The Federal Government Should Stop Paying for the Same Assurance Twice

Lohfeld Consulting
Night view of the U.S. Capitol lit up at night, with its reflection shimmering in the water.

A commercial-first model for CAS, contract audit, small business, and government-wide acquisition

For decades, the federal government has built specialized systems for protecting public funds: the Cost Accounting Standards (CAS), DCAA audits, contractor business-system reviews, agency-specific qualification processes, and an expanding collection of government-wide and agency-specific contract vehicles.

Most of those requirements were created to solve legitimate problems.

The question today is different: Does every layer still provide enough additional protection to justify its cost?

That question matters because the cost is not limited to contractor compliance departments. Complex federal requirements affect which companies are willing to compete for government work.

A sophisticated commercial company considering federal business may already maintain Generally Accepted Accounting Principles (GAAP)-compliant financial statements, audited internal controls, an internal audit function, independent external auditors, sophisticated enterprise systems, cybersecurity controls, and mature procurement and accounting processes. Yet entering the federal market can require the company to construct an additional government-specific infrastructure alongside the one it already operates.

The better approach is straightforward: Start with the commercial standard the company already meets. Identify the specific federal risk that standard does not address, and add only the control necessary to address that risk.

That principle leads to five significant reforms.

1. Make GAAP the Default and CAS the Exception

The federal government has already begun moving CAS toward GAAP. That direction should become the governing philosophy for the entire CAS framework.

GAAP and CAS do not serve identical purposes. Government contracting raises legitimate questions that ordinary financial reporting does not always answer, particularly concerning the allocation of costs to individual government contracts.

But that distinction should not justify maintaining requirements simply because they have existed historically. Instead, the presumption should be reversed: GAAP governs unless the government can identify a specific federal risk that requires different treatment.

The CAS Board should review the remaining standards individually. Where GAAP adequately addresses the government’s underlying concern, CAS should defer to GAAP. Where a genuine government-specific requirement remains necessary, the government should articulate the risk and retain the minimum additional requirement necessary to address it.

This would not eliminate government cost-accounting protections. It would force those protections to demonstrate their continuing purpose.

Small businesses should remain exempt from CAS.

2. Create a “One Audit” Model

The most significant opportunity may be in contract audit.

The federal government has a legitimate interest in determining whether costs charged to its contracts are allowable, allocable, and reasonable and whether contractor systems adequately protect government funds.

But the government’s need for assurance does not necessarily mean that a government auditor must personally perform every test used to obtain that assurance. DCAA has developed sophisticated government-contract audit programs over decades. Those procedures address matters that an ordinary financial statement audit may not cover. Those procedures have value.

The duplication occurs when a sophisticated contractor has already undergone extensive internal-control and independent audit testing, and the government subsequently creates an entirely separate audit process rather than incorporating the additional government-specific procedures into the existing assurance environment.

For contractors already subject to SOX 404(b), independent financial audits, or equivalent assurance, applicable government-contract procedures could be incorporated into existing audit and internal-control testing wherever practicable.

The objective should be: Perform the test once. Use the result everywhere.

This does not mean declaring that a SOX audit is equivalent to a DCAA audit. It is not. Instead, the government should identify what the commercial audit does not test and add the necessary government-specific procedures to that work.

Nor should reform simply create another mandatory annual CPA certification, a SOC-style report, or an expensive compliance product. That risks replacing one compliance bureaucracy with another.

The government should specify the assurance it requires rather than unnecessarily prescribing an entirely separate mechanism for producing it.

3. Make DCAA the Architect of a Larger Assurance Ecosystem

This model could make DCAA’s expertise more consequential, not less.

There is a fundamental scalability problem with any system in which specialized government auditors must personally perform most of the testing. The government’s ability to obtain assurance becomes constrained by the number of auditors it employs.

DCAA could instead serve as the federal government’s technical leader for contract-audit standards, procedures, and reliance criteria. Its responsibilities could include maintaining government-specific audit procedures; determining where GAAP, SOX, and commercial audit work already provide adequate coverage; establishing criteria for government reliance on work performed by qualified auditors; conducting quality-assurance activities; developing government-wide contract-audit analytics; and directing its own auditors to higher-risk contractors and programs.

DCAA would continue performing audits directly where complexity, risk, referral, or materiality warrants government involvement. Its forensic capabilities and support for complex cost and pricing negotiations would remain particularly valuable.

The difference is leverage. Rather than limiting DCAA’s expertise to the audits its own workforce can physically perform, the government could make DCAA’s methodology the standard against which a much larger assurance ecosystem operates.

4. Stop Treating Small Businesses Like Small Defense Primes

Small businesses require a different model. They are already exempt from CAS, and that exemption should remain. But federal accounting reform should go further than creating a lighter version of a large-contractor compliance checklist.

A five-person business cannot maintain the same segregation of duties as a multinational corporation. Requiring artificial organizational separation may create the appearance of internal control without materially improving assurance.

For small businesses, the government’s core questions should be practical: Can charges to the government be substantiated? Can labor be traced when required? Are indirect costs allocated reasonably and consistently? Are invoices reliable? Are the controls reasonable given the company’s size, contract type, dollar volume, and risk?

Contract type is particularly important. A small business performing a cost-reimbursement contract creates substantially different accounting risk than one delivering a defined product or outcome under a firm-fixed-price arrangement.

That raises a more fundamental question: For many small-business fixed-price acquisitions, is a government-approved accounting system necessary at all? Where the government does not need a requirement, eliminating it is better reform than simplifying it.

5. Qualify Suppliers Once and Compete the Actual Work

The same principle should extend beyond accounting and audit.

Federal contractors routinely qualify for multiple IDIQs, GWACs, schedules, BPAs, and agency-specific vehicles. Each can involve separate solicitations, representations, certifications, qualification requirements, and administrative processes, often to reach substantially the same federal customer.

The government should explore a common government-wide qualification architecture. This should not be confused with one enormous winner-take-all federal contract. A government-wide master agreement could qualify thousands of suppliers across domains and socioeconomic categories. Common representations, certifications, responsibility requirements, and other foundational qualifications could be established once. Agencies would then compete individual requirements among qualified suppliers.

The principle is: Compete the work, not repeated admission to overlapping contract vehicles.

Existing small-business programs, including 8(a), SDVOSB, WOSB, and HUBZone authorities, could remain part of the architecture. Agencies would continue to compete requirements and make source-selection decisions. What would disappear is unnecessary repetition in determining whether the supplier is eligible to participate in the first place.

Implementing such a model would require careful analysis of existing competition statutes, FAR Parts 6 and 16, GWAC and IDIQ authorities, and executive-agent authorities. Some portions may be achievable administratively; others may ultimately require regulatory or statutory changes.

But the complexity of implementation should not prevent examination of the underlying question: Why does one federal customer need so many separate doors through which suppliers must repeatedly qualify to enter?

Reciprocity Should Become the Default

These reforms share one underlying principle that deserves explicit recognition in federal acquisition policy: reciprocity.

If an authorized federal organization has accepted a contractor’s accounting system under a government-wide standard, another contracting organization should not automatically repeat the review. If required audit procedures have already been performed by a qualified auditor and accepted by the cognizant authority, another organization should not automatically repeat them. If a supplier has already established a government-wide qualification, another agency should not require a substantially identical qualification merely because it uses a different contract vehicle.

There will always be legitimate exceptions: material changes, control deficiencies, credible allegations, fraud indicators, unusual contract risks, and independent Inspector General activities.

But duplication should require a reason. The presumption should change from “prove it again” to “rely on what has already been established unless circumstances justify additional work.”

A Commercial-First Federal Marketplace

None of this requires the government to accept greater financial risk. The objective should be the opposite: concentrate federal oversight resources where they produce the greatest marginal protection of taxpayer funds.

Government-specific controls should exist where government-specific risks exist. But when a mature commercial accounting, audit, control, or qualification process already addresses the risk, the federal government should use it.

That provides a simple decision framework for acquisition reform: Start with the commercial standard. Identify the unique federal risk. Add only the necessary control. Perform the resulting assurance once. Accept the result across the federal government.

The federal government should continue protecting taxpayers. It should stop paying—and requiring contractors to pay—for the same protection twice.


By Jacob Bertram, Principal Consultant at Lohfeld Consulting Group

Jacob is a senior leader in the federal procurement industry with over 20 years of experience spanning GSA, the Department of Energy, DCMA, and DCAA. He currently advises Fortune 500 companies, government agencies, and federal contractors on acquisition strategy, pricing, audit readiness, and operational efficiency. Jacob is DAWIA Level III certified in Contracting and a member of the Defense Acquisition Corps.

Lohfeld Consulting Group has proven results specializing in helping companies create winning captures and proposals. As the premier capture and proposal services consulting firm focused exclusively on government markets, we provide expert assistance to government contractors in Capture Planning and Strategy, Proposal Management and Writing, Capture and Proposal Process and Infrastructure, and Training. In the last 3 years, we’ve supported over 550 proposals winning more than $170B for our clients—including the Top 10 government contractors. Lohfeld Consulting Group is your “go-to” capture and proposal source! Start winning by contacting us at www.lohfeldconsulting.com and join us on LinkedInFacebook, and YouTube(TM).