Breadcrumb

Audit of Program Management for the Benefits Enterprise Platform Modernization

Report Information

Issue Date
Report Number
25-01098-103
VA Office
Information and Technology (OIT)
Report Author
Office of Audits and Evaluations
Report Type
Audit
Report Topic
Information Technology and Security
Major Management Challenges
Information Systems and Innovation
Recommendations
5
Questioned Costs
$0
Better Use of Funds
$0
Congressionally Mandated
No

Summary

Summary

The VA Office of Inspector General (OIG) conducted this audit to assess the Office of Information and Technology’s (OIT) program management of the Benefits Enterprise Platform (BEP) modernization. BEP is a mission critical system supporting veterans’ benefits processing. It was identified as one of 85 legacy systems that needed to be modernized or decommissioned to improve overall claims processing efficiency. The audit evaluated whether the planning and execution of the BEP modernization aligned with federal standards, VA policy, and legislation. 

The OIG found that the modernization effort was at risk of delays, cost increases, and security vulnerabilities due to insufficient oversight and weak program management. Specifically, the OIG found that OIT lacked a comprehensive, reliable program schedule as recommended by the Government Accountability Office's Schedule Assessment Guide. Instead, OIT relied on an agile tool that planned work only in three-month increments and lacked full project roadmaps. This limited visibility raises the risk that VBA will face delays or fail to complete modernization efforts successfully.

The OIG also found that OIT did not produce a reliable life cycle cost estimate as required by Office of Management and Budget Circulars A-130 and A-11. Costs were not fully reported in VA’s Product (Line) Accountability and Reporting System, and expenditures from the Cost of War Toxic Exposures Fund were not tracked in the required dashboard. Cost information across various BEP plans was inconsistent, limiting VA’s ability to make informed decisions.

Finally, OIT hosted minor applications without required security assessments, potentially exposing veterans’ sensitive information. The OIG briefed OIT leaders on early findings, including security weaknesses. VA subsequently assessed and resolved vulnerabilities in minor applications hosted on its network. To address broader issues in scheduling, cost estimation, and security practices, the OIG issued five recommendations. VA concurred or concurred in principle with all recommendations.

Open Recommendation Image, SquareOpenClosed and Implemented Recommendation Image, CheckmarkClosed-ImplementedNot Implemented Recommendation Image, X character'Closed-Not Implemented
No. 1
Open Recommendation Image, Square
to Information and Technology (OIT)

Develop and maintain a Benefits Enterprise Platform modernization program schedule that (1) captures both agile and nonagile tasks and (2) documents the time frame for the delivery of all system modernization requirements.

No. 2
Open Recommendation Image, Square
to Information and Technology (OIT)

Ensure staff follow VA’s Product (Line) Accountability and Reporting System Guide to include all program schedule information in the System.

No. 3
Open Recommendation Image, Square
to Information and Technology (OIT)

Develop reliable, validated life cycle cost estimates for the Benefits Enterprise Platform modernization program that support planning and budgeting as required by Office of Management and Budget Circulars A-130 and A‑11.

No. 4
Open Recommendation Image, Square
to Information and Technology (OIT)

Include all Benefits Enterprise Platform modernization costs in the VA’s Product (Line) Accountability and Reporting System as required by the Veteran-Focused Integration Process Guide, and track Cost of War Toxic Exposures Fund obligations and expenditures in the Office of Information and Technology PACT Act Dashboard consistent with VA financial policy.

No. 5
Open Recommendation Image, Square
to Information and Technology (OIT)

Establish a mechanism for enforcing VA policy that requires minor applications to include an approved security assessment before being placed on VA’s network.