Single audit requirements under the Uniform Guidance (2 CFR 200)

Adam Tahir
September 9, 2026

A nonprofit client you have audited for years calls in October. A new pass-through grant pushed their federal awards expended above the threshold this year, and they want to know whether a single audit now applies. You have run this scenario across engagements: federal award activity grows, and the scoping question lands on your desk under a filing deadline.

Get the scope wrong and the consequences follow the whole engagement. Misclassify a major program or miss a compliance requirement buried in the Compliance Supplement, and the file may not survive peer review. An independence call can sink it too.

This guide walks the core mechanics: the expenditure threshold, the SEFA, major program determination, the Compliance Supplement, subrecipient classification, reporting, and FAC submission. It focuses on scoping and the core mechanics, not a complete AU-C 935 or GAGAS execution methodology, and it closes with the cross-authority problem that consumes the most partner time: reconciling GASB, the Uniform Guidance, and GAGAS on a single engagement.

Key takeaways

  • A single audit is required when a non-federal entity expends $1,000,000 or more in federal awards in its fiscal year (2 CFR 200.501)
  • The $1,000,000 threshold applies to fiscal years beginning on or after October 1, 2024, up from the prior $750,000
  • It applies to non-federal entities such as states, local governments, tribes, nonprofits, and higher education institutions; procurement contracts for the federal government's own goods or services are governed by the FAR rather than the single audit rules
  • The auditee prepares the Schedule of Expenditures of Federal Awards (SEFA); the auditor uses it to determine major programs
  • Major programs are selected with a risk-based approach and the Type A/B thresholds in 2 CFR 200.518
  • The reporting package and data collection form are due to the Federal Audit Clearinghouse within 30 days after the auditee receives the auditor's report or nine months after year end, whichever is earlier (2 CFR 200.512)

When is a single audit required? The federal expenditure threshold

A single audit is required when a non-federal entity expends $1,000,000 or more in federal awards during its fiscal year. Section 200.501(a) sets the trigger at "$1,000,000 or more" and calls for a single or program-specific audit for that year.

This figure is current for fiscal years beginning on or after October 1, 2024. That means January 1, 2025 for calendar-year entities and July 1, 2025 for entities on a July-to-June year. For fiscal years that began before October 1, 2024, the prior $750,000 threshold still governs.

The rule reaches specific non-federal entities: states, local governments, Indian tribes, nonprofits, and higher education institutions. It does not apply solely because an entity holds a federal procurement contract for the government's own goods or services, which is governed by the FAR rather than the single audit rules.

The count turns on spending, not cash receipts. Federal awards expended are measured based on when the activity occurs, not on when funds are received (2 CFR 200.502(a)). That basis captures pass-through funds to subrecipients and non-cash assistance, while Medicare and most Medicaid payments are excluded under 200.502(h) and (i).

OMB revises this threshold periodically, so confirm the current figure against the eCFR before you scope.

What 2 CFR 200 actually covers, and what it does not

The Uniform Guidance is OMB's single rulebook for federal financial assistance. It runs from definitions through audit requirements, and each mechanic in this article lives in a specific subpart.

The subpart structure of the Uniform Guidance

Part 200 is organized into six subparts. Knowing where each rule sits saves search time when a question crosses topics.

  • Subpart A defines terms used throughout Part 200
  • Subpart B sets general provisions and applicability
  • Subpart C covers pre-award requirements for federal agencies
  • Subpart D holds post-award requirements, including subrecipient rules
  • Subpart E sets the cost principles for allowability
  • Subpart F contains the audit requirements, where the single audit lives

Subrecipient classification and monitoring sit in Subpart D, while major program determination and reporting sit in Subpart F. A scoping question often pulls from both.

What falls outside the Uniform Guidance

Not every dollar an entity receives counts toward the threshold. State-only appropriations, purely private foundation grants, and routine financial statement audits that are not single audits all sit outside Part 200.

The grant-versus-contract line trips up first-timers. Federal financial assistance flows through the Uniform Guidance. A procurement contract for the government's own goods and services is governed by the FAR, not Part 200.

Preparing the Schedule of Expenditures of Federal Awards (SEFA)

As the auditee's responsibility, the SEFA is the backbone of every scoping decision. Get it wrong and the major program determination that follows inherits the error.

What must appear on the SEFA

The auditee must prepare the SEFA for the same period as the financial statements, showing total federal awards expended under 200.502 (2 CFR 200.510(b)).

  • List programs by federal agency using the applicable Assistance Listing Number (ALN)
  • Identify the pass-through entity name and number for awards received as a subrecipient
  • Show total federal awards expended for each individual program
  • Show the total amount passed through to subrecipients from each program
  • Identify outstanding loan and loan guarantee balances in the notes
  • Include notes on significant accounting policies, including any de minimis indirect cost rate election

Common SEFA errors that create downstream problems

Small SEFA mistakes cascade into wrong scoping. Each error below maps to a specific failure later in the engagement.

Misclassified loans: understating loan or loan guarantee activity shrinks total federal awards expended and can drop the Type A threshold too low.

Missing subrecipient breakouts: without pass-through amounts, subrecipient monitoring and coverage tests cannot be assessed correctly.

Timing mismatches: a SEFA that does not tie to the general ledger produces an expended total that misstates major program determination.

Major program determination: Type A and Type B programs

Major programs drive the audit's compliance testing, and the risk-based approach in 200.518 controls how you get there. The Type A threshold sets to $1,000,000 when total federal awards expended are at least $1,000,000 but no more than $34 million.

Lock the Type A threshold before you begin selecting programs. Everything downstream depends on it.

Calculating the Type A threshold

The threshold slides with total federal awards expended (FAE). Section 200.518(b)(1) sets it as follows.

Nonaudit service GAGAS treatment
A permissible service with threats assessed, SKE confirmed, and the understanding documented Permitted when safeguards reduce threats to an acceptable level (paras. 3.64, 3.73, 3.77).
Preparing financial statements in their entirety from a client trial balance Significant threats (para. 3.88): document safeguards applied, or decline.
Assuming a management responsibility or decision Impairment (para. 3.78): no safeguard can reduce it to an acceptable level.

Programs above the threshold are Type A; the rest are Type B.

Risk-based selection of Type B programs

The auditor assesses risk for Type B programs as required by the 200.518 process, but 200.518(d)(2) limits which Type B programs must be considered: only those that exceed 25 percent (0.25) of the Type A threshold. The auditor is not expected to assess relatively small programs.

Weigh the usual risk factors when you assess a Type B program:

  • Prior audit findings or a history of noncompliance
  • New programs or awards in their first year of operation
  • Recent management or system turnover
  • Complexity of the program's compliance requirements

Coverage then depends on the auditee's risk profile. Under 200.518(f), major programs must cover at least 20 percent of total federal awards expended for a low-risk auditee, and 40 percent for others.

Low-risk status itself depends on the conditions in 2 CFR 200.520, met for each of the preceding two audit periods.

Using the OMB Compliance Supplement to identify requirements

The Compliance Supplement identifies the compliance requirement types that are subject to audit for each program and provides audit objectives and suggested procedures. The auditor still determines which applicable requirements are direct and material to the major program, using Part 3 and the applicable program or cluster supplement.

Finding the right program in Part 2

Start with the program's Assistance Listing Number. Use the Part 2 matrix to match the ALN to its Compliance Supplement chapter, which points you to the requirements that apply to that program.

The twelve types of compliance requirements

Part 3 of the Compliance Supplement identifies 12 types of compliance requirements where noncompliance may have a direct and material effect on a program.

  • Activities allowed or unallowed
  • Allowable costs and cost principles
  • Cash management
  • Eligibility
  • Equipment and real property management
  • Matching, level of effort, and earmarking
  • Period of performance
  • Procurement and suspension and debarment
  • Program income
  • Reporting
  • Subrecipient monitoring
  • Special tests and provisions

The 12 types are the full taxonomy, but the auditor does not automatically test all 12 for a program. Since 2019, OMB has capped the number of requirement types subject to audit at six per program, with the activities-allowed and allowable-costs requirements counted as a single type for this purpose.

The 2025 Compliance Supplement continues that cap, with one exception: the Research and Development cluster, where OMB permits seven. The Part 2 matrix marks which types apply to a given program with a Y or an N, so your test plan comes from that program's specific matrix entry, not the full list of 12.

Tooling for compliance testing: what exists, and where research fits

Two categories of software sit on an auditor's desk during a single audit, and they answer different questions. One documents that testing happened; the other interprets what the guidance requires.

Testing and workflow software

Compliance audit software and federal grant management software handle the mechanics of execution. They automate sampling, standardize workpapers, track documentation, and route reviews.

That work matters, and these tools do it well. What they do not do is tell you what a specific compliance requirement means or how two authorities relate when they overlap.

Where research tools fit differently

A research tool answers the interpretive question: what does this requirement say, and where is the authority. It finds the guidance, cites it to the section, and shows how sources connect, rather than documenting that a test was performed.

Bizora Audit Research illustrates the difference, covering the Uniform Guidance, the Compliance Supplement, and the authorities behind each answer, including GASB, PCAOB, AICPA, and GAO Yellow/Green/Red Book guidance alongside 2 CFR 200. It's included with Pinnacle plans on the web app, or billed at $0.65 per query through the API and MCP server, with automatic routing that needs no code changes on an existing integration.

Subrecipient vs. contractor: classification and the monitoring obligation

Classification is not a paperwork label. It decides whether monitoring duties and single audit rules flow down to the entity receiving the funds.

The pass-through entity makes this call case by case, and the wrong call leaves either a monitoring gap or an unnecessary compliance burden.

The substance-over-form test under 200.331

Under 2 CFR 200.331, the pass-through entity uses judgment to classify each agreement. The rule is that "the substance of the relationship is more important than the form of the agreement," so no single factor controls. The section lists characteristics for each side.

Subrecipient Contractor
Determines who is eligible for federal assistance Provides the goods and services within normal business operations
Has performance measured against program objectives Provides similar goods or services to many purchasers
Has responsibility for programmatic decisions Operates in a competitive environment
Must follow federal program requirements in the award Provides goods or services ancillary to the program
Runs a program for a public purpose set in statute Is not subject to program compliance requirements from the agreement

What subrecipient monitoring actually requires

Once you confirm a subrecipient relationship, 200.332 sets the monitoring obligation. The pass-through entity carries three duties across the award life cycle.

  • Evaluate each subrecipient's risk of noncompliance for purposes of determining appropriate monitoring
  • Monitor subrecipient activities during the period so the subaward's goals are met
  • Follow up on the subrecipient's own audit findings and verify the subrecipient is audited under Subpart F

Reporting: findings, questioned costs, and the data collection form

Single audit findings generally follow the classic criteria, condition, cause, effect, and recommendation structure, but 2 CFR 200.516(b) requires additional detail as applicable: federal program and award identification, questioned costs and how they were computed, perspective on the finding's prevalence and consequences, whether it repeats a finding from the immediately prior audit, and the auditee's views where they differ from the auditor's.

Questioned costs get their own threshold. Auditors report questioned costs over $25,000 when known or likely amounts exceed that figure for a compliance requirement type on a major program (2 CFR 200.516(a)(3)). The same $25,000 line applies to a non-major program under 200.516(a)(4) when the auditor becomes aware of the costs.

The results feed the data collection form required by Appendix X to Part 200, commonly called the SF-SAC. The regulation itself refers to it as the data collection form, so use that term in workpapers and note the informal name.

How to submit to the Federal Audit Clearinghouse

Submission runs on a firm clock. Section 200.512 sets the deadline for the audit, the data collection form, and the reporting package. Submit within 30 calendar days after the auditee receives the auditor's report, or nine months after the audit period ends, whichever is earlier (200.512(a)(1)).

Work the submission in order:

  1. Confirm the earlier of the two due dates and calendar it against the auditor's report date
  2. Assemble the reporting package: financial statements, the SEFA, the auditor's reports, the schedule of findings and questioned costs, and any corrective action plan
  3. Complete the data collection form (Appendix X) with the auditee's program and audit result data
  4. Submit both electronically to the FAC, which is the repository of record for Subpart F packages

The FAC now operates under the General Services Administration at fac.gov, so verify the current portal before you file.

Reconciling GASB, Uniform Guidance, and GAGAS in one engagement

Consider a state university that receives federal research funding. For the auditor, the engagement stack is not just the Uniform Guidance: a single audit generally layers GAGAS, Subpart F of 2 CFR Part 200, the applicable year's OMB Compliance Supplement, and AU-C 935, Compliance Audits, while the financial statements follow the entity's own reporting framework, GASB for a state university. Those authorities serve different purposes and do not substitute for one another, and Subpart F explicitly references GAGAS in several places, so the two are already meant to interact.

Take one question: whether a nonaudit service the firm provided creates a self-review threat that affects the research program's major program testing. Tracing it across GASB's reporting treatment, the Uniform Guidance compliance requirements, and the Yellow Book's stricter independence standard, and showing where they diverge, is exactly the kind of cross-authority work that consumes the most time in engagements like this.

The major program determination and the independence conclusion remain the auditor's own call, whatever tool or reference is used to research the underlying authorities.

Sources

Frequently Asked Questions

What is the dollar threshold for a single audit under 2 CFR 200?

A single audit is required when a non-federal entity expends $1,000,000 or more in federal awards during its fiscal year, per 200.501(a). This figure applies to fiscal years beginning on or after October 1, 2024, up from the prior $750,000.

Who is required to have a single audit?

States, local governments, Indian tribes, nonprofits, and higher education institutions that expend $1,000,000 or more in federal awards must have one. For-profit entities are not subject to Subpart F solely because they hold federal procurement contracts governed by the FAR; if a for-profit entity receives federal financial assistance instead, the award terms and pass-through requirements require separate analysis.

What is the difference between a Type A and Type B program?

Type A programs are those with federal awards expended above the Type A threshold set in 200.518, while Type B programs fall below it. The distinction drives which programs get risk assessment and how much of total spending the audit must cover.

Does 2 CFR 200 apply to for-profit federal contractors?

No, procurement contracts for the government's own goods and services are governed by the FAR rather than the Uniform Guidance. For-profit federal contractors are not covered by the single audit requirement solely because they hold procurement contracts; federal financial assistance arrangements require separate analysis, and a for-profit entity acting as a subrecipient can still owe compliance duties that the pass-through entity must monitor.

What happens if a subrecipient does not submit its own single audit?

The pass-through entity must follow up under 200.332, verify the subrecipient is audited under Subpart F, and act on any findings. Persistent failure can lead to enforcement actions such as withholding funds or disallowing costs.

How long must single audit records be retained?

Recipients and subrecipients must retain records for three years from the date they submit their final financial report, per 2 CFR 200.334. The clock pauses if litigation, a claim, or an audit begins before the three years run out

Your Next Answer Is One Search Away

Bizora AI turns hours of manual research into seconds, with every answer backed by primary source citations. Start your 7-day free trial. No credit card required.

Start Free Trial