Skip to main content
Framework library
Framework module · gao-fiscam-2026

GAO FISCAM

The federal audit methodology for assessing the design, implementation, and operating effectiveness of information-system controls under generally accepted government auditing standards. It is audit guidance, not an agency authorization or certification.

June 2026 (GAO-26-108633) · US Government Accountability Office and CIGIE · published 2026-06-29

Standing today
Directory entry

00Answer

from the registry record
What is GAO FISCAM?
The federal audit methodology for assessing the design, implementation, and operating effectiveness of information-system controls under generally accepted government auditing standards. It is audit guidance, not an agency authorization or certification.
Who does GAO FISCAM apply to?
GAO FISCAM applies to federal, government audit, public sector, US, per US Government Accountability Office and CIGIE.
What is the current version of GAO FISCAM?
The current edition is June 2026 (GAO-26-108633), issued by US Government Accountability Office and CIGIE and published 2026-06-29. Source: https://www.gao.gov/products/gao-26-108633.
What does an assessment under GAO FISCAM require?
No control catalog has been ingested for GAO FISCAM yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

GAO FISCAM is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

GAO publishes the manual plus framework and crosswalk workbooks; pin the June 2026 release before normalization.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Entitywide controls · Access controls · Configuration management · Segregation of duties · Contingency planning · Business-process controls
Applies to
federal · government audit · public sector · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28
Pending change
The June 2026 revision is already effective for fiscal-year and calendar-year 2026 federal financial statement audits; it becomes effective for attestation and performance-audit engagements beginning on or after 2026-10-01.Expected: 2026-10-01 for attestation and performance audits

03Version ledger

2 editions
September 2024 (GAO-24-107026)Superseded2024-09-05
June 2026 (GAO-26-108633)Current edition · supersedes September 2024 (GAO-24-107026)2026-06-29

05Change history

06Related frameworks

scored from registry facts
  1. GAO Green Book2025 Revision

    Also applies to federal · The federal internal-control standard for designing, implementing, operating, and evaluating controls over operations, reporting, and compliance. It supplies auditable criteria for federal entities; it is not an organizational certification.

  2. Also applies to government audit · Generally accepted government auditing standards for financial audits, attestation engagements, reviews, and performance audits. They govern auditor and audit-organization quality; they do not certify the entity being audited.

  3. Also applies to federal · CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.

  4. FISMAFederal Information Security Modernization Act of 2014

    Also applies to federal · The Federal Information Security Modernization Act of 2014 — the statutory authority a federal RFP names, implemented operationally through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked as their own registry entries.

GAO FISCAM | ControlFrame