All articles
Product
Solutions

QASP surveillance software: turn surveillance into records you can compile

A-Frame Solutions Built by former federal Contracting Officers

The short answer: the FAR tells you what a quality assurance surveillance plan has to specify, and it is short. FAR 46.401(a) says the plan should specify all work requiring surveillance, and the method of surveillance. What the FAR does not tell you is how to keep six or twelve months of executed surveillance records comparable to each other. That is where most shops lose the thread, because the plan and the records end up in the same editable document. Lock the criteria in a controlled master, capture results as data, version-lock each period, and the rollup becomes something you generate instead of rebuild.

What the FAR actually requires

FAR 37.604, Quality assurance surveillance plans, is one paragraph. It points at subpart 46.4 for the requirements and adds that the Government may either prepare the QASP itself or require offerors to submit a proposed plan for the Government's consideration in developing its own.

The substance sits in FAR 46.401(a). Quality assurance surveillance plans should be prepared in conjunction with the statement of work, and the plans should specify:

46.401(b) adds that each contract shall designate the place or places where the Government reserves the right to perform quality assurance.

One caveat on citations, because it matters this year. FAR Part 37 is among the parts in the June 23, 2026 proposed rules under the Revolutionary FAR Overhaul, so its numbering and text may move. Part 46 is not in that batch. Confirm the current text on acquisition.gov before relying on a specific paragraph, and see our summary of the June 23 proposed rules for what changed.

Why a QASP in a word processor stops working

The requirement is modest. Executing it every month for every vendor, for a year, is where it breaks. Four costs, and they compound.

None of this is a discipline problem. It is structural. The document that carries the standard and the document that captures the result are the same file.

What a contractor performance surveillance tool should do

Four things, and the order matters.

  1. Hold the standard in locked cells. The performance objective, the acceptable quality level, the surveillance method, and the deduction schedule live in the document as spreadsheet cells that the person executing it cannot edit. That single property is what makes a set of records comparable at all.
  2. Capture observations as data. Fillable result cells, not a narrative box. What was received, when, whether it met the criterion, what deduction applies.
  3. Version-lock each executed record. At finalization the content is frozen and stamped, so the version reviewed is the version preserved and any later change is a new version with its own history.
  4. Generate the aggregate. Because the results were captured as data in known cells, the period rollup is a view of the records rather than a separate document that can disagree with them.

Surveillance records are also the documentation behind a CPARS narrative. A rating that traces to dated, version-locked observations is a rating you can defend when the contractor disagrees with it.

Federal contract acceptance surveillance, worked end to end

This is ArcCompose, the controlled-document module of ArcSuite AI. The walkthrough below is about a minute, narrated, with captions. A services contract with defined acceptance criteria and a deduction schedule, one record per delivery, compiled into an acceptance rollup.

In the acceptance walkthrough, four records compile into one rollup: three of the four delivered on time, $18,500 in deductions across the period, and one item flagged for rework. Every figure traces back to the record and the locked criterion that produced it.

The second walkthrough is the same mechanism running an equipment qualification protocol in a regulated manufacturing environment. Different vocabulary, identical structure. It is there because it shows the pattern is not a quirk of federal contracting: a controlled document, a standard that must not move, a record per execution, and an aggregate somebody eventually has to defend.

What this does not do

It does not make the acceptance decision. It does not decide whether a deliverable met the standard, whether a deduction is warranted, or what a performance rating should be. Those are the COR's and the contracting officer's calls, and they should be.

What it removes is the clerical work around those calls: the re-keying, the criteria drift, and the day spent rebuilding a rollup that could have been generated. The platform speeds up the repeatable scaffolding, never the judgment.

It also does not retroactively fix records created the old way. Migrating a historical set means re-executing against the master, which is worth doing for an active contract and usually is not worth doing for a closed one.

Common questions

What is a quality assurance surveillance plan?

A QASP is the document that says how the Government will verify a contractor met the requirements of a performance-based service contract. FAR 37.604 points to subpart 46.4 for the requirements, and FAR 46.401(a) says the plan should be prepared alongside the statement of work and should specify all work requiring surveillance and the method of surveillance. FAR 46.401(b) adds that each contract shall designate where the Government reserves the right to perform quality assurance.

What should QASP surveillance software do?

Four things. Hold the performance objectives, acceptable quality levels, surveillance methods, and deduction schedule in cells the executor cannot edit. Capture observations as data rather than prose. Version-lock each executed record at finalization so the content reviewed is the content preserved. And generate the period rollup from those records instead of rebuilding it by hand.

Why does a QASP in Word or a spreadsheet stop working at scale?

Because the document carrying the standard and the document capturing the result are the same file. Every execution is a copy, every copy is editable including the acceptance criteria, and the results are text rather than data. So the criteria drift, the aggregate has to be rebuilt by hand, and a year later the file shows current content rather than what it said the day it was signed.

How does a contractor performance surveillance tool help with CPARS?

Surveillance records are the documentation behind a CPARS narrative. When each observation is dated, tied to a locked criterion, and preserved in a version-locked record, the rating traces to evidence rather than to recollection. That is what makes it defensible when the contractor disagrees.

Does this only apply to federal contracts?

No. The pattern is a controlled document, a standard that must not move, a record per execution, and an aggregate someone has to defend. That describes federal acceptance surveillance and equipment IQ/OQ qualification in regulated manufacturing equally well, along with inspections, audits, and calibration.

Bring your QASP and we will run one period end to end.

Build it as a controlled master with your criteria locked, execute one surveillance record against it, and compile the rollup. With a former contracting officer, not a sales engineer.

Book a walkthrough → See all demos