Business leaders collaborate on workflow automation data using a tablet in a corporate office.

CPSR Audit: What It Is and How to Prepare

The Contractor's system for purchasing and subcontracting is referred to as the "Purchase System." It covers aspects such as evaluating quotes, making or buying decisions, vendor selection, price negotiation, placement, order administration, and expediting the delivery of materials.

The Contractor Purchasing System administration is subject to the criteria outlined in DFARS 242.244-7001.

A Contractor Purchasing System Review (CPSR) is conducted when the value of awarded government prime contracts and subcontracts is expected to be more than $25 million over the next 12 months.

The administrative contracting officer (ACO) will consider a wide range of factors when deciding whether a CPSR is needed, including, but not limited to, the Contractor's past performance and the volume, complexity, and dollar value of subcontracts. The review determines the ACO's decision to approve, reject, or revoke authorization for the Contractor's purchasing system.

What is a CPSR Review?

The U.S. Government carries out a Contractor Purchasing System Review in accordance with Federal Acquisition Regulation Part 44. As stated in FAR 44.101, the CPSR is an evaluation of a contractor's purchasing and subcontract management that begins with the identification of the requirement and ends upon completion of subcontract performance.

A CPSR audit is a review that determines the effectiveness of a contractor's purchasing system, incorporating its policies, procedures, and practices. Consisting of a series of steps designed to evaluate the effectiveness of a contractor's purchasing system, a CPSR begins with a review of requirements and progresses to an audit of all relevant policies, procedures, and practices.

The assessment process examines risk management, cost management, supplier selection, and performance evaluation. During the audit, the auditor will review both internal and external documents, interview personnel, and observe activities that are related to purchasing.

Once the CPSR audit is complete, the auditor will prepare a report of their findings. The information will include an analysis of compliance with the DFARS 242.244-7001 criteria and any issues identified during the audit. The Contractor can use this report to assess areas of improvement in their system and make changes as needed.

What is DFARS 242.244-7001?

DFARS 242.244-7001 is a Department of Defense (DoD) regulation that provides guidance and criteria for evaluating contractors' purchasing systems.

It sets forth standard requirements, including risk management, cost management, supplier selection, performance evaluation, and more. The regulation applies to any purchase or subcontract exceeding the simplified acquisition threshold in FAR Part 2.

Additionally, DFARS 242.244-7001 applies to any contract involving subcontracting or the acquisition of supplies or services.

The DFARS adequacy criteria goes into depth across these areas, including:

  • Procurement planning & market research (2 Criteria)
  • Conflict of interest & misconduct (1 Criterion)
  • Competition (2 Criteria)
  • Negotiated procurement (1 Criterion)
  • Cost or pricing data & price reasonableness (5 Criteria)
  • Source selection (3 Criteria)
  • Contract formation and content (3 Criteria)
  • Foreign purchasing and performance (3 Criteria)
  • Procurement administration (4 Criteria)

How to Prepare for a CPSR Audit

Before an audit, the Contractor needs to prepare. Preparation includes gathering all relevant documents and personnel needed for the review. The Contractor should also ensure that their purchasing system is aligned with the requirements of DFARS 242.244-7001.

This effort should involve a self-review of your policies, procedures, and practices to ensure they comply with the regulation.

An organization must confirm the following key indicators before completing a CPSR review.

  1. Ensure competition is maximized for the contract.
  2. Documented records and standardized business processes
  3. Prove the effectiveness of negotiation
  4. Maximize subcontractor performance, and ensure compliance is monitored
  5. Satisfactory small business support program
  6. Successful Self-assessment of system requirements

CPSR Audit Checklist

A CPSR checklist is a helpful tool for contractors to ensure they have fulfilled all requirements before beginning their CPSR audit.

This checklist outlines the fundamental elements when assessing a contractor's purchasing system.

1. Don't Wait

Adequate time and resources are necessary to complete a CPSR. Even if you have not yet reached the $25M threshold, it is prudent to begin preparing for it. Identify the stakeholders and project manager, assess current procedures, and devise a time/resource budget.

2. Evaluate Business Processes & Systems

Data call inaccuracies are a point of weakness. For the CPSR, confirm that your organization's existing business systems can extract the required data. If this is not the situation, an evaluation of systems and a solution must be established before conducting the review.

3. Self-Review

Arrange a preliminary assessment to pinpoint weaknesses and areas for improvement rather than performing an official audit. Ensuring consistent lead times for purchases is a priority for organizations.

4. Procurement Training

Employees should be familiarized with the Procurement Manual, and the training should be recorded. The Procurement Manual should incorporate policies and procedures, but must not detail instructions on how tasks should be carried out. Training on the CPSR process should be provided for staff and senior management, with expectations clearly outlined.

What Happens if I Fail a CPSR Audit?

Less than 1% of first-time CPSR audits are passed. So, if you fail a CPSR audit, don't panic; you are not alone.

But it is important to understand and address the deficiencies that led to the failed review.

First and foremost, contact your assigned Contracting Officer (CO) to inform them of your failed audit. Your CO will then guide the following steps and assist in addressing any issues noted during the review.

To address the problems in a CPSR review, contractors must evaluate processes and procedures, update policies and procedures in the procurement manual, establish controls where needed, and document the changes.

Ensuring that any personnel trained on the new processes know their duties and responsibilities is vital.

Lastly, you must begin preparing for a subsequent audit before being selected for one by your CO.

CPSR Review: Post Evaluation

After a CPSR review, evaluating the audit's success is essential. It is necessary to document any failures and successes that could be replicated in future audits, as well as any areas of improvement that may still need addressing. This will help to ensure an organization remains compliant and is prepared for the following review.

Risk Mitigation & Continuous Improvement

A CPSR audit is only a snapshot; organizations should continuously strive to improve their procurement processes.

To mitigate your company's risk and improve performance, it is important to create a formalized review and evaluation process. This can be done by implementing internal procedures that analyze key metrics such as cost of goods sold, on-time delivery, and supplier performance.

Additionally, an organization should regularly review its procurement manual to ensure its policies are up to date and compliant with regulations.

By taking these steps, organizations can effectively mitigate risk and reduce the likelihood of an audit failure.

Free Guide

Your Guide to Government Compliance

Navigating compliance regulations can be difficult for even the most seasoned of government contractors. Get an overview of top priorities and how Costpoint provides a clear path to compliance.

United States Capitol Building in Washington D.C.

Featured Thoughts

U.S. capitol building in background

Article

What is a CPSR?

A complete guide to the CPSR (contractor purchasing system review). Learn what it is and get tips to manage future audits.

Business leader presenting a strategy to a team in a modern glass-walled meeting room

Article

How to Manage Government Contracts: Best Practices and Strategies

Explore how your business can navigate the complex requirements of managing government contracts.

Business Professionals Reviewing Project Performance Analytics and KPI Charts on Tablet in Team Meeting

Article

Your Material Estimation Process May Work. What Happens When You Must Prove It?

Most proposals don't lose on price. They lose on defensibility. Learn why material estimation traceability is your biggest proposal risk — and what to do about it.

American soldier using a laptop

Article

Deltek Replicon Achieves FedRAMP Moderate Authorization

In a continued demonstration of leadership in cybersecurity compliance, Deltek Replicon has achieved FedRAMP Moderate Authorization—an important distinction for SaaS providers supporting government contractors.

Project Manager Reviewing Multi-Project Gantt Chart Schedule and Timelines

Article

GSA Has Accelerated CUI Compliance: What This Means for Government Contractors Today

GSA’s accelerated CUI framework raises the bar overnight, demanding independent assessments, FedRAMP‑aligned infrastructure, and real evidence of security maturity from contractors. Deltek Costpoint GCCM gives GovCons a head start by delivering a FedRAMP‑authorized, third‑party‑validated environment with the documentation and controls GSA now expects. Contractors leveraging Deltek can move faster, reduce compliance risk, and compete with confidence as requirements tighten.