Financial statement / account
readDisbursements, accounts payable, journal entries, and the obligation approval chain.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Audit-risk object · Information technology
Ten elements built at material weakness grain from the published audit record. Every element below says whether the cited document states it or this site read it out of the narrative — and none of them is an extracted Notice of Findings and Recommendations, because those are not public documents.
Path database/seed_nfr.json, built by scripts/build_nfr_seed.py · extracted 2026-09-19 04:55 · refresh annual
Limitations Individual NFRs are not public documents. Nothing here is an extracted notice: the OIG publishes counts and material weakness narratives, so the finest grain available is the material weakness. Every element records whether it is reported in the cited document or read out of it, and the outcome element is computed from the rosters rather than asserted. FY2018 is published at year grain only, because its per-entity table does not foot to its own published total. FY2023 publishes no roster.
On the published roster in 5 of 7 years, first FY2020, last FY2025.
No published file carries an actor or approver on a transaction.
Read in order, these answer a different question from the report they come from: not what happened, but what a system built to prevent it would have to measure.
Disbursements, accounts payable, journal entries, and the obligation approval chain.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Existence and rights/obligations; in the fraud dimension, the completeness of what is recorded.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
One person initiates and approves the same transaction, so a fictitious or improper obligation or payment can be created and concealed without a second party.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Conflicting capabilities are not held by the same user, enforced in role design and monitored in the system.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Conflicting roles were assigned, and compensating detective controls over the conflicts were not consistently performed or evidenced.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Role design is inherited from the system implementation and never re-derived from the business process, so the conflict matrix describes roles as the vendor shipped them rather than duties as the Department performs them. Small Components then have fewer people than the matrix requires, and the conflict is granted rather than mitigated.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Not published at this grain. GAO has separately reported that the Department has not assessed fraud risk across its financial activity to a standard that would size this.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Auditors tested role assignments against conflict matrices and requested evidence of compensating review where conflicts were accepted.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Role redesign and conflict remediation at Component level; reissued every year since FY2020.
Structured reading of DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements
Open. On the roster in 5 of the 7 years a roster is published, first in FY2020, and carried into FY2025.
Computed from the published rosters, FY2018, FY2019, FY2020, FY2021, FY2022, FY2024, FY2025
One row per published roster. A year absent from this table is a year in which this weakness was not on the roster, or — for FY2023 — a year for which no roster was published at all.
| FY | Printed as | Rank in the report | Citation |
|---|---|---|---|
| FY2020 | Segregation of Duties | 4 | DoD OIG, "Understanding the Results of the Audit of the FY 2020 DoD Financial Statements" (February 2021) |
| FY2021 | Segregation of Duties | 4 | DoD OIG, "Understanding the Results of the FY 2021 Audit" (June 2022) |
| FY2022 | Segregation of Duties | 4 | DoD OIG report DODIG-2023-070, "Understanding the Results of the Audit of the FY 2022 DoD Financial Statements" |
| FY2024 | Segregation of Duties | 12 | DoD OIG report DODIG-2025-112, "Part 2. Understanding the Results of the Audit of the FY 2024 DoD Financial Statements" |
| FY2025 | Segregation of Duties | 5 | DoD OIG report DODIG-2026-032, independent auditor’s report on the FY2025 financial statements |
Rosters published for FY2018, FY2019, FY2020, FY2021, FY2022, FY2024, FY2025.
The first three steps come from the record above. The rest is a design, and is marked as one: nothing on this site evidences that any of it was built or that it works.
The order is the argument. Building an anomaly detector for this account without steps 1 to 3 gives a model trained on whichever side of the relationship happens to be in a data lake, and it will find anomalies there — reliably, and without any of them being the failure the auditor reported. Materiality decides whether the work is worth doing, and the public record sizes this one no further than the roster it sits on: the reports name no population or dollar exposure at material weakness grain, so the decision to build has to be made on the balance, not on the finding.