US Federal News Bureau
Written by: Tathagata Sen
Updated 1:47 AM EDT, October 8, 2026

The Government Accountability Office (GAO) found that federal agencies did not always accurately or promptly rate the risks of major IT investments, according to an October 7 report.
Meritalk reported that GAO’s review found agency chief information officers (CIOs) frequently underestimated investment risks.
GAO compared CIO risk ratings with its own assessments of 53 major IT investments across 12 agencies. Its assessment identified more risk than the CIO rating in 24 cases, matched the rating in 27 and identified less risk in two.
GAO attributed some differences to outdated ratings and lengthy assessment processes.
GAO found that 21 of the 53 CIO ratings had not been updated on time under the agencies’ own processes. Two agencies also had rating processes that lasted longer than a quarter, contrary to Office of Management and Budget (OMB) guidance.
The findings show how the quality and timeliness of management data can affect technology oversight. When risk ratings do not reflect current conditions, high-risk investments may receive less scrutiny than they require.
For chief data officers (CDOs), risk assessments are themselves management data that require defined processes for collection, validation and updating. This makes data quality relevant even when the information is used primarily for portfolio and investment decisions.
The findings come as OMB moves to replace the Federal IT Dashboard with a streamlined system. GAO said agencies need to address the quality and frequency of their risk ratings as the dashboard is replaced so the new system can support accurate oversight.
GAO issued 17 recommendations to nine agencies to improve the quality and timeliness of CIO risk ratings. The recommendations reinforce a broader data-management principle: management decisions depend on information that is current, consistent and reliable.