Reading the FCA settlements: what actually failed
The False Claims Act settlements against U.S. universities for research disclosure failures since 2020 are not a random set of unrelated failures. Reading across them, the same three things fail in almost every case: the researcher's disclosure did not reflect a foreign engagement that was visible in the public record; the institution had no process that would have caught the mismatch; and, when questioned, the institution could not show what it had reviewed. Verification is what changes each of those three.
The setup: why the FCA is the vehicle
A federal research award is federal funds obtained on the basis of a certification. Since NSPM-33 and the Common Forms transition, that certification explicitly covers the accuracy of researcher disclosures. A knowingly false certification that induces a federal payment is the core cause of action under the False Claims Act (31 U.S.C. §§3729–3733). The full framing is on the FCA enforcement page.
"Knowingly" under the statute includes actual knowledge, deliberate ignorance, and reckless disregard. The operational stakes for institutions live in that third clause — reckless disregard is where a failure to have a verification process becomes an FCA problem.
What the settlements have in common — the pattern
1. The predicate is a real disclosure, made inaccurately
Cases have rarely turned on a researcher inventing something out of whole cloth. The recurring predicate is a disclosure that was made and was true as far as it went, but omitted or mischaracterized something — a foreign appointment, an in-kind lab arrangement, a talent-program participation, a foreign grant characterized as a personal honor rather than a research support. The disclosure looked complete because nothing on it was clearly false; it was incomplete in a way that only cross-checking would reveal.
2. The record showed it — if anyone had looked
The details enforcement built cases on were often visible in the public record: papers acknowledging support the disclosure did not mention; foreign university websites listing the researcher as faculty; talent-program directories carrying the name; travel disclosures (institutional or federal) that did not line up with the funding narrative. In hindsight, every case involved information the institution could have seen. The failure was not that the information was hidden; it was that no process was verifying against it.
3. When challenged, the institution could not show what it had checked
The costliest institutional posture in enforcement discovery is the one where the answer to "what did you review before certifying?" is a narrative rather than an artifact. Narratives are contested; artifacts are not. Institutions that could point to a captured record of the checks they ran and the resolutions they reached were in a much stronger negotiating position than those that had to reconstruct it years later.
The unifying feature of the institutions involved
Institutions in the FCA settlement history to date are not unusual. Most are well-known research universities and academic medical centers with substantial federal funding, mature compliance offices, and long-established disclosure processes. What they lacked was the verification layer: the piece that reconciles what the researcher attested against what the public record shows, and captures the reconciliation as evidence per certification.
That is not a criticism of the compliance offices in question. The volume of disclosures at a research-intensive institution is beyond hand-reconciliation. The tools that would have caught the mismatches did not exist at the shape and integration those offices needed.
What a verification program has to answer
The specific defensive questions the enforcement record now generates:
- Did we reconcile this disclosure against the public record before certifying? Publications, affiliations, sponsor acknowledgments — reconciled per researcher, per certification.
- If a mismatch existed, did we see it, review it, and resolve it? Not "did we miss it" — did we see it, and can we show the resolution.
- Do we have an immutable record of the review as it stood at the time of the certification? Not a narrative reconstructed years later — a captured artifact from the moment.
- Can we produce that record on demand, for any past certification? Retrievability matters. IG investigations look at what an institution can show, not what it can describe.
What this changes about how institutions build compliance
Post-NSPM-33, compliance offices are being asked to do something that reads simple and is operationally hard: turn every certification into an evidence artifact. That requires verification, capture, and retrievability as infrastructure — not as tasks. The institutions that got hurt in the enforcement history to date did the tasks; what they did not have was the infrastructure. That is what has to change.
Verification for the institution certifying these disclosures.
Founding partners run ResearchSecurity.ai against their own compliance reality — with preferred terms and direct access to the team building it.