Feature Operational Risk
Tetra Tech’s $57M False Claims Settlement: When Control Evidence Is the Product
The Tetra Tech False Claims Act settlement turns on allegedly falsified soil data. Here is the evidence-integrity control plan.
Table of Contents
TL;DR
- Tetra Tech EC Inc. paid $57 million to resolve DOJ allegations that it fabricated work and falsified data used by the Navy to assess radiological cleanup at Hunters Point Naval Shipyard.
- DOJ alleged technicians substituted known clean soil for samples from potentially contaminated locations and that scan records were manipulated in a database.
- The control failure is bigger than “bad data.” The evidence itself was the contracted deliverable, and downstream release, remediation, payment, and public-safety decisions depended on its integrity.
- Teams should connect chain of custody, raw-data immutability, exception review, invoice reconciliation, independent resampling, and whistleblower escalation into one evidence-lineage control.
The Tetra Tech False Claims Act settlement puts a price on a control problem risk teams routinely underestimate: what if the evidence proving the work was done is itself unreliable?
On August 24, 2026, DOJ announced that Tetra Tech EC Inc., a wholly owned subsidiary of Tetra Tech Inc., paid $57 million to resolve allegations involving radiological testing and remediation at the former Hunters Point Naval Shipyard in San Francisco. The government says the Navy relied on Tetra Tech’s work and data to determine whether the property was free from harmful radiation and ready for redevelopment.
According to the DOJ settlement announcement, technicians were allegedly instructed to discard soil collected from potentially contaminated locations, replace it with known clean soil, and submit the replacement samples for laboratory analysis. DOJ also alleged that database scan results were intentionally manipulated so scans taken at different locations appeared to have been performed by the same technician at the same time.
The settlement resolves allegations only; there has been no determination of liability. But the operational-risk lesson is concrete. A reviewer cannot validate a high-stakes outcome by inspecting a polished final report when the collection, custody, raw data, and change history underneath it are not independently reconstructable.
What happened at Hunters Point
DOJ’s account starts with Navy contracts issued between 2003 and 2014. Tetra Tech was required to investigate soil and buildings at Hunters Point, identify areas with excessive radiation, and perform remediation so the property could eventually be transferred to the City of San Francisco for redevelopment.
The alleged misconduct attacked the process at two points:
- Physical evidence. Potentially contaminated samples were allegedly discarded and replaced with clean soil before laboratory analysis.
- Digital evidence. Scan results were allegedly altered in the database to misrepresent where, when, and by whom work occurred.
DOJ alleged that Tetra Tech benefited by receiving contract award fees it had not earned and avoiding additional remediation obligations, reducing costs and increasing profit.
The settlement followed a consolidated whistleblower matter brought by former employees and contractors under the False Claims Act’s qui tam provisions: United States ex rel. Jahr, et al. v. Tetra Tech EC, Inc., Case No. 13-3835 in the Northern District of California. DOJ says the relators’ share is approximately $11.97 million.
The same announcement notes a separate $40 million settlement under the Comprehensive Environmental Response, Compensation, and Liability Act, or CERCLA, entered by the federal court on July 2, 2025. Keep the two figures separate: the $57 million announced in 2026 resolved False Claims Act allegations; the $40 million was a separate environmental settlement.
| Resolution | Amount | Stated basis | Status |
|---|---|---|---|
| 2026 False Claims Act settlement | $57 million | Alleged fabricated work and falsified data tied to Navy contracts | Paid; allegations resolved without a determination of liability |
| 2025 CERCLA settlement | $40 million | Separate Superfund resolution referenced by DOJ | Entered by the federal court July 2, 2025 |
| Relators’ share from FCA settlement | About $11.97 million | Qui tam share for former employees and contractors | Reported by DOJ as part of the FCA resolution |
The dollar amount gets attention. The evidence architecture is what practitioners should study.
Why this is an evidence-integrity case
In many controls, evidence is a byproduct. A manager approves a payment; the workflow retains the approval. A system blocks an unauthorized user; the log records the event.
At Hunters Point, the test data was central to the service itself. Collection locations, sample identity, instrument readings, custody records, laboratory results, and database entries collectively supported decisions about remediation, payment, property transfer, and public safety.
That creates a different risk model:
| Evidence layer | Failure mode | Downstream consequence |
|---|---|---|
| Collection | Wrong location, substituted item, incomplete sample, undocumented retest | Test result does not represent the target condition |
| Custody | Unrecorded handoff, broken seal, relabeled sample | Identity and integrity cannot be proven |
| Instrument/raw data | Deleted file, overwritten reading, changed timestamp | Reviewer sees only a curated result |
| Transformation | Manual edit, undocumented exclusion, altered coordinates | Final data departs from source evidence |
| Approval | Same person prepares, changes, and accepts results | Manipulation can pass without challenge |
| Reporting | Summary omits exceptions or uncertainty | Decision-maker receives false confidence |
| Billing | Invoice relies on completion status not reconciled to verified work | Payment can occur for unsupported deliverables |
A policy requiring “accurate records” will not control that chain. Each transition needs identity, authorization, traceability, and independent challenge.
The False Claims Act, summarized by the Justice Department’s Civil Division, creates exposure when false or fraudulent claims are knowingly submitted or caused to be submitted to the government. In an evidence-based contract, records supporting performance can be material to payment even if the invoice itself contains no obvious arithmetic error.
The controls that should surround high-stakes evidence
1. Bind the physical or source event to a unique identity
Assign a unique, tamper-evident identifier at the point of collection or performance—not later in an office workflow.
For a physical sample, the minimum record should include:
- unique sample ID;
- collector identity;
- date and time;
- geolocation or designated collection point;
- collection method;
- container or seal identifier;
- required photo or instrument evidence;
- custody transfer history; and
- reason and authorization for any rejection, destruction, or recollection.
For a financial-services analogue, substitute “transaction, complaint, call, model decision, access review, or remediation test” for “sample.” The principle holds. Evidence created after the event, without a source-system link, is weaker than evidence bound to the event when it occurred.
2. Preserve raw data and make changes visible
The final spreadsheet should never be the system of record for high-consequence testing.
Use controls that preserve:
- original instrument or source-system output;
- cryptographic hash or write-once retention where appropriate;
- user-level access logs;
- before-and-after values for every change;
- reason code and ticket for corrections;
- reviewer approval for material edits; and
- linkage from reported result back to the raw record.
If operational needs permit data correction, do not overwrite history. Append a corrected record, retain the original, identify the person making the change, and document why the correction was necessary.
3. Reconcile work, evidence, decisions, and invoices
A completion certificate should not trigger payment by itself.
Build a four-way reconciliation:
- Work scheduled: What location, population, control, or deliverable was required?
- Work performed: What source evidence proves it occurred?
- Result accepted: Who reviewed exceptions and concluded requirements were met?
- Amount billed: What invoice line and award fee depends on that accepted work?
Unmatched items should stop payment or require a documented exception approved outside the delivery team.
This is where ownership gets messy. Operations may say invoice validation belongs to Finance. Finance may say technical completion belongs to the project manager. Compliance may not see the invoice at all. The control needs a named integrator—often the accountable program owner—who certifies that technical acceptance and payment evidence reconcile.
4. Independently retest what management most wants to pass
Risk-based sampling should focus on incentives and anomalies, not only random coverage.
A starting sample design could prioritize:
- locations or records near a release threshold;
- results that changed from fail to pass after rework;
- high-value milestones or award-fee periods;
- repeated collections by the same crew;
- unusual time or location patterns;
- destroyed, rejected, or recollected samples;
- manual database changes; and
- work completed unusually quickly.
These are illustrative risk factors, not mandated thresholds. Calibrate them using the process, contract, historical exceptions, and consequences of a false conclusion.
The independent tester should control sample selection and obtain evidence from source systems. Letting the delivery team choose “representative” examples creates a showroom, not a test.
5. Treat anomalies as possible integrity events
A duplicated timestamp may be a harmless system artifact. A location mismatch may be a data-entry error. A cluster of both may indicate something worse.
Create integrity-specific escalation triggers such as:
- source record missing for a reported result;
- duplicate or impossible time-location combinations;
- sample destruction without approved reason;
- unusually high manual-edit rate;
- repeated use of shared credentials;
- laboratory receipt inconsistent with field custody;
- retest results materially different from originals; or
- whistleblower allegation involving substitution, falsification, or pressure to pass.
Do not route these only through routine data-quality cleanup. Preserve records, restrict alteration, involve Legal and Compliance, assess payment and reporting impact, and determine whether an independent investigation is needed.
Whistleblowers are part of the control environment
The Tetra Tech matter was brought by former employees and contractors. That fact should change how a program evaluates speak-up controls.
A hotline metric showing “zero substantiated complaints” can mean the process is clean. It can also mean contractors do not know the channel, fear retaliation, or believe reports disappear into management.
For evidence-intensive work, test whether:
- employees and contractors receive the reporting channel at onboarding;
- reports can bypass the project chain of command;
- allegations involving evidence integrity trigger preservation steps immediately;
- investigators are independent from the people whose results are challenged;
- retaliation monitoring continues after case closure; and
- issue closure requires proof that the root cause—not just one record—was addressed.
The statutory False Claims Act framework includes qui tam mechanisms that permit private parties to bring actions on behalf of the United States. A credible internal escalation path gives the organization a chance to identify and address misconduct before the problem expands across years of work, payments, and decisions.
Five things to check Monday morning
1. Pick one decision that depends on submitted evidence
Choose a high-consequence process: customer remediation, model validation, fair-lending testing, sanctions alert closure, vendor SLA certification, cybersecurity patch evidence, business-continuity testing, or government-contract performance.
Write down the decision and every evidence object supporting it.
2. Trace one record backward without help from its preparer
Can a second-line reviewer move from the final report to the source event, raw data, custody or workflow history, changes, exception decisions, approval, and related payment?
If the preparer has to explain where everything is, the evidence chain is person-dependent.
3. Find overwrite capability
Identify who can edit source values, timestamps, locations, status, ownership, and completion fields. Review whether edits preserve prior values and generate alerts.
A quarterly access review does not answer this. You need to know what privileged users can change and whether anyone reviews actual changes.
4. Reconcile exceptions to outcomes
Select rejected records, retests, overrides, reopened issues, and manual corrections. Determine whether they are overrepresented in passing results or payment milestones.
This is an anti-gaming test. A dashboard can show a high pass rate because failed items were deleted, relabeled, or repeatedly retested until they passed.
5. Open issues at the right level
Do not create one vague issue called “improve data quality.” Separate the failure modes:
| Issue | Owner | Closure evidence |
|---|---|---|
| Source records can be overwritten | Data platform owner | Immutable history enabled and independently tested |
| Chain-of-custody handoffs are incomplete | Operations lead | Required scans enforced; sampled transfers reconcile |
| Manual edits lack review | Quality Assurance | High-risk edits routed to independent approval; exception sample tested |
| Acceptance is disconnected from payment | Program owner and Finance | Four-way reconciliation operating for sampled invoices |
| Contractors cannot bypass management | Compliance | Direct channel deployed, awareness tested, retaliation monitoring documented |
That structure matters because closure testing differs for each root cause.
A 30/60/90-day evidence-integrity plan
Days 1–30: map and contain
Owner: Chief Risk Officer or Operational Risk lead, with the accountable business owner.
- Inventory decisions that rely on high-stakes internally or externally produced evidence.
- Select the top process based on customer, safety, regulatory, or financial consequence.
- Map source, custody, transformation, approval, reporting, and payment lineage.
- Freeze destructive retention practices for relevant records while gaps are assessed.
- Open discrete issues for missing lineage, overwrite access, weak segregation, and unreconciled payment.
Evidence: lineage map, access inventory, retention decision, issue records, and risk acceptance for any interim operation.
Days 31–60: rebuild the control chain
Owner: Operations, Data Governance, Quality Assurance, and Finance.
- Implement unique identifiers and required metadata at source.
- Preserve original records and before-and-after change history.
- Establish risk-based independent retesting.
- Connect technical acceptance to invoice approval.
- Define integrity-event triggers and preservation procedures.
- Add contractor reporting channels and investigation independence.
Evidence: configured workflows, access logs, reconciliation output, retest results, investigation playbook, and training completion.
Days 61–90: prove it works
Owner: Internal Audit or independent second-line testing.
- Select samples without relying on the process owner.
- Reconstruct final decisions from raw evidence.
- Attempt unauthorized and authorized changes in a controlled test environment.
- Verify alerts and approvals for high-risk edits.
- Reconcile rejected, retested, and overridden records to final outcomes.
- Validate issue closure using operating evidence, not implementation screenshots.
Evidence: test script, sample population, exceptions, remediation tickets, closure validation, and risk-committee reporting.
The EPA-hosted 2020 Tetra Tech litigation filing is also a reminder that contested technical work can generate years of litigation and competing interpretations. Preserve the source record, decision logic, and change history as if an independent reviewer will need to reconstruct them long after the project team has moved on—because they may.
The lesson from the Tetra Tech settlement
The most dangerous evidence failure is not a missing attachment. It is a complete-looking record that no longer represents what happened.
Take one high-stakes control result this week. Trace it from report to raw event, inspect every place it can be changed, reconcile it to the decision and payment it supported, and ask an independent reviewer to reproduce the conclusion.
If that chain breaks, open the issue now. The Issues Management Tracker & Template can assign the root cause, remediation owner, due date, evidence requirement, and closure test before a data-integrity gap becomes an enforcement narrative.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
How much did Tetra Tech pay in the Hunters Point False Claims Act settlement?
What did DOJ allege Tetra Tech did at Hunters Point?
Did Tetra Tech admit False Claims Act liability?
What control would best detect substituted samples or manipulated test data?
Who should own evidence integrity in a regulated program?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Operational Risk
KRI Traceability Matrix: Link Risk, Control, Incident, Threshold, Owner, and Action
Build a KRI traceability matrix that connects each indicator to risks, controls, incidents, thresholds, owners, breaches, and actions.
Aug 22, 2026
Operational Risk
RCSA Risk-Statement Rewrite Lab: Cause–Event–Impact Examples and Testability Checks
Vague RCSA risk statements don't just frustrate examiners — they make your entire RCSA unauditable. Here's how to rewrite them using cause–event–impact syntax, with before-and-after examples and a testability rubric.
Aug 21, 2026
Operational Risk
Post-Approval Product Change Review: When to Reopen the Risk Assessment
Run a product change risk assessment review with clear reopen triggers, targeted reassessment rules, approvals, and retained evidence.
Aug 20, 2026