Skip to main content
Report File
Date Issued
Submitting OIG
U.S. AbilityOne Commission OIG
Agencies Reviewed/Investigated
Committee for Purchase From People Who Are Blind or Severely Disabled (AbilityOne Program)
Report Number
OA-2024-01
Report Description

The OIG Audit office initiated this audit based upon an assessment of program risks. Our audit objective was to determine whether the U.S. AbilityOne Commission’s (Commission) enterprise risk management (ERM) process is effective and used to make risk-based decisions. 

Although the Commission has designed and implemented a formal ERM program, the OIG determined that the ERM program is not fully effective. This could impact the Commission’s ability to make fully informed risk-based decisions. Specifically, we found that the Commission’s ERM process and related internal controls need improvements, and the Commission lacked the ERM training to identify and correct these improvement areas. 

The OIG recommended that the Commission ensure that the appropriate individuals are trained through a structured ERM program training, assess and update existing ERM policies and procedures, and research and adopt an appropriate ERM maturity model. We also recommended that the Commission develop and implement effective key controls and results assessment, include a process in the ERM program to document management’s determination of key process decisions for its other process considerations, and develop and implement a process for tracking the consolidation of risks.

Report Type
Audit
Agency Wide
Yes
Number of Recommendations
6
Questioned Costs
$0
Funds for Better Use
$0
Report updated under NDAA 5274
No

Open Recommendations

This report has 6 open recommendations.
Recommendation Number Significant Recommendation Recommended Questioned Costs Recommended Funds for Better Use Additional Details
01 No $0 $0 CFO-2025-01

Ensure the appropriate individuals are trained through a structured ERM program training to increase knowledge and understanding throughout the organization and share key takeaways and materials with employees at all levels to effectively contribute to the
organization’s program success.

02 No $0 $0 CFO-2025-02

Assess and update the Commission’s existing policies and procedures to ensure compliance with federal requirements and that the policies and procedures reflect the processes that it wants to adopt.

03 No $0 $0 CFO-2025-03

Research and adopt an appropriate ERM maturity model.

04 No $0 $0 CFO-2025-04

Develop and implement effective key controls that identify risks and assign the Commission’s risk tolerances by aligning each control objective with the appropriate control activity and completing an updated entity-level control and results assessment.

05 No $0 $0 CFO-2025-05

Include a process in the ERM program to include documenting management’s determination of key process decisions for its other process considerations.

06 No $0 $0 CFO-2025-06

Develop and implement a process for tracking the consolidation of risks.

U.S. AbilityOne Commission OIG

United States