Federal Contractor Compliance in Transition: Ten Steps to Building a Sustainable Compliance Program

Federal Contractor Compliance in Transition: Ten Steps to Building a Sustainable Compliance Program ...



Posted by Berkshire on September 30 2026
Berkshire
Federal Contractor Compliance in Transition: Ten Steps to Building a Sustainable Compliance Program
9:55


Federal Contractor Compliance in Transition: Ten Steps to Building a Sustainable Compliance Program 

During a recent webinar, Berkshire Associates’ Lynn Clements and Ogletree Deakins shareholder Scott Kelly explained why fewer federal requirements do not necessarily mean less risk—and why employers should use this moment to build compliance programs that can withstand continued change.

The webinar focused on several key compliance updates for federal contractors:

  • The continued obligation to prepare annual affirmative action plans under Section 503 of the Rehabilitation Act of 1973 (Section 503) and the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA)
  • The impact of new contract clause certifications under Executive Order 14173 and 14398 on compliance and risk
  • Lessons learned from the Department of Justice’s three recent False Claims Act settlements challenging employer “DEI-related” employment practices
  • The status of disparate impact claims, especially as it relates to the use of artificial intelligence tools in employment selection processes
  • The pending changes to the EEO-1 report 

The central takeaway: Flexibility creates opportunity, but it also shifts more responsibility to employers to determine what compliance looks like, document a reasonable basis for their decisions, and monitor risk over time.

Section 503 and VEVRAA Plans Are Still Required

Despite recent rule changes by the Office of Federal Contract Compliance Programs (OFCCP), covered federal contractors must still prepare annual Section 503 and VEVRAA affirmative action programs by establishment. Plans dated before September 21, 2026 should be completed under the prior rules, while later plans should follow the revised requirements set forth in the August 21, 2026 final rules. Because contractors make related certifications in the System for Award Management, leaving required plans unfinished can create risk beyond a routine compliance gap.

For VEVRAA, the webinar highlighted limited change. The coverage threshold increased to $200,000, but contractors must still invite protected-veteran self-identification at the pre- and post-offer stages, collect and analyze the required applicant and hire data, evaluate results against the applicable hiring benchmark, and list covered jobs with the appropriate state employment service delivery system, among other items.

Although Section 503 requirements changed more substantially, many obligations remain under Section 503. Contractors should continue disability outreach, prepare a written annual assessment of that outreach, train people involved in selection, and document reviews of personnel processes and physical and mental job qualifications, among other requirements. Contractors must continue to ensure equal employment opportunity for individuals with disabilities and provide appropriate reasonable accommodation. Future voluntary disability status self-identification practices should be evaluated under the Americans with Disabilities Act and applicable state and local laws. The presenters also cautioned employers not to purge previously collected disability data as existing record-retention obligations still apply.

Contract Certifications Raise the Stakes

Newer executive-order and Federal Acquisition Regulation provisions, including those under Executive Order 14173 and 14398, are creating new risks for federal contractors. The webinar emphasized that certifications under these new executive orders can reach recruiting, hiring, promotion, staffing, vendor relationships, employee programs, and the allocation of organizational resources. Covered clauses may also need to flow down to subcontractors and vendors supporting federal contract performance.

Under the Department of Justice’s Civil Rights Fraud Initiative, the False Claims Act (FCA) is a particularly important enforcement mechanism. Historically, the FCA - which prohibits submitting false or fraudulent claims or records to the government for payment - was used to police financial or procurement fraud. However, under recent enforcement priorities and executive orders, compliance with federal anti-discrimination laws has been made explicitly material to government contract payment. As a result, compliance practitioners should ensure that they understand the enforcement process under the FCA, which can include claims by both the government and/or a whistleblower.

The presenters discussed three recent FCA settlements against federal contractors totaling millions of dollars each and noted that civil penalties - not only contract damages - can drive the exposure sharply upward. In each settlement, the Department of Justice argued that the federal contractor was subject to contractual anti-discrimination requirements and falsely certified compliance with those requirements, while engaging in unlawful “DEI-related” employment practices. Each settlement reached reach years into the past, and two settlements expressly preserved the ability to bring separate discrimination claims based on the underlying allegations.

Based on these recent settlements, practices warranting close review include:

  • using race or sex to make employment decisions
  • linking manager compensation or performance ratings to representation targets, and
  • limiting mentorship, leadership development, training, or similar opportunities based on protected characteristics.

EEO-1 Uncertainty Does Not Eliminate the Need for Data

The EEOC has proposed eliminating annual EEO reporting, but the proposal was not final at the time of the webinar. The presenters recommended staying prepared to file while also deciding what workforce demographic data the organization needs for lawful business purposes, recordkeeping, pay equity review, state-law compliance, and responses to agency investigations. Eliminating a filing requirement would not eliminate those needs.

Disparate Impact and AI Risk Are Shifting, Not Disappearing

Federal agencies have moved away from some disparate-impact regulations and enforcement approaches, but Title VII has not been amended and courts are not bound by an executive-branch legal opinion. States and private plaintiffs may continue to pursue disparate-impact theories, creating a growing patchwork of risk.

AI-assisted employment tools deserve particular attention. Employers may be using automated decision-making features embedded in applicant tracking or HR systems without fully appreciating their role. The speakers recommended understanding where AI influences decisions and testing outcomes at the job level and at each stage of the selection process rather than relying only on organization-wide averages.

10 Steps Toward a Sustainable Compliance Program

While the Administration’s deregulation efforts have created confusion for many federal contractors, the presenters emphasized the continued need for a robust compliance program. They suggested contractors consider the following steps when building a compliance program in today’s complex environment:

  1. Expect continued change. Build a program that can adapt across administrations and jurisdictions.

  2. Document a compliance plan. Confirm that all remaining federal contractor obligations are assigned, completed, and retained.

  3. Create a reasonable basis for new contract certifications. Do not rely on a review of policy language alone; review data and actual practices.

  4. Repeat assessments. Revisit risk at least annually and after acquisitions, mergers, new programs, or material workforce changes.

  5. Track state and local developments. Plan for a patchwork of requirements, especially with multistate and remote workforces.

  6. Define organizational values and risk tolerance. Align lawful workforce programs with business priorities and culture.

  7. Build a cross-functional team. Include HR, compliance, legal, procurement, risk, data, and business leaders.

  8. Identify high-risk practices. Review current decision criteria; understand future initiatives, including any planned use of artificial intelligence in selection decisions; and identify areas of high risk that should be monitored regularly.

  9. Decide what data to collect and retain. Evaluate collection and use of employment data, including employee demographic information, on documented legal and business purposes, instead of focusing on whether the information is subject to a federal filing requirement.

  10. Monitor quantitatively and qualitatively. Evaluate your employment practices through quantitative and qualitative metrics. Apply the discipline of financial auditing - regular testing, trend analysis, and controls - to identify gaps, assess effectiveness, and drive continuous improvement.

From Prescribed Rules to Proactive Governance

The compliance landscape may be less prescriptive, but it is not less consequential. Employers that preserve useful data, understand their actual practices, involve the right internal partners, and document why their decisions are reasonable will be better positioned to respond to contracting officials, enforcement agencies, employees, and future regulatory change. The worst option, the presenters emphasized, is to treat deregulation as permission to do nothing.

 

This recap is for educational purposes only and does not constitute legal advice. Organizations should consult qualified counsel regarding their specific obligations and circumstances.

Contact Us

Get in Touch With a Berkshire Expert