Telecommunications: FCC Should Take Action to Better Manage Persistent Fraud Risks in the Schools and Libraries Program
Fast Facts
The Federal Communications Commission's "E-rate" program funds schools' and libraries' efforts to obtain technology products and services, like broadband. In 2019, the E-rate program committed about $2.4 billion to eligible applicants.
But, the program's design allows participants to "self-certify," with insufficient FCC oversight to identify potential fraud risks. For example, an applicant could receive payments for services they've claimed to have provided, but don't have the documentation to prove it.
Our 3 recommendations could help the agency adhere to GAO's Fraud Risk Framework as it implements plans to address fraud risks in the program.
Highlights
What GAO Found
Since 1998, the Federal Communications Commission's (FCC) E-rate program has been a significant source of technology funding for schools and libraries (applicants) to obtain affordable broadband and telecommunications services. Other program participants include service providers and E-rate consultants that assist applicants and service providers with the application and funding processes. GAO identified several key fraud risks affecting the E-rate program, as shown below, including a reliance on self-certification statements. This inherent overarching key fraud risk presents opportunities for participants to misrepresent dozens of self-certification statements on various FCC forms.
Key Fraud Risks in the E-rate Program
FCC and the Universal Service Administrative Company (USAC) that administers the E-rate program have not yet implemented plans to comprehensively assess fraud risks, as called for in GAO's Fraud Risk Framework. Leading practices include tailoring fraud risk assessments to the program and examining the suitability of existing controls. FCC and USAC have established time frames for comprehensively assessing the E-rate program's fraud risks by the end of 2021. However, past fraud risk management initiatives have been delayed. Ensuring that such an assessment is completed as scheduled could help ensure FCC and USAC are prioritizing key fraud risks that persist in the E-rate program, and provide greater assurance that control activities are efficiently and effectively addressing the most significant fraud risks.
FCC and USAC face challenges in effectively employing data analytics to support future fraud risk management activities. For example, officials said that they are or will be using data analytics for fraud risk management, but have not implemented leading practices for data-analytics activities nor documented their efforts or plans for doing so. GAO's Fraud Risk Framework calls for agencies to design and implement control activities, including data-analytics activities, to prevent and detect fraud. Having FCC and USAC implement leading practices for data analytics and document how data-analytics activities will be used in antifraud strategies could position the agency to better prevent, detect, and respond to fraud in the E-rate program.
Why GAO Did This Study
In 2017, the FCC's Office of Inspector General (OIG) reported that FCC's ability to deter and detect alleged E-rate program fraud has been severely limited since the program's inception due to a lack of certain controls. Also, as recently as February 2020, a number of E-rate program participants pled guilty to defrauding the program by billing for equipment and services that were not provided, and obtaining more than $2.6 million in program funds to which they were not entitled.
GAO was asked to review fraud risk management in the E-rate program. This report addresses: (1) the E-rate program's key fraud risks; (2) the extent to which FCC and USAC are managing fraud risks in accordance with leading practices; and (3) the extent to which FCC and USAC face challenges in effectively employing data analytics to support fraud risk management activities. GAO reviewed cases of fraud, OIG reports, and risk assessments, among other things. GAO assessed FCC's and USAC's procedures against leading practices in the Fraud Risk Framework. GAO interviewed FCC and USAC officials responsible for the E-rate program and fraud risk management.
Recommendations
GAO makes three recommendations, including that FCC and USAC comprehensively assess fraud risks to the E-rate program and follow leading practices when designing and implementing data analytics to prevent and detect fraud. FCC agreed with the recommendations and outlined actions to address them.
Recommendations for Executive Action
Agency Affected | Recommendation | Status |
---|---|---|
Federal Communications Commission | The Chairman of FCC should direct and coordinate with the Chief Executive Officer of USAC to comprehensively assess fraud risks to the E-rate program, including implementing their respective plans for developing periodic fraud risk assessments, examining the suitability of existing fraud controls, and compiling fraud risk profiles following the timelines described in this report. The assessments should be informed by the key fraud risks identified in this report from closed court cases, prior risk assessments, and OIG reports, among other sources. (Recommendation 1) |
As of January 2024, based on supporting documentation provided, we determined that FCC's and USAC's efforts address our recommendation to comprehensively assess fraud risks to the E-rate program and plan for periodic fraud risk assessments. In October 2023, FCC provided a fraud risk assessment report of the E-rate program. This report comprehensively identified and assessed E-rate fraud risks that included those we identified, examined the suitability of USAC's existing mitigating controls, and compiled fraud risk profiles for each of the identified fraud risks. In January 2024, FCC provided USAC's policy for conducting periodic and ad hoc fraud risk assessment refreshes. By taking these steps, FCC and USAC are in a better position to help ensure that their key oversight efforts and antifraud controls are targeted at areas at greatest risk for fraud in the E-rate program and help safeguard and allocate program resources to legitimate recipients.
|
Federal Communications Commission | The Chairman of FCC should ensure that FCC and USAC follow the leading practices in GAO's Fraud Risk Framework when designing and implementing data-analytics activities to prevent and detect fraud as part of their respective antifraud strategies for the E-rate program. (Recommendation 2) |
As of October 2023, FCC provided documentation to demonstrate that it and USAC have designed and operationalized procedures for periodically using a variety of data analytical tools to identify fraud risks as part of their antifraud strategies for the E-rate program. By taking these steps, FCC's and USAC's fraud risk managers are in a better position to prevent, detect, and respond to fraud risks in the E-rate program, which can contribute to the program's overall antifraud strategies.
|
Federal Communications Commission | The Chairman of FCC should direct the Chief Executive Officer of USAC to clearly define and fully document the data fields in all relevant E-rate program computer systems to help improve FCC's ability to understand and use data to manage fraud risks. (Recommendation 3) |
FCC agreed with this recommendation. From April 2022 through April 2023, FCC provided documentation in support of this recommendation, including three USAC data dictionaries. Based on our review and assessment of this documentation and additional information that FCC provided during this period, USAC clearly and comprehensively defined all key data fields for application, competitive bidding, and invoice data maintained in USAC's E-rate systems. By taking these steps, FCC and USAC are better positioned to more effectively and efficiently understand and analyze key program data for the purpose of managing fraud risks within the E-rate program.
|