OMB Circular A-123: Internal Control, ERM, and Fraud Risk

OMB Circular A-123 is the Office of Management and Budget’s directive telling executive branch agencies how to build, maintain, assess, and report on internal controls over their operations, financial reporting, and legal compliance, and how to manage risk across the enterprise. It draws its authority from the Federal Managers’ Financial Integrity Act of 1982 and the GPRA Modernization Act of 2010, and it makes each agency head personally responsible for whether those controls actually work.1The White House. OMB Circular No. A-123, Management’s Responsibility for Internal Control The current version was issued in March 2026 and supersedes every prior revision.

Who Must Comply and Under What Authority

The statutory backbone is 31 U.S.C. § 3512. It requires each executive agency head to establish internal accounting and administrative controls that reasonably ensure obligations and costs comply with applicable law, that assets are safeguarded against waste and unauthorized use, and that revenues and expenditures are properly recorded. The same statute directs the OMB Director to issue guidelines for evaluating whether agencies meet those requirements.2Office of the Law Revision Counsel. 31 USC 3512 – Executive Agency Accounting and Other Financial Management Reports and Plans A-123 is those guidelines.

The circular applies to every executive agency as defined in 31 U.S.C. § 102, including independent regulatory agencies. That sweep covers cabinet departments, standalone agencies such as EPA and NASA, and regulatory bodies such as the SEC and FCC.1The White House. OMB Circular No. A-123, Management’s Responsibility for Internal Control Compliance is not discretionary. The statute mandates it; A-123 translates the mandate into operational expectations.

What Agencies Must Do

A-123 imposes three overlapping obligations: run an enterprise risk management program, maintain a working system of internal control, and treat fraud risk as a first-class part of both.

Enterprise Risk Management

Leadership must look at risks across the whole organization rather than program by program. A Chief Risk Officer or equivalent senior official champions the effort and gives agency leaders a portfolio view of what could go wrong.3The White House. OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk Management and Internal Control Each agency defines its risk appetite — the level and type of risk it will accept to pursue its mission — and sets tighter risk tolerances for individual programs and objectives. Employees at every level are expected to understand both.

Agencies must also prepare a formal risk profile documenting the most significant threats to their objectives and refresh it at least annually. The profile feeds directly into strategic planning, a link reinforced by the GPRA Modernization Act, which requires agencies to identify key factors affecting goal achievement, describe management challenges, and categorize priority goals by the risk of falling short.4U.S. Congress. GPRA Modernization Act of 2010

Internal Control Standards

The design standards for internal controls come from the Government Accountability Office’s Standards for Internal Control in the Federal Government, widely known as the Green Book. The 2025 revision (GAO-25-107721) takes effect with fiscal year 2026 reporting. It defines internal control as a continuous process that provides reasonable assurance over three categories of objectives: operations, reporting, and compliance.5U.S. Government Accountability Office. Standards for Internal Control in the Federal Government (Green Book)

The Green Book organizes internal control into five components that must work together:

  • Control environment: the foundation of integrity, ethical values, accountability, and competence that leadership sets.
  • Risk assessment: identifying and analyzing risks, including fraud, and deciding how to respond.
  • Control activities: the policies, procedures, and actions that carry out those responses, from approval workflows to system access restrictions.
  • Information and communication: generating and sharing the quality information controls need to function.
  • Monitoring: ongoing and separate evaluations to determine whether the other components are working, with prompt remediation when they are not.

Seventeen underlying principles support the five components. The structure is deliberately binary: if any principle is not operating effectively, the associated component fails, and if any component fails, the entire system of internal control cannot be considered effective.5U.S. Government Accountability Office. Standards for Internal Control in the Federal Government (Green Book)

Fraud Risk

Fraud risk management is not a side program. Under 31 U.S.C. § 3357, agencies must evaluate fraud risks using a risk-based approach, design controls specifically to mitigate them, and continuously improve prevention by analyzing detection and reporting data.6Office of the Law Revision Counsel. 31 USC 3357 – Financial and Administrative Controls Relating to Fraud and Improper Payments The 2025 Green Book reinforces this by making fraud, improper payments, and information security explicit considerations under the risk assessment component.5U.S. Government Accountability Office. Standards for Internal Control in the Federal Government (Green Book)

How Agencies Assess and Report

A-123 lays out a structured assessment that agencies must complete before reporting on the state of their controls. Management evaluates controls for each principle across each objective category, aggregates the deficiencies found, evaluates whether each of the 17 principles is designed, implemented, and operating effectively, rolls those conclusions up to the component level, and then reaches an overall conclusion on whether all five components function together as an integrated system.1The White House. OMB Circular No. A-123, Management’s Responsibility for Internal Control

Testing runs on two tracks. Design testing asks whether the right controls exist and would work if performed as intended. Operating effectiveness testing asks whether employees actually perform them, typically through transaction sampling, documentation review, or direct observation. A well-designed control that nobody follows is just a policy on paper.

Deficiency Tiers

When testing surfaces problems, management categorizes them in three tiers:

  • Control deficiency: a gap in design or operation that does not rise to a higher tier.
  • Significant deficiency: serious enough to warrant attention from those responsible for governance, but not likely to cause a material misstatement.
  • Material weakness: a deficiency, or combination of deficiencies, creating a reasonable possibility that a material misstatement of the agency’s financial statements will not be prevented or detected and corrected on a timely basis.1The White House. OMB Circular No. A-123, Management’s Responsibility for Internal Control

Severity turns on aggregation as well as individual weight. Minor deficiencies affecting related processes or the same financial statement line item can combine into something material, and agencies that assess them one at a time often underestimate exposure.

Statement of Assurance

Once the assessment is done, the agency head signs a Statement of Assurance — a personal conclusion on whether the agency’s internal controls work. It takes one of three forms: unmodified assurance (controls effective, no material weaknesses), modified assurance (generally effective, with specific material weaknesses or compliance gaps identified), or no assurance (pervasive material weaknesses, or no assessment process in place).3The White House. OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk Management and Internal Control The statement appears in the Agency Financial Report or Performance and Accountability Report, which agencies normally publish by November 15.7U.S. Department of the Treasury. Chapter 4700 – Federal Entity Reporting Requirements for the Financial Report of the United States Government

Corrective Action

Every identified deficiency requires a corrective action plan with specific elements: root cause analysis, milestones, planned actions, measurable remediation indicators, the responsible official, and a target completion date.1The White House. OMB Circular No. A-123, Management’s Responsibility for Internal Control Agencies that treat symptoms rather than causes tend to report the same weakness year after year. Any material weakness unresolved at reporting time must be summarized in the financial report with a status update and resolution timeline. Corrective actions cannot be declared complete until they have been tested, verified, documented in writing, and supported by evidence, and performance appraisals of responsible officials may reflect their effectiveness at driving remediation.

What the Four Appendices Cover

Most of the operational detail sits in four appendices that remain in effect alongside the 2026 main body.

Appendix A supplies the methodology for assessing, documenting, and reporting on internal controls over reporting, both financial and non-financial. Documentation scales with agency size, but at minimum agencies must document their rationale for any principle deemed not relevant, their written internal control policies, monitoring results, and corrective actions.3The White House. OMB Circular No. A-123, Management’s Responsibility for Enterprise Risk Management and Internal Control

Appendix B governs government purchase, travel, and fleet card programs. Each agency maintains a written charge card management plan, updates it annually, and submits it to OMB by January 31. Cardholders and managers must complete training before receiving privileges and refresher training at least every three years.8The White House. OMB Circular A-123, Appendix B – A Guide to Opportunities for Improving Grant Accountability

Appendix C implements the Payment Integrity Information Act of 2019. Every program spending more than $10 million annually must conduct an improper payment risk assessment at least once every three years. A program is susceptible to significant improper payments if those payments could exceed either $10 million and 1.5 percent of program outlays, or $100 million regardless of the percentage.9U.S. Congress. S.375 – Payment Integrity Information Act of 2019 Programs that cross those thresholds must publish annual improper payment estimates, set reduction targets, develop corrective action plans, and demonstrate improvement. Programs with annual monetary loss estimates of $100 million or more are designated “high-priority” and face additional quarterly reporting to their Inspector General and OMB.10The White House. M-21-19 – Appendix C to OMB Circular A-123, Requirements for Payment Integrity Improvement

Appendix D governs compliance with the Federal Financial Management Improvement Act of 1996 and applies to the 24 CFO Act agencies. It requires substantial compliance with federal financial management systems requirements, federal accounting standards issued by the Federal Accounting Standards Advisory Board, and the U.S. Government Standard General Ledger at the transaction level.11The White House. M-23-06, Appendix D to OMB Circular No. A-123 – Management of Financial Management Systems, Risk and Compliance

What Changed in the 2026 Revision

The March 2026 update shifts tone as well as content. OMB stated that previous iterations of A-123 had “overly deferred to direction and priorities of external entities whose views are not binding on the Executive Branch such as the Government Accountability Office,” and that the result was internal control processes that failed to adequately protect taxpayer dollars.1The White House. OMB Circular No. A-123, Management’s Responsibility for Internal Control The revision emphasizes a preventative, risk-informed approach and positions agency leadership, rather than external standard-setters, as the primary drivers of how controls are designed and prioritized. It supersedes all prior versions, so agencies operating under policies written against the 2016 circular should review the current text before their next assessment cycle.