Skip to content

Invest1 publisher3 min readPublished

Fed's watchdog ties a year-long unresolved removal of classified FOMC files to unclear division roles

Fed's inspector general found that unclear roles among Fed divisions left a former staffer's removal of classified FOMC files unresolved for over a year. The Fed says its fix for escalating such alerts arrives by the first quarter of 2027, and part of the removed material has not been retrieved.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Fed's watchdog ties a year-long unresolved removal of classified FOMC files to unclear division roles
Generated illustration

What happened

  • Three months before retiring, the employee set off 279 data loss prevention alerts, and the tool flagged 111 of them as possibly involving FOMC classified information.
  • The information security team believed it could only alert the Records Management Program, while FOMC Secretariat staff wrongly believed the Legal Division had been told.
  • In 2023, the same employee unsuccessfully tried to send FOMC classified information to a personal email account.
  • Concern over the Board's handling led the OIG to issue a management alert before it finished its planned audit of offboarding records controls.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint The stall came from who owned escalation, so no single division, information security included, can close the gap by itself; any remedy has to assign responsibility across divisions.
  • exposure Until the protocols arrive in early 2027, Board staff leave under the escalation arrangements the OIG faulted, and rules for future alerts do not recover the files already taken.
  • decision The Fed now has to decide whether to go past role-and-escalation protocols to the consolidated insider-risk program the OIG says this case shows is needed.

Roughly 40% of the retiring employee's alerts, 111 of 279, pointed at possible FOMC classified material [1]. They fired shortly before what the report called a "personal trip to a restricted country" [8]. The Board's data loss prevention tool produced a signal. The OIG places the failure in what happened next. "Each group's conflicting understanding of escalation and resolution responsibilities resulted in a general lack of clarity about how to proceed in addressing the incident and contributed to overreliance on the employee's division," the OIG wrote [10]. "This lack of clarity contributed to the incident remaining unresolved for over a year." [15]

The division the others leaned on had been warned before. The Division of International Finance was notified in 2021 that the employee had copied FOMC classified files to an unencrypted USB device, which the employee called an accident [12]. Add the 2023 email attempt and the 2024 removal, and the record runs to three episodes in four calendar years [3].

The Fed says it plans to put in place processes and protocols to clarify roles and strengthen the escalation of alerts by the first quarter of 2027 [3]. Measured from the 2024 incident, that deadline lands 27 to 39 months later, depending on when in 2024 it began [2]. The OIG raised its concerns while auditing the Board's records controls during employee offboarding in 2025 [5]. The Board's own escalation chain had not closed the case by then [6].

The 2024 offboarding numbers are small. Departing employees filed 18 information-removal requests that year, and IS Operations told the Records Management Program about five potential cases of removal by departing staff [14]. If those five cases were routine, the problem is one employee with a long record, and protocols by early 2027 are roughly proportionate. If any of them stalled the same way, the gap runs across divisions and sits in how the Board assigns responsibility. The third possibility runs through the unretrieved files. The report, as American Banker describes it, does not say what the documents contained. A later finding that any were used or shared would turn a governance audit into a disclosure question.

I think the second reading fits the evidence better. The tool fired and the employee's history was on file, yet the case ran for more than a year because each group assumed another had the next step [9]. The OIG reaches the same place in its own words, writing that the confusion "highlights the need for a consolidated program to manage insider risks at the Board" [2]. The counter-case is that one person with a record dating to 2021 is an outlier, and five notifications in a year is a light caseload [14]. I'd drop my view if the next offboarding audit found alerts under the new protocols reaching the Legal Division within weeks instead of stopping at records management.

What to watch

  • Whether the Fed commits to, and puts a date on, a consolidated insider-risk program beyond the first-quarter 2027 protocols.
  • Any Board or OIG disclosure on retrieving the remaining material, or on what the removed documents contained.
  • Whether the first-quarter 2027 deadline holds, and whether a follow-up OIG audit tests the new escalation path.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories