DCAA Audit
Doing business with the United States federal government has long been a dream of many companies, large and small. With roughly $600 billion spent annually on goods and services, the potential income makes it an attractive option. Especially since the COVID-19 pandemic, more focus has been placed on contracting with small businesses owned and operated by underrepresented communities.
While this may sound attractive, some rules and regulations must be understood before entering into such agreements. A critical element of contracting with the federal government are audits, such as a DCAA audits.
The Defense Contract Audit Agency (DCAA) is responsible for conducting audits and financial advisory services for the Department of Defense (DoD). The DCAA performs independent audits of DoD contractors to ensure government funds are used appropriately and follow applicable laws, regulations, and contracts. The DCAA audit process begins when the agency receives a request from a DoD contracting officer. The contracting officer typically requests the audit because a contractor failed to comply with the contract's specifications.
The DCAA audit process includes reviewing the contractors' accounting systems, contracts, and subcontracts. The DCAA audit process is comprehensive and can take several months to complete. During the audit, the DCAA will evaluate a contractor's accounting system for accuracy, completeness, and efficiency.
What is a DCAA audit, and what are they looking for?
A full DCAA Business System Audit can be the longest and one of the most difficult audits a government contractor can experience. To provide some perspective, at a recent audit of one of our clients, DCAA sent 15 auditors to perform the audit. In general, our experience is that these audits take 12 months to over 18 months for DCAA to perform.
As noted above, the DCAA audit is a comprehensive review conducted by the Defense Contract Audit Agency (DCAA). The DCAA audit process includes examining the contractor's accounting system, contracts, subcontracts, invoices, time records, travel vouchers, and other documents. The DCAA will also evaluate compliance with the Federal Acquisition Regulations (FAR) and the Truth In Negotiations Act (TINA)—the audit results in a report to the contracting officer with findings and recommendations.
Your Guide to Understanding DCAA Compliance
Learn what the DCAA does, what types of audits it carries out and how to get and stay compliant.
DCAA Audit Risk Assessment
Obtaining an understanding of the contractor’s compliance with DFARS 252.242-7006(c) is basically the risk assessment stage of the audit. In the first stage of the risk assessment, DCAA will request the contractor to complete a “Description of System and Controls Designed to Comply with DFARS 252.242-7006” form. The form is 20+ pages long before the contractor provides any information. It is broken into subsystems:
- System/IT Overview and Internal Audit
- Organizational Structure
- General Accounting
- Labor – Timekeeping & Payroll
- Indirect Costs
- Direct Material and Subcontracts & ODCs
- Billing
Each of these subsystems is then broken down further into additional sub-areas that align with the above-mentioned subsystems, where DCAA requests the contractor to provide the below data for each sub-area:
- Summary narrative on how the contractor follows specific system criteria
- ERP/applications and org structure
- Key process flows
- Key controls
- Key policies, procedures, and desk instructions (formal and informal)
- Key personnel
The preparation of information required and completion of this form/request by DCAA is resource intensive and time consuming. By the time this form is completed, the final document to be delivered to DCAA can easily be 75 to 100 pages long. Once the form is received and reviewed by DCAA, the auditors will then expect a complete walkthrough of every area of the accounting system, as described in the request form.
DCAA Audit Detailed Procedures
Once the risk assessment is completed, DCAA will then review your policies, procedures, and practices and compare those to DCAA’s expectations for compliance with each of the 18 specific DFARS criteria for an adequate accounting system. This step will likely involve significant data requests and interviews/discussions with accounting and management personnel.
While the DCAA will work with you to some extent on the timeline for receipt of requested information, they are not known for having significant concern about level of effort required over and above your normal activities.
Also, the term “specific” regarding what constitutes compliance with the DFARS criteria is a bit of a misnomer. Most of the criteria is in relatively broad terms allowing DCAA to use significant judgement in the application of the criteria, so be proactive in understanding the criteria for yourself and provide substantive information that supports your interpretation and practices of compliance with the specific criteria.
Finally, it is essential to note that the DCAA audit process is part of an overall assessment of the DoD contractor's performance. The DCAA audit results are reported to the contracting officers and are used as evidence in any possible legal proceedings.
DCAA Audit Results
The final phase of the audit is for the auditor to determine if there are significant deficiencies related to any of the criteria that require corrective action. Although the DCAA will discuss the issues with you to some extent during the audit, nothing is final until it goes through DCAA supervision. You can’t assume that because nothing was brought to your attention by the auditor during the detailed audit procedures that there won’t be significant findings. In addition, the term “significant” has a large judgmental component and DCAA’s definition may be quite different from your understanding of what is significant. Significant findings will result in significant withholdings on government contract payments to contractors until corrective action is taken.
If significant findings are identified in the report, a whole new phase of contractor effort will be required in responding to the finding, preparing corrective action plans, implementing corrective actions, and having the DCAA back in to determine if the corrective actions were sufficient to correct the deficiency.
What are the different types of DCAA audits?
DCAA audits can arise from various reasons based on reviews from the inspector general offices, cybersecurity audits, voucher verifications checks (VVC), internal controls reviews (ICR), and financial statement audit requests. Each type of audit carries specific criteria that must be successfully addressed for compliance to be achieved and to work as a government contractor.
The DCAA supports several types of audits designed to help the different areas of contracting and payment for goods or services. These include pre-award surveys, which review existing internal controls before awarding contracts; forward pricing rate agreements, which identify fair price allocations among various pricing involved in a contract; submitted cost/price proposals which obtain agreed rates between buyer and seller; incurred costs which assess billed costs after delivery of services or goods; and finally past performance reviews which examine a vendor's current work performance to determine qualification for future contracts.
Prospective contractors need to understand these different types of DCAA audits to prevent any unexpected interruptions or financial losses that could happen due to inadequate preparation or understanding.
1. Pre-Award Audit
The DCAA conducts a pre-award audit before a contract award. This review will determine if the contractor's proposed cost and price are reasonable. Additionally, this type of audit includes reviewing the accuracy of financial information and evaluating internal accounting controls.
2. Post-Award Audit
After a contract award, a post-award audit will ensure that the contractor complies with the contract's requirements. This audit includes examining contracts, subcontracts, invoices, time records, travel vouchers, and other documents.
3. Progress Payment Audit
Progress payment audits are performed at various stages of a contract to verify that payments submitted by the contractor are accurate and per the contract details. The DCAA will also evaluate the contractor's use of funds for labor and materials.
4. Cost Allowability Audit
A cost allowability audit confirms that all costs charged to the government are reasonable, allocable, and allowable under the contract terms and conditions. This type of audit includes examining invoices, time records, travel vouchers, and other documents.
5. Closeout Audit
A closeout audit comes after the finalization of a contract. This process inspects the final costs to ensure that all expenses charged to the government are reasonable and allowable under the contract. The DCAA will also review any claims submitted by the contractor and recommend how to close out the contract properly.
6. Incurred Cost Audit
These reviews inspect a contractor's accounting system for compliance with FAR Part 31 requirements and determine if all costs claimed were incurred and complied with appropriate laws. This incurred cost audit focuses on the propriety of contractors' requests for payments from federal agencies by examining records such as timesheets, cost elements, overhead rates, and other accounts.
7. Procurement System Audits
This contractor procurement system review evaluates a contractor's procurement system processes and internal controls for acquiring property/supplies. This type of audit assesses performance in areas such as source selection, price/cost analysis, negotiation techniques, amount purchased at each procurement level, and administrative practices related to purchasing documents.
8. Forward Pricing Rate Proposals (FPRPs) Reviews
The DCAA reviews forward pricing rate proposals submitted by certain contractors concerning contracting officers' cost negotiations with them. Such reviews range from detailed examinations of accounting systems to limited studies of specific elements of cost proposals.
9. Additional Audits and Reviews
The DCAA also performs a wide range of other reviews, including performance audits to evaluate the effectiveness and efficiency of a contractor's operations, systems audits to assess the adequacy of internal controls, and compliance audits to ensure that contractors are meeting their obligations under the contract. Additionally, the DCAA may conduct investigations into potential fraud or wrongdoing by contractors.
Preparing for a DCAA Audit
Preparing for a DCAA audit can be intimidating but critical in ensuring that your business complies with the requirements of FAR Part 31 and other applicable regulations. Organizations should ensure they have the necessary documentation to pass the audit successfully. This documentation must include having accurate and up-to-date records of all financial transactions, contracts, pricing estimates, labor charges, and other areas related to government contracting.
Before the actual audit, firms should implement their own internal audits to identify any areas of weakness or room for improvement before the official DCAA review. Additionally, it's vital to seek advice from a Certified Public Accountant (CPA) or tax attorney who can advise on any applicable laws that may have changed since the last audit or answer pertinent questions about possible outcomes.
To prepare for an impending audit, contractors must ensure that all accounting systems, policies, procedures, and records are up-to-date and accurate. This inspection includes guaranteeing adequate segregation of duties between departments within your organization and ensuring that all necessary supporting documentation is readily available.
By ensuring your business is organized and having a plan for responding to DCAA audit processes in clear terms, you will have a better chance of passing the audit effectively and avoiding any costly penalties or errors due to improper record keeping.
By taking proactive steps to prepare for a DCAA audit early, organizations can reduce their chances of any adverse outcomes from being audited by a governmental agency.
A DCAA Compliance Checklist for Government Contractors
A DCAA compliance checklist for Government Contractors is essential to ensure that businesses meet all the requirements to pass a DCAA audit.
Your DCAA compliance checklist should include the following steps:
- Ensure that your accounting systems, policies, and procedures are up-to-date and accurate.
- Make sure your organization has adequate segregation of duties between departments.
- Make sure all required documents and information are readily available upon request.
- Make sure that subcontractors and vendors are following the regulations of the contract.
- Have a plan for responding to DCAA audit processes in clear terms.
- Train staff on government contracting regulations to ensure everyone can answer any questions during the review.
- Connect with other government contractors who have gone through similar audits to gain insight into potential points of scrutiny.
- Conduct regular internal audits and seek advice from knowledgeable accounting professionals.
- Review all FAR Part 31 requirements and ensure your business meets them.
By following this checklist, businesses can be better prepared for their DCAA audit and reduce the chances of any negative outcomes.
Your Guide to Understanding DCAA Compliance
Learn what the DCAA does, what types of audits it carries out and how to get and stay compliant.
Related Resources
Guide to Government Contracting
Get the information you need to successfully find win and manage government contracts.Learn More »
How to Find Government Contracts
Get started by finding government contracts that best fit your business.Learn More »
What is DCAA Compliance?
Learn more about DCAA compliance, and how contractors can reduce risk by avoiding and preparing for DCAA audits.Learn More »
Federal Government Contracting
Learn more about federal government contracts and where you can find them.Learn More »
Small Business Contracting
Discover how to find, win and deliver on small business government contracts.Learn More »
Types of Government Contracts
Learn about the four main types of government contracts that contractors encounter.Learn More »
How to Win Government Contracts
Discover how to beat the competition and win more government contracts.Learn More »
Guide to Govcon Compliance
Learn why compliance should be top of mind for all government contractors.Learn More »
What is CMMC?
Learn more about the basics of Cybersecurity Maturity Model Certification (CMMC).Learn More »
What is ITAR Compliance?
Learn more about the International Traffic in Arms Regulations (ITAR) and who it applies to.Learn More »
State & Local Contracting
Learn the basics of state and local government contracts and where you can find them.Learn More »
Basics of FAR & CAS
Learn about the Federal Acquisition Regulation (FAR) and Cost Accounting Standards (CAS).Learn More »