Skip to main content

Chief Information Officers: Private Sector Practices Can Inform Government Roles

GAO-22-104603 Published: Sep 15, 2022. Publicly Released: Sep 16, 2022.
Jump To:

Fast Facts

Most of the 71 private sector chief information officers we surveyed reported having responsibilities that align with those of agency CIOs in nearly all key IT management areas.

But, the Federal CIO position isn't established in law, resulting in its responsibilities being more limited than those of other types of CIOs. And former agency CIOs reported challenges in achieving meaningful collaboration with other executives.

Congress should consider establishing the Federal CIO position in law, and we recommended that the Office of Management and Budget make collaboration between CIOs and other executives a higher priority, among other things.

Skip to Highlights

Highlights

What GAO Found

A majority of the 71 private sector Chief Information Officer (CIO) survey respondents reported having responsibilities that aligned with those of agency CIOs in 13 of 14 key IT management areas. These areas include strategic planning, investment management, and information security. One area of responsibility (the statistical policy area) was reported by more than half of respondents as being outside their scope of responsibility. In addition, CIO respondents also reported sharing responsibility with other executives in each IT management area (see figure 1).

Figure 1: Extent of Sharing of IT Management Area Responsibilities Reported by 71 Private Sector Chief Information Officer (CIO) Respondents

Notes: Survey results are from a non-probability sample and may not generalize to all private sector CIOs.

This figure shows 16 areas because one of the 14 key responsibility areas (IT systems acquisition, development, and integration) is presented as three different items in order to provide increased visibility into these activities.

Private sector CIO respondents were highly educated and experienced, with a majority reporting previous IT-related experience, previous CIO experience, industry knowledge, and a college degree (see figure 2). Notably, a majority of respondents reported that their degrees were not IT-related. Respondents reported an average tenure in their current CIO role of about 6 years. Among respondents, CIOs with more authority over technology-related decisions tended to have a higher level of previous CIO experience, as well as the longest tenures.

Figure 2: Qualifications and Experience of Private Sector Chief Information Officer (CIO) Respondents

This graph shows selected responses from two survey questions. The variables are categorical and the numbers are not intended to add to 71 or the percentages to 100 percent.

Responsibilities currently assigned to the Federal CIO correspond to those of agency CIOs in 10 of the 14 key IT management areas. The Federal CIO's responsibilities also correspond to those of private sector survey respondents in each of five responsibility areas directly relevant to the roles of both. However, the Federal CIO position is not established in law, and its main legal authorities remain those established in 2002 for the OMB position from which the role was established. As such, its responsibilities are often more limited in key CIO management areas than those of the other types of CIOs. For example, the Federal CIO is not responsible for ensuring that cybersecurity duties are carried out. By formalizing the Federal CIO position and establishing responsibilities and authorities over government-wide IT management, the position's impact over federal IT may be more consistent over time and across administrations.

Private sector and former agency CIOs participating in panel discussions reported challenges faced by federal agency CIOs. Specifically, private sector CIO panelists stated that collaboration between the CIO and other senior executives is essential to driving successful business outcomes. Conversely, former federal CIO panelists reported difficulty achieving meaningful collaboration with other managers. In addition, private sector panelists stated that their companies often look for managerial skills, such as project management skills, when hiring CIOs. By contrast, former agency CIO panelists stated that technical skills are often a primary driver in the selection of agency CIOs. Fostering shared collaboration and increasing focus on managerial skillsets for agency CIOs could assist federal agencies and their CIOs in securing resources and implementing IT priorities.

Why GAO Did This Study

Over the years, Congress has enacted various laws in an attempt to improve the government's management of IT. GAO has previously reported on the challenges faced by federal agency CIOs.

GAO was asked to review the extent of alignment among the responsibilities of federal agency CIOs, their private sector counterparts, and the overall Federal CIO located in the Office of Management and Budget. This report examines (1) the responsibilities of selected CIOs in the private sector and how they compare to the responsibilities of federal agency CIOs; (2) the qualifications and tenure of selected CIOs in the private sector; (3) how the responsibilities of the Federal CIO compare with those of federal agency and private sector CIOs; and (4) how private sector CIO experiences can be applied to the challenges facing federal agency CIOs.

GAO conducted a survey of a non-generalizable sample of private sector CIOs and asked about their responsibilities, experience, and qualifications. Of 488 surveys sent, CIOs or CIO equivalents returned 71 fully complete responses. GAO then compared the results of the completed surveys to the responsibilities outlined in laws and Office of Management and Budget guidance for agency CIOs and the Federal CIO.

GAO also held two expert panels with both private sector CIOs and former federal agency CIOs. Both panels addressed their experiences with qualifications, tenure, reporting relationships, and challenges. After holding the panels, GAO analyzed the main points made by the panelists and developed resulting common themes from the discussions.

Recommendations

GAO is recommending that Congress consider formalizing the Federal CIO position and establishing responsibilities and authorities for government-wide IT management.

GAO is making two recommendations to the Director of the Office of Management and Budget to increase emphasis on collaboration between CIOs and other executives, and to take steps to ensure that managerial skills have an appropriate role in CIO hiring criteria. Staff from the Office of Management and Budget did not agree or disagree with GAO's recommendations.

Matter for Congressional Consideration

Matter Status Comments
Congress should consider formalizing the Federal CIO position and establishing responsibilities and authorities for government-wide IT management. (Matter for Consideration 1)
Open
In July 2023, the House and Senate introduced identical bills that would, among other things, change the title of the Administrator of the Office of Electronic Government to the Federal Chief Information Officer (H.R. 4552 and S. 2251). The bills did not establish responsibilities and authorities for the role. As of March 2024, the bills have yet to be passed and enacted into law. We will continue to monitor the implementation of this recommendation.

Recommendations for Executive Action

Agency Affected Sort descending Recommendation Status
Office of Management and Budget The Director of OMB should direct the Federal CIO to increase emphasis placed on shared collaboration between agency CIOs and other senior executives to accomplish agency-wide and government-wide goals. (Recommendation 1)
Open
OMB did not agree or disagree with our recommendation. In a March 2024 update, OMB stated that it has actions planned to address this recommendation. We will continue to monitor the implementation of this recommendation.
Office of Management and Budget The Director of OMB should direct the Federal CIO to take steps to ensure that managerial skills, such as communication and program management skills, have an appropriate role in the hiring criteria for agency CIOs. (Recommendation 2)
Open
OMB did not agree or disagree with our recommendation. In a March 2024 update, OMB stated that it has actions planned to address this recommendation. We will continue to monitor the implementation of this recommendation.

Full Report

GAO Contacts

Office of Public Affairs

Topics

Chief information officersE-governmentInformation securityInformation technologyIT investmentsIT managementPrivate sectorPaperwork reductionCompliance oversightFederal agencies