THE NEWS IN BRIEF
On July 15, 2026, New York City Comptroller Mark Levine launched a formal audit of $243 million in expired shelter contracts that the city’s Department of Homeless Services (DHS) awarded — without competitive bidding — to a Brooklyn nonprofit called BHRAGS Home Care Corp between October 2022 and February 2024, according to The City Reporter. Levine’s office says it will test whether DHS’s reimbursements to BHRAGS “were reasonable and consistent with the terms and conditions of the contracts,” and separately review whether the agency’s ongoing oversight of new contracts is adequate.
The audit follows a federal indictment unsealed in March 2026 by the U.S. Attorney’s Office for the Eastern District of New York, charging BHRAGS’s former board chairman Jean Ronald Tirelus and former executive director Roberto Samedy with wire fraud, embezzlement, bribery, and money laundering conspiracy, according to Gothamist. Prosecutors allege the pair embezzled more than $1.3 million from the nonprofit and solicited kickbacks from subcontractors, including a security firm run by retired NYPD sergeant Edouardo St. Fort, who was charged alongside them; a fourth defendant, Miguel Jorge, was also named. All four have pleaded not guilty and the case is pending trial. Separately, Gothamist has reported that even after the indictment, BHRAGS retained roughly $94 million in active city contracts, with DHS opting to place the group under a “corrective action plan” rather than terminate the relationship — a decision now folded into the scope of Levine’s audit.
THE CONSULTANT’S VERDICT
Strip away the geography and this is a textbook vendor-fraud case built on the one condition that reliably defeats procurement controls: an emergency. New York’s 2022–2024 migrant influx overwhelmed DHS’s shelter capacity, and the agency responded the way pressured public agencies almost always do — it waived competitive bidding and handed a sole-source contract to an organization it already had a relationship with. No-bid emergency contracting is not itself the fraud. It is the opportunity. The fraud is what management does, or fails to do, once the waiver is granted.
Run the fraud triangle on what prosecutors allege. The pressure was institutional, not personal: a housing crisis that needed shelter beds now, with normal vetting treated as a luxury the city couldn’t afford. The opportunity was structural: a no-bid award with, as alleged, no independent verification loop checking whether billed services matched delivered services, and subcontractor selection — the security contract awarded to a firm run by a retired NYPD sergeant — left in the hands of the same insiders accused of taking a cut. The rationalization is the easiest part to imagine: in a declared emergency, insiders can tell themselves the paperwork can catch up later, that everyone is cutting corners, that the mission justifies the shortcut. None of that requires anyone to be a criminal mastermind. It requires only that nobody outside the transaction is checking.
The deeper failure here isn’t at BHRAGS. It’s at the oversight layer above BHRAGS. Bribery accusations tied to this contract surfaced as early as December 2023, according to reporting cited by The City Reporter, and the prior comptroller did not audit the relationship while in office. DHS itself didn’t move beyond a “corrective action plan” even after the indictment, and continued paying out against roughly $94 million in live contracts with a vendor whose top two executives were under federal indictment for stealing from that same organization. That is not a control gap at the fraud level; it is a control gap at the governance level. The IIA Global Internal Audit Standards are explicit that internal audit’s mandate includes providing assurance over how management identifies, monitors, and responds to third-party and vendor risk — not merely over the vendor’s own books. When a vendor is criminally charged, “continue and monitor” cannot be the default response with no defined trigger for suspension, escalation, or independent verification of continued payments.
I see the regional mirror of this constantly across the GCC, where sole-source and “urgent” government or quasi-government awards are even more normalized than in the US — sometimes for genuine emergencies, sometimes simply because the vendor has the right relationship. The lesson travels directly: the moment competitive bidding is waived “because of urgency” is exactly the moment compensating controls need to switch on, not off — mandatory post-award audit within a fixed window, independent invoice-to-delivery verification, disclosed subcontractor ownership. Western public bodies at least tend to have these triggers written into policy, even when enforcement lags, as this case shows. Many GCC entities I’ve reviewed don’t have the policy on paper at all.
WHAT YOU SHOULD DO MONDAY MORNING
- Pull every contract your organization has awarded without competitive bid in the last 24 months. For each one, confirm there is a documented, time-bound compensating-control plan — a mandatory audit date, an independent invoice-verification process — not just a written justification for the waiver.
- Cross-check subcontractor ownership against employee and related-party records. Do not rely on self-disclosed conflicts of interest from the people choosing the subcontractors; verify independently, especially on any contract where the same individuals control both vendor selection and vendor payment approval.
- Write down — today, not after the next indictment — what happens to a vendor relationship the moment that vendor’s leadership is criminally charged. Define who signs off on continued payments, at what dollar threshold payments pause automatically, and what independent verification is required to resume them.
- If your organization procures crisis or surge services of any kind — disaster response, temporary staffing, emergency housing — build the compensating-control checklist now, before the next emergency forces a no-bid award under time pressure with no plan already in place.
- Ask internal audit or the audit committee when the last risk-based review of high-dollar sole-source vendors was performed. If there isn’t one on a recurring cycle, that is the exact gap that let this contract run for more than two years before anyone with an audit mandate looked at it.
DON’T WAIT FOR THE HEADLINE TO BE ABOUT YOU
Right now, somewhere, a sole-source contract signed under pressure is being managed by the same people who benefit from nobody checking the invoices against the work. Leadership assumes a “corrective action plan” or a monitoring memo is the control doing the work. It isn’t, until someone independent actually verifies it. This exact scheme is running inside organizations whose leaders assume emergency procurement is a one-time exception rather than a standing invitation. If you want a confidential, independent look at whether your vendor oversight, subcontractor disclosures, or emergency-procurement controls would actually catch this before a headline does, message me directly — before a fraudster finds the gap first.







