GAO says Secret Service policy gaps left threat decisions poorly documented
A new Government Accountability Office review found that the Secret Service did not consistently document why security incidents failed to produce changes to protection policies, raising accountability questions about how the agency learns from threats involving national political leaders and foreign dignitaries.
GAO publicly released its report, GAO-26-108455, on September 3, 2026. The review examined Secret Service protection policies and 83 security incidents from fiscal years 2015 through 2025.
The report found that the agency updated protection policies after 25 of those incidents. But when officials decided that no policy change was needed after other incidents, Secret Service policy did not require personnel to record the reasons in writing.
What GAO found about incident reviews
GAO said written explanations are important because they create a record of how officials evaluated emerging threats and whether follow-up was assigned. Without that documentation, it can be difficult to determine why the agency maintained the status quo after an incident.
The report identified drone incidents from 2015 through 2021 as an example. GAO said information from earlier civilian drone incidents might have helped officials identify drone use as an emerging threat before a drone was used during the July 2024 assassination attempt on then-former President Donald Trump in Butler, Pennsylvania.
GAO did not conclude that the documentation gap caused the Butler attack, and the report did not accuse an individual Secret Service employee of misconduct. Its finding was narrower: earlier incidents were not consistently connected to documented policy decisions, which limited the agency’s ability to show how it assessed the risk and decided whether changes were needed.
Eight policies were overdue for review
GAO also found that eight of the Secret Service’s 22 protection policies had not been reviewed or updated within the agency’s required four-year period.
Secret Service officials told GAO that the agency tried to make timely updates but was not always able to identify personnel available to do the work. GAO recommended assigning responsibility to specific positions so policies are reviewed within required time frames.
The finding does not establish that current protection procedures are unsafe or that an immediate operational change has occurred. It does show that some written guidance was not reviewed on schedule while the agency’s protective missions and threat environment changed.
A 1991 agreement remains in place
GAO separately examined a memorandum of understanding between the Secret Service and the State Department’s Diplomatic Security Service. The agreement sets out separate and shared responsibilities for protecting the president and other full-time protectees traveling abroad, as well as foreign dignitaries traveling to the United States.
The agencies have not updated that agreement since 1991. GAO said the document does not fully reflect changing threats, missions and responsibilities, including the emergence of drone threats, and recommended that the agencies revise it.
An outdated interagency agreement can make accountability more difficult when multiple federal organizations share protective duties. The issue is not only which agency performs a task, but whether current guidance clearly identifies who is responsible for decisions, coordination and follow-up.
What happens next
GAO issued four recommendations. Two are directed to the Secret Service and concern documenting incident reviews and assigning responsibility for policy updates. Two others call on the Secret Service and the State Department to update the memorandum of understanding.
The Department of Homeland Security, which includes the Secret Service, and the State Department concurred with the recommendations. GAO lists all four as open, meaning the agencies have not yet completed the actions needed for GAO to confirm implementation.
The next accountability test will be whether the agencies create a documented process for explaining decisions, bring overdue policies up to date and replace the 1991 agreement with guidance that reflects current protective responsibilities. Until then, the report provides a record of gaps in the system used to turn security incidents into policy changes.
Sources
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.