If you've ever waited weeks for an SBA loan decision, wondered why a certification application seemed to vanish into a black hole, or worried that a routine data mismatch might get your business flagged as fraudulent, a new federal watchdog report explains a lot. In June 2026, the Government Accountability Office (GAO) released its latest checkup on the Small Business Administration — and the results aren't reassuring. Of the 17 highest-priority fixes GAO identified for the agency back in May 2025, SBA has only closed out three. Fourteen are still open, more than a year later.
That's not a routine bureaucratic footnote. These are the specific problems GAO's auditors consider most likely to cause real damage — wasted taxpayer money, easier fraud, and technology failures — if they stay unfixed. And two of the biggest clusters land directly on things small business owners touch: how SBA screens loan and disaster-aid applicants for fraud, and the digital systems used to apply for and maintain SBA certifications and financing.
What a "Priority Open Recommendation" Actually Is
Every year, GAO reviews the hundreds of recommendations it has made to federal agencies and picks out the ones its auditors judge most urgent — problems serious enough that GAO sends a formal letter directly to agency leadership rather than letting the finding sit in a routine audit report. For SBA, that priority list in 2025 numbered 17 items. As of GAO's June 2026 follow-up (GAO-26-108956), 3 have been implemented and 14 remain open, out of 60 total open recommendations across the agency.
GAO groups the unfinished work into two categories it says deserve the most immediate attention:
- Fraud risk management in COVID-19 pandemic programs — the systems and processes SBA uses to catch bad actors in programs like COVID-EIDL and PPP, and by extension, the fraud controls that inform how SBA screens applicants going forward.
- Cybersecurity and IT management — the technology infrastructure behind the systems small businesses actually use, including the platform that handles federal contracting certifications.
Neither category is abstract. Both shape whether the loan or certification process you interact with today works the way it's supposed to.
The Fraud-Control Gap: A System Drowning in Bad Data
GAO's fraud findings center on a specific, concrete failure: SBA's process for referring suspected fraud to its Office of Inspector General (OIG) for investigation has been generating referrals that investigators can't actually use. According to GAO, SBA submitted almost 3 million fraud referrals tied to COVID-EIDL — and OIG officials told GAO that roughly 2 million of them weren't actionable. Not because the fraud wasn't real, but because the referrals were missing key data elements, contained duplicates, or had incorrect information baked in from the start.
To close this gap, GAO recommended SBA do two things it currently doesn't do well:
- Build cross-program data analytics so the agency can spot an applicant who's trying to defraud multiple SBA programs at once, instead of evaluating each program's applications in isolation.
- Obtain access to external data sources to independently verify what applicants report, rather than relying solely on self-reported information that a bad actor controls.
Both recommendations remain open. In practice, that means the fraud-detection net SBA is currently operating with still has the same structural gaps that let a fraction of pandemic-era relief slip through — and it's the same infrastructure that underpins fraud screening for whatever comes next, whether that's a future emergency lending program or ordinary 7(a) and disaster-loan underwriting today.
The IT Gap: The Platform Behind Your Certifications
The second cluster is more technical but arguably more disruptive day-to-day: SBA's Unified Certification Platform, the system built to let small businesses apply for and maintain certifications for federal contracting programs like 8(a), HUBZone, WOSB, and VOSB in one place instead of juggling separate legacy systems.
A dedicated GAO review of that platform (GAO-25-106963) found SBA hadn't done the basic groundwork that keeps a major IT project from derailing:
- No project-level risk management strategy and no risk mitigation plan.
- Risks not fully identified or documented.
- No documented plan for managing cybersecurity risks specific to the platform.
- No traceability analysis to confirm the system's security requirements were actually met — a gap GAO says raises the odds of a successful cyberattack.
GAO issued 14 recommendations from that review alone. SBA's response was mixed: it agreed with 3, partially agreed with 3, and disagreed outright with 8 — meaning a chunk of the identified risk isn't on a committed path to being fixed at all. Beyond the certification platform, GAO also flagged unresolved gaps in SBA's privacy workforce planning and continuing weaknesses under the Federal Information Security Modernization Act (FISMA), both independently confirmed by SBA's own Inspector General and outside financial auditors.
What This Means If You're the One Applying
None of this means don't use SBA programs — 7(a) loans, 504 loans, disaster assistance, and contracting certifications remain some of the most valuable financing and growth tools available to small businesses, often at terms the private market won't match. But a report like this is a useful signal to adjust your expectations and your own habits:
- Expect friction in the certification platform. If you're applying for or renewing an 8(a), HUBZone, WOSB, or VOSB certification, budget extra time and don't assume a stalled or glitchy application means you did something wrong. Save confirmation screenshots and correspondence at every step — with a system GAO says lacks basic risk documentation, your own paper trail is your best backstop.
- Keep your own records airtight. The fraud-referral breakdown GAO found wasn't really about fraud — it was about data quality. Duplicate entries, missing fields, and inconsistent information gummed up a system meant to catch bad actors. As a legitimate applicant, the clearer and more internally consistent your financial records are, the less likely a data mismatch is to slow down your own application or trigger an unnecessary review.
- Don't assume "approved" means "final." With external data verification still a gap rather than a strength, some of what SBA currently accepts at face value may get revisited later as the agency (eventually) builds out better cross-checks. Documentation you can produce on demand protects you either way.
Clean Books Are Your Best Defense Against a System Under Repair
A federal agency's IT and fraud-control backlog isn't something a small business owner can fix — but you can control how well-documented and internally consistent your own financial picture is, which is exactly the kind of clean, verifiable record GAO says SBA's systems currently struggle to cross-check on their own. Beancount.io gives you plain-text accounting that's transparent, version-controlled, and easy to hand over or audit whenever a lender, program administrator, or your own peace of mind requires it — no black box, no vendor lock-in. Get started for free and keep your records ready for whatever the process throws at you.