• Increase font size
  • Default font size
  • Decrease font size
Apogee Consulting Inc

Deaf, Dumb, and Blind Auditors from GAO

E-mail Print PDF
Deaf_Dumb_BlindGAO released its long-awaited report on DoD’s management of the Contractor Business Systems (CBS) oversight process. We read it. It didn’t take very long, as there wasn’t really anything there.

You know that feeling when you have a first date with somebody you are really attracted to? You look forward to it. You think about what you will wear. You think about the best place to meet each other, one that is slightly romantic (but not too romantic—after all, it’s a first date). It can’t be too loud, because then you won’t be able to talk to each other and get to know each other, and explore that connection you feel. And then it’s time! You both get to this special place, wearing nice clothes. You sit down and look at each other ….

… and then you realize you have nothing in common. Nothing at all. All the conversational gambits fail. Questions get one-word answers. Or maybe he spends all the time looking at the game on the TV over the bar. Whatever. But after a few minutes you realize that attraction you felt has faded away and you start looking at your watch (or phone), counting the minutes until the date is over. Maybe you start texting your friend to call you with a made-up emergency, just to get out of there that much faster.

What you looked forward to has evaporated and it’s been replaced with nothing. There’s now a hole where the expectation of a potential great relationship used to be.

“Disappointment” is a word that might describe your feelings about the situation, but it’s hardly the right description. Sure, there’s disappointment. But there’s also anger as well. Anger that the opportunity was wasted. Anger that the money was wasted. Anger that the you were misled, that the attraction you felt was really a mirage.

Disappointment and anger and maybe a bit of a betrayal.

Those are our feelings about GAO’s report on Contractor Business Systems.

How did this fiasco get started?

Section 890 of the 2018 National Defense Authorization Act (NDAA), required the Comptroller General of the United States to “submit to the congressional defense committees a report evaluating the implementation and effectiveness of the program for the improvement of contractor business systems established pursuant to section 893 of the Ike Skelton National Defense Authorization Act for Fiscal Year 2011 (Public Law 111–383; 10 U.S.C. 2302 note).”

Note that key word: evaluate.

But more than that was required. Section 890 went on to say:

The report shall—

(1) describe how the requirements of such program were implemented, including the roles and responsibilities of relevant Defense Agencies and known costs to the Federal Government and covered contractors;

(2) analyze the extent to which implementation of such program has affected, if at all, covered contractor performance or the management and oversight of covered contracts of the Department of Defense;

(3) assess how the amendments to contractor business system requirements made by section 893 of the National Defense Authorization Act for Fiscal Year 2017 (Public Law 114–328; 130 Stat. 2324) were implemented, including—

(A) the effects of revising the definition of “covered contractor” in section 893(g)(2) of the Ike Skelton National Defense Authorization Act for Fiscal Year 2011 (Public Law 111–383; 10 U.S.C. 2302 note) and the feasibility and the potential effects of further increasing the percentage of the total gross revenue included in the definition; and

(B) the extent to which third-party independent auditors have conducted contractor business system assessments pursuant to section 893(c) of the Ike Skelton National Defense Authorization Act for Fiscal Year 2011 (Public Law 111–383; 10 U.S.C. 2302 note);

(4) identify any additional information or management practices that could enhance the process for assessing contractor business systems, particularly when covered contractors have multiple covered contracts with the Department of Defense; and

(5) include any other matters the Comptroller General determines to be relevant.

But more than that was required. The House language (quoted above) was modified in Committee and “the Senate recedes with an amendment that would expand the review to evaluate overall implementation and effectiveness of the contractor business system program…” (Emphasis added.)

Again, we note the key word: evaluate.

Evaluate the effectiveness.

Thus, the Comptroller General and GAO had a clear mandate and the topics to be covered were clearly stated. Too bad the Comptroller General and GAO ignored their mandate and ignored the topics to be covered, and issued a nothing burger of a report.

Let’s be clear that auditors from GAO made token efforts to try to hit the marks established by the NDAA. They met with individual contractors and they met with industry associations. Those people interviewed by GAO were led to believe that their inputs were valued, that they would be considered in the final report. Contractors gave their time and taxpayers paid for that time, just like taxpayers paid for GAO auditors to travel to those contractor sites to obtain the valuable insight from the contractors. And it was going to be used in the report and that report was going to pull the curtain away from the utter nonsense that is the Contractor Business System oversight regime.

Yeah, about that. Not so much.

Report findings:

  • DOD does not have a mechanism to monitor and ensure that these reviews are being conducted in a timely manner.

  • DCMA currently lacks a mechanism based on relevant and reliable information, such as the number of reviews that are outstanding and the resources available to conduct such reviews, to ensure reviews are being completed in a timely fashion.

And … that’s it.

Does that sound like GAO actually did what Congress demanded—via Public Law—that it do? No?

We didn’t think so either.

What about the table that showed actual versus planned DCAA Contractor Business System audits? You know, the one that showed less than 20 audits per year over the period GFY 2013 through GFY 2018, but then the number of planned audits suddenly increasing from low levels to more than 100 per year by GFY 2020?

(We mean, we’ve seen charts like that one before—mostly prepared by Marketing. They’re called “hockey stick” charts because they’re flat until they suddenly turn upwards at the very end of the year. That way, the Marketing folks get to keep their jobs longer, until it becomes painfully obvious they will not meet their plans.)

What did GAO say about that hockey stick DCAA audit chart? Well, on pages 22 and 23, GAO wrote about DCAA’s plans to radically amp-up its CBS audits. GAO wrote—

DCAA officials acknowledged they have not been able to conduct audits of contractor business systems within the timeframes outlined in DCMA instructions. … Recognizing that it cannot perform all of the required CBS audits in a timely fashion to meet current DCMA policy requirements, DCAA officials told us they focus their audits on business systems they identify as high-risk. … Our analysis indicates that successfully executing [DCAA’s] plan is dependent on several factors, including the ability to shift resources from conducting incurred cost audits to business systems audits, the use of public accounting firms to perform a portion of the incurred cost audits, and the ability of DCAA auditors to use new audit plans and complete the required audits in a timely manner. … DCAA plans to shift more than 378,000 hours from incurred cost audits to CBS audits between fiscal years 2018 and 2020. DCAA officials noted, however, that although they have made significant progress in addressing incurred cost audits, the fiscal year 2018 NDAA requires DCAA to have all incurred cost audits performed within 12 months. DCAA officials noted that this means it will have to continue to spend significant resources on incurred cost audits in fiscal year 2019 to meet this legislative requirement. … DCAA officials stated that these estimates include the resources that are expected to become available to perform CBS audits as DCAA starts using public accounting firms to perform incurred cost audits. …

In summary, Marketing has a plan to hit its sales goals but it’s dependent on things happening that almost certainly will not happen. Recognition of failure is thus delayed: the can is kicked into GFY 2020.

About those contractor interviews—

Our review of six selected contractors’ business system reviews illustrates the challenges in identifying and resolving deficiencies in a timely manner. Overall, our review of these six cases found that it took from 15 months to 5 years or more to resolve deficiencies initially identified by DCAA or DCMA. Factors contributing to the time it took to resolve these issues included contractors submitting inadequate corrective action plans, DCMA or DCAA identifying additional deficiencies in subsequent reviews or audits, and the use of different auditors to conduct the reviews. [But] DCMA and DCAA officials believe the cases we analyzed were not representative of the length of time needed to complete the CBS review process, but could not provide data to support their views because DCMA and DCAA do not track data on the length of time it takes to complete the entire CBS review process (i.e., from the start of an audit or review to the resolution of system deficiencies and final determination).

(Emphasis added.)

There you have it. In the time-honored tradition of government bureaucrats, contractor complaints and actual audit findings were arm-waved away as being “not representative” of the situation—even though they absolutely were representative of the situation. GAO accepted the bureaucratic rebuttal at face value, even though (as GAO noted) the bureaucrats “could not provide data to support their views.”

So much for contractor and industry association input.

Oh, there was something about the use of independent auditors and how DoD and DDP haven’t yet acted on the GFY 2017 NDAA Public Law requirements. Because there are “concerns.” Moreover—

… the Director of the Defense Acquisition Regulation Council—who is responsible for promulgating proposed and final rule changes to the DFARS— tasked her staff to draft a proposed rule by March 2017. This deadline was subsequently extended to January 23, 2019. In November 2018, Defense Pricing and Contracting (DPC) officials told us that they now expect to issue the proposed rule for public comment in the third or fourth quarter of fiscal year 2019. DPC officials attributed this delay, in part, to a recent executive order that calls for the reduction and control of regulatory costs, as well as the complexity of having public accounting firms perform CBS reviews.

Again, note that the statements were taken at face value. The nearly three-year delay in even issuing a proposed rule for public comment was explained as being President Trump’s fault. If only he hadn’t issued that pesky Executive Order, well then, of course the DAR Council would have fulfilled its role and complied with Public Law. To us, that smells very much like GAO auditors not acting with professional skepticism.

And that’s the report. All of it.

Our understanding is that a representative from GAO will be meeting with contractor industry associations to discuss the findings of this report, just as if it were an important report, with actionable findings. We hope those industry associations ask probing questions about what happened to the Congressional mandate GAO had to evaluate the effectiveness of the CBS oversight regime?

Where the heck was the evaluation of the effectiveness to be found in the report?

This report was supposed to be an important report. Just like that first date was supposed to be an important event. Things were supposed to happen, based on this report. Reforms were possible. Just like that first date was supposed to lead to a beautiful relationship.

Yet, at the end there was nothing.

Nothing of substance. Nothing of consequence.

And now we’re wondering when that “emergency” phone call is going to happen, because we want to get out of here.

 

CPSRs Get Harder

E-mail Print PDF

DFARS contract clause 252.244-7001 (“Contractor Purchasing Systems”) establishes 24 adequacy criteria. A “significant deficiency” in any one of those criteria will lead to a disapproved purchasing system and possible payment withholds. As readers may know, in 2014 the clause was revised to add adequacy criteria related to compliance with the requirements of DFARS contract clause 252.246-7007 (“Contractor Counterfeit Electronic Part Detection and Avoidance System”) (CEPDAS). We wrote about the new criteria (with a certain air of smugness, since we had predicted the increased emphasis on the area) in this article.

The point is, a CPSR doesn’t just cover purchasing files. It covers a wide range of requirements including compliance with CEPDAS and compliance with Item Unique Identification (IUID). If you think your Supply Chain Management department can pass a CPSR on its own, think again.

And now comes word that CPSRs are getting even harder. On January 21, 2019, Under Secretary of Defense (Acquisition and Sustainment) Ellen Lord issued a Memo that directed DCMA to “validate, for contracts for which they provide contract administration and oversight, contractor compliance with the requirements of DFARS clause 252.204-7012.” That DFARS contract clause, for those who don’t know, is the Cybersecurity clause, known more formally as “Safeguarding Covered Defense Information and Cyber Incident Reporting.”

Consequently, when CPSRs are performed, reviewers will be assessing how well contractors are complying with cybersecurity requirements.

According to the Memo, reviewers will—

  • Review contractor procedures to ensure contractual DoD requirements for marking and distribution statements on DoD CUI flow down appropriately to their Tier 1 Level Suppliers.

  • Review Contractor procedures to assess compliance of their Tier 1 Level Suppliers with DFARS Clause 252.204-7012 and NIST SP 800-171.

According to a client alert from attorneys at Crowell & Moring, “the scope of DCMA’s review appears broader than the Clause’s textual requirements.” To us, this means that CPSR adequacy may hinge on more than complying with the requirements of the clause itself, which is not good news for contractors.

Importantly, the actual Purchasing System clause was not rewritten. There are no additional adequacy criteria. The cybersecurity review steps appear to be “unwritten” adequacy criteria. Consequently, we don’t know what happens if a contractor doesn’t pass the cybersecurity review steps. Will a system be failed? Will payment withholds be implemented? We just don’t know.

But if history is any guide, it is just a matter of time until the clause is revised (again) to add cybersecurity to IUID and CEPDAS requirements. Meaning, of course, that it will become even harder to pass a CPSR, and that it will require even more cross-functional support to do so.

 

Financial Management of Government Contracts

E-mail Print PDF
It’s a busy time here at Apogee Consulting, Inc.. It’s not busy in terms of traditional client service; it’s busy in terms of other stuff. One of the “other stuff” is an upcoming class I’m going to be teaching at San Diego State University (SDSU) College of Extended Studies (CES).

SDSU CES is, essentially, a learning environment for those who have already completed their traditional undergraduate (or graduate) studies. Among the CES offerings are more than 50 Certificate Programs—including the Professional Certificate in Contract Management. You take six “core” courses and four elective courses, and you get the Certificate. Each course takes one night a week for six weeks. The Contract Management Certificate program is offered in cooperation with the San Diego Chapter of the National Contract Management Association (NCMA).

I’ve been offered the opportunity to instruct one of the Contract Management Certificate classes: Financial Management of Government Contracts. I jumped at the chance, because it sounded fun and (frankly) easy. It’s what I’ve been doing for the past 35 years. In addition, I get paid!

But putting together 17 hours of classroom instruction is not particularly easy, no matter how well one knows the subject matter. It’s not only the PowerPoint slides, of which there are more than 230. It can’t be just about PowerPoint slides, because who wants 17 hours of PowerPoint? There are also discussion questions, and exercises. There are legal decisions to download. There are DCAA audit programs to provide, and DCMA Instructions to provide. In short, I’ve spent about 50 hours preparing for the 17 hours of classroom instruction. And I haven’t even written the Final Exam yet.

So if the blog articles haven’t been as frequent recently, please understand. My attention has been elsewhere.

Here’s my course outline:

Week 1: Financial Risks Throughout the Contract Lifecycle

Week 2: Understanding Contract Costs

Week 3: Contract Cost Principles and The Cost Accounting Standards

Week 4: Business Systems and Adequacy Criteria

Week 5: Indirect Rates, Payments, Audits, and Disputes

Week 6: Other Compliance Risks

If the outline above sounds interesting, consider taking the class! It starts in a month.

If you live outside of the San Diego area, consider hiring Apogee Consulting, Inc. (that’s me!) to develop a similar course for your team, to be taught at your place of business. It will be inexpensive. Trust me on that one; most of the work has already been done!

 

Let’s Discuss Procurement Fraud

E-mail Print PDF
It’s been a while since we’ve discussed procurement fraud. Let’s fix that today.

As readers know, we don’t post many of the fraud stories that come our way, courtesy of the U.S. Department of Justice. The reason for that decision to elide them, as we’ve told you before, is that they are (for the most part) boring. Fraudster does a scheme. Fraudster gets caught. Fraudster pays. Company pays. Repeat ad infinitum.

But today we have a couple of more interesting ones. Let’s dive in, shall we?

The first story concerns a small business, E.M. Photonics (EMP). EMP and its CEO recently settled allegations that they violated the False Claims Act. The reported settlement amount was $2.75 million.

What’s the story? Well, “as alleged in the settlement agreement”—

EMP received SBIR and STTR funds from various agencies (including DARPA, military services, the DOE, and NASA) during the period January 2009 to April 2014. (Let’s say 5 years.) EMP and its CEO allegedly defrauded the SBIR/STTR programs via two schemes.

(1) EMP received duplicative funds; i.e., they submitted proposals (and received funding) from different agencies for doing essentially the same work. As part of their proposals, they certified that the work was non-duplicative; but it wasn’t.

(2) EMP and its CEO “directed EMP employees, or caused others to direct EMP employees, to falsely complete timesheets for direct labor that the employees did not perform.” Thus, the invoices that contained the false labor hours/dollars were considered to be false claims under the False Claims Act.

The two schemes make sense when you look at them together. The first scheme brought in duplicable contract and grant funding, but then EMP needed to create false labor costs to show that work was being performed. In the words of the DOJ announcement, “The government alleged that both of these schemes were designed to maximize charges to each contract or grant.”

Yeah, it looks that way.

The second story is about Microsoft. According to The Seattle Times (in a story written by Mike Carter), a “former” Microsoft Director agreed to a plea deal related to an alleged corporate fraud worth as much as $1 million. The story states that “Jeff Tran, 45, who served as director of Microsoft’s Sports Marketing and Alliances division,” allegedly did a number of naughty things, including—

  • Stole 62 Super Bowl tickets intended for company employees and sold them online for $200,000.

  • Stole “blocks of Super Bowl tickets and Super Bowl Party tickets belonging to Microsoft. … In one instance, he sold an unnamed Microsoft employee a pair of the free tickets for $12,400 and pocketed that money.”

  • “Solicited a $775,000 payment from a vendor … The indictment alleged Tran funneled the payment to his own bank account, and then asked the vendor to help cover it up, threatening to remove the business from a preferred vendor list if it didn’t.”

  • “Tried to solicit a second, $670,000 payment through a fraudulent invoice and was planning to ask for a third for $500,000 …” but was caught before he could consummate those schemes.

We might have been happier if Microsoft’s internal controls had detected the wrongdoing. Alas, it is not so. Instead, “Microsoft vendors became suspicious of Tran’s activity and reported the conduct to the company.” That was when Tran allegedly “destroyed electronic communications and told the vendors to lie to Microsoft about the $775,000 payment.” Unfortunately for Mr. Tran, his scheme was uncovered and he subsequently “paid $1,036,000 to Microsoft in restitution.” Yeah, we would have been “suspicious” as well, if somebody had tried to extort hundreds of thousands of dollars from us.

So the suspicious vendors told Microsoft, who then told the FBI. And that’s how Tran went down. Not a shining moment for Microsoft, who let a Director perpetrate (alleged) fraud schemes and didn’t detect any wrongdoing.

But Tran’s restitution to his (former) employer didn’t end his legal problems. According to Mike Carter’s story, “he pleaded guilty to a single count of wire fraud in a deal that will result in the dismissal of four other counts when he’s sentenced May 10 by U.S. District Judge Ricardo Martinez…. Wire fraud carries a possible prison term of up to 20 years. As part of the plea agreement, prosecutors will ask that Tran serve no more than three years in prison, according to a statement from the U.S. Attorney’s Office.”

When Tran is released from prison, we suspect he’s going to have a hard time finding gainful employment in the white-collar sector of private industry.

 

Questioned and Sustained Costs

E-mail Print PDF
Sometime in the next few months DCAA will issue its Annual Report to Congress. The Annual Report will be dated March 31 (covering the previous Government Fiscal Year that ended September 30, 2018), but who knows when it will appear on the DCAA website for the public to see? It’s not as if DCAA has a great record with respect to timely internet publication of its documents. That said, we know it’s coming, because there’s a public law that requires DCAA to submit that report each year.

When the Annual Report appears, we’ll look at it carefully, as we always do. We’ll look at productivity statistics and we’ll compare the most recent statistics to historical values. We’ll look at the information in the Annual Report and match it up to the statistics in the DoD Office of Inspector General’s Semi-Annual Reports to Congress for the same period. We’ll try to put the current DCAA audit stats into an historical context and we’ll try to draw some conclusions about what the stats are telling us.

One of the most important stats we’ll look at is the Questioned Cost values as a percentage of total dollars examined. It’s not really a good metric, taken alone. It doesn’t really tell us much of anything about audit quality, though for a few years DCAA tried to make it seem as if it did. It doesn’t really say much about taxpayer dollars saved or taxpayer dollars recovered, though DCAA would like you (and Congress) to believe that’s the case. It is not really a metric that says anything about the quality of audits that DCAA is performing—since a quality audit may or may not result in findings.i

If anything, it’s a metric that indicates contractor quality. The better job contractors are doing, the lower the CQ percentage of dollars examined should be.

So why do we care about a statistic that’s not particularly meaningful?

We care about CQ statistics because they are an indicator of risk.

The DCAA CQ statistics can be used to make a guestimate as to about how many dollars our clients might see questioned, on the average. If the client books a contingent liability reserve related to future DCAA audits, and lacks much history upon which to base that reserve amount, then the DCAA CQ stats are a decent place to start.

In addition, the CQ statistics are a natural benchmark. If you are experiencing significantly more CQ (as a percentage of total dollars examined) than the average value, you might ask yourself why that’s the case. Are you more aggressive than the average contractor? Are you taking positions you know DCAA will challenge? Or perhaps you have a more aggressive DCAA auditor than the average. Perhaps you have an auditor who is taking positions that are not well-supported by the Contract Audit Manual.

On the other hand, if your CQ stats are lower than average, does it mean that you are better than average at self-disallowing costs before audit? Or does it perhaps mean that you are being overly conservative—and leaving money on the table?

In any case, it’s an indicator and a benchmark. As such, it has value when analyzed and put into context.

But the real deal is the QC sustention rate. This is the percentage of QC that are actually sustained by a contracting officer. That is a more powerful indicator of DCAA audit quality.

Readers of this blog know that, because we’ve written about it before. Just about every time the DoD OIG Semi-Annual Report to Congress is issued, we write about QC sustention rates.ii As the DoD OIG tells Congress: “Cost Questioned represents the amount of audit exception, potential cost avoidance, or recommended price adjustment in the audit report [but] Cost Sustained represents the questioned costs, potential cost avoidance, or recommended price adjustment sustained by the contracting officer.“

The CQ sustention rate is a real indicator of audit quality. It tells us the percentage of time that a contracting officer is persuaded by an audit finding. It tells us the percentage of time that a contractor is unsuccessful at persuading a contracting officer that a DCAA audit finding is wrong. It is as close to a definition of “win” or “lose” as we have.

Historically, the CQ sustention rates have not been very good, if you are a DCAA auditor. On the other hand, if you are a contractor, then they have been good news indeed. In GFY 2017, the overall QC sustention rates for DCAA audit reports issued after contract award was 29%. That means that less than one-third of all CQ dollars were sustained by a contracting officer—meaning that more than two-thirds of all dollars questioned were not sustained. The contracting officer did not agree with the audit findings. The contractor won.

DCAA management knows this. DCAA management knows that CQ sustention is the metric that matters. In fairness, it’s not the only metric that matters. In its first Report, the Section 809 Panel recommended that DCAA report 12 metrics to Congress each year. But until that recommendation is accepted and implemented, CQ sustention is the best metric we have to evaluate audit quality. And DCAA management knows people are using it that way.

Because DCAA management is aware of the power of that metric, contractors (and contracting officers) have started to see a not-so-subtle pressure applied from auditors to sustain findings during negotiations with contractors. Sometimes, it’s not about the right or wrong of the audit finding; instead, it’s about the need to report a high sustention rate to Fort Belvoir. It’s about the need to create the appearance of audit quality, regardless of whether or not it is deserved.

Remember, auditors always have the ability to report contracting officers to the DoD Office of Inspector General if they believe the contracting officer is not operating with the best interests of the U.S. government in mind. The threat is that the CO will be investigated and forced to explain their position to the IG if they don’t cave-in and sustain the audit finding. That threat, whether spoken or not, is always there.

As a result, we are seeing an up-tick in “split the baby” negotiations, where contractors are being asked to give in, to a certain percent, to an audit finding. Even though the contractor may believe the finding is without merit, there is pressure to give a bit so that DCAA doesn’t look too bad. A "split-the-baby" 50/50 sustention is a huge win for DCAA, because it's nearly double what the audit agency has been getting, according to 2017 statistics.

What can contractors do when faced with this situation? Well, they can agree, of course. But if they don’t want to agree, they have a tricky path ahead of them. They need to remind the CO that it is the CO who has the warrant—not the DCAA auditor—and, as a result, it is the CO who is charged with independent business judgment. It is the CO who has to negotiate a fair and reasonable solution to the differing views with which they are presented. Sometimes “splitting the baby” is appropriate; but other times it may not be.

When negotiating audit findings with a contracting officer, it’s going to be helpful to keep in mind that the auditor is watching and mentally calculating the CQ sustention rate. If that value falls too far below the agency average, that auditor may get upset. That’s not to say that findings without merit should be accepted in the name of relationship management. But we think it’s something to keep in mind.

i Though we noted—and wrote about—a fairly recent DCAA policy shift in which audits that have no findings do not result in issuance of formal audit reports. We suspect that’s a policy that focuses on reducing GAGAS noncompliance risk, rather than manipulation of audit productivity statistics.

ii Though it turns out we didn’t write about the latest DoD OIG Semi-Annual Report to Congress, published in November, 2018. We’ll catch up on that next time around.

 


Page 36 of 278

Newsflash

Effective January 1, 2019, Nick Sanders has been named as Editor of two reference books published by LexisNexis. The first book is Matthew Bender’s Accounting for Government Contracts: The Federal Acquisition Regulation. The second book is Matthew Bender’s Accounting for Government Contracts: The Cost Accounting Standards. Nick replaces Darrell Oyer, who has edited those books for many years.