BlackLeafwatch the watchmen
SBIR/STTR Small Business Research Program Fraud and Foreign-Risk Oversight

The government may have paid twice for small-business research

Summary

SBIR and STTR pay small businesses more than $4 billion a year to do federally funded research. Two 2024 GAO reports tested that money for two different kinds of exposure. The first found 842 of 10,570 tested awardees tripped four or more of GAO's 27 fraud, waste, and abuse indicators, and $445 million went to awardees for research that may have already been funded elsewhere -- the single largest dollar total in any eligibility category GAO tested. The second, on the newer foreign-influence screening mandate, found three agencies -- EPA, DHS, and NASA -- still have no documented process for how their program offices request or receive the classified counterintelligence findings they say they already use to vet applicants.

By Nero · July 12, 2026

The Small Business Innovation Research and Small Business Technology Transfer programs pay small companies more than $4.4 billion a year in federal research money. Two 2024 reports tested that spending for two different kinds of exposure. One found 842 of 10,570 tested awardees tripped four or more of 's 27 fraud, waste, and abuse risk indicators, and that $445 million -- the largest dollar total in any category tested -- went to awardees for research that may have already been funded elsewhere. The other found that three of the program's 11 participating agencies still have no documented process for how they request or share the classified counterintelligence findings they say they already rely on to screen applicants for foreign ties.

Nearly every eligibility rule GAO tested turned up money that shouldn't have gone out

turns 44 this year: since its 1982 start, federal agencies have made more than 180,000 awards worth about $61.6 billion; , launched in 1992, has made more than 18,000 awards worth $6.4 billion more. In fiscal year 2022 alone, the program's 11 participating agencies -- , Commerce, Defense, Education, Energy, Health and Human Services, Homeland Security, Transportation, , , and the National Science Foundation -- handed out over 6,500 awards worth $4.4 billion to more than 4,000 small businesses. The Small Business Act requires to review the program every four years; its September 2024 report is the fourth.

built 27 analytic tests -- covering things like conflicts of interest, principal investigators listed on suspiciously many awards, and foreign ownership -- and ran them against 10,570 awardees from fiscal years 2016 through 2021. Only 1,842 awardees, about 17 percent, cleared every test cleanly. The rest tripped at least one; 842 of them, about 8 percent, tripped four or more, a threshold treats as signaling elevated risk warranting further review.

8 percent of awardees tripped four or more of GAO's 27 fraud tests
SBIR/STTR awardees (fiscal years 2016-2021) by number of GAO analytic tests that flagged fraud, waste, or abuse risk
0 tests flagged
1,842
1 test flagged
3,744
2 tests flagged
2,878
3 tests flagged
1,264
4 or more tests flagged
842
Source: GAO-24-105470, Figure 16, p.80
View data as table
Awardees by number of fraud-risk analytic tests flagged, FY2016-2021 (of 10,570 total)
0 tests flagged1,842
1 test flagged3,744
2 tests flagged2,878
3 tests flagged1,264
4 or more tests flagged842

's separate review of publicly reported fraud cases -- convictions, civil settlements, and administrative actions from fiscal years 2016 through 2023 -- found 37 distinct fraud schemes tied to 43 individuals and 36 businesses: 18 schemes ended in criminal action, 22 in civil action, and 9 in administrative action, with some schemes producing more than one type of outcome. In one illustrative case, a man and two businesses he owned won seven / awards from the Army, Air Force, DARPA, the Missile Defense Agency, , and the Department of Energy, then subcontracted sensitive work to engineers in Venezuela despite certifying that only U.S. citizens or permanent residents working at U.S. facilities would perform it. He was sentenced to 32 months in prison; both businesses were placed on three years' probation; all three defendants were ordered to pay $2.9 million in restitution.

The biggest dollar total wasn't caught fraud -- it was duplicate funding

also tested awards data directly against five specific eligibility rules: an applicant can't be more than 50 percent foreign-owned, can't exceed 500 employees, must list a principal investigator primarily employed by the business, must list a real research facility address, and can't receive funding twice for essentially the same research. Every rule turned up money at risk. Text-mining awardee abstracts for duplicated language, flagged 280 awardees -- across 10 of the 11 agencies -- with potentially essentially equivalent work funded more than once, totaling about $445 million. That is more than the dollars flagged in any of the other four categories combined with foreign ownership, and more than triple the amount tied to potentially ineligible facility addresses.

Every eligibility rule GAO tested turned up money that shouldn't have gone out
Dollars awarded to potentially ineligible SBIR/STTR applicants, by rule violated (fiscal years 2016-2021 awardees)
Essentially equivalent work already funded (280 awardees)
445
Potentially ineligible facility address (157 awardees)
157
Business exceeds 500-employee size limit (42 awardees)
117
Principal investigator employment overlap (117 awardees)
95
Potential foreign ownership (18 awardees)
34.3
Source: GAO-24-105470, pp.60-71
View data as table
Dollars to potentially ineligible SBIR/STTR applicants, by category (millions)
Essentially equivalent work already funded (280 awardees)445
Potentially ineligible facility address (157 awardees)157
Business exceeds 500-employee size limit (42 awardees)117
Principal investigator employment overlap (117 awardees)95
Potential foreign ownership (18 awardees)34.3

The address test showed how thin the program's verification runs. Using only the address .gov had on file, flagged 157 awardees, worth about $157 million, with addresses the U.S. Postal Service listed as undeliverable or vacant. 's criminal investigators then physically visited 17 of the flagged addresses tied to 12 awardees -- and confirmed only 3 as genuine independent office suites. The rest turned out to be a vacant lot, an address that appears not to exist, a government facility with no sign of the business, two mailboxes inside shared office suites with no physical presence, a private home, and several more without confirmable business activity. Neither the Policy Directive nor the statute requires agencies to verify an applicant's address at all; most rely solely on the applicant's own certification.

Paid to SBIR/STTR awardees for research GAO's own text analysis flagged as potentially already funded elsewhere
$445M
went to 280 of 10,570 awardees GAO tested -- the largest dollar total in any of GAO's five eligibility-vulnerability categories
Of 10,570 fiscal-year 2016-2021 awardees flagged with four or more fraud, waste, or abuse risk indicators, across GAO's 27 analytic tests
842
about 8 percent of all awardees tested; only 1,842 (17 percent) triggered zero of the 27 tests
Of the 11 SBIR/STTR agencies still lack a documented process for requesting or sharing classified counterintelligence findings used in foreign-risk screening
3 of 11
EPA, DHS, and NASA all told GAO they already use counterintelligence analysis to vet applicants -- without a written procedure for how that information reaches the program office

As of April 2023, only three of the 11 participating agencies -- Energy, Homeland Security, and Health and Human Services, through five agency subcomponents -- had conducted any /-specific fraud risk assessment at all, the practice 's own Fraud Risk Framework treats as foundational. Agencies told they lacked staff, training, and clear guidance from on how to do one; , for its part, said detailed fraud risk assessment guidance isn't required by the statute and pointed agencies toward their own inspectors general instead. made eight recommendations in this report -- six to , one to , one to -- and all three agencies agreed to act on them.

Congress ordered a foreign-ties check in 2022. Three agencies still can't document how theirs works.

A separate, newer mandate governs a different risk: foreign government access to the research itself. The and Extension Act of 2022 required every participating agency to stand up, by June 27, 2023, a due diligence program screening applicants for ties to a 'foreign country of concern' -- defined in the statute as China, North Korea, Russia, Iran, or any other country the Secretary of State designates -- across cybersecurity practices, patents, employee affiliations, and foreign ownership. All 11 agencies met that deadline, and 's November 2024 follow-up report found the screening working as intended in specific instances.

The National Institutes of Health denied an award after determining an undisclosed principal investigator had likely received funding from a Chinese 'malign talent recruitment program'; the National Science Foundation denied an award to an applicant that had raised significant investment from a Chinese firm and generated revenue through a Chinese subsidiary; the Air Force denied an award after finding an applicant held patents filed with a Chinese government-affiliated university and had concealed funding from a Chinese venture capital firm; and Homeland Security denied an award to an applicant with overseas offices, including in Hong Kong, that had major cybersecurity deficiencies.

Other findings ended differently. discovered an applicant had received a small equity investment from a company partly owned by a Chinese government-owned aerospace and defense corporation -- and decided it could manage that risk with increased monitoring, then made the award anyway. found that a key project staffer had failed to disclose foreign relationships as recently as 2020; the applicant removed that person after raised the issue, and the award went forward.

Six of the 11 agencies -- the Air Force, , , , , and -- told they lean on their agency's own counterintelligence office, including classified sources, to help make these calls. Only three of those six -- the Air Force, , and -- have a documented process describing how that classified information reaches the program office making the award decision. At , found the gap had already produced an unresolved internal disagreement: the counterintelligence office said staff handling its information needed Top Secret clearance, while the program office said no one there had needed that clearance level so far -- a disagreement nobody had reason to formally resolve, because there was no documented process requiring them to.

Half the agencies using classified intelligence to screen applicants can't show how
SBIR/STTR participating agencies, by counterintelligence-analysis practice in foreign-risk due diligence (as of August 2024)
Use CI analysis, process documented (Air Force, NIH, DOE)
3
Use CI analysis, process undocumented (EPA, DHS, NASA)
3
Do not use CI analysis in due diligence
5
Source: GAO-25-107402, p.21
View data as table
11 SBIR/STTR participating agencies, by counterintelligence-analysis documentation status
Use CI analysis, process documented (Air Force, NIH, DOE)3
Use CI analysis, process undocumented (EPA, DHS, NASA)3
Do not use CI analysis in due diligence5

's conclusion was procedural, not accusatory: without written agreements on how the program office and the counterintelligence office share information, decisions rest on institutional memory held by a handful of people rather than a documented, repeatable process. recommended , , and each document their procedures for requesting and sharing analytical support, including classified information, with their counterintelligence offices. All three agencies concurred.

The takeaway

  • Nearly every eligibility rule tested turned up money at risk, and the single biggest dollar total wasn't caught fraud -- it was duplicate funding. $445 million went to 280 awardees for research 's text analysis flagged as potentially already funded elsewhere, more than the dollar totals tied to ineligible addresses, oversized businesses, or overlapping principal investigators.
  • 's combined analytic testing flagged 8 percent of awardees -- 842 of 10,570 -- with four or more fraud, waste, or abuse risk indicators, while only 17 percent of awardees cleared all 27 tests cleanly. As of 2023, only 3 of the 11 participating agencies had conducted any /-specific fraud risk assessment at all.
  • Congress's 2022 foreign-risk screening mandate is producing real denials -- , , and the Air Force have all turned away applicants over specific China-related ties, and separately denied one over cybersecurity gaps at an applicant with overseas offices including in Hong Kong -- but three of the 11 agencies running that screening, , , and , still have no documented process for how the classified intelligence behind such decisions actually reaches the people making them.

Fraud-scheme, analytic-test, and eligibility-vulnerability figures are from -24-105470, 'Small Business Research Programs: Opportunities Exist for and Agencies to Reduce Vulnerabilities to Fraud, Waste, and Abuse' (September 9, 2024). Foreign-risk due-diligence and counterintelligence-documentation figures are from a separate, later review: -25-107402, 'Small Business Research Programs: Agencies Identified Foreign Risks, but Some Due Diligence Programs Lack Clear Procedures' (November 21, 2024). Both were read directly. The two reports examine distinct risks to the same program -- financial fraud and waste versus foreign-influence security screening -- and share only the general fiscal year 2022 award-volume figures cited in both; no other figure in this piece is treated as confirmed by both unless sourced to both.

Sources(2) ▾
  • U.S. Government Accountability Office, Small Business Research Programs: Opportunities Exist for SBA and Agencies to Reduce Vulnerabilities to Fraud, Waste, and Abuse (2024-09-09)'s fourth statutory review (required every 4 years) of the / small-business federal R&D grant programs, focused on fraud, waste, and abuse vulnerabilities. Direct gao.gov PDF access returns HTTP 403; read via the Wayback Machine capture. gao.gov · original document
  • U.S. Government Accountability Office, Small Business Research Programs: Agencies Identified Foreign Risks, but Some Due Diligence Programs Lack Clear Procedures (2024-11-21)Second in a report series (mandated by the and Extension Act of 2022) on agencies' foreign-risk due-diligence programs for / applicants. Direct gao.gov PDF access returns HTTP 403; read via the Wayback Machine capture. gao.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account