Quick Hits
- Federal contractors encounter agency guidance at nearly every stage of contract performance.
- DOJ’s revised policy distinguishes between agency guidance that tracks binding regulations and guidance that is purely advisory.
- Under DOJ’s revised policy, noncompliance with agency guidance, standing alone, cannot establish an FCA violation.
- A contract that requires compliance with agency guidance can make that guidance enforceable or “material,” so the source of the obligation matters.
- DOJ may still rely on guidance as evidence of knowledge, industry practice, or materiality, particularly where a contractor has certified compliance.
The DOJ said in its revised Justice Manual that the department generally may not base an FCA action solely on a contractor’s failure to follow “agency guidance,” which are the broad category of documents that agencies issue to explain, interpret, or implement their programs, such as handbooks, manuals, frequently asked questions (FAQs), policy memoranda, and technical publications. These documents can be persuasive and practically important, but they do not carry the force of law. Under the revised policy, an FCA case must rest on a violation of a binding legal requirement, meaning a statute, a regulation, or an enforceable contract term, alone or in combination. Guidance can still play a supporting role in an FCA case, but noncompliance with guidance cannot itself supply the violation. For federal contractors seeking to understand compliance risk, the change makes the source of each compliance obligation the central question, because guidance that is merely advisory on its own can become binding when a contract incorporates it.
Under the revised policy, DOJ enforcement actions must be based on violations of applicable legal requirements. Consistent with the Justice Manual’s broader limits on the use of guidance documents, noncompliance with an agency guidance document cannot, by itself, establish a violation. Much of this material shapes day-to-day performance, but not all of it carries the force of law. Awareness of the actual legal source of an asserted compliance obligation rather than assuming every government instruction is binding can provide contractors with a more accurate assessment of compliance risk.
A Contract Can Make Guidance Binding
DOJ recognizes that a government contract may require compliance with an agency guidance document. In that situation, the contract, not the guidance itself, creates the enforceable obligation. Because federal contracts routinely incorporate outside documents, guidance that is merely advisory for the public may be mandatory for a particular contractor. To accurately assess compliance obligations and risk, agency guidance can be traced through:
- Federal Acquisition Regulation (FAR), Defense Federal Acquisition Regulation Supplement (DFARS), and agency supplement clauses;
- solicitation requirements;
- contract specifications and statements of work;
- incorporated documents and standards; and
- contractor representations and certifications.
This tracing exercise is not always straightforward. Contract clauses often point to other documents, which may be revised after award. Whether a contractor is bound by the version in effect at award or by later updates can depend on the precise incorporation language.
Cybersecurity is a clear example. A National Institute of Standards and Technology (NIST) publication, an agency FAQ, or a U.S. Department of Defense (DoD) implementation document may not independently create FCA liability. The analysis changes, however, when a DFARS clause or contract term requires the contractor to implement a particular standard, such as the NIST SP 800-171 requirements flowing through DFARS 252.204-7012. At that point, the standard is a contractual obligation and knowingly falling short while seeking payment can support FCA liability.
Contract clauses can also shape the materiality analysis. Some recent clauses, such as the FAR clause implementing Executive Order 14398, require the contractor to recognize that compliance is material to the government’s payment decisions for FCA purposes. That language can make a later materiality defense considerably harder.
Guidance That Arrives After Award
Much of the guidance contractors will follow during performance may not arrive with the solicitation. It surfaces after award through agency policy memoranda, updated handbooks, portal instructions, and emails from program personnel. Under DOJ’s revised policy, those materials do not independently create an FCA violation, and they generally do not change the contract either. Only a contracting officer acting within the scope of his or her authority can modify a contract on the government’s behalf.
That distinction matters in an FCA case. Contractors may want to determine whether post-award agency guidance or instructions were ever incorporated into the contract through a modification, a clause that expressly reaches later-issued documents, or the contractor’s own agreement or certification. If not, the instruction may reflect good practice, but it may not be the legal requirement DOJ’s policy demands.
‘Nonbinding’ Guidance Can Still Matter in an FCA Case
An overreading of the new policy could create risk. DOJ may still use agency guidance as evidence of:
- knowledge or notice of an obligation;
- industry standards or practices; and
- falsity or materiality when the contractor has made representations concerning compliance.
There are several steps contractors can take now to assess compliance risk presented by agency guidance materials during performance.
First, consider identifying the source of every significant compliance requirement, and distinguishing statutes, regulations, and contract requirements from guidance. For key performance requirements, it is important to understand where the obligation comes from and which version applies.
Second, consider a careful review of incorporation and certification language. A contract or contractor certification can give legal significance to requirements that otherwise might be merely advisory.
Finally, don’t assume agency guidance is irrelevant to FCA risk. Even when guidance does not independently impose an obligation, DOJ may use it as evidence of scienter, materiality, or industry practice.
DOJ’s revisions do not eliminate FCA risk associated with agency guidance. Instead, they make the source of the contractor’s obligation increasingly important. For federal contractors, the critical question may no longer be simply whether the government issued a particular requirement, but where that requirement appears and how it became binding.
Ogletree Deakins’ Government Contracting and Compliance Practice Group and Workforce Analytics and Compliance Practice Group will continue to monitor developments and will post updates on the Cybersecurity and Privacy, Government Contracting and Compliance and Workforce Analytics and Compliance blogs as additional information becomes available.
Follow and Subscribe
LinkedIn | Instagram | Webinars | Podcasts