What Auditors Look for in Your ERP: System Features That Make or Break DCAA Reviews
Summary of Key Points
Your ERP Vendor Said the System Was “DCAA Compliant.” The Auditor Disagrees.
No ERP system is DCAA compliant out of the box. That phrase appears in marketing materials from nearly every GovCon software vendor, and it misleads contractors into believing that purchasing the right software is the same as passing an audit. It is not.
DCAA does not certify or approve accounting software. There is no list of approved systems. What DCAA evaluates is whether your accounting system, the combination of software, configuration, processes, and controls, meets the adequacy criteria defined in SF 1408. The system is a tool. The architecture and the practices around it are what get audited.
This article explains exactly what DCAA auditors look for when they examine your ERP, which system features and configurations matter most, and where the gaps typically hide between what the software can do and what your implementation actually does.
The SF 1408 Framework: What Adequacy Looks Like
Every accounting system audit references the criteria in SF 1408, the Pre-Award Survey of Prospective Contractor Accounting System. These criteria define what your system must be able to do, and they are the framework auditors use to evaluate your ERP.
Segregation of direct and indirect costs. The auditor will verify that your ERP distinguishes between costs charged directly to contracts and costs accumulated in indirect pools at the point of entry. This is a structural requirement. If your staff enters an expense and then a supervisor reclassifies it later, the system technically works, but the process creates audit risk. Auditors prefer systems where the account structure itself prevents misclassification, not systems that rely on after-the-fact correction.
Accumulation of costs by contract. The auditor will pull cost reports by individual contract and verify that labor, materials, travel, subcontractor costs, and other direct charges are traceable to specific cost objectives. Your ERP’s job costing or project accounting module must produce these reports directly from system data. If contract cost reports require manual assembly from multiple data sources, that is a process weakness the auditor will note.
Identification of unallowable costs. The auditor will review your chart of accounts for dedicated unallowable cost accounts and test whether expenses that should be unallowable are actually coded there. They will also sample transactions from your indirect pools and check whether FAR Part 31 unallowable costs have been properly excluded. The ERP must support this segregation structurally, not just through optional tagging that staff may or may not apply.
Interim billing capability. Your system must generate interim cost invoices for cost-reimbursement contracts using your approved provisional billing rates. The auditor will verify that invoice amounts are mathematically correct, that rates match your established provisionals, and that billed amounts are traceable to the underlying cost data in your general ledger.
Consistency with GAAP. Your ERP must support accounting methods that comply with Generally Accepted Accounting Principles. The auditor will review your revenue recognition method, your accrual practices, and your financial statement presentation. Systems that default to cash-basis reporting for government contracts will be flagged.
Timekeeping system integration. While timekeeping is audited separately, the auditor will examine how timesheet data flows into your ERP. If there is a manual step between timesheet approval and labor cost posting, the auditor will test whether that manual step introduces errors or delays. Automated integration between your timekeeping system and your general ledger reduces this risk.
The Features Auditors Actually Test
Beyond the SF 1408 criteria, experienced DCAA auditors evaluate specific system capabilities and configurations that reveal whether the ERP is functioning as intended.
Audit Trail and Change Logging
Auditors look for a complete, unalterable audit trail. Every transaction entry, every modification, every deletion should be logged with a timestamp and user identification. The auditor will test this by selecting transactions and reviewing the change history to verify that the trail exists and is complete.
Systems that allow users to overwrite transactions without preserving the original entry are a serious compliance risk. If an employee changes a time charge from Contract A to Contract B, the original entry and the correction must both be visible, along with who made the change and when. An ERP that permits “edit in place” without logging the original value fails this test.
Access Controls and User Permissions
The auditor will review your system’s user permission structure. Not every employee should have the ability to create journal entries, modify accounts, approve payments, or change billing rates. Your ERP should enforce segregation of duties through role-based access controls.
The specific configurations the auditor checks include: who can create and modify vendor records (to prevent fictitious vendor fraud), who can post journal entries (to prevent unauthorized cost transfers), who can modify the chart of accounts (to prevent uncontrolled account proliferation), and who can adjust billing rates (to prevent unauthorized billing changes).
If your ERP has granular permission settings but you have configured everyone as an administrator, the auditor will flag it. The system has the capability. Your configuration does not use it.
Indirect Rate Calculation
Auditors verify that your ERP can produce indirect rate calculations from system data. This means the system must be able to sum costs within each indirect pool, calculate the appropriate allocation base, and divide to produce the rate, all without exporting data to a separate spreadsheet.
Contractors who calculate rates outside the system, in Excel or a standalone tool, create a reconciliation risk. The auditor will compare the rate calculations in your external tool to the source data in the ERP. If the numbers do not match, or if the reconciliation process is unclear, the rate calculations become suspect.
The ideal configuration produces indirect rates as a standard system report that ties directly to the general ledger. That means no manual steps or external files. Every number is traceable to a posted transaction.
Report Consistency and Reproducibility
The auditor will run the same report multiple times, or request reports for the same period at different points during the audit, and compare results. If the reports produce different numbers, the system has a data integrity problem.
Reproducibility matters because the audit may span months. If your ERP allows retroactive posting of transactions to closed periods, reports generated early in the audit may not match reports generated later. Systems that enforce period-close controls, preventing changes to closed periods without documented reopening and approval, protect against this problem.
Data Integration Points
Every point where data enters your ERP from an external source is a point the auditor will examine. Timekeeping integrations, payroll feeds, bank imports, subcontractor invoice uploads, and inter-system data transfers all represent potential failure points.
The auditor will test whether data arriving through these integrations matches the source system. If your timekeeping system shows 40 hours for an employee in a week but your ERP shows 38 hours, the two-hour discrepancy needs explanation. Automated integrations that include validation checks are more defensible than manual imports that depend on staff accuracy.
Common System Gaps That Create Audit Findings
The system supports compliance, but the configuration does not use it. This is the most common gap. The ERP has the capability to segregate unallowable costs, enforce approval workflows, and produce indirect rate reports. However, the contractor never configured those features, or configured them initially and then disabled them when staff found them inconvenient.
Timekeeping runs on a separate system with no integration. Employees enter time in one system. Someone manually transfers that data to the ERP weekly. The manual step introduces timing gaps, rounding errors, and classification mistakes. The auditor tests the connection between timesheets and labor cost postings, and the manual process fails the traceability test.
Rate calculations live in spreadsheets. The ERP holds the cost data, but rate calculations happen in an Excel workbook maintained by the controller. The auditor asks how the spreadsheet reconciles to the general ledger. If the answer involves manual data entry from system reports, every number in the rate calculation becomes questionable.
Period-close controls are not enforced. The ERP allows transactions to be posted to prior periods without restriction. Month-end reports are not locked. Year-end data can be modified. The auditor discovers that the ICS schedules submitted last June do not match the current system data because someone posted an adjustment to the prior year after submission.
User permissions are too broad. Everyone has administrator access because it was easier during setup. The bookkeeper can modify the chart of accounts. The project manager can adjust billing rates. The accounts payable clerk can approve their own vendor payments. The auditor sees no evidence of segregation of duties.
Preparing Your ERP for Audit
The preparation is not a last-minute exercise. It is an ongoing configuration and maintenance practice.
Verify your access controls annually. Review user permissions and confirm they reflect current roles and responsibilities. Remove access for departed employees. Restrict administrative privileges to the smallest number of users possible.
Enforce period-close discipline. When a period is closed, it stays closed. Any reopening requires documented approval and a clear business justification. This protects the integrity of every report generated from that period’s data.
Test your integrations monthly. Reconcile data between your timekeeping system and your ERP. Verify that payroll postings match payroll records. Confirm that bank imports are complete and accurate. Catching integration errors in the month they occur is infinitely easier than discovering them during an audit.
Run your own audit trail test. Select ten random transactions and trace them from source document to general ledger entry to financial statement. If you cannot complete the trace in your own system, the auditor will not be able to either.
Produce indirect rates from the system. If your rate calculations currently happen outside the ERP, invest the time to bring them into the system. Build the reports. Validate them against your existing calculations. Migrate the process before the auditor arrives.
The Bottom Line
DCAA auditors do not audit your software. They audit what your software produces and how it produces it. A purpose-built GovCon ERP that is poorly configured fails the same audit that a well-configured QuickBooks system passes. The system is the tool. The architecture, the configuration, the controls, and the processes around it are what the auditor evaluates.
If your ERP cannot produce contract cost reports, indirect rate calculations, and a complete audit trail from system data without manual intervention, you have gaps that will surface during the audit. If your access controls do not enforce segregation of duties, your period-close procedures do not protect data integrity, and your integrations do not reconcile cleanly, those gaps will produce findings.
The contractors who pass DCAA accounting system audits consistently are the ones who treat their ERP as compliance infrastructure, not just accounting software. The configuration is intentional. The controls are enforced. The data is reliable. That is what auditors look for.
Need help configuring your ERP for audit readiness? Contact Eubanks Accounting & Advisory for a system evaluation that identifies gaps before the auditor does.
Resources
- DCAA Pre-Award Survey (SF 1408) – dcaa.mil
- DCAA Checklists and Tools – dcaa.mil
- DCAA Contract Audit Manual – dcaa.mil
- FAR Part 31: Contract Cost Principles – acquisition.gov