It is an absolute cf because the current system is a bowl of manually verified spreadsheet spaghetti that exists mostly in two guys' heads. We are currently discovering that no one knows how many servers don't actually have recovery backups ready because the buck has been passed so often and so many people have come and gone.
So I totally believe some employee as the single point of buck-passing would absolutely rubber stamp metallurgical tests just to avoid jamming up the system.
I can also say that there are a range of engineering specs, and some are absolutely critical and some are just specified out of habit. It IS our job to communicate with the customer (whether DOD or prime contractor) and determine which is which, and charge appropriately.
I.e., if there is some spec that will cost a lot to build into the component and there is a more efficient or cost-effective way to get sufficiently similar results, then we should (and do) propose that change, and if they say "OK", get it in writing, and if they say "nope, we really need that feature as spec'd", then charge properly for it and make damn sure it is done and documented. Plus, get all the exchanges in writing, it doesn't always have to be formal proposals & change orders, often just email is fine.
I'd say that the vast majority of the time when something creates a production problem, or some subcomponent, coating, etc. is unavailable (like one time a handful of component X was now out of production and the new minimum order quantity was like 20K parts, so a line item that should have been maybe $50 would now be $25K+), a quick discussion will usually resolve issue, such as "yes, it's ok to increase the radius there", "yes that other component/coating is an acceptable substitute" or "what do you recommend as a substitute?". But there are those times where the answer is "we really need it with those crazy tolerances to mate to this other component".
So, yes, unless you have some direct evidence of the CYA behavior you describe, I'd strongly recommend against treating it as you suggest.
On that indefinite user list, but without knowing for sure the purpose of the checks, I'd strongly avoid putting my name on that document. Are we just checking that the approximate totals seem to match the org size, or are we after specific checks for hostile fake or obsolete accounts? I sure don't want my sig on the document stating that I made checks X, Y, & Z for fake/obsolete accts when I hadn't, and we get hacked next week.
I.e., if it is 'just bureaucracy' and they don't actually care about the result, then likely someone is trying to get your neck in the noose when the sht hits the proverbial fan.
That's why they want to get your sig on documents, get "Certificates of Compliance", etc.
And yes, that part is largely BS, until the sht hits the fan. What counts here is indeed ensuring that the subset of specs that the one-level-up contractor really cares about are truly met, and sorting out (in writing) what you can relax about because it was just cut/paste or generic/SOP specs on that particular feature.