Skip to main content
(G A O website.)

IT DASHBOARD:

Selected Agencies’ Investment Ratings Fail to Fully Consider Risks

GAO-27-108416. Published: Oct 07, 2026. Publicly Released: Oct 07, 2026.

Report to the Committee on Oversight and Government Reform,

House of Representatives

October 2026

GAO-27-108416

                        

United States Government Accountability Office

Highlights

A report to the Committee on Oversight and Government Reform, House of Representatives

Contact: Carol Harris at harrisc@gao.gov 

What GAO Found

The Federal Information Technology (IT) Dashboard is intended to show the level of risk for an investment. The Dashboard reflects Chief Information Officers’ (CIO) ratings of risk. Selected agencies that GAO reviewed used different processes to develop their ratings. Most of these processes included some, if not all, of six factors that the Office of Management and Budget (OMB) suggested.

GAO’s assessments generally identified the presence of more risk compared to the associated CIO ratings. GAO determined its assessments based on investment risk documentation. Of the 53 investments assessed, GAO’s assessments matched the CIO ratings 27 times, showed more risk 24 times, and showed less risk two times (see graphic).

Comparison of Selected Investment’s Chief Information Officer Ratings to GAO Assessments

Two issues contributed to the differences between GAO and CIO ratings. Specifically, 21 of the 53 CIO ratings were not updated in a timely manner according to agencies’ processes. In addition, two agencies’ rating processes span longer than quarterly, contrary to OMB’s guidance.

In April 2026, OMB announced that it was taking steps to sunset the Dashboard and replace it with a new streamlined system but did not provide a timeframe for its release. In the interim, it is critical that selected agencies address issues with their CIO ratings. Without doing so, critical IT investments may not receive proper oversight, and emerging risks may remain unidentified or unmanaged. For example, a system modernization effort that falls behind schedule but continues to display an outdated “low‑risk” rating might not get the scrutiny it needs and fall further behind schedule.

GAO previously recommended that OMB improve its oversight of troubled investments identified from CIO rating data; however, OMB has not yet acted on this recommendation. As a result, agencies and OMB may be unable to identify emerging risks in time, potentially allowing underperforming investments to proceed without needed intervention and increase the risk of higher costs. As OMB transitions to a new system, it is imperative that agencies address issues with the quality and frequency of CIO ratings. This is critical to ensuring that the new system strengthens the monitoring of IT investment risk.

Why GAO Did This Study

The federal government spends over $100 billion annually on IT and cyber investments, but many projects fail, facing cost overruns and delays. In 2009, OMB launched the IT Dashboard to provide transparency on IT investments. OMB sets Dashboard policies and the General Services Administration operates the Dashboard.

GAO was asked to review the CIO ratings on the IT Dashboard. This report describes agencies’ processes for determining the CIO risk ratings for major IT investments, assesses the risks of federal IT investments, and analyzes any differences with the investments’ CIO risk ratings, among other things.

GAO reviewed 26 agencies’ fiscal year 2025 budget data reported to OMB to identify major IT investments of $35 million or more of development activities; this resulted in 53 selected investments at 12 agencies. GAO then reviewed agencies’ CIO ratings processes, assessed the risks of the 53 investments, and compared GAO’s assessments to the CIO ratings.

What GAO Recommends

GAO is making 17 recommendations to nine agencies to improve the quality and frequency of CIO ratings. Five agencies agreed with the recommendations, one agency agreed with one recommendation and disagreed with the other, two agencies disagreed, and one agency did not state whether it agreed or disagreed. OMB did not provide comments. GAO maintains that its recommendations are warranted.

 

 

 

Abbreviations

 

 

 

CIO

Chief Information Officer

CPIC

Capital Planning and Investment Control

DOD

Department of Defense

DHS

Department of Homeland Security

FAC-P/PM

Federal Acquisition Certification for Program and Project Managers

FITARA

Federal Information Technology Acquisition Reform Act

GSA

General Services Administration

HHS

Department of Health and Human Services

IT

information technology

OCIO

Office of Chief Information Officer

OGP

Office of Government-Wide Policy

OMB

Office of Management and Budget

SSA

Social Security Administration

VA

Department of Veterans Affairs

 

This is a work of the U.S. government and is not subject to copyright protection in the United States. The published product may be reproduced and distributed in its entirety without further permission from GAO. However, because this work may contain copyrighted images or other material, permission from the copyright holder may be necessary if you wish to reproduce this material separately.

 

Letter

October 7, 2026

The Honorable James Comer
Chairman
The Honorable Robert Garcia
Ranking Member
Committee on Oversight and Government Reform
House of Representatives

Each year, the federal government spends more than $100 billion on information technology (IT) and cyber-related investments. However, investments in IT often result in failed projects that incur cost overruns and schedule slippages, while contributing little to mission-related outcomes. The Office of Management and Budget (OMB) launched the Federal IT Dashboard in 2009; the Dashboard was intended to improve oversight, transparency, and accountability of federal IT investments.[1]

Recognizing the severity of issues related to the government-wide management of IT, in December 2014, Congress enacted federal IT acquisition reform legislation, commonly referred to as the Federal Information Technology Acquisition Reform Act (FITARA) as part of the Carl Levin and Howard P. ‘Buck’ McKeon National Defense Authorization Act for Fiscal Year 2015.[2] Among other things, FITARA codified requirements for OMB and covered executive branch agencies to make publicly available detailed information on major federal IT investments, and agency Chief Information Officers (CIO) to categorize their major IT investment risks.[3] These requirements are addressed by the IT Dashboard, which is currently operated by the General Services Administration (GSA).

The IT Dashboard is intended to provide agencies, OMB, other oversight bodies—including Congress—and the public with information on the health of federal IT investments. According to OMB, agencies are to submit risk ratings from their CIOs, which should reflect the level of risk facing an investment relative to its ability to accomplish goals.

GAO has issued a series of reports about the IT Dashboard which noted issues with the accuracy and reliability of the data it contains.[4] In addition, in 2015, we added improving the management of IT acquisitions and operations to our list of High Risk areas for the federal government, in part due to the issues we identified with the IT Dashboard’s data.[5] This designation still remains in our most recent High Risk report.[6]

In April 2026, OMB announced that it was taking steps to sunset the IT Dashboard website.[7] Further, OMB stated that “agencies will pivot to a streamlined state that refocuses on statutorily required data.” However, the announcement did not provide additional details or a time frame for this change, and OMB did not respond to our request for more information. As of May 2026, GSA officials from the Office of Government-Wide Policy (OGP) stated that the Dashboard remains accessible to public and authenticated users.[8]

This report responds to your request to review the CIO ratings on the dashboard. Specifically, our objectives were to (1) describe selected agencies’ processes for determining the CIO risk ratings for major IT investments, (2) assess the extent to which selected agencies’ CIO ratings align with IT investment risks, and (3) determine what challenges, if any, selected agencies have identified with using the IT Dashboard and what efforts, if any, GSA or OMB have underway to address them.

To select the agencies and investments, we reviewed data reported to OMB as part of the federal budget process to identify major IT investments planning to spend $35 million or more on development, modernization, and enhancement activities in fiscal year 2025.[9] This produced an initial list of 12 agencies and 67 investments. After reviewing agency documentation and interviewing agency officials, we removed 14 investments that fell below the $35 million threshold or lacked a risk register we could analyze (e.g., had no open risks), among other reasons. This resulted in 53 selected investments at 12 agencies. These agencies were: the Departments of Agriculture, Commerce, Defense (DOD), Education, Health and Human Services (HHS), Homeland Security (DHS), State, Transportation, the Treasury, and Veterans Affairs (VA), as well as GSA[10] and the Social Security Administration (SSA).

To address our first objective, we collected relevant CIO rating process documentation from the 12 selected agencies, such as capital planning and investment control (CPIC) guides and program health assessment guidance. We also met with agency officials to discuss their CIO rating processes. We then compared the agencies’ processes to the OMB suggested evaluation factors for creating CIO ratings.[11]

To address our second objective, we downloaded the April 2025 CIO ratings information for the 53 selected investments from the IT Dashboard. We focused on April 2025, the month that our audit work began, to minimize any influence that our ongoing work could have on the agencies’ processes and resulting ratings. We also interviewed agency officials regarding their CIO ratings.

To develop our assessments of investments’ risk, we collected March 2025 risk documentation (the data we would expect to be reflected in the April ratings), executive review board briefings, and relevant reports (e.g., GAO and Inspector General reports). In cases where agencies were unable to provide March documentation, we used documents from the closest available date. We did not consider risks that were introduced after March in these documents.

We combined and scored this information based upon industry and government best practices to create our assessments of the investments’ risk.[12] Specifically, we

·        scored every risk’s probability and impact to create a risk exposure (risk exposure = probability * impact);

·        created a weighted average of the investment’s risk exposure scores;

·        translated these scores to a low, moderately low, medium, moderately high, or high rating scale to parallel the IT Dashboard’s rating scale; and

·        adjusted ratings if serious risks to an investment were discussed in: 1) publicly available reports (e.g., GAO and Inspector General reports), and 2) agency executive review board briefings (when available).

We then compared our assessments to agencies’ April 2025 CIO risk ratings and identified investments where our assessment of risk was higher, lower, or the same.

For the third objective, we examined how selected agencies use the IT Dashboard and the challenges they encounter. We interviewed agency officials to understand what challenges, if any, they faced in using the Dashboard. We then consolidated the challenges that agencies reported and summarized our analysis.

To assess GSA and OMB efforts to address agency challenges, we reviewed GSA documentation and interviewed GSA officials regarding their efforts to address IT Dashboard challenges reported by users. We also reviewed OMB guidance related to the IT Dashboard, as well as our prior reports on the Dashboard that pertained to OMB. OMB did not respond to our requests for additional information on its actions to address IT Dashboard user challenges or requests for interviews with agency officials. Appendix I provides more details regarding our objective, scope, and methodology.

We conducted this performance audit from April 2025 to October 2026 in accordance with generally accepted government auditing standards. Those standards require that we plan and perform the audit to obtain sufficient, appropriate evidence to provide a reasonable basis for our findings and conclusions based on our audit objectives. We believe that the evidence obtained provides a reasonable basis for our findings and conclusions based on our audit objectives.

Background

OMB plays a key role in overseeing how federal agencies manage their IT investments by working with them to better plan, justify, and manage them. In June 2009, OMB deployed the Federal IT Dashboard, a public website with information on the performance of major federal investments to improve the transparency into, and oversight of, federal agencies’ IT investments.[13] Subsequently, in March 2022, the operation of the IT Dashboard was transferred to GSA which released a modernized version.

The IT Dashboard displays information on the cost, schedule, and performance of nearly 600 major IT investments at 26 federal agencies.[14] According to GSA, the Dashboard is intended to provide data on the health of federal IT investments, the impact of federal IT portfolios, and the ability of agencies to deploy technology, among other things. Further, the public display of these data is intended to allow OMB, other oversight bodies, including Congress, and the general public to hold government agencies accountable for progress and results.

As previously stated, the Dashboard website includes an announcement indicating there are plans to replace the system with a streamlined one that will focus on statutorily required data. As of May 2026, GSA OGP officials stated that the Dashboard remains accessible to public and authenticated users. Further, the officials noted that it receives regular security patching and operation and maintenance work to ensure system reliability and security.

GSA officials also indicated that, while GSA maintains operational responsibility for the IT Dashboard, all strategic planning and policy decisions regarding its future direction are managed by OMB's Office of the Federal CIO. This includes any decisions about system evolution, modernization, or lifecycle management. Further, specific information about the replacement system, its development timeline, implementation plans, and any agency involvement is also being managed by OMB. However, OMB did not respond to our request for more information about its plans for the future of the IT Dashboard.

The IT Dashboard is Intended to Provide Visibility into the Peformance of Federal IT Investments

The Dashboard visually presents performance ratings for agencies and for individual investments using metrics that OMB has defined—cost, schedule, and CIO evaluation.

Cost and schedule ratings. The Dashboard calculates these ratings by determining cost and schedule variances based on agency-submitted data, such as planned versus actual costs or planned versus actual completion dates. The Dashboard then assigns rating colors (red, yellow, green) based on the magnitude of the variances. Specifically, a variance greater than or equal to 30 percent is red, a variance greater than or equal 10 percent and less than 30 percent is yellow, and a variance less than 10 percent is green.

CIO ratings. Unlike the cost and schedule ratings, the Dashboard’s CIO rating is determined by the agency CIO. According to OMB’s instructions, covered agencies are to submit ratings from their CIOs, which should reflect the CIO’s best judgment of the current level of risk for an investment in terms of its ability to accomplish its goals.[15]

These risk ratings are based on a five-point scale where 1 represents the highest risk and 5 represents the lowest risk. The Dashboard then translates the agency CIOs’ numerical ratings into a color for depiction on the Dashboard, with green (5) signifying low risk, light green (4) signifying moderately low risk, yellow (3) signifying medium risk, light red (2) signifying moderately high risk, or red (1) signifying high risk.

To determine the CIO rating, OMB suggests six evaluation factors, as shown in table 1.

Table 1: Investment Evaluation Factors Identified by the Office of Management and Budget for Assigning Chief Information Officer Ratings

Evaluation factor

Supporting examples

Risk management

Risk management strategy exists

Risks are well understood by senior leadership

Risk log is current and complete

Risks are clearly prioritized

Mitigation plans are in place to address risks

Requirements management

Investment objectives are clear and scope is controlled

Requirements are complete, clear, and validated

Appropriate stakeholders are involved in requirements definition

Contractor oversight

Acquisition strategy is defined and managed via an integrated program team

Agency receives key reports, such as earned value reports, current status, and risk logs

Agency provides appropriate management of contractors such that the government is monitoring,
controlling, and mitigating the impact of any adverse contract performance

Historical performance

No significant deviations from planned cost and schedule

Lessons learned and best practices are incorporated and adopted

Human capital

Qualified management and execution team for the IT investment and/or contracts supporting the investment 

Low turnover rate

Other

Other factors that the Chief Information Officer deems important to forecasting future success

Source: Office of Management and Budget guidance and the General Service Administration’s IT Dashboard.  |  GAO‑27‑108416

OMB provides that covered agency CIOs should continually evaluate the risk of all IT investments throughout their lifecycle. However, OMB’s reporting requirements for agency CIO ratings have changed over the last decade. For example, OMB’s July 2024 Circular A-11 guidance did not state the frequency of CIO rating updates required.[16] According to OMB’s most recent Circular A-11, issued in August 2025, these risk evaluations must be reported at least once per quarter.[17]

Figure 1 illustrates the CIO rating information presented on the IT Dashboard for an example investment.

Figure 1: Example of an Agency’s IT Investment Page from the IT Dashboard Website, April 2026

FITARA Reinforced the Importance of the Dashboard

As previously mentioned, Congress enacted IT acquisition reform legislation—commonly referred to as FITARA—in December 2014. FITARA applies to covered executive branch agencies and was designed to improve agencies’ acquisition of IT and enable Congress to monitor agencies’ progress and hold them accountable for reducing duplication and achieving cost savings. FITARA contains specific requirements related to seven areas, including one titled “Enhanced Transparency and Improved Risk Management in Information Technology Investments.” Among other things, that area requires OMB and agencies to make publicly available detailed information on major federal IT investments, and agency CIOs to categorize their major IT investments by risk. The IT Dashboard addresses this requirement.

FITARA also includes requirements for OMB and agency CIOs related to performing high-risk IT investment reviews based on IT Dashboard data. For example, FITARA requires OMB to carry out consultation responsibilities of the Federal CIO with agency CIOs and program managers of major IT investments that receive high-risk ratings on the Dashboard for four consecutive quarters.[18] Similarly, FITARA includes requirements for agency CIOs related to high-risk IT investment reviews. For example, the CIO of each agency and the project manager of the investment in question are to review a major IT investment when it has received a high-risk rating for four consecutive quarters on the Dashboard.

GAO Has Previously Reported on the Dashboard

Over the past 16 years, we have issued a series of reports about the IT Dashboard. Most recently, in November 2024, we reported on federal agencies’ IT portfolio management, including whether OMB and agencies were conducting high-risk investment reviews of investments rated as high-risk on the IT Dashboard for four consecutive quarters (as required by FITARA).[19] We determined that OMB was not following its statutory requirements for these reviews. In particular, we noted that our review of agency documentation of 27 high-risk review sessions showed that the Federal CIO was not consulted for any of them.

Further, we reported that agencies did not follow the FITARA requirements for performing high-risk investment reviews. Specifically, eight agencies had a total of 17 major investments that were rated high risk for four consecutive quarters on the Dashboard; however, none of the eight agencies fully met the related FITARA requirements. We reported that the lack of high-risk investment review guidance from OMB had directly resulted in agencies’ inability to fulfill their FITARA portfolio review requirements. Several agencies noted that the OMB guidance was outdated, included links to websites that did not work, and was unclear.

Accordingly, we recommended that OMB update existing guidance or issue new guidance to agencies to implement a process to assist agencies in reviewing their IT portfolios that includes the requirements provided by FITARA. OMB neither agreed nor disagreed with our recommendation. As of October 2026, OMB had not yet taken action to address this recommendation. We also recommended that agencies, among other things, conduct high-risk IT investment reviews as prescribed by FITARA. Agencies provided varied responses to the recommendations but have started to take action to address them.

In addition, between 2010 and 2016, we issued six reports regarding the IT Dashboard.[20] These reports noted both the significant steps OMB has taken to enhance the oversight, transparency, and accountability of federal IT investments by creating the Federal IT Dashboard, as well as issues with the accuracy and reliability of the data it contains. We made a total of 47 recommendations to OMB and the associated agencies. Forty-five of the recommendations were implemented, and two were closed but not implemented.

Most recently, in June 2016, we reported on the IT Dashboard’s CIO risk ratings and noted that agencies underreported the risk of almost two-thirds of the investments their CIOs reviewed.[21] In particular, of the 95 investments we assessed, our assessments matched the CIO ratings 22 times, showed more risk 60 times, and showed less risk 13 times.

We noted that the effectiveness of the Dashboard depends on the quality of the CIOs’ ratings. However, selected agencies’ rating methods did not provide an accurate assessment of investment risk and thus reduced the value of this important tool for transparency and oversight. Further, multiple agencies’ infrequent submissions raised concerns that those updates were not reflecting timely and accurate risk information, contrary to OMB’s policy requiring monthly updates at the time. We concluded that such practices limited the transparency and oversight of the government’s billions of dollars in IT investments.

Accordingly, we made 25 recommendations to 15 agencies to improve the quality and frequency of CIO ratings. The 15 agencies implemented our recommendations.

Agencies Use a Variety of Processes to Determine Investments’ CIO Ratings

The 12 selected agencies determine investments’ CIO ratings using a variety of processes, which include OMB’s suggested factors. However, their interpretation of these factors varies significantly. In addition, about half of the selected agencies base their ratings on qualitative assessments, while the other half base them on quantitative methodologies. Further, seven agencies’ process guidance calls for at least monthly updates while five agencies call for less frequent updates (quarterly or semi-annually).

Agencies Use Many of OMB’s Suggested Factors to Determine CIO Ratings

As described earlier, OMB requires that each covered agency CIO rate the risk of the agency’s IT investments. According to OMB’s guidance, the CIO’s evaluation can be informed by the following factors, including: risk management, requirements management, contractor oversight, historical performance, human capital, and other factors that the CIO deems important to forecasting future success.[22]

Each of the 12 selected agencies has incorporated at least two of OMB’s suggested factors into their CIO’s risk rating processes and seven use all of the factors. Table 2 summarizes the extent to which the 12 selected agencies incorporate OMB’s suggested evaluation factors into their CIO’s risk rating processes. Appendix II provides more information on the selected agencies’ CIO rating processes.

Table 2: Selected Agencies’ Use of Office of Management and Budget’s Suggested Factors in Chief Information Officer Rating Processes

Agency

Risk management

Requirements management

Contractor oversight

Historical performance

Human capital

Other

Department of Agriculture

ü

—

ü

ü

—

ü

Department of Commerce

ü

ü

ü

ü

ü

ü

Department of Defense

ü

ü

ü

ü

ü

ü

Department of Education

ü

ü

ü

ü

ü

ü

Department of Health and Human Services

ü

ü

ü

ü

ü

ü

Department of Homeland Security

ü

ü

ü

ü

ü

ü

Department of State

ü

—

ü

ü

—

ü

Department of Transportation

ü

—

—

ü

—

—

Department of the Treasury

ü

ü

—

ü

—

ü

Department of Veterans Affairs

ü

ü

ü

ü

ü

ü

General Services Administration

ü

ü

—

ü

—

ü

Social Security Administration

ü

ü

ü

ü

ü

ü

ü= Factor used in the agency’s Chief Information Officer rating process

— = Factor not used in the agency’s Chief Information Officer rating process

Source: GAO analysis of agencies’ process documentation and interviews with relevant officials.  |  GAO‑27‑108416

While the factors suggested by OMB were considered in the agencies’ CIO rating processes, their interpretation of these factors varied. In particular, the selected agencies considered different types of historical data when rating their IT investments. While all the agencies considered performance measures and cost and schedule variances, three considered the investment’s earned value, and two considered relevant news, GAO, or Inspector General reports. All of these approaches align with OMB’s suggested factors.[23]

Selected Agencies Used Both Quantitative and Qualitative Methodologies

Of the 12 selected agencies, seven used formulas to create CIO ratings. Specifically, Agriculture, DHS, State, Transportation, Treasury, VA, and GSA determined their ratings by quantifying and combining inputs such as cost and schedule variances, risk exposure values, and compliance with agency processes. Metrics for compliance with agency processes included those related to program and project management, project execution, the quality of investment documentation, and whether the investment is regularly updating risk management plans and logs.

The remaining five agencies—Commerce, DOD, Education, HHS, and SSA—based their CIO ratings on qualitative assessments of performance metrics, risks, and investment documentation. In particular, they assign ratings based on metrics such as investment performance, discussions with management staff, and the quality of investment documentation.

Most Selected Agencies Require Monthly CIO Rating Updates

Seven agencies’ process guidance calls for at least monthly updates to CIO ratings while five agencies require less frequent updates. Of the five agencies, three agencies schedule their reviews quarterly (DOD, DHS, and SSA), one agency (Education) schedules its reviews semi-annually, and one agency (HHS) has a mixed schedule of quarterly and semi-annually depending on the component agency. Although monthly updates are not required by OMB’s August 2025 guidance, which requires at least quarterly updates,[24] we noted in our previous report that frequent and appropriate updating of agencies’ CIO ratings can increase transparency and oversight.[25] Table 3 summarizes the frequency of CIO rating updates called for by the selected agencies’ processes.

Table 3: Frequency of Dashboard Updates, as Called for by Selected Agencies’ Processes, as of May 2026

Agency

Monthly

Quarterly

Semi-annually

Department of Agriculture

ü

—

—

Department of Commerce

ü

—

—

Department of Defense

—

ü

—

Department of Education

—

—

ü

Department of Health and Human Services

—

üa

üa

Department of Homeland Security

—

ü

—

Department of State

ü

—

—

Department of the Treasury

ü

—

—

Department of Transportation

ü

—

—

Department of Veterans Affairs

ü

—

—

General Services Administration

ü

—

—

Social Security Administration

—

ü

—

ü= Update frequency specified in the agency’s processes

— = Update frequency not specified in the agency’s processes

Source: GAO analysis of agencies’ process documentation and interviews with relevant officials.  |  GAO‑27‑108416

aThe Department of Health and Human Services conducts either quarterly or semi-annual reviews based on certain component agencies’ requirements.

The two selected agencies that do not meet OMB’s current requirement for quarterly ratings updates in their agency processes are Education and HHS. In particular:

·        Education updates CIO ratings semi-annually.

·        HHS conducts either quarterly or semi-annual reviews based on certain component agencies’ requirements.

This issue is discussed further later in the report.

Almost Half of Selected Agencies’ CIO Ratings Did Not Fully Align with Investment Risks

Our assessments of 53 investments at 12 agencies showed that almost half of the investments were riskier than the associated CIO ratings. In particular, our assessments showed more risk 24 times, matched the CIO ratings 27 times, and showed less risk two times. We identified two factors which contributed to these differences: (1) 21 of the 53 CIO ratings were not updated in a timely manner according to agency processes and (2) two agencies’ rating processes span longer than quarterly (as previously discussed).

According to OMB’s guidance, CIO ratings “should reflect the CIO’s best judgment of the current level of risk for an investment in terms of its ability to accomplish its goals.” Such assessments of risk inherently involve a great deal of human judgment. Consequently, risk assessments should be expected to vary across organizations. For example, GSA’s CIO ratings process documentation states investments are scored based on a number of specific criteria, such as whether the investment is a high value asset or has pending financial obligations or funding risks. That is, when measuring risk, GSA uses a different set of requirements than other agencies.

We attempted to minimize the subjectivity in our risk assessments by using the agencies’ own lists of risks, known as risk registers, as the basis of our assessments (see Appendix I for additional details on our methodology). We also augmented our ratings with agencies’ briefings to review boards and investment performance information, as well as relevant reports (e.g., GAO and Inspector General). Our assessments are only intended to provide a standardized view of risk across all the agencies and investments we reviewed, and this methodology is not intended to serve as a prescriptive approach to the agencies’ evaluation of investment risk. 

Nevertheless, almost half of our assessments showed more risk than the associated CIO ratings for the 53 selected investments. Figure 2 summarizes how our assessments compared to the select investments’ CIO ratings.

Figure 2: Comparison of Selected Investments’ April 2025 Chief Information Officer Ratings to GAO Assessments

Additionally, our assessments showed more risk for at least one investment at nine of the 12 agencies we assessed. Table 4 summarizes these comparisons by agency, and Appendix III lists the April 2025 CIO ratings and our assessments for each of the selected investments.

Table 4: Comparison of GAO’s Assessments to April 2025 Chief Information Officer Ratings for the Selected Investments

Agency

Selected investments

GAO’s assessment reflected less risk

GAO’s assessment matched

GAO’s assessment reflected more risk

Department of Agriculture

5

0

5

0

Department of Commerce

5

0

4

1

Department of Defense

8

1

6

1

Department of Education

1

0

0

1

Department of Health and Human Services

9

1

4

4

Department of Homeland Security

4

0

2

2

Department of State

1

0

1

0

Department of the Treasury

4

0

1

3

Department of Transportation

8

0

3

5

Department of Veterans Affairs

6

0

0

6

General Services Administration

1

0

0

1

Social Security Administration

1

0

1

0

Total

53

2

27

24

Source: GAO’s assessment of IT Dashboard and agencies’ data.  |  GAO‑27‑108416

Our Assessments Reflected Less Risk than the Agencies’ CIO Ratings for Two Investments

Our assessments showed less risk than the CIO ratings for two of the 53 selected investments (almost four percent). Specifically, we assessed one moderately low that the agencies rated moderately high and one low that the agencies rated moderately low; there were no instances where we assessed an investment green that the agencies rated yellow. These investments belonged to two agencies: DOD and HHS. Table 5 lists those investments, the April 2025 CIO rating, and our associated assessment.

Table 5: Selected Investments for Which GAO’s Assessment Reflected Less Risk than the April 2025 Chief Information Officer (CIO) Ratings

Agency

Investment title

April 2025 CIO rating

GAO assessment

Department of Defense

Enterprise Business Systems - Convergence

Moderately High

Moderately Low

Department of Health and Human Services

Quality Improvement Organizations Information Systems

Moderately Low

Low

Source: GAO’s assessment of IT Dashboard and agencies’ data.  |  GAO‑27‑108416

The reasons why our assessments showed less risk among these investments varied. Specifically:

·        DOD officials stated the discrepancy may be due to timing variations related to when DOD updates its CIO ratings. These timing variations frequently occur due to when investments submit rating information to DOD’s Cost Assessment and Program Evaluation office for review before posting.

·        HHS officials stated that the team previously responsible for managing the investment risk ratings had been impacted by a reduction in force in April 2025. They noted that they were in the process of putting together updating risk ratings at that time, but that it did not get completed. Furthermore, investments reviewed by the CIO were generally expected to carry some level of risk and therefore were not considered completely low risk.

Our Assessments Matched the Agencies’ CIO Ratings for 27 Investments

For 27 of the 53 selected investments (51 percent), our assessments matched the CIO rating. Specifically, we matched eight moderately low risk ratings, 17 medium ratings, and two moderately high ratings. These included five investments at Agriculture, four at Commerce, six at DOD, four at HHS, three at Transportation, two at DHS, one at State, one at Treasury, and one at SSA. Table 6 lists those investments, the April 2025 CIO rating, and our associated assessment.

Table 6: Selected Investments for Which GAO’s Assessment Reflected Same Risk as April 2025 Chief Information Officer (CIO) Ratings

Agency

Investment title

April 2025 CIO rating

GAO assessment

Department of Agriculture

Commercial Loans, Grants and Guarantees

Medium

Medium

Geospatial Services

Moderately low

Moderately low

Natural Resources and Management Information

Moderately low

Moderately low

Farm Programs

Moderately low

Moderately low

Conservation Field Delivery Programs

Moderately low

Moderately low

Department of Commerce

Census Data Ingest and Collection for the Enterprise

Medium

Medium

2030 Decennial Census

Medium

Medium

Patents Product Line

Medium

Medium

Enterprise Business Product Line

Medium

Medium

Department of Defense

Air Force Integrated Personnel and Pay System

Medium

Medium

Joint Operational Medicine Information Systems

Medium

Medium

Advancing Analytics

Medium

Medium

Navy Personnel and Pay

Medium

Medium

Navy Electronic Procurement System

Medium

Medium

Naval Maintenance, Repair, and Overhaul

Medium

Medium

Department of Health and Human Services

Vaccine Tracking System

Moderately low

Moderately low

Federally Facilitated Exchange

Medium

Medium

Quality Payment Program

Moderately low

Moderately low

Unaccompanied Children

Moderately high

Moderately high

Department of Homeland Security

Integrated Surveillance Towers

Medium

Medium

Cyber Analytic and Data System

Medium

Medium

Department of State

Consular Systems Modernization

Medium

Medium

Department of Transportation

Terminal Flight Data Manager

Moderately high

Moderately high

Next Generation Air/Ground Communications

Moderately low

Moderately low

En Route Automation Modernization Enhancement and Sustainment

Medium

Medium

Department of the Treasury

Digital Services

Moderately low

Moderately low

Social Security Administration

Benefits Modernization

Medium

Medium

Source: GAO’s assessment of IT Dashboard and agencies’ data.  |  GAO‑27‑108416

Our Assessments Reflected More Risk than the Agencies’ CIO Ratings for 24 Investments

For 24 of the 53 selected investments (45 percent), our assessments reflected more risk than agencies’ CIO ratings. Specifically, we assessed five as high risk that the agencies rated medium or lower risk, seven moderately high that the agencies rated medium or lower, and 12 medium that the agencies rated moderately low or low. Table 7 lists those investments, the April 2025 CIO rating, and our associated assessment.

Table 7: Selected Investments for Which GAO’s Assessment Reflected More Risk than the April 2025 Chief Information Officer (CIO) Ratings

Agency

Investment title

April 2025 CIO rating

GAO assessment

Department of Commerce

Trademarks Product Line

Moderately low

Medium

Department of Defense

Integrated Personnel and Pay System – Army Increment 2

Moderately low

Moderately high

Department of Education

Loan Servicing

Medium

Moderately high

Department of Health and Human Services

Medicaid and Children's Health Insurance Program Business Information and Solutions

Moderately low

Medium

Modernization Health IT System & Support

Moderately low

Medium

End Stage Renal Disease Quality Reporting System

Moderately low

Medium

Hospital Quality Reporting 2.0

Moderately low

Moderately high

Department of Homeland Security

Federal Emergency Management Agency Financial Systems Modernization

Medium

Moderately high

CheckPoint Property Screening System

Moderately low

Medium

Department of Transportation

Wide Area Augmentation System

Moderately low

Medium

Standard Terminal Automation Replacement System

Medium

Moderately high

Automatic Dependent Surveillance-Broadcast

Moderately low

High

Airport Surface Detection Equipment

Moderately low

Moderately high

Enterprise Information Display System

Moderately low

High

Department of the Treasury

Tax Account Management

Low

Medium

Case Management

Moderately low

High

Filing and Intake

Moderately low

Medium

Department of Veterans Affairs

Health Management Platform

Moderately low

High

Benefits Appeals

Low

Medium

Benefits Payment

Low

Moderately high

Veterans Benefits Management

Low

Medium

Customer Relationship Management

Moderately low

Medium

Enterprise Data Services

Low

Medium

General Services Administration

Login.gov

Medium

High

Source: GAO’s assessment of IT Dashboard and agencies’ data.  |  GAO‑27‑108416

Most agencies’ explanations of why our assessments showed more risk can be attributed to differences in the methodology used to calculate the risk assessments. Officials from DOD, DHS, HHS, Treasury, VA, and GSA stated that their respective agencies’ methodologies incorporate multiple factors than only risk scores. For example, VA officials stated that VA uses all five other OMB-required factors to assess their risk rating rather than risk rating scores alone. They stated that only looking at the score for risk management may attain a score that is closer to what GAO found, but the fact that they considered the four additional factors is likely what caused the discrepancy between our assessment and their overall CIO risk rating. HHS officials also stated that under their process, each investment completed a self-assessment that was subsequently reviewed by the CIO, who either concurred with or adjusted the rating based on the CIO’s knowledge of the investment and its associated risks.

Additionally, DHS officials stated that DHS CIO ratings are determined through a separate process that evaluates more than the current risk exposure score, including performance, human capital, requirements and delivery, IT governance, contracts and acquisition, and security and privacy. Each area is assessed using detailed criteria and fixed weights. The resulting composite score is converted to a red/yellow/green rating and used to inform the DHS CIO’s rating for the IT Dashboard.

In addition to noting differences in the methodologies used to calculate risks, some agencies also offered insights on specific investments. For example,

·        Commerce rated its Trademarks Product Line investment as moderately low, but we assessed it as medium. Commerce officials stated that because this investment was undergoing a modernization effort, it was assigned a lower risk rating compared to other investments. Conversely, we assessed the investment as medium because seven of the eight risks in the investment’s risk register had medium or higher overall risk scores.

·        GSA rated its Login.gov investment as medium, but we assessed it as high. GSA OCIO officials stated that, based on GSA’s evaluation criteria, an investment rated as high would need to demonstrate factors such as consistently missing performance metric targets or experiencing persistent high cost and schedule variances which are issues that the Login.gov investment did not exhibit. However, our assessment was based on the three risks in the investment’s risk register having an average of moderately high. Additionally, we increase our assessment to high risk because Login.gov had unresolved technical issues that affected the reliability and performance of the platform, as well as incomplete data protection implementation, that were applicable as of March 2025.[26]

·        Education rated its Loan Servicing investment as medium, but we assessed it as moderately high. Education officials stated that this discrepancy is due to the ratings not being updated in a timely manner and ended up spanning longer than the usual quarterly timeline. The main reason for this delay was the challenges they faced with the investment owner as they worked through implementing a new risk rating methodology. We assessed the investment as moderately high as 16 of the 20 applicable risks in the investment’s provided risk registers had moderately high or high overall risk scores.

As noted earlier, the subjective nature of a CIO’s assessment may reflect a broader organizational view of investment risk beyond the contents of the investment’s risk register. However, unlike the two CIO ratings that reflected more risk than our assessments, these 24 CIO ratings minimized the potential severity and impact of high-risk scores. Our past work has shown that such an approach to risk management can often lead to cost and schedule overruns or failed projects.[27] Until these agencies ensure that their CIO ratings reflect the level of risk facing an investment relative to that investment’s ability to accomplish its goals, it raises the likelihood that critical IT investments are not receiving the appropriate level of oversight.

Two Issues Contributed to Discrepancies Between Agencies’ CIO Ratings and Our Assessments

In addition to the previously discussed issue of rating subjectivity, we identified two factors which contributed to differences between our assessments and CIO ratings at six of the 12 selected agencies. In particular,

·        ratings were not updated in a timely manner according to agency processes, and

·        rating processes spanned longer than quarterly.

Rather than pertaining to the CIOs’ subjective evaluations of risk, these additional issues relate to the seven agencies’ update practices or rating processes. Because these issues are with underlying practices and processes, they have the potential to impact all investment ratings—whether or not we reviewed them as part of our assessment. Specifically, we found that 21 of the 53 CIO ratings were not updated in a timely manner, as required by agency processes, and two agencies’ rating processes span longer than quarterly (see table 8). Following the table is a further description of these issues.

Table 8: Causes of Differences Between the Selected Investments’ Chief Information Officer (CIO) Rating and Our Assessment

Agency

CIO rating not updated for at least one investment in a timely manner according to agency processes

Rating process spans longer than quarterly

Department of Commerce

ü

—

Department of Education

ü

ü

Department of Health and Human Services

ü

ü

Department of Homeland Security

ü

—

Department of Transportation

ü

—

General Services Administration

ü

—

ü= Issue identified

— = Issue not identified

Source: GAO analysis of IT Dashboard data, agency documentation, and interviews with agency officials.  |  GAO‑27‑108416

Agencies Did Not Update CIO Ratings for 21 Investments in a Timely Manner According to Processes

Of the 53 investments we selected, we found that agencies had not updated CIO ratings for 21 investments in a timely manner according to their agency processes, as discussed earlier. More specifically, three agencies (Commerce, Transportation, and GSA) call for monthly updates in their processes but did not update one or more investments in April 2025. Further, two agencies (HHS and DHS) call for quarterly updates, but did not update in the 3 months before the April 2025 timeframe we assessed. Lastly, one agency (Education) calls for semi-annual updates, but did not update in the 6 months before the April 2025 timeframe we assessed. See table 9 for the number of agencies and investments that did not update their CIO ratings in a timely manner.

Table 9: Number of Agencies and Investments That Did Not Update Chief Information Officer (CIO) Ratings in a Timely Manner

Agency

Selected investments

CIO ratings not updated in a timely manner according to agency processes

Department of Commerce

5

5

Department of Education

1

1

Department of Health and Human Services

9

9

Department of Homeland Security

4

4

Department of Transportation

8

1

General Services Administration

1

1

Source: GAO analysis of IT Dashboard data.  |  GAO‑27‑108416

Of the 21 ratings that were not updated, nine were at one agency (HHS). As noted earlier, HHS officials stated that the personnel responsible for these updates were affected by a staff reduction in April 2025 while they were in the middle of compiling the CIO risk ratings. HHS officials also noted that they are working to establish and implement a standardized quarterly CIO risk rating reporting cadence rather than allowing component agencies to report on either a quarterly or semiannual basis.

Until these agencies update their CIO ratings in a timely manner consistent with their processes, the CIO ratings on the Dashboard may not reflect the current level of investment risk.

Two Selected Agencies’ Rating Processes Took Longer than Quarterly

The duration of agencies’ CIO rating processes also impacted the comparison between the CIO ratings and our assessment. As mentioned earlier, OMB’s August 2025 guidance requires at least quarterly updates to agency CIO risk ratings.[28] Further, FITARA requires agency CIOs, in consultation with the Federal CIO, to conduct a review of any investment that has been evaluated as high risk for four consecutive quarters. It is important that agencies conduct CIO risk ratings in accordance with OMB guidance to be able to align with FITARA’s requirements.

As previously discussed, 10 of the 12 selected agencies indicated that they update the IT Dashboard quarterly or more frequently. However, processes at two agencies—Education and HHS—can be longer than quarterly, as described earlier. For example, Education officials explained that they assess IT investments on a semi-annual basis, coinciding with their Annual IT Portfolio Submission.  

Further, HHS’s processes describe different timelines for different component agencies. For example, according to HHS’s processes, HHS’s Administration for Children and Families is required to submit their CIO rating quarterly, while the Centers for Disease Control and Prevention is required to submit their ratings semi-annually. Longer processes mean that CIO ratings are based upon older data. Until these agencies update their policies and procedures to report CIO ratings at least as frequently as directed in OMB’s guidance, their ratings on the Dashboard may not reflect the current level of investment risk.

Agencies Report Dashboard Challenges; GSA Addresses Issues, but OMB Oversight Gaps Persist

Of the 12 agencies we reviewed, seven identified challenges and five reported none. The challenges cited fell into three primary areas—usability, data quality and accuracy, and data submission and timeliness. However, these issues were not significant enough to prevent agencies from accessing, using, or interpreting Dashboard data. In addition, GSA has established processes to track and address user‑reported challenges. Moreover, OMB updated its IT Dashboard guidance but has not addressed key oversight gaps.

Agencies Reported Challenges Related to Usability, Data Quality, and Submission Timeliness

Selected agencies reported challenges in using the IT Dashboard. Specifically, seven agencies reported challenges, and five agencies reported no challenges. The seven agencies cited challenges in the areas of usability, data quality and accuracy, and data submission and timeliness. Table 10 below details the reported challenges and the number of agencies citing each category. These challenges are discussed following the table.

Table 10: Agency-Reported Challenges in Using the IT Dashboard

Challenge category

Number of agencies

Usability

3

Data quality and accuracy

2

Data submission and timeliness

2

IT = information technology

Source: GAO analysis.  |  GAO‑27‑108416

As shown in the table, seven agencies cited challenges with usability, data quality and accuracy, and data submission and timeliness.

·        Usability issues. Three agencies reported challenges with usability of the IT Dashboard. Specifically, officials from Agriculture’s Office of the CIO stated that data quality review messages were often unclear or contradictory, making it difficult to determine required corrective actions. Similarly, officials from Commerce’s Office of Compliance and Oversight noted that the document search interface was not intuitive and that users could not easily break down data by bureau or component, limiting the system’s analytical usefulness. Officials from HHS’s Centers for Medicare and Medicaid Services also reported that data feeds lack change tracking or version history, reducing transparency into updates.

·        Data quality and accuracy issues. Two agencies reported concerns regarding the reliability and clarity of data. In particular, an official from the State’s IT Portfolio Management Team stated that the agency did not have access to historical CIO ratings, limiting their ability to conduct trend analysis. In addition, officials from the Treasury’s Office of the CIO noted that retired investments appear in the system with a value of $0, which they consider misleading and potentially confusing to users.

·        Data submission and timeliness issues. Two agencies cited challenges related to guidance and the timing of Dashboard updates. Specifically, officials from DHS’s Office of the CIO stated that late CPIC guidance from OMB compresses reporting timelines and complicates compliance efforts. Similarly, officials from the SSA’s Office of the CIO reported that the public-facing Dashboard data is not consistently updated, reducing its usefulness for external stakeholders who rely on timely information.

In addition, five agencies—DOD, Education, Transportation, and VA, Education, and GSA—reported no challenges using the Dashboard. For example, officials from DOD’s Office of the CIO stated that the system functions as expected for their operational needs. The Director of Transportation’s Business Planning and Governance team noted that, although public users sometimes misinterpret point-in-time data, the Dashboard itself operates reliably. Officials from VA’s Office of Information and Technology as well as Education’s Director of Information Technology and Program Services did not identify any operational issues but suggested minor improvements, such as faster public posting of data.

GSA Has Established Processes to Resolve Dashboard Challenges

GSA has taken a variety of steps to resolve Dashboard challenges. GSA’s OGP, in its role as manager for the IT Dashboard, has a process in place to help address Dashboard user challenges. Specifically, an IT specialist from GSA stated that the agency actively works to improve the Dashboard based on user feedback. According to this official, the agency gathers input from end users and incorporates that feedback into system improvements. Further, the official stated that GSA prioritizes Dashboard enhancements from a backlog of user requests and implements them on a three-week cycle using Agile software development practices.[29]

In discussion of the specific challenges cited by agencies earlier, GSA officials stated that the agency receives feedback from a variety of stakeholders, including agencies discussed. The officials added that GSA documents this feedback and communicates it to OMB’s Office of the Federal CIO, which provides policy direction and directs enhancements and system changes. GSA officials noted that the agency performs technical actions as approved and directed by OMB’s Office of the Federal CIO. The backlog discussed earlier includes feature requests and product enhancements from multiple sources, including agency feedback, user experience improvements, technical updates, and system modernization initiatives. According to GSA officials, these items are prioritized and implemented based on OMB Office of the Federal CIO direction, technical feasibility, and resource availability.

An IT Specialist at GSA provided several examples of recent improvements driven by user feedback, such as the implementation of a backend function that improves the user experience for data feed exports by reducing download times and system timeouts while increasing data accuracy. In addition, the CIO rating indicators on the IT Dashboard were expanded from three color codes to five color codes.

In addition to direct issue tracking, GSA’s CPIC Project Management Office conducted a user survey between September 25 and October 9, 2024, to assess satisfaction with the Dashboard.[30] The survey included 37 respondents from federal agencies and found that users were generally satisfied with system performance and functionality. More specifically, about two-thirds (26) of the respondents reported being very satisfied or somewhat satisfied with their overall experience using the Dashboard. See table 11 for the level of satisfaction and the number of respondents reporting each level.

Table 11: Overall Satisfaction with IT Dashboard According to GSA’s October 2024 User Survey

Satisfaction level

Number of respondents

Very satisfied

6

Somewhat satisfied

20

Neutral

6

Somewhat dissatisfied

5

Very dissatisfied

0

IT = information technology

Source: General Services Administration (GSA) October 2024 IT Dashboard User Survey Results.  |  GAO‑27‑108416

Further, about three-fourths (28) of the respondents reported being very satisfied or somewhat satisfied with the level of effort needed to complete tasks. See table 12 for the level of satisfaction and the number of respondents reporting each level.

Table 12: Satisfaction with the Level of Effort Required to Complete Tasks on the IT Dashboard According to GSA’s October 2024 User Survey

Satisfaction level

Number of respondents

Very satisfied

11

Somewhat satisfied

17

Neutral

6

Somewhat dissatisfied

3

Very dissatisfied

0

IT = information technology

Source: General Services Administration (GSA) October 2024 IT Dashboard User Survey Results.  |  GAO‑27‑108416

According to GSA’s survey results, agency users reported using the Dashboard primarily for internal analysis and investment oversight. Further, users cited the most useful features of the Dashboard as the investment details page and the IT portfolio dashboard. Although respondents identified opportunities for improvement such as faster data updates, more granular bureau-level access, and improved navigation, the survey results indicate that most users view the Dashboard as functional and reliable for oversight and reporting.

Overall, based on the survey results and GSA’s documented processes for collecting and addressing user concerns, GSA’s approach to tracking and resolving reported issues is appropriate for addressing agencies’ challenges. Further, agencies’ reported challenges did not impede using core Dashboard functionality, and GSA’s incremental enhancements may further improve the Dashboard’s usability.

OMB Issued Dashboard Guidance, but Oversight Gaps Remain

In addition to GSA’s efforts, OMB has also taken action to update its IT Dashboard guidance. As mentioned earlier, OMB has issued updated CPIC guidance through Circular A-11 related to IT portfolio reporting requirements, including for the Dashboard. For example, the updated guidance noted that agencies should update the CIO risk ratings on at least a quarterly basis (previously, no timeframe was cited).[31] OMB did not respond to our request for additional information regarding actions taken to address agency-reported challenges.

Nevertheless, we previously reported in November 2024 that OMB needed to take further action to use the IT Dashboard and investment reviews with agencies to help them address challenges with their high-risk investments.[32] As mentioned earlier, FITARA requires OMB to carry out consultation responsibilities on high-risk IT investment reviews for major investments that are rated as high risk on the Dashboard for four consecutive quarters. We determined that OMB was not following its statutory requirements for these high-risk investment reviews. In particular, we noted that our review of agency documentation of 27 high-risk review sessions showed that the Federal CIO was not consulted for any of them.

Accordingly, we recommended that the Director of OMB ensure that the Federal CIO carries out the consultation responsibilities of the Federal CIO to agency CIOs and program managers of major IT investments that receive high-risk ratings for four consecutive quarters, as prescribed by FITARA. OMB neither agreed nor disagreed with our recommendation. As of October 2026, OMB had not yet taken action to address this recommendation.

OMB’s implementation of our recommendation is critical to its ability to use IT Dashboard data and investment reviews to help agencies address challenges with their high-risk IT investments. Our prior report noted that, until OMB follows FITARA’s requirements related to performing these reviews, it is less likely to be able to fully provide effective oversight of challenged IT investments. As a result, the federal government is likely to expend resources on IT investments that may not fulfill the needs of the government or the public.

Conclusions

Since its inception in 2009, the IT Dashboard has increased transparency into the government’s multi-billion dollar spending on major IT investments, with CIO ratings serving as a critical mechanism for visibility into investment risks. Beyond transparency, these ratings offer a vital opportunity to improve CIOs’ understanding of their IT portfolios and identify investments needing additional oversight. However, selected agencies’ ratings do not consistently provide an accurate assessment of investment risk. When agencies understate these risks, critical federal IT investments may fail to receive appropriate management intervention, leaving the government vulnerable to costly project failures.

Compounding these accuracy discrepancies is a widespread lack of timely CIO ratings updates across many agencies. Frequently changing investment risks require timely reporting, yet many ratings are not updated in accordance with agency processes or OMB guidance. This lag in reporting limits the real-time transparency necessary for agencies and OMB to actively monitor and respond to emerging risks associated with the government’s billions of dollars of IT investments.

OMB’s recent announcement that it was planning to sunset the IT Dashboard introduces critical uncertainty regarding the future of public transparency into the risk level of federal IT investments. OMB’s public reporting of investment risk for major IT investments is not just best practice; it is mandated by FITARA. Such reporting is critical to the ability of agencies and oversight entities, including Congress, to monitor and respond to IT investment risks. As OMB transitions to a new system, it is imperative that any successor to the IT Dashboard strengthens the public reporting of investment risk while addressing the underlying quality and timeliness issues that continue to limit the current tool's efficacy. Accordingly, in the interim, it is critical that agencies address the issues we identified with their CIO ratings.

To its credit, GSA has taken positive steps to help ensure IT Dashboard user satisfaction and maintain processes to track and resolve user reported challenges. However, persistent gaps in OMB’s oversight increase the likelihood that high-risk investments may not receive enough oversight and face higher costs. As OMB transitions to a new system, its implementation of our prior recommendation in this area is critical to address this issue, improve accountability, and enhance the monitoring of investment risk across agencies’ IT portfolios.

Recommendations for Executive Action

To improve the quality and frequency of federal IT investment risk ratings, we are making a total of 17 recommendations, including two to Commerce, one to DOD, three to Education, three to HHS, two to DHS, two to Transportation, one to Treasury, one to VA, and two to GSA.

·        The Secretary of Commerce should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 1)

·        The Secretary of Commerce should direct the department CIO to update their ratings in a timely manner consistent with their processes. (Recommendation 2)

·        The Secretary of Defense should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 3)

·        The Secretary of Education should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 4)

·        The Secretary of Education should direct the department CIO to update their ratings in a timely manner consistent with their processes. (Recommendation 5)

·        The Secretary of Education should direct the department CIO to update their policies and procedures for their ratings to be reported at least as frequently as required in OMB’s guidance. (Recommendation 6)

·        The Secretary of Health and Human Services should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 7)

·        The Secretary of Health and Human Services should direct the department CIO to update their ratings in a timely manner consistent with their processes. (Recommendation 8)

·        The Secretary of Health and Human Services should direct the department CIO to update their policies and procedures for their ratings to be reported at least as frequently as required in OMB’s guidance. (Recommendation 9)

·        The Secretary of Homeland Security should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals.  (Recommendation 10)

·        The Secretary of Homeland Security should direct the department CIO to update their ratings in a timely manner consistent with their processes. (Recommendation 11)

·        The Secretary of Transportation should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 12)

·        The Secretary of Transportation should direct the department CIO to update their ratings in a timely manner consistent with their processes.  (Recommendation 13)

·        The Secretary of the Treasury should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals.  (Recommendation 14)

·        The Secretary of Veterans Affairs should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 15)

·        The Administrator of General Services should direct the GSA CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 16)

·        The Administrator of General Services should direct the GSA CIO to update their ratings in a timely manner consistent with their processes. (Recommendation 17)

Agency Comments and Our Evaluation

We provided a draft of this report to OMB and the 12 selected agencies for review and comment. We received comments from the nine agencies to which we made recommendations. Five agencies (Education, HHS, Transportation, VA, and GSA) agreed with our recommendations, one agency (DHS) agreed with one recommendation and disagreed with another, two agencies (Commerce and Defense) disagreed, and one agency (Treasury) neither agreed or disagreed. The three selected agencies (Agriculture, State, and SSA) without recommendations either stated that they had no comments or only provided technical comments. OMB did not provide comments on our report. Specific agency responses include the following:

·        Education concurred with our recommendations. In written comments from Education, reprinted in Appendix IV, Education’s Acting Chief Information Officer stated that the agency plans to review the identified investment and make appropriate adjustments. The agency stated that it will also work towards following documented timelines and will review all documented OMB guidance and update agency policies and procedures as necessary.

·        HHS concurred with our recommendations. In written comments from HHS, reprinted in Appendix V, HHS’s Assistant Secretary for Legislation stated that the agency is updating their policies and procedures for their ratings to make risk reporting more realistic, actionable, and standardized. The agency stated that OCIO anticipates completion of these revisions by the second quarter of calendar year 2027.

·        Transportation concurred with our recommendations. In written comments from Transportation, reprinted in Appendix VI, the department stated that it has established a portfolio management process that includes regular portfolio reviews, performance monitoring, and risk evaluation, among other areas. Transportation stated that it will provide a detailed response to the recommendations after the final report is issued. We will continue to monitor the department’s implementation of our recommendations. Transportation also provided technical comments which we incorporated as appropriate.

·        VA concurred with our recommendation. In written comments from VA, reprinted in Appendix VII, VA’s Chief of Staff stated that it has restructured the six investments we reviewed and redistributed their functions and associated risks across its current investment portfolio. The agency plans to trace relevant material risks to current investments and governance owners, reassess associated CIO ratings and supporting documentation, and update its procedures to require documented consideration and escalation of material risks in final CIO ratings. VA anticipates completing these actions by December 31, 2026.

·        GSA concurred with our recommendations. In written comments from GSA, reprinted in Appendix VIII, the Administrator of General Services stated that, in response to our recommendation to ensure CIO risk ratings accurately reflect an investment’s ability to accomplish its goals, GSA would review the criteria used to determine risk ratings, including any new guidance from OMB. Regarding our recommendation to update ratings in a timely manner consistent with its processes, GSA stated that it plans to update risk ratings in a timely manner, including incorporating any new OMB guidance. GSA also provided technical comments, which we incorporated as appropriate.

·        DHS concurred with one of our recommendations and did not concur with the other. Specifically, DHS concurred with our recommendation to direct the department CIO to update their ratings in a timely manner consistent with their processes. In its written comments, reprinted in Appendix IX, DHS’s Director of Financial Management and Systems stated that the OCIO plans to reinforce its internal controls and procedures to ensure that all major IT investment ratings are reviewed and updated in a timely manner, consistent with the Department’s established quarterly reporting process. The department expects to complete this by June 30, 2027.

DHS did not concur with our recommendation to direct the department CIO to ensure that, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. DHS’s Director of Financial Management and Systems stated that while the agency agrees that investment health ratings should accurately reflect an investment’s ability to accomplish its goals, DHS believes the existing Program Health Assessment process provides an accurate and appropriately risk-informed assessment of investment health and therefore does not believe additional directions to the Chief Information Officer is necessary.

Our report acknowledges that DHS has a framework for assessing investments that considers all of OMB’s suggested factors. However, as we discussed in the report, DHS’s CIO risk ratings for the timeframe we examined were not updated in a timely manner. Our review of more recent risk information showed that the risks for two of their investments were higher than their CIO rating assessments, which raises questions whether the CIO ratings accurately reflect the abilities of the investments to accomplish their goals. Accordingly, we maintain our recommendation is warranted.

·        Commerce disagreed with our recommendation to direct the department CIO to ensure that, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. In its written comments, reprinted in Appendix X, Commerce’s Acting Deputy Assistant Secretary for Administration stated that Commerce’s OCIO considers several factors when determining the risk rating of an investment, and a CIO rating of “moderately low risk” was warranted based on this combined analysis.

We agree that Commerce includes several factors based on OMB’s requirements. However, as mentioned in our report, our analysis of Commerce’s Trademarks Product Line risk register showed that seven of the eight risks in the investment’s risk register had medium or higher overall risk scores. As a result, our assessment showed more risk than the department’s rating of moderately low for this investment. Accordingly, we maintain our recommendation is warranted.

Commerce also disagreed with our recommendation to update their ratings in a timely manner consistent with their processes. The department stated that the one-time delay was due to renewal of an interagency agreement and that the CIO continued to track and monitor the risk with the published May 2025 rating. However, as we discussed in the report, Commerce’s CIO risk ratings for the timeframe we examined were not updated in a timely manner according to the department’s processes. Accordingly, we maintain our recommendation is warranted. We acknowledge that publishing the CIO ratings in May 2025 is a positive step forward, and we will continue to monitor that Commerce’s CIO risk ratings are updating in a timely manner consistent with their processes.

·        DOD disagreed with our recommendation to direct the department CIO to ensure that, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. In comments provided via email on September 10, 2026, DOD’s Principal Director of the CIO Enterprise Technology Excellence stated that GAO’s report lacks any documented methodology to justify its conflicting “moderately high” rating. The department stated that it has fully complied with the published OMB and FITARA risk assessment guidelines, which includes OMB’s 5-point risk scale.

We agree that DOD is using a risk assessment process based on OMB’s 5-point scale. However, we disagree with DOD’s statement that the report lacks a documented methodology for our “moderately high” rating for the Integrated Personnel and Pay System – Army investment. During our review, we provided DOD with detailed information regarding our methodology (which is also presented in Appendix I) and how we determined our risk assessment for this investment using the March 2025 risk register that the department provided. Specifically, our analysis of DOD’s Integrated Personnel and Pay System – Army risk register showed that investment had three moderately-high risks, resulting in an overall assessment of moderately high. As a result, our assessment showed substantially more risk than the department’s rating of moderately-low risk for this investment. Accordingly, we maintain our recommendation is warranted.

DOD also disagreed with our recommendation to update their ratings in a timely manner consistent with their processes. The department provided additional documentation and context related to the frequency of its CIO risk rating assessment process. Upon our review of the documentation, we agree that the department had sufficiently updated their ratings in a timely manner consistent with their processes. Accordingly, we updated our report and removed the recommendation. In addition, DOD provided technical comments, which we incorporated as appropriate.

·        Treasury did not state whether it agreed or disagreed with our recommendation. In written comments, reprinted in Appendix XI, Treasury’s Deputy Assistant Secretary for Information Systems and CIO stated that it supported the objective of providing meaningful and accurate assessments of the risks affecting major investment. Treasury further noted that GAO used a different approach to assess risk based on the likelihood and potential impact of risks and stated that differences between the two approaches do not necessarily mean that Treasury’s ratings did not accurately reflect investment risks.

We acknowledge that our approach focused primarily on the probability and impact of investment risks during the timeframe we assessed. However, our approach showed substantially more risk for three investments that raises questions whether the CIO ratings accurately reflect the abilities of the investments to accomplish their goals. Accordingly, we maintain our recommendation is warranted.

Treasury also stated that it plans to continue to use its current methodology, monitor major IT investments, and update ratings as needed. We will follow up on Treasury’s actions to determine the extent to which it has implemented the recommendation.

Of the three agencies to which we did not make recommendations, Agriculture and SSA stated they had no comments on our draft report. Additionally, State provided technical comments, which we incorporated as appropriate. OMB did not provide comments on our draft report.

We are sending copies of this report to the appropriate congressional committees, the Director of the Office of Management and Budget, the Secretaries and agency heads of the departments and agencies in this report, and other interested parties. In addition, the report is available at no charge on the GAO website at https://www.gao.gov.

If you or your staff have any questions about this report, please contact me at harriscc@gao.gov. Contact points for our Offices of Congressional Relations and Media Relations may be found on the last page of this report. GAO staff who made key contributions to this report are listed in appendix XII.

Carol C. Harris
Director, Information Technology and Cybersecurity

Appendix I: Objectives, Scope, and Methodology

Our objectives for this engagement were to (1) describe selected agencies’ processes for determining the Chief Information Officer (CIO) risk ratings for major IT investments, (2) assess the extent to which selected agencies’ CIO ratings align with IT investment risks, and (3) determine what challenges, if any, selected agencies have identified with using the IT Dashboard and what efforts, if any, the General Services Administration (GSA) or the Office Management and Budget (OMB) have underway to address them.

To select the agencies and investments, we reviewed data reported to OMB as part of the federal budget process to identify major IT investments planning to spend $35 million or more on development, modernization, and enhancement activities in fiscal year 2025. This produced a list of 12 agencies and 67 selected investments. These agencies were: the Departments of Agriculture, Commerce, Defense (DOD), Education, Health and Human Services (HHS), Homeland Security, State, Transportation, the Treasury, and Veterans Affairs, as well as GSA and the Social Security Administration (SSA).  

After reviewing agency documentation, we removed 14 investments. This included eight investments that fell below the $35 million threshold (e.g., due to changes in agency planned spending), four that lacked risk registers we could analyze (e.g., had no open risks), one that lacked a CIO risk rating on the IT Dashboard due to being a new investment, and one that was managed under a larger program without a standalone risk register. This resulted in 53 investments at the 12 agencies. Appendix III contains a complete listing of the selected agencies and investments.

To address our first objective, we collected relevant CIO rating process documentation from the 12 selected agencies, such as capital planning and investment control (CPIC) guides and program health assessment guidance. We also met with agency officials to discuss their CIO rating processes. We then compared the agencies’ processes to the OMB suggested evaluation factors for creating CIO ratings.[33] These evaluation factors are: (1) risk management, (2) requirements management, (3) contractor oversight, (4) historical performance, (5) human capital, and (6) other (i.e., the other factors that the CIO deems important to forecasting future success). We also analyzed the agencies’ documents to determine how the agencies’ use of OMB’s factors varied.

To address our second objective, we downloaded the April 2025 CIO ratings information for the 53 selected investments from the IT Dashboard. We focused on April 2025, the month that our audit work began, to minimize any influence that our ongoing work could have on the agencies’ processes and resulting ratings. We also interviewed agency officials regarding their CIO ratings.

To assess the reliability of the IT Dashboard CIO risk rating data, we asked agencies about their processes for assigning the CIO ratings of their IT investments and for revising inaccurate ratings if needed. We also verified the CIO ratings data with agency officials. We determined that the CIO risk rating data was sufficiently reliable for our purposes.

According to OMB’s guidance, CIO ratings should reflect the CIO’s best judgment of the current level of risk for an investment in terms of its ability to accomplish its goals.[34] To develop our assessments of investments’ risk, we collected March 2025 risk documentation (the data we would expect to be reflected in the April ratings), executive review board briefings, and relevant reports (e.g., GAO and Inspector General reports). In cases where agencies were unable to provide March documentation, we used documents from the closest available date. We did not consider risks that were introduced after March in these documents.

To assess the reliability of agencies’ risk registers, we reviewed related documentation, such as agency risk management policies and procedures. We also performed manual checks for missing data or obvious errors. In instances where we identified such issues, we followed up with agency officials to determine the cause or request additional information. We determined that the risk registers were sufficiently reliable for our purposes.

We used agencies’ risk register information to assess each selected investment’s overall risk. Specifically, we combined the probability and impact of every active risk in the risk registers of each of the selected investments to determine what is known as the exposure of each risk.[35] These exposure scores ranged from “low” to “high” and were based upon industry and government best practices. Table 13 shows how probability and impact values derived from these sources were combined to determine risk exposure.

Table 13: Example of Risk Exposure Scores Resulting from Agency-Assigned Probability and Impact Values

 

 

 

 

Impact

 

 

 

 

Low

Moderately low

Medium

Moderately high

High

Probability

Low

Low

Low

Moderately low

Medium

Medium

Moderately low

Low

Moderately low

Moderately Low

Medium

Medium

Medium

Moderately Low

Moderately low

Medium

Moderately high

Moderately high

Moderately high

Medium

Medium

Moderately high

Moderately high

High

High

Medium

Medium

Moderately high

High

High

Source: GAO analysis of industry and government best practices.  |  GAO‑27‑108416

We then weighed each risk exposure, placing significantly increased emphasis on higher risks so that they were not canceled out by lower risks. Table 14 lists the weights we assigned to the exposures.

Table 14: Risk Exposures and Associated Weight

Risk exposure level

Weight

Low

0

Moderately low

1

Medium

3

Moderately high

9

High

27

Source: GAO.  |  GAO‑27‑108416

We then averaged these weights and translated the result into green, light green, yellow, light red, and red grades according to the following scale, as shown in table 15.

Table 15: Range of Weighted Averages and Corresponding Risk Level and Color

Weighted Average Range

Risk Level

Color

Less than 1

Low

Green

Greater than or equal to 1 and less than 3

Moderately low

Light green

Greater than or equal to 3 and less than 9

Medium

Yellow

Greater than or equal to 9 and less than 18

Moderately high

Light red

Greater than or equal to 18 and less than or equal to 27

High

Red

Source: GAO.  |  GAO‑27‑108416

For example, we would assess the following risk register as medium risk, or yellow, as shown in table 16.

Table 16: Example of Probability, Impact, Exposures, and Grading, Based on the Evaluation of Risks for a Generic Investment

Individual Risk

Probability

Impact

Risk Exposure

Weight

Example A

Low

Low

Low

0

Example B

Low

Low

Low

0

Example C

Moderately low

Medium

Moderately low

1

Example D

Moderately low

Moderately high

Medium

3

Example E

Medium

Medium

Medium

3

Example F

Medium

Moderately high

Moderately high

9

Example G

High

Moderately high

High

27

Average

 

 

 

6.1

Source: GAO.  |  GAO‑27‑108416

We then lowered the assessments based on consideration of the following elements: (1) relevant reports (e.g., GAO and Inspector General reports) and (2) relevant executive review board briefings.

Specifically, we first reviewed GAO, Inspector General, and other relevant reports that pertained to the selected investments. We used these sources to lower our assessment one level (e.g., moderately low to medium or medium to moderately high) if we deemed the identified issues represented serious risks to the investment and remained relevant in April 2025. In order to keep our assessment focused on current issues, we only considered information dated from March 2024 through March 2025. Using this approach, we lowered our assessment for nine investments. In certain cases, we lowered our assessment more than once when multiple GAO or IG reports identified different areas of risk.

Second, if an investment had an executive review board briefing covering the March 2025 time period, we reviewed the documentation to determine if the investment was facing serious issues that could increase investment risk. In cases where agencies were unable to provide March documentation, we used documents from the closest available date. We did not consider risks that were introduced after March in these documents. Using this approach, we lowered our assessment two levels for one investment.

We then compared our assessments to the April 2025 CIO ratings on the Dashboard and identified investments where our assessment of risk was higher, lower, or the same. We also discussed our findings with agency officials and corroborated the Dashboard’s data with agency officials. Our calculations are only intended to provide a standardized view of risk across all the departments and investments we reviewed, and this methodology is not intended to serve as a prescriptive approach to the agencies’ evaluation of investment risk.

For the third objective, we examined how selected agencies use the IT Dashboard and the challenges they encounter. We interviewed agency officials to understand what challenges, if any, they faced in using the IT Dashboard. We then consolidated the challenges that agencies reported and summarized our analysis.

To assess GSA and OMB actions to address agency challenges, we first reviewed GSA documentation and interviewed GSA officials from its Office of Government-Wide Policy and CPIC Project Management Office.[36] The documentation reviewed included, for example, GSA’s processes and procedures for addressing IT Dashboard issues reported by users. We also reviewed the results of GSA’s IT Dashboard user survey conducted between September and October 2024. To assess the reliability of GSA’s user survey, we reviewed the survey results for outliers or obvious errors. We also discussed with agency officials regarding how the survey was conducted and steps taken to ensure its reliability. We determined that the GSA survey data was sufficiently reliable for our purposes.

In addition, regarding OMB, we reviewed updated OMB guidance related to the IT Dashboard. We also reviewed our prior reports on the IT Dashboard and related issues that pertained to OMB. OMB did not respond to our requests for additional information on their actions to address IT Dashboard user challenges or requests for interviews with agency officials.

We conducted this performance audit from April 2025 to October 2026 in accordance with generally accepted government auditing standards. Those standards require that we plan and perform the audit to obtain sufficient, appropriate evidence to provide a reasonable basis for our findings and conclusions based on our audit objectives. We believe that the evidence obtained provides a reasonable basis for our findings and conclusions based on our audit objectives.

Appendix II: Selected Agencies’ CIO Rating Processes

Table 17 describes the processes used by selected agencies to create the CIO rating for their investments.

Table 17: Details of the Chief Information Officer (CIO) Rating Processes Reported by Selected Agencies

Agency

Responsibility for drafting the CIO rating

Factors used to create the CIO rating

How factors are used to determine the CIO rating

Department of

Agriculture

Office of Chief Information Officer (OCIO) Information Resource Management Center, IT Portfolio Management Division, Mission Area Assistant CIO

According to Agriculture’s CIO Rating Criteria Overview and Agriculture officials, the following categories make up the criterion:

·         Investment overview, where all investment information provided is supported and updated;

·         Performance metrics have been met consistently throughout the trend assessment period;

·         Risk management, such as risk mitigation strategies in place for all identified active risks, and evidence of risk management practices being updated monthly with follow-up actions documented;

·         Contracts and planned acquisitions have sufficient details (management, execution, etc.) provided in an Acquisition Strategy/Acquisition Plan;

·         Federal Acquisition Certification for Program and Project Managers (FAC-P/PM) certificationa is active and within current cycle;

·         Technology Business Managementb, where investments are rated for variances between cost areas (i.e. cost pools/towers) and percent of costs categorized by IT solutions.

Each category is given a weighed score ranging from 1 to 5. The score is determined by responses to a CIO Rating self-assessment, and these determine if the investment complies with the criteria of that category. The weighed score in each category is used to calculate the CIO rating.

Department of Commerce

Capital Planning and Investment Control team, OCIO, IT Portfolio team

According to Commerce’s Capital Planning and Investment Control (CPIC) How to Guide: CIO Ratings Module document, the following factors are used to evaluate the health and risk of each investment:

·         risk management

·         requirements management

·         contractor oversight

·         historical performance

·         human capital

·         security

·         operational analysis and metrics

·         overall evaluation

A monthly data call is distributed to bureaus with major investments requesting:

·         updates to projects, activities, risks, performance metrics, and contracts, among other things;

·         an evaluation of the investment updates, artifacts, responses to questions, and any external evaluations (e.g., Office of Inspector General audits/investigations).

Overall score is calculated based on the self-assessment responses for each factor.

Department of Defense (DOD)

Component CIO, Director of Cost Assessment and Program Evaluation

According to DOD’s CIO Risk Ratings Process Guide for the Federal Information Technology (IT) Dashboard document, the following factors are used to evaluate each investment:

·         Risk management, such as a risk management strategy, exists in a complete and current manner;

·         Requirements management, with requirements being complete, clear, and validated;

·         Contractor oversight, such as an acquisition strategy that is defined and properly managed;

·         Historical performance with no significant deviations from planned cost and schedule;

·         Human capital, with qualified management and execution teams for the IT investments and/or contracts supporting the investment;

·         Other factors that the CIO deems important to forecasting future success.

A qualitative assessment of the factors.

Department of Education

Investment and Acquisition Management Branch

According to Education’s OCIO CIO Risk Rating Evaluation Overview, the following factors contribute to the CIO rating for each investment:

·         Requirements management, with a primary focus on a current and comprehensive requirements management plan for investments with active projects;

·         Risk management, with a focus on a current and comprehensive risk management plan at the investment level, communication of risk to stakeholders, mitigation of high-risk areas, and meeting reporting compliance of risk data;

·         Human capital, focusing on key personnel and identifying qualified management and execution team for the investment and contracts supporting the investment;

·         Contract management, focusing on a current and comprehensive acquisition strategy, accountable oversight by key stakeholders, and current reporting of all IT contracts associated with the investment;

·         Historical performance, focusing on how well initiatives within the investment are performing relative to planned cost, schedule, scope, return on investment, established performance, in addition the submission of the required artifacts that support these areas;

·         Cybersecurity, with a focus on the assessment of the systems that are supported by the investment and ensuring that security risks for these systems are relatively low.

Each factor will be assessed and given its own individual rating, which will populate an aggregate raw score ranging from 1 to 5.

The CIO will review the ratings and determine if there are any additional factors that should impact the score. If there are, the CIO discretion rating will become the final rating score. If there aren’t, the raw score will remain the final score for the evaluation. 

Department of Health and Human Services (HHS)

CPIC Team, Investment Manager, CIO

According to HHS’s IT Investment Risk Evaluation Template, the following factors contribute to the CIO rating for each investment:

·         Risk management, such as an updated risk management plan, an active risk log or risk register, and a risk assessment;

·         Requirements management, such as updated alternatives analysis and updated investment compliancy following a post-implementation review;

·         Contractor oversight, such as a defined acquisition strategy and complete contract report for each investment;

·         Investment performance, such as operational metrics meeting investment targets, budget, and schedule;

·         Human capital, such as FAC/P-PM certification of investment/project managers and filled key roles;

·         Cybersecurity, such as all systems associated with investments having an active authority to operate.

A self-assessed rating based on evaluation scores from the factors. The CIO then gives a discretionary risk rating and rationale.

Department of Homeland Security (DHS)

OCIO Chief Technology Officer Directorate Enterprise Technical Engineering Division /Program Health Assessment team

According to DHS’s CIO Program Health Assessment Process Guide and DHS officials, the following criteria are used to determine ratings:

·         Risk and risk management, intending to ensure that programs develop a risk management plan and manage a risk register;

·         Performance risk, intending to ensure that the program’s critical cost, schedule, and performance parameters are met to accomplish its goals;

·         Human capital, intending to measure the extent to which the program is adequately staffed;

·         Requirements and delivery, reflecting the program’s capabilities to deliver as expected and to measure its customer satisfaction. It also highlights the program’s effort to increase the probability of on-time deliveries through increased flexibility across the life cycle of its projects;

·         IT governance, reflecting the degree to which planning, development, and management are consistent with compliance regulations, agile directives, and legislative requirements;

·         Contracts and acquisition, intending to ensure that the program is operating in accordance with DHS’s acquisition policies and procedures to ensure sound management, review, support, approval, and oversight of all types of acquisitions;

·         Security and privacy, evaluating the degree to which the programs are adhering to DHS’s personally identifiable information standards and privacy policies.

Each criterion is scored and weighted to calculate the overall program score.

Department of State

Technology Executive Council Program Management Office

According to State’s CIO IT Evaluation (CITE) Dashboard and Evaluation Factor Overview and State officials, the following criteria are used to determine ratings:

·         Cyber funding management, including evaluation of cyber functions and capabilities;

·         Financial management, such as financial planning, continuous development and operations to indicate significant vulnerabilities, and cost accounting;

·         Investment management, such as government resources supporting the management of IT investments, investment manager qualification, and investment team engagement;

·         Performance management, such as determining how often performance metric actuals are updated and reviewing return on investment and cost benefit analyses;

·         Project management, including effective cost planning, effective schedule planning of projects, and an investment’s ability to provide incremental value with agile development;

·         Risk management, such as examining the investment team’s capacity to conduct risk management activities and report on risks to the IT portfolio;

·         Steady State management, including operational activities planning, operational activities management, and contract oversight;

·         System management, including architecture alignment and Federal Information Security Modernization Act systems security examining the system assets associated with each investment.

Overall score is calculated based on the self-assessment responses for each factor.

Department of Transportation

Investment managers, CPIC team, Federal Aviation Administration technical team

According to Transportation’s Information Technology (IT) Portfolio Management Guide and Transportation officials, the following factors are used to determine ratings:

·         A combination of risk probability and risk impact of all active risks, resulting in an average weighted score;

·         Performance of active projects such as cost variance and operational metrics;

Project manager assessment where the investment manager will provide his/her overall assessment on whether the program is on-track to meet the baseline cost, schedule, and technical performance objectives.

Each criterion is scored and weighted to calculate the overall program score.

Department of the Treasury

OCIO is supported by a team of CPIC Desk Officers

According to Treasury’s IT CPIC Guide and Treasury officials, the following criteria are used to determine ratings:

·         An operational risk rating based on all current investment risks, including cost and schedule performance, variance in operational metrics, and current operational risk assessment;

·         The bureau CIO rating as an integer between 1 and 5;

·         Informed judgment of the Treasury CPIC Desk Officer.

The factors are scored, summed, and put through an overall investment rating equation rounded to the nearest integer.

Veterans Affairs (VA)

CIO, investment manager, IT Governance Board, Program and Acquisition Review Council, Operations and Portfolio Management Committee, IT Performance Review Team Working Group, IT Enterprise Governance Team

According to VA’s CIO Evaluation Ratings Overview and VA officials, the following factors are used to determine ratings:

·         Human capital, including measuring the percentage of projects with project manager experience commensurate with project level, and percentage of project managers managing multiple projects;

·         Historical performance, including percentage of cost variance and schedule variance;

·         Risk management, including risk matrix rating based on average risk probability and impact;

·         Requirements management, including number of expiring authority to operate at-risk by system and percentage of planned project functionality delivered within 6-month increment;

·         Contractor oversight, including percentage of projects with contractor evaluations per month and percentage of contractor rating by IT investment.

A quantitative assessment of the factors with 1 point possible per category, for an overall score of 5 points possible per investment.

General Services Administration (GSA)

Office of the CIO, CPIC team

According to GSA’s CIO Rating Scoring Criteria and GSA OCIO officials, several factors are used to determine ratings. Specifically, whether the investment:

·         is a shared service or E-government initiative;

·         is a security investment;

·         is a high visibility initiative (i.e. the investment has been included in testimony before Congress);

·         is a high value asset;

·         has a development, modernization, and enhancement budget greater than $5 million or the percentage of development, modernization, and enhancement spending greater than 50 percent;

·         has no FAC-P/PM level 3 certification with specialization;

·         has pending financial obligations or fundings risks;

·         has three or more active risks rating 10 or above.

An investment will receive a rating based on whether it meets any three of the combined factors.

Social Security Administration (SSA)

CIO, The Office of IT Financial Management & Support

According to SSA officials and SSA’s Investment Management Tool Modern User Experience User Guide, the factors pertain to the Office of Management and Budget’s recommended categories. Specifically, performance, human capital, risk management, contract/acquisition management, and requirements management. Additional categories include incremental development and transparency. Under all categories, the following factors are used to determine ratings:

·         Fiscal year cost variance percent;

·         Number of missed implementation dates;

·         Number of change requests;

·         Number of high risks in project management, project team, business, and/or requirements;

·         Number of missing stakeholder contacts in the following fields: Business Owner, Business Sponsor Contact, Project Manager, OCIO Tech Lead;

·         Number of missing mitigation strategies across all project risks;

·         Number of past due target response dates across all project risks;

·         Duration between completed implementation dates;

·         Number of high risks identified across all project risks;

·         Value realization at the investment level.

A qualitative assessment of the factors.

Source: GAO analysis of agencies’ process documentation and interviews with relevant officials.  |  GAO‑27‑108416

aAccording to General Services Administration guidance, FAC/P-PM certification is meant for acquisition professionals performing program and project management activities and functions and focuses on essential functional and technical competencies needed for program and project managers. It does not include agency-specific competencies.

bTechnology Business Management is a framework focused on providing technology, finance, and business leaders with standards for managing the value that IT brings to their organizations.

Appendix III: Agencies and Investments Selected for Review

Table 18 lists the selected agencies and investments, as well as the associated Chief Information Officer (CIO) ratings and our assessments.

Table 18: Agencies and Investments Selected for Review, Associated Chief Information Officer (CIO) Ratings, and Our Assessments

Agency

Investment title

April 2025 CIO rating

GAO assessment

Department of Agriculture

Commercial Loans, Grants and Guarantees

Medium

Medium

Geospatial Services

Moderately low

Moderately low

Natural Resources and Management Information

Moderately low

Moderately low

Conservation Field Delivery Programs

Moderately low

Moderately low

Farm Programs

Moderately low

Moderately low

Department of Commerce

Census Data Ingest and Collection for the Enterprise

Medium

Medium

2030 Decennial Census

Medium

Medium

Patents Product Line

Medium

Medium

Trademarks Product Line

Moderately low

Medium

Enterprise Business Product Line

Medium

Medium

Department of Defense

Air Force Integrated Personnel and Pay System

Medium

Medium

Navy Electronic Procurement System

Medium

Medium

Integrated Personnel and Pay System – Army Increment 2

Moderately low

Moderately high

Joint Operational Medicine Information Systems

Medium

Medium

Advancing Analytics

Medium

Medium

Navy Personnel and Pay

Medium

Medium

Naval - Maintenance, Repair, and Overhaul

Medium

Medium

Enterprise Business Systems - Convergence

Moderately high

Moderately low

Department of Education

Loan Servicing

Medium

Moderately high

Department of Health and Human Services

Vaccine Tracking System

Moderately low

Moderately low

Federally Facilitated Exchange

Medium

Medium

Medicaid and Children's Health Insurance Program Business Information and Solutions

Moderately low

Medium

Quality Improvement Organizations Information Systems

Moderately low

low

Quality Payment Program

Moderately low

Moderately low

Unaccompanied Children

Moderately high

Moderately high

Modernization Health IT System & Support

Moderately low

Medium

End Stage Renal Disease Quality Reporting System

Moderately low

Medium

Hospital Quality Reporting 2.0

Moderately low

Moderately high

Department of Homeland Security

Federal Emergency Management Agency Financial Systems Modernization

Medium

Moderately high

Integrated Surveillance Towers

Medium

Medium

CheckPoint Property Screening System

Moderately low

Medium

Cyber Analytic and Data System

Medium

Medium

Department of State

Consular Systems Modernization

Medium

Medium

Department of Transportation

Terminal Flight Data Manager

Moderately high

Moderately high

Wide Area Augmentation System

Moderately low

Medium

Next Generation Air/Ground Communications

Moderately low

Moderately low

Standard Terminal Automation Replacement System

Medium

Moderately high

Automatic Dependent Surveillance-Broadcast

Moderately low

High

En Route Automation Modernization Enhancement and Sustainment

Medium

Medium

Airport Surface Detection Equipment

Moderately low

Moderately high

Enterprise Information Display System

Moderately low

High

Department of the Treasury

Tax Account Management

Low

Medium

Case Management

Moderately low

High

Digital Services

Moderately low

Moderately low

Filing and Intake

Moderately low

Medium

Department of Veterans Affairs

Health Management Platform

Moderately low

High

Benefits Appeals

Low

Medium

Benefits Payment

Low

Moderately high

Veterans Benefits Management

Low

Medium

Customer Relationship Management

Moderately low

Medium

Enterprise Data Services

Low

Medium

General Services Administration

Login.gov

Medium

High

Social Security Administration

Benefits Modernization

Medium

Medium

Source: GAO’s assessment of IT Dashboard and agencies’ data.  |  GAO‑27‑108416

Appendix IV: Comments from the Department of Education

Appendix V: Comments from the Department of Health and Human Services

Appendix VI: Comments from the Department of Transportation

Appendix VII: Comments from the Department of Veterans Affairs

Appendix VIII: Comments from the General Services Administration

Appendix IX: Comments from the Department of Homeland Security

Appendix X: Comments from the Department of Commerce

Appendix XI: Comments from the Department of the Treasury

Appendix XII: GAO Contact and Staff Acknowledgments

GAO Contact

Carol C. Harris, at harriscc@gao.gov

Staff Acknowledgments

In addition to the contact named above, individuals making contributions to this report included Jon Ticehurst (Assistant Director), Neha Bhatt (Analyst-in-Charge), Jonnie Genova, Smith Julmisse, Hassan Kane, Evan Kreiensieck, and Sarah Ong.

GAO’s Mission

The Government Accountability Office, the audit, evaluation, and investigative arm of Congress, exists to support Congress in meeting its constitutional responsibilities and to help improve the performance and accountability of the federal government for the American people. GAO examines the use of public funds; evaluates federal programs and policies; and provides analyses, recommendations, and other assistance to help Congress make informed oversight, policy, and funding decisions. GAO’s commitment to good government is reflected in its core values of accountability, integrity, and reliability.

Obtaining Copies of GAO Reports and Testimony

The fastest and easiest way to obtain copies of GAO documents at no cost is through our website. Each weekday afternoon, GAO posts on its website newly released reports, testimony, and correspondence. You can also subscribe to GAO’s email updates to receive notification of newly posted products.

Order by Phone

The price of each GAO publication reflects GAO’s actual cost of production and distribution and depends on the number of pages in the publication and whether the publication is printed in color or black and white. Pricing and ordering information is posted on GAO’s website, https://www.gao.gov/ordering.htm.

Place orders by calling (202) 512-6000, toll free (866) 801-7077, or
TDD (202) 512-2537.

Orders may be paid for using American Express, Discover Card, MasterCard, Visa, check, or money order. Call for additional information.

Connect with GAO

Connect with GAO on X, LinkedIn, Instagram, and YouTube.
Subscribe to our Email Updates. Listen to our Podcasts.
Visit GAO on the web at https://www.gao.gov.

To Report Fraud, Waste, and Abuse in Federal Programs

Contact FraudNet:

Website: https://www.gao.gov/about/what-gao-does/fraudnet

Automated answering system: (800) 424-5454

Media Relations

Sarah Kaczmarek, Managing Director, Media@gao.gov

Congressional Relations

David A. Powner, Acting Managing Director, CongRel@gao.gov

General Inquiries

https://www.gao.gov/about/contact-us



[1]The IT Dashboard can be found at https://itdashboard.gov/, as of October 2026.

[2]Federal Information Technology Acquisition Reform provisions of the Carl Levin and Howard P. “Buck” McKeon National Defense Authorization Act for Fiscal Year 2015, Pub.  L. No. 113-291, div A, title VIII, subtitle D, 128 Stat. 3292, 3438-3450 (Dec. 19, 2014)

[3]40 U.S.C. § 11302(c)(3).

[4]GAO, IT Dashboard: Agencies Need to Fully Consider Risks When Rating Their Major Investments, GAO‑16‑494 (Washington, D.C.: June 2, 2016); IT Dashboard: Agencies Are Managing Investment Risk, but Related Ratings Need to Be More Accurate and Available, GAO‑14‑64 (Washington, D.C.: Dec. 12, 2013); IT Dashboard: Opportunities Exist to Improve Transparency and Oversight of Investment Risk at Select Agencies, GAO‑13‑98 (Washington, D.C.: Oct. 16, 2012); IT Dashboard: Accuracy Has Improved, and Additional Efforts Are Under Way to Better Inform Decision Making, GAO‑12‑210 (Washington, D.C.: Nov. 7, 2011); Information Technology: OMB Has Made Improvements to Its Dashboard, but Further Work Is Needed by Agencies and OMB to Ensure Data Accuracy, GAO‑11‑262 (Washington, D.C.: Mar. 15, 2011); and Information Technology: OMB’s Dashboard Has Increased Transparency and Oversight, but Improvements Needed, GAO‑10‑701 (Washington, D.C.: July 16, 2010). 

[5]GAO, High-Risk Series: An Update, GAO‑15‑290 (Washington, D.C.: Feb. 11, 2015). More information on our High Risk List can be found at https://www.gao.gov/high‑risk‑list.

[6]GAO, High-Risk Series: Heightened Attention Could Save Billions More and Improve Government Efficiency and Effectiveness, GAO‑25‑107743 (Washington, D.C.: Feb. 25, 2025).

[7]https://itdashboard.gov/. Accessed on April 27, 2026.

[8]According to GSA, the Office of Government-Wide Policy provides policy, guidance, and best practices in federal property, technology, mission support operations, and sustainable solutions for the current and future government.

[9]These data are comprised of submissions from the following 26 federal agencies: the Departments of Agriculture, Commerce, Defense, Education, Energy, Health and Human Services, Homeland Security, Housing and Urban Development, Justice, the Interior, Labor, State, Transportation, the Treasury, and Veterans Affairs; the Environmental Protection Agency; the General Services Administration; the National Aeronautics and Space Administration; National Archives and Records Administration; National Science Foundation; Nuclear Regulatory Commission; Office of Personnel Management; Small Business Administration; Social Security Administration; U.S. Agency for International Development; and the U.S. Army Corps of Engineers. 

[10]As part of our review, we interviewed officials from GSA’s Office of Government-Wide Policy regarding the agency’s IT Dashboard management responsibilities. We also interviewed officials from GSA’s Office of the CIO regarding the Login.gov investment. The applicable offices of the GSA officials are specified throughout the report where appropriate.

[11]OMB, Preparation, Submission, and Execution of the Budget, Circular No. A-11, Section 55 (Washington, D.C.: Aug. 29, 2025). 

[12]According to the Software Engineering Institute, risk can be calculated as a combination of probability (or likelihood) and impact (or consequences). The institute gives credit for the formula to Barry W. Boehm.

[13]According to OMB, a major IT investment is one that requires special management attention because of its importance to the mission or function to the government; has significant program or policy implications; has high executive visibility; has high development, operating, or maintenance costs; has an unusual funding mechanism; or is otherwise defined as major by the agency’s capital planning and investment control (CPIC) process. Investments not considered major are non-major.

[14]These data are comprised of submissions from the following 26 federal agencies: the Departments of Agriculture, Commerce, Defense, Education, Energy, Health and Human Services, Homeland Security, Housing and Urban Development, Justice, the Interior, Labor, State, Transportation, the Treasury, and Veterans Affairs; the Environmental Protection Agency; the General Services Administration; the National Aeronautics and Space Administration; National Archives and Records Administration; National Science Foundation; Nuclear Regulatory Commission; Office of Personnel Management; Small Business Administration; Social Security Administration; U.S. Agency for International Development; and the U.S. Army Corps of Engineers. 

[15]OMB, Preparation, Submission, and Execution of the Budget, Circular No. A-11, Section 55, (Washington, D.C.: Aug. 29, 2025).

[16]OMB, Preparation, Submission, and Execution of the Budget, Circular No. A-11, Section 55, (Washington, D.C.: July 25, 2024).

[17]OMB, Preparation, Submission, and Execution of the Budget, Circular No. A-11, Section 55, (Washington, D.C.: Aug. 29, 2025).

[18]40 U.S.C § 11302(c)(4).

[19]GAO, IT Portfolio management: OMB and Agencies Are Not Fully Addressing Selected Statutory Requirements, GAO‑25‑107041 (Washington, D.C.: Nov. 14, 2024)

[22]OMB, Preparation, Submission, and Execution of the Budget, Circular No. A-11, Section 55 (Washington, D.C.: Aug. 29, 2025).

[23]Earned value is determined by measuring of the value of work accomplished in a given period and comparing it with the planned value of work scheduled for that period and with the actual cost of work accomplished. It can provide important information about the health of an investment and an objective view of program status. For more information, see GAO, Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs, GAO‑20‑195G (Washington, D.C.: Mar. 12, 2020).

[24]OMB, Preparation, Submission, and Execution of the Budget, Circular No. A-11, Section 55 (Washington, D.C.: Aug. 29, 2025).

[26]GAO, Identity Verification: GSA Should Demonstrate Its Implementation of Policies for Testing Data Backups on Login.gov, GAO‑25‑107500  (Washington, D.C.: June 3, 2025) and Identity Verification: GSA Needs to Address NIST Guidance, Technical Issues, and Lessons Learned, GAO‑25‑106640 (Washington, D.C.: Oct. 16, 2024).

[27]GAO, Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs, GAO‑20‑195G (Washington, D.C.: Mar. 12, 2020).

[28]OMB, Preparation, Submission, and Execution of the Budget, Circular No. A-11, Section 55 (Washington, D.C.: August 29, 2025).

[29]Agile software development is an approach that emphasizes the development of software in iterations that are being continuously evaluated on their functionality, quality, and customer satisfaction. For more information, see GAO, Agile Assessment Guide: Best Practices for Agile Adoption and Implementation, GAO‑24‑105506 (Washington, D.C.: Nov. 28, 2023).

[30]GSA’s CPIC Project Management Office is part of GSA’s OCIO.

[31]Office of Management and Budget, Circular No. A-11: Preparation, Submission, and Execution of the Budget, Section 55 (Washington, D.C.: Aug. 29, 2025).

[32]GAO, IT Portfolio Management: OMB and Agencies Are Not Fully Addressing Selected Statutory Requirements, GAO‑25‑107041 (Washington, D.C., Nov. 14, 2024).

[33]OMB, Preparation, Submission, and Execution of the Budget, Circular No. A-11, Section 55 (Washington, D.C.: Aug. 29, 2025). 

[34] See Footnote 9.

[35]According to the Software Engineering Institute, risk can be calculated as a combination of probability (or likelihood) and impact (or consequences). The institute gives credit for the formula to Barry W. Boehm. We used that formula to calculate risk exposure scores: risk exposure = likelihood of occurrence (probability) * loss due to undesirable outcome (impact).

[36]GSA’s CPIC Project Management Office is part of GSA’s Office of the CIO.