The Treasury Inspector General for Tax Administration (TIGTA) has issued multiple reports identifying security and compliance gaps in the IRS's Bring Your Own Device (BYOD) program across several years. A 2019 TIGTA audit found vulnerabilities including uncontrolled screenshot capability on personally owned iPhones, inadequate logging, and no formal procedure to wipe data from a lost or stolen BYOD device. A December 2023 TIGTA report found the IRS was not fully complying with the No TikTok on Government Devices Act, including thousands of BYOD-enrolled devices that could still access TikTok. A May 2026 TIGTA evaluation separately found IRS BYOD and government-furnished devices connecting to foreign cellular networks without travel authorization, with no process to confirm the devices were sanitized afterward.
2019 audit — device-level security vulnerabilities
TIGTA's 2019 report described the BYOD program as increasing risk because personally owned mobile devices are easily lost or stolen, and because IRS data on such devices could be subject to unauthorized access if that occurred. The report specifically flagged that personally owned iPhones could not be configured to disable screenshot functionality without disabling it for all device applications, creating a data-leakage risk the IRS could not monitor or detect. The report also found the IRS was not maintaining or reviewing application logs on BYOD systems and had no local procedure requiring a manual wipe of a lost or stolen device.
2023 audit — No TikTok Act compliance
TIGTA's December 2023 report found the IRS was not fully complying with the No TikTok on Government Devices Act and OMB Memorandum M-23-13's implementation guidance. The audit identified approximately 2,800 handheld devices and 900 employees, concentrated in the IRS Criminal Investigation division, that could still access TikTok months after the OMB deadline. TIGTA recommended the IRS's Chief Information Officer coordinate with OMB to determine whether the BYOD program's own policies and procedures complied with the Act, and the IRS agreed to update its BYOD policy to align with OMB guidance.
2026 evaluation — unauthorized overseas device use
A May 2026 TIGTA evaluation reviewed IRS fiscal year 2024 mobile device usage and identified 173 instances of IRS employee mobile devices — including BYOD-enrolled devices — connecting to a foreign cellular network without a corresponding travel authorization, spanning 121 employees in 37 countries. The report noted IRS procedures did not track which specific devices, including BYOD devices, were taken overseas, which limited the agency's ability to confirm that affected devices were sanitized and reimaged upon return, consistent with IRS's own security procedures. TIGTA recommended the IRS implement a process to review vendor usage reports for overseas activity and update its travel-authorization form to capture device-identifying information.
This entry restates publicly available technical and policy sources and asserts nothing beyond them. It is not legal or compliance advice. BYODPolicy.org is not affiliated with, endorsed by, or accredited by NIAP, NIAP-CCEVS, or any government body.