Financial statement / account
readPervasive. Entity-level controls set whether any process-level control can be relied on.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Audit-risk object · Management responsibility and accountability
Ten elements built at material weakness grain from the published audit record. Every element below says whether the cited document states it or this site read it out of the narrative — and none of them is an extracted Notice of Findings and Recommendations, because those are not public documents.
Path database/seed_nfr.json, built by scripts/build_nfr_seed.py · extracted 2026-09-19 04:55 · refresh annual
Limitations Individual NFRs are not public documents. Nothing here is an extracted notice: the OIG publishes counts and material weakness narratives, so the finest grain available is the material weakness. Every element records whether it is reported in the cited document or read out of it, and the outcome element is computed from the rosters rather than asserted. FY2018 is published at year grain only, because its per-entity table does not foot to its own published total. FY2023 publishes no roster.
On the published roster in 7 of 7 years, first FY2018, last FY2025.
Control-environment evidence; not carried in any published financial file.
Read in order, these answer a different question from the report they come from: not what happened, but what a system built to prevent it would have to measure.
Pervasive. Entity-level controls set whether any process-level control can be relied on.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
All assertions, indirectly.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
The control environment at Component level does not support reliable financial reporting, so process-level controls cannot be relied on even where they are designed well.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Risk assessment, control documentation, monitoring and accountability under OMB Circular A-123, performed at Component level.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Risk assessments were incomplete, control documentation was not current, and monitoring did not reach the processes that produce the statements.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
A-123 assurance is produced as an annual statement rather than as a year-round process, and it is prepared by the organisation being assured. The assurance statement can therefore be complete and the control environment still unreliable, which is what the auditor-identified count against the Department’s own count shows: 69 financial reporting and 39 operational weaknesses self-reported in the FY2025 assurance statement against 26 identified by the auditor.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Not published at this grain.
DoD FY2025 Agency Financial Report, FMFIA assurance statement; DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Auditors tested entity-level control documentation, risk assessments and monitoring evidence.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
A-123 programme improvements at Component level; reissued every year since FY2018.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Open. On the roster in 7 of the 7 years a roster is published, first in FY2018, and carried into FY2025. Printed under 4 different titles over that period; the pairing is this site’s, not the Department’s.
Computed from the published rosters, FY2018, FY2019, FY2020, FY2021, FY2022, FY2024, FY2025
One row per published roster. A year absent from this table is a year in which this weakness was not on the roster, or — for FY2023 — a year for which no roster was published at all.
| FY | Printed as | Rank in the report | Citation |
|---|---|---|---|
| FY2018 | Entity Level Controls | 19 | DoD OIG, "Understanding the Results of the Audit of the DoD FY 2018 Financial Statements" (January 2019) |
| FY2019 | Entity-Level Controls | 23 | DoD OIG, "Understanding the Results of the Audit of the DoD FY 2019 Financial Statements" (January 2020) |
| FY2020 | Entity-Level Controls | 24 | DoD OIG, "Understanding the Results of the Audit of the FY 2020 DoD Financial Statements" (February 2021) |
| FY2021 | Entity-Level Controls | 26 | DoD OIG, "Understanding the Results of the FY 2021 Audit" (June 2022) |
| FY2022 | Component Entity-level Controls | 27 | DoD OIG report DODIG-2023-070, "Understanding the Results of the Audit of the FY 2022 DoD Financial Statements" |
| FY2024 | Component Entity-Level Controls | 2 | DoD OIG report DODIG-2025-112, "Part 2. Understanding the Results of the Audit of the FY 2024 DoD Financial Statements" |
| FY2025 | Component Entity-Level Controls | 25 | DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements |
Rosters published for FY2018, FY2019, FY2020, FY2021, FY2022, FY2024, FY2025.
The first three steps come from the record above. The rest is a design, and is marked as one: nothing on this site evidences that any of it was built or that it works.
The order is the argument. Building an anomaly detector for this account without steps 1 to 3 gives a model trained on whichever side of the relationship happens to be in a data lake, and it will find anomalies there — reliably, and without any of them being the failure the auditor reported. Materiality decides whether the work is worth doing, and the public record sizes this one only this far: Not published at this grain.