Audit-risk object · Management responsibility and accountability

Government Property in the Possession of Contractors

Ten elements built at material weakness grain from the published audit record. Every element below says whether the cited document states it or this site read it out of the narrative — and none of them is an extracted Notice of Findings and Recommendations, because those are not public documents.

Source
DoD OIG annual audit-result reports FY2018-FY2025; GAO
Grain
Fiscal year; reporting entity; material weakness
Vintage
2026-09-12
Rows loaded
557

Path database/seed_nfr.json, built by scripts/build_nfr_seed.py · extracted 2026-09-19 04:55 · refresh annual

Limitations Individual NFRs are not public documents. Nothing here is an extracted notice: the OIG publishes counts and material weakness narratives, so the finest grain available is the material weakness. Every element records whether it is reported in the cited document or read out of it, and the outcome element is computed from the rosters rather than asserted. FY2018 is published at year grain only, because its per-entity table does not foot to its own published total. FY2023 publishes no roster.

On the published roster in 7 of 7 years, first FY2018, last FY2025.

Position

Outcome
Open
Computed from the 7 published rosters, not asserted
Years on the roster
7 of 7
First published FY2018
Titles it has been printed under
2
Paired across years by this site, not by the Department
What the sources on this site could testpartial

FPDS on this site identifies contract actions and their values but carries no property clause indicator and no property report, so it can bound which contracts might carry the obligation and nothing further. That bound is a starting population, not a test.

The ten elements

Read in order, these answer a different question from the report they come from: not what happened, but what a system built to prevent it would have to measure.

1

Financial statement / account

read

Inventory, operating materials and supplies, and general PP&E held by contractors rather than by the Department.

Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements

2

Assertion

read

Existence, completeness and rights. The Department owns property it does not hold.

Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements

3

Audit risk

read

Government property held by contractors is unrecorded or misstated, because the record depends on a party outside the Department’s systems.

Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements

4

Control

read

Contract terms requiring property reporting, a Department record of property furnished and acquired under contract, and reconciliation of contractor reports to that record.

Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements

5

Control failure

read

The Department could not produce a complete population of government property held by contractors, and contractor reporting was incomplete and unreconciled.

Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements

6

Root cause

read

The obligation to report sits in the contract, and the contract is administered by an acquisition organisation that has no reporting line into financial reporting. Nobody in the accounting chain is a party to the instrument that would compel the data, so the population cannot be assembled from inside the Department at all.

Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements

7

Population / exposure

reported

Not published at this grain; among the balances behind the FY2025 scope limitation.

DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements

8

Historical audit evidence

read

Auditors attempted to establish the population from contract terms and contractor submissions and reported the inability to do so as a scope limitation.

Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements

9

Remediation

read

Property clause compliance and contractor reporting initiatives; reissued every year since FY2018.

Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements

10

Outcome

read

Open. On the roster in 7 of the 7 years a roster is published, first in FY2018, and carried into FY2025. Printed under 2 different titles over that period; the pairing is this site’s, not the Department’s.

Computed from the published rosters, FY2018, FY2019, FY2020, FY2021, FY2022, FY2024, FY2025

Where it appeared, and what it was called

One row per published roster. A year absent from this table is a year in which this weakness was not on the roster, or — for FY2023 — a year for which no roster was published at all.

FYPrinted asRank in the reportCitation
FY2018Government Property in Possession of Contractors9DoD OIG, "Understanding the Results of the Audit of the DoD FY 2018 Financial Statements" (January 2019)
FY2019Government Property in Possession of Contractors9DoD OIG, "Understanding the Results of the Audit of the DoD FY 2019 Financial Statements" (January 2020)
FY2020Government Property in Possession of Contractors12DoD OIG, "Understanding the Results of the Audit of the FY 2020 DoD Financial Statements" (February 2021)
FY2021Government Property in the Possession of Contractors13DoD OIG, "Understanding the Results of the FY 2021 Audit" (June 2022)
FY2022Government Property in the Possession of Contractors14DoD OIG report DODIG-2023-070, "Understanding the Results of the Audit of the FY 2022 DoD Financial Statements"
FY2024Government Property in the Possession of Contractors9DoD OIG report DODIG-2025-112, "Part 2. Understanding the Results of the Audit of the FY 2024 DoD Financial Statements"
FY2025Government Property in the Possession of Contractors13DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements

Rosters published for FY2018, FY2019, FY2020, FY2021, FY2022, FY2024, FY2025.

From this root cause to a system that can be audited

The first three steps come from the record above. The rest is a design, and is marked as one: nothing on this site evidences that any of it was built or that it works.

  1. 1

    Root cause

    from the record
    The obligation to report sits in the contract, and the contract is administered by an acquisition organisation that has no reporting line into financial reporting. Nobody in the accounting chain is a party to the instrument that would compel the data, so the population cannot be assembled from inside the Department at all.
  2. 2

    The business relationship that should hold

    from the record
    Every contract with a property clause should have a current contractor property report, and those reports should reconcile to the recorded balance.
  3. 3

    Data the relationship requires

    from the record
    Contracts carrying property clauses, contractor property reports, the Department’s property record.FPDS on this site identifies contract actions and their values but carries no property clause indicator and no property report, so it can bound which contracts might carry the obligation and nothing further. That bound is a starting population, not a test.
  4. 4

    Rule

    design
    State the relationship as a testable condition over that data and run it over the whole population, not a sample. Every break is an exception with a transaction behind it. A rule that can only be evaluated on one side of the relationship is not a test of it, which is why step 3 has to come first and has to be honest about what is missing.
  5. 5

    Machine learning

    design
    Patterns the rule does not express: a break that appears only at a particular period end, a counterparty whose exceptions cluster, a value distribution that moves before a reconciliation fails. Trained on the exception history the rule produces, so the model has a labelled population rather than an unsupervised guess at what “unusual” means for this account.
  6. 6

    Language model

    design
    Explain a specific exception against the source records it was raised from, quoting them. Grounded in the retrieved evidence, never in the model’s own account of how the process works — an explanation that cannot name the record it rests on is not audit evidence.
  7. 7

    Automation

    design
    Route the exception to the accountable office, collect the supporting document, open the correction, and record what was done and by whom. The automation is the part that makes the control operate on a schedule rather than at year end under an auditor’s deadline.
  8. 8

    Monitoring

    design
    Measure whether the control performs: exception rate, time to clear, ageing of what is unresolved, and recurrence after closure. Recurrence after closure is the one that matters here, because the oversight weakness on this roster is precisely that a corrective action can be reported complete while the control it was meant to install never operates.
  9. 9

    Audit evidence

    design
    Retain the tested population, the exceptions, the investigation, the remediation and the control-performance history, each immutable and timestamped. The deliverable is not a dashboard. It is a package an auditor can test that demonstrates the control operated across the period.

The order is the argument. Building an anomaly detector for this account without steps 1 to 3 gives a model trained on whichever side of the relationship happens to be in a data lake, and it will find anomalies there — reliably, and without any of them being the failure the auditor reported. Materiality decides whether the work is worth doing, and the public record sizes this one only this far: Not published at this grain; among the balances behind the FY2025 scope limitation.