Pandemic Darlings The pandemic economy, in original documents
Home Court filings SBA Oig 26 03 Fy2025 Financial Statements Audit SBA OIG Report 26-03 — FY2025 Financial Statements Audit

Court filing

SBA OIG Report 26-03 — FY2025 Financial Statements Audit

Filed January 21, 2026 in SBA OIG 26 03 Fy2025 Financial Statements Audit, the only filing from this case in the archive.

Record facts

CourtSBA Office of Inspector General
Filed2026-01-21

Full text

OFFICE OF INSPECTOR GENERAL 
U.S. SMALL BUSINESS ADMINISTRATION 
 
409 Third St. SW, Washington, DC 20416  •  (202) 205-6586  •  Fax (202) 205-7382 
DATE: 
January 21, 2026 
TO: 
Kelly Loeffler 
Administrator 
FROM: 
William W. Kirk 
Inspector General 
SUBJECT: Independent Auditors’ Report on SBA’s Fiscal Year 2025 Financial Statements 
(Report 26-03) 
I am pleased to present the attached independent auditors’ report on the U.S. Small Business 
Administration’s (SBA) financial statement for fiscal year (FY) 2025. The Chief Financial Officers 
Act of 1990, as amended, requires the Inspector General or an independent auditor, as 
determined by the Inspector General, to audit SBA’s financial statements. 
We contracted with the independent certified public accounting firm KPMG LLP to conduct an 
audit of SBA’s consolidated balance sheet as of September 30, 2025 and the related notes. 
KPMG was not engaged to audit the consolidated statement of net cost, consolidated statement 
of changes in net position, and combined statement of budgetary resources. Our contract 
required KPMG to conduct the audit in accordance with Government Auditing Standards (GAS) 
and Office of Management and Budget Bulletin No. 24-02, Audit Requirements for Federal 
Financial Statements. 
KPMG issued a disclaimer of opinion on the consolidated balance sheet as of September 30, 
2025. The basis for the disclaimer was that because of control deficiencies identified, SBA was 
unable to provide adequate evidential matter in support of a significant number of transactions 
and account balances related to the Paycheck Protection Program and Economic Injury Disaster 
Loan programs. Additionally, management was unable to provide sufficient appropriate audit 
evidence to support the data used to develop assumptions used in the subsidy allowance 
estimate for SBA’s direct loan and loan guaranty programs. 
During the audit, KPMG identified four material weaknesses and one significant deficiency in 
internal control over financial reporting. We note that SBA made considerable progress 
addressing prior year audit findings, resulting in the successful remediation of two material 
weaknesses (controls over general information technology and controls over the evaluation of 
service organizations) and the downgrading of one material weakness (controls over monitoring 

 
Restaurant Revitalization Fund and Shuttered Venue Operators Grant programs) to a significant 
deficiency. Appendices I and II of this report describe details of KPMG’s conclusions about the 
material weaknesses and significant deficiency. KPMG also identified three instances of 
noncompliance with applicable laws or other matters, which are discussed in Appendix III of this 
report. 
We reviewed KPMG’s report and related documentation and inquired of its personnel. Our 
review, as differentiated from an audit of the financial statements in accordance with GAS, was 
not intended to enable us to express, and we do not express, opinions on 1) SBA’s financial 
statements or internal control over financial reporting; 2) whether SBA’s financial systems 
complied substantially with the Federal Financial Management Improvement Act of 1996 
requirements; 3) or conclusions on compliance and other matters. KPMG is responsible for the 
attached auditors’ report dated January 21, 2026 and the conclusions expressed. Our review 
disclosed no instances where KPMG did not comply in all material respects with GAS. 
We appreciate the cooperation and assistance extended to KPMG and our office during the 
audit. Should you or your staff have any questions, please contact me or Andrea Deadwyler, 
Assistant Inspector General for Audits, at (202) 205-6586. 
cc: 
Bill Briggs, Deputy Administrator, Office of the Administrator 
 
Wesley Coopersmith, Chief of Staff, Office of the Administrator 
 
Ben Grayson, Deputy Chief of Staff, Office of the Administrator 
 
Robin Wright, Chief Operating Officer, Office of the Administrator 
 
Nathan Davis, Chief Financial Officer and Chief Risk Officer, Office of Performance, 
Planning, and the Chief Financial Officer 
 
Deborah Chen, Deputy Chief Financial Officer, Office of Performance, Planning, and the 
Chief Financial Officer 
 
Thomas Kimsey, Associate Administrator, Office of Capital Access 
 
Chris Stallings, Associate Administrator, Office of Disaster Recovery and Resilience 
 
Wendell Davis, General Counsel, Office of General Counsel 
 
Michael Simmons, Attorney Advisor, Office of General Counsel 
 
Attachment 

KPMG LLP
Suite 12000
1801 K Street, NW
Washington, DC 20006
KPMG LLP, a Delaware limited liability partnership, and its subsidiaries are part of  
the KPMG global organization of independent member firms affiliated with KPMG  
International Limited, a private English company limited by guarantee.
 
Independent Auditors’ Report 
Inspector General 
U.S. Small Business Administration: 
Administrator 
U.S. Small Business Administration: 
Report on the Audit of the Consolidated Financial Statement 
Disclaimer of Opinion 
We were engaged to audit the consolidated balance sheet of the United States (U.S.) Small Business 
Administration (SBA) as of September 30, 2025, and the related notes to the consolidated balance sheet (the 
consolidated financial statement).  
We do not express an opinion on the accompanying consolidated financial statement of the SBA. Because of the 
significance of the matter described in the Basis for Disclaimer of Opinion section of our report, we have not been 
able to obtain sufficient appropriate audit evidence to provide a basis for an audit opinion on the consolidated 
financial statement. 
Basis for Disclaimer of Opinion  
The SBA’s pandemic relief programs include the Paycheck Protection Program, Economic Injury Disaster Loan 
program, Restaurant Revitalization Fund program, and Shuttered Venue Operators Grant program, which were 
authorized by the Coronavirus Aid, Relief, and Economic Security Act of 2020 and related legislations. These 
programs affect a substantial proportion of SBA’s consolidated financial statement.  As of the date of our audit 
report, management was still in the process of designing and implementing corrective actions to remediate control 
deficiencies identified in the prior and current years. These control deficiencies contributed to SBA’s inability to 
provide relevant and reliable information to support a significant number of transactions and account balances 
related to these programs. Additionally, management was unable to provide sufficient appropriate audit evidence to 
support the data used to develop assumptions used in the subsidy allowance estimate for SBA’s direct loan and 
loan guaranty programs. As a result of these matters, we were unable to determine whether any adjustments might 
have been necessary related to the Credit Program Receivables and Related Foreclosed Property, Net; Downward 
Reestimate Payable to Treasury; Loan Guarantee Liabilities; and the related notes. 
Other Matters 
Report on Certain Fiscal Year 2025 Information 
We were not engaged to audit the consolidated statements of net cost and changes in net position, and combined 
statement of budgetary resources for the year ended September 30, 2025, and the related notes to these 
statements. Accordingly, we express no opinion on them. 
Interactive Data 
Management has elected to reference to information on websites or other forms of interactive data outside the 
Agency Financial Report to provide additional information for the users of its consolidated financial statement. Such 
information is not a required part of the consolidated financial statement or supplementary information required by 
the Federal Accounting Standards Advisory Board. The information on these websites or the other interactive data 

has not been subjected to any of our auditing procedures, and accordingly we do not express an opinion or provide 
any assurance on it. 
Responsibilities of Management for the Consolidated Financial Statement 
Management is responsible for the preparation and fair presentation of the consolidated financial statement in 
accordance with U.S. generally accepted accounting principles, and for the design, implementation, and 
maintenance of internal control relevant to the preparation and fair presentation of the consolidated financial 
statement that is free from material misstatement, whether due to fraud or error. 
Auditors’ Responsibilities for the Audit of the Consolidated Financial Statement 
Our responsibility is to conduct an audit of the SBA’s consolidated financial statement in accordance with auditing 
standards generally accepted in the United States of America (GAAS), Government Auditing Standards, issued by 
the Comptroller General of the United States, and Office of Management and Budget (OMB) Bulletin No. 24-02, 
Audit Requirements for Federal Financial Statements, and to issue an auditors’ report. However, because of the 
matter described in the Basis for Disclaimer of Opinion section of our report, we were not able to obtain sufficient 
appropriate audit evidence to provide a basis for an audit opinion on the consolidated financial statement. 
We are required to be independent of the SBA and to meet our other ethical responsibilities, in accordance with the 
relevant ethical requirements relating to our audit. 
Required Supplementary Information 
U.S. generally accepted accounting principles require that the information in the Management’s Discussion and 
Analysis and Required Supplementary Information sections be presented to supplement the basic consolidated 
financial statement. Such information is the responsibility of management and, although not a part of the basic 
consolidated financial statement, is required by the Federal Accounting Standards Advisory Board who considers it 
to be an essential part of financial reporting for placing the basic consolidated financial statement in an appropriate 
operational, economic, or historical context. We were unable to apply certain limited procedures to the required 
supplementary information in accordance with GAAS because of the significance of the matter described in the 
Basis for Disclaimer of Opinion paragraph. We do not express an opinion or provide any assurance on the 
information. 
Other Reporting Required by Government Auditing Standards 
Report on Internal Control Over Financial Reporting 
In connection with our engagement to audit the SBA’s consolidated financial statement as of September 30, 2025, 
we considered the SBA’s internal control over financial reporting (internal control) as a basis for designing audit 
procedures that are appropriate in the circumstances for the purpose of expressing an opinion on the consolidated 
financial statement, but not for the purpose of expressing an opinion on the effectiveness of the SBA’s internal 
control. Accordingly, we do not express an opinion on the effectiveness of the SBA’s internal control. We did not 
test all internal controls relevant to operating objectives as broadly defined by the Federal Managers’ Financial 
Integrity Act of 1982. 
Our consideration of internal control was for the limited purpose described in the preceding paragraph and was not 
designed to identify all deficiencies in internal control that might be material weaknesses or significant deficiencies 
and therefore, material weaknesses or significant deficiencies may exist that were not identified. However, as 
described in the accompanying Appendices I and II, we identified certain deficiencies in internal control that we 
consider to be material weaknesses and significant deficiencies. 
A deficiency in internal control exists when the design or operation of a control does not allow management or 
employees, in the normal course of performing their assigned functions, to prevent, or detect and correct, 
misstatements on a timely basis. A material weakness is a deficiency, or a combination of deficiencies, in internal 
control, such that there is a reasonable possibility that a material misstatement of the entity’s financial statement 

will not be prevented, or detected and corrected, on a timely basis. We consider the deficiencies described in the 
accompanying Appendix I to be areas of material weaknesses. 
SBA management did not report the material weakness, Controls over Subsidy Reestimate Need Improvement, in 
its Statement of Assurance, included in Management's Discussion and Analysis section of the accompanying 
Agency Financial Report. 
A significant deficiency is a deficiency, or a combination of deficiencies, in internal control that is less severe than a 
material weakness, yet important enough to merit attention by those charged with governance. We consider the 
deficiencies described in the accompanying Appendix II to be significant deficiencies. 
Report on Compliance and Other Matters 
In connection with our engagement to audit the SBA’s consolidated financial statement as of September 30, 2025, 
we performed tests of its compliance with certain provisions of laws, regulations, contracts, and grant agreements, 
noncompliance with which could have a direct and material effect on the consolidated financial statement. 
However, providing an opinion on compliance with those provisions was not an objective of our engagement, and 
accordingly, we do not express such an opinion. The results of our tests disclosed instances of noncompliance or 
other matters that are required to be reported under Government Auditing Standards or OMB Bulletin No. 24-02, 
and which are described in the accompanying Appendix III. 
We also performed tests of the SBA’s compliance with certain provisions referred to in Section 803(a) of the 
Federal Financial Management Improvement Act of 1996 (FFMIA). Providing an opinion on compliance with FFMIA 
was not an objective of our engagement, and accordingly, we do not express such an opinion. The results of our 
tests disclosed instances, described in the accompanying Appendix III as item C, in which the SBA’s financial 
management systems did not substantially comply with the (1) Federal financial management systems 
requirements, and (2) applicable Federal accounting standards. The results of our tests disclosed no instances in 
which the SBA’s financial management systems did not substantially comply with the United States Government 
Standard General Ledger at the transaction level. 
Additionally, if the scope of our work had been sufficient to enable us to express an opinion on the consolidated 
financial statement, other instances of noncompliance or other matters may have been identified and reported 
herein. 
SBA’s Response to Findings 
Government Auditing Standards requires the auditor to perform limited procedures on the SBA's response to the 
findings identified in our engagement and described in the accompanying Appendix IV. The SBA’s response was 
not subjected to the other auditing procedures applied in the engagement to audit the consolidated financial 
statement and, accordingly, we express no opinion on the response. 
Purpose of the Other Reporting Required by Government Auditing Standards 
The purpose of the communication described in the Report on Internal Control Over Financial Reporting and the 
Report on Compliance and Other Matters sections is solely to describe the scope of our testing of internal control 
and compliance and the results of that testing, and not to provide an opinion on the effectiveness of the SBA’s 
internal control or compliance. This communication is an integral part of an engagement to audit in accordance with 
Government Auditing Standards in considering the SBA’s internal control and compliance. Accordingly, this 
communication is not suitable for any other purpose. 
Washington, DC  
January 21, 2026 

 
 
 
Appendix I 
U.S. Small Business Administration 
Material Weaknesses 
The following deficiencies are considered to be areas of material weaknesses in internal controls over financial 
reporting. 
1. Controls over Coronavirus Disease 2019 (COVID-19) Economic Injury Disaster Loans (EIDLs) 
Need Improvement 
2. Controls over Paycheck Protection Program (PPP) Loan Program Need Improvement 
3. Controls over Subsidy Reestimate Need Improvement 
4. Entity Level Controls Need Improvement 
Background 
The COVID-19 EIDL direct loan and PPP guaranty loan programs were authorized and funded by the 
Coronavirus Aid, Relief, and Economic Security Act of 2020, and the Paycheck Protection Program and 
Health Care Enhancement Act. The referenced laws are collectively referred to as the CARES Act and 
related legislation. The CARES Act and related legislation were passed by Congress to provide emergency 
assistance in response to the extensive effects of the public health and economic crisis arising from the 
COVID-19 pandemic. The COVID-19 EIDL and PPP programs affect a substantial proportion of the 
consolidated financial statement. 
The 7(a) Loan Guaranty Program, SBA’s primary business loan program, provides loan guarantees to lenders 
that allow them to provide financial help for small businesses. 
1. Controls over COVID-19 EIDLs Need Improvement 
The COVID-19 EIDL transactions were approved in fiscal years 2020 through 2022. These loans have a 30-
year term, and the originating payment start date was deferred by the SBA for up to 30 months after the loan 
disbursement. The payment deferral period ended for a significant number of COVID-19 EIDLs beginning in 
fiscal year 2023 and continued into fiscal year 2024. As COVID-19 EIDLs began repayment in fiscal years 2023 
and 2024, a substantial number became delinquent, and many were identified by management as potentially 
fraudulent. Consequently, management charged off many of these delinquent and potentially fraudulent 
COVID-19 EIDLs. In fiscal year 2025, management implemented a funds recovery accounting policy for 
COVID-19 EIDLs and concluded that all COVID-19 EIDLs previously charged off on the basis of a prior charge-
off policy should be reinstated and recorded as Credit Program Receivables in accordance with SFFAS 2. As a 
result of the updated funds recovery accounting policy, SBA reinstated a large volume of COVID-19 EIDLs as 
Credit Program Receivables. Management reinstated these loans based on the anticipation of further 
collectability. 
Management did not design and implement adequate monitoring controls over the COVID-19 EIDL portfolio to 
ensure reliable financial reporting as of the end of the fiscal year. Management’s analysis did not support the 
completeness and accuracy of the COVID-19 EIDL population of loans and related data elements as of the 
balance sheet date. Management did not sufficiently design and implement a review control to identify a 
complete population of loans with eligibility concerns that are critical in assessing the completeness and 
accuracy of the COVID-19 EIDL Credit Program Receivable balances. In addition, the monitoring controls for 
reviewing the loan status of COVID-19 EIDLs were not adequately designed to detect instances where the 
recorded loan status was not supported by the underlying accounting records or loan life cycle events. 

Management did not apply consistent accounting treatment of COVID-19 EIDLs with fraud-related hold codes 
where there is no anticipated further collectability. As a result, a sub-population of loans with these fraud-
related hold codes were not excluded from the Credit Program Receivable balance based on management’s 
fiscal year 2025 funds recovery accounting policy.   
Further, management’s review controls over their reinstatement process did not provide sufficient evidence to 
support the completeness and accuracy of the COVID-19 EIDL population as of the balance sheet date. For 
example, a sub-population of charged-off loans that management intended to reinstate had not been reinstated 
as of fiscal year-end and therefore were not reflected in the Credit Program Receivable balance. In addition, 
management reinstated certain loans which were not eligible for reinstatement. 
These deficiencies were caused by challenges, such as complexity and considerable effort, in retroactively 
generating the necessary point-in-time historical population data from the current system used for the portfolio 
analysis as of the end of the fiscal year. Additionally, management’s review controls were not adequately 
designed and implemented to identify a complete and accurate population of COVID-19 EIDLs with potential 
eligibility concerns. Further, the reinstatement controls implemented by management were not implemented 
effectively to complete all eligible loan reinstatements before fiscal year-end. Finally, management’s information 
systems were not designed to properly update the loan status of COVID-19 EIDLs to ensure the loan status 
was correct and supported by the underlying transactions.  
The following criteria were considered with respect to the matters described in the preceding paragraphs: 
•
GAO’s Green Book, Principle 3, Establish Structure, Responsibility, and Authority; Principle 6, 
Define Objectives and Risk Tolerances; Principle 7, Identify, Analyze, and Respond to Risks; 
Principle 9, Identify, Analyze, and Respond to Change; Principle 10, Design Control Activities; 
Principle 11, Design Activities for the Information System; Principle 12, Implement Control 
Activities; and Principle 16, Perform Monitoring Activities
•
OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk Management and 
Internal Control
The deficiencies described above may result in a material misstatement of the Credit Program 
Receivables and Related Foreclosed Property, Net and Downward Reestimate Payable to Treasury line 
items, and related elements in the consolidated financial statement. 
Recommendations – Controls over COVID-19 EIDLs Need Improvement 
We recommend the Administrator coordinate with the Associate Administrator for the Office of Capital 
Access to: 
1.
Establish and document a process to generate, save, and securely retain complete data
extracts of loan populations and relevant data elements (e.g., loan status, balances) as of the
date that management’s analyses are performed (such as the fiscal year-end). This process
will ensure relevant data is maintained by management to support their analyses for financial
reporting purposes.
2.
Implement a comprehensive, risk-based, and proactive process that regularly assesses the
loan population for potential fraud or ID theft concerns (e.g. periodic systematic reviews, data
analytics, or other proactive monitoring controls). (2024, recommendation 1)
3.
Apply consistent accounting treatment of non-performing loans with open agency hold codes.
4.
Consistently implement financial reporting controls to ensure the Credit Program Receivable
balance is completely and accurately stated throughout the fiscal year. If new policies are
implemented, conduct an analysis to assess the financial reporting implications. (2024,
recommendation 2)

 
 
 
5. Review controls over information technology program changes within the applicable systems 
of record for loan accounting so that they are designed, implemented and operating 
effectively, to ensure changes are appropriate and function as intended, and the information 
systems reflect the underlying accounting transactions. (2024, recommendations 3 & 4) 
2. Controls over PPP Loan Program Need Improvement 
The PPP program terms, authorized by the CARES Act and related legislation, permitted for the 
forgiveness of PPP loan guarantees if the borrower met the forgiveness criteria. To request forgiveness, 
borrowers submit the forgiveness application to the lenders for approval. The lenders will subsequently 
notify SBA of their forgiveness decision and submit the request to SBA. 
Management’s post-payment review control was not sufficiently designed and implemented to determine 
the appropriate status and financial reporting impact of PPP loans forgiven as of September 30, 2025. 
Specifically, management indicated that post-payment reviews were conducted on only two percent of the 
total population of forgiven PPP loans. Additionally, management’s process and related control activities 
for recovering funds of PPP loans with eligibility concerns that were identified and confirmed after 
forgiveness were not fully documented or implemented. While management established a funds recovery 
accounting policy, the implementation of related control activities was ongoing as of fiscal year-end.  
These deficiencies were caused by the volume of forgiveness payments and management’s ability to remediate 
other deficiencies, which prevented SBA from completing all corrective actions. Consequently, the risk 
assessment process did not adequately evaluate or address the risks associated with post-payment review and 
funds recovery for PPP loans.  
The following criteria were considered with respect to the matter described in the preceding paragraphs: 
• 
GAO’s Green Book, Principle 3, Establish Structure, Responsibility, and Authority; Principle 6, 
Define Objectives and Risk Tolerances; Principle 7, Identify, Analyze, and Respond to Risks; and 
Principle 10, Design Control Activities  
• 
OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk Management and 
Internal Control 
The deficiencies described above may result in a material misstatement to the Credit Program 
Receivables and Related Foreclosed Property, Net, and Downward Reestimate Payable to Treasury line 
items, and other related elements in the consolidated financial statement. 
Recommendations – Controls over PPP Loan Program Need Improvement 
We recommend the Administrator coordinate with the Associate Administrator for the Office of Capital 
Access to: 
6. Establish regular monitoring and reporting control activities to track progress of post payment 
reviews, to ensure timely and effective decision making related to implementation of funds 
recovery policies and procedures. (2024, recommendation 7) 
7. Strengthen the risk assessment process and conduct a risk-based, comprehensive analysis of 
the entire population of forgiven PPP loans to identify whether additional reviews may be 
needed in determining the complete and accurate population for funds recovery. (2024, 
recommendation 8) 

 
 
 
3. Controls over Subsidy Reestimate Need Improvement 
Statement of Federal Financial Accounting Standards Number 2, Accounting for Direct Loans and Loan 
Guarantees, requires that direct loans and loan guarantees obligated after September 30, 1991, be 
recorded on a present value basis consistent with the intent of the Federal Credit Reform Act of 1990. As 
such, SBA developed an estimation methodology to reestimate annually the future net cash inflows and 
outflows for the COVID-19 EIDLs and PPP loan portfolios as of the end of the fiscal year. 
Management’s review controls were not adequately designed and implemented over the data inputs used 
in the PPP and 7(a) Loan Guaranty subsidy reestimate models. Specifically, management did not provide 
sufficient documentation to evidence adequate review controls to validate the reliability of loan data used 
in key assumptions for the cash flow PPP model to develop the subsidy cost estimates. Further, 
management did not provide sufficient appropriate audit evidence to support the reliability for all key data 
elements used in the 7(a) reestimate model. 
In addition, management did not design and implement adequate review controls over the data inputs 
used for COVID-19 EIDLs subsidy reestimate. The reviews were in process as of the end of the fiscal year 
and not appropriately designed to identify a complete and accurate COVID-19 EIDLs population of 
outstanding loans disbursed to eligible recipients. 
These deficiencies were caused by management’s inability to coordinate and obtain the supporting 
documentation necessary to provide sufficient appropriate audit evidence to support the relevant data 
elements. Additionally, the control environment was insufficient with respect to the design and implementation 
of controls over the review of the PPP and COVID-19 EIDL portfolios. This review control was not sufficiently 
precise to ensure that the data inputs used for the reestimate models were complete and accurate. 
The following criteria were considered with respect to the matter described in the preceding paragraphs: 
• 
GAO’s Green Book, Principle 3, Establish Structure, Responsibility, and Authority; Principle 10, 
Design Control Activities; Principle 13, Use Quality Information; and Principle 14, Communicate 
Internally 
• 
OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk Management and 
Internal Control 
The deficiencies described above may result in a material misstatement to the subsidy reestimate 
impacting the Liability for Loan Guarantees, the Allowance for Direct Loan Receivables, and the 
Downward Reestimate Payable to Treasury and the related elements in the consolidated financial 
statement. 
Recommendations – Controls over Subsidy Reestimate Need Improvement 
We recommend the Administrator coordinate with the Chief Financial Officer to: 
8. Identify and implement a method to improve SBA’s ability to demonstrate evidence of 
adequate support and controls over relevant data elements in a timely manner.  
9. Continue implementing review controls in collaboration with relevant program offices for the 
PPP and COVID-19 EIDL portfolios to accumulate relevant, complete and accurate data on 
which to base the reestimate. (2024, recommendation 23) 
4. Entity Level Controls Need Improvement  
Management faced challenges in maintaining an adequate entity level controls system and enterprise risk 
management infrastructure and did not design or implement effective controls necessary to achieve its intended 
objective of reliable and accurate financial reporting. The significance of the internal control matters indicated 
weaknesses across several entity level control categories. The following conditions were identified. 

 
 
 
A. Control Environment  
Management did not establish an effective control environment. The following deficiencies were identified: 
• 
Management did not establish an agency-wide oversight body to govern the internal control system 
during the fiscal year. 
• 
Management did not establish a formal internal control plan to support the entity’s financial 
reporting objectives. In addition, there was no formal planning and accountability for the design and 
testing of controls. 
• 
Management did not effectively identify and remediate gaps in personnel roles and responsibilities 
within the agency’s organizational structure, particularly regarding the delegation of authority and 
assignment of roles within certain program offices. 
B. Risk Assessment  
Management did not perform effective risk assessment processes. The following deficiencies were identified: 
• 
Management did not establish a coordinated agency-wide risk assessment framework and a 
comprehensive evaluation of financial reporting. In addition, management did not perform an 
analysis of program and agency changes to address evolving risks specific to the fiscal year.  
• 
Management did not implement adequate risk assessment processes to effectively identify, 
analyze, and respond to relevant financial and reporting compliance risks for fiscal year 2025. For 
example, management did not sufficiently evaluate the risks related to the large-scale 
reinstatement of certain pandemic program transactions or consider the potential impact on the 
completeness of related portfolio balances in the consolidated financial statement. Additionally, 
management did not adequately respond to the increased risk of noncompliance with applicable 
laws arising from the significant volume of loans in delinquency status during fiscal year 2025. 
C. Control Activities 
Management did not adequately design and implement effective control activities. The following deficiencies 
were identified: 
• 
Management did not develop or implement agency-wide internal control testing plans during the 
fiscal year to support the entity’s financial reporting and compliance objectives, respond to relevant 
risks, or to achieve an effective internal control system. 
• 
Management did not adequately design or implement controls within the relevant program offices 
to operate at a sufficient level of precision to achieve the reporting objective of preparing financial 
statements free from material misstatement. For instance, the COVID-19 EIDLs and PPP loan 
review processes were not designed to ensure that the reviews conducted were precise enough to 
confirm that the related balances were free of material misstatement. 
D. Information & Communication 
Management did not adequately design and implement effective information and communication control 
processes. Specifically, management did not establish an agency-wide oversight body during the fiscal year to 
govern the internal control system. As a result, quality information on internal controls, policies, and procedures 
was incomplete, insufficient, unavailable, and impeded effective communication across all levels of authority 
and lines of responsibility to achieve internal control objectives. 

 
 
 
E. Monitoring 
Management did not design and implement effective monitoring processes. The following deficiencies were 
identified: 
• 
Management did not establish formal internal control testing plans at the agency-wide level, 
resulting in a lack of effective monitoring activities to evaluate the effectiveness of internal controls 
across the agency.  
• 
While certain deficiencies identified in the prior year were remediated, management did not fully 
design and implement corrective action plans to effectively remediate prior year findings in the 
current fiscal year.  
These deficiencies were caused by operational challenges that impeded the agency’s ability to support 
effective entity level controls throughout the fiscal year. A transition plan was under development at the end of 
the fiscal year to respond to resource constraints in order to properly prioritize and execute the agency’s 
enterprise risk management process, including the establishment of an agency-wide oversight body, 
development of internal control testing plans, and risk assessment frameworks.  
The following criteria were considered with respect to the matters described in the preceding paragraphs: 
• 
GAO’s Green Book, Principle 2, Exercise Oversight Responsibility; Principle 4, Demonstrate 
Commitment to Competence; Principle 6, Define Objectives and Risk Tolerances; Principle 7, 
Identify, Analyze, and Respond to Risks; Principle 9, Identify, Analyze, and Respond to Change; 
Principle 10, Design Control Activities; Principle 12, Implement Control Activities; Principle 13, Use 
Quality Information; Principle 14, Communicate Internally; Principle 16, Perform Monitoring 
Activities; and Principle 17, Evaluate Issues and Remediate Deficiencies 
• 
OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk Management and 
Internal Control 
As a result of the deficiencies described above, we noted that without the proper level of entity level controls 
in place and operating effectively, there is an increased risk that a material misstatement in the consolidated 
financial statement, and noncompliance with the relevant laws and regulations would neither be prevented 
nor detected and corrected in a timely manner. 
Recommendations – Entity Level Controls Need Improvement 
We recommend that the Administrator coordinate with the Chief Financial Officer to: 
10. Finalize and implement the transition plan to respond to resource constraints, which includes 
establishing the proper delegation of authority for personnel roles and responsibilities, 
ensuring the agency can properly design and effectively operate entity level controls 
throughout the fiscal year.  
11. Establish an agency-wide oversight body to provide governance, guidance, information and 
communication over internal control systems and risk management activities.  
12. Design, implement, and document comprehensive internal control testing plans and regularly 
monitor and evaluate the effectiveness of internal controls. (2024, recommendation 32) 
13. Coordinate with key stakeholders to develop robust risk assessment frameworks to identify, 
analyze, and respond to emerging or evolving risks across the agency. (2024, 
recommendation 31) 
 

 
 
 
Appendix II 
U.S. Small Business Administration  
Significant Deficiencies 
Monitoring of Restaurant Revitalization Fund and Shuttered Venue Operators Grant Programs Need 
Improvement 
A. Monitoring of RRF Awards 
The period to use RRF awards for eligible purposes expired in fiscal year 2023. SBA relies on award 
recipients to submit Post Award Reports to disclose the amount of the award used on eligible purposes prior to 
expiration. If any amount of the award was not used for eligible purposes before expiration, the unused funds 
must be returned to SBA. In fiscal year 2025, SBA implemented a process for funds recovery for RRF awards 
with eligibility concerns. 
Management did not sufficiently design and implement monitoring controls to evaluate the accuracy and 
completeness of accounts receivable balances impacted by their recovery of funds efforts. Management 
reviewed a sample of RRF awards and completed testing at the end of the fiscal year. However, 
management did not perform a detailed analysis and extrapolation of results. Further, management did 
not assess whether additional testing was needed to support the balances recorded at fiscal year-end. 
These deficiencies were caused by management’s risk assessment process not incorporating a final evaluation 
of sample results to determine whether the sampling risk was appropriate and supported their adjustments to 
accounts receivable related to the recovery of funds for RRF awards. 
The following criteria were considered with respect to the matters described in the preceding paragraphs: 
• 
GAO’s Green Book, Principle 10, Design Control Activities; and Principle 16, Perform Monitoring 
Activities 
• 
OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk Management and 
Internal Control 
The deficiencies described above may result in a misstatement to the Other than Intragovernmental 
Accounts Receivable, Net, line item and the related elements in the consolidated financial statement. 
Recommendations – Monitoring of RRF Awards 
We recommend the Administrator coordinate with the Associate Administrator for the Office of Capital 
Access to: 
14. Design and implement key monitoring control procedures earlier in the fiscal year to allow 
adequate time for thorough execution, review, and analysis before year-end. (2024, 
recommendation 15) 
15. Conduct a risk-based, comprehensive analysis of the RRF sample review results to identify 
whether additional reviews may be needed in determining the complete and accurate 
population for funds recovery. (2024, recommendation 16) 
B. Monitoring of SVOG Awards 
The period to use SVOG funds for eligible purposes expired in fiscal year 2023. The SBA relies on award 
recipients to submit an Expense Report and Standard Form (SF) 425, Federal Financial Report, to disclose the 
amount of the award used for eligible purposes prior to expiration. If any amount of the award was not used for 
eligible purposes before expiration, the unused funds must be returned to SBA. In fiscal year 2025, SBA 
implemented a process for funds recovery for SVOG awards with eligibility concerns. 

 
 
 
Management’s monitoring controls over SVOG awards to ensure compliance with the CARES Act and 
related legislation, as well as accurate financial reporting at fiscal year-end were not fully implemented. 
Specifically, as of September 30, 2025, certain awards lacked a submitted Expense Report or SF-425. 
Management also selected samples of SVOG awards to assess the accuracy of report submissions and 
recipient eligibility. However, sample reviews were not completed by the end of the fiscal year. 
Furthermore, management’s funds recovery process was not fully implemented for SVOG awards with 
identified eligibility concerns to support the balances recorded at year-end. 
These deficiencies were caused by the design and implementation of the funds recovery procedures occurring 
close to fiscal year-end, resulting in insufficient time to thoroughly execute sample reviews.  
The following criteria were considered with respect to the matters described in the preceding paragraphs: 
• 
Federal Accounting Standards Advisory Board (FASAB) Statement of Federal Financial Accounting 
Standards 1 (SFFAS 1): Accounting for Selected Assets and Liabilities 
• 
GAO’s Green Book, Principle 10, Design Control Activities; and Principle 13, Use Quality 
Information 
The deficiencies described above may result in a misstatement to the Other than Intragovernmental 
Accounts Receivable, Net, line item and the related elements in the consolidated financial statement. 
Recommendations – Monitoring of SVOG Awards 
We recommend the Administrator coordinate with the Associate Administrator for the Office of Disaster, 
Recovery, and Resilience to: 
16. Complete the outstanding sample reviews to identify the complete population of recipients that may 
not have been eligible to receive awards or that may have spent awards on ineligible expenses in 
accordance with the program’s terms. This will ensure the data provided to the Office of 
Performance, Planning, and the Chief Financial Officer (OPPCFO) is complete, accurate and 
reported in a timely manner for year-end financial reporting. (2024, recommendations 18 & 19) 
 

 
 
 
Appendix III 
U.S. Small Business Administration  
Compliance and Other Matters 
A. Debt Collection Improvement Act of 1996, as amended (DCIA) 
Certain provisions of the DCIA require agencies to notify and refer debts that are delinquent by 120 days or 
more, for purposes of administrative offset and centralized collection, to the U.S. Department of Treasury 
(Treasury). 
Management did not refer delinquent loans to the Treasury for collection within the required timeframe. 
Management identified and communicated that approximately 481,258 COVID-EIDLs and 81,782 PPP loans 
were noncompliant with DCIA requirements for the fiscal year ended September 30, 2025. 
In addition, management did not design and implement effective controls to identify and refer delinquent loans 
that meet the criteria for referral to Treasury to ensure compliance with DCIA requirements. 
The conditions identified were caused by inadequate design and implementation of risk assessment and 
monitoring processes that enable management to identify, analyze, and respond to the relevant risks of 
noncompliance and to ensure delinquent loans were identified and referred to Treasury within the required 
timeframe. Also, the deficiencies were caused by inadequate system configuration in place to refer delinquent 
loans to Treasury within the appropriate timeframe.  
The following criteria were considered with respect to the matter described in the preceding paragraphs: 
• 
DCIA 
• 
GAO’s Green Book, Principle 9, Identify, Analyze, and Respond to Change; Principle 10, Design 
Control Activities; and Principle 16, Performing Monitoring Activities.  
As a result of delays and absence of referrals of delinquent borrowers and guarantors to Treasury, SBA did 
not comply with DCIA requirements. 
Recommendations – DCIA 
We recommend the Administrator coordinate with the Associate Administrator for the Office of Capital Access 
to: 
17. Reevaluate delinquency policies and procedures, such as system controls and configurations, to 
ensure borrowers are notified timely of delinquency, and if applicable, subsequently referred within 
the required timeframe. (2024, recommendation 52) 
18. Update risk assessment and monitoring controls to address and mitigate noncompliance risks 
related to DCIA. (2024, recommendation 51) 
19. Document the review and assessment of current and prospective processes and policies to ensure 
they address compliance risks. (2024, recommendation 50) 
 
 

 
 
 
B. Federal Managers’ Financial Integrity Act of 1982 (FMFIA)  
Management did not perform an internal control assessment as required under FMFIA and did not comply with 
FMFIA and the related OMB Circular No. A-123 requirements. Specifically, management did not:  
• 
Document a comprehensive evaluation of internal control over financial reporting regarding current 
programs while giving consideration to relevant risks during the fiscal year. 
• 
Design or establish a formal internal control program, including the design and implementation of 
risk assessment processes and testing across SBA programs and functions.  
• 
Ensure their own assurance process was sufficient to identify material weaknesses and significant 
deficiencies that existed during the fiscal year in addition to those identified by external auditors. 
This noncompliance was caused by operational challenges that impeded the agency’s ability to support 
effective entity level controls and FMFIA compliance throughout the fiscal year. A transition plan was under 
development at the end of the fiscal year to properly prioritize and execute the agency’s enterprise risk 
management process, which led to insufficient oversight and validation in management’s assurance process. 
The following criteria were considered with respect to the matter described in the preceding paragraphs: 
• 
Section 2 of FMFIA 
• 
OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk Management and 
Internal Control 
Management did not comply with FMFIA and the related OMB Circular No. A-123 requirements, which may 
lead to not identifying the appropriate risks and key controls, and not detecting internal control or compliance 
deficiencies. The risk of not detecting and correcting control deficiencies could result in misstatements to the 
consolidated financial statement. 
Recommendations – FMFIA 
We recommend the Administrator coordinate with the Chief Financial Officer to: 
20. Strengthen controls, such as entity level controls, manual controls, general information technology 
controls, and system application controls by developing standardized procedures for assessing and 
reporting on internal controls across all offices within SBA. (2024, recommendation 53) 
21. Collaborate with appropriate program office management to assess internal control testing results 
and revise corrective action plans to remediate identified control deficiencies. (2024, 
recommendation 54) 
22. Update existing policies and implement effective monitoring controls that incorporate independent 
validations of program offices’ Statement of Assurance (SOA) process.  Ensure that SOAs from all 
program offices are thoroughly documented and independently reviewed for completeness and 
accuracy, providing a reliable basis for the Administrator’s SOA. (2024, recommendation 55) 
 
 

 
 
 
C. Federal Financial Management Improvement Act of 1996 (FFMIA) 
Management did not establish and maintain financial management systems that substantially comply with the 
following FFMIA requirements:  
• 
Federal Financial Management Systems Requirements. As discussed in Appendix I – Material 
Weaknesses, control deficiencies over direct and guaranty loan transactions do not enable reliable 
and accurate financial reporting, do not ensure compliance objectives are met. 
• 
Federal Accounting Standards. The deficiencies identified and reported in Appendix I – Material 
Weaknesses, provide an indication that SBA’s financial systems were substantially noncompliant 
with applicable federal accounting standards. For example, management did not apply consistent 
accounting treatment over the COVID-19 EIDL and PPP loan programs.  
Management did not substantially meet FFMIA requirements because of the reasons discussed in Appendix I – 
Material Weaknesses and due to an inadequate agency-wide control environment to implement the provisions 
of the CARES Act and related legislation with sufficiently designed and implemented controls. 
The following criteria were considered with respect to the matter described in the preceding paragraphs: 
• 
Section 803(a) of FFMIA 
• 
GAO’s Green Book, Section 2, Establishing an Effective Internal Control System 
• 
Appendix D to OMB Circular No. A-123, Compliance with the Federal Financial Management 
Improvement Act of 1996 
Management did not substantially comply with FFMIA, increasing the risk that transactions are incorrectly 
recorded to the general ledger, impacting the completeness, existence, and accuracy of the balances in the 
consolidated financial statement. 
Recommendations – FFMIA 
We recommend the Administrator coordinate with the Chief Financial Officer to: 
23. Address the control deficiencies over transactions arising from the implementation of the 
CARES Act and related legislation by working with the Office of Capital Access and the Office 
of Disaster Recovery and Resilience to implement the recommendations in Appendix I – 
Material Weaknesses. (2024, recommendation 56) 
 

 
CFO Response to Audit Report on FY 2025 Financial Statements 
 
 
DATE: 
January 21, 2026 
TO: 
William Kirk, Inspector General 
FROM: 
Nathan Davis, Chief Financial Officer and Chief Risk Officer 
SUBJECT: 
FY 2025 Financial Statement Audit 
 
The Small Business Administration (SBA) has reviewed the Independent Auditors’ Report issued 
by KPMG, which includes a disclaimer of opinion on the Agency’s FY 2025 Consolidated Balance 
Sheet. The independent audit of the Agency’s financial statements and related processes is a core 
component of SBA’s financial management program, and management takes the results of this 
audit seriously. 
The FY 2025 Agency Financial Report (AFR) reflects meaningful improvements resulting from 
sustained leadership focus, cross-functional collaboration and disciplined execution of corrective 
action plans. During the fiscal year, material weaknesses related to Controls over Service 
Organizations and Controls over General Information Technology were fully remediated. In 
addition, significant deficiencies related to Controls over Payments for Debt Relief and Controls 
over Reporting of Contingencies were also fully remediated. Further, the material weakness 
related to Controls over Monitoring of Restaurant Revitalization Fund and Shuttered Venues 
Operators Grant Programs was downgraded to a significant deficiency. These outcomes 
demonstrate tangible progress in strengthening SBA’s financial management and internal control 
environment.  
The auditors identified material weaknesses related to the internal controls over four areas: 
COVID-19 Economic Injury Disaster Loans (EIDL), Paycheck Protection Program (PPP) Loan 
Program, Subsidy Reestimate, and Entity Level Controls. Management agrees that certain 
conditions identified in the audit report and associated with these material weaknesses were the 
result of the auditors’ inability to obtain sufficient and appropriate audit evidence.  However, 
management does not fully concur with several underlying characterizations and contributing 
factors that are presented within the audit report for the reported material weaknesses related to 
internal controls over COVID-19 EIDL and Subsidy Re-estimate.  In particular, 
• 
Management disagrees with the characterization that the COVID-19 EIDL population 
analysis was inadequate as of the balance sheet date (September 30, 2025).  Management 
assessed the population and concluded that it was complete and appropriate for financial 
reporting purposes. Management acknowledges, however, that certain data attributes 
supporting this analysis were not available in the form requested by KPMG at the time of 
their audit procedures (December 2025), due to the inability to reproduce the population at 

a prior point in time. This limitation reflects challenges associated with retrospective audit 
evidence requirements rather than deficiencies in management’s assessment as of the 
reporting date. (Material Weakness 1) 
 
Additionally, management disagrees with the auditors’ conclusions regarding certain 
review controls. SBA does not believe that additional reviews of the population for potential 
fraud or identity theft would alter management’s assessment of the completeness of the 
population for financial reporting purposes. (Material Weakness 1, Recommendation 1) 
 
Management agrees that a material weakness exists related to controls over COVID-19 
EIDLs because of inconsistent accounting treatment of the COVID EIDL population and 
the need for improvements in the controls over the reinstatement process implemented in 
the fourth quarter of FY 2025.  (Material Weakness 1)  
 
• 
Management does not believe that there is a clear or likely indicator that SBA does not have 
adequate controls over the data inputs used in the 7(a) Loan Guaranty subsidy reestimate 
model. The conditions noted by the auditor in the reported subsidy reestimate material 
weakness were primarily due to the timing of when the audit procedure was initiated and 
performed; the complexity involved with obtaining documentation from third parties, 
which increases the amount of time necessary to obtain supporting documents; and the 
fact that this was the first time this audit procedure was performed, which led to a 
“learning curve” for both the auditor and SBA as to the best approach for testing and 
obtaining documentation for audit evidence. Although SBA does not agree that the 
conditions reported are likely to result in a material misstatement, SBA is committed to 
identifying and implementing a method that improves SBA’s ability to demonstrate 
evidence of adequate support and controls over the over the data elements in a timely 
manner.  (Material Weakness 3)   
 
Additionally, management disagrees with the inclusion of PPP and COVID-19 EIDL within 
the reported material weakness related to controls over the subsidy reestimate. The 
underlying conditions and impacts associated with PPP and COVID-19 EIDL are already 
reflected within Material Weaknesses 1 and 2. Because the root causes and corrective 
actions overlap, inclusion within the subsidy reestimate material weakness is duplicative 
and may be misleading.  Additionally, as indicated above, management disagrees with the 
auditor regarding COVID-19 EIDL review controls. SBA does not believe additional 
reviews of the population would alter its assessment of completeness of the population.  
(Material Weakness 3, Recommendation 9) 
 
• 
Management does not agree that SBA is not in substantial compliance with the FFMIA.  
SBA’s core financial management systems are substantially compliant with Federal 
financial management systems requirements, applicable Federal accounting standards and 

USSGL at the transaction level. The deficiencies the auditor cited as causing FFMIA non-
compliance were due to factors external to the core financial management systems, rather 
than a limitation in the system’s design or ability to prepare financial statements, 
disclosures and related information. For example, SBA’s assessment is that the material 
weaknesses cited by the auditor are related to the COVID-19 EIDL and PPP programs are 
the result of material uncertainty regarding completeness of populations and potential 
funds recovery policy decisions. As such, management does not believe this constitutes 
substantial FFMIA noncompliance.  (Compliance C, Recommendation 23) 
Management respects the independent role of the auditors and values their perspectives, and 
we remain committed to constructive engagement to resolve these matters. At the same time, 
management believes it is important to distinguish between limitations associated with large-
scale COVID-19 pandemic-era programs, which were executed under emergency conditions, 
and the effectiveness of SBA’s current control environment governing ongoing operations.     
Notwithstanding these differences, management recognizes the seriousness of the conditions 
contributing to the disclaimer of opinion. SBA remains focused on sustaining the improvements 
achieved in FY 2025 and building upon them in the year ahead. Management will continue to 
evaluate auditor recommendations and, where appropriate, refine our processes and controls to 
address identified areas of concern.   
We appreciate the efforts of the Office of the Inspector General and KPMG, and we remain 
committed to continued progress in strengthening SBA’s financial management and oversight 
capabilities. 
 

Appendix V 
Auditors’ Response to Management’s Response 
We acknowledge SBA management’s response to our Independent Auditors’ Report, presented in Attachment 
IV, and commend their commitment to financial management and the accountability for and transparency of 
their programs. SBA management agreed with two of the areas of material weakness included in our report, 
Controls over Paycheck Protection Program (PPP) Loan Program Need Improvement and Entity Level Controls 
Need Improvement. However, management did not agree in part with the other two areas of material 
weaknesses included in our report, Controls over Coronavirus Disease 2019 (COVID-19) Economic Injury 
Disaster Loans (EIDLs) Need Improvement and Controls over Subsidy Reestimate Need Improvement. 
Additionally, management did not agree with our finding over the agency’s substantial noncompliance with 
Federal Financial Management Improvement Act of 1996 (FFMIA). 
We have reviewed management’s responses and have determined that all aspects of the material weaknesses 
in internal control over financial reporting and substantial noncompliance with FFMIA remain appropriate. We 
provide the following additional information related to the Controls over Coronavirus Disease 2019 (COVID-19) 
Economic Injury Disaster Loans (EIDLs) Need Improvement, Controls over Subsidy Reestimate Need 
Improvement, and our findings related to substantial noncompliance with the Federal Financial Management 
Improvement Act of 1996 (FFMIA). 
In the area of COVID-19 EIDL: 
• 
Management indicated that they assessed the COVID-19 EIDL portfolio and determined it was complete 
and accurate. However, the data supporting management’s analysis and conclusion did not substantiate 
management’s analysis performed. We identified examples where loans were included in the COVID-19 
EIDL population and the Credit Program Receivable balance at September 30, 2025, however these loans 
were recorded with a zero balance in management’s analysis. As a result, the data utilized in 
management’s analysis did not support management’s conclusion regarding the completeness and 
accuracy of the COVID-19 EIDL population. Further, management indicated that their inability to provide 
supporting evidence over the COVID-19 EIDL population was due to an audit evidence requirement. 
However, OMB Circular A-123, Management's Responsibility for Internal Control, requires management to 
establish and maintain effective internal controls to ensure reliable financial reporting. As part of this 
responsibility, management must maintain sufficient documentation to support its financial transactions and 
account balances.  
• 
Management indicated that they believe additional review would not alter their assessment of the 
completeness of the COVID-19 EIDL population. However, management’s review control is not designed to 
remove COVID-19 EIDLs with similar eligibility concerns from the portfolio in a consistent manner. We 
identified COVID-19 EIDLs with similar eligibility characteristics that were both included in the Credit 
Program Receivable balance as of September 30, 2025, and written off to be excluded from this balance, 
which resulted in inconsistent accounting treatment. As a result, management did not design and 
implement adequate monitoring controls and review processes to support the completeness and accuracy 
of the COVID-19 EIDL portfolio and related financial data as of year-end.  
In the area of the Subsidy Reestimate: 
• 
Management disagrees with our finding that SBA did not have adequate controls over the data inputs. 
However, management did not provide the necessary supporting documentation for the integral data 
related to borrower characteristics and the underlying loans used in the 7(a) Loan Guaranty subsidy 
reestimate model. Management attributed the material weakness in the 7(a) Loan Guaranty reestimate to 
the nature and timing of the audit procedures and complexity involved in obtaining supporting 
documentation from third parties. However, it is management’s responsibility to maintain, support, and 
report the information for the loan guaranty reestimate. The material weakness resulted from 

management’s ineffective coordination with third parties to obtain the necessary supporting documentation 
for the relevant data elements. As a result, the loan guaranty reestimate material weakness existed as of 
September 30, 2025. 
• 
Management indicated that elements of material weakness entitled Controls over Subsidy Reestimate 
Need Improvement are already covered by material weaknesses entitled Controls Over COVID-19 EIDLs 
Need Improvement and Controls Over PPP Loan Program Need Improvement. This is not accurate, as the 
material weakness entitled Controls Over Subsidy Reestimate Need Improvement specifically pertains to 
the controls over the data inputs used in the subsidy reestimate models, while the material weaknesses 
entitled Controls Over COVID-19 EIDLs Need Improvement and Controls Over PPP Loan Program Need 
Improvement address separate findings relating to the controls over the COVID-19 EIDL portfolio and 
controls over the post-payment review of forgiven PPP loans, respectively. 
In the area of FFMIA: 
• 
Management indicated that they believe SBA’s financial management systems are in substantial 
compliance with Federal financial management systems requirements and Federal accounting standards. 
FFMIA defines Federal financial management systems as software, hardware, processes, procedures, and 
controls necessary to support financial management. In our evaluation of management’s compliance with 
FFMIA and based on the Basis for Disclaimer of Opinion and the material weaknesses identified, we 
determined that management was unable to demonstrate substantial compliance with Federal financial 
management systems requirements. Additionally, management was unable to consistently, completely, and 
accurately record and account for balances and transactions in accordance with generally accepted 
accounting principles, resulting in substantial noncompliance with Federal accounting standards.

File and source

File
26-03-fy2025-financial-statements-audit.pdf
Size
784,154 bytes
SHA-256
507ac6e5af3a71587978f94a144155ec0aef95305cd4c05f7129de7a32dbec18
Our copy
26-03-fy2025-financial-statements-audit.pdf
Original
www.oversight.gov
Back to top