The Transportation
Security Administration runs background checks on card applicants to ensure
that they do not pose a threat to port facilities. About two million people had
a TWIC card as of June 2025, authorizing them to enter port facilities without
an escort. The U.S. Coast Guard
inspects TWIC cards at port facilities to help prevent unauthorized access. But
GAO has found a risk of people with revoked TWIC cards entering the facilities.
TSA has taken some
steps to communicate Transportation Worker Identification Credential (TWIC)
program information with stakeholders. However, TSA relies on an ad hoc
communication approach rather than a documented communication plan to determine
how to share information with stakeholders. This has contributed to some
stakeholders reporting that they experienced declining engagement with and
delays receiving key program updates from TSA. Developing and implementing a
communication plan could help TSA ensure that all stakeholders receive the
information necessary to effectively operate the TWIC program and reduce
security risks. The Coast Guard
does not share or analyze all of the data it collects during inspections to
oversee how facility operators implement the TWIC program. For example, the
Coast Guard collects data on deficiencies, a less severe form of noncompliance,
and violations, a more severe form of noncompliance that can result in notices
of violation or civil penalties. GAO’s assessment of inspection findings for
fiscal years 2019 through 2024 showed:
888 TWIC-related deficiencies, such as operators not ensuring that
facility personnel with security duties were qualified to perform their roles,
and 83 TWIC violations, such as
unescorted individuals entering a secure area, highlighting areas that may
warrant improvement. However, the Coast Guard does not provide
the data to TWIC inspectors. According to officials, this is because the data
did not relate to areas that would require a change to the program. However, by
communicating the data with inspectors, regardless of their effect on the
program, the Coast Guard could improve inspectors’ awareness of TWIC-related
risks. Total Number of Transportation
Worker Identification Credential (TWIC®)-related Deficiencies and Violations,
Fiscal Years 2019–2024 Total Number of Transportation Worker Identification
Credential (TWIC®)-related Deficiencies and Violations, Fiscal Years 2019–2024 The TWIC program aims to provide a
tamper-resistant biometric card to maritime workers who require unescorted
access to designated secure areas of facilities and vessels under Maritime
Transportation Security Act of 2002 regulations. As of August 2025, more than 2
million individuals held a TWIC credential.
TSA oversees TWIC
applicants’ enrollment and background checks. The Coast Guard enforces certain
TWIC regulatory requirements, including by inspecting facilities for
compliance. The Transportation
Security Screening Modernization Act of 2024 includes a provision for us to
review TSA’s security threat assessment programs and we were asked to review
other aspects of TWIC operations. This report examines (1) the extent to which
TSA communicates TWIC program information to stakeholders, and (2) the extent
to which the Coast Guard has overseen the implementation of the TWIC program by
facility operators, among other objectives. GAO also examined TSA and Coast Guard
policy and data for fiscal years 2019 through 2024. In addition, GAO
interviewed agency officials and port stakeholders. To obtain a range of TWIC
perspectives, these stakeholders included TWIC operators at facilities selected
in part for diversity in size and geographic regions. GAO is making seven
recommendations, including that the TSA Administrator implement a plan to
communicate TWIC information to stakeholders and that the Coast Guard
communicate TWIC-related violation and deficiency data with inspectors. The
Department of Homeland Security concurred with these recommendations. Transportation Security Administration: The
TSA Administrator should develop and implement a communication plan to
systematically relay TWIC program updates to stakeholders. United States Coast Guard The Commandant of
the Coast Guard should communicate TWIC-related violation and deficiency data
with inspectors in the field who enforce TWIC requirements. actions the agency
has taken in response to this recommendation, we will provide updated
information. United States Coast Guard
The Commandant of the Coast Guard should include deficiency data in its
TWICperformance measure reporting. United
States Coast Guard The Commandant of the Coast Guard should develop a method to
mitigate the risks of unauthorized individuals with TWIC cards on the Canceled
Card List accessing secure areas of MTSA-regulated facilities. United States Coast Guard: The Commandant of
the Coast Guard should coordinate with TSA, through DHS, to acquire TWIC reader
devices for use during inspections. Transportation
Security Administration: The TSA Administrator should coordinate with the Coast
Guard, through DHS, to acquire TWIC readers for use during inspections, as
appropriate. And United States Coast
Guard The Commandant of the Coast Guard should develop and implement a plan on
how it will issue final regulations to specify which facilities must have TWIC
card readers.