The IRS was handed a simple assignment: help the Trump administration find waste, cut unnecessary contracts, and protect taxpayer money.
To do it, the agency built a Procurement Hub for the government-wide “Defend the Spend” initiative. Then, the watchdog arrived and found the IRS had rushed the tool into service while bypassing some of the very contracting and security controls designed to protect taxpayer money.
We found that the expedited procurement and deployment of the Procurement Hub bypassed key preventive controls. For example, the third contract for the Procurement Hub, valued at $4.5 million did not include clear milestones or deliverables for the engineering services. The IRS also paid the vendor in full at the beginning of the period of performance.
According to the IRS, this was because the contract was a software licensing contract and those costs are paid upfront. In addition, the IRS did not complete sufficient market research before awarding the $4.5 million contract, despite a significant price increase from the first 2 contracts. The third contract expires in September 2026.
Additional market research could prevent future potentially unnecessary spending. Furthermore, the IRS bypassed key security controls for the new Procurement Hub. For example, the Procurement Hub was deployed without properly assessing and documenting the risk of adding the system to an existing analytic platform environment.
In addition, most Procurement Hub users were allowed to bypass the IRS’s access control system. Federal agencies are required to e
The Procurement Hub started modestly. The IRS signed two contracts with the same vendor in 2025, each worth $250,000, covering the first six months of development and operation. Then came the third contract: $4.5 million for another 12 months, including AI capabilities intended to expand what the system could do.
TIGTA found the IRS didn’t conduct sufficient market research before making that $4.5 million commitment, even though the introductory pricing had disappeared and the price climbed sharply. The watchdog also found the contract lacked clear milestones or deliverables for its engineering work, making it harder for the agency to measure whether the vendor actually delivered what taxpayers bought.
Then there was the payment. The IRS paid the entire $4.5 million upfront in October 2025. Agency officials said software licensing costs are paid that way, but TIGTA noted the contract also contained $651,000 in engineering services and concluded that paying that portion upfront was inappropriate because it reduced the government’s leverage if the work wasn’t completed.
Security controls didn’t fare much better. Of 1,017 employees with access to the Procurement Hub in September 2025, 959, or 94%, hadn’t gone through the IRS system required to approve and document access. Even the 58 who did use the system were granted permissions that TIGTA found didn’t properly reflect their actual levels of access.
National Institute for Standards and Technology requires an updated authorization in the following circumstances:
- Change in the Authorizing Official. The IRS changed the Authorizing Official for the analytic platform in April 2025. Therefore, an updated authorization should have been completed at that time.
- Significant changes to the system. The IRS added the Procurement Hub to the analytic platform, which changed the type of information being processed and stored. According to NIST, significant changes to the system include modifications to how information is processed; changes in information types processed, stored, or transmitted by the system; or modifications to security and privacy controls.
- Significant changes to the operational environment. A new mission to the analytic platform by adding the Procurement Hub (i.e., consolidating contract data). This was not previously part of analytic platform’s core mission. According to NIST, significant changes to the system include adding new core missions or business functions.
The numbers get stranger. TIGTA found 903 of the 1,017 people with access never used the Procurement Hub during the six-month period it examined. IRS policy required accounts to be disabled after 120 days of inactivity, yet those dormant accounts remained active for at least 164 days, leaving another avoidable security risk hanging around a system that contained contract information, including material that could be sensitive or proprietary.
Why were so many basic controls bypassed? TIGTA said IRS officials pointed to the rush to get the Procurement Hub operational, a decision made at the direction of a senior IRS official. The watchdog warned that weak controls can produce inaccurate information, wasted resources, and a lack of accountability, which is an uncomfortable list for a system created specifically to help Washington eliminate waste and improve efficiency.
Oversight.gov lists $4,458,165 in questioned costs tied to the audit. That figure shouldn’t be confused with a finding that $4.46 million was stolen or entirely wasted. It means TIGTA questioned whether those expenditures were properly supported under the contracting controls it examined, while recommending better milestones, stronger market research, and proper security authorization.
The IRS agreed or partially agreed with all three recommendations. More tellingly, after TIGTA issued its draft report, the agency announced on September 21 that it would sunset the Procurement Hub and terminated access two days later, with plans to move its functions to an existing platform.
President Donald Trump’s Defend the Spend idea was supposed to force Washington to justify how it spends taxpayers’ money. At the IRS, the tool built to help enforce that discipline became an example of why the discipline was needed in the first place. A government serious about cutting waste can’t afford to rush past the controls protecting the money it says it wants to save.