Dive Brief:
- The Federal Reserve’s Office of Inspector General has flagged gaps in the central bank board’s ability to pinpoint and respond swiftly if information is removed by an exiting employee, the watchdog said Monday.
- The OIG issued a management alert prior to the completion of its planned audit over “concerns about the Board’s diligence” in resolving a 2024 information security situation. “This potential incident highlighted information security risks and control breakdowns and deficiencies that we believe require the Board's immediate attention so that it can take appropriate corrective actions,” the OIG said in the Thursday report.
- The watchdog offered recommendations to prevent and address future incidents, including enhancing governance of the Fed’s information security program and strengthening enforcement.
Dive Insight:
The OIG’s alert related to a departing division of international finance employee who potentially removed Federal Open Market Committee classified and other sensitive information. The OIG learned of this in July 2025, a year after the employee retired.
In February 2024, the employee had announced plans to retire as well as a desire to remove files before their departure, the report said. That June, the employee traveled to a country the Fed board had designated as restricted, and the international finance division was unaware of those travel plans.
The information incident began shortly before that travel and continued past the employee's retirement in July 2024, the OIG report said.
“We became increasingly concerned about this incident after becoming aware of a previous incident of this employee improperly removing sensitive FOMC classified information by transferring it to an unencrypted USB device,” the OIG said.
That occurred in 2021, when the information security operations team notified the international finance division that the employee copied files to the device, the report said. “Documentation showed that the employee claimed that they mistakenly thought they were using an encrypted USB device to back up files,” the OIG noted.
And in 2023, the same employee tried to send sensitive FOMC classified information to their personal email account. The international finance division told the OIG that the employee claimed this was inadvertent.
Despite counseling about using an encrypted USB device when transferring sensitive information, the employee engaged in similar activity before their 2024 retirement, without seeking their supervisor’s review, the OIG said.
Although there wasn’t sufficient basis to pursue a misconduct investigation of the 2024 offboarding information removal incident – in part because many alerts related to the potential removal of sensitive information were false positives – it did “help to illustrate the systemic concerns about the offboarding process we have identified in this review,” the OIG said.
Those include “information security risks and control breakdowns and deficiencies that we believe require the Board’s immediate attention,” the OIG said. “The failures involved a collective lack of action across multiple divisions, and the limited follow-up activities that did occur were not commensurate with the accumulation of risks in this situation.”
In particular, the board’s governance of its information security program and enforcement of controls lack clarity, driven by various groups’ “conflicting understanding of escalation and resolution responsibilities,” which “contributed to the incident remaining unresolved for over a year,” the report said.
“Clear standardized processes and roles and responsibilities for all groups, as well as a sense of shared responsibility, will enable the Board to respond to such incidents appropriately,” the OIG said.
Otherwise, “process weaknesses are likely to persist, undermining the effectiveness of the Board's overall information security program and increasing the risk of a major information security breach,” the OIG warned.
The OIG also determined the Fed’s review of the information removal incident was insufficient, as are its policies for responding to information removal incidents, and the board didn’t escalate the possible incident as it should have.
The Fed board concurred with the OIG’s various recommendations. Among other improvements, the central bank plans to implement processes and protocols to define roles and responsibilities and strengthen escalation alerts by the first quarter of 2027, and intends to create enhanced monitoring capabilities and escalation protocols through implementation of a new data loss prevention solution by the third quarter of 2027, the report said.