Tracking manual labor in federal contracting isn’t just inefficient, it’s a vulnerability that can bankrupt you. It only takes a spreadsheet and a couple misallocated hours to uncover the gap between a compliant operation and a False Claims Act investigation.
Labor costs sit at the center of every federal audit
Out of all the expenses eligible for reimbursement that a federal contractor requests, labor is the one that auditors delve into the most. Not only is it responsible for most billable expenses in virtually all contracts, but it is also the most easily distorted and the most challenging to recreate if your records are inadequate.
The DCAA (Defense Contract Audit Agency) was established to shield the government from overpayments. Its auditors do not examine the end product of your work since they were responsible for assessing whether the hours you claimed corresponded to the actual work, whether those hours were correctly attributed to the contracts, and whether your records could legally stand. If your response to those queries depends on an Excel sheet or a basic timekeeping platform unsuitable for government contracts while the door hits the audit, you are already falling behind.
Given that the government addresses actual rather than set costs, cost-reimbursable contracts are the most closely screened. They are required to be supported by records that relate to actual costs.
The daily entry rule is not a suggestion
Guidance from DCAA specifies that time needs to be recorded by employees daily and not at the end of the week. This is a verifiable, predefined rule – not an option or a suggestion. Allowing employees to estimate the hours on Friday for time worked on Monday through Thursday is violating the rule, whether this estimated time is correct or not.
This is where manual systems lose their credibility, because they don’t have any. An employee will simply open an excel file, enter the estimated hours that he/she worked over the last five days and save it. No one knows when this data was entered, and there is no way to prove it was entered three days ago. When you are required to show it to the auditor, you can’t.
With an automated system, employees are reminded, logged, and prompted to enter times every day and a record is created to show exactly when it was submitted. This is what you need to prove compliance.
Spreadsheets can’t produce an audit trail
An audit trail is a timeline of all the actions and modifications taken with a timesheet. All of these records must be kept safe from tampering, as the audit trail demonstrates who submitted hours, who tried to falsify records, who approved hours, and even why any changes were made. An audit trail is a necessity rather than an option in DCAA compliance.
With a spreadsheet, there is no audit trail. For instance, when that one cell is edited and saved, the last value is no longer in the system. Sure, you can find tools with version tracking but that’s not an audit trail. That’s an easily manipulated, self-policed free for all. An audit trail tracks everything in a sanctuary of records. An auditor will ask why an employee was switched from Contract A to Contract B three days after submitting their hours. He won’t take “I remember doing that…” or “Here’s an email…” as an answer.
This is where DCAA Compliant timekeeping software becomes a structural necessity. Audit trails are automatically generated within these systems, timesheets are made read-only after final approval, and a hard-copy of the timesheet with all audit trails and approved work is stored for records.
The False Claims Act has a very low bar for “knowing”
It’s not fraud that catches most contractors liable to the False Claims Act. It’s simple administrative error. The FCA doesn’t require you to have intended to defraud the government, just to “knowingly” have submitted false claims. And “knowingly” under the statute includes acting in deliberate ignorance or reckless disregard of the truth.
If your labor tracking process is manual, and manual processes are known to be error-prone, and you kept using them, that’s a defensible path to FCA liability even if no one in your company ever intended to mischarge the government.
The size of the settlements and judgments the government wins reflects how seriously it takes this. The federal government recovered $2.68 billion under the False Claims Act in fiscal year 2023, with procurement fraud and government contracting disputes remaining the largest sources of these false claims. Contractors who win that fight in court still manage to lose it in time, legal fees, and reputation.
Generally speaking, labor mischarging, i.e. assigning hours to the wrong contract, task code, or indirect cost pool, is the most common vector for a False Claims Act case. It’s also the easiest source of claims to prevent.
Floor checks don’t wait for you to get your records in order
DCAA floor checks are surprises. A person arrives, picks a few employees at random, and asks who they are and what they’re working on. The person then reviews your timekeeping to see if those employees have recorded their time against that contract, right now.
If your timekeeping is a spreadsheet an admin updates monthly, it can’t possibly tell you where employees are working today. If they fill out their timesheets on a weekly basis, there is not a current record identifying an employee’s work location. If the spreadsheet is stored on a drive and takes minutes to open and find an entry, you have already flunked the “do things look good?” portion of the review – before anything is audited.
A direct URL, SAML, or other automated access puts the employee’s timesheet directly into their hands from their own computer. They are entering time at the point of work. So when someone walks in, the current state of your labor records can be in front of the auditor immediately. And it matches real life, because that’s how they knew where to charge their time.
Manual errors compound into indirect cost problems
Labor hours impact your indirect cost pools (overhead rates, general, and administrative rates) and those rates are driven by how labor is spread across your organization. Employee hours that are inadvertently charged to the incorrect contract or the incorrect indirect pool result in inaccurate costs.
It may not seem like a big issue, but consider this – one of the supporting documents for your incurred cost submission is the labor distribution report, and this report details any variances between your labor costs in your general ledger and what you reported to the government. If your forward pricing rates are based on your historical rates which include unapproved labor rate increases because of inaccurate labor charging….you can see where I’m going with this.
What is the Labor Distribution Report (LDR)? It’s a report that ties your timekeeping system to your general ledger. Have you ever had a timekeeping system tell you that your numbers are wrong or that you’ve double-counted something or that it puts you over your eight-hour day? No? I didn’t think so. Then how do you prevent inaccurate/invalid charges from ever getting to your general ledger if not by someone providing oversight and approving them before they hit it? That’s the LDR.
Uncompensated overtime is a specific trap for salaried employees
Handling situations where salaried employees work over 40 hours a week creates an added layer of complexity in compliance for which manual processes are unforgiving. Uncompensated overtime (time worked over 40 hours that is not allocated to a direct project) must be tracked in a manual system but is simply viewed as part of the general indirect cost pool. Therefore, uncompensated overtime will not be factored into rates. If you’re not tracking it separately, you’re in essence billing the government and not accounting for the full indirect rate you proposed (which would include uncompensated overtime). That’s an overcharge.
Under DCAA guidelines, you are to spread uncompensated overtime proportionally across all direct projects that the employee works on. This requires daily entry labor with the ability to allocate to projects. It’s not enough to simply record that an employee has worked 45 hours in a week and therefore has accumulated 5 hours of uncompensated overtime, you must also know the daily allocation of those hours down to the quarter hour. A manual system will not accurately be able to timestamp this level of detail. A solid system that captures at least daily and potential multiple daily entries with project-level tracking will.
The cost of switching is lower than the cost of staying
Moving from manual timekeeping to an automated system is not a quick task, but it’s also not a complex one. This is the most efficient approach and it’s a three-step process. First, you must map your current cost structure; in plain English, that means figuring out all contract numbers, task codes, and indirect pools that employees must charge their time to. Second, you configure a compliant system based on the structure identified in the first step, while ensuring employees are selecting pre-approved charge codes, rather than entering free text. Third, and most importantly, you must train each employee and manager on the system and the compliance issues associated with timekeeping.
An automated system is only as good as the information entered into it, and that requires a well-trained user base. Labor charges will always be the people’s data, not the software’s automatically generated data. So, if you don’t have a cultural buy-in to compliance, you won’t get actual compliance in your system. And the fastest way to turn a $7,000 system into a $7 million-a-year problem is to implement it, but then not ‘parent’ the system with training and management buy-in.
Training is more critical than most assume. Many smaller contractors assume there’s no need to train staff on the basics of why daily entry matters and what labor mischarging means legally. They quickly regret making that assumption. Then they make the second mistake of focusing on training administrators on the system mechanics while forgetting that the system is just software. It must serve the processes, not the other way around.