Skip to main content
U.S. flag

An official website of the United States government

Government Website

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Safely connect using HTTPS

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Audits, Inspections, and Evaluations

Report Number Title Issue Date Sort ascending Fiscal Year
OIG-21-64 FEMA did not have reliable data to inform allocation decisions and ensure accurate adjudication of resource requests, it did not have a process to allocate the limited supply of PPE, and FEMA’s strategic documents did not clearly outline roles and responsibilities to lead the Federal response.  We made three recommendations that FEMA improve the reliability of WebEOC, formally document the policies and procedures for allocating critical lifesaving supplies and equipment, and that FEMA work with the Secretary of Health and Human Services to clarify the agencies’ pandemic response roles and responsibilities under Stafford Act declarations.  FEMA concurred with all three recommendations which remain open and resolved.

>Lessons Learned from FEMA's Initial Response to COVID-19
OIG-21-65 Summary: Rescue 21 Alaska, Coast Guard’s maritime search and rescue communication system, has experienced outages resulting from antiquated equipment in Coast Guard’s District 17.  Challenges and funding shortages during system acquisition caused Coast Guard to limit the purchase of new equipment for Rescue 21 Alaska, requiring District 17 to maintain existing equipment for longer than initially planned.  Alaska’s winter weather conditions and remote access to communication site locations cause lengthy repair times, further exacerbating the outage impacts.  The outages have prevented Coast Guard, at times, from effectively receiving and responding to distress calls from mariners.  Coast Guard has made some upgrades to the Rescue 21 Alaska system to enhance distress communication availability and reliability.  Although Coast Guard plans for further upgrades, outages persist.  When notifying the public about the outages, Coast Guard primarily relies on a “Local Notice to Mariners” posted on their public website.  However, this limits who can receive the notices, as not all mariners go to the internet to determine outage locations.  Alaska mariners shared other effective methods Coast Guard could use to improve its notifications to the public when there are known VHF distress communications outages.  Adequately upgrading the communications equipment and ensuring robust attempts are made to notify the public when outages occur is essential for Coast Guard to achieve its search and rescue mission in Alaska.  We made two recommendations to ensure the Coast Guard is prioritizing Rescue 21 Alaska upgrades and appropriately notifying the public of outages. Coast Guard concurred with both recommendations.

>Coast Guard Should Prioritize Upgrades to Rescue 21 Alaska and Expand Its Public Notifications during Outages
OIG-21-62 CBP officials had legitimate reasons for placing lookouts on American journalists, attorneys, and others suspected of organizing or being associated with the migrant caravan.  However, many CBP officials were unaware of CBP’s policy related to placing lookouts and, therefore, may have inadvertently placed lookouts on these Americans, which did not fully comport with the policy.  Additionally, CBP officials did not remove lookouts promptly once they were no longer necessary and, as a result, subjected some of these U.S. citizens to repeated and unnecessary secondary inspections.  During the same time period, a CBP official requested that Mexico deny entry to caravan associates, including 14 Americans.  Unlike CBP’s legitimate reasons for placing lookouts on these U.S. citizens, CBP had no genuine basis for requesting Mexico to deny entry to these individuals.  On several other occasions throughout Operation Secure Line, other CBP officials also improperly shared the names and sensitive information of U.S. citizens with Mexico.  We made six recommendations that will improve CBP’s controls on placing and removing lookouts and sharing Americans’ sensitive information with foreign countries.  CBP concurred with all six recommendations.

>CBP Targeted Americans Associated with the 2018-2019 Migrant Caravan
OIG-21-61 During our unannounced inspection of Otay Mesa in San Diego, California, we identified violations of ICE detention standards that compromised the health, safety, and rights of detainees.  Otay Mesa complied with standards for classification and generally provided sufficient medical care to detainees.  In addressing COVID-19, Otay Mesa did not consistently enforce precautions including use of facial coverings and social distancing.   Overall, we found that Otay Mesa did not meet standards for grievances, segregation, or staff-detainee communications.  Specifically, Otay Mesa did not respond timely to detainee grievances and did not forward staff misconduct grievances to ICE as required.  In addition, Otay Mesa was not consistently providing required services for detainees in segregation including access to recreation, legal calls, laundry, linen exchange, mail, legal materials, commissary, and law library.  Further, ICE did not consistently respond to detainee requests timely and did not specify times for visits with detainees.  Finally, we determined the declining detainee population at Otay Mesa caused ICE to pay more than $22 million for unused bed space under a guaranteed minimum contract.  We made seven recommendations to ICE’s Executive Associate Director of Enforcement and Removal Operations to ensure the San Diego ERO Field Office overseeing Otay Mesa addresses identified issues and ensures facility compliance with relevant detention standards.  ICE concurred with six recommendations and non-concurred with one recommendation.

>Violations of ICE Detention Standards at Otay Mesa Detention Center
OIG-21-60 U.S. Customs and Border Protection (CBP) does not conduct COVID-19 testing for migrants who enter CBP custody and is not required to do so.  Instead, CBP relies on local public health systems to test symptomatic individuals.  According to CBP officials, as a frontline law enforcement agency, it does not have the necessary resources to conduct such testing.  For migrants that are transferred or released from CBP custody into the United States, CBP coordinates with DHS, U.S. Immigration and Customs Enforcement, U.S. Department of Health and Human Services, and other Federal, state, and local partners for COVID-19 testing of migrants.  In addition, although DHS generally follows guidance from the Centers for Disease Control and Prevention for COVID-19 preventative measures, the DHS’ multi-layered COVID-19 testing framework does not require CBP to conduct COVID-19 testing at CBP facilities.  Further, DHS’ Chief Medical Officer does not have the authority to direct or enforce COVID-19 testing procedures.  We recommended DHS reassess its COVID-19 response framework to identify areas for improvement to mitigate the spread of COVID-19 while balancing its primary mission of securing the border.  Additionally, we recommended DHS ensure the components continue to coordinate with the DHS Chief Medical Officer and provide available resources needed to operate safely and effectively during the COVID-19 pandemic and any future public health crisis.  We made two recommendations to improve DHS’ response to COVID-19 at the southwest border.  DHS concurred with both recommendations.

>DHS Needs to Enhance Its COVID-19 Response at the Southwest Border
OIG-21-59 CISA cannot demonstrate how its oversight has improved Dams Sector security and resilience because CISA has not coordinated or tracked its Dams Sector activities, updated overarching national critical infrastructure or Dams Sector plans, and collected and evaluated performance information on Dams Sector activities.  Furthermore, we found that CISA does not consistently provide information to FEMA to help ensure its assistance addresses the most pressing needs of the Dams Sector.  CISA and FEMA also do not coordinate their flood mapping information.  Finally, CISA does not effectively use the Homeland Security Information Network Critical Infrastructure Dams Portal to provide external Dams Sector Stakeholders with critical information.  We recommended that CISA update the Dams Sector-Specific Plan, its internal organization structures, and establish performance metrics to determine its impact on the Dams Sector.  We also recommended it coordinate with FEMA on its grants and flood mapping systems.  Finally, we recommended CISA implement a strategy to use the HSIN-CI Dams portal to its fullest potential.  We made five recommendations to update CISA’s Sector-Specific Plan, internal organization structures, and coordination with FEMA that, when implemented, will improve dam security and resilience.  CISA concurred with all five recommendations.

>CISA Can Improve Efforts to Ensure Dam Security and Resilience
OIG-21-58 ICE has taken various actions to prevent the pandemic’s spread among detainees and staff at their detention facilities. At the nine facilities we remotely inspected, these measures included maintaining adequate supplies of PPE such as face masks, enhanced cleaning, and proper screening for new detainees and staff. However, we found other areas in which detention facilities struggled to properly manage the health and safety of detainees. For example, we observed instances where staff and detainees did not consistently wear face masks or socially distance. In addition, we noted that some facilities did not consistently manage medical sick calls and did not regularly communicate with detainees regarding their COVID-19 test results. Although we found that ICE was able to decrease the detainee population to help mitigate the spread of COVID-19, information on detainee transfers was limited. We also found that testing of both detainees and staff was insufficient, and that ICE headquarters did not generally provide effective oversight of their detention facilities during the pandemic. Overall, ICE must resolve these issues to ensure it can meet the challenges of not only the COVID-19 pandemic, but future pandemics as well. We made six recommendations to improve ICE’s management of COVID-19 in its detention facilities. ICE concurred with all six recommendations.

>ICE’s Management of COVID-19 in Its Detention Facilities Provides Lessons Learned for Future Pandemic Responses
OIG-21-57  Although ICE had controls in place that required Capgemini Government Solutions, LLC to provide qualified labor, ICE did not properly construct or monitor the contract.  This occurred because ICE awarded a firm-fixed-price contract but required a labor-hour performance measurement to monitor and track work hours, which was not appropriate for this type of contract.  The contractor also did not provide the number of staff ICE required for specific labor categories.  As a result, ICE cannot ensure it received all services, and it overpaid $769,869 in labor costs.  Finally, ICE did not ensure the contractor met statement of work requirements for staff skill sets, education, and work experience, nor did it ensure all contractor staff worked at the designated place of performance

>ICE's Oversight of the Capgemini Contract Needs Improvement
OIG-21-55 Since our FY 2020 evaluation, the Office of Intelligence and Analysis (I&A) has continued to provide effective oversight of the department-wide intelligence system and has implemented programs to monitor ongoing security practices.  We determined that DHS' information security program for Top Secret/Sensitive Compartmented Information intelligence systems is effective this year as the Department achieved “Level 4 – Managed and Measurable” in three of five cybersecurity functions, based on current reporting instructions for intelligence systems.  However, we identified deficiencies in DHS’ protect and recover functions.  We made three recommendations to I&A to address the deficiencies identified, and I&A concurred with all three recommendations.

>Evaluation of DHS' Compliance with Federal Information Security Modernization Act Requirements for Intelligence Systems for Fiscal Year 2020 - Secret
OIG-21-56 We identified deficiencies in E-Verify’s processes for confirming identity during employment verification.  E-Verify’s photo matching process is not fully automated, but rather, relies on employers to confirm individuals’ identities by manually reviewing photos.  We attribute these deficiencies to USCIS not developing or evaluating the plans and internal controls needed to improve its processes and detect, track, and investigate system errors.  Until USCIS addresses E-Verify’s deficiencies, it cannot ensure the system provides accurate employment eligibility results.  We made 10 recommendations to improve E-Verify’s accuracy, internal controls, and workload capabilities.  USCIS concurred with all 10 recommendations.

>USCIS Needs to Improve Its Electronic Employment Eligibility Verification Process
OIG-21-54 FEMA did not use its SFM initiative to ensure that Public Assistance (PA) funds were obligated in accordance with Federal, Department, and component requirements.  Specifically, FEMA obligated PA funds for 83 projects from fiscal years 2017 through 2019 that we reviewed, even though the subrecipients did not need the funding until after 180 days, which made them eligible for incremental obligation under SFM.  This occurred because FEMA did not provide adequate oversight to its Regions.  FEMA relied on the Regions’ decisions to determine whether subrecipients’ projects were eligible for SFM funding, without ensuring there was sufficient supporting documentation to validate the determinations.  This increases the risk of projects being over obligated.  As a result, FEMA is not meeting the intent of SFM, which is to better manage resources in the Disaster Relief Fund to fulfill present and future disaster funding requirements.  We made two recommendations that, when implemented, should improve FEMA’s management and oversight of the Disaster Relief Fund.  FEMA concurred with the recommendations. 

>FEMA Prematurely Obligated $478 Million in Public Assistance Funds from FY 2017 through FY 2019
OIG-21-53 CBP did not effectively manage its aviation fleet acquisitions to meet operational mission needs.  Specifically, AMO acquired and deployed 16 multi-role enforcement aircraft (MEA) that did not contain the necessary air and land interdiction capabilities to perform its mission.  In addition, CBP AMO initiated the MEA and medium lift helicopter program without well-defined operational requirements and key performance parameters — critical items in the acquisition planning process.  This occurred because CBP did not provide oversight and guidance to ensure acquisition personnel followed key steps required by the DHS Acquisition Lifecycle Framework.  As a result, AMO expended approximately $330 million procuring multi-role enforcement aircraft that, at the time of acceptance, did not effectively respond to emergent air threats along the northern or southern borders, and experienced schedule delays deploying the medium lift helicopter.  Without effective oversight and guidance, AMO risks aviation acquisitions taking longer to deliver, at a greater cost, and without the needed capabilities.  We made four recommendations aimed at improving CBP’s acquisition management of aviation fleet to meet operational needs.  CBP concurred with three of the four recommendations. 

>U.S. Customs and Border Protection's Acquisition Management of Aviation Fleet Needs Improvement to Meet Operational Needs
OIG-21-52 TSA partially complied with the Act by establishing operational processes for routine activities within its Explosives Detection Canine Team (EDCT)  program for surface transportation.  Specifically, TSA has a national training program for canines and handlers, uses canine assets to meet urgent security needs, and monitors and tracks canine assets.  However, TSA did not comply with the Act’s requirements to evaluate the entire EDCT program for alignment with its risk-based security strategy or develop a unified deployment strategy for its EDCTs for surface transportation.  We recommended that TSA coordinate with its law enforcement agency partners to conduct an evaluation of the EDCT program and develop an agency-wide deployment strategy for surface transportation consistent with TSA's Surface Transportation Risk-Based Security Strategy.  TSA concurred with both recommendations.   

>TSA Did Not Assess Its Explosives Detection Canine Team Program for Surface Transportation Security
OIG-21-50 FEMA did not ensure Louisiana adequately managed and provided oversight of PA grants to make certain they complied with Federal regulations.  Specifically, Louisiana had a backlog of 600 incomplete projects beyond their approved completion dates.  We attributed this to the State not conducting regular site visits to assess subrecipients’ ongoing projects, identify and resolve issues as they arose, or ensure prompt project completion.  In addition, FEMA had a backlog of 2,150 completed grant projects it had not closed out due to inadequate oversight of its Region 6 staff to ensure they promptly carried out this responsibility.  As of the fourth quarter of 2018, the combined backlog of 2,750 grant projects represented nearly $6.6 billion in obligated funds.  By May 2020, FEMA had reduced the backlog, but the significant number of remaining projects could lead to delays reimbursing applicants as well as deobligating funds that could be put to better use.  We made three recommendations to FEMA to strengthen its oversight of project completion and closeout processes to ensure they are timely and compliant.  FEMA concurred with one recommendation and did not concur with two.  However, FEMA’s responses resulted in all three recommendations being considered open and unresolved.

>Inadequate FEMA Oversight Delayed Completion and Closeout of Louisiana's Public Assistance Projects
OIG-21-51 In FY 2018, S&T did not always adhere to DHS and internal purchase card policies and procedures.  Of 421 purchase card transactions selected for review, we identified 394 transactions that did not have required supporting documentation, separation of key transaction duties, approvals and other required signatures, or compliance with other risk-based procedures.  According to S&T officials, these issues were due to shortfalls in program oversight and training, as well as outdated policy.  We identified $63,213 in questionable costs associated with purchase card transactions.  We made four recommendations to improve S&T’s adherence to DHS policies and procedures for its Bankcard Program.  S&T concurred with the four recommendations. 

>FY 2018 Audit of Science and Technology Bankcard Program Indicates Risks
OIG-21-49 We found Border Patrol provided adequate medical assistance to the mother and her newborn, and complied with applicable policies. However, we found that Border Patrol’s data about pregnant detainees is limited and the agency lacks the necessary processes and guidance to reliably track childbirths that occur in custody. In addition, our review of a sample of childbirths in custody showed Border Patrol did not always take prompt action to expedite the release of U.S. citizen newborns, resulting in some being held in stations for multiple days and nights. Although some of these instances may have been unavoidable, Border Patrol needs reliable practices to expedite releases because holding U.S. citizen newborns at Border Patrol stations poses health, safety, and legal concerns. Lastly, we found that Border Patrol agents do not have guidelines on interpreting for Spanish-speaking detainees at hospitals. As a result, an agent assigned to hospital watch for the detainee provided interpretation that may not have comported with CBP’s language access guidance. We made four recommendations to improve CBP’s processes for tracking detainee childbirths, its practices for expediting release of U.S. citizen newborns, and its guidance to agents on providing interpretation for detainees. CBP concurred with all four recommendations

>Review of the February 16, 2020 Childbirth at the Chula Vista Border Patrol Station
OIG-21-48 CBP needs better oversight and policy to adequately safeguard migrants experiencing medical emergencies or illnesses along the southwest border.  According to CBP’s policies, once an individual is in custody, CBP agents and officers are required to conduct health interviews, and “regular and frequent” “welfare checks” to identify individuals who may be experiencing serious medical conditions.  However, CBP could not always demonstrate staff conducted required medical screenings or consistent welfare checks for all 98 individuals whose medical cases we reviewed.  This occurred because CBP did not provide sufficient oversight and clear policies and procedures, or ensure officers and agents were adequately trained to implement medical support policies.  As a result, CBP may not identify individuals experiencing medical emergencies or provide appropriate care in a timely manner.  CBP concurred with all three of our recommendations, which when implemented, should improve medical attention and procedures for migrants at the southwest border. 

>CBP Needs to Strengthen Its Oversight and Policy to Better Care for Migrants Needing Medical Attention
OIG-21-47 CBP did not always protect MPC apps from cybersecurity threats.  This occurred because app version updates were not always scanned for vulnerabilities and CBP did not always identify vulnerabilities detected in scans.  CBP also did not complete seven required security and privacy compliance reviews of MPC apps because it did not establish a schedule for the reviews or track and centrally store review documentation.  In addition, CBP did not obtain the information needed for the reviews, had competing priorities, and did not ensure app developers created a process for a required internal audit.  Finally, CBP did not implement Department server configuration requirements for its MPC servers.  We made eight recommendations that, when implemented, should improve the security of CBP’s MPC program.  CBP concurred with all eight recommendations.

>CBP Has Placed Travelers' PII at Risk of Exploitation
OIG-21-45 DHS issued notices to appear (NTA), to MPP participants that were mostly accurate and in accordance with laws and regulations.  However, some NTAs were completed inaccurately.  Specifically, of our sample of 106 NTAs from February 2019 through April 2020, U.S. Customs and Border Protection (CBP) served 20 that did not meet legal sufficiency standards or contained inaccurate information.  However, CBP agents and officers documented proactively issuing 105 of 106 NTAs in our sample in person before returning migrants to Mexico.  If CBP serves a legally insufficient NTA, U.S. Immigration and Customs Enforcement cannot prosecute its removal case if a migrant fails to appear for the initial hearing.  Serving NTAs by mail to migrants in Mexico could result in migrants missing their hearings or the Government’s cases being dismissed or challenged.  We recommended that CBP’s Executive Director of the Office of Field Operations’ Admissibility and Passenger Programs and the Deputy Chief of Border Patrol’s Law Enforcement Operations Directorate develop procedures for quality control and supervisory review of NTAs for MPP enrollees to better ensure that officers and agents fill out the NTAs accurately and completely.  We made one recommendation to improve the accuracy and completeness of NTAs issued to MPP participants.  CBP non-concurred with the recommendation due to it being overcome by events when the program was terminated by the Secretary of Homeland Security on June 1, 2021.  We administratively closed the recommendation.

>CBP Generally Provided Accurate Notices to Appear to Migrant Protection Protocols Enrollees, but Could Improve Procedures to Reduce Future Errors
OIG-21-46 During our unannounced inspection of Adams in Natchez, Mississippi, we identified violations of ICE detention standards that threatened the health, safety, and rights of detainees.  Although Adams generally provided sufficient medical care, we identified one case in which the medical unit examined a sick detainee but did not send the detainee to the hospital for urgent medical treatment, and the detainee died.  We also found the medical unit did not document outcomes of detainee sick calls or ensure proper review and follow-up of detainee test results.  In addressing COVID-19, Adams took some measures to prevent the spread of COVID-19, but detainees did not consistently follow some guidelines, including use of facial coverings and social distancing, which may have contributed to repeated COVID-19 transmissions.  Adams did not meet standards for classification, grievances, segregation, or staff-detainee communications.  Specifically, we discovered a low custody detainee comingled with higher custody detainees, and found the facility did not always identify detainees with special vulnerabilities or those requiring translation services.  Adams also did not respond timely to detainee grievances and was not consistently providing required care for detainees in segregation including access to recreation, legal calls, laundry, linen exchange, mail, legal materials, commissary, law library, and to ICE forms and drop-boxes for detainees to make requests.  In addition, ICE did not consistently respond to detainee requests timely.  Finally, we determined the declining detainee population at Adams resulted in ICE paying more than $17 million for unused bed space under a guaranteed minimum contract.  We made seven recommendations to ICE’s Executive Associate Director of Enforcement and Removal Operations (ERO) to ensure the New Orleans ERO Field Office overseeing Adams addresses identified issues and ensures facility compliance with relevant detention standards.  ICE concurred with all seven recommendations.

>Violations of ICE Detention Standards at Adams County Correctional Center
OIG-21-43 FEMA has not prioritized compliance with the DMA 2000.  According to FEMA officials, the agency has instead focused on immediate needs of disaster operations and other high- profile initiatives necessary to carry out its mission.  As such, FEMA has not published regulations and related policies as required by the Robert T. Stafford Disaster Relief and Emergency Assistance Act (Stafford Act) to reduce repetitive damages to facilities, including the Nation’s roads and bridges.  We made four recommendations to FEMA, including that FEMA should prioritize the DMA 2000 by addressing the unresolved implementation issues and publishing a regulation as required. 

>FEMA Has Not Prioritized Compliance with the Disaster Mitigation Act of 2000, Hindering Its Ability to Reduce Repetitive Damages to Roads and Bridges
OIG-21-44 Specifically, in reviewing 16 contract files, we found files that did not have relevant Federal tax information, were missing information on the contractor’s past performance evaluations, and contained incomplete and inconsistent documentation.  We attribute these deficiencies to FEMA not providing guidance on procedures for implementing Federal regulations to contracting personnel, and the Department of Homeland Security removing guidance from its acquisition manual that is used by component personnel.  As a result of inadequate guidance, FEMA personnel awarded contracts without making fully informed determinations as to whether prospective contractors could meet contract demands.  If contractors cannot meet demands, FEMA may have to cancel contracts it has awarded, which has happened in the past and continues.  In fact, between March and May 2020, FEMA awarded and canceled at least 22 contracts, valued at $184 million, for crucial supplies in response to the national COVID-19 pandemic.  By awarding contracts without ensuring prospective contractors can meet contract demands, FEMA will continue wasting taxpayer dollars and future critical disaster and pandemic assistance will continue to be delayed.  We made one recommendation that, when implemented, should help strengthen FEMA’s responsibility determination process.  The Department concurred with our recommendation. 

>FEMA Must Strengthen Its Responsibility Determination Process
OIG-21-42 FEMA’s Intergovernmental Service Agreement (IGSA) with the Texas General Land Office (TxGLO) was appropriate to ensure direct housing assistance program compliance with applicable laws and regulations.  However, FEMA initiated the IGSA without first developing the processes and controls TxGLO needed to administer the program.  As a result, FEMA and the State had to develop and finalize implementation guidelines after signing the IGSA, delaying TxGLO’s disaster response.  In addition, FEMA disaster personnel had to prepare the necessary guidance, toolkits, and training resources while simultaneously responding to Hurricane Harvey.  Also, FEMA used workarounds and TxGLO set up a separate system, creating additional operational challenges and inefficiencies.  We made three recommendations to improve future state administered direct housing assistance efforts.  FEMA concurred with all three recommendations. 

>FEMA Initiated the Hurricane Harvey Direct Housing Assistance Agreement without Necessary Processes and Controls
OIG-21-41 We determined that FEMA followed applicable laws, regulations, and guidance in its efforts to provide funding for reconstruction of the Vieques’ Community Health Center.  FEMA’s assessment of the funding needs for the project is complete and $39,569,695 (Federal share) was obligated on January 21, 2020 for a full facility replacement.  We did not make any recommendations but announced an audit to assess FEMA’s Public Assistance Program Alternative Procedures process for all permanent work projects.

>FEMA's Efforts to Provide Funds to Reconstruct the Vieques Community Health Center
OIG-21-40 U.S. Immigration and Customs Enforcement (ICE) did not adequately identify and track human trafficking crimes.  Specifically, ICE Homeland Security Investigations (HSI) did not accurately track dissemination and receipt of human trafficking tips, did not consistently take follow-up actions on tips, and did not maintain accurate data on human trafficking. These issues occurred because HSI did not have a cohesive approach for carrying out its responsibilities to combat human trafficking. We made one recommendation to improve ICE’s coordination and human trafficking efforts to assist victims. ICE concurred with our recommendation.

>ICE Faces Challenges in Its Efforts to Assist Human Trafficking Victims
OIG-21-38 We determined DHS had not yet strengthened its cybersecurity posture by implementing a Continuous Diagnostics and Mitigation (CDM) Program.  DHS spent more than $180 million between 2013 and 2020 to design and deploy a department-wide continuous monitoring solution but faced setbacks.  DHS initially planned to deploy its internal CDM solution by 2017 using a “One DHS” approach that restricted components to a standard set of common tools.  We attributed DHS’ limited progress to an unsuccessful initial implementation strategy, significant changes to its deployment approach, and continuing issues with component data collection and integration.  As of March 2020, DHS had developed a key element of the program, its internal CDM dashboard.  However, the dashboard contained less than half of the required asset management data.  As a result, the Department cannot leverage intended benefits of the dashboard to manage, prioritize, and respond to cyber risks in real time.  Finally, we identified vulnerabilities on CDM servers and databases.  This occurred because DHS did not clearly define patch management responsibilities and had not yet implemented required configuration settings.  Consequently, databases and servers could be vulnerable to cybersecurity attack, and the integrity, confidentiality, and availability of the data could be at risk.  We made three recommendations for DHS to update its program plan, address vulnerabilities, and define patch management responsibilities

>DHS Has Made Limited Progress Implementing the Continuous Diagnostics and Mitigation Program
OIG-21-39 We determined that the Transportation Security Administration (TSA) did not manage the Recruitment and Hiring (R&H) contract in a fiscally responsible manner.  Specifically, TSA did not properly plan contract requirements prior to awarding the contract and did not develop accurate cost estimates for all contract modifications.  We recommended TSA establish a cross-functional requirements working group for planning and awarding the R&H re-compete efforts as well as other Personnel Futures Program contract requirements.  The working group should develop a holistic and forward-thinking acquisition strategy, as well as implement a comprehensive process for reviewing and determining requirements.  We also recommended TSA ensure Human Capital improves contract management activities including, but not limited to, requirements planning and realistic cost estimate development by obtaining additional expert resources or leveraging existing expertise.  We made two recommendations to improve TSA’s contract management.  TSA concurred with both recommendations.

>TSA Needs to Improve Its Oversight for Human Capital Contracts
OIG-21-37 We determined that DHS needs to improve the collection and management of data across its multiple components to better serve and safeguard the public.  The data access, availability, accuracy, completeness, and relevance issues we identified presented numerous obstacles for DHS personnel who did not have essential information they needed for decision making or to effectively and efficiently carry out day-to-day mission operations.  Although DHS has improved its information security program and developed plans to improve quality and management of its data, follow through and continued improvement will be essential to address the internal control issues underlying the data deficiencies highlighted in the report.  We made no recommendations in the summary report.

>Persistent Data Issues Hinder DHS Mission, Programs, and Operations
OIG-21-36 We determined that before July 12, 2018, migrant parents did not consistently have the opportunity to reunify with their children before removal.  Although DHS and ICE have claimed that parents removed without their children chose to leave them behind, there was no policy or standard process requiring ICE officers to ascertain, document, or honor parents’ decisions regarding their children.  As a result, from the time the Government began increasing criminal prosecutions in July 2017, ICE removed at least 348 separated parents without documenting whether those parents wanted to leave their children in the United States.  In fact, ICE removed some parents without their children despite having evidence the parents wanted to bring their children back to their home country.  In addition, we found that some ICE records purportedly documenting migrant parents’ decisions to leave their children in the United States were significantly flawed.  We made two recommendation that will ensure ICE documents separated migrant parents’ decisions regarding their minor children upon removal from the United States, and develops a process to share information with Government officials to contact parents for whom ICE lacks documentation on reunification preferences.  ICE concurred with our recommendations.

>ICE Did Not Consistently Provide Separated Migrant Parents the Opportunity to Bring Their Children upon Removal
OIG-21-35 We determined DHS law enforcement components did not consistently collect DNA from arrestees as required.  Of the five DHS law enforcement components we reviewed that are subject to these DNA collection requirements, only Secret Service consistently collected DNA from arrestees.  U.S. Immigration and Customs Enforcement (ICE) and the Federal Protective Service inconsistently collected DNA, and U.S. Customs and Border Protection (CBP) and the Transportation Security Administration (TSA) collected no DNA.  DHS did not adequately oversee its law enforcement components to ensure they properly implemented DNA collection.  Based on our analysis, we project the DHS law enforcement components we audited did not collect DNA for about 212,646, or 88 percent, of the 241,753 arrestees from fiscal years 2018 and 2019.  Without all DHS arrestees’ DNA samples in the Federal Bureau of Investigation’s criminal database, law enforcement likely missed opportunities to receive investigative leads based on DNA matches.  Additionally, DHS did not benefit from a unity of effort, such as sharing and leveraging processes, data collection, and best practices across components.  We recommended DHS oversee and guide its law enforcement components to ensure they comply with collection requirements.  DHS concurred with all four of our recommend.

>DHS Law Enforcement Components Did Not Consistently Collect DNA from Arrestees
OIG-21-34 We determined that U.S. Customs and Border Protection (CBP) and Border Patrol headquarters officials were only aware of a few of the 83 CBP employees’ cases of social media misconduct.  CBP and Border Patrol senior officials only responded to one of those cases, upon direction from DHS.  In contrast, the senior Office of Field Operations (OFO) headquarters leader issued guidance to remind OFO employees of acceptable use of social media.  With regard to the posts media outlets published in July 2019, we found no evidence that senior CBP headquarters or field leaders were aware of them until they were made public by the media.  We also found some senior leaders questioned the legality or the application of CBP policies, which may undermine CBP’s ability to enforce the policies.  We made two recommendations to help reduce the incidence of social media misconduct.  First, we recommended the Commissioner ensures CBP uniformly applies social media misconduct policies, and establishes social media training for new recruits and annual refresher training for all employees.  CBP concurred with all recommendations.

>CBP Senior Leaders' Handling of Social Media Misconduct
OIG-21-33 We determined DHS did not comply with Payment Integrity Information Act of 2019 (PIIA)  in fiscal year 2020 because it did not achieve and report an improper payment rate of less than 10 percent for 2 of 12 programs reported in its FY 2020 Agency Financial Report.  DHS complied with Executive Order 13520 by properly compiling and making available to the public its FY 2020 Quarterly High-Dollar Overpayment reports.  We made two recommendations to DHS to follow Office of Management and Budget requirements and ensure the Federal Emergency Management Agency continues its remediation process to reduce improper payments.  DHS concurred with both recommendations. 

>Department of Homeland Security's FY 2020 Compliance with the Payment Integrity Information Act of 2019 and Executive Order 13520, Reducing Improper Payments
OIG-21-32 During our unannounced inspection of Pulaski County Jail, we identified violations of U.S. Immigration and Customs Enforcement (ICE) detention standards that threatened the health, safety, and rights of detainees.  In addressing COVID-19, Pulaski did not consistently enforce precautions including use of facial coverings and social distancing, which may have contributed to repeated COVID-19 transmissions at the facility.  Pulaski did not meet standards for classification, medical care, segregation, or detainee communication.  We found that the facility was not providing a color-coded visual identification system based on the criminal history of detainees, causing inadvertent comingling of a detainee with significant criminal history with detainees who had no criminal history.  The facility generally provided sufficient medical care, but did not provide emergency dental services and the medical unit did not have procedures in place for chronic care follow-up.  We also found that the facility was not consistently providing required oversight for detainees in segregation by conducting routine wellness checks.  Finally, we found deficiencies in staff communication practices with detainees.  Specifically, ICE did not specify times for staff to visit detainees and could not provide documentation that it completed facility visits with detainees during the pandemic.  We did find that Pulaski generally complied with the ICE detention standard for grievances.  We made five recommendations to ICE’s Executive Associate Director of Enforcement and Removal Operations (ERO) to ensure the Chicago ERO Field Office overseeing Pulaski addresses identified issues and ensures facility compliance with relevant detention standards.  ICE concurred with all five recommendations. 

>Violations of ICE Detention Standards at Pulaski County Jail
OIG-21-31 Under 40 U.S.C. § 1315, DHS had the legal authority to designate and deploy DHS law enforcement officers from CBP, ICE and United States Secret Service to help the Federal Protective Service protect Federal facilities in Portland, Oregon.  However, DHS was unprepared to effectively execute cross-component activities to protect Federal facilities when component law enforcement officers first deployed on June 4, 2020.  Specifically, not all officers completed required training; had the necessary equipment; or used consistent uniforms, devices, and operational tactics when responding to the events in Portland.  This occurred because DHS did not have a comprehensive strategy that addressed the potential for limited state and local law enforcement assistance, and cross-designation policies, processes, equipment, and training requirements.  We made two recommendations to improve DHS’ preparedness for protecting Federal property.  DHS concurred with both recommendations.

>DHS Had Authority to Deploy Federal Law Enforcement Officers to Protect Federal Facilities in Portland, Oregon, but Should Ensure Better Planning and Execution in Future Cross-Component Activities
OIG-21-30 Violations of Detention Standards Amidst COVID-19 Outbreak at La Palma Correctional Center in Eloy, AZ 2021
OIG-21-18 CBP Needs Additional Oversight to Manage Storage of Illicit Drugs (REDACTED) 2021
OIG-21-29 DHS' Fragmented Approach to Immigration Enforcement and Poor Planning Resulted in Extended Migrant Detention during the 2019 Surge 2021
OIG-21-27 We determined that U.S Customs and Border Protection’s (CBP) mail inspection processes and physical security at the John F. Kennedy (JFK) International Airport International Mail Facility (IMF) are ineffective, showing limited progress since our prior audit.  CBP inspected approximately [REDACTED] percent of the 1.3 million pieces of mail it received during our June 2019 site visit.  CBP also did not timely inspect and process mail from high-risk countries, creating unmanageable backlogs. These deficiencies were largely because of inadequate resources and guidance.  Consequently, more than [REDACTED] pieces of mail were sent out for delivery without physical inspection.  We made eight recommendations aimed at improving international mail processes at JFK International Airport.  CBP concurred with six, but non-concurred with two of the recommendations. 

>CBP Faced Challenges in its Inspection Processes and Physical Security at the JFK International Mail Facility (Redacted)
OIG-21-28 FEMA Needs Revised Policies and Procedures to Better Manage Recovery of Disallowed Grant Funds 2021
OIG-21-23 We determined that the Federal Emergency Management (FEMA) Region II (Region II) and New York State’s Division of Homeland Security Emergency Services (DHSES) have not adequately monitored or timely closed hundreds of projects, awarded at $578.8 million, for 7 disasters we reviewed. We made four recommendations that will help strengthen internal controls to improve oversight of the PA grant program.  FEMA concurred with all four of our recommendations.

>FEMA Needs to Reduce the $579 Million Backlog of Projects in its New York Public Assistance Grant Program
OIG-21-26 We determined that FEMA did not ensure procurements and costs for debris removal operations in Monroe County, Florida, met Federal requirements and FEMA guidelines.  Specifically, FEMA did not adequately review local entities’ procurements for debris removal projects and reimbursed local entities for questionable costs.  These deficiencies were due to weaknesses in FEMA training and its quality assurance process.  As a result, FEMA approved reimbursement to local entities for nearly $25.6 million (more than $23 million in Federal share) for debris removal projects, including contracts that may not have met Federal procurement requirements, and more than $2 million in questionable costs.  Without improvements to FEMA’s training and project review processes, FEMA risks continuing to expose millions of dollars in disaster relief funds to fraud, waste, and abuse.  We made three recommendations with which FEMA officials concurred.  Based on the information FEMA provided, we consider the three recommendations resolved and open.

>FEMA's Procurement and Cost Reimbursement Review Process Needs Improvement
OIG-21-24 We determined that the Federal Emergency Management Agency (FEMA) did not ensure state and local law enforcement agencies expended FEMA’s grant for protection of the President’s non-governmental residences in accordance with Federal regulations and Agency guidelines. We made four recommendations to FEMA that should improve the management of the program.  FEMA concurred with three recommendations and nonconcurred with one recommendation.

>FEMA Needs to Improve Guidance and Oversight for the Presidential Residence Protection Assistance Grant
OIG-21-25 This report provides a summary of our previous findings and recommendations, which may inform future disaster response efforts.  Based on our prior work, we identified a pattern of internal control vulnerabilities that negatively affect both disaster survivors and disaster program effectiveness that may hinder future response efforts, including shortcomings in acquisition and contracting controls, interagency coordination challenges, and insufficient privacy safeguards that affect disaster survivors.  Additionally, FEMA did not adequately oversee disaster grant recipients and subrecipients, manage disaster assistance funds, or oversee its information technology environment.  This report discusses these vulnerabilities and the correlating recommendations we previously made that, if implemented, would better prepare FEMA to respond to future disasters.  We made no new recommendations. 

>Success of Future Disaster Response and Recovery Efforts Depends on FEMA Addressing Current Vulnerabilities
OIG-21-22 We determined that DHS’ Countering Weapons of Mass Destruction Office (CWMD) BioWatch has information sharing challenges that reduce nationwide readiness to respond to biological terrorism threats.  We made four recommendations that, when implemented, will improve BioWatch. CWMD concurred with all four recommendations. 

>Biological Threat Detection and Response Challenges Remain for BioWatch (REDACTED)
OIG-21-21 We determined that, in response to Executive Order 13767, U.S. Customs and Border Protection (CBP) implemented new tools and technologies that have enhanced Border Patrol’s surveillance capabilities and efficiency along the southwest border.  We made three recommendations to improve CBP’s border technology, enhance situational awareness of the southwest border, and address potential IT security vulnerabilities.  CBP concurred with all three recommendations.

>CBP Has Improved Southwest Border Technology, but Significant Challenges Remain
OIG-21-20 During the course of the audit, we determined that FEMA provided hotel rooms to about 90,000 households (nearly 227,000 survivors) after the 2017 California wildfires and Hurricanes Harvey, Irma, and Maria.  However, FEMA did not oversee and manage the Transitional Sheltering Assistance (TSA) program to ensure it operated efficiently and effectively to meet all disaster survivors’ needs.  We made two recommendations that when implemented, will improve FEMA’s oversight and pre-disaster planning of transitional sheltering.  FEMA concurred with both recommendations and the recommendations are resolved and open.

>Better Oversight and Planning are Needed to Improve FEMA's Transitional Sheltering Assistance Program
OIG-21-19 We determined that U.S. Customs and Border Protection’s (CBP) training approach and execution do not fully support the canine teams’ mission to detect smuggling of illegal narcotics, agriculture products, and humans at and between ports of entry.  In total, we made four recommendations that, if implemented, should help CBP improve oversight of its Canine Program, formalize and implement a realignment plan for the training academy, provide proper training capabilities, and update and standardize program guidance.  CBP concurred with all our recommendations. 

>CBP Needs to Improve the Oversight of its Canine Program to Better Train and Reinforce Canine Performance (REDACTED)
OIG-21-17 Based on our review of 45 judgmentally sampled awards (15 non-competitive grants and 30 other than full and open competition [OTFOC] contracts), we found DHS complied with applicable laws and regulations.  We made two recommendations to help improve DHS’ procedures and ensure future reporting submissions are accurate.  The Department concurred with the two recommendations.  

>DHS Grants and Contracts Awarded through Other Than Full and Open Competition, FYs 2018 and 2019
OIG-21-16 This report offers DHS OIG’s initial observations on the PACR and HARP programs based on our March 2020 visit to the El Paso, Texas area and analysis of data and information provided by CBP and USCIS headquarters.  We determined that CBP rapidly implemented the pilot programs and expanded them without a full evaluation of the pilots’ effectiveness.  Additionally, we determined there are potential challenges with the PACR and HARP programs related to how aliens are held and provided access to counsel and representation, and how CBP and USCIS assign staff to program duties and track aliens in the various agency systems.  We made six recommendations to improve PACR and HARP program implementation.  DHS did not concur with five of the six recommendations, stating that lawsuits and the COVID-19 pandemic had, in effect, ended the programs.  We reviewed evidence provided by CBP and concluded the lawsuits themselves did not terminate the PACR and HARP pilot programs.  Therefore, the recommendations remain open and unresolved.  If the programs resume, we plan to resume actual or virtual site visits and issue a report detailing DHS’ full implementation of the PACR and HARP pilot programs.

>DHS Has Not Effectively Implemented the Prompt Asylum Pilot Programs
OIG-21-15 ICE Guidance Needs Improvement to Deter Illegal Employment,” OIG-21-15.  We determined the Worksite Enforcement (WSE) program compliance, civil enforcement, and outreach activities are not as effective as they could be to support U.S. Immigration and Customs Enforcement’s (ICE) immigration enforcement strategy.  ICE officials did not consistently enforce ICE guidance, take timely and affirmative steps against unauthorized alien workers, and ensure the outreach program achieved measurable progress and was cost effective.  We made four recommendations with which ICE officials concurred.  Based on the information ICE provided, we consider the four recommendations resolved and open.

>ICE Guidance Needs Improvement to Deter Illegal Employment