The Offices of Audit and Evaluation supervise and conduct independent and objective audits, evaluations, and other reviews of U.S. Department of Housing and Urban Development (HUD) programs and activities to ensure they operate economically, efficiently, and effectively. This page contains links to our audit and evaluation reports and memoranda.
The OIG evaluated the U.S. Department of Housing and Urban Development’s (HUD) progress in applying zero trust security principles to protect personally identifiable information (PII). HUD maintained a significant number of records that contain PII with limited zero trust controls in place to secure these data. In FY 2022, HUD established a zero trust implementation plan to help the agency address the five zero trust…
December 12, 2024
Report
#2023-OE-0007
The OIG evaluated the U.S. Department of Housing and Urban Development (HUD) Office of Housing’s (Housing) progress in applying zero trust security principles to protect personally identifiable information (PII) within the Federal Housing Administration (FHA) Catalyst system.HUD was in the beginning stages of implementing zero trust requirements for the data and identity pillars. HUD Office of Housing systems, including FHA Catalyst,…
October 31, 2024
Report
#2023-OE-0007a
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to…
October 29, 2024
Report
#2024-OE-0002
The Geospatial Data of 2018 (the Act) governs the collection, production, acquisition, maintenance, distribution, use, and preservation of geospatial data of covered agencies, including the U.S. Department of Housing and Urban Development (HUD). We audited the U.S. Department of Housing and Urban Development’s (HUD) efforts to meet the geospatial data requirements stated in the Act. The Act requires the Inspector…
September 20, 2024
Report
#2024-LA-0002
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation to…
January 29, 2024
Report
#2023-OE-0001
The U.S. Department of Housing and Urban Development (HUD) program offices issued departmental notices to inform public housing agencies (PHA) and owners of the Consolidated Appropriations Act of 2021’s (the Act) requirements. In addition, HUD program offices planned to use HUD’s revised physical inspection processes to ensure that PHAs and owners complied with the Act, namely under its new National Standards for the Physical…
October 26, 2023
Report
#2022-OE-0004
We audited the Philadelphia Housing Authority’s (Authority) management of lead‐based paint in its public housing program based on our assessment of the risks of lead‐based paint in public housing agencies’ (PHA) housing developments. The risk factors included the age of buildings, the number of units, household demographics, reported cases of childhood lead poisoning, and reports of missing lead‐based paint inspections in HUD’s data…
March 22, 2023
Report
#2023-CH-1001
According to the Centers for Disease Control and Prevention (CDC), lead-based paint and lead-contaminated dust are some of the most widespread and hazardous sources of lead exposure for young children in the United States. There is no safe blood lead level in children, and there is no cure for lead poisoning. Therefore, it is important to prevent exposure to lead, especially among children.
U.S. Department of Housing…
February 28, 2023
Report
#2021-OE-0011b
We conducted this evaluation to assess the maturity of HUD’s Robotic process automation (RPA) activities and determine whether HUD had implemented related controls to address technology and program management risks. RPA is a software technology used to emulate human actions on a computer. RPA software programs, referred to as “bots,” can complete repetitive tasks quickly and consistently, freeing up employees to work on…
February 17, 2023
Report
#2021-OE-0007
We audited the U.S. Department of Housing and Urban Development’s (HUD) information technology (IT) infrastructure to support mandatory telework. During mandatory telework, more employees simultaneously needed remote access to HUD’s network and agency resources for an extended period, which presented unique risks and security requirements. While HUD is no longer operating under mandatory telework, understanding the challenges it faced…
January 24, 2023
Report
#2023-FO-0008
HUD established procedures in the Lead Safe Housing Rule in 1999 to eliminate lead-based paint hazards, as far as practicable, in public housing. However, it did not have a plan to manage lead-based paint and lead-based paint hazards in public housing. Additionally, HUD generally did not monitor whether public housing agencies had implemented lead-based paint hazard reduction and documented the activities at their public…
October 11, 2022
Report
#2023-CH-0001
The Federal Information Security Modernization Act of 2014 (FISMA) directs Inspectors General to conduct an annual evaluation of the agency information security program. FISMA, Department of Homeland Security (DHS), Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) establish information technology (IT) security guidance and standards for Federal agencies. We conducted this evaluation…
September 30, 2022
Report
#2022-OE-0001
We audited the U.S. Department of Housing and Urban Development’s (HUD) efforts to meet the Geospatial Data Act of 2018 (the Act).Our audit objective was to determine whether HUD met the 13 responsibilities stated in the Act with regard to its collection, production, acquisition, maintenance, distribution, use, and preservation of geospatial data. The Act also generally requires covered agencies provide access to geospatial data…
September 30, 2022
Report
#2022-LA-0004
We reviewed the U.S. Department of Housing and Urban Development’s (HUD) ability to effectively complete information technology (IT) acquisitions. HUD’s IT systems and its modernization plans depend heavily on contractors, yet HUD has historically faced significant challenges with implementing effective acquisition processes. Therefore, HUD’s acquisition capacity represents a key potential risk within HUD’s IT environment. We…
November 17, 2021
Report
#2020-OE-0004
In February 2021, the Office of the Chief Information Officer (OCIO) identified funding risks with the development contract under which HUD contracted for Federal Housing Administration (FHA) Catalyst’s development. In response, HUD officials took steps to slow FHA Catalyst spending on the contract while awaiting approval for additional contract funds. Despite efforts to slow project spending, it was not enough to prevent…
November 17, 2021
Memorandum
#2021-OE-0003a