BlackLeafwatch the watchmen
National Archives and Records Administration (NARA) -- information-technology asset accountability and property management

NARA's Own IT Inventory System Doesn't Know Who Has What

Summary

An inspector general evaluation of the National Archives' information-technology tracking system found that most of the more than 25,000 equipment records it reviewed listed no employee responsible for the device. The report also found the agency isn't reliably reconciling equipment against employees who have separated, isn't handing off custody of deployed equipment to the offices actually using it, and hasn't updated the property-management policy governing all of it since 2012.

By Frontinus · July 28, 2026

's own inspector general reviewed a full export of the system the National Archives and Records Administration uses to track its computers, servers and mobile devices, and found it can't reliably answer a basic question: who has the equipment. Of the over 25,000 asset records the OIG examined, more than 19,000 -- 78% -- had no value in the field showing which employee is responsible for the device.

A tracking system NARA inherited broken

The gap traces in part to a vendor handoff. A previous NARA IT support contractor's engagement ended in 2022, and the contractor did not provide a complete or accurate export of its IT asset data to the agency when it left. never established a timely process to verify the data it inherited was accurate, and the found the consequences three years later: beyond the missing user assignments, over 2,500 records were missing asset tags -- the unique identifiers needed to physically locate a device -- and some records were still assigned to employees who no longer work at the agency.

IT asset records reviewed
25,000+
Full export of NARA's Hardware Asset Management module, examined by the agency's inspector general
Missing an assigned user
78%
More than 19,000 of those records had no employee of record showing who has the device
Recommendations issued
10
Across five findings spanning inventory data, exit processing, asset transfers, sensitive-property rules and PAO training
Most of NARA's tracked IT equipment has no listed owner
Scale of data-quality gaps found in a full export of NARA's Hardware Asset Management (HAM) module
Total asset records reviewed
25,000
Missing an assigned user
19,000
Missing an asset tag
2,500
Source: NARA Office of Inspector General, Evaluation of NARA's Information Technology Inventory (26-R-03), February 25, 2026
View data as table
These are three separate counts from the same 25,000-plus-record export, not a breakdown that sums to the total -- a single asset record can be missing a tag, an assigned user, both, or neither. The OIG's own language ('over,' 'more than') reflects the report's precision; NARA's inventory system does not currently support an exact count.
Total asset records reviewed25,000Full HAM export reviewed by the OIG, described in the report as 'over 25,000' records
Missing an assigned user19,000'More than 19,000' records -- 78% of the total -- had no value in the field showing who has the device
Missing an asset tag2,500'Over 2,500' records lacked the unique tag needed to physically locate the device

Equipment doesn't get reconciled when employees leave

requires departing employees to file an electronic exit-clearance form, which is supposed to trigger a check that all government equipment has been returned. But the found no monthly reconciliation between those exit-clearance records and the asset-tracking system was actually happening. When investigators asked for copies of the reconciliations that should have run January through April 2025, officials acknowledged the vendor responsible hadn't been performing them, and said the practice wasn't planned to start until September 1, 2025 -- because the written procedure for doing it didn't exist in the first place.

Equipment stays parked under IT's own account, not the office using it

Every unit at designates a Property Accountable Officer (PAO) responsible for the equipment in its custody -- and, under agency policy, can be held personally financially liable if that property is lost or damaged. But the found that when Information Services issues a laptop or other device to an employee, it is not reassigning that equipment to the receiving office's PAO -- it stays parked under Information Services' own codes instead. Staff told investigators it was simply simpler that way. The found this happening at all four sites it checked: Archives I in Washington, Archives II in College Park, the National Personnel Records Center, and the Allegany Ballistics Laboratory. The effect is that the PAOs actually positioned to see and control the equipment day to day have no formal record that it's theirs to watch.

Government phones don't count as 'sensitive' property

Federal rules give a category of government property -- items like laptops and communications equipment -- extra layers of accountability as "sensitive personal property," specifically because of the risk if they're lost or misused. 's regulation defines that category to include IT and communications equipment with memory capability, "regardless of dollar value" -- the value threshold that otherwise governs which equipment has to formally account for is $3,000 per unit, so the sensitive-property category exists to catch cheaper devices that still carry outsized risk. 's own property policy specifically excludes government-issued cell phones from that sensitive-property designation, meaning the class of device most likely to walk out the door in a pocket gets less formal scrutiny than the policy intends.

That policy -- Directive 600, which governs all of this -- hasn't been updated since 2012. The also found has not published the annual training the directive itself requires for PAOs, nor established a recertification process -- so the employees personally on the hook for this equipment aren't consistently trained on how to manage it.

  • The reviewed a full export of 's Hardware Asset Management (HAM) module -- over 25,000 asset records -- and found more than 19,000 (78%) had no assigned employee listed, and over 2,500 were missing the physical asset tags needed to locate the device.
  • The data-quality gap traces partly to a 2022 contractor transition: the outgoing IT support vendor did not hand off a complete or accurate export of asset data, and never verified what it inherited.
  • has not been performing the monthly reconciliations meant to confirm departing employees returned their equipment; officials told the the practice wasn't planned to start until September 1, 2025, because no written procedure existed.
  • Information Services keeps deployed equipment under its own accountability codes rather than transferring it to the receiving office's Property Accountable Officer, at all four sites the checked -- Archives I, Archives II, the National Personnel Records Center, and the Allegany Ballistics Laboratory.
  • Government-issued cell phones are specifically excluded from 's 'sensitive personal property' category, even though 's regulation says IT and communications equipment with memory capability qualifies regardless of dollar value; the property policy itself hasn't been updated since 2012, and required annual training for accountable officers isn't being provided.
  • The issued ten recommendations across the five findings; had 30 days from the February 25, 2026 report to submit planned corrective actions and target completion dates.

This piece describes findings from a single evaluation by 's independent statutory Office of Inspector General, conducted under Quality Standards for Inspection and Evaluation, with fieldwork at Archives I and Archives II from March through August 2025 and issued February 25, 2026. The report frames every finding as a control or process gap -- inaccurate data, missing procedures, unclear policy responsibilities -- not as an allegation of fraud, theft, or misconduct by any named individual; no person is named in this piece as a wrongdoer. The report does not state a total dollar value for the equipment covered by these gaps, and this piece does not estimate one. As of this writing, 's public corrective-action response to the report's ten recommendations has not been separately published on the 's own site, so this piece describes the findings and 's committed 30-day response window, not a verified after-the-fact resolution.

Sources(2) ▾
  • National Archives and Records Administration, Office of Inspector General, Evaluation of NARA's Information Technology Inventory (OIG Report No. 26-R-03) (2026-02-25) 's evaluation of the completeness, accuracy and internal controls behind 's information-technology asset inventory, with fieldwork at Archives I (Washington, D.C.) and Archives II (College Park, MD) from March-August 2025. Evidences the Hardware Asset Management (HAM) module data-quality findings, the unperformed exit-clearance reconciliations, the PAO asset-transfer gap, the cell-phone sensitive-property gap, the PAO-training gap, the $3,000 accountable-property threshold, and the ten recommendations. Published directly on 's own oversight.gov-hosted domain (naraoig.oversight.gov), which is the official Inspectors General portal operated by . naraoig.oversight.gov · original document
  • National Archives and Records Administration, Office of Inspector General, Evaluation of NARA's Information Technology Inventory -- report landing page (2026-02-25) 's official report index entry confirming the report number (26-R-03), issue date (February 25, 2026), report type (Inspection/Evaluation), scope (Agency Wide) and the canonical link to the PDF above -- used to verify the primary document is the issuer's own official copy. naraoig.oversight.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account