Mandatory Privacy Training
A recent final rule revised the FAR to require contractors whose employees have access to “a system of records” or that “handle personally identifiable information” (PII) to complete training on privacy. The final rule applies to acquisitions of commercial items and to acquisitions valued below the simplified acquisition threshold (SAT). The privacy training must be “role-based [and provide for] foundational as well as more advanced levels of training” and include tests of the knowledge levels of users.
Training must cover—
-
The provisions of the Privacy Act of 1974 (5 U.S.C. 552a), including penalties for violations of the Act;
-
The appropriate handling and safeguarding of PII;
-
The authorized and official use of a system of records or any other PII;
-
Restrictions on the use of unauthorized equipment to create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise access, or store PII;
-
The prohibition against the unauthorized use of a system of records or unauthorized disclosure, access, handling, or use of PII or systems of records; and
-
Procedures to be followed in the event of a potential or confirmed breach of a system of records or unauthorized disclosure, access, handling, or use of PII.
The requirement is a flow-down, meaning that prime contractors are required to include it in subcontracts, where applicable (i.e., where the subcontractor handles PII).
The contractor (or subcontractor) must maintain documentation evidencing that the privacy training requirements were met, and must provide that documentation upon request.
A new subpart (24.3) is added to the FAR to address the issue.
What is PII? According to the new rule, “Personally identifiable information means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.”
What do we think of the new rule?
Well, we just finished up a lot of compliance training. And in that training we learned that a company—not just a government contractor, but any publicly traded entity—should have a policy on PII protection and that employees should be trained in that policy, and that compliance with the policy should be tested. So from that point of view, this is something that many companies should already have in place. For them, it will be no big deal.
But we also know that there are many upon many small businesses and other contractors for whom this will be a brand new and disconcerting requirement. For them, it will be a big deal indeed.
We also think that the rule is unnecessarily prescriptive and creates a bureaucratic solution to what is essentially a free market problem. For example, the government could have chosen to create a mandatory source evaluation factor that covered the same requirements. That would have pushed companies toward the same end state without actually prescribing it.
But whatever. Here we are.
If you would like assistance in designing your training program or in training your employees, Apogee Consulting, Inc., is here to help you.
Inspector General Criticizes DCMA CAS Administration
Because of course it does.
The Department of Defense Office of Inspector General has a long and illustrious pedigree, reaching right back to von Steuben and his critical impact on the readiness of the Continental Army. But of late it seems that the DoDOIG exists to offer criticism of its sister DoD components, without actually addressing root causes and making recommendations that would proactively fix the underlying problem(s).
The Defense Contract Management Agency (DCMA) is often in the DoDOIG’s crosshairs, because DCMA makes it harder on its own people than it needs to be, and therefore creates an easy target. DCMA’s own ill-conceived policies (called “Instructions”) actually create a situation where it is nearly impossible to be in compliance with them, and thus DoDOIG is able to easily report “findings” of contracting officer failure to comply.
Between DoDOIG’s focus on literal compliance with rules, and DCMA’s insistence on creating arbitrary and unreasonable rules, you get audit reports that seem to indicate vast levels of waste and abuse; whereas the reality is somewhat different than what’s pictured.
Today’s example of the phenomenon: DoDOIG Report Number DODIG-2017-032, published 8 December 2016, with the catchy title “Evaluation of Contracting Officer Actions on Cost Accounting Standard Noncompliances Reported by Defense Contract Audit Agency.”
According to the Objective section of the report, the DoDOIG reviewed 27 DCAA reports alleging that a contractor compliance with the Federal Cost Accounting Standards (CAS). The OIG reviewed contracting officer actions taken after receiving those reports to see whether those actions “complied with Federal Acquisition Regulation (FAR) 30.6, ‘Cost Accounting Standards Administration,’ DoD Instruction 7640.02, ‘Policy for Follow-up on Contract Audit Reports,’ and applicable agency instructions.”
Even before getting to the content, we can be fairly confident that the OIG is going to find problems. A recent ASBCA decision, discussed here, already found that a contracting officer failed to comply with FAR 30.602. From our informal research, we have reason to believe that individual CO was not in any way an outlier. In fact, we believe that many—if not most—DCMA contracting officers do not understand FAR 30.6 and are ill-prepared to comply with it. So when we see that the OIG will be evaluating a DCMA CO’s compliance with FAR 30.6, we are pretty sure there will be lots of findings.
Indeed, out of the 27 instances reviewed, there were 15 noncompliances with the requirements of FAR 30.6. In addition, DoDOIG found 16 instances of noncompliance with DoD Instruction 7640.02 and 8 instances of noncompliance with DCMA Instruction 108.
Whatever.
As per usual, the OIG failed to do any root cause analysis and the recommendations were superficial. The recommended corrective actions were:
We recommend that the Director, DCMA, and the Commander, Naval Sea Systems Command (NAVSEA), provide training on the requirements for processing CAS noncompliances in a timely manner.
We also recommend that the Director, DCMA:
-
develop effective controls for helping to ensure that contracting officers adequately document their rationale when concluding that a noncompliance is immaterial, and
-
remind contracting officers of the requirements for obtaining legal and management reviews of CAS determinations.
And there you have it.
When you think about waste and abuse, consider whether an OIG report that fails to consider root causes and make effective corrective action recommendations should fall into that category. Ask yourself whether such a report is consistent with the high standards established by von Steuben … or if such a report is simply another example, in a long line of examples, of bureaucratic infighting on the taxpayer’s dollar.
|
Accounting for Credits
When talking about the FAR cost principles, too many people focus exclusively on the 47 principles dealing with “selected costs” and ignore the seven “general” principles—or those principles that the late Mel Rishe called the “cornerstone principles.” The general or cornerstone principles provide overarching guidance that applies to every single contractor that has a contract with the 52.216-7 (“Allowable Cost and Payment”) clause. As such, it is arguably more important to understand the general cost principles than it is to understand the principles dealing with selected costs.
This article with address one of the seven general cost principles: FAR 31.201-5 (“Credits”). It is a deceptively simple rule; yet it is one that has gotten many a contractor into trouble.
The cost principle is quite short. It reads (in its entirety) as:
The applicable portion of any income, rebate, allowance, or other credit relating to any allowable cost and received by or accruing to the contractor shall be credited to the Government either as a cost reduction or by cash refund. See 31.205-6(j)(3) for rules governing refund or credit to the Government associated with pension adjustments and asset reversions.
It’s two sentences long, and one of those sentences refers the reader to another cost principle. Basically, then, the “credits” cost principle is a single sentence. Should be easy to comply with, right?
The credits cost principle is tied to the FAR Part 31 definition of “total cost” found at 31.201-1. That cost principle defines the composition of total cost as “the sum of the direct and indirect costs allocable to the contract, incurred or to be incurred, plus any allocable cost of money … less any allocable credits.” Notice the slight wording change, i.e., the use of “applicable portion” versus the use of “allocable”—is that a meaningful difference? In practice, no.
In her essential and indispensable book, Government Contract Costs & Pricing, Karen Manos notes that the credits cost principle has been in existence since 1948. The original ASPR language added some details, including this sentence: “Income and other credits arising out of operations under the contract, where the related cost was reimbursed or accepted as an allowable cost, will be credited to the Government.” Accordingly, we see that the intent was to create a nexus between income and/or credits received by a contractor and allowable costs. It seems to be the case, then, that income and/or credits related to unallowable costs need not be credited to the government. Indeed, as Ms. Manos notes in her commentary, the ASBCA explained (in MRK-BRJ, ASBCA No. 16031) that “It is not every refund which a contractor may receive to which the Government is entitled. Before any entitlement arises the Government must [first] have paid the costs to which the refund is applicable.”
That being said, the credits clause has been applied to state tax refunds received by contractors, to returned vendor items, to annual rebates from travel agencies, to prompt payment and other trade discounts, to receipts from the sale of scrap, to dividends and rebates received under insurance policies, and to many other transactions in which a contractor receives a benefit. In fact, Darrell Oyer, in his book Pricing and Cost Accounting, goes so far as to write that the Credits cost principle “compels contractors to analyze any and all credits received to ascertain their direct or indirect impact on [their] government contracts. … Any credit received needs to be scrutinized to ensure that the government receives its due cost reduction.”
Both Manos and Oyer make the point that the requirement to flow-back income and rebates does not end when the contract has been formally closed. The requirement will extend so long as there is a nexus between the credit and the original contract cost. Moreover, the requirement extends to indirect costs as well as to direct costs. Credits received related to claimed indirect costs must be allocated to the government in the same, or in a similar, fashion as the original indirect cost was allocated. This can be difficult to accomplish if the credit shows up a decade or more after the cost was originally incurred. (Think about state taxes and associated tax refunds, for example.)
While the Credits cost principle seems straightforward and simple on its face, in practice compliance with its requirements can present a challenge.
Dealing with Workers’ Compensation insurance is particularly tricky. We wrote about the issue here. In that article we noted one construction company that was forced to settle a False Claims Act matter related to its expected premium costs used in pricing contract Requests for Equitable Adjustment (REAs).
In another article, we discussed the cost principle related to employee relocation reimbursements, and noted that employees who do not fulfill the requirement to stay employed for a year following their relocation trigger a need to credit the relocation cost claimed, regardless of whether the employee pays back their relocation expense to the company.
In our experience, many companies trip over the Credits cost principle requirements. They don’t scrutinize their “other income/expense” transactions or they don’t “true-up” their Workers’ Comp costs accurately, or they do something that seems innocuous until the government shows up to demand its fair share plus interest and penalties. Way back in 1999, we came across a contractor that failed to give the government its fair share of rebates it had received related to providing cafeteria milk to low-income students. That was a multi-million dollar settlement.
The bottom-line is this: if you get something of value related to an allowable direct or indirect government contract cost, you need to give the government its fair share.
Perpetual Audit
The Defense Contract Audit Agency performs a variety of audits, many of which the average contractor never experiences. For most contractors, their experience of DCAA is gained through an audit of a cost proposal submitted in the hope of winning a contract. The auditor shows up, looks at the proposed costs (both direct and indirect), looks at the support for the proposed costs, and then expresses an opinion on whether or not the proposed costs were adequately supported. Then the auditor departs and the next time the contractor hears about the audit is during negotiations.
Some contractors have their proposals audited well after contract award, in order to validate that the contractor complied with the requirements of what used to be called the Truth-in-Negotiations Act (TINA) but which is now called by some other name. Those audits used to be called “post-award audits” or sometimes “defective pricing audits”—but they are now called “Truth in Negotiation audits” because that’s what DCAA is calling them these days.
Contractors with cost-type (or perhaps T&M) contract types know that DCAA audits a different type of proposal: the annual proposal to establish final billing rates (commonly known as the “incurred cost proposal”). These contractors often submit provisional billing rate proposals to establish the indirect rates to the used for contract invoicing until final billing rates can be established. Still other contractors submit forward pricing rate proposals that are audited, negotiated, and (hopefully) become forward pricing rate agreements.
Thus, speaking in a very broad sense, the average DCAA auditor spends most of their time auditing some form of contractor proposal; and the average contractor’s experience of DCAA is having some form of proposal being audited. But that’s not all DCAA does.
DCAA reviews contractor business systems, of course. At least three of the six business systems formalized in the DFARS fall under DCAA’s cognizance. Contractors’ business systems were a big deal five or six years ago; but by now the ritual Kabuki Dance between auditor, contractor, and contracting officer is well known and it’s a rare event when a business system is failed. That’s not to say that pre-award accounting system reviews—which are performed by DCAA—are easy to pass; indeed, they are not easy to pass and too many new contractors fail their first (or second) pre-award reviews. But once that hurdle is passed the DFARS contractor business system oversight regime is pretty much a paper tiger at this point. It’s not even enforced at any but the largest of the defense contractors.
In addition to all the activity listed above, DCAA also performs what it terms “mandatory annual audit requirements” (MAARs). Each MAAR audit is to be performed each year. (Thus: “annual audit”.) For a long time, MAAR audits used to be performed on an individual basis, but that didn’t always work out. It became clear that DCAA was deferring the required MAAR audits—even though they were “mandatory”—because of “resource constraints”. That posed a problem because an audit performed in 2014 has little relevance to an audit of a contractor’s 2007 incurred costs; yet, that was how the audit agency was applying the findings. It was a problem because the MAAR testing results were supposed to give the auditors assurance that the systems that fed incurred costs (such as purchasing and labor accounting) were working adequately. Without that assurance, it was difficult to support a valid conclusion on the accuracy of a contractor’s claimed costs.
A couple of years ago somebody at Fort Belvoir figured out that there would be a higher probability of the MAARs being performed timely if they baked the requirements into the incurred cost audit program. So now the MAARs are linked to that audit. At about that same time, somebody else decided that “mandatory annual audits” were only mandatory, on an annual basis, at “major” contractors. MAAR audits would only be performed at non-major contractors once every 3 years. Those two decisions helped MAAR audits get back into sync with incurred cost audits.
There are eighteen individual MAAR audits, but often some are performed in the background (so to speak) and the contractor is barely aware of them. Other MAAR audits, on the other hand, require contractor participation and support.
The two most obvious “in your face” MAAR audits are MAAR 6 and MAAR 13. MAAR 6 is commonly known as a labor “floor check” audit and MAAR 13 is known as a “purchase existence and consumption” audit. (We should note that, technically, the MAAR 6 audit can be either a floor check (observation) or an employee interview. But everybody calls it a floor check even if it’s chock-full of employee interviews.) Both those two audits are labor intensive and can take significant contractor resources to support. And both those two audits can take a long time to perform.
In fact, we believe that those two MAAR audits are now at the point that they are never, ever, completed.
From the auditor’s perspective, of course the audits are completed; they have to be. If there are no findings the auditor prepares a Memorandum for the Record and that ends the annual exercise. But that’s not what a contractor experiences.
First, when the auditor prepares a Memorandum for the Record to document the work performed and lack of findings, there is no requirement for an exit conference. There is no formal feedback. From the contractor’s perspective, there is only silence. Is the audit over? The contractor may never know.
Second, in order to comply with DCAA’s interpretation of GAGAS (Generally Accepted Government Auditing Standards), auditors are directed to select their transaction samples from throughout the year. In earlier times, the MAAR random sample was selected at a single point, or perhaps the samples were selected from a quarter’s worth of transactions. No longer. Nowadays auditors are told to select their sample so that the entire year is covered. This means that the auditors are requesting multiple transaction universes as the year progresses, and making multiple sample selections for testing. Which means that the contractor has to support the audit throughout the entire fiscal year.
In other words, the audit never, ever, stops.
Each month, or each quarter, the auditor requests a transaction universe and makes a selection. The contractor provides the supporting documentation. Questions are asked and answered. Then the next month (or quarter) arrives and the cycle repeats. If all goes well, the auditor prepares a Memorandum for the Record at year-end.
And then the cycle starts again the next month, or quarter, for the next year’s MAAR coverage.
Remember, the contractor doesn’t see the Memorandum for the Record. From the contractor’s perspective there is an endless cycle of transaction universe requests and transaction samples to be supported. There may or may not be a new year’s entrance conference, but there is no other indication that there is a new audit. For the contractor, it must seem like a never-ending audit.
It must seem like a perpetual audit.
|