A nonprofit client you have audited for years calls in October. A new pass-through grant pushed their federal awards expended above the threshold this year, and they want to know whether a single audit now applies. You have run this scenario across engagements: federal award activity grows, and the scoping question lands on your desk under a filing deadline.
Get the scope wrong and the consequences follow the whole engagement. Misclassify a major program or miss a compliance requirement buried in the Compliance Supplement, and the file may not survive peer review. An independence call can sink it too.
This guide walks the core mechanics: the expenditure threshold, the SEFA, major program determination, the Compliance Supplement, subrecipient classification, reporting, and FAC submission. It focuses on scoping and the core mechanics, not a complete AU-C 935 or GAGAS execution methodology, and it closes with the cross-authority problem that consumes the most partner time: reconciling GASB, the Uniform Guidance, and GAGAS on a single engagement.
A single audit is required when a non-federal entity expends $1,000,000 or more in federal awards during its fiscal year. Section 200.501(a) sets the trigger at "$1,000,000 or more" and calls for a single or program-specific audit for that year.
This figure is current for fiscal years beginning on or after October 1, 2024. That means January 1, 2025 for calendar-year entities and July 1, 2025 for entities on a July-to-June year. For fiscal years that began before October 1, 2024, the prior $750,000 threshold still governs.
The rule reaches specific non-federal entities: states, local governments, Indian tribes, nonprofits, and higher education institutions. It does not apply solely because an entity holds a federal procurement contract for the government's own goods or services, which is governed by the FAR rather than the single audit rules.
The count turns on spending, not cash receipts. Federal awards expended are measured based on when the activity occurs, not on when funds are received (2 CFR 200.502(a)). That basis captures pass-through funds to subrecipients and non-cash assistance, while Medicare and most Medicaid payments are excluded under 200.502(h) and (i).
OMB revises this threshold periodically, so confirm the current figure against the eCFR before you scope.
The Uniform Guidance is OMB's single rulebook for federal financial assistance. It runs from definitions through audit requirements, and each mechanic in this article lives in a specific subpart.
Part 200 is organized into six subparts. Knowing where each rule sits saves search time when a question crosses topics.
Subrecipient classification and monitoring sit in Subpart D, while major program determination and reporting sit in Subpart F. A scoping question often pulls from both.
Not every dollar an entity receives counts toward the threshold. State-only appropriations, purely private foundation grants, and routine financial statement audits that are not single audits all sit outside Part 200.
The grant-versus-contract line trips up first-timers. Federal financial assistance flows through the Uniform Guidance. A procurement contract for the government's own goods and services is governed by the FAR, not Part 200.
As the auditee's responsibility, the SEFA is the backbone of every scoping decision. Get it wrong and the major program determination that follows inherits the error.
The auditee must prepare the SEFA for the same period as the financial statements, showing total federal awards expended under 200.502 (2 CFR 200.510(b)).
Small SEFA mistakes cascade into wrong scoping. Each error below maps to a specific failure later in the engagement.
Misclassified loans: understating loan or loan guarantee activity shrinks total federal awards expended and can drop the Type A threshold too low.
Missing subrecipient breakouts: without pass-through amounts, subrecipient monitoring and coverage tests cannot be assessed correctly.
Timing mismatches: a SEFA that does not tie to the general ledger produces an expended total that misstates major program determination.
Major programs drive the audit's compliance testing, and the risk-based approach in 200.518 controls how you get there. The Type A threshold sets to $1,000,000 when total federal awards expended are at least $1,000,000 but no more than $34 million.
Lock the Type A threshold before you begin selecting programs. Everything downstream depends on it.
The threshold slides with total federal awards expended (FAE). Section 200.518(b)(1) sets it as follows.
Programs above the threshold are Type A; the rest are Type B.
The auditor assesses risk for Type B programs as required by the 200.518 process, but 200.518(d)(2) limits which Type B programs must be considered: only those that exceed 25 percent (0.25) of the Type A threshold. The auditor is not expected to assess relatively small programs.
Weigh the usual risk factors when you assess a Type B program:
Coverage then depends on the auditee's risk profile. Under 200.518(f), major programs must cover at least 20 percent of total federal awards expended for a low-risk auditee, and 40 percent for others.
Low-risk status itself depends on the conditions in 2 CFR 200.520, met for each of the preceding two audit periods.
The Compliance Supplement identifies the compliance requirement types that are subject to audit for each program and provides audit objectives and suggested procedures. The auditor still determines which applicable requirements are direct and material to the major program, using Part 3 and the applicable program or cluster supplement.
Start with the program's Assistance Listing Number. Use the Part 2 matrix to match the ALN to its Compliance Supplement chapter, which points you to the requirements that apply to that program.
Part 3 of the Compliance Supplement identifies 12 types of compliance requirements where noncompliance may have a direct and material effect on a program.
The 12 types are the full taxonomy, but the auditor does not automatically test all 12 for a program. Since 2019, OMB has capped the number of requirement types subject to audit at six per program, with the activities-allowed and allowable-costs requirements counted as a single type for this purpose.
The 2025 Compliance Supplement continues that cap, with one exception: the Research and Development cluster, where OMB permits seven. The Part 2 matrix marks which types apply to a given program with a Y or an N, so your test plan comes from that program's specific matrix entry, not the full list of 12.
Two categories of software sit on an auditor's desk during a single audit, and they answer different questions. One documents that testing happened; the other interprets what the guidance requires.
Compliance audit software and federal grant management software handle the mechanics of execution. They automate sampling, standardize workpapers, track documentation, and route reviews.
That work matters, and these tools do it well. What they do not do is tell you what a specific compliance requirement means or how two authorities relate when they overlap.
A research tool answers the interpretive question: what does this requirement say, and where is the authority. It finds the guidance, cites it to the section, and shows how sources connect, rather than documenting that a test was performed.
Bizora Audit Research illustrates the difference, covering the Uniform Guidance, the Compliance Supplement, and the authorities behind each answer, including GASB, PCAOB, AICPA, and GAO Yellow/Green/Red Book guidance alongside 2 CFR 200. It's included with Pinnacle plans on the web app, or billed at $0.65 per query through the API and MCP server, with automatic routing that needs no code changes on an existing integration.
Classification is not a paperwork label. It decides whether monitoring duties and single audit rules flow down to the entity receiving the funds.
The pass-through entity makes this call case by case, and the wrong call leaves either a monitoring gap or an unnecessary compliance burden.
Under 2 CFR 200.331, the pass-through entity uses judgment to classify each agreement. The rule is that "the substance of the relationship is more important than the form of the agreement," so no single factor controls. The section lists characteristics for each side.
Once you confirm a subrecipient relationship, 200.332 sets the monitoring obligation. The pass-through entity carries three duties across the award life cycle.
Single audit findings generally follow the classic criteria, condition, cause, effect, and recommendation structure, but 2 CFR 200.516(b) requires additional detail as applicable: federal program and award identification, questioned costs and how they were computed, perspective on the finding's prevalence and consequences, whether it repeats a finding from the immediately prior audit, and the auditee's views where they differ from the auditor's.
Questioned costs get their own threshold. Auditors report questioned costs over $25,000 when known or likely amounts exceed that figure for a compliance requirement type on a major program (2 CFR 200.516(a)(3)). The same $25,000 line applies to a non-major program under 200.516(a)(4) when the auditor becomes aware of the costs.
The results feed the data collection form required by Appendix X to Part 200, commonly called the SF-SAC. The regulation itself refers to it as the data collection form, so use that term in workpapers and note the informal name.
Submission runs on a firm clock. Section 200.512 sets the deadline for the audit, the data collection form, and the reporting package. Submit within 30 calendar days after the auditee receives the auditor's report, or nine months after the audit period ends, whichever is earlier (200.512(a)(1)).
Work the submission in order:
The FAC now operates under the General Services Administration at fac.gov, so verify the current portal before you file.
Consider a state university that receives federal research funding. For the auditor, the engagement stack is not just the Uniform Guidance: a single audit generally layers GAGAS, Subpart F of 2 CFR Part 200, the applicable year's OMB Compliance Supplement, and AU-C 935, Compliance Audits, while the financial statements follow the entity's own reporting framework, GASB for a state university. Those authorities serve different purposes and do not substitute for one another, and Subpart F explicitly references GAGAS in several places, so the two are already meant to interact.
Take one question: whether a nonaudit service the firm provided creates a self-review threat that affects the research program's major program testing. Tracing it across GASB's reporting treatment, the Uniform Guidance compliance requirements, and the Yellow Book's stricter independence standard, and showing where they diverge, is exactly the kind of cross-authority work that consumes the most time in engagements like this.
The major program determination and the independence conclusion remain the auditor's own call, whatever tool or reference is used to research the underlying authorities.
A single audit is required when a non-federal entity expends $1,000,000 or more in federal awards during its fiscal year, per 200.501(a). This figure applies to fiscal years beginning on or after October 1, 2024, up from the prior $750,000.
States, local governments, Indian tribes, nonprofits, and higher education institutions that expend $1,000,000 or more in federal awards must have one. For-profit entities are not subject to Subpart F solely because they hold federal procurement contracts governed by the FAR; if a for-profit entity receives federal financial assistance instead, the award terms and pass-through requirements require separate analysis.
Type A programs are those with federal awards expended above the Type A threshold set in 200.518, while Type B programs fall below it. The distinction drives which programs get risk assessment and how much of total spending the audit must cover.
No, procurement contracts for the government's own goods and services are governed by the FAR rather than the Uniform Guidance. For-profit federal contractors are not covered by the single audit requirement solely because they hold procurement contracts; federal financial assistance arrangements require separate analysis, and a for-profit entity acting as a subrecipient can still owe compliance duties that the pass-through entity must monitor.
The pass-through entity must follow up under 200.332, verify the subrecipient is audited under Subpart F, and act on any findings. Persistent failure can lead to enforcement actions such as withholding funds or disallowing costs.
Recipients and subrecipients must retain records for three years from the date they submit their final financial report, per 2 CFR 200.334. The clock pauses if litigation, a claim, or an audit begins before the three years run out
Bizora AI turns hours of manual research into seconds, with every answer backed by primary source citations. Start your 7-day free trial. No credit card required.
Start Free Trial