Fast Facts

The Federal Communications Commission's "E-rate" program funds schools' and libraries' efforts to obtain technology products and services, like broadband. In 2019, the E-rate program committed about $2.4 billion to eligible applicants.

But, the program's design allows participants to "self-certify," with insufficient FCC oversight to identify potential fraud risks. For example, an applicant could receive payments for services they've claimed to have provided, but don't have the documentation to prove it.

Our 3 recommendations could help the agency adhere to GAO's Fraud Risk Framework as it implements plans to address fraud risks in the program.

FCC Headquarters

Skip to Highlights
Highlights

What GAO Found

Since 1998, the Federal Communications Commission's (FCC) E-rate program has been a significant source of technology funding for schools and libraries (applicants) to obtain affordable broadband and telecommunications services. Other program participants include service providers and E-rate consultants that assist applicants and service providers with the application and funding processes. GAO identified several key fraud risks affecting the E-rate program, as shown below, including a reliance on self-certification statements. This inherent overarching key fraud risk presents opportunities for participants to misrepresent dozens of self-certification statements on various FCC forms.

Key Fraud Risks in the E-rate Program

Key Fraud Risks in the E-rate Program

FCC and the Universal Service Administrative Company (USAC) that administers the E-rate program have not yet implemented plans to comprehensively assess fraud risks, as called for in GAO's Fraud Risk Framework. Leading practices include tailoring fraud risk assessments to the program and examining the suitability of existing controls. FCC and USAC have established time frames for comprehensively assessing the E-rate program's fraud risks by the end of 2021. However, past fraud risk management initiatives have been delayed. Ensuring that such an assessment is completed as scheduled could help ensure FCC and USAC are prioritizing key fraud risks that persist in the E-rate program, and provide greater assurance that control activities are efficiently and effectively addressing the most significant fraud risks.

FCC and USAC face challenges in effectively employing data analytics to support future fraud risk management activities. For example, officials said that they are or will be using data analytics for fraud risk management, but have not implemented leading practices for data-analytics activities nor documented their efforts or plans for doing so. GAO's Fraud Risk Framework calls for agencies to design and implement control activities, including data-analytics activities, to prevent and detect fraud. Having FCC and USAC implement leading practices for data analytics and document how data-analytics activities will be used in antifraud strategies could position the agency to better prevent, detect, and respond to fraud in the E-rate program.

Why GAO Did This Study

In 2017, the FCC's Office of Inspector General (OIG) reported that FCC's ability to deter and detect alleged E-rate program fraud has been severely limited since the program's inception due to a lack of certain controls. Also, as recently as February 2020, a number of E-rate program participants pled guilty to defrauding the program by billing for equipment and services that were not provided, and obtaining more than $2.6 million in program funds to which they were not entitled.

GAO was asked to review fraud risk management in the E-rate program. This report addresses: (1) the E-rate program's key fraud risks; (2) the extent to which FCC and USAC are managing fraud risks in accordance with leading practices; and (3) the extent to which FCC and USAC face challenges in effectively employing data analytics to support fraud risk management activities. GAO reviewed cases of fraud, OIG reports, and risk assessments, among other things. GAO assessed FCC's and USAC's procedures against leading practices in the Fraud Risk Framework. GAO interviewed FCC and USAC officials responsible for the E-rate program and fraud risk management.

Skip to Recommendations

Recommendations

GAO makes three recommendations, including that FCC and USAC comprehensively assess fraud risks to the E-rate program and follow leading practices when designing and implementing data analytics to prevent and detect fraud. FCC agreed with the recommendations and outlined actions to address them.

Recommendations for Executive Action

Agency Affected Recommendation Status
Federal Communications Commission The Chairman of FCC should direct and coordinate with the Chief Executive Officer of USAC to comprehensively assess fraud risks to the E-rate program, including implementing their respective plans for developing periodic fraud risk assessments, examining the suitability of existing fraud controls, and compiling fraud risk profiles following the timelines described in this report. The assessments should be informed by the key fraud risks identified in this report from closed court cases, prior risk assessments, and OIG reports, among other sources. (Recommendation 1)
Open
FCC agreed with this recommendation. According to FCC officials, as of February 2021, FCC has implemented a comprehensive fraud risk management strategy, which includes an annual risk assessment of the E-rate program. As of August 2021, FCC has not yet provided supporting documentation that this strategy has been implemented and that it has comprehensively assessed fraud risks to the E-rate program as we recommended. We will continue to monitor FCC's progress in this area.
Federal Communications Commission The Chairman of FCC should ensure that FCC and USAC follow the leading practices in GAO's Fraud Risk Framework when designing and implementing data-analytics activities to prevent and detect fraud as part of their respective antifraud strategies for the E-rate program. (Recommendation 2)
Open
FCC agreed with this recommendation. According to FCC officials, as of February 2021, FCC has been working collaboratively with USAC to incorporate the use of data-analytics activities in FCC's fraud risk management plans and also coordinating on USAC's implementation of its framework to use data analytics to combat future fraud risks in the E-Rate program. As of August 2021, FCC has not yet provided supporting documentation that its fraud risk management plans and USAC's framework for using data analytics address our recommendation. We will continue to monitor FCC's progress in this area.
Federal Communications Commission The Chairman of FCC should direct the Chief Executive Officer of USAC to clearly define and fully document the data fields in all relevant E-rate program computer systems to help improve FCC's ability to understand and use data to manage fraud risks. (Recommendation 3)
Open
FCC agreed with this recommendation. According to FCC officials, as of February 2021, USAC has notified FCC that it has begun to update its data dictionaries across all data fields in the E-rate program. As of August 2021, FCC has not yet provided supporting documentation that USAC's data dictionaries have been updated to address our recommendation. We will continue to monitor FCC's progress in this area.

Full Report

GAO Contacts