On Wednesday the Government Accountability Office reported that the federal government’s public gauge of IT project risk understates trouble on nearly half the projects it checked. By the time of writing, the Office of Management and Budget, which owns that gauge, had offered no public reply. The silence is at least consistent. According to GAO’s report, OMB did not answer the auditors’ questions, did not comment on the draft, and is in the middle of retiring the very website under examination.
A Thermometer That Flatters the Patient
Since 2009 the IT Dashboard has shown how risky the government’s biggest technology projects are, as judged by each agency’s Chief Information Officer on a five-point scale. Congress wrote the idea into law in 2014, and the Federal Information Technology Acquisition Reform Act (FITARA) now requires public information on major investments and risk categories assigned by CIOs.
GAO tested the scale. It took 53 investments at 12 agencies, each planning at least $35 million in development spending, and scored their risks from the agencies’ own risk registers. Its scores matched the CIO rating 27 times, showed more risk 24 times, and showed less risk twice. Five investments that GAO put at “high” risk had been rated medium or lower by their own agencies. They include two Transportation systems (Automatic Dependent Surveillance-Broadcast and the Enterprise Information Display System), a Treasury case management system, the Veterans Affairs Health Management Platform, and Login.gov, which the General Services Administration rated medium.
Fairness requires some caveats, and GAO supplies them. Risk assessment involves judgment, agencies such as VA, Homeland Security and Treasury say they weigh more than a risk register, and GAO describes its method as a standardized yardstick rather than a prescription. The ratings date from April 2025, and 53 investments are a sample of the roughly 600 on the Dashboard. The picture is also better than in 2016, when GAO found 60 of 95 investments understated. Nobody should say that half of federal IT is secretly on fire. It is fair to say the gauge cannot be trusted to tell them.
The Veterans Affairs Perfect Record
VA is the only agency with more than one investment in the sample where GAO matched none. All six were understated. Four carried a rating of “low,” the safest on the scale (Benefits Appeals, Benefits Payment, Veterans Benefits Management and Enterprise Data Services). GAO scored Benefits Payment moderately high and the other three medium. The Health Management Platform, rated moderately low, drew a high.
This is a tradition. In its 2013 review of 80 investments at eight agencies, GAO found VA the worst offender, and Nextgov reported that none of the ten VA investments examined was being reported properly. More recently, Bureaucracy News detailed how VA paid for yet another troubled technology effort in “Paying for Nothing: How the VA Spent $11.2 Million on Services Never Delivered.”
VA agreed with GAO’s recommendation, and its response contains a remarkable manoeuvre. It told GAO that it has restructured the six investments and redistributed their functions and associated risks across its portfolio, and that it will trace those risks to current investments, reassess the ratings and update its procedures by Dec. 31, 2026. A rating cannot be wrong about a project that no longer exists in its original form, which is accountability with a certain elegance. Whether the restructuring moved the risk or only the label is a question the report does not settle.
The Calendar as Alibi
Even a sound rating is useless if it is stale. GAO found that 21 of the 53 ratings were not updated on the schedule the agencies’ own procedures prescribe, including all nine at Health and Human Services, all five at Commerce and all four at Homeland Security. HHS told GAO that a reduction in force in April 2025 had struck the team responsible for the ratings in the middle of an update, which makes this a rare staffing story in which the casualty is a gauge.
Some agencies are slow by design. Education reviews its investments twice a year, matching its annual portfolio submission, and HHS lets certain components, the Centers for Disease Control and Prevention among them, report only semiannually. OMB’s August 2025 guidance requires quarterly updates. This matters because FITARA requires a review when an investment has been rated high risk for four consecutive quarters. My inference, resting on GAO’s remark that agencies must follow OMB’s cadence to align with FITARA’s requirements, is that a rating refreshed twice a year cannot show four consecutive quarters of anything, so the trigger may never fire. Both agencies concurred with GAO, and HHS expects to finish revising its procedures by the second quarter of 2027.
Unplugging the Witness
The Dashboard’s homepage now carries an open letter from Federal CIO Greg Barbaccia, who says the site “does not fully deliver on that promise” of transparency and announces steps to sunset it and refocus on statutorily required data. No timeline accompanies the letter. Federal News Network reported that a former OMB analyst, Kristine Lam, called the data manually self-reported and often dated by the time it was published, and that GSA’s Dashboard contract runs about $3 million a year. The Dashboard itself displays roughly $102 billion in fiscal 2025 IT spending, so by my arithmetic the upkeep is about three thousandths of one percent of what it watches.
OMB’s complaint is not frivolous, and it overlaps with GAO’s. Both agree the ratings are unreliable. They differ on the remedy, since GAO would fix the gauge and OMB would remove it. The 2016 remedies were tried. According to GAO, all 15 agencies implemented its 25 recommendations, and understatement fell from 63 percent of the sample to 45 percent (different samples, so treat the comparison as indicative). A fix that moved the needle by roughly 18 points is an odd candidate for the scrap heap.
There is also the matter of the statute. OMB says it will keep statutorily required data public, and GAO concludes that public reporting of investment risk is mandated by FITARA. My inference, resting on those two statements, is that CIO risk ratings belong in whatever replaces the Dashboard. OMB has not said whether they will, or when anything will arrive. Its record on the oversight FITARA already demands is not reassuring. In November 2024 GAO found the Federal CIO had been consulted on none of 27 high-risk reviews, and MeriTalk reported that OMB answered by saying GAO’s recommendations rested on incorrect readings of the law. GAO says that recommendation remains unaddressed.
The ratings erred in one direction, toward comfort. A government unhappy with its thermometer can calibrate it or confiscate it. So far OMB has chosen the second, without saying what it will use instead.
Sources
- GAO-27-108416 — IT Dashboard: Selected Agencies’ Investment Ratings Fail to Fully Consider Risks, Oct. 2026
- GAO-16-494 — IT Dashboard: Agencies Need to Fully Consider Risks When Rating Major Investments, 2016
- GAO-14-64 — Information Technology: Agencies Need to Strengthen Oversight of Billions of Dollars in Operations and Maintenance Investments, 2013
- GAO-25-107041 — IT Portfolio Management: OMB and Agencies Are Not Fully Addressing Selected Statutory Requirements, Nov. 2024
- Federal IT Dashboard — Open Letter from Federal CIO Greg Barbaccia, 2026
- Federal News Network — OMB to Refresh the Federal IT Dashboard, May 2026
- MeriTalk — GAO: Agencies Failing Key FITARA IT Management Requirements
- FITARA — 40 U.S.C. § 11302
