Data & Analytics|September 30, 2026|12 min read

Cost Volume Data Lineage: An Audit Trail DCAA Can Follow

Build a documented lineage from ledger extract to priced cost volume so bid rates, indirect pools, and escalation assumptions can be re-derived years later under DCAA and DCMA review.

Marcus Chen|Senior Compliance Analyst

It is a Tuesday morning and a DCAA auditor asks you to support one senior engineer labor line from a cost volume you submitted 19 months ago. Not the whole volume. One line. Show the booked hours it came from, the labor distribution report that grouped them, the pool and base that produced the indirect load, the escalation assumption for option year two, and who approved the manual override in the fringe rate.

If your answer starts with "let me find the analyst who built the model," you already have a finding forming.

Cost volume data lineage is a recorded chain from each system of record, through every transformation, to the number printed in the submitted volume, with a named owner, an extract query, an extraction date, and a frozen snapshot at each step. It is what turns an audit response from a reconstruction project into a retrieval. The obligations that assume this kind of record are not new: the Table 15-2 submission format requires supporting breakdowns and identification of judgmental factors [1], the Audit and Records-Negotiation clause gives the Government examination rights over records supporting proposed and incurred cost [2], and final indirect cost rates get established through a settlement process that compares what you proposed to what you actually incurred [4].

This article gives you the lineage architecture, a field-level register format, a screening gate for unallowables, and the audit response package you should assemble before anyone asks for it.

The Question That Ends Careers: "Show Me How You Got That Rate"

The failure mode here is almost never fraud. It is an analyst-owned rate model, a folder of vendor quotes nobody indexed, and an ERP that has posted eleven months of transactions since submission. The numbers were defensible when they were built. They are just no longer reachable.

That gap matters because the examination rights in the Audit and Records clause extend to the records that support proposed cost, not only the PDF you uploaded [2]. Records retention under FAR Subpart 4.7 applies to the underlying documentation as well [5]. When a contracting officer or a DCAA auditor asks for derivation, "we no longer have the extract" is not a neutral answer. It converts a rate question into a business system question.

The second reason it matters is timing. Under cost-reimbursement work, the Allowable Cost and Payment clause drives an annual incurred cost submission that must reconcile to your accounting system [3], and final indirect cost rates are settled through the process in FAR 42.705 [4]. Auditors compare proposed rates against incurred results as a matter of course, and DCAA publishes its audit posture and guidance openly [7]. If the proposed rate cannot be traced, every variance becomes a conversation you enter without evidence.

Four Feeds, One Number, Zero Traceability

Walk through how a typical mid-size contractor assembles a cost volume. An ERP general ledger extract lands in a workbook. A staffing spreadsheet from the capture team supplies hours by labor category. A shared drive folder holds vendor quotes and subcontractor pricing at varying levels of completeness. A rate model applies pools, bases, fringe, and escalation, and exactly one person understands its tab structure.

The gap widens the moment you submit. The live accounting system keeps posting while your submitted volume is frozen in a PDF. Then a chart-of-accounts change, a reorganization, or an acquisition silently remaps pools between the proposal and the incurred cost submission, and nobody writes down the mapping because it happened in finance, not in pricing.

Subcontractor portals and automated allocation rules add feeds faster than documentation practice absorbs them. The result is that the number is correct and unprovable at the same time.

FeedSystem of RecordWhat BreaksLineage ControlOwner
Labor distributionERP labor distribution moduleRate rebuilt from a later period after accounts are remappedFrozen extract with query ID, period, and checksumPricing analyst
Timekeeping hoursTimekeeping systemHours adjusted post-extract, so base no longer tiesPeriod-close lock plus a recorded as-of timestampAccounting manager
Purchase orders / ODCsERP procurement recordsQuotes superseded, no record of which version was pricedQuote register with quote date, vendor, and expirationContracts / purchasing
Subcontractor quotesSubcontractor submission packagePrime analysis missing, so proposed total is unsupportedCost or price analysis memo filed with the quoteSubcontracts manager
Escalation modelRate model fileAssumption source undocumented, treated as "standard"Versioned model file with cited index and approverPricing lead

Read that table as an assignment sheet, not a diagram. Every row needs a person, a retrievable artifact, and a control that survives the next reorganization.

Build the Field-Level Lineage Register

The register is the unglamorous core of this whole practice. Every field in the priced volume gets a row recording five things: source system, extract query or report ID, extraction date, transformation applied, and accountable owner. If a field cannot be described that way, it is an undocumented judgment call wearing a number costume.

Record judgmental factors immediately next to the number, because that is what the Table 15-2 format contemplates: pool and base definitions, allocation steps, escalation assumptions, and any manual override with its reason and approver [1]. Do not park these in a separate narrative document that gets rewritten during the final proposal revision. Keep them adjacent to the figure they explain so the two cannot drift apart.

Separate derived fields from entered fields, and require a documented method for anything typed by hand. Here is a worked lineage record for one labor category:

FIELD: Senior Systems Engineer, Base Year direct labor rate
  SOURCE        ERP labor distribution, report LD-204
  QUERY         Cost center 4410, job codes SE3*, FY25 P01-P09
  EXTRACTED     2026-02-14 09:20 ET, checksum a41f...c7
  TRANSFORM 1   Booked hours summed by job code (derived)
  TRANSFORM 2   Weighted average rate = total dollars / total hours (derived)
  TRANSFORM 3   Two long-term leave records excluded (entered)
                Reason: non-representative availability
                Approver: Pricing Lead, 2026-02-17
  TRANSFORM 4   Out-year escalation applied, cited index, model v3.2
  OUTPUT        Base year rate, Option Year 1-4 escalated rates
  OWNER         Pricing analyst (named), backup: Pricing Lead
  RETENTION     Per FAR Subpart 4.7 schedule, archive path recorded

Set retention and access consistent with FAR Subpart 4.7 for the register and every artifact it points to, because the retention requirement covers the supporting documentation and not just the submitted volume [5]. Assign an owner for the lineage record itself. A register with no owner becomes a register with no updates.

Freeze the Data Before the Ledger Moves On

Your proposal-time snapshot has to be immutable and physically separate from the production system that will keep changing. That means an archived copy of the exact extract, not a saved query you could re-run. A re-run against a live ledger in March does not reproduce a February extract, and the difference is exactly what an auditor will notice.

Use checksums or write-once storage so you can prove the archived extract is byte-identical to what fed the model. This is cheap insurance. A hash recorded in the register next to the extraction timestamp answers the "is this the same data" question in one line instead of one meeting.

Version the rate model itself, not only its output. Allocation logic, pool definitions, and formula changes are part of the derivation, and a spreadsheet saved over itself destroys them. Then maintain a revision log across the initial proposal, discussions, and each final proposal revision so submitted totals reconcile to the supporting narrative at any point in the negotiation history.

The mid-proposal refresh that quietly breaks your audit trail

Pricing gets a new ledger extract three days before submission to pick up a fresher period. The rate model updates. Nobody re-runs the unallowable cost screen, because the screen "already ran." You have now submitted indirect rates derived from data that was never screened, and your screening log points to a data version that no longer matches the proposal. If you refresh, you re-screen, you re-log, and you archive both extracts with a written reason for the swap.

Screen Unallowables on the Frozen Extract, Not at Year End

FAR 31.201-6 requires unallowable costs, and the costs directly associated with them, to be identified and excluded from any billing, claim, or proposal [9]. That is a pre-submission obligation, not a year-end cleanup task. Allowability itself turns on the tests in FAR 31.201-2: reasonableness, allocability, consistency with CAS or GAAP, and contract terms [8].

Build an account-level allowability matrix tied to the selected cost categories enumerated in FAR 31.205 [10], and record the rationale for each mapping decision instead of keeping it in one controller's memory. Then run the screen against the same frozen extract that produced the proposed indirect rates, and log the run with date, data version, and reviewer. That log is what makes the screened population identifiable a year later.

Re-run the screen after any chart-of-accounts change, reorganization, or acquisition, and reconcile before and after pool balances line by line with an explanation for each movement. Automated pool mappings and shared service allocations are exactly how an account that was clean last year absorbs unallowable activity without anyone touching it directly.

Finally, tie the screened pool balances forward. The same pools feed your provisional billing rates and the incurred cost submission required under the Allowable Cost and Payment clause [3], and eventually the final indirect cost rate settlement [4]. One screened population, carried forward, is a much shorter conversation than three unrelated ones.

One Rate Story for Every Audience

Four audiences look at your rates: the proposal evaluator, the DCMA rate reviewer, the billing side of your own company, and the auditor who settles final indirect rates. They should all see the same pool and base definitions. When bid rates, provisional billing rates, and forward pricing rate proposals use different structures, you have created three stories and will be asked to defend the differences.

Where Cost Accounting Standards apply, the model must actually do what your Disclosure Statement says it does, per the standards published in 48 CFR Chapter 99 [6]. This sounds obvious and fails constantly, usually because a pricing team introduced a service center allocation or a new base for a competitive reason and nobody amended the disclosed practice.

Build the crosswalk before anyone asks: submitted volume to trial balance, trial balance to incurred cost submission tie-out, and a change log covering every revision between the initial proposal and final proposal revisions. Keep subcontractor cost or price analysis in the same package, because the prime's analysis is part of what supports the proposed total.

Basis of estimate discipline is the evaluator-facing half of this. Each cost element needs a stated source, method, and assumption, consistent with the staffing described in the technical volume, so the evaluator can document support instead of inventing assumptions. That is also where cybersecurity assertions quietly become pricing problems: if the technical volume promises a controlled environment for covered defense information under the CMMC program codified at 32 CFR Part 170 [11], with controls drawn from NIST SP 800-171 [12] and flowdown governed by the DFARS clauses in 48 CFR Part 252 [13], the cost volume needs priced labor for documentation upkeep, monitoring, and assessment support. Unfunded assertions read as either unrealistic pricing or an unsupported technical claim, and both invite questions.

The Rehearsal: Re-Derive a Sampled Line Without the Analyst

Run the audit before the auditor does. Pick one line from a submitted volume, hand it to someone who did not build the model, and give them only the archived artifacts. No calls to the original analyst. No live ERP access.

Score the rehearsal on three measures: time to retrieve the frozen extract, time to explain the transformation chain, and number of judgment calls that turn out to be unrecorded. That third number is the one that predicts audit pain. Every unrecorded judgment call is a question you will answer from memory under conditions you do not control.

Use these maturity tiers to place yourself honestly:

  • Tier 1, spreadsheet only. Evidence is a workbook with no archived extract. Rate audit exposure is high and business-system risk is real. First fix: archive and checksum the extracts behind your most recent submission this week.
  • Tier 2, archived but unmapped. Extracts exist somewhere, but no register ties fields to sources. Exposure is moderate to high, driven by retrieval time. First fix: build the field-level register for the top ten cost drivers only.
  • Tier 3, registered. Every field has a source, query, date, and owner, but the model itself is not versioned and overrides are thin. Exposure is moderate. First fix: version the rate model and capture reason plus approver for every manual override.
  • Tier 4, registered and frozen. Immutable snapshots, versioned models, logged screening runs, and a rehearsed walkthrough. Exposure is low and limited to substantive disagreement rather than missing records. First fix: extend the same discipline to subcontractor quote packages.

The operational discipline here is the same one that makes requirement tracking work. Linking a requirement to an owner, an evidence artifact, and a next action is exactly what compliance matrix automation does for Section L and M, and what structured drafting does for narrative sections. Cost lineage is that pattern applied to numbers instead of prose: field, source, owner, evidence, next action. Teams that already run price-to-win modeling with documented assumption sets find the register easier to stand up, because the assumptions are already written down somewhere. Basis of estimate language belongs in your reusable content library alongside past performance and management approach text.

Frequently asked questions

What is cost volume data lineage?

A recorded chain from each originating system of record, through every transformation, to the figure in the submitted cost volume, with the extract query, extraction date, transformation logic, judgmental factors, and accountable owner captured at each step, plus a frozen snapshot of the data that fed the model.

How long must supporting records be kept?

Retention follows the schedules in FAR Subpart 4.7, and it applies to the underlying documentation, not only the final submitted volume [5]. Your archive plan should name the retention basis and the storage path in the register itself.

Does this apply to fixed-price bids?

Yes, in a narrower form. You may not face incurred cost submission or final rate settlement, but examination rights still reach records supporting proposed cost where the clause applies [2], and the Table 15-2 identification of judgmental factors still governs how the submission is built [1]. Fixed-price competitions generate reasonableness questions instead of realism adjustments, and both are answered with traceable bases of estimate, which is why a shift toward fixed-price awards changes the questions you field rather than removing the need for documented cost support.

Who owns the lineage record?

One named person, typically the pricing lead, with a named backup. Shared ownership means no ownership. The owner is accountable for archiving extracts, logging screening runs, versioning the model, and running the annual rehearsal.

Does DCAA require a specific lineage register format?

No prescribed template governs how you record lineage. What is required is that the proposal identify judgmental factors and supporting breakdowns in the Table 15-2 format [1], and that records supporting proposed and incurred cost stay available for examination [2] under the retention schedules in FAR Subpart 4.7 [5]. A field-level register is one way to meet those obligations rather than a separate requirement of its own.

How do bid rates differ from provisional billing rates?

Bid rates are the forward-looking rates proposed for a specific effort. Provisional billing rates are what you bill against during performance, and they are trued up when final indirect cost rates are established through the settlement process in FAR 42.705 [4], drawing on the incurred cost submission that the Allowable Cost and Payment clause requires [3]. Carrying one pool and base structure across both keeps that comparison short.

What should happen when the chart of accounts changes mid-cycle?

Re-run unallowable cost screening against the new structure and reconcile pool balances line by line before and after, with a written explanation for each movement, because FAR 31.201-6 requires unallowable costs and directly associated costs to stay identified and excluded from any proposal or billing [9]. Record the old-to-new account mapping in the register so the pre-change extracts stay interpretable.

Your Next Two Weeks

Week one

Pick your most recently submitted cost volume and attempt to re-derive three sampled lines using archived artifacts only. One direct labor rate, one indirect rate, and one significant subcontractor or ODC element. Record where each attempt stalls.

The metric to start tracking this week: the percentage of cost volume fields with a named system of record, extract date, and accountable owner. Baseline it, publish it, and set a target before the next submission.

Week two

Stand up the account-level allowability matrix against the selected cost categories in FAR 31.205 [10], with recorded rationale per mapping, and log your first screening run against a frozen, checksummed extract. Capture directly associated costs alongside each exclusion as FAR 31.201-6 requires [9].

Then go back to that Tuesday morning question about one senior engineer labor line from 19 months ago. The objective is not a better explanation. The objective is that the answer is a retrieval.

References