Friday 9 October 2026Search
Politics

Federal IT Investment Ratings Often Miss Risk, GAO Finds

1 min read

The Government Accountability Office released a report finding that selected agencies' Chief Information Officer risk ratings for federal IT investments did not always fully consider risks. GAO assessed 53 selected investments and compared its findings to the agencies' CIO ratings. GAO's assessments identified more risk than the CIO ratings in 24 cases, matched the CIO ratings in 27 cases, and showed less risk in 2 cases.

GAO found that 21 of the 53 CIO ratings were not updated in a timely manner according to agencies' own processes. In addition, two agencies' rating processes span longer than quarterly, contrary to Office of Management and Budget guidance. Selected agencies GAO reviewed used different processes to develop their ratings, and most included some, if not all, of six factors that OMB suggested. The OMB sets policies for the Federal IT Dashboard, which is operated by the General Services Administration.

The federal government spends over $100 billion annually on IT and cyber investments, but many projects face cost overruns and delays. GAO reviewed 26 agencies' fiscal year 2025 budget data reported to OMB to identify major IT investments of $35 million or more of development activities. This resulted in 53 selected investments at 12 agencies. GAO then reviewed agencies' CIO ratings processes and assessed the risks of the 53 investments.

In April 2026, OMB announced steps to sunset the IT Dashboard and replace it with a new streamlined system but did not provide a timeframe for its release. Without addressing issues with CIO ratings, GAO said critical IT investments may not receive proper oversight and emerging risks may remain unidentified or unmanaged. GAO previously recommended that OMB improve its oversight of troubled investments identified from CIO rating data. OMB has not yet acted on this recommendation.