The FAR Mandatory Disclosure Rule: What Every Government Contractor Needs to Know
Government contractors spend significant time focused on winning contracts, delivering performance, and managing compliance requirements. Yet one of the most important compliance obligations in federal contracting often receives attention only after a problem has already surfaced.
The Federal Acquisition Regulation (FAR) Mandatory Disclosure Rule (MDR) requires contractors to disclose certain violations of law, False Claims Act issues, and significant overpayments discovered during contract performance. Failure to comply can result in suspension, debarment, financial penalties, reputational damage, and the loss of future contracting opportunities.
For many contractors, the challenge is not understanding that disclosure may be required. The challenge is knowing when the obligation begins and having the processes in place to respond appropriately.
As federal agencies continue to increase scrutiny of contractor ethics, cybersecurity, billing practices, and internal controls, understanding the Mandatory Disclosure Rule has become a critical component of doing business with the federal government.
What Is the Mandatory Disclosure Rule?
The Mandatory Disclosure Rule is primarily implemented through FAR 52.203-13, Contractor Code of Business Ethics and Conduct.
The rule requires contractors to disclose credible evidence of:
Violations of federal criminal law involving fraud, bribery, gratuities, or conflicts of interest.
Violations of the Civil False Claims Act.
Significant overpayments received in connection with a federal contract.
The disclosure must generally be submitted to the appropriate Office of Inspector General (OIG) with a copy provided to the Contracting Officer.
Perhaps most importantly, the obligation is ongoing. It extends throughout contract performance and continues for three years after final payment.
This means compliance is not simply a proposal requirement or contract administration exercise. It is a continuous responsibility that follows the entire lifecycle of a federal award.
The Biggest Challenge: Defining "Credible Evidence"
One of the most difficult aspects of the rule is determining when an issue becomes serious enough to require disclosure.
The FAR does not provide a precise definition of "credible evidence."
Consider the following scenarios:
An employee reports a potential labor charging issue.
An internal audit identifies questionable billing practices.
A subcontractor raises concerns regarding procurement integrity.
A hotline complaint alleges improper use of contract funds.
At what point does an allegation become credible evidence?
Unfortunately, there is no universal answer.
Many contractors make one of two mistakes:
First, they wait too long while attempting to conduct a complete investigation before reporting;
Second, they disclose prematurely before performing any meaningful assessment of the facts.
The most effective compliance programs balance these competing risks by conducting prompt preliminary reviews while maintaining a structured decision-making process.
Why Small Businesses Should Pay Attention
Many small businesses assume the Mandatory Disclosure Rule only affects large defense contractors.
That assumption can be costly.
As agencies increasingly evaluate contractor responsibility and integrity, small businesses are expected to maintain the same ethical standards as their larger counterparts.
In fact, smaller organizations often face greater risk because they may lack:
Formal compliance programs
Internal audit functions
Dedicated legal counsel
Established reporting mechanisms
A single compliance failure can have an outsized impact on a small business that relies heavily on government revenue.
Building a Compliance Program Before You Need One
The best time to prepare for a disclosure event is before one occurs.
An effective ethics and compliance program should include:
Written Policies and Procedures
Employees should understand expectations regarding ethics, procurement integrity, billing practices, cybersecurity, conflicts of interest, and reporting obligations.
Internal Reporting Mechanisms
Organizations should provide multiple avenues for employees to report concerns without fear of retaliation.
Training and Awareness
Compliance training should be tailored to employee responsibilities and refreshed regularly.
Internal Controls
Financial, operational, and contract management controls should help identify issues before they become systemic problems.
A mature compliance culture often identifies potential problems long before they reach the level of mandatory disclosure.
Do Not Ignore Overpayments
One of the most overlooked portions of the Mandatory Disclosure Rule involves significant overpayments.
Many contractors immediately think of fraud investigations when discussing mandatory disclosures. However, overpayments often occur through routine business operations.
Examples include:
Labor charging errors
Incorrect indirect rates
Duplicate invoices
Contract administration mistakes
Government payment processing errors
Importantly, fraud is not required.
If a contractor receives a significant overpayment, disclosure obligations may still apply.
This is why strong accounting systems and contract management processes remain critical for government contractors.
Establish a Formal Disclosure Process
Every government contractor should have a documented process for evaluating potential disclosure situations.
That process should answer several key questions:
Who receives allegations or reports?
Who conducts investigations?
Who determines whether credible evidence exists?
When is legal counsel involved?
Who approves disclosures?
How are decisions documented?
Without a structured framework, organizations risk inconsistent decision-making and delayed responses.
Subcontractor Risk Is Your Risk
Prime contractors frequently focus on their own compliance programs while overlooking subcontractor activities.
However, subcontractor misconduct can create significant risk for the prime contractor.
Areas requiring attention include:
Labor charging practices
Procurement integrity compliance
Small business representations
Cybersecurity requirements
Cost accounting practices
Regular oversight, compliance certifications, and subcontractor monitoring activities can help reduce exposure.
What Government Agencies Really Want to See
When disclosures occur, agencies often focus less on the original mistake and more on how the contractor responds.
Government officials frequently evaluate:
Transparency
Cooperation
Root cause analysis
Corrective actions
Internal controls
Leadership accountability
A contractor that identifies an issue, investigates promptly, implements corrective actions, and communicates openly is often viewed far differently than one that ignores warning signs or attempts to conceal problems.
The question is not whether mistakes happen.
The question is how organizations respond when they do.
What This Means for GovCon
As federal oversight continues to evolve, compliance is becoming a competitive differentiator.
Contractors that invest in ethics programs, internal controls, training, and accountability are not simply reducing risk. They are strengthening their ability to win and retain government business.
For small and mid-sized contractors, the Mandatory Disclosure Rule should not be viewed as a legal requirement buried in the FAR. It should be viewed as a business readiness requirement.
Organizations that build compliance into their culture today will be better positioned to navigate audits, investigations, contract performance challenges, and future growth opportunities.
In government contracting, responsibility is not measured by whether problems occur. It is measured by how effectively contractors identify, address, and disclose them when they do.
If you want to focus on your business while winning government contracts, reach out to our team and let’s see how we can win together!