Time-and-effort certification: the signature at the centre of federal grant fraud
Effort certification is a personal attestation that federal payroll charges reflect actual work. It is executed as a checkbox on a period summary, on data the certifier cannot independently verify, often by an administrator clearing a queue on the principal investigator's behalf.
Why is time-and-effort certification a fraud mechanism?
Because it is a bulk approval in an administrative system, frequently completed by departmental staff rather than the person whose effort is being certified. Federal watchdogs have named false certifications a principal grant-fraud mechanism, and the artefact is a checkbox on a period summary.
- Federal investigators warned Congress on 24 June 2026 that false time-and-effort certifications and overstated compliance are central grant-fraud mechanisms.
- False Claims Act exposure is personal and trebled, and it attaches to the named certifier.
- Delegation is widespread and prohibited by most institutional policies, which means the practice is invisible rather than absent.
Part of Education and credential identity
The regulatory basis
Under 2 CFR Part 200, charges to federal awards for salaries and wages must be based on records that accurately reflect the work performed. The Uniform Guidance moved away from prescribing a particular method — the older effort-reporting mandate — toward requiring that internal controls produce reasonable assurance that charges are accurate, allowable and properly allocated.
Most institutions responded by keeping effort certification, because it was the control they had. The certification is therefore doing regulatory work it was not redesigned for, in a framework that asks about internal control effectiveness rather than about the form of the record.
What was said to Congress
On 24 June 2026, federal investigators testified about grant fraud, identifying false time-and-effort certifications and overstated compliance representations among the principal mechanisms. A House committee hearing the same month examined the False Claims Act's role in combating grant fraud.
Enforcement in 2026 was consistent with that emphasis. A major research university paid $2.3 million in January 2026 under civil monetary penalty authority after self-disclosing falsified NIH grant data, and HHS-OIG continued publishing enforcement actions for false claims to NIH-funded grants through the year.
Why the certification is evidentially weak
| What the certifier is attesting | What the system captures | Gap |
|---|---|---|
| That the effort distribution reflects actual work | A percentage allocation across awards | No basis; the percentages were computed by payroll |
| That they have direct knowledge of the work | A user id and timestamp | No record of what was examined |
| That they personally certified | A workflow completion | Frequently completed by a delegate |
| That the charges are allowable | Implicit in the certification | Allowability is a separate determination |
Row three is the one that converts an administrative weakness into personal legal exposure. A principal investigator whose certification was clicked by a departmental administrator has, on the face of the record, personally certified.
The delegation problem, stated honestly
Institutional policy almost universally prohibits delegating effort certification. The practice persists because principal investigators are travelling, on sabbatical, or simply unresponsive, and certification deadlines are hard.
Prohibiting a practice that operational reality requires does not eliminate it. It makes it undocumented, which is the worst of both outcomes: the institution gets the exposure and none of the visibility.
A policy that is universally violated for good operational reasons is a design problem wearing a compliance costume.
The Effort Certification Evidence Standard
Two elements: bind the certification to what was shown, and make permitted delegation explicit.
{
"type": "manav-stmt/1",
"action": "effort_certification",
"render": [
"Certifier: [name] Period: [start]–[end]",
"Award [id]: [pct]% — [title]",
"Award [id]: [pct]% — [title]",
"Institutional / non-sponsored: [pct]%",
"Basis: [personal knowledge | suitable means of verification]"
],
"certifier": "[credential assertion]",
"delegation": "[reference, where the certifier authorised another to prepare]"
}
The delegation reference is the important addition. It represents what institutions actually do: a principal investigator authorises an administrator to prepare and submit, while the certification itself remains theirs and is signed by them.
Why an investigator should want this
The framing that works with faculty is not compliance. It is personal protection.
False Claims Act liability is personal, damages are trebled, and a whistleblower action can name an individual. An investigator whose effort certification was submitted by someone else currently has no way to demonstrate that, and the record affirmatively says they certified.
A signed certification is the investigator's own record of exactly what they attested to. The absence of their signature on a certification submitted in their name is, equally, evidence.
Sequencing
- Measure first: sample a certification cycle and determine how many were completed from an IP address or session associated with someone other than the certifier. Most institutions have never looked.
- Fix the delegation policy to permit preparation-by-delegate with certification-by-principal, which is what already happens.
- Bind the certification to the rendered distribution.
- Report the delegation rate to the research compliance committee, which converts an invisible practice into a managed one.
What the certification asserts
That the distribution of activity represents a reasonable estimate of the work performed. It is a statement about a person's time, made under penalties that attach to the certifier and the institution, on a form whose default is to accept the system's allocation.
| Role | Should certify | Usually certifies |
|---|---|---|
| The individual whose effort it is | Yes | Sometimes |
| Someone with suitable means of verification | Yes | Sometimes |
| Departmental administrator | No | Frequently |
| A batch process on a deadline | No | In effect, yes |
Objections and honest limits
“Administrators have suitable means of verification.” Sometimes they genuinely do. The gap is that the record does not distinguish the cases, so an investigation cannot tell which certifications were informed.
“Bulk certification is a practical necessity.” At volume, yes. Then the record should say who certified, on what basis, and whether they were the individual or someone with verification means — which costs one field.
Making effort certification defensible
- Record who certified and in what capacity. Individual, or someone with suitable means of verification.
- Render the allocation being certified. Percentages by award, not a summary line.
- Bind the signature to that allocation. So a later adjustment does not inherit the certification.
- Flag certifications made by a third party. Not to prohibit them — to make them visible.
Terms used here
- Time and effort certification
- The periodic attestation that salary charged to federal awards reasonably reflects the work performed.
- Suitable means of verification
- The standard for someone other than the individual certifying their effort.
- Cost transfer
- A post-hoc reallocation of charges between awards, which should invalidate a prior certification and frequently does not.
Frequently asked questions
Does Uniform Guidance require effort certification? It requires that charges be based on records accurately reflecting work performed, supported by adequate internal controls. It does not mandate the certification form specifically, which is why institutions have latitude in how they discharge it.
Is delegated submission prohibited? Most institutional policies prohibit it. The proposal here is to permit delegated preparation explicitly while requiring the certification itself to be signed by the certifier, which aligns policy with practice.
What if the investigator genuinely cannot certify in time? Define an escalation with a documented alternate certifier who has suitable means of verification, and record it. Silence is worse than a documented exception.
Does this reduce FCA exposure? It provides evidence about who certified and what they saw. It does not alter the legal standard, and this article gives no legal advice.
Who is supposed to certify effort? The individual, or someone with suitable means of verification. Departmental administrators frequently certify without the record distinguishing the cases.
Why does binding matter here? Because cost transfers adjust the allocation afterwards, and an unbound certification silently continues to cover the new figures.
Is bulk certification prohibited? No. It should be visible — the record should say who certified, in what capacity, and over which allocation.
Where this fits in Manav
Manav binds the authorising person to the exact record or disbursement being authorised, and produces a receipt an auditor, a regulator or a receiving institution can verify without contacting the issuer.