Skip to main content
Certifications Now Cost More Than Bad InvoicesTraining & Monitoring
3 min readFor HR Professionals

Certifications Now Cost More Than Bad Invoices

The Department of Justice (DOJ) reported over $6.8 billion in False Claims Act (FCA) settlements and judgments for fiscal year 2025, marking the highest single year in the statute's history. This shift in federal enforcement is significant for anyone working with government contracts, as it highlights a change in focus from billing fraud to certification accuracy.

The Shift in Focus

Traditionally, FCA cases targeted billing fraud, charging for work not done or inflating invoices. However, the focus has shifted. Now, the certification itself, the statement made to win or maintain a contract, can be the false claim. The invoice doesn't need to be incorrect.

This approach, known as implied certification, was recognized by the Supreme Court in Universal Health Services v. United States ex rel. Escobar in 2016. The DOJ has since explored its boundaries, and the fiscal 2025 numbers show it's a robust tool.

For instance, the DOJ recovered over $52 million in civil cyber-fraud settlements in fiscal 2025. Penn State paid $1.25 million in October 2024 to resolve allegations of failing to implement certified cybersecurity controls across several Defense Department and NASA contracts. No data breach occurred, but the certification was alleged to be false, which sufficed for liability.

In April 2026, the DOJ announced its first FCA resolution under the Civil Rights Fraud Initiative. IBM agreed to pay over $17 million over allegations of breaching anti-discrimination requirements in its federal contracts. While IBM denied wrongdoing, the mechanism is noteworthy. DOJ applied a compliance area traditionally seen as administrative under a statute with severe penalties.

Key Findings

Certifications carry the same liability as billing. Under the implied certification theory, a knowingly false statement can be a false claim, even if invoices are accurate. The gap between certified claims and actual practices is now a federal fraud issue.

Cybersecurity and labor compliance are new priorities. The DOJ's focus on cybersecurity and labor compliance is evident from recent settlements. If your organization certifies compliance with security controls or labor standards, these are under scrutiny akin to cost accounting.

Outsiders are filing cases. Whistleblowers filed about 1,300 qui tam suits in fiscal 2025. Data miners, who analyze public government data, filed over 45% of these complaints since fiscal 2024. They may not have worked at your company but are scrutinizing your public filings.

The certification-to-operations gap is a liability. Often, the person signing a certification and the one verifying its truth work separately. This distance can lead to liability. If compliance says yes but operations says "we're working on it," you're at risk of investigation.

What This Means for Your Team

If you're in HR at a federal contractor, you're signing certifications about labor practices and compliance standards. These signatures are no longer just administrative.

Your compliance team certifies cybersecurity controls, supply chain integrity, and more. Each statement is a potential false claim if knowingly inaccurate and material to government payments.

The risk model has evolved. It's not just insiders who might blow the whistle; outsiders are already analyzing your data.

Action Items by Priority

Inventory all certifications from the last five years. Identify every compliance statement made to secure or maintain federal contracts. Ensure the right people are involved in the process.

Verify certification accuracy independently. Ask compliance and operations if each certification is accurate. If there's a discrepancy, investigate and document it. Address the gap before a qui tam suit arises.

Treat certifications like financial disclosures. Certifications should receive the same scrutiny as financial disclosures. Assign accountability, require operational sign-off, and document the basis for each certification.

Monitor responses to flagged gaps. When an employee highlights a certification gap, track the response. If it's deferred and the certification is signed regardless, you're facing a potential settlement scenario.

Educate your team on certification significance. Ensure everyone understands that certifications are not formalities. They're statements to the federal government with serious consequences if false.

For further guidance, refer to the Department of Justice's FCA resources and consider consulting with compliance experts to align your practices with current enforcement trends.

You Might Also Like