The audit trail stopped at multiple agencies

GAO asked six agencies what systems their Department of Government Efficiency teams could access and what controls protected those systems. Four agencies provided access information; the Small Business Administration and Department of Veterans Affairs did not.

Only three agencies—CFPB, Education and SEC—provided control documentation, and GAO called it limited. NOAA, SBA and VA did not provide the requested control information.

Records supplied to GAO
Audit questionAgencies supplying informationAgencies not supplying it
Which systems were accessible?4 of 62 of 6
Were security controls followed?3 of 6, limited3 of 6
Systems identifiedMore than 23 at 4 agenciesExtent could not be determined
Sources: GAO-26-108192

Even the records received had holes

CFPB documented privacy briefings for six DOGE members but security training for four. Education supplied signed rules-of-behavior forms for five of six. SEC documented one background check in progress and another from 2017 without confirming favorable adjudication.

Those are documentation gaps, not findings that the named people misused data. GAO said it could not determine precise permissions, such as whether individuals could view personally identifiable information or modify data.

No documented assurance is not a documented breach

The four reporting agencies said DOGE teams had access to more than 23 systems handling contracts, grants, personnel and finances. GAO concluded Congress and the public lacked assurance that all six agencies implemented and followed controls.

GAO did not report a proven breach, unlawful disclosure or corrupted record. CFPB disputed the report’s accuracy; GAO said it stood by the facts. The other five agencies offered no comments.

Method

The newsroom built a response matrix from GAO’s system-access and control findings and separated absence of evidence from evidence of failure. GAO reviewed security rules, training, access documents and background-investigation materials.

The contribution is a denominator-based accountability finding: one-third of reviewed agencies withheld access records and half withheld control records, leaving the oversight question unresolved.

Photo update, September 30, 2026: An unrelated federal evidence photograph has been replaced with an identified Marine Corps server-room photograph. The replacement is illustrative and does not depict a system examined in this audit.

Sources and further reading

GAO: DOGE Systems and Data Protection ↗