Skip to content
The Defense Acquisition Newsletter

The Expanding Reach of Procurement Fraud Enforcement

Leslie Faircloth
Leslie Faircloth

8 The Fraud Landscape

The Department of Justice (DOJ) is aggressively escalating its pursuit of procurement fraud, utilizing the False Claims Act (FCA) to recover a record-breaking $6.8 billion in settlements and judgments in Fiscal Year 2025 alone. However, the most significant danger for small businesses is no longer traditional billing fraud—such as intentionally overcharging or failing to deliver goods. Instead, the greatest risk lies in the rapid expansion of "certification-based liability".

Under this model, the government uses ancillary compliance representations as the legal hook for FCA enforcement. Today, your certifications regarding cybersecurity, anti-discrimination (DEI), and trade compliance carry the exact same fraud risks as your financial invoices. The DOJ's Civil Cyber-Fraud Initiative is actively prosecuting contractors who misrepresent their cybersecurity posture, while the new Civil Rights Fraud Initiative is targeting companies that falsely certify compliance with civil rights laws. To make these cases easier to prosecute, the government is now explicitly writing "materiality" findings directly into contract clauses—such as the new mandatory DEI clause under EO 14398—intentionally strengthening their hand against one of the strongest legal defenses contractors have.

Furthermore, the threat of whistleblowers has evolved. Driven by a record 1,297 qui tam suits filed in FY 2025, the DOJ recently launched the FOCUS initiative to collaborate directly with professional "data miners". These are external whistleblowers who use data analytics and public databases to spot contractor compliance anomalies without ever setting foot inside your company.

Finally, if you do discover an internal compliance failure, navigating the disclosure process has become a legal minefield. While the FAR mandates disclosure of credible evidence of misconduct to the agency's Inspector General, the DOJ's new Corporate Enforcement Policy (CEP) only offers leniency and declination of prosecution if you voluntarily self-disclose directly to the DOJ.

STRATEGIC ACTION PLAN FOR YOUR BUSINESS

As your advisor, I must warn you that the line between a routine regulatory violation and a serious fraud investigation has practically vanished. Here is how you must adapt:

  • Treat Every Certification as a Fraud Risk: The FCA relies on a "reckless disregard" standard, meaning you do not need an actual intent to deceive to be found liable. Every operational function that provides information your company later certifies—including human resources (for DEI), IT (for CMMC), and your supply chain (for trade)—must be rigorously audited to ensure your actual day-to-day practices match what is written in your proposals.
  • Resolve the Disclosure Dilemma Early: If you discover a significant compliance issue, coordinate with outside legal counsel immediately to sequence your response. You must now determine in real-time whether a failure triggers a mandatory IG disclosure under FAR 52.203-13, warrants a strategic voluntary disclosure to the DOJ to seek CEP cooperation credit, or both.
  • Heed Internal Complaints: The fastest way to invite an FCA lawsuit is to ignore your own employees. Insiders have direct visibility into the gaps between your certified policies and actual practices, especially in new, fact-intensive areas like cybersecurity and DEI. Ensure you have robust tracking for internal hotline complaints and investigate red flags immediately.

Credits & Further Reading: This critical analysis is based on "The Evolving Procurement Fraud Landscape: Emerging Risks for Government Contractors," authored by Jessica Tillipman and Sarah Needham, published in Thomson Reuters' Briefing Papers and the GW Law School Public Law and Legal Theory Paper No. 2026-42.

Share this post