The quality of the CFPB’s information security program “has decreased since last year, leading us to conclude the program no longer is effective,” the bureau’s Inspector General (IG), said in a report.
The bureau’s overall security program has decreased from “manageable and measurable” to “defined,” the IG said in an annual audit conducted between April 2025 and October 2025, which is only one step above the lowest security rating. This is significant, as data maintained by the CFPB includes personally identifiable information on consumers and confidential supervisory information on companies.
“The CFPB is unable to maintain an effective level of awareness of security vulnerabilities in its environment,” according to the report.
The current problem has been exacerbated by the Trump Administration’s efforts to downsize the agency, the IG said. According to several news reports, Acting CFPB Director Russell Vought recently said on the “Charlie Kirk Show” that he thinks he will be successful in shutting down the CFPB in the next two or three months.
Problems at the CFPB have been compounded by the loss of contractors supporting information security monitoring and testing activities, according to the IG. About 65% of the individuals supporting the CFPB’s information security program at the start of 2025 were contractors, according to the IG. By the end of February, that figure had dropped to 25%.
The CFPB’s Enterprise Risk Management (ERM) Program has been placed on hold since the agency’s chief risk officer and other individuals in the ERM office left the agency in March 2025, according to the report. Those positions have not been filled and their responsibilities are not being fully performed, the IG said.
The IG also reported that:
The IG made several technical recommendations. While the CFPB agreed with the IG recommendations, it disputed the notion that it has a lax information security posture.