GAO Gives NTIA Good Marks on BEAD Fraud Controls Without Testing Them

Benton Institute for Broadband & Society

Monday, July 27, 2026

Digital Beat

GAO Gives NTIA Good Marks on BEAD Fraud Controls Without Testing Them

Kevin Taglang
      Taglang


On July 23, 2026, the U.S. Government Accountability Office (GAO)—the legislative branch's audit and investigative agency—released Combating Fraud: Managing Risks in Federally Funded, State-Administered Programs (GAO-26-109100). GAO calls this a "Q&A report," a short-form GAO product prepared for the House Committee on Oversight and Government Reform and addressed to Chairman James Comer R-KY) and Ranking Member Robert Garcia (D-CA). The report examines 20 of the largest federal programs funded by the federal government but run by the states. One of the 20 is the Broadband Equity, Access, and Deployment (BEAD) Program, the $42.45 billion broadband deployment program created by the Infrastructure Investment and Jobs Act and administered by the National Telecommunications and Information Administration (NTIA), an agency within the Department of Commerce. In BEAD, all 50 states, the District of Columbia, and U.S. territories (collectively called "eligible entities") are award recipients who distribute funds to subgrantees who, in turn, build the actual internet networks. GAO reports BEAD federal obligations of $16.9 billion in fiscal year 2025—the second-largest of the five programs GAO groups under "Infrastructure," behind Highway Planning and Construction at $67.2 billion. Infrastructure as a category accounts for 8.6 percent of the obligations GAO analyzed.

Two groups have a direct stake in this analysis:

  1. State broadband offices. GAO's central structural argument is that every layer between the federal government and the ultimate recipient adds an entry point for fraud, and that federal agencies have no direct legal relationship with subrecipients. Federal regulation instead assigns most subrecipient oversight to the pass-through entity—states and territories. In BEAD, that is the state broadband office. States carry the primary responsibility for evaluating whether an ISP subgrantee poses a fraud risk. NTIA's role is to ensure that states fulfill that responsibility.
  2. Internet service providers (ISPs). GAO identifies subgrantees—which it defines for BEAD as ISPs—as one of three categories of potential fraud actors, alongside grantees and "internal parties."

GAO's assessment of fraud risk management in these programs is an assessment of federal agencies: GAO gathered fraud risk management information from "federal agencies overseeing the programs," and evaluated the documentation those agencies supplied. State broadband offices were not examined. That matters for BEAD because GAO's own account of how these programs work assigns most subrecipient oversight—in BEAD, the vetting of ISP subgrantees—to states rather than to NTIA. GAO suggests its Fraud Risk Framework "may be applicable to states and subrecipients," and that congressional attention could encourage wider adoption. The findings below cover the federal end of a two-layer system.

What GAO Learned About BEAD

GAO reports that NTIA's current fraud risk assessment for BEAD and other broadband programs identifies fraudulent invoices and expense reports as an inherent fraud risk—meaning a risk that exists in the program's design, before any controls are applied—along with collusion and conflicts of interest. GAO also identifies who could commit it: grantees (states and territories), subgrantees (ISPs), and "internal parties" (program staff). [That last category is not hypothetical. The only NTIA broadband fraud case GAO cites involves a grant manager who created fraudulent invoices and expense reports to misappropriate more than $800,000, and who was sentenced in April 2025 to 28 months in prison and ordered to pay $828,152 in restitution.]

One element is reported for NTIA's other broadband programs but not for BEAD: fraud risk tolerance, the level of residual risk an agency decides it will accept. In closing its 2023 recommendations, GAO confirmed that NTIA set tolerance at "low" for the Tribal Broadband Connectivity Program and the Broadband Infrastructure Program. GAO's BEAD profile does not state a tolerance, and NTIA has not published one.

GAO describes BEAD as "a grant program that includes funds for deployment of broadband in the United States to unserved and underserved areas," funding states and territories (including the District of Columbia), which then award competitive subgrants to ISPs through a multistep planning process requiring NTIA review and approval. As of May 2026, NTIA had approved 54 of the 56 state and territorial final proposals. [Editor's note: As of July 24, only Illinois was waiting for NTIA approval of its final BEAD plan.]

BEAD oversight is shared between NTIA and the states and territories. The program has semiannual and other reporting requirements: states and territories report to NTIA, and subgrantees report to their administering state or territory, with NTIA able to request those subgrantee reports for review. GAO also notes that the National Institute of Standards and Technology (NIST) "performs certain administrative functions to review and administer grants." Readers familiar with BEAD know that after NTIA approves a state's final BEAD plan, NIST must also review and approve it.  

GAO states plainly that, as a newer program that began providing funding to states in fiscal year 2023, "fraud risk management for BEAD has not been reviewed by us." GAO then points to its January 2023 report, Broadband Funding: Stronger Management of Performance and Fraud Risk Needed for Tribal and Public-Private Partnership Grants (GAO-23-105426), which covered NTIA's Tribal Broadband Connectivity Program and the Broadband Infrastructure Program. That report found NTIA's fraud risk management did not align with leading practices. GAO recommended that NTIA designate a dedicated entity to lead fraud risk management, identify inherent fraud risks, and assess their likelihood and impact. GAO reports that NTIA agreed with the recommendations and fully implemented all of them, and that, "[a]ccording to NTIA," those actions also apply to BEAD.

GAO identified no adjudicated fraud cases for BEAD. GAO reports that NTIA ranks these risks by likelihood to enable the agency to prioritize action.

GAO reviewed the fraud risk assessment documentation agencies provided for all 20 programs and sorted them into three groups:

  • five programs where agencies identified fraud risks and assessed the likelihood to prioritize action;
  • ten where agencies identified some risks but did not assess likelihood; and
  • five that provided no assessment at all.

BEAD is in the top group of five, alongside the National School Lunch Program, the Home Energy Rebates Program, Public Assistance, and the Airport Improvement Program.

GAO analyzed single audit findings from 2020 through 2024 and found severe and persistent findings in 18 of the 20 programs. BEAD is one of the two exceptions: the program had ten single audits completed during the period, and none had both severe and persistent findings. GAO cautions that newer programs and programs with fewer audits may have rates that do not reflect program integrity.


What is a "single audit"?

A single audit is the annual, entity-wide audit that a state, local government, tribe, university, or nonprofit must undergo if it spends $1 million or more in federal awards from all sources in a fiscal year. It is one audit covering all of an entity's federal spending—not a separate audit for each grant or program. The requirement comes from the Single Audit Act and the Office of Management and Budget's implementing guidance. The threshold rose from $750,000 to $1 million effective October 1, 2024. Results are reported to the Federal Audit Clearinghouse, which is the dataset GAO analyzed.

GAO explicitly states that single audits are "not specifically designed to detect fraud," but treats their findings as an indicator that a program may be vulnerable to fraud. GAO uses two terms together. A severe finding is one that the auditor determined contributed to either a modified opinion on a compliance audit or a material weakness in internal control over compliance. A persistent finding is one that remained unresolved by corrective action for at least 2 years or was reported in 3 audits.

One feature of how single audits work explains BEAD's clean record. Auditors take a risk-based approach, focusing on the programs from which recipients spent the most money that year, so not every program is reviewed for every recipient every year. BEAD had 10 completed single audits across 2020–2024, against an average of nearly 5,000 for the other 18 programs GAO examined. GAO warns directly that for newer or less-audited programs, a low rate of severe and persistent findings "may not relate to program integrity issues." 


What to Watch

Stakeholders may want to keep the following issues in mind.

NTIA's Improvement

BEAD's rating is a reversal from GAO's 2023 posture toward NTIA. In 2023, GAO found NTIA's broadband fraud risk management deficient across the board. In 2026, NTIA was one of five agencies whose documentation GAO said met leading practices. For a program under sustained political scrutiny, that is a citable, on-the-record improvement—and it comes from the same auditor that issued the original criticism.

An Assessment of Untested Controls

GAO is scrupulous about what it is not saying. "Fraud risk management for BEAD has not been reviewed by us" is an explicit disclaimer of independent verification. "According to NTIA, the agency took actions … and these actions also apply to BEAD" attributes the extension of the 2023 fixes to the agency, not to GAO. A figure titled "Observations from GAO's Review of Agency Fraud Risk Assessments" rests on "documentation that agencies provided"—it evaluates paperwork, not outcomes. Read together, GAO is saying NTIA's fraud risk assessment documentation is good, not that BEAD's controls have been tested. Similarly, "[f]raud in BEAD could be carried out by" grantees, subgrantees, and internal parties describes inherent risk, not observed conduct.

These two findings are less contradictory than they appear. Under GAO's Fraud Risk Framework—the 2015 set of leading practices (GAO-15-593SP) against which all 20 programs were measured—assessment is the second of four components, and it is the precondition for the third. An agency cannot design controls against risks it has not identified and ranked, and it cannot evaluate whether those controls work without a baseline to test against. Documentation quality is not the goal; it is what makes the rest possible. So NTIA's placement is a real finding about a real prerequisite. It is not a finding that the prerequisite has been built upon.

Why There Are No Open Recommendations for NTIA​

GAO says the appendix "references our relevant open recommendations, when applicable." The BEAD profile references none, and NTIA does not appear among the agencies holding the 22 open fraud risk management recommendations GAO highlights. There is a documented reason. All 15 recommendations from GAO's 2023 report on NTIA's broadband grant programs—including the seven fraud risk management recommendations covering designation of a lead entity, identification of inherent risks, likelihood assessment, risk tolerance, control suitability, and documentation of a fraud risk profile—are now closed as implemented.1 GAO closed them in stages, confirming the lead-entity designation in July 2024, the risk identification and likelihood assessments in July and September 2025, and the final items on documentation NTIA supplied in January 2026. That last date falls just before the June 2026 cutoff for GAO's assessment.

No Assessment of State-Level Capacity

Although GAO assigns most subrecipient oversight to states, the report does not examine whether state broadband offices have the staff or tools to vet ISP subgrantees, and does not say whether any state uses the Department of the Treasury's Do Not Pay program2 for that purpose. GAO reports that about 4 percent of all federal programs use the U.S. Treasury's full suite of services. Notably, for the Home Energy Rebates program, the U.S. Department of Energy (DOE) now requires grantees to use Do Not Pay to verify information on potential contractors. GAO's BEAD profile describes no equivalent control.

What the Report Does Not Cover

The report does not address NTIA's June 2025 BEAD Restructuring Policy Notice, the "Benefit of the Bargain" subgrantee selection round, or the suspension of non-deployment funding. Nor does GAO examine whether state broadband offices have the staff or tools to vet ISP subgrantees, or whether any state uses the Department of the Treasury's Do Not Pay program,2 a centralized federal service for verifying recipient identity and eligibility before an award or payment for that purpose.

These are scope limits, not gaps. GAO conducted this audit between April and July 2026, gathered fraud risk management information "from federal agencies overseeing the programs," and gave each of the 20 programs a two-page appendix profile. No states were examined for any program. But the limits define what the report can and cannot address: the analysis speaks to NTIA's documentation, not to BEAD's current selection process, nor to the capacity of the offices conducting subgrantee vetting.

One point of comparison is available within the report. For the Home Energy Rebates Program, the Department of Energy now requires grantees to use Do Not Pay to verify information on potential contractors. GAO's BEAD profile describes no equivalent required control. GAO reports that about 4 percent of all federal programs use Treasury's full suite of services.

Conclusion

GAO's finding is narrow and favorable. NTIA identified BEAD's inherent fraud risks, ranked them by likelihood, and documented the work well enough to place among the top five of 20 programs—a reversal from GAO's 2023 assessment of the same agency, delivered by the same auditor. Agencies don't often get credit for addressing recommendations.

What GAO does not settle is nearly everything downstream. GAO did not test BEAD's controls, examine the states that will do the actual subgrantee vetting, or assess how the restructured selection process affects the program's exposure. The single-audit record is clean, but ten audits across five years describe a program that had barely spent money. As construction dollars start to flow, that number will climb, and the picture should become clearer. GAO indicates more work in this area is planned.

One caution belongs to readers rather than to NTIA. GAO estimates that, for fiscal years 2018 through 2022, the federal government loses between $233 billion and $521 billion annually to fraud, or 3 to 7 percent of federal obligations—and states directly that "[f]raud risks can vary substantially by program, and these percentages should not be applied to infer fraud incidence at the agency or program level." 

Finally, GAO writes that efforts to prevent fraud "must also consider how to protect federal funds without compromising individuals' privacy and creating barriers to access," because many of these programs serve the nation's most vulnerable populations. The programs GAO surveyed here deliver food, health care, housing, and now broadband. Verification that keeps out fraudsters and legitimate applicants in equal measure is not program integrity. It is a different kind of failure, and it does not show up in a single audit.


Notes

  1. Readers who followed our earlier coverage of GAO's open broadband recommendations should note the difference in scope. This report counts only fraud risk management recommendations. NTIA's open items in that earlier accounting—technical assistance and reporting on Tribal broadband financial sustainability, and the 2022 recommendations on statutory alignment and the BroadbandUSA Federal Funding Guide—sit outside this report's frame and are unaffected by it.
  2. Do Not Pay provides federal agencies and federally funded state-administered programs access to data and services to verify recipient identity and eligibility before making an award or issuing a payment. 

The Benton Institute for Broadband & Society is a non-profit organization dedicated to ensuring that all people in the U.S. have access to competitive, High-Performance Broadband regardless of where they live or who they are. We believe communication policy - rooted in the values of access, equity, and diversity - has the power to deliver new opportunities and strengthen communities.


© Benton Institute for Broadband & Society 2026. Redistribution of this email publication - both internally and externally - is encouraged if it includes this copyright statement.


For subscribe/unsubscribe info, please email headlinesATbentonDOTorg

Kevin Taglang

Kevin Taglang
Executive Editor, Communications-related Headlines
Benton Institute
for Broadband & Society
1041 Ridge Rd, Unit 214
Wilmette, IL 60091
847-220-4531
headlines AT benton DOT org

Share this edition:

Benton Institute for Broadband & Society Benton Institute for Broadband & Society Benton Institute for Broadband & Society

Benton Institute for Broadband & Society

Broadband Delivers Opportunities and Strengthens Communities


By Kevin Taglang.