the exact recommendation texts, and the Commerce non-concurrence detail are only in the full report body, not the Highlights summary. gao.gov · original document
Comments
Always open. Logged-in readers can annotate paragraphs in place.
reviewed five federal award programs at five different agencies -- backed by a combined $227 billion in appropriations⧉ their agencies received from the , IRA, and CHIPS Act -- against nine fraud-prevention practices it identified from its own Fraud Risk Framework and guidance. Only one program built in all nine⧉: the 's E-Rate program, which subsidizes internet and telecom for schools and libraries.