Neither of the Merchant Marine Academy's misconduct trackers works
Summary
The U.S. Merchant Marine Academy at Kings Point operates under two separate congressional mandates to track student misconduct: one for sexual assault and harassment claims, one for honor and conduct violations. In December 2024, DOT's Inspector General found MARAD still hadn't built the information management system the fiscal year 2023 NDAA required for the Academy's Sexual Assault Prevention and Response Program -- USMMA was using a spreadsheet instead, one the Academy's own Superintendent said didn't meet its needs, missing required data fields and lacking basic cybersecurity and privacy controls. About a year later, GAO's December 2025 cross-service-academy review found the same underlying problem in the Academy's separate honor and conduct system: incomplete data collection across multiple stages, unclear guidance on evidentiary rights, and a 25-year-old database that officials say they can't query without going through an outside contractor.
A 2023 law, a spreadsheet instead
The fiscal year 2023 National Defense Authorization Act required to build a proper information management system for USMMA's Sexual Assault Prevention and Response (SAPR) Program by January 1, 2023, so that assault and harassment claims involving cadets could be tracked in a way that let patterns be identified. 's Inspector General found that, nearly two years past that deadline, had done no such thing: the SAPR Program was instead using a spreadsheet, which USMMA's own Superintendent acknowledged didn't meet the Academy's operational needs.
View data as table
| Categories required by the NDAA | 6 |
|---|---|
| Fully tracked in the spreadsheet | 4 |
Every cybersecurity control category came up short
The spreadsheet's problems went beyond missing data fields. 's Inspector General assessed the system against six cybersecurity control categories required by federal standards -- access control, encryption, data integrity, audit logging, data exfiltration protection, and backup -- and found every one deficient. Staff who didn't need it, including IT personnel who might not even work at the Academy, had read/write access to sexual assault victims' claims, and the monthly account reviews required to catch and remove that kind of access hadn't been conducted. The network drive holding the spreadsheet wasn't encrypted. There was no audit logging, no data-loss-prevention software, and no special backup protections for the sensitive files. 's own Privacy Officer had never even analyzed the system to determine what privacy protections it needed.
View data as table
| Control categories assessed | 6 |
|---|---|
| Found deficient | 6 |
The Inspector General made four recommendations -- securing the data, completing the required fields, implementing interim cybersecurity controls, and finishing a privacy impact analysis. concurred with all four and provided completion dates; the recommendations remain open pending that work.
A year later: the other tracking system, the same gap
's December 2025 review of honor and conduct systems across all five service academies found USMMA's separate misconduct-tracking system -- for honor-code violations and conduct offenses, not sexual assault -- had parallel problems. USMMA doesn't collect data on three specific stages of its conduct process: investigations, the method used to adjudicate a case, and the use of remediation as a disciplinary outcome. On evidentiary rules, USMMA's guidance -- like several other academies' -- doesn't clearly specify what kinds of evidence, including hearsay, are admissible in honor hearings, even though officials say hearsay is in practice allowed.
USMMA officials also told they can't directly access their own historical conduct data. Instead, they have to go through an outside contractor who manages the database -- a database says is 25 years old, which officials said makes it hard to query directly. USMMA has identified a replacement system but, as of the report, had not set a timeline for putting it in place.
Two systems, seven promised fixes
made 13 recommendations across all five academies; three were directed specifically at the Secretary of Transportation for the Merchant Marine Academy -- clarify the honor and conduct system's due-process guidance, identify and document a complete set of data-collection requirements for every stage of the process, and set a timeline for fixing the data-access problems. The Department of Transportation concurred with all three. Combined with the four SAPR-system recommendations 's own Inspector General made a year earlier, that's seven recommendations across two entirely separate, congressionally mandated tracking systems at the same Academy -- and all seven have been accepted, not disputed.
View data as table
| DOT OIG, SAPR information system (Dec. 2024) | 4 |
|---|---|
| GAO, honor/conduct system, USMMA-specific (Dec. 2025) | 3 |
The takeaway
- Two different congressionally mandated systems, the same underlying failure. A spreadsheet standing in for a legally required information system on sexual assault claims, and a 25-year-old database that officials can't query directly for honor and conduct cases -- a year apart, two watchdogs found USMMA's data infrastructure isn't built to do what the law asks of it.
- The SAPR system's problems go past missing fields. Every one of the six cybersecurity control categories 's Inspector General checked came back deficient, on a system holding sexual assault survivors' claims -- and 's own Privacy Officer had never assessed what privacy protections it needed.
- Both agencies said yes to every fix -- accountability now rests on follow-through. and concurred with all seven recommendations across the two reports. None have been reported as completed; the SAPR recommendations remain open pending action, and USMMA's honor/conduct data-access fix still has no stated timeline.
Findings on USMMA's Sexual Assault Prevention and Response Program spreadsheet system, its NDAA-mandated data requirements, its cybersecurity and privacy deficiencies, and 's response are from Report IT2025013, ' Has Not Established a Compliant Information Management System for USMMA's Sexual Assault Prevention and Response Program' (December 4, 2024), read directly in full from the Inspector General's website. Findings on USMMA's honor and conduct system's data-collection gaps, due-process guidance, database age, and 's response are from -26-107049, 'Service Academies: Clarifying Guidance Would Enhance Effectiveness of Honor and Conduct Systems' (December 2025), read directly in full via an archived copy after the current gao.gov asset URL blocked direct access; that report also covers West Point, the Naval Academy, the Air Force Academy, and the Coast Guard Academy, and only its Merchant Marine Academy-specific findings are used here. The two reports examine two separate, congressionally mandated tracking systems at the same institution about a year apart -- one on sexual assault and harassment claims, the other on honor and conduct violations -- and find the same underlying data-infrastructure gap in both.
Sources(2) ▾
- U.S. Department of Transportation, Office of Inspector General, MARAD Has Not Established a Compliant Information Management System for USMMA's Sexual Assault Prevention and Response Program (2024-12-04) — Report IT2025013, a mandated cybersecurity/compliance audit finding had not built the information management system NDAA FY2023 required for the U.S. Merchant Marine Academy's (USMMA) Sexual Assault Prevention and Response (SAPR) Program, using an informal spreadsheet instead -- the SAPR-system facet. Distinct from doc-gao26-107049 (the honor/conduct-system facet, published about a year later, finding the same kind of data-tracking gap in a separate, also congressionally mandated USMMA system). Direct fetch of this PDF URL succeeded (HTTP 200). oig.dot.gov · original document
- U.S. Government Accountability Office, Service Academies: Clarifying Guidance Would Enhance Effectiveness of Honor and Conduct Systems (2025-12-16) — -26-107049, a cross-service-academy review (West Point, Naval, Air Force, Coast Guard, Merchant Marine) of honor and conduct systems, including USMMA-specific findings on unclear due-process guidance, incomplete honor/conduct data collection, and a 25-year-old database USMMA officials say they cannot query directly -- the honor/conduct-system facet, published about a year after doc-oig-it2025013's SAPR-system warning. Direct gao.gov PDF fetch returns HTTP 403; fetched in full via an archived copy. gao.gov · original document
Comments
Always open. Logged-in readers can annotate paragraphs in place.
The U.S. Merchant Marine Academy, at Kings Point, New York, operates under two separate congressional mandates requiring it to properly track student misconduct: one covering sexual assault and harassment claims, the other covering honor and conduct violations. In December 2024⧉, 's Inspector General audited the first system. About a year later⧉, audited the second, as part of a review covering all five U.S. service academies.