GAO Recommended Fraud Training for Pentagon IT Programs
The report identified training gaps across 18 major information technology systems managed by the Pentagon.
Updated on Oct. 1, 2026 in Financial Crime

Live Poll
Should federal agencies be required to provide standardized cybersecurity training for all staff?
The Government Accountability Office has recommended that the Pentagon implement mandatory fraud risk training for staff overseeing 18 major IT business programs. The review found that staff in seven programs were unaware of or lacked proper training to identify potential fraud within their systems.
Why it matters
Ensuring staff can identify fraud is critical to protecting $10.29 billion in planned spending across these IT programs. This oversight is particularly important given that 11 of the programs have experienced cost or schedule changes since early 2024.
The GAO recommendation targets 18 programs representing $10.29 billion in total planned spending. Currently, 12 programs are implementing zero trust architecture, while seven face schedule delays ranging from two to 12 months.
The players
Government Accountability Office
This is a non-partisan federal agency that provides auditing, evaluation, and investigative services for the United States Congress.
Pentagon
This is the headquarters of the United States Department of Defense, responsible for managing the nation's military and its associated technological infrastructure.
The details
The review highlighted that the 18 systems under investigation have an average age of 18 years, with operations and sustainment accounting for 74 percent of total planned spending. While 15 programs currently track minimum performance metrics, only five programs have utilized artificial intelligence tools for threat detection.
Timeline
Eleven programs reported cost or schedule changes starting in January 2024.
Staff in 11 programs received fraud awareness training during the past two years.
The Department of War plans to complete zero trust architecture implementation by 2027.
Legal Context
The GAO audit reinforces the federal mandate to modernize cybersecurity infrastructure via the Department of Defense's Zero Trust Strategy. This push for improved oversight follows a long-standing pattern of legislative efforts to secure aging government IT systems against internal and external threats.
The report highlights risks to billions in taxpayer-funded IT spending, signaling a shift toward more rigorous oversight of defense contractors and internal IT staff. Residents and stakeholders may see increased security mandates and procedural audits as the department works to meet its 2027 cybersecurity goals.
The takeaway
The GAO audit underscores that aging IT infrastructure requires both technical modernization and enhanced human capital training to prevent systemic financial loss. Implementing standardized fraud awareness ensures that oversight keeps pace with the technological upgrades required for modern cybersecurity.
What happens next
The Department of War is scheduled to meet its official deadline for full zero trust architecture implementation across these programs in 2027.
Further reading
For more information on systemic oversight, visit the Financial Crime section.
Source note: This article includes information reported by Executive Gov.
Live Poll
Should federal agencies be required to provide standardized cybersecurity training for all staff?










