Manav.id
Compliance · 5 min read

Time-and-effort certification: the signature at the centre of federal grant fraud

Time-and-effort certification: the signature at the centre of federal grant fraud

Effort certification is a personal attestation that federal payroll charges reflect actual work. It is executed as a checkbox on a period summary, on data the certifier cannot independently verify, often by an administrator clearing a queue on the principal investigator's behalf.

Why is time-and-effort certification a fraud mechanism?

Because it is a bulk approval in an administrative system, frequently completed by departmental staff rather than the person whose effort is being certified. Federal watchdogs have named false certifications a principal grant-fraud mechanism, and the artefact is a checkbox on a period summary.

Key takeaways
  • Federal investigators warned Congress on 24 June 2026 that false time-and-effort certifications and overstated compliance are central grant-fraud mechanisms.
  • False Claims Act exposure is personal and trebled, and it attaches to the named certifier.
  • Delegation is widespread and prohibited by most institutional policies, which means the practice is invisible rather than absent.

The regulatory basis

Effort workedthe actual factPeriod summary generatedfrom payroll allocationCertified in bulkoften departmental staffCharged to the awardon that certification
The signature is about someone's time. Frequently they are not the one signing.

Under 2 CFR Part 200, charges to federal awards for salaries and wages must be based on records that accurately reflect the work performed. The Uniform Guidance moved away from prescribing a particular method — the older effort-reporting mandate — toward requiring that internal controls produce reasonable assurance that charges are accurate, allowable and properly allocated.

Most institutions responded by keeping effort certification, because it was the control they had. The certification is therefore doing regulatory work it was not redesigned for, in a framework that asks about internal control effectiveness rather than about the form of the record.

What was said to Congress

On 24 June 2026, federal investigators testified about grant fraud, identifying false time-and-effort certifications and overstated compliance representations among the principal mechanisms. A House committee hearing the same month examined the False Claims Act's role in combating grant fraud.

Enforcement in 2026 was consistent with that emphasis. A major research university paid $2.3 million in January 2026 under civil monetary penalty authority after self-disclosing falsified NIH grant data, and HHS-OIG continued publishing enforcement actions for false claims to NIH-funded grants through the year.

Why the certification is evidentially weak

What the certifier is attestingWhat the system capturesGap
That the effort distribution reflects actual workA percentage allocation across awardsNo basis; the percentages were computed by payroll
That they have direct knowledge of the workA user id and timestampNo record of what was examined
That they personally certifiedA workflow completionFrequently completed by a delegate
That the charges are allowableImplicit in the certificationAllowability is a separate determination

Row three is the one that converts an administrative weakness into personal legal exposure. A principal investigator whose certification was clicked by a departmental administrator has, on the face of the record, personally certified.

The delegation problem, stated honestly

Institutional policy almost universally prohibits delegating effort certification. The practice persists because principal investigators are travelling, on sabbatical, or simply unresponsive, and certification deadlines are hard.

Prohibiting a practice that operational reality requires does not eliminate it. It makes it undocumented, which is the worst of both outcomes: the institution gets the exposure and none of the visibility.

A policy that is universally violated for good operational reasons is a design problem wearing a compliance costume.

The Effort Certification Evidence Standard

Two elements: bind the certification to what was shown, and make permitted delegation explicit.

{
  "type": "manav-stmt/1",
  "action": "effort_certification",
  "render": [
    "Certifier: [name]  Period: [start]–[end]",
    "Award [id]: [pct]%  — [title]",
    "Award [id]: [pct]%  — [title]",
    "Institutional / non-sponsored: [pct]%",
    "Basis: [personal knowledge | suitable means of verification]"
  ],
  "certifier": "[credential assertion]",
  "delegation": "[reference, where the certifier authorised another to prepare]"
}

The delegation reference is the important addition. It represents what institutions actually do: a principal investigator authorises an administrator to prepare and submit, while the certification itself remains theirs and is signed by them.

Why an investigator should want this

The framing that works with faculty is not compliance. It is personal protection.

False Claims Act liability is personal, damages are trebled, and a whistleblower action can name an individual. An investigator whose effort certification was submitted by someone else currently has no way to demonstrate that, and the record affirmatively says they certified.

A signed certification is the investigator's own record of exactly what they attested to. The absence of their signature on a certification submitted in their name is, equally, evidence.

Sequencing

  1. Measure first: sample a certification cycle and determine how many were completed from an IP address or session associated with someone other than the certifier. Most institutions have never looked.
  2. Fix the delegation policy to permit preparation-by-delegate with certification-by-principal, which is what already happens.
  3. Bind the certification to the rendered distribution.
  4. Report the delegation rate to the research compliance committee, which converts an invisible practice into a managed one.

What the certification asserts

That the distribution of activity represents a reasonable estimate of the work performed. It is a statement about a person's time, made under penalties that attach to the certifier and the institution, on a form whose default is to accept the system's allocation.

Who should certify, and who usually does
RoleShould certifyUsually certifies
The individual whose effort it isYesSometimes
Someone with suitable means of verificationYesSometimes
Departmental administratorNoFrequently
A batch process on a deadlineNoIn effect, yes

Objections and honest limits

“Administrators have suitable means of verification.” Sometimes they genuinely do. The gap is that the record does not distinguish the cases, so an investigation cannot tell which certifications were informed.

“Bulk certification is a practical necessity.” At volume, yes. Then the record should say who certified, on what basis, and whether they were the individual or someone with verification means — which costs one field.

Making effort certification defensible

  1. Record who certified and in what capacity. Individual, or someone with suitable means of verification.
  2. Render the allocation being certified. Percentages by award, not a summary line.
  3. Bind the signature to that allocation. So a later adjustment does not inherit the certification.
  4. Flag certifications made by a third party. Not to prohibit them — to make them visible.

Terms used here

Time and effort certification
The periodic attestation that salary charged to federal awards reasonably reflects the work performed.
Suitable means of verification
The standard for someone other than the individual certifying their effort.
Cost transfer
A post-hoc reallocation of charges between awards, which should invalidate a prior certification and frequently does not.

Frequently asked questions

Does Uniform Guidance require effort certification? It requires that charges be based on records accurately reflecting work performed, supported by adequate internal controls. It does not mandate the certification form specifically, which is why institutions have latitude in how they discharge it.

Is delegated submission prohibited? Most institutional policies prohibit it. The proposal here is to permit delegated preparation explicitly while requiring the certification itself to be signed by the certifier, which aligns policy with practice.

What if the investigator genuinely cannot certify in time? Define an escalation with a documented alternate certifier who has suitable means of verification, and record it. Silence is worse than a documented exception.

Does this reduce FCA exposure? It provides evidence about who certified and what they saw. It does not alter the legal standard, and this article gives no legal advice.

Who is supposed to certify effort? The individual, or someone with suitable means of verification. Departmental administrators frequently certify without the record distinguishing the cases.

Why does binding matter here? Because cost transfers adjust the allocation afterwards, and an unbound certification silently continues to cover the new figures.

Is bulk certification prohibited? No. It should be visible — the record should say who certified, in what capacity, and over which allocation.

Where this fits in Manav

Manav binds the authorising person to the exact record or disbursement being authorised, and produces a receipt an auditor, a regulator or a receiving institution can verify without contacting the issuer.

See issuance receipts →

Sources and further reading