Skip to content

Six agencies would not show auditors what DOGE could see in their systems

The Government Accountability Office spent 18 months trying to check how DOGE teams accessed sensitive data. Most of its questions went unanswered.

By IQGov Editors

Cybersecurity, Report. 29 September 2026, 3 min read

The Government Accountability Office building in Washington
Photo: ajay_suresh / Wikimedia Commons, CC BY 2.0

Six US agencies failed to provide the records needed to judge whether Department of Government Efficiency (DOGE) staff properly accessed and protected government systems, the Government Accountability Office said in a report published on 29 September.

"Without the ability to examine the requested information, Congress and the public lack assurance that these agencies implemented controls needed to ensure DOGE team members appropriately secured information," the auditors wrote.

What auditors could find

The review, which ran from March 2025 to September 2026, covered the Consumer Financial Protection Bureau (CFPB), the Education Department, the National Oceanic and Atmospheric Administration (NOAA), the Securities and Exchange Commission (SEC), the Small Business Administration (SBA) and the Department of Veterans Affairs (VA). Four agencies reported giving DOGE teams access to more than 23 systems for contracts, grants, finance and personnel, Nextgov/FCW reported, but the full extent of that access could not be established.

At the CFPB, officials reported access to 19 systems. One DOGE team member could view, change and delete records in the bureau's main human resources system, and three had full access to a Microsoft system used to manage user access. Two had enough permissions to grant themselves or others access to supervision and enforcement systems, though the bureau said they did not.

Refusals

The SEC and NOAA disputed GAO's authority to conduct the review. Education cited litigation and privacy. The VA declined without explanation, and the SBA left requests unanswered. The CFPB called the review a "fishing expedition". GAO said the objections "do not alter or diminish" its statutory right of access, noting it routinely obtains and protects such information in other audits.

Access logs and permission records are the basic evidence of any security audit. When agencies cannot or will not produce them, the question is no longer only what DOGE did, but whether anyone can tell.

IQGov Editors

Newsroom, Online

Stories by the IQGov newsroom are researched and written by AI agents to our editorial rulebook, checked against their sources by a separate fact-checking agent, and approved by the publisher before publication. Every fact links to its source.

Keep reading

More Security

Liked this story? Get the Monday Briefing.

Weekly, free. Unsubscribe with one click.