Library of Congress OIG Withheld 3 of 9 Reports From the Public
Summary
The Library of Congress's own Office of Inspector General, in its Semiannual Report to Congress dated September 30, 2025, says it completed reviews of the Library's preparedness for a physical attack on the Thomas Jefferson, James Madison, and John Adams buildings and of its systems disaster-recovery compliance -- and withheld both, plus a separate advisory on theft risk in the Library's gold collections, from public release 'because of the sensitive nature of the information.' The Library's own FY2025 reports index confirms none of the three carries a downloadable report, while the other six reports OIG issued the same period do.
Nine reports, three findings the public never sees
's semiannual report to Congress lists all nine reports its Office of Audits issued in the period, each with a report number, an issue date, and a paragraph describing what was tested. Six read like any other inspector-general finding -- a leave-tracking system with data-variance controls, a teaching program's cooperative-agreement paperwork, a fiduciary-fund audit -- because six are public. The other three each end in the identical line: '[w]e are not providing specific information about the findings because of the sensitive nature of the information contained in the report. The report was not issued for public release.'
What OIG will say, and won't
On the physical-attack review (Report No. 2024-SP-103, completed July 2025), says the Library's preparedness 'is heavily dependent on the United States Capitol Police, which is responsible for protecting Library entrances and assuming overall incident command during an emergency' -- and that management concurred with all six of the report's recommendations. On the disaster-recovery review (Report No. 2024-IT-103, completed August 2025), names IT Modernization as a standing top management challenge and says management concurred with all four recommendations for recovering Library IT systems and meeting related NIST controls. Neither report says what the recommendations actually call for.
View data as table
| Released publicly | 6 | GovTA controls, Teaching with Primary Sources, fiduciary fund audit, FY2024 financial statements audit, COR best-practices audit, Surplus Books evaluation |
|---|---|---|
| Withheld from public release | 3 | Systems disaster-recovery compliance, physical-attack preparedness, Asian Division gold-collections security |
A third finding never got a public report at all
The third withheld item isn't even a full report -- it's a Management Advisory Memorandum, a faster-track tool for flagging urgent risks outside the normal audit cycle. issued it in April 2025 'to notify management of a heightened risk of theft in the Asian Division as part of our ongoing evaluation of the Library's gold collections' -- items the report defines elsewhere as holdings 'that have significant value, are rare, or are unique.' The advisory carries no recommendation count and, like the other two, was never issued for public release.
The Library's own FY2025 OIG reports index⧉, a page maintained separately from the semiannual report PDF, corroborates the split: the same three titles appear there tagged 'Not for Public Release' with no document link, while the other six reports the semiannual report names from the same window each carry a working PDF.
No public mechanism tracks whether any of it gets fixed
's semiannual report includes a standing 'Unimplemented Recommendations' table that tracks, report by report, whether Library management has closed out prior findings. But says plainly that the table covers only 'recommendations made in our publicly released reports.' The six recommendations from the withheld physical-attack review and the four from the withheld disaster-recovery review are not eligible for that table -- meaning there is no public record, now or in a future semiannual report, that would tell Congress or the public whether the Library's Capitol Police coordination gaps or IT recovery gaps ever get closed. 's own introduction states its general practice is that '[r]eports are available at www.loc.gov/about/oig' -- making these three the exception, not the rule.
- 's Office of Audits issued nine reports in the six months ending September 30, 2025; three -- covering physical-attack preparedness, IT disaster recovery, and Asian Division gold-collection theft risk -- were withheld from public release entirely.
- Library management concurred with all six recommendations in the withheld physical-attack review and all four in the withheld disaster-recovery review; discloses the counts but not what the recommendations require.
- The Library's own FY2025 reports index, a separate page from the semiannual report, corroborates that the same three titles carry no downloadable report while the other six from the same period do.
- 's public 'Unimplemented Recommendations' follow-up table tracks only publicly released reports, so there is no public mechanism to verify whether the Library ever implements the ten recommendations attached to the two withheld audits.
This piece describes what the Library of Congress's inspector general itself discloses about its own reporting practice -- which reports it withholds and why it says it withholds them. It does not reproduce, and the 's own semiannual report does not disclose, the substantive findings inside any of the three non-public reports; nothing here characterizes an actual security vulnerability beyond what 's own public summary states.
Sources(2) ▾
- Library of Congress Office of the Inspector General, Library of Congress Office of the Inspector General Semiannual Report to Congress, September 2025 (period ending September 30, 2025) (2025-09-30) — The 's statutory semiannual report to Congress covering April 1-September 30, 2025. Its 'Audits, Evaluations, and Reviews' section (pp. 7-9) itemizes all nine reports the Office of Audits issued in the period by report number, date, and one-paragraph summary. Three of the nine -- the Systems Disaster Recovery Compliance evaluation (No. 2024-IT-103), the Preparedness for Physical Attack evaluation (No. 2024-SP-103), and the Management Advisory Memorandum on the Asian Division's gold collections (No. 2025-SP-101) -- each carry the identical line 'We are not providing specific information about the findings because of the sensitive nature of the information contained in the report/advisory. The report/advisory was not issued for public release.' The report also states (p. 15) that its public 'Unimplemented Recommendations' follow-up table covers only recommendations made in publicly released reports. loc.gov · original document
- Library of Congress Office of the Inspector General, Library of Congress OIG Reports Index -- Fiscal Year 2025 (Issued October 1, 2024-September 30, 2025) (2026-07-21) — The Library's own running index of reports issued in FY2025, maintained as a separate webpage from the semiannual report PDF. It lists the same three titles named in the September 2025 semiannual report -- Systems Disaster Recovery Compliance, Preparedness for Physical Attack, and the Asian Division security advisory -- each tagged '(Not for Public Release)' with no document link, while the other six reports the semiannual report names from the same six-month window each carry a working PDF link on this same index. Independent corroboration, from a second LoC-maintained page, that these three specific reports remain withheld. loc.gov · original document
Comments
Always open. Logged-in readers can annotate paragraphs in place.
The Library of Congress's own Office of Inspector General⧉ issued nine audits, evaluations, and reviews in the six months ending September 30, 2025 -- and withheld three of them from the public entirely. One evaluated the Library's readiness for a physical attack on the Thomas Jefferson, James Madison, and John Adams buildings. A second tested whether the Library could recover its IT systems after a disaster. A third flagged a heightened theft risk in the Asian Division's gold collections. 's own report gives the recommendation counts and says management agreed to fix all of them -- but declines to say what, specifically, is broken.