A sheet metal fabricator in the Midwest — call them R&M Fabrication — held three federal subcontracts, each under $750,000. They had a compliance program. It was in a three-ring binder in the owner's office, written by a consultant four years earlier, and it said all the right things: anti-kickback policy, gift policy, a paragraph about the False Claims Act, a complaint mechanism that directed employees to talk to the owner. It existed. It was not a functioning program.
When a routine audit by the prime contractor's compliance team surfaced a subcontractor billing error — $14,000 in labor charges that had been allocated to the wrong contract — R&M's binder didn't help. The auditor wanted to see evidence that the compliance program was operational: training records, internal monitoring documentation, evidence that the complaint mechanism had been communicated to employees, documentation of any prior self-assessment. R&M had none of it. The billing error turned out to be a genuine clerical mistake, not fraud. But the gap between R&M's written program and its actual practices became the audit's primary finding — and it cost R&M two of its three subcontracts.
That gap — between having a compliance program and operating one — is where most small federal contractors are exposed, and most don't know it until someone looks.
The mandatory disclosure rule and why it matters
Federal Acquisition Regulation (FAR) 52.203-13 requires contractors to disclose certain violations — credible evidence of fraud, conflicts of interest, and bribery related to a federal contract — to the agency's Office of Inspector General. This isn't a suggestion; it's a contract clause that applies to contracts over $6 million and subcontracts over $6 million under such contracts. Failure to make a required disclosure can result in suspension or debarment, and the disclosure obligation is the reason your compliance program needs to actually detect things.
A program that exists on paper but doesn't conduct internal reviews, doesn't train employees on what to report, and doesn't have a functional mechanism for receiving complaints has no realistic way to detect the kinds of violations the mandatory disclosure rule requires you to report. You can't disclose what you never discover. And a failure to disclose what a functioning program should have discovered looks worse to a contracting officer than the underlying violation in many cases.
The False Claims Act exposure
The False Claims Act (31 U.S.C. § 3729) imposes treble damages and per-claim penalties — currently $13,946 to $27,894 per false claim — for knowingly submitting false claims to the government. “Knowingly” includes acting with deliberate ignorance or reckless disregard for the truth of the information. This is where small contractors often stumble: they assume the standard is intentional fraud, so a clerical error feels safe. It's not. Reckless disregard — which can mean failing to implement reasonable controls against billing errors — meets the statutory knowledge standard.
The practical consequence is that a contractor with poor internal controls who submits inaccurate invoices may face False Claims Act liability even if nobody intended to defraud anyone. The billing error itself might be small. The treble damages and per-claim penalties are not. And the reputational consequence of a False Claims Act settlement or judgment can end a small company's ability to compete for federal work entirely.
What “adequate” actually looks like
The U.S. Sentencing Guidelines' criteria for an effective compliance program (§8B2.1) provide the framework most courts and agencies use to evaluate whether a contractor's program is real. The elements include: standards and procedures to prevent and detect criminal conduct; a designated compliance officer or point of contact; training and communication; monitoring and auditing; consistent enforcement and response; and periodic assessment and improvement.
For a small contractor, this doesn't require a dedicated compliance department. It does require documented evidence that each element exists and operates. Specifically:
Training records showing that employees have been trained on the compliance policies relevant to their role — particularly employees involved in billing, timekeeping, and contract administration. Annual training with sign-off sheets meets the bar. A binder that nobody reads does not.
Internal monitoring — even informal — that demonstrates someone is reviewing billing accuracy, timekeeping against task orders, and material sourcing against contract requirements. For a small fabricator, this might be a monthly spot-check by the owner or office manager, documented with a date and any findings. The documentation matters as much as the activity.
A complaint mechanism that employees actually know about and believe they can use without retaliation. An open-door policy with the owner can work — but it has to be communicated in writing, and there should be an alternative path (even an email address) for situations where the complaint involves the owner.
Documented corrective actions when issues are identified. If the monthly spot-check finds a billing error, the correction and the steps taken to prevent recurrence need to be documented. This is what auditors look for: not a perfect record, but evidence that the system catches problems and responds to them.
The OBBBA dimension
The One Big Beautiful Bill Act's federal contracting provisions are still being implemented as of mid-2026, but the direction is clear: increased accountability for contractors and subcontractors, with compliance infrastructure as a factor in contract award decisions. Small businesses bidding on federal work should expect compliance program quality to receive more scrutiny in the evaluation process, not less. The contractors who are building these systems now — even imperfectly — will be better positioned than those who wait until a specific regulation requires it.
The practical steps most contractors skip
The steps that separate a functioning compliance program from a binder on a shelf are not expensive or complicated. They just require consistent execution:
Conduct an internal billing review quarterly. Pull a sample of invoices submitted in the previous quarter, compare them against timesheets and material records, and document what you checked and what you found. Even a clean review is valuable documentation.
Train your employees annually. Use plain language. Cover the False Claims Act, the mandatory disclosure obligation, how to report concerns, and the company's anti-retaliation commitment. Document attendance. Keep the records.
Review your compliance program annually. Ask whether the policies still match your current contracts, whether the complaint mechanism is functioning, and whether any new contract requirements have created gaps. Document the review and any updates made.
If you discover a potential violation — even a small one — get legal advice before deciding whether it triggers a mandatory disclosure obligation. The cost of a legal consultation is trivial compared to the cost of failing to disclose something you should have.
The bottom line
The gap between a compliance program on paper and a compliance program in practice is where small federal contractors are most vulnerable. The program doesn't need to be sophisticated. It needs to operate, and it needs to leave a documentary trail showing that it operates. R&M Fabrication's binder said all the right things. What the auditor found — or rather, didn't find — was any evidence that anyone had ever acted on it. Don't be R&M.
This article is for educational purposes only and does not constitute legal, tax, or financial advice. Consult a qualified professional for guidance specific to your situation.