All sources below were directly checked on August 26, 2026.
Office of Management and Budget. April 3, 2025.
Cross-functional acquisition teams, competition, testing, performance monitoring, pricing transparency, data rights, portability, privacy, and protection against vendor lock-in.
U.S. Government Accountability Office. April 13, 2026.
Current acquisition challenges, contract considerations, performance oversight, and systematic collection of lessons learned.
National Institute of Standards and Technology. AI RMF 1.0 with current NIST resource updates.
Voluntary risk management across Govern, Map, Measure, and Manage, including trustworthiness considerations throughout the AI life cycle.
National Institute of Standards and Technology. July 26, 2024.
Generative AI risks and suggested actions involving content provenance, information integrity, privacy, security, evaluation, and human oversight.
U.S. General Services Administration. Living public guide.
Problem selection, organizational readiness, integrated teams, buy-versus-build decisions, testing, data rights, sustainable capability, and lessons learned.
National Association of State Procurement Officials. 2024 edition.
A state and local procurement life-cycle frame. Access to the complete publication may require purchase.
U.S. DOGE Service. Current public edition.
User needs, iterative delivery, accountable ownership, security and privacy, and decision-linked measurement.
U.S. Government Accountability Office. Effective fiscal year 2026.
Risk-based control activities, quality information, documentation, review, and separation of key duties.
New York State Office of the State Comptroller. Official local-government management guide.
Reviewing claims for authority, mathematical accuracy, supporting documentation, and evidence that goods or services were received.
Office of the New York City Comptroller. December 17, 2025.
Using available route, GPS, complaint, and performance evidence to oversee contracted transportation service.
Electronic Code of Federal Regulations. Current eCFR text.
Subaward information, risk evaluation, monitoring, follow-up, and access to records for federal awards.
Office of Management and Budget. November 2025.
Current federal program compliance requirements and audit objectives that may apply in addition to the general Uniform Guidance.
Office of Management and Budget. Supplement to OMB Circular A-11, 2025.
Disciplined portfolio planning, prioritization, life-cycle cost, risk, acquisition, and performance management.
Cybersecurity and Infrastructure Security Agency. January 2023.
K-12 priorities including leadership ownership, multifactor authentication, patching, tested backups, incident response exercises, and training.
Cybersecurity and Infrastructure Security Agency. August 2023.
Security questions and secure-by-design considerations for K-12 technology purchasing.
National Institute of Standards and Technology. February 26, 2024.
A non-prescriptive set of outcomes across Govern, Identify, Protect, Detect, Respond, and Recover.
U.S. Department of Education Student Privacy Policy Office. Current resource hub.
Safeguarding student records, data security, data flows, retention, destruction, and online-service considerations.