Back to Blog
Audit ReadinessDCAAAgentic Workflows
Jules Martin

Jules Martin

September 23, 2026

Inside GovConDash

The DCAA Audit Response Agentic Workflow

DCAA now audits with AI, and GovConDash has built an agentic workflow to answer the audit findings that follow. We read everything the agency has published about its use of AI and advanced data analytics in a separate piece. An audit finding can now reach you sooner, cover more of your accounts, and arrive already argued from the regulation, and DCAA's own manual says the time you get to comment on a draft finding should be minimal.

The workflow answers on the same footing. Hand it the draft audit report, the Form 1 or the questioned cost schedule, or type what you know about the finding. It reads the cost principle, DCAA's own manual and every forum before it drafts a word, cites what it read, and says what it does not know. It writes for whoever is holding the finding: the contractor's controller, the consultant's client, or counsel building the record for the Board.

What follows is the walkthrough: what DCAA's manual says it owes you at the exit conference and how short the comment window is, the eight steps the agentic workflow works through, the 24 tools it can call across ten bodies of evidence, and one worked example end to end, from the document it produced to the three things it told the reader it did not know.

The run this piece reads

Workflow
DCAA Audit Response Builder, in Audit Readiness
Where it lives
Overview / Workflows in the dashboard
What was asked
DCAA questioned our executive compensation as unreasonable on a CPFF contract. Draft our response.
What it can call
8 steps, 24 tools, 10 evidence sources
What came back
3,494 words in 123 paragraphs, with 13 numbered citations

The short version

  1. 1Your auditor is already using AI. DCAA's auditors have finished two major incurred cost audits on generative AI months ahead of schedule, tested every indirect expense in an audit rather than a sample, and used AI for the regulatory research behind a finding. Those are the agency's numbers; what it means for you is our reading.
  2. 2Hand it the report, or describe the finding. Either one starts a run. An uploaded draft report, Form 1 or questioned cost schedule is read by a deterministic pre-pass before the first model turn, which lifts the assignment number, the cited sections, the amounts and fourteen procedural signals; a typed description is asked for the same facts, field by field.
  3. 3The comment window is DCAA's, and it is short. The Contract Audit Manual tells your auditor to hand you the draft and take your views, and to keep the time it allows you minimal. Miss it and the final report issues anyway, saying your comments were not received in time to include them.
  4. 4It retrieves before it writes, in a fixed order. The regulation first, then DCAA's own guidance, then every forum, then the arithmetic. The eight steps are the workflow's own, declared in the product rather than decided per run, and the model gets exactly that many turns to work through them, so it cannot skip one or add one.
  5. 5The strongest rebuttal is DCAA's own manual. Four of the 13 citations are Contract Audit Manual paragraphs, including the internal ten percent survey benchmark the response tells the contractor to make DCAA own.
  6. 6Every decision comes with its weight. The Federal Circuit binds the Board; the Court of Federal Claims and the civilian board persuade it. The response read the one precedential opinion on the section and then said plainly that it does not decide this finding.
  7. 7It says what it does not know, and what to go get. No award date, so no cap regime; no dollar amount, so no penalty arithmetic. It holds the cap tables and DCAA's own alert on them, and still declines to pick a figure for a contract whose award date nobody supplied. A response that invented one would be caught by the first person who checked it.

01Two ways to start a response

Most tools of this kind take a prompt and nothing else, which quietly makes the contractor do the transcription: read the report, decide what matters in it, and type that. This one takes text and attachments, and treats the two as equals. You can hand it the document, or you can tell it what you know. Either way it writes for whoever is holding the finding, because its own instructions say so: "The reader's role decides the voice and the next steps".

The auditor across the table has the same class of tool; DCAA published another example on September 15, 2026. That is the research a response now has to match, and it is what the rest of this piece is about.

You have not seen the report yet

Describe the finding

Type what the auditor told you, in the terms the box asks for. Everything you give it is something it goes and looks up; everything you cannot give it, it tells you is missing rather than guessing.

You are holding the document

Optional: add the audit documents

Attach the draft or final report, the Form 1, the questioned cost schedule or your exit conference notes. A deterministic pre-pass reads them before the first model turn, and the memo quotes the auditor's own words back.

The typed path is not a chat prompt. The box asks for the specific facts a response has to be argued from, and it lists them: Describe the finding (audit type, the cost questioned, DCAA's stated basis, contract type and award date, dollar amount, whether a Form 1 or penalty is in play), or upload the audit documents and say what you need. Each of those is a pointer, a fact the workflow uses to go and find the right authority. An award date decides which version of the cost principle governs. An activity code names the audit program the auditor was working from. Whether DCAA called the cost unreasonable or expressly unallowable decides whether a penalty is even in play.

The uploaded path does that reading for you. Before the first model turn, a deterministic pre-pass goes through the documents by pattern and lifts assignment numbers and the DCAA activity code inside each one, the FAR and DFARS sections the auditor cited, any Cost Accounting Standards named, the dollar amounts, the fiscal years and the procedural signals. There are fourteen procedural signals it knows to look for, from a DCAA Form 1 to questioned subcontract costs. None of them is treated as a finding. They are pointers, and every one is retrieved and checked against the authority before it reaches the memo.

What the pre-pass looks for in your documents

Fourteen procedural signals, read by pattern with no model call. Each one is a pointer to retrieve, never a conclusion.

  • DCAA Form 1
  • penalty recommendation or assessment
  • costs characterized as expressly unallowable
  • costs characterized as unreasonable
  • costs characterized as unsupported
  • the compensation cap (FAR 31.205-6(p))
  • a contracting officer's final decision
  • the Contract Disputes Act statute of limitations
  • provisional billing rates
  • an accounting or business system finding
  • a labor floor check
  • an incurred cost proposal or final indirect rate proposal
  • a CAS noncompliance
  • questioned subcontract costs

Which is why the attachment hint reads the way it does: Upload DCAA's draft or final audit report, the Form 1, the questioned-cost schedule or the exit conference notes. The workflow reads the auditor's own words, lifts the assignment number, the cited sections and the amounts before the first model turn, and quotes the documents in the memo.

02The draft finding you were handed

The upload path assumes you have the draft. You usually will, and that is not a courtesy your auditor is doing you. DCAA's own Contract Audit Manual tells the auditor to hold an exit conference and to come away with your side of it.

the auditor should hold an exit conference with the contractor's designated representative to discuss the audit results and obtain the contractor's views concerning the findings, conclusions, and recommendations for inclusion in the audit report as required by GAGAS

The same paragraph tells the auditor to hand over the document itself, though only for an engagement that does not turn on forecasted costs: "the auditor should provide the contractor a copy of the draft report, or at a minimum, the results of audit section of the draft report". It also says the conference happens whether or not anything was questioned, because "the exit conference is a minimum courtesy to the contractor and is an important part of contractor relations".

Nothing waits for the exit conference either. Under the interim guidance a paragraph earlier, "The auditor should discuss preliminary audit findings (e.g., potential system deficiencies, potential FAR/CAS noncompliances, etc.) with the contractor to ensure conclusions are based on a complete understanding of all pertinent facts." On a major problem the manual is blunter still: "Do not wait until the final exit conference or the issuance of the audit report."

So by the time the draft report lands you should already have seen the substance of it. What you then get is a window, and the manual is candid that it is a short one.

The contractor should be provided a reasonable amount of time to analyze the audit results and to submit its reaction for incorporation into the final report. However, this time should be minimal since the audit issues were discussed on a real-time basis during the evaluation.

And here is the sentence worth pinning above your desk. Miss the window and the report goes out anyway, with a line in it about you: "If the contractor's reaction is not provided in a timely manner, the final report should be issued stating that the report was provided for comments to the contractor but the comments were not received in time to incorporate them into the final report." Your silence becomes part of the record the contracting officer reads.

Chapter 10, Report Writing, rewritten

April 1, 2025 revision

68 paragraphs

CAM 10-210.3, Release of Audit Reports to the Contractor, opens by saying "DCAA routinely provides copies of draft reports for all audits" and goes on to set the comment window and what happens if you miss it.

September 3, 2026 revision

33 paragraphs

CAM 10-208 carries the same title and keeps only the exceptions. The phrase "routinely provides copies of draft reports" appears nowhere in the chapter.

Nothing was taken away from you. The obligation to hold the conference and hand over the draft is in Chapter 4, and that chapter was revised on September 18, 2026, which is after the Report Writing rewrite. But a contractor who goes looking in the chapter called Report Writing for the paragraph that says they get a draft for comment will now find only the exceptions: "Draft and final reports that are of a privileged and sensitive nature" and what happens if you ask for the final report after it has issued.

One more thing to know about how your answer gets recorded. "The auditor may obtain written comments from the contractor representative or oral comments at the exit conference." Oral is the weaker of the two, and the manual says what follows from it: "When only oral comments are provided the auditor should prepare a summary of the oral comments and provide a copy of the summary to the contractor official to verify the comments are accurately stated." A written response you drafted is a document in the file. A conversation is the auditor's summary of a conversation, which you are then asked to initial. That difference is the whole argument for having something written before you walk into the room.

One large exception, because everything above is about a finding on costs you have already incurred. If the audit is about costs you have not yet incurred, a forward pricing proposal or rate submission, you do not get the draft at all. "If the report includes forecasted costs that are subject to negotiations, such as forward pricing audits, the auditor should not provide the contractor a copy of the draft report or results and should limit the discussion to factual matters/differences."

The manual says why in the Report Writing chapter, and the reason is not about you: "In order to avoid disclosing the Government's negotiating position, draft reports that include forecasted costs to be used in negotiations are not provided to the contractor unless specifically authorized by the contracting officer". The release exception is built into the general rule as well, which provides the draft for all audits "except those dealing with negotiation of forecasted costs or those dealing with costs potentially under litigation".

Where you do not get the draft

"Draft and final audit reports on the areas listed below are not provided to the contractor unless the contracting officer directs such release in writing."

  • Individual Price Proposals
  • Should Cost Reviews
  • Forward Pricing Rate Proposals
  • Evaluations of Part of a Proposal, including audits of specified cost elements
  • Agreed-upon procedures
  • FPR/FPI Price Redetermination Proposals, containing forecasted costs
  • Equitable Adjustment and Termination Submissions, containing forecasted costs
  • Other evaluations where the PCO/requester restricts release to the contractor

CAM 10-210.3, April 1, 2025 revision

You are not left with nothing on those audits. What survives is the factual half: "the auditor should fully discuss with the contractor any factual differences, unsupported items, certified cost or pricing data inadequacies, and CAS/FAR noncompliances and obtain the contractor's reaction for inclusion in the final audit report". So the exit conference still happens, your reaction still goes into the final report, and the errors of fact are still yours to correct. What you cannot do is read the Government's conclusion before you negotiate against it. That is also why the workflow this piece is about is pointed at questioned costs rather than at proposal audits: a response to a forward pricing evaluation is an argument made at a negotiating table, not a reply to a report you were handed.

03Who decides a questioned cost

Here is the part most contractors get wrong under pressure. The auditor who wrote the finding does not decide it. FAR 42.101 gives the auditor one job: "Submitting information and advice to the requesting activity, based on the auditor's analysis of the contractor's financial and accounting records or other related data as to the acceptability of the contractor's incurred and estimated costs". Advice.

The deciding is somebody else's. Under FAR 42.201 a contract assigned for administration goes to a contract administration office, which must "Perform the functions listed in 42.302(a) to the extent that they apply to the contract, except for the functions specifically withheld", and the same section names who those offices are: "The Defense Contract Management Agency and other agencies offer a wide variety of contract administration and support services." For a Department of War contractor that is almost always the Defense Contract Management Agency.

Three of the functions on that list are the ones your questioned cost travels through. Under FAR 42.302 the office issues the notice of intent to disallow, establishes the final indirect cost rates, and, when it comes to that, will "prepare findings of fact and issue decisions under the Disputes clause on matters in which the administrative contracting officer (ACO) has the authority to take definitive action". Disallow, settle the rates, decide the dispute. For final indirect cost rates specifically, FAR 42.705-1 names the officer: the cognizant administrative contracting officer.

That chain is the incurred cost one, the path a questioned cost takes. On a forward pricing audit the same report is advice into a negotiation instead, and the position is settled at the table rather than disallowed after the fact. Either way the point holds: a questioned cost is a recommendation until the contracting officer adopts it. Your response at the exit conference is not an appeal, it is an argument to the person who has not decided yet, and it is the cheapest point in the whole process to win at. What you write there reaches that officer as part of the report.

Who decides a questioned cost

  1. 1

    DCAA: Questions the cost

    The auditor analyzes the records and advises. The audit report is a recommendation, not a determination. FAR 42.101

  2. 2

    You: Answer at the exit conference

    Your views go into the report itself. This is the only rung where nothing has been decided yet.

  3. 3

    DCMA: Determines

    The contract administration office disallows costs, settles the final rates, and issues the decision on a dispute. FAR 42.302

  4. 4

    The Board or the Court: Reviews

    After a final decision, 90 days to the Armed Services Board of Contract Appeals or 12 months to the Court of Federal Claims, at your election. FAR 33.211

If the contracting officer does adopt the finding and you still disagree, the route out is a claim and then a final decision under FAR 33.211. That decision starts two clocks, and the section prints the words the letter has to carry.

To the Board, 90 days
"within 90 days from the date you receive this decision, mail or otherwise furnish written notice to the agency board of contract appeals"
To the Court, 12 months
"Instead of appealing to the agency board of contract appeals, you may bring an action directly in the United States Court of Federal Claims"
If the officer never answers
"Any failure of the contracting officer to issue a decision within the required time periods will be deemed a decision by the contracting officer denying the claim"

That is where the Board comes in, and it is worth knowing what it does with appeals before you decide how much effort the exit conference deserves. This platform holds 4,630 Armed Services Board of Contract Appeals decisions, 2010 through 2026, with 4,568 of them analyzed. The first thing the whole set says is unwelcome: only 1,767 of those 4,568 reached the merits at all. The rest were dismissed, settled, withdrawn or remanded, most of them dismissed. An appeal is lost on procedure far more often than it is lost on the cost.

4,568 analyzed Board decisions, by outcome

  • dismissed2,478
  • deniedmerits913
  • sustainedmerits507
  • partially sustainedmerits347
  • settled withdrawn255
  • other62
  • remanded6

Outcomes are this platform's own analysis of each decision, over the 4,568 it has analyzed of 4,630 held. A dismissal is not a ruling on the cost.

Of the 1,767 the Board did decide, 854 were sustained in whole or in part and 913 were denied. Narrow it to the issue this workflow is built for and the picture is slightly better for the contractor: 105 analyzed decisions carry the cost allowability issue, 84 of them decided on the merits, of which 49 got something back against 35 denied.

Read those two numbers together and they say the same thing twice. Questioned costs are winnable, and the thing that decides them is the record: whether the argument was made, whether it was made in time, and whether it was made to the right authority. The record starts with what you said when the draft report was handed to you.

Which is the whole case for doing this with a grounded workflow rather than a blank page. The response has to be written inside DCAA's window, it has to argue from the cost principle rather than around it, it has to know whether the Board has already decided this question, and it has to say what it does not know instead of guessing, because every sentence in it may be read years later by people looking for the contractor's first position. Doing that by hand takes a specialist and a week.

04One worked example, end to end

The rest of this piece follows one run, so every claim above can be checked against something. The cost at issue is executive compensation, and that is only the example: the same eight steps run for unsupported labor, a CAS noncompliance, a business system deficiency or an inadequate incurred cost submission, against whichever cost principle the finding happens to name.

This run took the typed path, and deliberately the thinnest version of it: DCAA questioned our executive compensation as unreasonable on a CPFF contract. Draft our response. Nothing attached, no assignment number, no dollar figure. That is the hardest case rather than the flattering one: with nothing but a sentence, an ungrounded model will happily invent a questioned amount, a compensation cap and a case citation to match.

What came back instead was 3,494 words across 123 paragraphs, every substantive sentence carrying a bracketed number, and a table of authorities at the end listing what each number points at.

Three columns under the heading Describe the finding or upload the report: 8 steps, seven of them spent retrieving; 24 tools across ten bodies of evidence; and 13 citations, every one of them opening its source
Whichever way a run starts, the same eight steps run. The step and tool counts are read from the workflow's own catalog entry and tool roster; the citation count from the document one run produced.

05What it reads before it writes a word

A response to a DCAA finding is argued from four kinds of authority, and the order matters. The regulation comes first, because everything else is an interpretation of it. Then DCAA's own guidance, because a rebuttal that shows the finding departs from the auditor's own manual is the strongest one available. Then the case law, in its order of weight. Then the arithmetic of any penalty.

Those eight steps are not improvised. They are declared in the product, rendered in the runner before you spend anything, and the model cannot skip one or add one.

A numbered rail of the 8 steps a run works through, from "Read the finding and the audit documents" to "Draft the response memo"
The workflow's own step flow, read from the module the runner renders it from. Every step is drawn the same, because every one of them runs, in this order, on every request.

Step 2 is worth pausing on, because it is where most tools of this kind go wrong. FAR 31.205-6 is the longest of the 46 cost principles in Part 31, four times the length of the next one, long enough that anything reading it in a single pass gets a truncated copy. The senior executive compensation limitation is late in it, at paragraph (p), so a truncated read loses exactly the paragraph a cap question turns on. The workflow reads a long section one named paragraph at a time instead, and its prompt is blunt about why: "a response about the cap that never read paragraph (p) is not grounded."

The total compensation for individual employees or job classes of employees must be reasonable for the work performed

FAR 31.205-6(a), as the eCFR carries it

The regulation is not one section either. An unreasonableness finding runs through three: the cost principle itself, the reasonableness criterion at FAR 31.201-3, and the allowability criterion at FAR 31.201-2 that makes reasonableness a condition of allowability in the first place. The second of those is where the argument actually turns, because it decides who has to prove what: "the burden of proof shall be upon the contractor to establish that such cost is reasonable". And before it, "No presumption of reasonableness shall be attached to the incurrence of costs by a contractor." A response that does not know the burden has moved is a response that answers the wrong question.

The 24 tools behind those steps fall into ten bodies of evidence. All but one of them read data this platform already holds; the exception is get_regulation_as_of, which calls the eCFR's own point-in-time service at run time to read a section as it stood on a contract's award date.

Ranked columns of the corpora the toolbox reaches: 10,113 eCFR regulation sections, 6,227 DCAA audit steps, 4,630 ASBCA decisions, 3,622 Civilian Board decisions, 2,502 Contract Audit Manual paragraphs, and on down to 10 DCAA guidance memoranda
What is behind the 24 tools: 29,984 rows in all, counted on the production database.

eCFR regulations (FAR, DFARS, CAS)

Three tools

  • Search regulations. Full-text search of the eCFR Title 48 corpus (FAR, DFARS, CAS) by keyword or section code, returning titles, section codes and excerpts.
  • Read a regulation. The verbatim text of one section by its code, such as 31.205-6 or 52.216-7, or one named paragraph of it in full when the section is long.
  • Read a regulation as of a date. The text of one Title 48 section as it stood on a given date, from the keyless eCFR versioner, for the cost principles in effect when a contract was awarded.

DCAA Contract Audit Manual

One tool

  • Search the Contract Audit Manual. Semantic search over the verbatim paragraphs of the DCAA Contract Audit Manual.

One more thing the roster carries that a reader would not guess: get_compensation_cap. FAR 31.205-6 paragraph (p) makes compensation above a benchmark unallowable but never prints the benchmark, which lives in the Office of Federal Procurement Policy's own tables. The tool reads them with their provenance, so a memo states the figure and its source instead of asking the reader to go find it. For costs incurred in 2025 on a contract awarded on or after June 24, 2014, that figure is $671,000, and the tool cites DCAA's own restatement of it at CAM 6-414.7 beside the table. The run this piece reads never used it, for reasons part 08 comes back to.

06Answering DCAA with DCAA's own manual

Four of the 13 citations are Contract Audit Manual paragraphs. That is the part of this that a contractor usually cannot do alone: the manual is 2,502 paragraphs across DCAA's manual and its Selected Areas of Cost Guidebook, and the four that matter for an executive compensation finding are in Chapter 6.

The most useful of the four is the one the auditor is most likely to have applied without saying so.

DCAA's CAM includes an internal audit judgment that compensation may be considered unreasonable when the aggregate of allowable and measurable elements exceeds survey data's weighted average or median by 10 percent.

The response, quoting CAM 6-413.4

The response does not argue with the benchmark. It does something more useful: it tells the contractor to make DCAA own it. One sentence later it says "the Company should request that DCAA identify whether it actually applied this internal benchmark, which survey measure it used, how it selected the relevant comparator group, and how it treated executive-specific responsibilities." An auditor who applied an internal judgment and did not state it in the report has a finding that is hard to defend on its own terms.

It also uses the manual against the easy argument a contractor reaches for first. "The CAM also states that executive compensation can remain unreasonable even when it is below the applicable statutory compensation ceiling." Compliance with the cap is not a defense to unreasonableness, and the response says so before the contractor spends a paragraph on it.

None of that is a flourish of the model's. The workflow's prompt is explicit about why the manual is worth reading before a word is drafted:

a rebuttal that shows the finding departs from DCAA's own guidance is the strongest rebuttal available.

The workflow's own prompt, on the manual tool

07Four forums, and the weight each one carries

A response that cites a case without saying what the case is worth is worse than one that cites nothing, because the first person to check it will find the overreach and stop trusting the rest. The workflow states the weight of every decision it cites, and its prompt makes that a rule rather than a preference: "Never present a persuasive decision as binding, and never omit the weight."

A matrix of four forums: the Federal Circuit binds the Board with 452 opinions in the corpus and 2 tools reaching it, the ASBCA carries its own precedent across 4,630 decisions, and the Court of Federal Claims and the Civilian Board are persuasive
Which forum binds, which persuades, how much of each this platform holds, and how many of the workflow's tools reach it.

The binding search returned one precedential Federal Circuit opinion on the cost principle, and the response read it rather than characterizing it from a snippet. It reports what the opinion is worth: "a precedential decision affirming the ASBCA. It binds the ASBCA, the CBCA, and the Court of Federal Claims." Then, in the next breath, what it is not: "It should not be presented as controlling authority on whether XYZ's executive compensation was reasonable." That second sentence is the one a reviewer looks for.

At the Board itself the authority search is the sharpest instrument available, because it asks which decisions cite the section rather than which ones read similar. Its prompt says so plainly: "The Board-cited-authority match is the most on-point precedent signal there is." On the governing cost principle it found 24 analyzed decisions, which is still the count today: "The ASBCA authority search identified 24 decisions citing FAR 31.205-6."

A unit chart of the 13 citations, one glyph each: one governing cost principle, two regulations & standards, one federal circuit decisions, five board decisions, four contract audit manual
Every bracketed number in the response, grouped the way the document's own table of authorities groups them.

Of the five Board decisions it read, the useful one for a contractor is Metron: "The Board sustained the appeals and concluded that the disputed executive compensation for fiscal years 2004 and 2005 was reasonable and allowable." The response sets out what carried it, a documented survey analysis matched to the positions at issue, and then takes the argument away again before a reader can lean on it: "it does not establish a universal safe harbor for compensation within 10 percent of a survey median."

One of the five is a decision against the contractor itself. "This decision involved XYZ's FY 2006 incurred-cost proposal and government claims concerning executive compensation, the compensation cap, penalties, and a later proposed methodology for calculating the cap." A contractor writing this response by hand would be unlikely to go looking for its own loss; the authority search returns it because the decision cites the section, and the response uses its procedural holding as a guard against DCAA changing the basis of the finding later.

The stored analysis of every Board decision is itself AI-generated, and the response says so on the face of the page rather than in a footnote: "The official ASBCA decision should be reviewed before citing the analysis as precedent because the stored case analysis is AI-generated and its quoted excerpts are not page-verified."

08What it refused to say

This is the part that decides whether any of the rest is usable. The request gave the workflow almost nothing: a cost, a characterization and a contract type. An ungrounded model fills that silence, because a confident memo reads better than an honest one. Here is what this one did instead.

What the response refused to state

  • The facts the request never gave it

    The request does not provide the DCAA assignment number, contract award date, fiscal year, executive name or position, compensation amount, amount questioned, or the audit report's exact wording. Those items should be inserted from the audit report before submission.

  • The number it would not estimate

    Because no questioned dollar amount was provided, the current dollar exposure cannot be calculated.

  • The figure it would not choose between

    Accordingly, this response does not state a compensation-cap figure or determine whether the cap applies.

Those are not three separate gaps. They are one missing fact, working through. The request never fixed an award date or a fiscal year, and the memo says so itself: "The available request also does not provide the award date or fiscal year needed to determine whether a cap applies or to identify the applicable benchmark amount." Without the date there is no way to know which compensation cap regime governs, so the response declines to state a figure. Without a questioned amount there is nothing for the penalty multiples at FAR 42.709-1 to multiply, so the deterministic penalty tool was never called at all.

Note what the cap refusal is and is not. It is not that the platform does not hold the number. It holds the Office of Federal Procurement Policy's own tables, which is where the $671,000 figure earlier in this piece came from, and it holds DCAA's memorandum on the subject: 24-PSP-009(R), Audit Alert on Contractor Compensation Cap - Statutory Fiscal Year 2025. What it would not do is pick which of the several statutory regimes applies to a contract whose award date nobody had given it. Supply the date and it states the figure with its provenance; withhold it and the response tells you that the date is the thing to go find.

What it gives the reader instead of numbers it does not have is a list of dates to go find: the draft report, the response deadline, the final report, the contracting officer's determination, whether a Form 1 has issued, and whether a final decision under FAR 33.211 has been made, which is the one that starts an appeal clock. That is the right output for a request with nothing in it. It is also the part a contractor can act on within the hour.

That behavior is written into the workflow, not hoped for. Its prompt carries the rule twice, once as a prohibition and once as an instruction about what to do instead:

NEVER fabricate a FAR cost principle, a clause number, a dollar figure, a compensation cap, a penalty multiple, an ASBCA case name or a holding.

The workflow's own prompt, grounding rules

And the positive form, which is the harder one to follow: "If you cannot retrieve a governing principle, a DCAA guidance paragraph or an on-point decision, say so and point to where to verify it". The same prompt bars the model from declaring an absence too early: "Only after running the authority search, the facet search, the concept search and the Federal Circuit search may you write that no decision was found." A run that has not done the searching is not allowed to report that there is nothing there.

The citation discipline is the other half of it. "Place the [n] immediately after the sentence it supports, reuse the same number for the same source, never renumber and never invent a number." Numbers that cannot be renumbered or invented are numbers a reviewer can check one at a time, which is the only property of a citation that matters.

GovConDash.ai

Read the cost principle your auditor is working from, free

The workflow above needs a paid plan. The regulation underneath it does not. The Research / eCFR Research tab opens on a free account, with the research agent that reads the same regulation corpus one paragraph at a time and cites the sections it read. Ask it what FAR 31.205-6 requires of a compensation plan, or what paragraph (p) does on a contract awarded before June 24, 2014, and check every citation it gives you against the eCFR.

09The document you actually send

The response is a document, not a chat transcript. It downloads as Word, it carries a masthead, numbered citations and a grouped table of authorities, and its section order is prescribed by the workflow rather than chosen per run. Here is how it opens.

1It restates the finding, and then the gaps in it

Finding Summary restates the finding in the requester's own terms and then, in the same paragraph, lists what it was not given. Bottom Line is three to five sentences a controller can act on: the position, the exposure, and the one procedural fact that most changes the outcome, which here is whether this is still a draft finding or has reached a contracting officer's final determination.

The opening of the response: a masthead reading DCAA Audit Response, a Finding Summary restating that DCAA questioned XYZ, Inc.'s senior executive compensation as unreasonable on a cost-plus-fixed-fee contract, and a Bottom Line recommending a rebuttal
The first page of the response. Note for the reader is the workflow's own device for a conflict between the request and the account's company record.

2It takes a position, and drafts the words to send

Each finding gets a position of concede, rebut or partial. Here it is "Recommended position: Rebut, subject to reconciliation." Under it sits a twelve-item evidence list, from the executive's contemporaneous job description through to the general ledger detail and the indirect cost pool allocation behind the claimed amount.

Then the thing a contracts manager actually needs: the paragraph to send, written in the contractor's voice, opening "XYZ respectfully disagrees that the challenged senior-executive compensation has been shown to be unreasonable." It asks DCAA to identify what remains disputed so the parties can reconcile element by element, which is a narrower and more winnable posture than a general denial.

The Position and Response section: Recommended position, Rebut, subject to reconciliation, followed by the paragraph beginning XYZ, Inc. respectfully disagrees that the challenged senior-executive compensation has been shown to be unreasonable
Position and Response, with the twelve-item evidence list between the two blocks omitted for length. The indented block is the paragraph as it would go to the auditor.

3Every bracketed number resolves to something you can open

The document closes on the ledger the bracketed numbers point at, grouped by the kind of authority and led by the governing cost principle. Each entry carries an Open source link to the publisher's own document: the eCFR for the FAR sections, the court's own opinion for the Federal Circuit, the official decision for each Board case, and DCAA's manual for each CAM paragraph. A citation you cannot open is not a citation.

The table of authorities closing the response: 13 numbered entries grouped as Governing Cost Principle, Regulations and Standards, Federal Circuit Decisions, Board Decisions and Contract Audit Manual, each with an Open source link
The grouped table of authorities. Every entry carries a link to the publisher's own document, and the disclaimer travels with the page.

4It ends on named deliverables, not advice

Seven steps, each led by a short noun phrase naming a thing to produce rather than a thing to consider: Rebuttal Matrix, Market Analysis, Evidence Package, DCAA Data Request, Cap Review, Audit Response Letter, Legal Review. That shape is deliberate. This workflow generates next-step documents, so a named deliverable in the memo becomes a card you can click to draft it.

The Recommended Next Steps section, a numbered list of named deliverables: Rebuttal Matrix, Market Analysis, Evidence Package, DCAA Data Request, Cap Review, Audit Response Letter, Legal Review
The closing next steps. Each title names a deliverable the workflow can then generate as its own document, filed to the DCAA Audit Responses folder in the Workspace.

And the last line of the document is the one that should be there. The response tells its reader it is a draft for review with counsel, that it does not bind DCAA or the contracting officer, and that every authority should be verified against the official source. The prompt requires it: "It is not legal advice and does not bind DCAA or the contracting officer. Never assert that a position will prevail."

10Where this lives in GovConDash

The workflow sits in Overview / Workflows, one card in the Workflows gallery. Opening the card gives you the request box, the eight steps and the 24 tools, all before you spend a run.

1Find it in the Workflows gallery

The card carries the workflow's description and its two badges. It takes text and attachments both, and the hint under the upload box says what to bring: Upload DCAA's draft or final audit report, the Form 1, the questioned-cost schedule or the exit conference notes. The workflow reads the auditor's own words, lifts the assignment number, the cited sections and the amounts before the first model turn, and quotes the documents in the memo.

The DCAA Audit Response Builder card in the Workflows gallery, showing its description and two badges reading Draft, 8 steps and 24 tools
The card as the gallery renders it. Both badges read from the workflow's own catalog entry and tool roster, so what the card promises is what the runner can do.

2Read the steps before you spend a run

The steps badge opens the flow. Nothing here is a marketing summary of what the workflow does: the panel, the exhibit earlier in this piece and the number of turns the model gets are one list in one file, so they cannot drift apart.

The runner opened on the DCAA Audit Response Builder, with the How this workflow runs panel expanded to show all 8 numbered steps and the detail under each one
The runner's step panel, opened. This is the same list the exhibit above is drawn from, because both read the one module.

3See what it can reach, tool by tool

The tools badge opens the roster, grouped by the body of evidence each one reads. A tool that reaches an outside service at run time is badged live; everything else reads data the platform already holds. One is badged called once, the planner that declares what kind of document the next-step generator will draft.

The runner's tools panel, showing all 24 tools grouped into 10 evidence sources, each tool with its function name and a one-line description
The tools panel. Each tool shows the name the agent calls it by, so a citation in the output can be traced back to the thing that fetched it.

Overview / Workflows

The runner itself

Describe the finding or upload the audit documents. A deterministic pre-pass reads the assignment number, the cited sections, the amounts and the procedural signals out of your files before the first model turn, so the retrieval starts from the auditor's own words. It needs a paid plan.

Overview / Workspace

Where the output is kept

A saved response files under its own DCAA Audit Responses folder, because an audit response, its letters and its matrices accumulate per audit and a reader looks for the audit before the form. Each named next step in the memo can be generated as its own document beside it.

Research / eCFR Research

The regulation, free

The same regulation corpus the workflow's first step reads, 10,113 Title 48 sections, with the research agent that cites the sections it read. This is the one AI surface a free account opens.

Audit Readiness

What your auditor is working from

The 2,502 Contract Audit Manual and cost guidebook paragraphs this response quoted, plus the audit programs themselves: 72 programs and 6,227 verbatim steps. Reading them is free with an account.

ASBCA, Federal Circuit, COFC and CBCA

The decisions behind the citations

Every forum the response searched is a browsable corpus of its own: 4,630 Board decisions, 452 Federal Circuit opinions, 2,356 Court of Federal Claims opinions and 3,622 Civilian Board decisions. When the response cites one, you can open it and read the decision yourself.

Documents and data used in this piece

Every quotation above was checked against a stored copy of its source before this page was written, 59 checks in all. Every product fact was read from the module that decides it rather than typed, and every count was measured on the production database, with the regulation corpus last refreshed September 17, 2026. If a single check fails, nothing is written.

the run

  • DCAA audit response, the document one run produced

    GovConDash.ai. The Word document a single run produced: the finding restated, the position taken on it, the paragraph to send the auditor, and the grouped table of authorities it closes on. Every passage quoted in this piece was re-located in it.

the workflow

  • The workflow's own instructions, the prompt every run follows

    GovConDash.ai. The grounding rules, the hierarchy of authority, the retrieval order and the output structure every run follows. Quoted here, never paraphrased.

regulations

reference documents

  • Contractor compensation benchmark, Bipartisan Budget Act table

    Office of Federal Procurement Policy. The cap figure FAR 31.205-6(p) points at and never states: $671,000 for 2025, for contracts awarded on or after June 24, 2014. Tracked here with its provenance and cited beside DCAA's own restatement at CAM 6-414.7.

DCAA on its own use of AI

DCAA guidance

  • DCAA Contract Audit Manual

    Defense Contract Audit Agency. The manual the auditor works from, held here chapter by chapter and paragraph by paragraph, including revisions DCAA has since replaced. Chapter 4 is the exit conference, Chapter 6 the compensation guidance, Chapter 10 report writing.

  • DCAA Selected Areas of Cost Guidebook

    Defense Contract Audit Agency. The companion volume the auditor goes to for a question about a particular cost, 75 chapters of it. Its stored chapters were downloaded from this directory.

  • DCAA Directory of Audit Programs

    Defense Contract Audit Agency. The audit programs themselves: 72 programs and 6,227 verbatim steps, which is what the workflow reads to show what the auditor was required to test. Stored copies were downloaded from this directory.

decisions

Disclaimer. This piece is commentary on published regulations, on published audit guidance and on published decisions. It is not legal advice, and it is not a determination about any contractor, any contract or any audit. The response the workflow produces is a draft for review with counsel or a government contracts professional, and does not bind DCAA or a contracting officer.

GovConDash.ai

Answer your auditor with the record behind you

DCAA Audit Response Builder reads the cost principle, DCAA's own manual and every forum before it drafts a word, and cites what it read. The regulation corpus underneath it, 10,113 Title 48 sections with the research agent over them, is free with an account.

Inside GovConDash takes one surface of this platform per edition and walks it end to end: what it reads before it acts, what it produces, and what it refuses to state. This one is the DCAA Audit Response Builder.

Keep reading

DCAA Replaced Its Cost Chapter With a Fraud Chapter

The chapter your auditor now goes to instead, what it tells them not to say, and where a referral ends up.