Capability

COR File Checklist: What Belongs in It and Why

The three items FAR 1.604 requires, what your agency will expect on top of them, and the standard your file gets measured against when someone finally pulls it.

By Joary Khairudin-Casey, Founder · Principal Consultant · September 7, 2026 · Deep Read · 9 min

Every COR I teach asks some version of the same question, usually in the first hour: what actually has to be in my file? It's a fair question. The honest answer is that nobody hands you a definitive list. Search for one and you'll find a dozen agency PDFs, each with a different set of boxes, none of them explaining why a box is there or what to do when the item doesn't exist.

Here's what happens when that gap goes unaddressed. In an audit published 09-25-2025, the Inspector General at the U.S. International Trade Commission (USITC) reviewed the Contracting Officer's Representative (COR) files for twelve contracts against the agency's own COR Handbook. That handbook tells the COR to put a completed file checklist as the first page of the file. The Inspector General found it in none of the twelve. Four of those files were missing the contracting officer's letter of designation. The report described the consequence in language auditors rarely use: without a letter of designation, COR actions such as approving invoices or monitoring performance are “unauthorized and may be invalid.”

Those were ordinary files kept by busy people. So this week I want to walk you through the list I keep on my own desk, with the authority behind each item and the reason it earns its place.

The Standard

Before the list, the standard. The list makes more sense once you know what it's serving.

Federal Acquisition Regulation (FAR) 4.801(b) requires that documentation be sufficient to constitute a complete history of the transaction. It names four reasons why: to provide a background for informed decisions at each step, to support actions taken, to provide information for reviews and investigations, and to furnish essential facts in the event of litigation or a congressional inquiry.

That duty belongs to the head of the contracting, contract administration, or paying office. It governs the contract file your work feeds into, one step removed from your own COR file. It's still the standard your documentation gets measured against, because your material is what makes that history complete or leaves the hole in it. What I tell my students is this: your file works if a stranger can reconstruct what happened and why, years from now, without you in the room.

That standard matters more than usual right now. FAR 4.803, the section most of us were trained on, introduces its contents with three softeners in a single sentence. It offers examples of records normally contained, if applicable. It was always illustrative. Under the Revolutionary FAR Overhaul, that list leaves the regulation and reappears as guidance in the FAR Companion, which is not binding. So the regulation is handing the list back to you.

The FAR Minimum

Here's something most CORs don't realize. Only one section of the FAR requires a COR file at all. It names three things.

FAR 1.604 says the COR shall maintain a file for each assigned contract. That file must include, at a minimum:

  • 1.604(a). A copy of the contracting officer's letter of designation, along with other documents describing the COR's duties and responsibilities.
  • 1.604(b). A copy of the contract administration functions delegated to a contract administration office that may not be delegated to the COR.
  • 1.604(c). Documentation of COR actions taken in accordance with the delegation of authority.

Everything else on any COR file checklist, mine below included, is agency policy or good practice, or it comes from a section other than 1.604. That distinction is worth knowing when someone tells you a document is required.

The middle one, 1.604(b), is the item people skip. I'd argue it's the most useful of the three. It's the written boundary of the work someone else is responsible for. It's worth keeping where you can reach it quickly. The moment you need it is the moment a contractor asks you for something you can't give them.

The Checklist

Assignment

  • The letter of designation, signed and current. It's the document that gives every later action its authority, which is why the USITC report describes its absence so bluntly.
  • The statement of your authority and its limits. These come from the designation itself. FAR 1.602-2(d)(7) requires the designation to specify the extent of your authority to act for the contracting officer and to identify the limitations on it.
  • Proof of your current Federal Acquisition Certification for Contracting Officer's Representatives (FAC-COR). FAR 1.602-2(d)(2) requires you to be certified and to maintain that certification. Two of the twelve USITC files had CORs who were uncertified or whose certification had expired, and one of those had finished the training and never uploaded the certificates.
  • The contract itself, complete, with all attachments.

Performance

  • Every modification, filed as it issues. One USITC file was missing the initial award and ten separate modifications. A COR monitoring against a superseded version is monitoring the wrong requirement.
  • Inspection and acceptance records for each deliverable. These are your evidence that the Government received what it paid for. They also establish physical completion, which starts the closeout clock later.
  • Surveillance records of the kind FAR 4.803(b)(14) describes, and quality assurance records under 4.803(b)(15).
  • Invoice reviews that record your recommendation and your reasoning. The approval by itself doesn't show how you got there.
  • Correspondence that directs, clarifies, or interprets the work. If it changed what the contractor does, it belongs in the file.
  • A decision memo for anything you decided. This is where my earlier post on defensible documentation and this checklist meet. The document is the what, the memo is the why, and the why is what survives a reviewer.

Past Performance

  • Your Contractor Performance Assessment Reporting System (CPARS) input and the completed evaluation. At USITC, on the eight contracts where an evaluation was required, none had one, and no CPARS report appeared in any applicable COR file. One COR told the auditors they'd been instructed to stop doing contractor evaluations after 2021 because CPARS was difficult to use. Past performance is the one thing in your file that outlives the contract. The next source selection team will rely on it.

Closeout

FAR 4.804-5(a) lists fifteen conditions that administrative closeout has to satisfy. Most belong to the contracting officer, the contract administration office, or the auditors. Three are usually yours:

  • The contractor's final invoice is submitted.
  • The contractor's closing statement is completed.
  • Your input to the funds review, so money nobody is going to spend gets deobligated.

Two things about the timing. First, the clock starts at evidence of physical completion. The end of the period of performance doesn't start it. Then the targets in FAR 4.804-1(a), all stated as “should”: files using simplified acquisition procedures close on evidence of receipt of property and final payment, firm-fixed-price files other than those within six months, thirty-six months where indirect cost rates have to be settled, and twenty months for everything else.

Advisory targets are still worth hitting. A Peace Corps Inspector General review published 09-2024 found ten contracts an average of 411 days past the FAR closeout window with closeout never started. The final invoices on those contracts had already been processed.

The one hard rule in that section is a prohibition. Under FAR 4.804-1(c), the file shall not be closed while the contract is in litigation or under appeal, or while termination actions are incomplete.

Retention

  • Six years after final payment, if yours is the office of record. FAR 4.805 Table 4-1 sets that period, and FAR 4.805(a) points directly at the National Archives and Records Administration (NARA) General Records Schedule (GRS) 1.1, which says the same thing in records-management language. The two agree, which surprises people who assume they conflict.
  • Ask which row applies to you. Both the FAR table and GRS 1.1 add a second row for other copies used for administrative purposes, and those get destroyed when business use ceases. A COR file is frequently the copy set. Your agency records officer can tell you which one you're holding. The answer changes how long you keep it.
  • Don't destroy early. Under FAR 4.805(c), a shorter period requires NARA approval through the agency records officer. Early destruction happens anyway. The Government Accountability Office's own Inspector General found closeout documentation destroyed for three of twenty-five closed contracts, inside that agency's own seven-year retention policy.

Email and Handoff

Two things the agency PDFs won't tell you. I've watched both cost people time they didn't have.

Your inbox probably isn't the file. NARA's regulation at 36 CFR 1236.22(d) bars an agency from keeping the recordkeeping copy of a record in a mail system unless that system has full electronic recordkeeping functionality. Where it doesn't, the agency has to instruct staff how to copy records out of mail into a system that does. Unless your agency has told you its mail platform is the recordkeeping system, you can assume it isn't. The safer habit is filing the email into the contract file with its attachments, because a message left in a mailbox is on the mailbox's schedule. If your agency uses the Capstone approach, that schedule is GRS 6.1: permanent for senior officials, seven years for most staff, and three years for support and administrative roles. And under 44 U.S.C. 2911, anything you send from a personal account has to copy your official account on the message itself or reach it in a complete copy within twenty days.

The file has to survive you. At Peace Corps, CORs said documents were unaccounted for because the COR had left the agency and nothing could be located. At USITC, two of the twelve files had gaps traced to a change in COR. That report's diagnosis was structural: COR files lived on individual computers with no central location the Office of Procurement could reach. Both Inspectors General recommended centralizing the files. Until your agency does, it helps to keep yours somewhere your contracting officer can reach without you. FAR 4.802(c) already requires that files be maintained where they're readily accessible to their principal users, and a folder only you can open doesn't meet that.

Citations and Deviations

This is the part I expect to trip people up for the next year or two, so let me be precise about where things stand today.

The FAR in force is Federal Acquisition Circular 2026-01, effective 03-13-2026. Under it, your citations are FAR 1.604 for the COR file and FAR 4.801 through 4.805 for contract files, closeout, and retention. Those are the numbers to use.

The Revolutionary FAR Overhaul hasn't replaced them. A proposed rule published 06-23-2026 would restructure Part 4 substantially. Sections 4.801, 4.802, and 4.803 collapse into a single 4.101, closeout and retention move again to 4.309 and 4.310, and COR policy moves to 1.404. That rule is still proposed. Its comment period closed in July and no final rule has published.

Meanwhile, roughly thirty agencies have already issued class deviations for Part 4. If yours is one of them, the sections I've cited throughout this post, 4.801(b) and 4.802(c) among them, aren't the numbers your agency is following, even though the substance survives the move. It's worth confirming before you put a citation in a memo, because a section number that doesn't exist for your agency is worse than no citation at all.

One detail to watch if your agency adopts the new text: proposed 1.404 keeps only two of the three mandatory COR file items. The one it drops is the record of contract administration functions delegated elsewhere. I'd keep that document either way, for the same reason you keep a receipt.

Every finding I cited above came from a file that was probably fine on the day it was created. The designation letter existed once. The modifications were issued. Somebody accepted the deliverables. What broke down was the practice of putting each thing in one place, at the time, where the next person could find it. That's what a checklist protects. It's why the USITC handbook asked for one as the first page.

If this is useful, pass it to a COR on your team who inherited a file and isn't sure what should already be in it. And if you'd like the checklist as a one page reference, send me a note through the contact form and I'll get it to you.