FB pixel

Audit finds maritime TWIC program weakened by inspection, card reader gaps

Audit finds maritime TWIC program weakened by inspection, card reader gaps
 

The U.S. federal program intended to keep people who have not passed required security vetting out of secure ports and maritime facilities is being undermined by fragmented oversight, outdated inspection equipment, and years of delay in requiring biometric card readers at facilities handling dangerous cargo, according to a new Government Accountability Office (GAO) audit report.

The audit found that the Transportation Security Administration (TSA) and Coast Guard have left significant gaps in the Transportation Worker Identification Credential program (TWIC), even as more than 2 million people hold the tamper resistant biometric cards needed for unescorted access to secure areas of regulated vessels and facilities.

TSA enrolls workers, conducts fingerprint-based security threat assessments, and continuously vets cardholders for new disqualifying information.

The Coast Guard enforces the access control rules at about 3,400 facilities covered by the Maritime Transportation Security Act. GAO found, however, that TSA communicates important operational changes through an ad hoc process rather than a documented plan.

Five of six industry associations interviewed by auditors reported declining or deficient communication from TSA, while three said they had experienced delays receiving important program updates.

One association said a member learned of a 2018 card redesign only after its readers could not scan the cards. A later server address change affecting TSA’s Canceled Card List also left the Coast Guard without working readers, forcing inspectors to rely on visual checks.

The Coast Guard’s own inspection data revealed a broader compliance problem than the agency’s performance measures suggest. From fiscal years 2019 through 2024, inspectors recorded 888 TWIC-related deficiencies and 83 more serious violations.

Although TWIC requirements accounted for only nine of the Coast Guard’s 179 facility inspection points, they represented 38 percent of all facility inspection violations during the six-year period.

Forty-four percent of the TWIC violations involved unescorted people entering secure areas without a credential or escort.

Among the less severe deficiencies, the largest category involved facilities failing to ensure that personnel assigned security duties were qualified to perform them.

Another major category involved failures to prevent uncredentialed, unescorted access.

Yet, the Coast Guard does not routinely provide either the violation or deficiency data to field inspectors. It also bases its reported 99 percent TWIC compliance rate on facilities that avoided formal notices of violation or civil penalties, excluding the far larger number of deficiencies.

GAO said that practice gives the agency an incomplete picture of security risks and enforcement performance.

The audit also identified a more direct weakness. Only facilities currently required to use biometric readers – principally cruise terminals receiving vessels certified to carry more than 1,000 passengers – must check TSA’s Canceled Card List.

Other facilities can consult a public spreadsheet or use a mobile application, but are not required to do so.

Port representatives told GAO that manual spreadsheet checks are impractical and prone to error. None of the officials from the ten Area Maritime Security Committees interviewed by GAO reported using TSA’s mobile application.

In one case described to auditors, a worker whose credential had been canceled used his father’s TWIC card to enter a facility that lacked a reader.

The agencies have compounded that exposure by separately pursuing replacement inspection devices.

The Coast Guard terminated its reader contract in September 2024 after a server change rendered the devices obsolete. A subsequent $1.4 million contract for 250 readers was terminated following a bid protest and lapse in appropriations.

TSA, meanwhile, uses a smartphone attachment that is incompatible with newer government issued phones. Both agencies acknowledged that a coordinated purchase could reduce contracting work and per unit costs.

The larger reader mandate remains unresolved nearly two decades after the 2006 SAFE Port Act directed the Department of Homeland Security (DHS) to implement it.

Facilities handling certain dangerous cargoes, including chemicals and liquefied natural gas, are not scheduled to face reader requirements until May 2029.

The Coast Guard is reconsidering which facilities should be covered but has no detailed plan or timetable for completing the rule.

GAO issued seven recommendations, including calls for TSA to adopt a formal stakeholder communication plan and for the Coast Guard to share inspection data, include deficiencies in its performance measures, address canceled card access risks, and develop a plan for final reader regulations.

It also urged TSA and Coast Guard to coordinate their reader acquisitions through DHS.

DHS agreed with all seven recommendations.

Related Posts

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Digital and trust infrastructure investments unlock value of identity

As the role of digital identity in society evolves and biometrics increasingly form the foundation of trust in remote interactions,…

 

Listen: How age assurance platforms earn trust

The world has more or less decided that some online services should be age-restricted. The question now is, how to…

 

Sri Lanka sets Q4 target for SL-UDI rollout

Sri Lanka is preparing to issue its first production digital identities next quarter, beginning a phased rollout of the country’s…

 

Madagascar strengthens trust architecture for national digital ID

Madagascar is strengthening the legal, institutional and technical foundations of its national digital identity program, introducing new cybercrime legislation as…

 

Cybastion backs Cameroon digital sovereignty with $75M infrastructure project

Cybastion has committed $75 million to fund the construction of digital infrastructure in Cameroon, including a data center and an…

 

Co-Develop, Caribou outline governance blueprint for DPI adoption

Digital public infrastructure (DPI) programs have grown to include more than 100 countries globally. Recognizing this expansion, Co-Develop and Caribou…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events