TIGTA finds security failures at two IRS Zero Paper sites
The paper backlog has become a contractor-security problem, and the IRS is learning that while taxpayer documents are already onsite.
TL;DR
FedScoop reports that the Treasury Inspector General for Tax Administration found security failures at two Zero Paper Initiative contractor sites: 48% of vulnerabilities at one site were not fixed on time, another used unauthorized scanning software, and 14 employees without IRS authorization entered taxpayer-document areas 1,375 times. Primes, subs and assessors supporting ZPI now face the audit version of a pattern: TIGTA’s February schedule warning has become an active control-failure finding before the December 2030 digitization mandate.
FedScoop reports that the Treasury Inspector General for Tax Administration sent the IRS commissioner a memo last week finding security gaps at two contractor sites supporting the Zero Paper Initiative, the IRS effort to scan and digitize paper tax records. The findings are operational control failures: one site failed to resolve 48% of vulnerabilities in systems used to process taxpayer information on time, another used unauthorized software to scan systems for vulnerabilities, and 14 employees who lacked IRS authorization entered areas where taxpayer documents were stored, scanned or digitized 1,375 times.
The system-control picture gets worse at the device level. One site completed required monthly scans on one of 203 devices in August 2025. The other used a tool that did not capture enough configuration detail to tell how long a weakness had existed. TIGTA said cybersecurity personnel knew about an unauthorized configuration-scanning tool, but no one initiated action to bring the contractor back into agency requirements. For a program premised on industrializing paper intake, that is a bad place to discover that contractor control evidence is thin.
This is the second TIGTA warning on ZPI in 12 months. In February, the watchdog said the initiative had made limited progress and raised concern that the IRS might miss the federal mandate to digitize all records by December 2030. The new memo shifts the risk profile from schedule slippage to taxpayer-data handling. A delayed scanner is a management problem; an open loading dock, unauthorized tools and unauthorized staff access are contract security problems.
For primes and subs on ZPI, the immediate work is dull and non-optional: close overdue vulnerabilities, prove monthly scanning coverage, remove unauthorized tools, reconcile physical-access rosters against IRS approvals, and preserve evidence of corrective action. The open questions are contractual. TIGTA said the IRS has taken or will take corrective actions and plans to visit other contractor facilities; the memo does not say what standard applies to the 14 employees already identified or whether missed controls trigger deadlines with penalties. Assessors should assume the next site visit starts there.
Published ·Deep Fathom