Advertisement

CIOs often underestimated investment risks on IT dashboard, GAO says

The watchdog audited the process agency IT officials use to assess the risk of technology investments — though the IT dashboard where the information is posted is sunsetting.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
(Getty Images)

Chief information officers frequently underestimated risk in IT investments, according to a Government Accountability Office audit of the now-sunsetted federal dashboard that compiled those ratings.

To provide more transparency around the federal government’s roughly $100 billion annual spend on IT and cyber investments, the Office of Management and Budget in 2009 launched ITdashboard.gov. 

The website provided several details on hundreds of major IT investments across 26 federal agencies, including cost, schedule and performance. 

Agencies were asked to provide risk ratings determined by their CIOs, which the GAO said “should reflect the level of risk facing an investment relative to its ability to accomplish goals.”

Advertisement

But in its assessment of 53 selected investments and the corresponding CIO ratings, the watchdog “generally identified the presence of more risk compared to” the marks provided by agency IT chiefs. 

The GAO said 27 of the 53 CIO ratings, pulled from an April 2025 sample, matched the watchdog’s own risk assessment. The GAO assessed more risk on 24 CIO ratings, however, which it attributed to two factors: slow updates and the fact that the length of some agencies’ ratings processes exceeded OMB guidance.

Aside from the dashboard’s transparency benefits, the ratings help CIOs better understand their IT portfolios, the GAO said, in addition to helping the tech leaders pinpoint investments that are due additional oversight. 

“However, selected agencies’ ratings do not consistently provide an accurate assessment of investment risk,” the report said. “When agencies understate these risks, critical federal IT investments may fail to receive appropriate management intervention, leaving the government vulnerable to costly project failures.”

The audit’s findings, made public Wednesday, come six months after then-federal CIO Greg Barbaccia announced the sunsetting of the dashboard, a move that he said would eliminate “a costly, inefficient process” and allow “agencies to focus on higher value activities.”

Advertisement

Since April, agencies have been instructed to focus on “statutorily required data,” Barbaccia said at the time, though the data is still publicly available. 

Despite the ongoing changes to how CIOs assess risk in IT investments, the GAO said it remains “imperative” that agencies resolve issues “with the quality and frequency” of the ratings. 

“This is critical to ensuring that the new system strengthens the monitoring of IT investment risk,” it added.

The GAO delivered 17 recommendations to nine agencies, covering better accuracy in risk assessments and more timely evaluations. The General Services Administration and the departments of Education, Health and Human Services, Transportation and Veterans Affairs agreed with all of the suggestions.

The Department of Homeland Security agreed with a recommendation on more timely reporting but disagreed with one to ensure “that their rating accurately reflects the ability of the investment to accomplish its goals.”

Advertisement

The departments of Commerce and Defense disagreed with GAO’s recommendations. And the Treasury Department didn’t say whether it agreed or disagreed.  

Latest Podcasts