Thirty-Seven Thousand Loans Nobody Finished Reading

Report 26-01 came out of the SBA's own Office of Inspector General on December 18, 2025, thirty-six pages listing the five things most likely to go wrong at the agency in Fiscal Year 2026. Buried in Challenge 1 is a number the agency has never volunteered on its own: as of May 2024, the SBA had flagged Paycheck Protection Program loans for post-payment review and had 37,938 of them, worth roughly $4.6 billion, still unreviewed. The reviews started in July 2021. The agency's own words for the pace are that they will continue as resources allow.

Published August 17, 2026 • Filed under: Reading Is Fundamental, The Portfolio That Ate The Agency

A wall of paper files in storage, standing in for the tens of thousands of flagged loan reviews the SBA has not completed

Start with the arithmetic that makes the rest of this document make sense. The SBA's four pandemic relief programs pushed out 22.1 million loans and grants totaling roughly $1.2 trillion. It did that with, in the inspector general's phrasing, limited front-end fraud detection internal controls, because Congress told it to move fast and it moved fast. That part is not a scandal. That was the assignment.

The scandal is the plan for afterward. The agency's answer to gutting the checks at the front was that it would do the checking at the back, examining loans for eligibility after the money was gone and the loan was already forgiven. The inspector general has now written down, in a public report, that the agency presumed post-payment review would offset the risk. Presumed. That is the verb.

Five Years Of Flagging, Four Point Six Billion Unread

Flagging began in July 2021. By May 2024, thirty-four months later, 37,938 flagged loans totaling about $4.6 billion had not been reviewed at all. Not cleared, not referred, not closed. Sitting there.

The clock is not helping. PPP borrowers can apply for forgiveness for up to five years from the date the loan was issued, which means applications are still arriving through 2026. Meanwhile Congress extended the statute of limitations for PPP and COVID EIDL fraud from five years to ten, so in most cases the government now has until 2032 to prosecute. Eleven years to read a stack that took eighteen months to create.

There is a version of this where the extension is good news, and it genuinely might be, because ten years of exposure is a real deterrent and a real recovery window. There is also the version where an agency that could not finish 37,938 reviews in three years now has permission to not finish them for another six.

The Portfolio Went Up Fourteen Times And The Staff Did Not

Before the pandemic the SBA serviced roughly 263,000 disaster loans totaling about $9.4 billion. That was the job. Five years after, the agency is servicing approximately 3.8 million outstanding disaster loans totaling approximately $336.4 billion.

Fourteen times the dollars. The inspector general puts the multiplier in the report itself, in a figure with its own caption, which is the sort of thing an oversight office does when it wants a number to be impossible to miss.

Then, in a sentence written with the flatness that oversight offices reserve for their sharpest lines, the report notes that staff reductions occurred after its review, and that OIG has therefore not assessed any potential impact on the agency's servicing of the $336.4 billion COVID-19 EIDL portfolio. Translated: they cut people, we have not measured what that did, and we are telling you now so nobody claims later that we did not mention it.

The Fintech Number Is Worse Than The Fintech Story

Non-bank lenders made $14.2 billion in suspected fraudulent PPP loans, at a rate more than five times higher than loans made by traditional bank lenders. Of that $14.2 billion, more than $6.1 billion, nearly 43 percent, came from lenders the report categorizes as fintechs and other state-regulated finance companies.

The example the report picks to illustrate it is worth repeating in full. A national criminal ring involving 1,300 PPP applications tied to $600 million in fraud ended in convictions for the founders of a lender service provider. That same lender service provider facilitated over $6 billion in PPP loans and collected over $300 million in lender fees along the way.

Three hundred million dollars in fees. To a company whose founders were convicted. On a program the agency was told to run fast.

The Number That Should Be Framed On A Wall Somewhere

The Pandemic Response Accountability Committee estimated that simply verifying Social Security information could have prevented up to $79 billion in potentially fraudulent pandemic relief payments.

Seventy-nine billion dollars. Not through a Palantir deployment, not through a machine learning anomaly engine, not through a suspension list of 150,000 people who have not been charged with anything. Through checking whether the Social Security number on the application belonged to the person filing it.

Elsewhere the report notes the agency could miss the chance to recoup over $9.5 billion in potentially improper Restaurant Revitalization Fund payments, and that the Department of Labor's inspector general found $1.3 billion paid to the same likely fraudsters across both unemployment insurance and EIDL, with SBA OIG identifying another $1.4 billion nobody had flagged before. Every one of those figures is a data-sharing problem. None of them required a new technology to solve.

And Now, Artificial Intelligence

Challenge 5 of the report is Managing Risks in Information Technology Systems, and its subsections are: improving IT systems management, deploying and monitoring new third-party systems, cybersecurity and modernization, and Preparing for Artificial Intelligence Challenges.

The footnotes on that section include a citation to a trade-press story about OpenAI offering federal agencies ChatGPT access for a dollar a year.

So the sequence, as documented by the agency's own watchdog, runs like this. Skip the front-end controls because speed matters more. Promise to check afterward. Do not finish checking. Watch the portfolio grow fourteenfold. Reduce staff. Learn that a Social Security lookup would have stopped $79 billion. Then add artificial intelligence to the list of things to prepare for, at a dollar a year.

Nobody at LOLSBA is arguing the agency should have been slower in 2020. People needed the money and they needed it in April, not in November. The argument is narrower and it is the same one every time: an agency that cannot finish reading 37,938 files it flagged itself, over three years, with a ten-year statute of limitations and a $336.4 billion portfolio, does not have a technology problem. It has a reading problem. Buying a chatbot is not going to fix the reading problem.

Report 26-01 is thirty-six pages and it is public. The agency has had it since December 18, 2025.

SHARE ON X SHARE ON FACEBOOK SHARE ON LINKEDIN