Skip to main content

Risk-based approach to monitoring contractor business systems

Division A · Title VIII: Acquisition Policy, Acquisition Management, and Related Matters · Subtitle A: Acquisition Policy and Management

Plain-language summaryAI

The law requires the Department of Defense to use a risk-based method to monitor contractor business systems, focusing only on necessary reviews that align with commercial best practices or industry standards. Reviews of these systems generally occur no more than once every three years unless problems are detected, and contractors can submit internal reports to be considered during reviews. If significant weaknesses are found, the Department will work with contractors to create corrective action plans and may use other legal remedies as needed.

AI-generated from this section’s text — a quick orientation, not a substitute for the full text below. Not legal advice.

Section Text · Sec. 808.

(a) Requirement for risk-based approach

Section 3843 of title 10, United States Code, is amended to read as follows:

3843. Contractor business systems: monitoring and surveillance standards

(a) Requirement for risk-based approach

The Secretary shall implement an agile, streamlined risk-based approach to surveillance of contractor business systems that—

(1)

minimizes the requirements for the surveillance of contractor business systems to only those that are necessary to conform with commercial best practices or industry standards, as applicable;

(2)

integrates the surveillance of contractor business systems into the Defense Contract Management Agency’s standard surveillance framework, and requires that any additional reviews be risk-based and informed by the results of those standard surveillance activities; and

(3)

allows a contractor to provide internal reports in connection with such standard surveillance activities and targeted reviews, and ensures that any such report is considered in the course of reviewing the contractor’s business systems.

(b) Minimum requirements for surveillance

In establishing the minimum requirements for surveillance under subsection (a)(1) for each type of contractor business system, the Secretary shall ensure that such requirements do not exceed the minimum requirements that are necessary to conform with commercial best practices or industry standards, as applicable, for that type of system.

(c) Surveillance and review

(1)

Except as provided in paragraphs (2) and (3), in implementing the requirements of this section, the Secretary shall ensure that the frequency of review of a contractor business system shall be not more than once every three years, unless the standard surveillance activities under subsection (a)(2) indicate that the system has or may have a material weakness.

(2)

In a case in which the contractor is a company that is subject to the securities laws, if a registered public accounting firm attests to the internal control assessment of the contractor, pursuant to section 404(b) of the Sarbanes-Oxley Act of 2002 ( 15 U.S.C. 7262(b) ), and certified documentation from such registered public accounting firm reflects—

(A)

the unqualified opinion of such firm with respect to the contractor business system, such documentation shall eliminate the need for further review of the contractor business system by the Secretary;

(B)

a qualified opinion of such firm with respect to the contractor business system, the Secretary shall review only those aspects of the contractor business system as to which the opinion was qualified rather than unqualified; and

(C)

an adverse opinion of such firm with respect to the contractor business system, the Secretary shall take action under paragraph (1) or (2), or both, of subsection (d).

(3)

Notwithstanding paragraph (2), the Secretary may establish a profit-based exemption for cases in which the contractor is a company that is subject to the securities laws. Under the exemption, the contractor business system of such a contractor may be exempt from further review by the Secretary if the level of profit of the contractor, taking into account all contracts of the contractor with the Department, is below a threshold level established by the Secretary.

(d) Corrective actions and remedies

The approach implemented under subsection (a) shall ensure the following:

(1)

If the Secretary determines under subsection (c) that a contractor business system has a material weakness, appropriate officials of the Department will be available to work with the contractor to develop a corrective action plan defining specific actions to be taken to address the material weakness and a schedule for the implementation of such actions.

(2)

The Secretary may pursue any other remedies that may be available under the contract or under any other applicable law and regulation.

(e) Guidance and training

The approach implemented under subsection (a) shall provide guidance and training to appropriate Government officials on the approach, the requirements and limitations in subsection (c) that apply to companies that are subject to the securities laws, the data that is produced by contractor business systems, and the manner in which such data should be used to effectively manage Department programs.

(f) Definitions

In this section:

(1)

The term contractor business system means an integrated set of internal controls, processes, procedures, personnel, and information capabilities that a contractor uses to plan, execute, monitor, and report on its performance of Government contracts in a manner that is accurate, consistent, auditable, and compliant with clear and specific business system requirements that are identified and made publicly available.

(2)

The term material weakness means a deficiency or combination of deficiencies in the internal control over information in contractor business systems, such that there is a reasonable possibility that a material misstatement of such information will not be prevented, or detected and corrected, on a timely basis. For purposes of this paragraph, a reasonable possibility exists when the likelihood of an event occurring—

(A)

is probable; or

(B)

is more than remote but less than likely.

(b) Implementation

The initial approach required by section 3843 of title 10, United States Code, as added by subsection (a), shall be implemented not later than December 1, 2027.

(c) Report on implementing approach and defining minimum requirements

(1) Agreement

Not later than 90 days after the date of the enactment of this Act, the Secretary of Defense shall enter into an agreement with the acquisition research organization described in section 4142(a) of title 10, United States Code, requiring the organization to—

(A)

document and evaluate commercial best practices and industry standards for each type of contractor business system, as described in subsection (b) of such section 3843; and

(B)

make recommendations for the approach required by subsection (a) of such section 3843.

(2) Report

Not later than 90 days after the date on which the Secretary and the organization enter into the agreement required by paragraph (1), the organization shall submit to the Secretary a report on the results of the activities carried out under paragraph (1).

(3) Consideration of report

In implementing the initial approach required by subsection (a) of such section 3843, and in defining the minimum requirements for contractor business systems under subsection (b) of such section, the Secretary shall take into account the report submitted under paragraph (2).

(d) Repeal of contractor business systems improvement program

Section 893 of the Ike Skelton National Defense Authorization Act for Fiscal Year 2011 ( Public Law 111–383 ; 10 U.S.C. note prec. 3841) is repealed.