What Auditors Look for in Your ERP: System Features That Make or Break DCAA Reviews

Summary of Key Points

  • DCAA does not certify accounting software or maintain an approved ERP list. Auditors evaluate the complete accounting system—software, configuration, processes, controls, and reporting—against the adequacy criteria in SF 1408.
  • Auditors review whether the ERP properly separates direct and indirect costs, accumulates costs by contract, identifies unallowable expenses, supports interim billing, follows GAAP, and connects timekeeping data to labor cost postings.
  • Key system controls include complete audit trails, role-based user permissions, system-generated indirect rate calculations, reproducible reports, locked accounting periods, and reliable integrations with timekeeping, payroll, banking, and other data sources.
  • Common audit gaps occur when contractors leave compliance features unconfigured, calculate indirect rates in spreadsheets, transfer timekeeping data manually, allow retroactive changes to closed periods, or give users excessive administrative access.
  • Audit readiness requires ongoing maintenance, including annual permission reviews, disciplined period closes, monthly integration reconciliations, transaction-level audit trail testing, and indirect-rate reports that tie directly to the general ledger.

 

Your ERP Vendor Said the System Was “DCAA Compliant.” The Auditor Disagrees.

No ERP system is DCAA compliant out of the box. That phrase appears in marketing materials from nearly every GovCon software vendor, and it misleads contractors into believing that purchasing the right software is the same as passing an audit. It is not.

DCAA does not certify or approve accounting software. There is no list of approved systems. What DCAA evaluates is whether your accounting system, the combination of software, configuration, processes, and controls, meets the adequacy criteria defined in SF 1408. The system is a tool. The architecture and the practices around it are what get audited.

This article explains exactly what DCAA auditors look for when they examine your ERP, which system features and configurations matter most, and where the gaps typically hide between what the software can do and what your implementation actually does.

 

Is Your ERP GovCon-Ready?

Download the free guide to learn how to choose an ERP that supports compliance, audit readiness, and scalable growth.

 

 

The SF 1408 Framework: What Adequacy Looks Like

Every accounting system audit references the criteria in SF 1408, the Pre-Award Survey of Prospective Contractor Accounting System. These criteria define what your system must be able to do, and they are the framework auditors use to evaluate your ERP.

Segregation of direct and indirect costs. The auditor will verify that your ERP distinguishes between costs charged directly to contracts and costs accumulated in indirect pools at the point of entry. This is a structural requirement. If your staff enters an expense and then a supervisor reclassifies it later, the system technically works, but the process creates audit risk. Auditors prefer systems where the account structure itself prevents misclassification, not systems that rely on after-the-fact correction.

Accumulation of costs by contract. The auditor will pull cost reports by individual contract and verify that labor, materials, travel, subcontractor costs, and other direct charges are traceable to specific cost objectives. Your ERP’s job costing or project accounting module must produce these reports directly from system data. If contract cost reports require manual assembly from multiple data sources, that is a process weakness the auditor will note.

Identification of unallowable costs. The auditor will review your chart of accounts for dedicated unallowable cost accounts and test whether expenses that should be unallowable are actually coded there. They will also sample transactions from your indirect pools and check whether FAR Part 31 unallowable costs have been properly excluded. The ERP must support this segregation structurally, not just through optional tagging that staff may or may not apply.

Interim billing capability. Your system must generate interim cost invoices for cost-reimbursement contracts using your approved provisional billing rates. The auditor will verify that invoice amounts are mathematically correct, that rates match your established provisionals, and that billed amounts are traceable to the underlying cost data in your general ledger.

Consistency with GAAP. Your ERP must support accounting methods that comply with Generally Accepted Accounting Principles. The auditor will review your revenue recognition method, your accrual practices, and your financial statement presentation. Systems that default to cash-basis reporting for government contracts will be flagged.

Timekeeping system integration. While timekeeping is audited separately, the auditor will examine how timesheet data flows into your ERP. If there is a manual step between timesheet approval and labor cost posting, the auditor will test whether that manual step introduces errors or delays. Automated integration between your timekeeping system and your general ledger reduces this risk.

The Features Auditors Actually Test

Beyond the SF 1408 criteria, experienced DCAA auditors evaluate specific system capabilities and configurations that reveal whether the ERP is functioning as intended.

Audit Trail and Change Logging

Auditors look for a complete, unalterable audit trail. Every transaction entry, every modification, every deletion should be logged with a timestamp and user identification. The auditor will test this by selecting transactions and reviewing the change history to verify that the trail exists and is complete.

Systems that allow users to overwrite transactions without preserving the original entry are a serious compliance risk. If an employee changes a time charge from Contract A to Contract B, the original entry and the correction must both be visible, along with who made the change and when. An ERP that permits “edit in place” without logging the original value fails this test.

Access Controls and User Permissions

The auditor will review your system’s user permission structure. Not every employee should have the ability to create journal entries, modify accounts, approve payments, or change billing rates. Your ERP should enforce segregation of duties through role-based access controls.

The specific configurations the auditor checks include: who can create and modify vendor records (to prevent fictitious vendor fraud), who can post journal entries (to prevent unauthorized cost transfers), who can modify the chart of accounts (to prevent uncontrolled account proliferation), and who can adjust billing rates (to prevent unauthorized billing changes).

If your ERP has granular permission settings but you have configured everyone as an administrator, the auditor will flag it. The system has the capability. Your configuration does not use it.

Indirect Rate Calculation

Auditors verify that your ERP can produce indirect rate calculations from system data. This means the system must be able to sum costs within each indirect pool, calculate the appropriate allocation base, and divide to produce the rate, all without exporting data to a separate spreadsheet.

Contractors who calculate rates outside the system, in Excel or a standalone tool, create a reconciliation risk. The auditor will compare the rate calculations in your external tool to the source data in the ERP. If the numbers do not match, or if the reconciliation process is unclear, the rate calculations become suspect.

The ideal configuration produces indirect rates as a standard system report that ties directly to the general ledger. That means no manual steps or external files. Every number is traceable to a posted transaction.

Report Consistency and Reproducibility

The auditor will run the same report multiple times, or request reports for the same period at different points during the audit, and compare results. If the reports produce different numbers, the system has a data integrity problem.

Reproducibility matters because the audit may span months. If your ERP allows retroactive posting of transactions to closed periods, reports generated early in the audit may not match reports generated later. Systems that enforce period-close controls, preventing changes to closed periods without documented reopening and approval, protect against this problem.

Data Integration Points

Every point where data enters your ERP from an external source is a point the auditor will examine. Timekeeping integrations, payroll feeds, bank imports, subcontractor invoice uploads, and inter-system data transfers all represent potential failure points.

The auditor will test whether data arriving through these integrations matches the source system. If your timekeeping system shows 40 hours for an employee in a week but your ERP shows 38 hours, the two-hour discrepancy needs explanation. Automated integrations that include validation checks are more defensible than manual imports that depend on staff accuracy.

Common System Gaps That Create Audit Findings

The system supports compliance, but the configuration does not use it. This is the most common gap. The ERP has the capability to segregate unallowable costs, enforce approval workflows, and produce indirect rate reports. However, the contractor never configured those features, or configured them initially and then disabled them when staff found them inconvenient.

Timekeeping runs on a separate system with no integration. Employees enter time in one system. Someone manually transfers that data to the ERP weekly. The manual step introduces timing gaps, rounding errors, and classification mistakes. The auditor tests the connection between timesheets and labor cost postings, and the manual process fails the traceability test.

Rate calculations live in spreadsheets. The ERP holds the cost data, but rate calculations happen in an Excel workbook maintained by the controller. The auditor asks how the spreadsheet reconciles to the general ledger. If the answer involves manual data entry from system reports, every number in the rate calculation becomes questionable.

Period-close controls are not enforced. The ERP allows transactions to be posted to prior periods without restriction. Month-end reports are not locked. Year-end data can be modified. The auditor discovers that the ICS schedules submitted last June do not match the current system data because someone posted an adjustment to the prior year after submission.

User permissions are too broad. Everyone has administrator access because it was easier during setup. The bookkeeper can modify the chart of accounts. The project manager can adjust billing rates. The accounts payable clerk can approve their own vendor payments. The auditor sees no evidence of segregation of duties.

Preparing Your ERP for Audit

The preparation is not a last-minute exercise. It is an ongoing configuration and maintenance practice.

Verify your access controls annually. Review user permissions and confirm they reflect current roles and responsibilities. Remove access for departed employees. Restrict administrative privileges to the smallest number of users possible.

Enforce period-close discipline. When a period is closed, it stays closed. Any reopening requires documented approval and a clear business justification. This protects the integrity of every report generated from that period’s data.

Test your integrations monthly. Reconcile data between your timekeeping system and your ERP. Verify that payroll postings match payroll records. Confirm that bank imports are complete and accurate. Catching integration errors in the month they occur is infinitely easier than discovering them during an audit.

Run your own audit trail test. Select ten random transactions and trace them from source document to general ledger entry to financial statement. If you cannot complete the trace in your own system, the auditor will not be able to either.

Produce indirect rates from the system. If your rate calculations currently happen outside the ERP, invest the time to bring them into the system. Build the reports. Validate them against your existing calculations. Migrate the process before the auditor arrives.

 

Is Your ERP GovCon-Ready?

Download the free guide to learn how to choose an ERP that supports compliance, audit readiness, and scalable growth.

 

 

The Bottom Line

DCAA auditors do not audit your software. They audit what your software produces and how it produces it. A purpose-built GovCon ERP that is poorly configured fails the same audit that a well-configured QuickBooks system passes. The system is the tool. The architecture, the configuration, the controls, and the processes around it are what the auditor evaluates.

If your ERP cannot produce contract cost reports, indirect rate calculations, and a complete audit trail from system data without manual intervention, you have gaps that will surface during the audit. If your access controls do not enforce segregation of duties, your period-close procedures do not protect data integrity, and your integrations do not reconcile cleanly, those gaps will produce findings.

The contractors who pass DCAA accounting system audits consistently are the ones who treat their ERP as compliance infrastructure, not just accounting software. The configuration is intentional. The controls are enforced. The data is reliable. That is what auditors look for.

Need help configuring your ERP for audit readiness? Contact Eubanks Accounting & Advisory for a system evaluation that identifies gaps before the auditor does.

Resources

  1. DCAA Pre-Award Survey (SF 1408) dcaa.mil
  2. DCAA Checklists and Tools dcaa.mil
  3. DCAA Contract Audit Manual dcaa.mil
  4. FAR Part 31: Contract Cost Principles acquisition.gov

Leave a Comment