Resources for Fighting Fraud
We’ve not been shy about publicizing fraud and corruption in the defense acquisition environment. We’ve called out passive leadership, negligent leadership, and even actively corrupt leadership. We’ve called on public company senior leadership and Boards of Directors to invest in effective internal controls. We’ve called on the Secretary of Defense and the ranks of senior military officers to fight fraud and corruption. All in all, we’ve written nearly 50 articles that have something to do with internal controls, effective or otherwise.
Government auditors are taught to look for fraud and to report it when they find evidence of it. Indeed, they are taught to look for “fraud indicators” and are taught various fraud scenarios. While at times the training results in an attitude that goes a bit past “professional skepticism” and starts to look more like prejudgment, in point of fact there is enough wrongdoing by enough government contractors to justify an auditor’s sensitivity to fraud. The bottom line is that while some auditors take skepticism into the realm of adversarial bias, we as taxpayers very much want auditors to be looking for wrongdoing and to report it when they have evidence of it.
But more than that, we should want to create a culture of ethical decision-making and compliance. We should not wait for auditors to ferret out wrongdoing. We should not rely on after-the-fact audits to detect instances of fraud and corruption. We need to be fighting fraud on a regular basis, so that the auditors have nothing to find.
Another Apogee Axiom: You can’t audit an entity into compliance.
You cannot create a compliant state via audit.
The most an auditor can do is to detect instances of wrongdoing after they’ve occurred. When an auditor finds an instance of noncompliance, that means some individual or group of individuals chose not to comply. The organization created an environment where that person or those people felt it was okay to cut a corner or to do a little “gaming of the system.” Either the expectations weren’t made clear or the individuals didn’t receive appropriate training – or they ignored what they were told. In many cases, we suspect the individuals simply mimicked the behaviors they saw around them. Leadership set the example and the ranks mirrored it.
A study by the U.S. War College found that U.S. Army officers routinely lie. The study found “in the routine performance of their duties as leaders and commanders, U.S. Army officers lie.” That’s not us saying so; that’s the U.S. War College saying so in an official publication. CNN discussed the report, and wrote—
The study describes a ‘culture where deceptive information is both accepted and commonplace’ and where senior officials don't trust the information and data receive -- such as compliance with certain Army training requirements or forms outlining how a mission was carried out. But Army officers are faced with an increasing number of requirements and bureaucratic hoops, according to the study, and rather than work with a rigid military brass to reform a burdensome bureaucracy, officers will simply sidestep those requirements, lying on forms and often rationalizing their answers.
The result? ‘Officers become ethically numb,’ explains the study … ‘Eventually, their signature and word become tools to maneuver through the Army bureaucracy rather than symbols of integrity and honesty,’ the researchers wrote. ‘This desensitization dilutes the seriousness of an officer's word and allows what should be an ethical decision to fade into just another way the Army does business.’
And if military officers routinely engage in lies and deception, should we be surprised at the number of instances of bribery and corruption in the enlisted ranks being reported by the DoD Inspector General? And should we be surprised if the contractors start to mimic the behavior of their military customers, if only to survive?
Well, yes. We should be surprised. We should be surprised and appalled. But we’re not. Not really. We’re numb and a bit blasé to the notion of corruption within the Department of Defense and its contractors. It’s become the norm, hasn’t it? We have become so used to DoD IG auditors and DCAA Auditors and fraud investigators finding instances of fraud and corruption that we no longer question the source.
But you can’t audit an entity into compliance.
You can’t make employees accurately report time by conducting frequent timesheet audits and reporting instances of noncompliance. You can’t make buyers conduct a good source evaluation and selection by reviewing purchasing files months after the fact. You can’t detect bribes and kickbacks by making people fill out a form once a year.
You want an ethical cultural where compliance with expected standards is the norm? You’ve got to work for it. You’ve got to communicate expectations and train people. You’ve got to deploy rigorous internal controls. And most importantly, you’ve got to hold people of all ranks accountable for their decisions.
Creating an ethical culture is not the province of auditors; it’s the province of leadership. And academics studying leadership also study ethical cultures.
In one academic article, we read the following –
Individuals' intentions to report the ethical violations of others are also related to moral agency. If unethical behavior is to be addressed in organizations, authority figures must know about it and therefore must set conditions to promote follower reporting. Followers tend to keep their knowledge of ethical problems to themselves for a number of reasons, including fear of retaliation, a sense that nothing will be done, or habituation to silence in authority situations (Detert & Edmondson, 2011;Kish-Gephart, Detert, Treviño, & Edmondson, 2010). Ethical leadership and a strong ethical culture can be expected to enhance followers' willingness to speak up because they are more likely to feel protected from retaliation and to believe that positive actions will be taken to address their concern.
In sum, there are resources and people who can help guide cultures toward a state of compliance, but it won’t be the auditors leading the journey. Auditors exist to detect instances of noncompliance that the culture created, either through action or inaction. But until an entity, organization or culture reaches the desired state of ethical decision-making and compliance, auditors are all we’ve got.
And thus the need for resources to help auditors detect fraud, such as this great site hosted by the DoD Inspector General. The DoD IG site contains lots of resources for fighting fraud, including “Red Flags and Indicators,” “Contract Audit Fraud Scenarios and Resources,” and “Other Fraud Scenarios and Indicators.” Granted, some of the scenarios and indicators are intended for governmental use but they can be easily tailored for use by contractors.
There is even a set of quizzes to test one’s “Fraud IQ”. Go on, take the quizzes. You take all those quizzes on Facebook, don’t you?
But that’s not all.
We also found an Air Force Procurement Fraud Indicators Handbook, written in 2008. We located a 2012 PowerPoint slide deck from a presentation made by Jim Ratley (ACFE) to the Institute of Internal Auditors entitled Corporate Fraud Awareness in Today’s Global Regulated Environment. And we also dug up a book by the OIG of the National Science Foundation called Possible Grant Fraud Indicators.
And those were all returned within the first ten hits of a Google search using the phrase “fraud indicators.” We did not even look at the other 60 million hits Google returned.
The point is that there are many, many resources available for fighting fraud and corruption. And such resources need not be used only by auditors. They can – they must be – used by organizational leadership to drive behavior and decision-making toward a state where ethics and compliance is simply a part of the entity’s culture.
The resources to fight fraud and corruption are readily available.
But is the willingness?
Tone at the Top
You know we don’t like to post and repost and repost again the litany of fraud and corruption stories that flush down the sewer pipes of the internet like polluted storm runoff spills into the local lakes and beaches. The ones who might benefit from reading those stories don’t look for them, or don’t believe they apply. Fraudsters don’t think they can get caught, or they don’t think they have any other options available. So it doesn’t matter what we post to the ones who need to change.
And our passionate pleas for action and accountability at the top of the pyramid, for the “tone at the top” to be more than merely a tone, to be a full orchestrated symphony of internal control and monitoring, similarly falls on deaf ears. The ones who need to lead their organizations don’t look for them, or don’t believe they apply. Negligent leaders don’t believe they need to do any more, or think they have other, more pressing, priorities. So it doesn’t matter what we post to the leaders who need to change.
In one of our screeds (link above), we wrote –
“When you find an entity where senior leadership is not being held accountable for its actions (or inactions) then you can be fairly certain you are going to find corruption and fraud somewhere lower in the organization.”
With those depressing thoughts in mind, consider this recent news story published by The Washington Post. Written by Craig Whitlock, the story discusses gratuities accepted by three Admirals and how, as a consequence, they were censured. According to the story –
Navy officials said the three admirals improperly accepted ‘extravagant dinners’ and other gifts from Leonard Glenn Francis, a Malaysian defense contractor who made a fortune by supplying Navy vessels at Asian ports until his arrest in 2013. The three officers — Rear Adm. Michael Miller, Rear Adm. Terry Kraft and Rear Adm. David Pimpo — were sanctioned for misconduct committed in 2006 and 2007, when they were assigned to the USS Ronald Reagan aircraft carrier strike group.
The three Admirals did not act alone. As Mr. Whitlock reported—
Francis, known as ‘Fat Leonard’ in Navy circles for his girth, pleaded guilty in federal court last month and could face up to 25 years in prison. He admitted to bribing 'scores' of Navy officials with prostitutes, envelopes stuffed with cash, luxury travel and other enticements in exchange for classified information that he used to cinch federal contracts.
Five current and former Navy officials have also pleaded guilty in the case; two others are facing federal criminal charges. Prosecutors say more indictments are likely, especially now that Francis has agreed to cooperate with investigators. The Navy has said it expects to mete out discipline in the coming months to still more officers whose misconduct was not criminal in nature but who may have violated ethics rules.
Now, it’s not like this situation sprung up suddenly like Venus arose from the waves. We’ve been following it for some time. And we’ve clearly noted that this is not just a Navy problem; it’s a DoD-wide problem. For example, we reported that one Major General was called on the carpet for ethics violations. Meanwhile, a former US Air Force Lieutenant General just agreed to pay $125,000 to settle claims that he engaged in prohibited a conflict of interest after he left military service and became the CEO of Mav6, LLC, a privately owned defense contractor.
And while all this is going on, the lower ranks have their own stories of bribery and corruption. For example, here and also here.
As we asserted long ago, when you find an entity where senior leadership is not being held accountable for its actions (or inactions) then you can be fairly certain you are going to find corruption and fraud somewhere lower in the organization. We offer this blog article as evidence in support of that assertion.
Let’s put this into perspective, shall we?
While Contracting Officers and Contracting Specialists and contractor compliance folks are arguing over complex FAR and DFARS rules, while smart people with experience and training are arguing over the interpretation of a FAR clause or arguing over the interpretation of a recent legal decision, these military officers (who have risen to the top echelons of their professions) are wantonly and blatantly ignoring the most fundamental ethical precepts. While acquisition professionals publicly debate the authority granted to a Contracting Officer’s Representative or whether a Task Order can be modified after the expiration of the underlying ID/IQ Period of Performance, these leaders are accepting gratuities and proffering “classified information.”
Or, as Vern Edwards recently posted on WIFCON after a lengthy debate by seriously competent people about an arcane point —
… I'm leaving this petty crap topic behind me and moving on to more important topics in acquisition -- like the sources of workforce competence, the nature of services, the nature and principles of acquisition strategy, and the effectiveness of competition policy. I'll be damned if I'll spend my last years in this business arguing about COR authority rules when we don't know how to buy IT in a world in which IT is crucial to our national security and public well-being. … We've got serious problems in acquisition, what with Supply Corps admirals being admonished and relieved for accepting the services of prostitutes provided by ship husbanding contractors and a workforce that is losing respect, trust, self-esteem, and control of its own professional destiny.
Mr. Edwards was correct, as is usually the case. It’s human nature to focus on the little risks and to ignore the bigger problems. And make no mistake, the Department of Defense has some really big problems that desperately need to be solved.
It’s time for some acquisition leaders to emerge and to be listened-to. It’s time for the new SECDEF to shake things up, to up-end the status quo, and to implement some serious internal controls that act to detect and deter wrongdoing by the military and the acquisition folks that support them.
|
Sanders Presenting at Joint NCMA/AGA Educational Seminar
Nick Sanders, Principal Consultant of Apogee Consulting, Inc., will be a presenter at an upcoming educational seminar jointly sponsored by the San Diego Chapters of the National Contract Management Association (NCMA) and the Association of Government Accountants (AGA).
On Wednesday, March 18, 2015, Mr. Sanders will be participating in a seminar entitled “Estimating, Proposing and Analyzing Material & Subcontracts” along with Tom Schmitz (former Manager of Estimating and Pricing for Raytheon’s Space and Airborne Systems division), Leann Densley, and Jose Gutierrez (DCMA Cost/Price Analysts). The 3 hour seminar will cover such topics as:
-
How to support proposed material and subcontract costs
-
Ten ways a supplier/subcontractor can improve proposals
-
Documentation required to support acquisitions of commercial items
-
How the Government analyzes proposed material and subcontract costs
-
Performance of Cost Realism analyses
-
Government evaluations of prime contractors’ Cost/Price analyses
-
Providing cost or pricing data from subcontractors to prime contractors
-
When a prime contractor should request assist audits from DCAA and/or DCMA
-
Price Reasonableness and what happens if a prime contractor cannot support the reasonableness of subcontract pricing
Location: San Diego, CA
Cost: $75 for NCMA/AGA members, $100 for non-members
Register online at www.ncmasd.org
DOE IG Concerned About Lack of DCAA Audits
DCAA can’t catch a break.
First, NASA’s Office of Inspector General voiced concerns about DCAA’s decision to use a “risk-based” approach to determining which contractor annual proposals to establish final billing rates it chooses to audit. Those annual proposals – also known as “incurred cost proposals” – are used by Contracting Officers to determine final contract prices for cost-type contracts (and some other types such as Time & Materials). The audit of those annual proposals, historically performed by DCAA, is the primary means by which the NASA Contracting Officers ensure that NASA is paying only allowable, allocable and reasonable direct and indirect costs.
Did we say primary means? We meant to say only means. Only. As in, the NASA IG found that “NASA contracting officers relied almost exclusively on DCAA’s incurred cost audit process to identify unallowable, unreasonable, and unallocable costs. Contracting officers we spoke with pointed to these audits as their only means of identifying questioned costs.” Only. That’s what we meant to say.
Without DCAA performing audits of the annual proposals submitted by NASA contractors, the NASA COs were simply not going to have the means to identify any unallowable costs. That was not a great position in which to find the Space Agency, according to its Inspector General.
The NASA OIG was concerned that DCAA’s new risk-based approach to audit triage was going to create more risk for the Space Agency. We agree with that assessment and, indeed, voiced similar concerns about 36 months ago. And we were not alone in noting some concerns. As we wrote in another blog article, GAO issued a report that rang some alarm bells. We noted that “… there are many parties—both within and outside of government—who think the current DCAA approach to managing its audits has left the Defense Department in an untenable position.”
So to recap the past 36 months of history, DCAA changed its audit approach such that certain contractor annual proposals to establish final billing rates would no longer be reviewed. The GAO issued a report voicing some concerns about that new approach. The DoD Inspector General issued a report voicing some concerns about that new approach. The NASA Inspector General issued a report voicing some concerns about that new approach. We wrote some blog article voicing some concerns about the new approach.
And now the Department of Energy Inspector General has issued a report voicing some concerns about the new approach.
Readers not familiar with DOE’s contracting environment should know that there are basically two types of DOE contracts. There are the humongous Management & Operating contracts and then there’s everything else. There are 28 M&O contracts, all of which are cost-reimbursable, and all of which are really, really large. The M&O prime contractors engage hosts of subcontractors to perform the required work. According to the DOE IG, the DEARS 970 regulations state that those M&O primes are responsible for auditing those subcontractors when the subcontract prices are dependent on costs incurred. In the words of the DOE IG –
When these subcontracts are structured as cost-type, including time and materials, and cost reimbursable subcontracts, M&O contractors are contractually required to ensure that associated costs incurred are audited to provide assurance that the costs are allowable. The M&O contractors may use their internal audit staff, engage contract auditors, or use the services of the Defense Contract Audit Agency (DCAA) to audit the subcontractors. Internally performed audits must, at a minimum, meet professional standards prescribed by the Institute of Internal Auditors. M&O contractors presumably rely on audits of subcontractors when completing required annual certifications that all of their incurred costs are allowable.
The DOE IG had concerns with the M&O primes’ lack of procedures to assure that their subs were being audited. But that’s not what we’re going to discuss in this article. Instead, we are going to discuss the rest of the DOE contract environment – the non-M&O contracts. Just to put things into perspective, the universe of non-M&O contracts includes (but is not limited to) “more than 40 prime contracts valued at more than $90 billion” which involves “annual expenditures of about $5 billion” within the DOE’s Office of Environmental Management. In addition, the National Nuclear Security Administration (NNSA) has “several” non-M&O contracts, “including the nearly $5 billion contract to construct the Mixed Oxide Fuel Fabrication Facility at the Savannah River Site in South Carolina.” So while the M&O contracts may get a lot of management (and Congressional) attention, the fact of the matter is that the non-M&O contracts are a non-trivial part of the DOE’s spending.
In its report on the non-M&O contract universe, the DOE IG stated –
Historically, the Department has met its non-M&O contract cost audit requirements through an agreement with the Defense Contract Audit Agency (DCAA). … However, over the past several years, as responsible Department officials confirmed, DCAA has been unable to perform many of its audits on a timely basis. In fact, DCAA itself reported delays from 1 year to more than 8 years for audits of the Department's non-M&O contracts and related Department-funded subcontracts. These delays resulted in a backlog of audits of contracts and subcontracts with incurred costs valued at billions of dollars per year.
DCAA has been unable to meet the non-M&O contract audit needs of the Department and has asserted that it simply does not have the resources to meet all Department of Defense and civilian agency audit requests. As it pertains to the Department, this situation was exacerbated by the fact that the Department lacked a comprehensive strategy to ensure that non-M&O contractor costs were subjected to necessary audits.
Looking inside the audit report, the DOE IG found that –
To illustrate the magnitude of this problem, as of the date of our review, of the 16 largest Environmental Management non-M&O contractors:
- Seven had never had an incurred cost audit;
- Six had only received audits of costs incurred in 2010 or earlier
- Only three had received relatively current audits of costs incurred in 2012 or later
As the DOE IG noted, the Contract Dispute Act has a 6-year Statute of Limitations, the expiration of which makes recovery of improperly billed costs difficult, if not impossible. (We’ve written extensively on the CDA SoL.) The DOE IG found that DCAA’s inability to support the DOE’s audit needs with respect to non-M&O contractors impeded its ability to administer those contracts effectively. The DOE IG wrote –
Thus, significant delays in the contract audit process, such as the delays the Department has already experienced, would likely make it impossible to recover contractor incurred costs even if they are ultimately found to be unallowable. A recent Department contracting officer decision illustrates the impact of the statute of limitation issue: the Contracting Officer for the nearly $5 billion Shaw AREVA MOX Services, LLC (Shaw AREVA) contract recently suspended DCAA’s work on the 2005 Shaw AREVA incurred cost audit because she concluded that the statute of limitations had expired, rendering it impossible to recoup any questioned costs. Although DCAA is currently working on Shaw AREVA's 2006 incurred costs, the risks associated with exceeding the statute of limitations on this and other contracts remains.
The DOE IG discussed DCAA’s “risk-based” approach to choosing which contractors’ submissions to audit. It stated –
DCAA has initiated action to reduce its backlog of audits, but its actions to date have primarily targeted the Department of Defense and have not directly benefited the Department [of Energy]. … While DCAA's Low-Risk Incurred Cost Initiative has reduced the backlog of contract audits at the Department of Defense, its implementation at the Department in its current format would result in the failure to audit a majority of the Department's non-M&O contracts. Specifically, only about 20 percent of the Department's non-M&O contractors' incurred cost submissions would be subject to mandatory audit, with the other 80 percent identified as low risk and only subject to being randomly selected for audit. Thus, over time, as additional contracts are awarded, the Department's backlog of unaudited contracts would likely grow more severe. The practical impact of such action is to limit the Department's access to an important tool that helps detect and prevent contractor claims for questionable costs. In our view, this is an unacceptable risk going forward
The audit report discussed means by which DOE had “supplemented” the audit gaps left by DCAA’s inability to perform timely incurred cost audits. Those supplemental approaches included hiring a public accounting firm and hiring non-M&O contractors’ internal auditors to audit the submissions of other contractors. The IG also reported that “the Environmental Management Consolidated Business Center, which provides Environmental Management customers with business and technical support services, including contracting support, has explored the possibility of standing up its own audit function or utilizing independent public accounting firms to conduct incurred costs audits.” The DOE IG found those supplemental approaches “laudable.”
Nonetheless, the DOE IG made a couple of recommendations to address the gap in audit coverage of the non-M&O contractors. It recommended that the DOE –
-
Coordinate with DCAA to develop and implement an acceptable version of the risk-based audit approach to incurred cost audits.
-
Develop a comprehensive strategy to supplement DCAA’s [lack of] audit coverage until the backlog of unaudited contractor submissions is eliminated.
The DOE IG found management receptive to its recommendations. It reported –
Department and NNSA management concurred with each of the report's recommendations and indicated that corrective actions had been taken or were planned to address the identified issues. Specifically, Department management noted that it has stated its expectation that required audits must be obtained, whether from DCAA or KPMG; has issued guidance to that effect; has put a contract in place for audit services to ensure Contracting Officers have an alternative to DCAA to obtain quality audits; is coordinating closely with DCAA on its audits; and is following up with contracting activities to ensure they understand what is expected and have the appropriate support. Department management also noted that they believe it is important to recognize that whatever good intentions DCAA has, its track record makes it prudent to avoid assuming a marked change in DCAA's support. Additionally, they stated that all stakeholders, not just the report's addressees, have a role in ensuring required audit support is obtained.
To sum up, the Department of Energy seems to have recognized that it can no longer count on DCAA to provide the level of incurred cost audit support that it needs. It has developed alternatives, including awarding an audit support contract to KPMG. That’s all well and good.
But what is not being addressed is how DOE will implement its recent management decision to embrace the DFARS business systems administration regime. As we reported, “DOE has adopted a similar, yet subtly different, approach to contractor business system administration [than that used by DoD].” Though there are differences, the concept is much the same: non-M&O DOE contractors may be subject to payment withholds if their business systems are found to be inadequate.
Readers may recall that the DoD has experienced growing pains with its approach to administering the business systems rules – so much so that it has proposed to dramatically reduce DCAA’s role in the processes. Given the risks and concerns regarding DCAA’s audits of DOE contractors’ proposals to establish final billing rates, we wonder if DOE management is second-guessing its decision to embrace the DoD’s approach to administering contractor business systems, which at present is heavily reliant on DCAA’s participation.
|