Press Releases

Audit Report OC-27-04, Puerto Rico Innovation and Technology Service – Computerized Information Systems

July 13, 2026

Comptroller notes PRITS shortcomings in technological innovation and cybersecurity projects

San Juan, Puerto Rico (July 13, 2026) — The Comptroller of Puerto Rico, CPA and Attorney Carmen Vega Fournier, published today Audit Report OC-27-04 on the information systems operations of the Puerto Rico Innovation and Technology Service (PRITS).

One of the principal findings relates to the Electronic Eligibility Engine platform, known as E3, intended to facilitate the exchange of information among agencies and to automate the evaluation of citizens’ eligibility for economic assistance programs. This project was contracted for $232,000, corresponding to the first phase, which included design, development and implementation.

The audit found that, as of October 20, 2025, PRITS had neither implemented it nor used it for the purpose for which the platform was developed, even though the contractor delivered a functional version in June 2023, the date on which it notified PRITS of the conclusion of the project, for which it billed $130,000 between May and August 2023. The OCPR concluded that the digital platform did not fulfill the purpose of Phase 1. The associate director of the Innovation and Digital Development Directorate certified that the platform was implemented in a production environment, but that access to it was never published, and therefore it was neither operational nor used by government agencies.

A second finding points to the absence of a Strategic Innovation and Technology Plan, as required by Act 75-2019. In the report, PRITS argued that its institutional strategy was distributed across normative documents, policies and operational plans, but the OCPR concluded that those documents do not substitute for the strategic plan expressly required by law.

The audit also identified deficiencies in the Annual Progress Reports for fiscal year 2024, which was submitted outside the established time frame. In addition, the auditors determined that PRITS had not implemented a formal mechanism to require government entities to submit their Cybersecurity Programs for review and evaluation, as required by Act 40-2024, known as the Puerto Rico Cybersecurity Act.

As a result, as of October 24, 2025, only one government entity had formally submitted its program for evaluation by PRITS. The Comptroller warned that this situation limits the government’s ability to validate the level
of protection of its digital assets, identify vulnerabilities and verify uniform compliance with cybersecurity standards.

Among her recommendations, the Comptroller urged “accelerating the second phase of the E3 project, preparing and approving the strategic plan required by law, strengthening the annual reports and establishing a formal mechanism to review the agencies’ cybersecurity programs”.

Audit Report OC-27-04 is available at www.ocpr.gov.pr.

VIEW REPORT

Some documents on this page are saved in PDF format.
To view these documents, you must have the following free program installed.

Download Adobe® Reader®