Pandemic Darlings The pandemic economy, in original documents
Home Court filings DOL OIG Unemployment Insurance Alert Memorandum — ETA Can Improve Its Oversight to Ensure Integrity over CARES Act UI…

Court filing

Alert Memorandum — ETA Can Improve Its Oversight to Ensure Integrity over CARES Act UI Programs

Filed September 22, 2023 in DOL OIG Unemployment Insurance; one of 15 filings from this case.

Record facts

CourtU.S. Department of Labor, Office of Inspector General
Filed2023-09-22

Full text

U.S. Department of Labor 
Office of Inspector General 
 
 
Washington, DC 20210 
 
 
Working for America’s Workforce 
 
 
September 22, 2023 
 
 
MEMORANDUM FOR: 
BRENT PARTON 
Principal Deputy Assistant Secretary 
  for Employment and Training 
 
 
 
 
 
                                         
 
 
 
 
 
 
FROM: 
CAROLYN R. HANTZ 
Assistant Inspector General  
  for Audit 
 
SUBJECT: 
COVID-19 – ETA Can Improve its Oversight to 
Ensure Integrity over CARES Act UI Programs  
Report No. 19-23-011-03-315 
 
The purpose of this memorandum is to alert Employment and Training (ETA) 
management to three matters relating to the National Association of State 
Workforce Agencies (NASWA) that require attention. These matters resulted 
from our audit of ETA’s oversight of Unemployment Insurance (UI) integrity for 
three key Coronavirus, Aid, Relief, and Economic Security (CARES) Act 
programs: Pandemic Unemployment Assistance, Pandemic Emergency 
Unemployment Compensation, and Federal Pandemic Unemployment 
Compensation. This memorandum is not intended to address our complete audit 
objective. Given the additional work required to report on the objective as a 
whole, we are only reporting on the matters expressed in this memorandum and 
will subsequently close this audit. We anticipate that other ongoing and future 
work will address the remaining areas of focus not reported here. 
 
NASWA is a national organization representing 53 state workforce agencies that 
includes all 50 states, the District of Columbia, Puerto Rico, and the 
U.S. Virgin Islands. NASWA’s mission is to “enhance state workforce agencies’ 
ability to accomplish their goals, statutory roles and responsibilities.” Part of 
NASWA’s duties includes running the Integrity Data Hub (IDH). The IDH is a 
centralized platform that brings state workforce agencies together to compare 
and analyze UI claims data for enhanced detection and prevention of UI fraud 
and improper payments. 
 

 
 
 
- 2 - 
 
 
 
During the audit, we performed a comparative analysis of the effectiveness of 
NASWA’s IDH. We also reviewed the terms of the cooperative agreement for 
NASWA’s IDH (see Attachment I for full methodology).  
 
Background 
 
On March 27, 2020, Congress passed the largest stimulus package in U.S. 
history, the CARES Act. The estimated $2.2 trillion package created the three 
key UI programs previously listed. The legislation required the U.S. Department 
of Labor to provide guidance, technical assistance, and oversight of states’1 
implementation of these programs. ETA is responsible for oversight of these key 
CARES Act UI programs.  
 
In support of UI program integrity, ETA provided states with guidance and 
assistance to detect improper payments, including fraud. For example, ETA 
issued Unemployment Insurance Program Letter No. 23-20, which required 
states to maintain key eligibility determination processes for regular UI claims to 
be in conformity and compliance with federal UI laws. It also encouraged states 
to use NASWA’s UI Integrity Center’s tools, including the IDH, to ensure UI 
program integrity; to prevent, detect and recover improper UI payments; and to 
reduce UI fraud. 
 
ETA and NASWA’s Center for Employment Security Education and Research, 
Inc., entered into a cooperative agreement signed on March 27, 2018, to, among 
other things, establish and operate the IDH. The IDH is a part of NASWA’s UI 
Integrity Center and is a tool to develop, implement, and promote innovative 
program integrity strategies to reduce improper payments.  
 
ETA has two seats on NASWA’s steering committee and its role as a member of 
the steering committee is to monitor, oversee, and provide guidance and 
direction for the UI Integrity Center. Further, ETA’s role includes: 
  
• facilitating connections between the UI Integrity Center and federal 
agencies implementing anti-fraud screening systems,  
• leveraging ETA’s UI Community of Practice to disseminate the UI Integrity 
Center’s deliverables, and  
• assigning a Federal Project Officer to monitor and inspect the UI Integrity 
Center’s financial performance and products on an ongoing basis. 
 
                                                 
1 In this memorandum, the term “state” refers to the administrative body that administers the 
program within the state, district, or territory. For the 50 states, as well as the U.S. Virgin Islands, 
Puerto Rico, and the District of Columbia, that administrative body is a state workforce agency. 
There are, therefore, 53 state workforce agencies. The CARES Act also provided certain UI 
benefits to American Samoa, the Commonwealth of the Northern Mariana Islands, the Federated 
States of Micronesia, Guam, the Marshall Islands, and the Republic of Palau, provided the 
territory signed an agreement with the Department. 

 
 
 
- 3 - 
 
 
 
We conducted our performance audit in accordance with generally accepted 
government auditing standards. Those standards require that we plan and 
perform the audit to obtain sufficient, appropriate evidence to provide a 
reasonable basis for our findings and conclusions, based on our audit objective. 
We believe that the evidence obtained provides a reasonable basis for our 
findings and conclusions based on our audit objective. Our audit work focused on 
ETA’s UI oversight activity from March 27, 2020, to June 30, 2021. 
 
RESULTS 
 
ETA needs to improve its oversight of NASWA’s IDH. First, we found that ETA 
did not ensure an initial assessment of NASWA’s IDH was performed in 
compliance with federal requirements. Second, we found ETA did not provide 
documentation it evaluated NASWA’s security assessment reports. Because 
NASWA receives and stores UI data containing claimants’ personally identifiable 
information (PII) from participating states, it is imperative that the information 
stored in the IDH is secure and protected. ETA must ensure all 
federally-mandated authorizations and monitoring activities of the IDH are 
performed and documented and any issues identified are sufficiently mitigated. 
 
Last, we found the IDH was less effective at identifying potentially improper 
multistate claims when compared to the Office of Inspector General’s data. The 
IDH’s effectiveness was further limited by the varying participation of states in 
providing data for analysis. Greater oversight of IDH performance is needed if 
ETA and states’ reliance on this tool for program integrity, including fraud 
identification, is to continue. 
 
ETA DID NOT ENSURE AN INITIAL ASSESSMENT  
OF NASWA’s IDH WAS PERFORMED 
 
Despite the need for an effective and secure system, ETA did not have controls 
in place to ensure the Office of the Chief Information Officer’s (OCIO) awareness 
and approval of the system-related terms of the ETA-NASWA cooperative 
agreement regarding the IDH. As a result, neither ETA nor any other 
independent entity conducted an initial assessment or audit of NASWA’s IDH 
system in compliance with Office of Management and Budget Circular A-130.  
 
DOL’s authorizing official defined by departmental policy2 is responsible under 
Office of Management and Budget Circular A-130 to complete an initial 
authorization to operate for each information system and all agency designated 
common controls. The initial authorization to operate is based on a determination 
of, and explicit acceptance of, the risk to agency operations and assets, 
individuals, other organizations, and the Nation, and prior to operational status. 
DOL’s authorizing official would be responsible for such initial authorization and 
                                                 
2 Department of Labor Manual Series 7-408.G 

 
 
 
- 4 - 
 
 
 
ongoing authorizations, as well as establishing information security continuous 
monitoring and privacy continuous monitoring programs in accordance with 
relevant National Institute of Standards and Technology standards that 
continually assess the risk of the IDH. DOL’s authorizing official is a senior 
agency management official or designee. As it relates to the IDH, ETA was 
responsible for notifying OCIO of its requirement to serve in this capacity and 
perform the necessary security reviews of this system. 
 
According to the Chief Information Security Officer, OCIO did not perform any 
assessments or evaluations of NASWA’s IDH during the selection process for the 
cooperative agreement between NASWA and ETA. The Chief Information 
Security Officer stated the IDH was not evaluated initially because ETA did not 
inform OCIO of the need to review the IDH during the selection phase. 
 
ETA DID NOT ENSURE OCIO TIMELY EVALUATED NASWA’S SECURITY 
ASSESSMENT REPORTS 
 
ETA did not require a security assessment of the IDH system to be performed for 
more than 2 years after signing the cooperative agreement with NASWA for the 
operation of the IDH. Further, ETA did not ensure OCIO reviewed the results of 
the assessments or audits performed in a timely manner.  
 
A Notice of Award between ETA and NASWA, signed on September 18, 2020, 
included funding to contract for system security audit services for the next 
4 years, with an initial task of providing a complete audit of the IDH system 
security and yearly follow-on tasks providing audits of portions of the system. 
 
The contractor performed their first NASWA system security audit, a Cyber 
Maturity Assessment for NASWA’s IDH, and issued a report dated September 
17, 2020. In addition to the contracted audit, the following security audits were 
performed by cybersecurity service providers during 2020: 
 
• technical analysis/penetration test of NASWA’s Suspicious Actor 
Repository, issued February 14, 2020; and  
• risk assessment of NASWA’s UI-ICON system, issued in December 2020. 
 
Although the assessments were completed in 2020, OCIO did not start reviewing 
the assessments until August 2021. This was due to ETA’s late notification of the 
requirement to review. On February 23, 2022, OCIO notified the Office of 
Inspector General that it completed its review. However, OCIO had no written 
documentation that supported the completion of this effort.  
 
ETA’s Responsibility for Safeguarding Sensitive Data 
 
The September 18, 2020, Notice of Award between ETA and NASWA provided 
that NASWA must comply with the requirements in ETA’s Training and 

 
 
 
- 5 - 
 
 
 
Employment Guidance Letter 39-11, Guidance on the Handling and Protection of 
Personally Identifiable Information (PII), which specifies:  
 
ETA has examined the ways its grantees, as stewards of Federal 
funds, handle PII and sensitive information and has determined that 
to ensure ETA compliance with Federal law and regulations, 
grantees must secure transmission of PII and sensitive data 
developed, obtained, or otherwise associated with ETA funded 
grants. 
 
It also states: 
 
Grantees shall ensure that any PII used during the performance of 
their grant has been obtained in conformity with applicable Federal 
and state laws governing the confidentiality of information. 
 
Thus, ETA must monitor and evaluate NASWA and the IDH for compliance with 
federal requirements related to the storage, safeguarding, and handling of PII. 
 
Also, Training and Employment Guidance Letter 39-11 and ETA’s cooperative 
agreement with NASWA required that NASWA ensure the IDH is compliant with 
the Federal Information Security Modernization Act of 2014 (FISMA).3 Federal 
agency responsibilities under FISMA are laid out in FISMA § 3554. Based on 
FISMA requirements, DOL must periodically assess the risk and magnitude of 
the harm that could result from the unauthorized access, use, disclosure, 
disruption, modification, or destruction of information and information systems 
that support the operations and assets of the agency. DOL must also conduct 
periodic testing and evaluation of the effectiveness of information security 
policies, procedures, and practices, to be performed with a frequency depending 
on risk, no less than annually. 
 
In addition, FISMA § 3554(a)(1)(C) requires DOL to ensure information security 
management processes are integrated with agency strategic, operational, and 
budgetary planning processes. In order to properly equip NASWA to fulfill FISMA 
requirements, ETA needs to verify NASWA has budgeted for FISMA compliance, 
including how this was factored into its design and operation of the IDH. 
 
Stronger Processes are Needed to Ensure Continued Protection 
 
For almost 4 years, ETA did not ensure NASWA’s IT systems safeguarded and 
maintained the integrity of stored and communicated data. ETA must ensure all 
federally-mandated authorizations and monitoring of the IDH are performed and 
documented timely. 
 
                                                 
3 FISMA, Pub. L. 113-283, 42 U.S.C. §§ 3551-3559 

 
 
 
- 6 - 
 
 
 
Ultimately, upon review, OCIO indicated it found no issues with NASWA’s IDH 
security assessments and had one minor recommendation: that NASWA 
consider creating a unified report to document all identified risks to the system in 
one place. The Chief Information Security Officer stated he would provide that 
recommendation to ETA to relay to NASWA and he would not be sending an 
official report to NASWA.  
 
ETA’s continued oversight of these security assessments is critical to ensure 
adequate protection of the data within the IDH. This is particularly important as 
ETA has strongly encouraged states to participate and provide sensitive claimant 
PII for multi-party use. 
 
NASWA’S IDH WAS LESS EFFECTIVE IN IDENTIFYING POTENTIALLY 
IMPROPER MULTISTATE CLAIMS WHEN COMPARED TO THE OFFICE OF 
INSPECTOR GENERAL’s DATA 
 
Additionally, we found that NASWA’s IDH can improve its ability to identify a 
greater number of potentially fraudulent multistate claims. The IDH seeks to 
improve UI program integrity by identifying potentially improper UI claims as 
flagged transactions from the cross-matching of data it performs. ETA issued 
Unemployment Insurance Program Letter 23-20 encouraging states to use the 
IDH. However, ETA lacks the authority to require states to use NASWA’s IDH, 
which affects the data available that the IDH can use to cross-match. We 
compared the flagged transactions identified by the IDH to those we identified 
from subpoenaed data to evaluate the effectiveness of NASWA’s IDH.  
 
Specifically, our analysis found that the IDH was not able to identify the same 
amount of potentially improper multistate claims when compared to the Office of 
Inspector General’s data. NASWA’s IDH identified 39.7 percent of the potentially 
improper multistate claims when compared to those identified by the Office of 
Inspector General data for the same states using NASWA’s multistate 
methodology.  
 
Using NASWA’s methodology, we performed a comparative analysis of 
NASWA’s IDH flagged transactions to the potentially improper multistate claims 
identified by the Office of Inspector General. NASWA’s flagged transactions were 
based on a certain number of claims filed, for a specific individual, in multiple 
states. This methodology included a threshold that was higher than what the 
Office of Inspector General would use to flag improper multistate claims. We 
obtained data from the IDH for September 2020, in which 19 states4 participated. 
We found NASWA’s data included 735 potentially improper multistate claims. 
 
                                                 
4 As of February 22, 2023, 53 states had a participation agreement to use the IDH. However, the 
existence of a participation agreement does not provide information on whether the participants 
are using the IDH or the frequency in which they use the IDH. 

 
 
 
- 7 - 
 
 
 
We then evaluated the Office of Inspector General’s state subpoenaed data for 
September 2020, and adjusted it to the 19 states and threshold used by NASWA. 
In doing this, we identified 1,851 potentially improper multistate claims. 
Therefore, we found NASWA only flagged 39.7 percent (735 of 1,851) of 
potentially improper multistate claims. 
 
Based on our analysis, NASWA’s IDH is limited in its effectiveness in identifying 
potentially improper payments, including fraud. This is further compounded by 
the fact that the IDH lacks consistent, regular participation of enrolled states. ETA 
officials maintained it did not have the authority to require states to participate in 
the IDH, nor did ETA have an alternate means of meeting the same program 
integrity objectives when a state opted out of participation. As such, state UI 
programs dependent on NASWA’s IDH as a tool for reducing improper payments 
are vulnerable to under-detecting potentially improper payments, including fraud, 
due to lack of consistent, regular participation in the IDH by states and NASWA’s 
higher threshold for identifying potentially improper payments. 
 
RECOMMENDATIONS 
 
We recommend the Acting Assistant Secretary for Employment and Training: 
 
1. Implement a process to ensure OCIO performs required reviews of 
NASWA’s IDH system in a timely manner. 
 
2. Complete an evaluation of the effectiveness of the IDH system, including 
the methodology used in cross-matching data.  
 
3. Determine the best threshold for flagging multistate claims in conjunction 
with NASWA. 
 
SUMMARY OF ETA’S RESPONSE 
 
On September 6, 2023, ETA provided us its formal response to the draft 
memorandum and recommendations (see Attachment II). ETA partially agreed 
with our first two recommendations and agreed with the third recommendation. In 
its response, ETA stated it has taken some corrective actions to address our 
recommendations. 
 
For recommendation 1, ETA stated it agreed with the spirit of the 
recommendation but believed, according to DLMS 7-402, the IDH does not meet 
the definition of a federal information system, does not contain any DOL data, 
and did not require an initial assessment. To address the spirit of the 
recommendation, ETA did agree that oversight of the IDH is appropriate 
according to the terms of ETA’s cooperative agreement. ETA stated it has taken 
some action regarding recommendation 1. Specifically, ETA and OCIO have 
implemented a process to involve OCIO in periodic reviews of the IDH in a timely 

 
 
 
- 8 - 
 
 
 
manner. Further, ETA added requirements to the cooperative agreement with 
NASWA on September 27, 2022, that requires the UI Integrity Center to ensure 
annual independent security assessments of the IDH are conducted. ETA stated 
it will continue to consult with OCIO to ensure OCIO has access to and receives 
the security assessments for its review to identify any security concerns related 
to the IDH. 
 
For recommendation 2, ETA agreed with the intent of our recommendation. 
However, ETA requested removal of the recommendation from the memorandum 
because ETA believes it overlaps with an open OIG recommendation in a prior 
OIG report.5 That report recommended ETA work with NASWA to ensure the IDH 
cross-matches are effective at preventing the types of fraud that were detected 
during the pandemic and are regularly updated using the results of state fraud 
investigations. ETA said it has taken corrective actions in response to that audit’s 
recommendation, and has recently been working with DOL’s Chief Evaluation 
Office on an initial study to provide insights on the IDH’s effectiveness for 
identifying fraud. This study started in July 2023 and is anticipated to be 
completed in the third quarter of fiscal year 2024. 
 
Finally, ETA agreed with recommendation 3. ETA stated it has taken some action 
and worked with the UI Integrity Center to expand the IDH capabilities to identify 
and flag multi-state claims using a threshold that reduces false positives and 
ranks the multi-state claims as high priority. According to ETA, the IDH began 
returning prioritized claims to states on June 22, 2021. Additionally, ETA will 
continue to work with the UI Integrity Center on an ongoing basis to ensure the 
IDH identifies and appropriately flags claims that are high risk for potential fraud. 
 
In its response, ETA requested closure of these three recommendations based 
on its stated corrective action. 
 
OIG Response to ETA Management Comments  
 
For recommendation 1, given that ETA agreed with the spirit of the 
recommendation, and agreed that oversight of the IDH is appropriate according 
to the terms of ETA’s cooperative agreement, we consider the actions in 
response to the recommendation as meeting the intent. 
 
For recommendation 2, ETA agreed with the intent of our recommendation. 
While we did not agree to delete the recommendation, ETA’s approach is 
acceptable and meets the intent of the recommendation. We look forward to 
verification of the corrective action after the completion of the study. 
                                                 
5 COVID-19: ETA and States Did Not Protect Pandemic-Related UI Funds from Improper 
Payments including Fraud or from Payment Delays,  
Report No. 19-22-006-03-315 (September 30, 2022), available at:  
https://www.oig.dol.gov/public/reports/oa/2022/19-22-006-03-315.pdf 

 
 
 
- 9 - 
 
 
 
Finally, ETA agreed with the third recommendation. However, the response does 
not indicate that ETA determined the best threshold for flagging multistate claims 
in conjunction with NASWA. 
 
In its response, ETA requested closure of these three recommendations based 
on its stated corrective action. However, the OIG considers these 
recommendations open pending completion and/or verification of corrective 
action. 
 
We appreciate the cooperation and courtesies the ETA personnel extended us. If 
you have any questions, please contact Michael Kostrzewa, Audit Director, at 
(972) 850-4003.  
 
Attachments 

 
Attachment I 
 
 
SCOPE, METHODOLOGY, AND CRITERIA 
 
SCOPE 
 
Our scope for the audit covered ETA’s oversight activities for ensuring program 
integrity of the PUA, PEUC, and FPUC programs for the period March 27, 2020, 
to June 30, 2021. 
 
This memorandum is not intended to address our complete audit objective. Given 
the additional work required to report on the objective as a whole, we are only 
reporting on the matters expressed in this memorandum and will subsequently 
close this audit. We anticipate that other ongoing and future work will address the 
remaining areas of focus not reported here. 
 
METHODOLOGY 
 
We conducted our performance audit in accordance with generally accepted 
government auditing standards. Those standards require that we plan and 
perform the audit to obtain sufficient, appropriate evidence to provide a 
reasonable basis for our findings and conclusions based on our audit objectives. 
We believe that the evidence obtained provides a reasonable basis for our 
findings and conclusions based on our audit objectives.  
 
To answer our audit objective, we performed the following actions: 
 
• Confirmed our understanding of ETA’s guidance issuance processes 
through interviews with officials from ETA’s National Office, regional 
offices, and NASWA; 
• Reviewed the terms of the cooperative agreement between ETA and 
NASWA pertaining to NASWA’s Integrity Data Hub; 
• Reviewed laws, policies, procedures, documents, and internal/external 
audit reports; 
• Reviewed guidance issuance records to determine if ETA’s recent policies 
were consistent with requirements detailed in the CARES Act UI 
programs; 
• Obtained background information relating to the total number of UI claims 
within our period of review from ETA’s website; 
• Conducted interviews with NASWA to identify their responsibilities and 
identified the total amount of improper payments NASWA assisted states 
with preventing; and 
• Requested UI data from NASWA and compared it with the OIG’s database 
of subpoenaed UI claims data to determine the difference between 
potentially identified improper payments. 
 

 
Attachment I 
 
 
INTERNAL CONTROLS  
 
In planning and performing our audit, we considered ETA’s internal controls 
relevant to our audit objectives by obtaining an understanding of those controls, 
and assessing control risks for achieving our objectives. The objective of our 
audit was not to provide assurance of the internal controls; therefore, we did not 
express an opinion on ETA’s internal controls. Our consideration of internal 
controls for administering oversight of CARES Act UI programs would not 
necessarily disclose all matters that may be significant deficiencies. Because of 
the inherent limitations on internal controls, or misstatements, noncompliance 
may occur and not be detected. 
 
RELIABILITY ASSESSMENT 
 
We assessed the reliability of computerized data provided by states and 
NASWA. We evaluated the appropriateness of the data provided by assessing 
the data and controls over the data. Specifically, we performed analytical tests of 
the data and inquired with NASWA for any data discrepancies. Finally, as part of 
testing, we traced the data provided by NASWA to the OIG’s database, which 
contained subpoenaed state UI claimant information. 
 
CRITERIA 
 
We used the following key criteria to answer our audit objective: 
 
• Coronavirus Aid, Relief, and Economic Security Act of 2020 
• Unemployment Insurance Program Letter No. 23-20, Program Integrity for 
the UI Program and the UI Programs Authorized by the CARES Act 
• Office of Management and Budget Circular A-130 
• Federal Information Security Modernization Act  
• Training and Employment Guidance Letter 39-11, Guidance on the 
Handling and Protection of Personally Identifiable Information 
• Department of Labor Manual Series 7-408 
 
PRIOR COVERAGE 
 
In 2021, we issued an alert memorandum of significant relevance to the subject 
of this report:  
 
1. Alert Memorandum: The Employment and Training Administration (ETA) 
Needs to Ensure State Workforce Agencies (SWA) Implement Effective 
Unemployment Insurance Program Fraud Controls for High Risk Areas, 
Report No. 19-21-002-03-315 (February 22, 2021), available at: 
https://www.oig.dol.gov/public/reports/oa/2021/19-21-002-03-315.pdf

 
Attachment II 
 
 
 
 
 
 

 
Attachment II 
 
 
 
 
 

 
Attachment II 
 
 
 
 
 

 
Attachment II 
 
 
 
 
 

 
Attachment II

File and source

File
REPORT_DOL-OIG_covid-19-eta-can-improve-its-oversight-to-ensure-integrity-over-cares-_2023-09-22.pdf
Size
4,048,235 bytes
SHA-256
62028dee904f94d1f44154b1543e4c84fb5bed12164b3a59319b3a5a0d9ed9be
Our copy
REPORT_DOL-OIG_covid-19-eta-can-improve-its-oversight-to-ensure-integrity-over-cares-_2023-09-22.pdf
Original
www.oversight.gov
Back to top