Skip to main content

IT Dashboard: Selected Agencies’ Investment Ratings Fail to Fully Consider Risks

GAO-27-108416 Published: Oct 07, 2026. Publicly Released: Oct 07, 2026.
Jump To:

Fast Facts

The federal government spends over $100 billion annually on IT investments. The Federal IT Dashboard is a public website that provides information about these investments, including risk ratings—e.g., how likely it is that the investment will accomplish its goals.

We reviewed some of the investments on this dashboard and found that their risk ratings weren't always accurate. This is due, in part, to agencies not regularly updating these ratings.

Without timely and accurate ratings, high-risk IT investments may not receive proper oversight, leaving the government vulnerable to costly project failures.

Our recommendations address this issue.

The Federal IT Dashboard

A computer showing the ITdashboard.gov website

A computer showing the ITdashboard.gov website

Skip to Highlights

Highlights

What GAO Found

The Federal Information Technology (IT) Dashboard is intended to show the level of risk for an investment. The Dashboard reflects Chief Information Officers’ (CIO) ratings of risk. Selected agencies that GAO reviewed used different processes to develop their ratings. Most of these processes included some, if not all, of six factors that the Office of Management and Budget (OMB) suggested.

GAO’s assessments generally identified the presence of more risk compared to the associated CIO ratings. GAO determined its assessments based on investment risk documentation. Of the 53 investments assessed, GAO’s assessments matched the CIO ratings 27 times, showed more risk 24 times, and showed less risk two times (see graphic).

Comparison of Selected Investment’s Chief Information Officer Ratings to GAO Assessments

Comparison of Selected Investment’s Chief Information Officer Ratings to GAO Assessments

Two issues contributed to the differences between GAO and CIO ratings. Specifically, 21 of the 53 CIO ratings were not updated in a timely manner according to agencies’ processes. In addition, two agencies’ rating processes span longer than quarterly, contrary to OMB’s guidance.

In April 2026, OMB announced that it was taking steps to sunset the Dashboard and replace it with a new streamlined system but did not provide a timeframe for its release. In the interim, it is critical that selected agencies address issues with their CIO ratings. Without doing so, critical IT investments may not receive proper oversight, and emerging risks may remain unidentified or unmanaged. For example, a system modernization effort that falls behind schedule but continues to display an outdated “low‑risk” rating might not get the scrutiny it needs and fall further behind schedule.

GAO previously recommended that OMB improve its oversight of troubled investments identified from CIO rating data; however, OMB has not yet acted on this recommendation. As a result, agencies and OMB may be unable to identify emerging risks in time, potentially allowing underperforming investments to proceed without needed intervention and increase the risk of higher costs. As OMB transitions to a new system, it is imperative that agencies address issues with the quality and frequency of CIO ratings. This is critical to ensuring that the new system strengthens the monitoring of IT investment risk.

Why GAO Did This Study

The federal government spends over $100 billion annually on IT and cyber investments, but many projects fail, facing cost overruns and delays. In 2009, OMB launched the IT Dashboard to provide transparency on IT investments. OMB sets Dashboard policies and the General Services Administration operates the Dashboard.

GAO was asked to review the CIO ratings on the IT Dashboard. This report describes agencies’ processes for determining the CIO risk ratings for major IT investments, assesses the risks of federal IT investments, and analyzes any differences with the investments’ CIO risk ratings, among other things.

GAO reviewed 26 agencies’ fiscal year 2025 budget data reported to OMB to identify major IT investments of $35 million or more of development activities; this resulted in 53 selected investments at 12 agencies. GAO then reviewed agencies’ CIO ratings processes, assessed the risks of the 53 investments, and compared GAO’s assessments to the CIO ratings.

Recommendations

GAO is making 17 recommendations to nine agencies to improve the quality and frequency of CIO ratings. Five agencies agreed with the recommendations, one agency agreed with one recommendation and disagreed with the other, two agencies disagreed, and one agency did not state whether it agreed or disagreed. OMB did not provide comments. GAO maintains that its recommendations are warranted.

Recommendations for Executive Action

Agency Affected Recommendation Status
Department of Commerce The Secretary of Commerce should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 1)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Commerce The Secretary of Commerce should direct the department CIO to update their ratings in a timely manner consistent with their processes. (Recommendation 2)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Defense The Secretary of Defense should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 3)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Education The Secretary of Education should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 4)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Education The Secretary of Education should direct the department CIO to update their ratings in a timely manner consistent with their processes. (Recommendation 5)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Education The Secretary of Education should direct the department CIO to update their policies and procedures for their ratings to be reported at least as frequently as required in OMB's guidance. (Recommendation 6)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of Health and Human Services should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 7)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of Health and Human Services should direct the department CIO to update their ratings in a timely manner consistent with their processes. (Recommendation 8)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Health and Human Services The Secretary of Health and Human Services should direct the department CIO to update their policies and procedures for their ratings to be reported at least as frequently as required in OMB's guidance. (Recommendation 9)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Homeland Security The Secretary of Homeland Security should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 10)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Homeland Security The Secretary of Homeland Security should direct the department CIO to update their ratings in a timely manner consistent with their processes. (Recommendation 11)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Transportation The Secretary of Transportation should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 12)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Transportation The Secretary of Transportation should direct the department CIO to update their ratings in a timely manner consistent with their processes. (Recommendation 13)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of the Treasury The Secretary of the Treasury should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 14)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Department of Veterans Affairs The Secretary of Veterans Affairs should direct the department CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 15)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
General Services Administration The Administrator of General Services should direct the GSA CIO to ensure, for any investment we identified with more risk, that their rating accurately reflects the ability of the investment to accomplish its goals. (Recommendation 16)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
General Services Administration The Administrator of General Services should direct the GSA CIO to update their ratings in a timely manner consistent with their processes. (Recommendation 17)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.

Full Report

GAO Contacts

Media Inquiries

Sarah Kaczmarek
Managing Director
Office of Public Affairs

Public Inquiries

Topics

Chief information officersIT investment managementIT investmentsCompliance oversightInformation technologyHomeland securityContract performanceInvestment portfolioVeterans affairsAgency evaluations