Skip to content
RiskTemplates · The Daily Brief Tuesday, August 25, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Feature Operational Risk

Tetra Tech’s $57M False Claims Settlement: When Control Evidence Is the Product

The Tetra Tech False Claims Act settlement turns on allegedly falsified soil data. Here is the evidence-integrity control plan.

By Rebecca Leung · August 25, 2026 ·
Table of Contents

TL;DR

  • Tetra Tech EC Inc. paid $57 million to resolve DOJ allegations that it fabricated work and falsified data used by the Navy to assess radiological cleanup at Hunters Point Naval Shipyard.
  • DOJ alleged technicians substituted known clean soil for samples from potentially contaminated locations and that scan records were manipulated in a database.
  • The control failure is bigger than “bad data.” The evidence itself was the contracted deliverable, and downstream release, remediation, payment, and public-safety decisions depended on its integrity.
  • Teams should connect chain of custody, raw-data immutability, exception review, invoice reconciliation, independent resampling, and whistleblower escalation into one evidence-lineage control.

The Tetra Tech False Claims Act settlement puts a price on a control problem risk teams routinely underestimate: what if the evidence proving the work was done is itself unreliable?

On August 24, 2026, DOJ announced that Tetra Tech EC Inc., a wholly owned subsidiary of Tetra Tech Inc., paid $57 million to resolve allegations involving radiological testing and remediation at the former Hunters Point Naval Shipyard in San Francisco. The government says the Navy relied on Tetra Tech’s work and data to determine whether the property was free from harmful radiation and ready for redevelopment.

According to the DOJ settlement announcement, technicians were allegedly instructed to discard soil collected from potentially contaminated locations, replace it with known clean soil, and submit the replacement samples for laboratory analysis. DOJ also alleged that database scan results were intentionally manipulated so scans taken at different locations appeared to have been performed by the same technician at the same time.

The settlement resolves allegations only; there has been no determination of liability. But the operational-risk lesson is concrete. A reviewer cannot validate a high-stakes outcome by inspecting a polished final report when the collection, custody, raw data, and change history underneath it are not independently reconstructable.

What happened at Hunters Point

DOJ’s account starts with Navy contracts issued between 2003 and 2014. Tetra Tech was required to investigate soil and buildings at Hunters Point, identify areas with excessive radiation, and perform remediation so the property could eventually be transferred to the City of San Francisco for redevelopment.

The alleged misconduct attacked the process at two points:

  1. Physical evidence. Potentially contaminated samples were allegedly discarded and replaced with clean soil before laboratory analysis.
  2. Digital evidence. Scan results were allegedly altered in the database to misrepresent where, when, and by whom work occurred.

DOJ alleged that Tetra Tech benefited by receiving contract award fees it had not earned and avoiding additional remediation obligations, reducing costs and increasing profit.

The settlement followed a consolidated whistleblower matter brought by former employees and contractors under the False Claims Act’s qui tam provisions: United States ex rel. Jahr, et al. v. Tetra Tech EC, Inc., Case No. 13-3835 in the Northern District of California. DOJ says the relators’ share is approximately $11.97 million.

The same announcement notes a separate $40 million settlement under the Comprehensive Environmental Response, Compensation, and Liability Act, or CERCLA, entered by the federal court on July 2, 2025. Keep the two figures separate: the $57 million announced in 2026 resolved False Claims Act allegations; the $40 million was a separate environmental settlement.

ResolutionAmountStated basisStatus
2026 False Claims Act settlement$57 millionAlleged fabricated work and falsified data tied to Navy contractsPaid; allegations resolved without a determination of liability
2025 CERCLA settlement$40 millionSeparate Superfund resolution referenced by DOJEntered by the federal court July 2, 2025
Relators’ share from FCA settlementAbout $11.97 millionQui tam share for former employees and contractorsReported by DOJ as part of the FCA resolution

The dollar amount gets attention. The evidence architecture is what practitioners should study.

Why this is an evidence-integrity case

In many controls, evidence is a byproduct. A manager approves a payment; the workflow retains the approval. A system blocks an unauthorized user; the log records the event.

At Hunters Point, the test data was central to the service itself. Collection locations, sample identity, instrument readings, custody records, laboratory results, and database entries collectively supported decisions about remediation, payment, property transfer, and public safety.

That creates a different risk model:

Evidence layerFailure modeDownstream consequence
CollectionWrong location, substituted item, incomplete sample, undocumented retestTest result does not represent the target condition
CustodyUnrecorded handoff, broken seal, relabeled sampleIdentity and integrity cannot be proven
Instrument/raw dataDeleted file, overwritten reading, changed timestampReviewer sees only a curated result
TransformationManual edit, undocumented exclusion, altered coordinatesFinal data departs from source evidence
ApprovalSame person prepares, changes, and accepts resultsManipulation can pass without challenge
ReportingSummary omits exceptions or uncertaintyDecision-maker receives false confidence
BillingInvoice relies on completion status not reconciled to verified workPayment can occur for unsupported deliverables

A policy requiring “accurate records” will not control that chain. Each transition needs identity, authorization, traceability, and independent challenge.

The False Claims Act, summarized by the Justice Department’s Civil Division, creates exposure when false or fraudulent claims are knowingly submitted or caused to be submitted to the government. In an evidence-based contract, records supporting performance can be material to payment even if the invoice itself contains no obvious arithmetic error.

The controls that should surround high-stakes evidence

1. Bind the physical or source event to a unique identity

Assign a unique, tamper-evident identifier at the point of collection or performance—not later in an office workflow.

For a physical sample, the minimum record should include:

  • unique sample ID;
  • collector identity;
  • date and time;
  • geolocation or designated collection point;
  • collection method;
  • container or seal identifier;
  • required photo or instrument evidence;
  • custody transfer history; and
  • reason and authorization for any rejection, destruction, or recollection.

For a financial-services analogue, substitute “transaction, complaint, call, model decision, access review, or remediation test” for “sample.” The principle holds. Evidence created after the event, without a source-system link, is weaker than evidence bound to the event when it occurred.

2. Preserve raw data and make changes visible

The final spreadsheet should never be the system of record for high-consequence testing.

Use controls that preserve:

  • original instrument or source-system output;
  • cryptographic hash or write-once retention where appropriate;
  • user-level access logs;
  • before-and-after values for every change;
  • reason code and ticket for corrections;
  • reviewer approval for material edits; and
  • linkage from reported result back to the raw record.

If operational needs permit data correction, do not overwrite history. Append a corrected record, retain the original, identify the person making the change, and document why the correction was necessary.

3. Reconcile work, evidence, decisions, and invoices

A completion certificate should not trigger payment by itself.

Build a four-way reconciliation:

  1. Work scheduled: What location, population, control, or deliverable was required?
  2. Work performed: What source evidence proves it occurred?
  3. Result accepted: Who reviewed exceptions and concluded requirements were met?
  4. Amount billed: What invoice line and award fee depends on that accepted work?

Unmatched items should stop payment or require a documented exception approved outside the delivery team.

This is where ownership gets messy. Operations may say invoice validation belongs to Finance. Finance may say technical completion belongs to the project manager. Compliance may not see the invoice at all. The control needs a named integrator—often the accountable program owner—who certifies that technical acceptance and payment evidence reconcile.

4. Independently retest what management most wants to pass

Risk-based sampling should focus on incentives and anomalies, not only random coverage.

A starting sample design could prioritize:

  • locations or records near a release threshold;
  • results that changed from fail to pass after rework;
  • high-value milestones or award-fee periods;
  • repeated collections by the same crew;
  • unusual time or location patterns;
  • destroyed, rejected, or recollected samples;
  • manual database changes; and
  • work completed unusually quickly.

These are illustrative risk factors, not mandated thresholds. Calibrate them using the process, contract, historical exceptions, and consequences of a false conclusion.

The independent tester should control sample selection and obtain evidence from source systems. Letting the delivery team choose “representative” examples creates a showroom, not a test.

5. Treat anomalies as possible integrity events

A duplicated timestamp may be a harmless system artifact. A location mismatch may be a data-entry error. A cluster of both may indicate something worse.

Create integrity-specific escalation triggers such as:

  • source record missing for a reported result;
  • duplicate or impossible time-location combinations;
  • sample destruction without approved reason;
  • unusually high manual-edit rate;
  • repeated use of shared credentials;
  • laboratory receipt inconsistent with field custody;
  • retest results materially different from originals; or
  • whistleblower allegation involving substitution, falsification, or pressure to pass.

Do not route these only through routine data-quality cleanup. Preserve records, restrict alteration, involve Legal and Compliance, assess payment and reporting impact, and determine whether an independent investigation is needed.

Whistleblowers are part of the control environment

The Tetra Tech matter was brought by former employees and contractors. That fact should change how a program evaluates speak-up controls.

A hotline metric showing “zero substantiated complaints” can mean the process is clean. It can also mean contractors do not know the channel, fear retaliation, or believe reports disappear into management.

For evidence-intensive work, test whether:

  • employees and contractors receive the reporting channel at onboarding;
  • reports can bypass the project chain of command;
  • allegations involving evidence integrity trigger preservation steps immediately;
  • investigators are independent from the people whose results are challenged;
  • retaliation monitoring continues after case closure; and
  • issue closure requires proof that the root cause—not just one record—was addressed.

The statutory False Claims Act framework includes qui tam mechanisms that permit private parties to bring actions on behalf of the United States. A credible internal escalation path gives the organization a chance to identify and address misconduct before the problem expands across years of work, payments, and decisions.

Five things to check Monday morning

1. Pick one decision that depends on submitted evidence

Choose a high-consequence process: customer remediation, model validation, fair-lending testing, sanctions alert closure, vendor SLA certification, cybersecurity patch evidence, business-continuity testing, or government-contract performance.

Write down the decision and every evidence object supporting it.

2. Trace one record backward without help from its preparer

Can a second-line reviewer move from the final report to the source event, raw data, custody or workflow history, changes, exception decisions, approval, and related payment?

If the preparer has to explain where everything is, the evidence chain is person-dependent.

3. Find overwrite capability

Identify who can edit source values, timestamps, locations, status, ownership, and completion fields. Review whether edits preserve prior values and generate alerts.

A quarterly access review does not answer this. You need to know what privileged users can change and whether anyone reviews actual changes.

4. Reconcile exceptions to outcomes

Select rejected records, retests, overrides, reopened issues, and manual corrections. Determine whether they are overrepresented in passing results or payment milestones.

This is an anti-gaming test. A dashboard can show a high pass rate because failed items were deleted, relabeled, or repeatedly retested until they passed.

5. Open issues at the right level

Do not create one vague issue called “improve data quality.” Separate the failure modes:

IssueOwnerClosure evidence
Source records can be overwrittenData platform ownerImmutable history enabled and independently tested
Chain-of-custody handoffs are incompleteOperations leadRequired scans enforced; sampled transfers reconcile
Manual edits lack reviewQuality AssuranceHigh-risk edits routed to independent approval; exception sample tested
Acceptance is disconnected from paymentProgram owner and FinanceFour-way reconciliation operating for sampled invoices
Contractors cannot bypass managementComplianceDirect channel deployed, awareness tested, retaliation monitoring documented

That structure matters because closure testing differs for each root cause.

A 30/60/90-day evidence-integrity plan

Days 1–30: map and contain

Owner: Chief Risk Officer or Operational Risk lead, with the accountable business owner.

  • Inventory decisions that rely on high-stakes internally or externally produced evidence.
  • Select the top process based on customer, safety, regulatory, or financial consequence.
  • Map source, custody, transformation, approval, reporting, and payment lineage.
  • Freeze destructive retention practices for relevant records while gaps are assessed.
  • Open discrete issues for missing lineage, overwrite access, weak segregation, and unreconciled payment.

Evidence: lineage map, access inventory, retention decision, issue records, and risk acceptance for any interim operation.

Days 31–60: rebuild the control chain

Owner: Operations, Data Governance, Quality Assurance, and Finance.

  • Implement unique identifiers and required metadata at source.
  • Preserve original records and before-and-after change history.
  • Establish risk-based independent retesting.
  • Connect technical acceptance to invoice approval.
  • Define integrity-event triggers and preservation procedures.
  • Add contractor reporting channels and investigation independence.

Evidence: configured workflows, access logs, reconciliation output, retest results, investigation playbook, and training completion.

Days 61–90: prove it works

Owner: Internal Audit or independent second-line testing.

  • Select samples without relying on the process owner.
  • Reconstruct final decisions from raw evidence.
  • Attempt unauthorized and authorized changes in a controlled test environment.
  • Verify alerts and approvals for high-risk edits.
  • Reconcile rejected, retested, and overridden records to final outcomes.
  • Validate issue closure using operating evidence, not implementation screenshots.

Evidence: test script, sample population, exceptions, remediation tickets, closure validation, and risk-committee reporting.

The EPA-hosted 2020 Tetra Tech litigation filing is also a reminder that contested technical work can generate years of litigation and competing interpretations. Preserve the source record, decision logic, and change history as if an independent reviewer will need to reconstruct them long after the project team has moved on—because they may.

The lesson from the Tetra Tech settlement

The most dangerous evidence failure is not a missing attachment. It is a complete-looking record that no longer represents what happened.

Take one high-stakes control result this week. Trace it from report to raw event, inspect every place it can be changed, reconcile it to the decision and payment it supported, and ask an independent reviewer to reproduce the conclusion.

If that chain breaks, open the issue now. The Issues Management Tracker & Template can assign the root cause, remediation owner, due date, evidence requirement, and closure test before a data-integrity gap becomes an enforcement narrative.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

How much did Tetra Tech pay in the Hunters Point False Claims Act settlement?
Tetra Tech EC Inc. paid $57 million to resolve False Claims Act allegations announced by DOJ on August 24, 2026. DOJ also noted a separate $40 million CERCLA settlement entered in July 2025. The 2026 resolution concerns alleged fabricated work and falsified radiological testing data.
What did DOJ allege Tetra Tech did at Hunters Point?
DOJ alleged that field technicians were instructed to discard soil samples from potentially contaminated locations, replace them with known clean soil, and submit the replacement samples for laboratory analysis. The government also alleged manipulation of database scan results so scans from different locations appeared to have been performed by the same technician at the same time.
Did Tetra Tech admit False Claims Act liability?
No. DOJ states that the claims resolved by the settlement are allegations only and that there has been no determination of liability.
What control would best detect substituted samples or manipulated test data?
Use end-to-end evidence lineage: tamper-evident sample IDs, location and time metadata captured at collection, custody handoffs, independent laboratory receipt, immutable raw records, exception logs, and reconciliation between field activity, laboratory results, invoices, and remediation decisions. Add independent resampling for high-risk locations.
Who should own evidence integrity in a regulated program?
The first-line process owner owns capture and custody, Quality Assurance sets testing and exception rules, Data Governance controls lineage and change access, Compliance assesses legal and contractual obligations, and Internal Audit or an independent verifier tests whether the evidence can be reconstructed without relying on the preparer.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.