Supply Chain Management and Program Risk
It used to be a truism that the purpose of managing the supply chain was to ensure sufficient materials and parts so as to execute the program. The prime contractor won the work and subcontracted portions to lower-tier suppliers, who then subbed out some to the next tier of suppliers, and so on and so forth. Primes got graded on the socioeconomic status of their subcontractors, with competitive advantage being conferred to those primes who could locate suppliers that were both good at execution and at being the right shade of socioeconomic category. The same was true for the lower-tier suppliers. If you could quote a decent price plus be a small or small disadvantaged business, you had a decent chance at winning work and making some money along the way.
The decision to subcontract out a portion of the contract’s statement of work – the “make or buy” decision – was based on many factors, perhaps chief among them the notion that suppliers were generally smaller companies with less overhead—and thus cheaper. Often, there were other factors that also went into the make or buy decision. Some suppliers offered technical expertise unavailable to the prime contractor. Other suppliers offered the ability to promise good socioeconomic stats. Still other suppliers (often competitors) offered something even more valuable: the ability to deliver the political capital necessary to keep the program of record funded. To sum up a complex trade-off analysis in one sentence, the make or buy decision often pointed to a “buy”—a decision to subcontract out—even if the decision introduced additional program execution risk.
We’ve written about effective subcontractor management many times on this blog. For example, see this article, written about a year ago. Or see another example, written in 2010. We’ve asserted (with evidence in support of the assertion) that effective subcontractor management is the key to effective program management. We’ve written about the risks associated with subcontracting and the importance of identifying and managing those risks. We’re kind of passionate about the topic, you might say.
Many of the largest prime contractors have made a specialty of subcontracting out large portions of the SOW, to the point where they like to call themselves “system integrators” and point to subcontract management as one of their (few) core competencies. Their program win strategy is to lock-up and deliver large teams of individual corporations (along with those corporations’ local Congresspersons and Senators). And it tends to work for them often enough that they keep on doing it. Either they have figured out how to manage the risks associated with supply chain management or, perhaps, they haven’t noticed that those risks keep increasing … and so they keep on with what has been working for them.
But make no mistake, those risks do keep increasing. We’ve written about those more recent risks, and the need to manage them, as well. Hell, we’ve even ranted about the importance of a secure supply chain more than once on this site, not that you took us seriously enough to mobilize a tiger team to attack the problem. For example, remember that time where we told readers about the revisions to the DFARS that established criteria for a contractor system to detect and avoid counterfeit electronic parts (“CEPDAS”)? It wasn’t that long ago: it was posted in May, 2014. Yeah, that was the one where we noted that a failure to implement an adequate CEPDAS could lead to a disapproved Purchasing System. That wasn’t the entirety of the risk.
In that article, we noted the new DFARS Cost Principle at 231.205-71, which made the cost of counterfeit electronic parts “and the cost of rework or corrective action” necessary to remedy the impacts of counterfeit electronic parts unallowable, unless the contractor has an approved CEPDAS (among other criteria). If you don’t have an approved CEPDAS and your supplier delivers counterfeit electronic parts, you are going to be in a world of financial hurt, hurt which you will only hope will be recoverable through litigation against your supplier.
This is a supply chain management risk and it’s a big risk and it’s hard to mitigate. Thus, since 2014 the make or buy decision has been impacted and we bet not too many companies have revised their make or buy processes and trade-off criteria accordingly. If you are one of the few who are out in front of this issue, then good for you! If not, you may want to read the next part of this article.
We now link to a very recent Department of Justice press release, in which we learn that Mr. Jeffrey Krantz, CEO and owner of Harry Krantz, LLC, a New York company “that bought and sold, among other things, obsolete electronic parts for use by the U.S. Military and commercial buyers,” pleaded guilty to one count of wire fraud. What did Mr. Krantz and his company do? According to the press release, Krantz did the following –
Between 2005 and 2008, KRANTZ purchased and sold, and caused to be purchased and sold, over a thousand chips to Bay Components, which, in turn sold them to the Connecticut company. The chips were marked with certain information, including a certain manufacturer’s name and trademark, a date code, and a military part number. In approximately December 2005, the first shipments of about 330 chips that KRANTZ had sold to Bay Components were rejected by the Connecticut company for being the wrong part because the chip contained the wrong die inside. In 2006, KRANTZ replaced those chips with at least some of the replacement chips bearing the date code 9832. Between 2006 and 2008, KRANTZ sold and caused to be sold at least 900 chips with date code 9832 to Bay Components, the majority of which were sold to the Connecticut company. KRANTZ knew that the chips had originated from a parts supplier in China, and there was a high probability that the chips were falsely remarked not the original chips of the certain manufacturer as represented by the markings on the chip. He also avoided engaging in common practices in the industry, including those which Harry Krantz LLC routinely engaged in for other military parts, to avoid confirming that the chips were likely remarked. The investigation revealed that many of the chips were used in the assembly of U.S. Military and commercial helicopters.
So an unnamed Connecticut company purchased electronic parts from Bay Components, who in turn acquired them from Krantz. The unnamed Connecticut company rejected the first shipments, but permitted its supplier and lower-tier supplier to replace the rejected chips. Unfortunately, Krantz sourced the chips from China and knew they were likely to be counterfeit. The counterfeit chips were sold up the supply chain and installed on “U.S. Military and commercial helicopters.” Now in fairness, let’s note that this all took place a decade ago, well before the recent emphasis on counterfeit electronic part detection and prevention. So that unnamed Connecticut helicopter manufacturer really shouldn’t be embarrassed that it failed to manage the situation. But still, there are some obvious lessons to be learned here.
First lesson: there aren’t that many helicopter manufacturers in Connecticut. It’s kind of obvious who the company is, and we expect Lockheed Martin will implement its own version of CEPDAS after the acquisition is finalized.
Second lesson: if your part supplier delivers a shipment of non-conforming parts, that’s a huge red flag and should spark an immediate investigation. We’re talking about QA folks para-dropping into the supplier’s operation with no warning, along with sniffer dogs trained to detect made-in-China chips. (Okay that may have been a bit over the top, but we suspect you get the drift.) Procurement should not treat that event as a business-as-usual supplier mistake, as it may well just be the tip of a nasty iceberg looming dead ahead. That kind of event is the announcement that the supplier’s risk probability curve has reached an inflection point, and is quickly approaching a 100% certainty that your program is going to have significant negative cost and schedule variances. Does your supply chain team know what to do if there is such an event?
Third lesson: that unnamed Connecticut helicopter manufacturer may have an approved CEPDAS and, if so, its reaction and recovery costs may be allowable. But if not, then we bet a significant amount of unallowable costs were incurred. The negative impacts may be recoverable through litigation against the middleman supplier (Bay Components) or against Krantz directly. But that assumes that either or both companies have the financial resources to compensate the big unnamed Connecticut helicopter manufacturer. If the money (or insurance) isn’t there, then we suspect the big prime may be SOL.
So here’s a timely object lesson on the importance of securing your supply chain and implementing a strong CEPDAS. We’ve been ranting about this stuff for years, but we’re not asking you to listen to us. We’re asking you to look at the unnamed Connecticut helicopter manufacturer and learn from that company’s misadventures.
Lockheed Martin Also Acquires Sikorsky’s Legal Liabilities
At this point it’s old news that United Technologies Corporation has sold its Sikorsky subsidiary to Lockheed Martin. The acquisition is generally held to be a “win” for LockMart, and reports state it will be immediately accretive to earnings. So: Good for Lockheed Martin. Also: Good for Sikorsky, which escapes a corporate parent that really didn’t want it.
As is the case with any acquisition, the buyer doesn’t just get the assets; it also gets the liabilities. Due diligence is the process of reviewing the acquisition target to make sure all liabilities – especially including any contingent liabilities – are identified and factored into the purchase price. Due diligence on government contracting targets is a bit different and more focused than “normal” due diligence, because the cost of defending (or settling) a contract non-compliance can change a good deal into a bad one. For example, if the target has weak controls over its estimating and pricing, the due diligence team is supposed to assess the potential for post-closing “defective pricing” allegations to surface. Similarly, if timekeeping controls are week, the team is supposed to evaluate the possibility that systemic labor mischarging might be taking place. For a final example, an evaluation of the controls over identification and segregation of unallowable costs helps identify any potential legal issues in that area.
Presumably, when Lockheed Martin decided to acquire Sikorsky, it performed a rigorous due diligence and worked hard to identify any areas of potential non-compliance that might spark legal issues after the deal closed.
One issue – one contingent liability – that was already on the table months before the acquisition was the legal problem of Sikorsky’s subsidiary, Sikorsky Support Services, Inc. (SSSI). SSSI was awarded a Navy contract in 2006 to provide support to the T-34 and T-44 turoprop training aircraft. In turn, SSSI issued a subcontract to another Sikorsky subsidiary, Derco Aerospace, to procure and manage the spare parts needed to provide that support. Derco billed SSSI its costs for doing so, plus overhead and profit. The U.S. Government objected to that arrangement, and filed suit in October, 2014.
As our readers know, accounting for inter-company costs (or inter-organizational transfers, as they’re more formally called) between related parties under common control is difficult, and companies don’t always get it right. Normally, inter-organizational transfers are done at cost, excluding profit; but there are regulatory exceptions that permit transfers at price (including profit) under certain circumstances. We don’t know whether Derco was entitled to an exception.
In this case, not only is the government alleging that SSSI misbilled its Navy customer, but that SSSI also submitted “false Certificates of Final Indirect Costs” in its annual proposals to establish final billing rates for years 2006 through 2012. The government has alleged “numerous claims for violations of the False Claims Act, for breach of contract and for unjust enrichment.” The government seeks $148 million in restitution for SSSI’s alleged noncompliances.
For its part, Sikorsky stated (in its SEC filing) that “We believe that Derco was lawfully permitted to add profit and overhead to the cost of the parts, and maintain that SSSI did not submit any false certificates. We also believe that we have other substantial legal and factual defenses to the government’s claims.”
That being said, on July 13, 2015, or just a couple of weeks before the Lockheed Martin acquisition was announced, Sikorsky was informed that the Department of Justice had “opened a criminal investigation with respect this matter.” There is a difference – a big difference – between civil and criminal allegations. The DoJ’s subpoena definitely raised the stakes. Sikorsky was quick to note that it intends to “cooperate fully in the investigation.”
We are obviously unclear on the details of the matter or what DoJ’s motivation may have been for moving the matter from civil to criminal. However, we noted in this WaPo story that “the Justice Department also claims SSSI submitted false certificates for aircraft maintenance from 2006 to 2012.” If true, those allegations might have been sufficient to get the criminal thing going. But we don’t know.
We do wonder, though, if the continual series of investigations and allegations, and costs of providing legal defense for those investigations and allegations, played a role in UTC’s decision to sell Sikorsky. UTC is a conglomerate that has huge purely commercial entities. Those entities have their own issues, of course; but they don’t have the same level of regulatory oversight and extreme legal consequences that the government contracting entities do. Maybe the UTC Board of Directors got tired of dealing with the problems of one of its largest government contracting entities, and decided to sell the entity to the largest defense contractor in the world—one that presumably deals with such regulatory oversight and investigations and allegations on a daily basis.
Thus: We wonder if the known contingent liabilities associated with this matter played a role in bringing the sales price down to a point where commenters think that Lockheed Martin got a very good deal, one that is immediately accretive to earnings.
|
Engineer Misuses Corporate Credit Card in a Big Way
World Wide Technology, Inc. is a very large, privately owned, Minority Business Enterprise that describes itself as a “global systems integrator with $6.7 billion in annual sales and more than 3,000 employees.” The company sells IT-related “solutions” plus consulting services of various types. It sells those products and services to companies in the private sector, as well as to public sector entities. With respect to the public sector, WWTI has BPAs, ID/IQs and MAS contracts. It has a NASA SEWP contract, a NETCENTS 2 contract, a couple of SPAWAR MACs, a couple of NIH vehicles, and several other agency-specific awards. In other words, it is a player in the Federal contracting arena.
And yet, an employee of WWTI was able to misuse $476,000 in company funds to pay for an addiction to online strippers.
Nobody should be surprised that employees will abuse company credit cards. It’s a known thing—one we’ve discussed before. But this computer engineer from Gilbert, Arizona, seems to have set some kind of record for corporate credit card and expense report abuse. John Berrett was recently indicted on five counts of wire fraud related to his misuse of a corporate credit card, misuse that he allegedly attempted to hide by filing false expense reports.
What Berrett allegedly said he used his corporate credit card for: traveling to meet, train and entertain the company's customers; computer-networking supplies and training materials.
What Berrett allegedly actually used his corporate credit card for, over a 13 month period: buying tokens used to pay online strippers; giving one stripper about $27,000 to pay for her college tuition, buy new tires and finance her parents' utility bill; gifts for his favorite performers, including chocolates, flowers, shoes, wine, a handbag, a television, a laptop and an iPod; and other such worthy uses of corporate overhead funds.
According to one local news article—
Documents state that Berrett's claim of a ‘bribe for the UNIX guys’ was actually about $225 in wine for one stripper. He bought another stripper a digital piano, headphones and extended warranty worth about $2,300, but claimed it was fiber-optic cables, disc drives and patch cords, records show. Berrett also is accused of buying himself a gift: Records show he spent about $130 on a sex toy touted as a ‘top selling pleasure products brand for men’ but told the company he had purchased a training guide with practice questions.
Assuming the allegations are true, what lessons might we learn from this sad story?
First of all, what kind of spending limits were put on Berrett’s corporate credit card? He spent $476,000 over 13 months, which works out to about $36,600 per month in expenses. Did nobody at WWTI think that level of spending was a tad unusual? How hard would it have been to rack and stack employees based on credit card usage, and take a hard look at the top ten percent of all spenders, to see what in the heck they were spending their money on? Not hard, we assert. Not hard at all.
Also, don’t companies get reports showing employees’ credit card usage? Every place we’ve worked or seen, a corporate credit card means corporate visibility. Were no reports available? Were the reports available, but nobody reviewed them?
The only way this makes sense is if there were no corporate credit cards. Instead, employees were allowed to use their own personal credit cards and just submit expense reports for the corporate-related expenses. Even so, somebody could have reviewed the expense reports for propriety, for compliance with corporate policies, and for cost allowability (assuming expenses were charged to overhead for allocation to one of the many Federal contract vehicles).
One obvious lesson here is that corporations need to have their own credit cards, and require employees to use them exclusively for corporate expenses, just as a means to have visibility into employee expenses. In addition, having a corporate credit card permits the company to block certain vendors … say, for instance, online stripper sites.
Moreover, when a company permits employees to use their own personal credit cards for corporate expenses, those companies are missing out on volume discounts and other rebates offered by credit card companies. Just to come up with one hypothetical example, those companies are allowing their employees to earn frequent flyer miles or even cash back rebates, when instead the companies could be booking incentives and using those incentives to lower their overhead rates.
Another lesson here is what kind of internal controls does this multi-billion dollar contractor have in place, such that an employee can rack up those kind of expenses over a period in excess of one year? At a minimum, who reviewed and approved all those expense reports? Who signed-off on purchases of “optic cables, disc drives and patch cords” worth more than $2,000? Who signed-off on an expense report that said “bribe for the UNIX guys” and thought that was an appropriate expenditure of corporate funds?
Given the lack of scrutiny applied to this one employee’s expense reports, what does that say about all the other employees’ expense reports? Remember, WWTI is a government contractor. Presumably it has contracts with the Allowable Cost and Payment clause in them, which invokes the Cost Principles of FAR Part 31. What other kind of nasty unallowable costs have snuck into the direct and indirect expenses? We don’t know, but we do know that this sad news story should be seen as a humongous audit lead for any DCAA folks in the area.
So: use corporate credit cards and don’t let employees use personal credit cards. Set individual spending limits. Block certain vendors. Get individual expenditure reports from the credit card issuer and review them. Rack and stack employees by spend and scrutinize the top ten percent of spenders. Ensure each expense report is reviewed and approved by somebody who understands what is an appropriate reimbursable expense, and what is verboten.
Those are not really advanced controls over employee credit card usage. They are kind of fundamental, actually. Stuff that any multi-billion dollar government contractor should have implemented as a matter of course.
Stuff that you should be implementing right now, if you haven’t already done so.
In Case You Were Wondering …
The blog hasn’t been updated in a couple of weeks and I thought I’d let you know what was going on (or not going on, as the case may be). It’s not really a big deal.
To give you an understanding of why no article has appeared for a couple of weeks, I need to tell you the mechanics of how articles get published here. It’s something I’ve been meaning to do for a while, and this seems like an opportune time to get into the sausage-making of the blog.
In order to get a new article on this site, several things need to happen. Those things are, in chronological order –
-
Something has to catch my eye in the world of government contracting, accounting, or compliance. It has to be of interest to me, personally. Something that sparks my passion. If I don’t have that initial passion, the article doesn’t get written. Yes, ideally the topic should be of general interest to a wider audience, but the truth of the matter is that if I can’t find a reason to write the article, then the article doesn’t get written.
-
I have to have a hook. I need a lesson to be learned or a moral to the story. I need to visualize the first couple of sentences and, in general, how the article will flow. In a perfect world, I will see how the article will end, but frankly that doesn’t happen every time. I know I have a good hook when I have a title. If I can’t pick the title right off the bat, I’ll try typing a couple of sentences to see where the article will go. Rarely (and I mean very rarely), I’ll hold-off on giving the article a title until I’ve roughed-out a draft, just to see what the real hook is. From time to time, I’ll type out a thousand or more words, only to realize that there is no hook. That article does not get published.
-
I have to have the time to write. Each of these articles takes from an hour to three or more hours to type and proof-read. Finding that time is not easy. For example, this article is being written at 10:30 PM on a Thursday night. It will take at least an hour to write. So it probably won’t be done until nearly midnight.
-
After the article is written and proofed, I send it to Mark, my webmaster and publisher. Chances are, if I send it by midnight, he’ll get it in the morning. No offense to Mark, but his morning is not my morning. He works around the clock some times, but more often he’s not in the office until 9 AM or even 10 AM. So he won’t see the new article until then, at best, But Mark has a job in addition to being my webmaster, so he may not be able to get to the new article right away.
-
When Mark does get to the article, it takes him less than 30 minutes to prep it for publishing. He does some magic with Google docs and other assorted software, formatting my Word document into a web-ready article.
-
When I send Mark the article, I specify when I want it to be published. Typically I write two or three articles on the weekend, and then he sets them up for publication at midnight on the dates I specify. I like a random pattern (as you may have noticed) because I like the notion that articles just spring up unexpectedly.
-
I see the articles before you do, and I give them a once-over before publication, looking for typos and infelicitous syntax. I have the ability to edit them, and I frequently do edit them, even after publication, when I see something that bugs me.
So based on the foregoing, you may have noted some variables in the timing. There is the lag between me finding a topic and typing it up. There is the lag between me sending the article to Mark and his ability to get to it. And there is the lag between when Mark puts in on the site and when I set it for publication. Those variables affect the timing of when you see a blog article.
What happened in the past couple of weeks is that Mark’s “real” job took him out of the office and on the road for 10 days. I have a couple of articles in his queue for him to get to, but he’s not been able to get to a computer to do his thing. He gets back to the office tomorrow, and then the articles will start to flow again. This will be the third article in his queue when he returns.
I am also working on two other articles. One is the promised article on DCAA audit quality, and the other is a review of the recent ASBCA decision on concurrent changes to cost accounting practices. Each of those is rather long and involved, so they’ll take a while to finish. But when they are done, Mark should be able to get to them quickly.
So all this detail may be of little interest to you. But some of you may have been wondering, and I trust this answers your questions.
|