Examining the examiner: GAO audit of CFPB identifies internal control issues


We can’t help finding a bit of irony in the Government Accountability Office’s report issued on May 21 that discusses seven internal control issues the GAO identified during its audit of the CFPB’s fiscal year 2011 statements. According to the report, the issues identified by the GAO increase the risk of the CFPB “not preventing or promptly detecting and correcting (1) misappropriation of assets because of insufficient internal controls; (2) unauthorized access, modification, or both of its data; and (3) misstatements in its financial statements.”

Among the seven issues identified by the GAO was the CFPB’s failure to develop, document and implement “an agencywide program to provide information security for the information and information systems that support the financial reporting, operations, and assets of the bureau, including those systems provided or managed by its service provider organizations.” Although the GAO’s comments regarding information security appear to be limited to the CFPB’s financial reporting systems, they lead us to question whether any similar deficiencies exist in the CFPB’s information security program for data that relates to its supervisory activities, such as consumer complaint data.

The report includes the GAO’s recommendations for how the CFPB should address these issues and the CFPB’s written comments on the draft of the report provided to it by the GAO.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Ballard Spahr LLP | Attorney Advertising

Written by:


Ballard Spahr LLP on:

Readers' Choice 2017
Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:

Sign up to create your digest using LinkedIn*

*By using the service, you signify your acceptance of JD Supra's Privacy Policy.

Already signed up? Log in here

*With LinkedIn, you don't need to create a separate login to manage your free JD Supra account, and we can make suggestions based on your needs and interests. We will not post anything on LinkedIn in your name. Or, sign up using your email address.