What is a Single Audit and who needs one?
The Single Audit
A Single Audit is an organization-wide audit of financial statements plus a compliance and internal control audit of federal awards. It is required of any non-federal entity that expends federal awards above the threshold in its fiscal year, counting direct awards and pass-through subawards together.
Current figures — verified 2026-08-11
Item Value Source Single Audit trigger $1,000,000 or more in federal awards expended during the fiscal year 2 CFR 200.501(a) Type A program threshold, smallest tier $1,000,000 for entities expending $1,000,000 to $34 million 2 CFR 200.518(b) Percentage-of-coverage rule 20 percent of total federal awards expended for a low-risk auditee; 40 percent otherwise 2 CFR 200.518(f) Questioned-cost reporting threshold Known or likely questioned costs greater than $25,000 for a type of compliance requirement for a major program 2 CFR 200.516(a)(3) Reporting package submission deadline The earlier of 30 calendar days after receipt of the auditor’s report or nine months after the end of the audit period 2 CFR 200.512(a) Management decision deadline Within six months of the Federal Audit Clearinghouse’s acceptance of the audit report 2 CFR 200.521(d) Type A low-risk disqualifier, questioned costs Known or likely questioned costs exceeding five percent of the total federal awards expended for that Type A program 2 CFR 200.518(c) Type B high-risk governors No more high-risk Type B programs than one-fourth the number of low-risk Type A programs; risk assessments required only on Type B programs exceeding 25 percent of the Type A threshold 2 CFR 200.518(d) These figures change. Verify against the linked source before relying on them. Report an outdated figure
Key takeaways
- The trigger is federal awards expended, not received or awarded.
- Pass-through subawards aggregate with direct awards toward the threshold.
- Auditors test compliance for major programs, not every award.
- A finding is not a debt; a management decision creates one.
- Findings raise your risk score with every future funder.
What is a Single Audit?
A Single Audit is two audits delivered as one engagement: an audit of the entity’s financial statements under generally accepted accounting principles, and an audit of compliance and internal control over compliance for the entity’s major federal programs. Governing rules sit in Subpart F of the Uniform Guidance (2 CFR 200.500–200.521), and the engagement follows Government Auditing Standards.
The name describes the design intent. Before the Single Audit Act, each federal agency could audit its own awards separately, so a grantee with awards from six agencies could face six audits of the same books. The Single Audit substitutes one organization-wide engagement that every agency relies on, which is why it “must cover the entire operations of the auditee” rather than a single grant (2 CFR 200.514(a)).
Three products come out of the engagement. An opinion on the financial statements. An in-relation-to opinion on the schedule of expenditures of federal awards, the schedule that lists every federal dollar the entity spent by program and Assistance Listing number. And a report on compliance for each major program plus internal control over compliance, which is where findings live.
A Single Audit is not a program audit, not an agency site visit, and not an inspector general investigation. Those happen separately and can reach awards a Single Audit never touched. What a Single Audit provides is the government-wide record of whether an organization managed federal money in accordance with the rules, and that record is public. The engagement is one part of a broader post-award obligation set covered across managing the award.
Who must have a Single Audit?
An entity must have a Single Audit when it expends federal awards at or above the threshold shown in the figures above during its own fiscal year (2 CFR 200.501(a)). Three features of that sentence do most of the work, and each one catches organizations out.
The test is expended, not received, awarded, or budgeted. The determining factor is “when the activity related to the Federal award occurs” (2 CFR 200.502(a)). Expenditures include ordinary expense transactions, disbursements to subrecipients, the use of loan proceeds, receipt of property including surplus property, the receipt or use of program income, distribution of food commodities, interest subsidies, and periods when federally required insurance is in force. A three-year award drawn down evenly crosses the threshold in the year the spending crosses it, not the year it was signed.
The test aggregates every federal source. Direct awards and funds received as a subrecipient through a pass-through entity are added together. An organization holding one modest federal grant and a dozen small state contracts funded with federal money can be over the threshold without ever having applied to a federal agency, and the state agency is not obligated to warn it. Identifying which state dollars carry a federal Assistance Listing number is a recurring surprise for subrecipients — the flow-down duties are covered under subrecipient monitoring and pass-through funding.
The test excludes contractor payments. An entity “may simultaneously be a recipient, a subrecipient, and a contractor,” and payments received for goods or services provided as a contractor “are not subject to audit under this part” (2 CFR 200.501(g)). Whether a relationship is a subaward or a procurement contract therefore decides whether the money counts, which makes that determination a financial question rather than a paperwork one. Subpart F also does not apply to for-profit organizations; a pass-through entity must instead build its own assurance into the subaward (2 CFR 200.501(i)).
An entity below the threshold is exempt from federal audit requirements for that year, but its records remain available for review by the awarding agency, the pass-through entity, and the Government Accountability Office (2 CFR 200.501(e)).
How does a Single Audit differ from other audits?
A Single Audit differs from a standard financial statement audit by adding a federal compliance opinion, and from a program-specific audit by covering the whole organization rather than one program. Choosing between them is not discretionary in most cases; the rules set the conditions.
The table below compares the three engagement types an organization spending federal money might encounter.
| Engagement | What it covers | When it applies |
|---|---|---|
| Financial statement audit | Financial statements only | Required by lenders, state law, or bylaws; no federal compliance opinion |
| Single Audit | Financial statements, schedule of expenditures of federal awards, and compliance for major programs | Federal awards expended at or above the threshold |
| Program-specific audit | One federal program’s financial statements and compliance | Entity expends awards under only one program, excluding research and development, and no financial statement audit is otherwise required |
A program-specific audit election is narrower than it looks. Beyond the single-program condition, the program’s own statutes, regulations, or award terms must not require a financial statement audit (2 CFR 200.501(c)). For research and development, the election is available only if all awards come from the same federal agency, or the same agency and the same pass-through entity, and the agency approves in advance (2 CFR 200.501(d)). Most multi-funder organizations do not qualify.
What does a Single Audit examine?
A Single Audit examines four things: the financial statements, the schedule of expenditures of federal awards, internal control over compliance for major programs, and compliance with the requirements that apply to those major programs. Scope is fixed by regulation and by the OMB Compliance Supplement, not negotiated with the auditor.
On the financial side, the auditor determines whether the statements are presented fairly under generally accepted accounting principles, and whether the schedule of expenditures of federal awards is stated fairly in relation to the statements as a whole (2 CFR 200.514(b)). On the compliance side, the auditor must obtain an understanding of internal control over federal programs sufficient to plan testing that supports a low assessed level of control risk, and then perform that testing (2 CFR 200.514(c)).
Compliance testing is organized around the types of compliance requirements defined in the OMB Compliance Supplement, incorporated into the regulation at 2 CFR Appendix XI to Part 200: activities allowed or unallowed; allowable costs and cost principles; cash management; eligibility; equipment and real property management; matching, level of effort, and earmarking; period of performance; procurement and suspension and debarment; program income; reporting; subrecipient monitoring; and special tests and provisions.
Scope narrows from there. The Supplement limits the number of compliance requirements identified as subject to audit for each program, and the Part 2 matrix records which ones apply to which Assistance Listing (OMB Compliance Supplement). One consequence is widely misread: a requirement marked as not subject to audit is still a requirement. The Supplement governs what the auditor tests, not what the recipient must obey.
Which federal programs does a Single Audit test?
A Single Audit tests major programs, selected through a four-step risk-based process rather than by testing everything. The auditor’s judgment in applying the process “must be presumed correct when the determination was performed and documented in accordance with this part” (2 CFR 200.518(h)).
Step one sorts programs by size. Programs above the Type A threshold in the figures above are labeled Type A; everything else is Type B. A cluster of related programs counts as one program, and large loan programs are identified separately and removed before the Type A threshold is recalculated so they cannot crowd out other programs.
Step two identifies which Type A programs are low-risk. A Type A program qualifies only if it was audited as a major program in at least one of the two most recent audit periods and, in the most recent period, had no material weakness in internal control over the program, no modified opinion on the program, and no known or likely questioned costs above the percentage shown in the figures above (2 CFR 200.518(c)).
Step three identifies high-risk Type B programs using professional judgment against the criteria at 2 CFR 200.519, subject to the two governors shown in the figures above, which cap how many high-risk Type B programs the auditor must identify and set a floor below which Type B programs need no risk assessment (2 CFR 200.518(d)).
Step four sets the tested set: every Type A program not identified as low-risk, every high-risk Type B program, and enough additional programs to satisfy the percentage-of-coverage rule shown in the figures above. Low-risk auditee status halves the required coverage, which is the concrete financial argument for compliance infrastructure. Qualifying requires, for each of the two preceding audit periods, annual audits filed on time, unmodified opinions on the statements and on the schedule of expenditures of federal awards, no material weaknesses under Government Auditing Standards, no going-concern doubt, and no Type A program with a material weakness, modified opinion, or questioned costs above the percentage shown in the figures above (2 CFR 200.520).
What is a Single Audit finding?
A Single Audit finding is a defect the auditor is required to report in the schedule of findings and questioned costs. Seven categories are reportable, including significant deficiencies and material weaknesses in internal control over major programs, material noncompliance related to a major program, known questioned costs above the threshold shown in the figures above, known or likely fraud affecting a federal award, and instances where the summary schedule of prior audit findings materially misrepresents a prior finding’s status (2 CFR 200.516(a)).
Four terms are worth separating precisely, because they are routinely conflated.
- Questioned cost — an amount that in the auditor’s judgment is noncompliant or suspected noncompliant, “lacked adequate documentation to support compliance” at the time of the audit, or appeared unreasonable and did not reflect the actions a prudent person would take (2 CFR 200.1). A questioned cost is an allegation.
- Disallowed cost — a charge the federal agency or pass-through entity has determined to be unallowable. A disallowed cost is a debt.
- Significant deficiency — under the compliance-audit standards applied through Government Auditing Standards, a deficiency in internal control over compliance less severe than a material weakness, yet important enough to merit attention by those charged with governance (GAO, Government Auditing Standards).
- Material weakness — a deficiency, or combination of deficiencies, such that there is a reasonable possibility that material noncompliance with a type of compliance requirement will not be prevented, or detected and corrected, on a timely basis.
Every reported finding must carry eleven elements: program and award identification, the criteria, the condition, the cause, the effect, questioned costs by Assistance Listing and award number with the computation, an explanation where an amount could not be determined, perspective on whether the issue is isolated or systemic, whether the finding repeats a prior-year finding with its reference number, recommendations, and the views of responsible officials (2 CFR 200.516(b)). A finding missing the cause or the criteria is incomplete, and a corrective action plan written against a missing cause is unlikely to close it.
What happens after a Single Audit finding?
After a Single Audit finding, the auditee writes a corrective action plan, the reporting package goes to the Federal Audit Clearinghouse, and the responsible federal agency or pass-through entity issues a management decision. Findings do not disqualify an organization from future funding, but they change how every funder scores it.
The corrective action plan must be a document separate from the auditor’s findings, and must name the contact person responsible, the corrective action, and the anticipated completion date; disagreement with a finding requires a detailed explanation (2 CFR 200.511(c)). The auditee also prepares a summary schedule of prior audit findings reporting the status of every prior finding, including the fiscal year in which it first occurred.
The reporting package — financial statements and the schedule of expenditures of federal awards, the summary schedule of prior audit findings, the auditor’s reports, and the corrective action plan — goes to the Federal Audit Clearinghouse by the deadline in the figures above (2 CFR 200.512). The Clearinghouse is the repository of record and is public, and it is operated by the General Services Administration at fac.gov. A senior-level representative of the auditee must certify the data collection form, including that the package contains no protected personally identifiable information.
The management decision follows. The agency or pass-through entity states whether the finding is sustained, the reasons, and the expected action to repay disallowed costs or make financial adjustments, within the deadline in the figures above (2 CFR 200.521). One provision is worth knowing before the decision issues: the agency “may request additional information or documentation from the auditee, including a request for auditor assurance related to the documentation, as a way of mitigating disallowed costs.” Documentation produced after fieldwork ends can still reduce the amount owed.
Downstream, findings compound in three ways. Low-risk auditee status is lost, roughly doubling required audit coverage and audit fees for at least two years. Federal agencies may consider audit history in pre-award risk review and impose specific conditions such as reimbursement-only payment (2 CFR 200.208), and pass-through entities are required to weigh the results of previous audits when assessing subrecipient risk. And repeat findings are flagged by prior-year reference number, which is the strongest available signal to a funder that the control never changed.
The scale of unresolved findings is documented. The Government Accountability Office found that $1.17 trillion of $6.97 trillion in direct federal award funds spent by recipients from 2017 through 2021 was linked to single audit findings that were both severe and persistent, and identified 213 findings reported in 2015 or earlier that remained unresolved in 2021 (GAO-24-106173).
How do you prepare for a Single Audit?
Preparation for a Single Audit is mostly finished before the auditor arrives, because the engagement tests records that had to exist during the year. The most useful preparation is treating the schedule of expenditures of federal awards as a live document rather than a year-end reconstruction.
Six items carry most of the weight:
- The schedule of expenditures of federal awards. Build it from the general ledger throughout the year, with the Assistance Listing number, federal award identification number, pass-through entity, and amounts passed through to subrecipients for each line.
- Written policies. Cash management and drawdowns, allowability determinations, procurement with suspension and debarment checks, conflict of interest, subrecipient monitoring, compensation and time-and-effort documentation, travel, property management, records retention, cost sharing, and program income.
- The audit trail for any sampled dollar. A tester should be able to move from a schedule line to the general ledger, to the transaction, to the source document, to the approval, to the award term that permits the cost, without leaving the room.
- Payroll allocation evidence. Records that meet the personnel documentation standards, plus the dated reconciliations proving the control operated — the mechanics are set out in time and effort documentation.
- The prior-year finding file. Status of every previous finding, with evidence that corrective action actually happened, since the auditor must follow up regardless of whether the program is major in the audit period under way (2 CFR 200.514(e)).
- Subrecipient audit verification. Evidence that each subrecipient was audited as required by Subpart F, along with your monitoring records.
Selecting the auditor matters more than the fee comparison suggests. Ask how many Single Audits the firm issues annually, whether the engagement partner sits on governmental or nonprofit engagements year-round, how the firm handles major program determination documentation, and whether the firm participates in a governmental audit quality program. A firm that performs a handful of these engagements a year will spend your staff’s time learning the framework.
Cost and timeline are real budget items. The audit is an allowable cost, generally recovered through the indirect cost pool, which makes it one more reason to understand indirect cost rates and the de minimis option. Fieldwork commonly runs several weeks and the full cycle from fiscal year end to Clearinghouse submission commonly runs several months, which is why the submission deadline in the figures above binds earlier than organizations expect. Crossing the threshold for the first time is a permanent change in operating cost, not a one-year event.
This article is general information about federal audit requirements, not legal, audit, or accounting advice. Whether an audit is required, and what it covers, depends on your expenditures, your award terms, and your auditor’s professional judgment.
Frequently asked questions
Does money received but not yet spent count toward the Single Audit threshold?
No. The test is federal awards expended during the fiscal year, based on when the activity related to the award occurs. Funds drawn down and sitting in the bank do not count; costs incurred against the award do. Disbursements to subrecipients count as expenditures by the pass-through entity.
Do state grants count toward the federal threshold?
They count when the state dollars originate in a federal award and the organization receives them as a subrecipient. State-appropriated money does not count. The subaward agreement should identify the Assistance Listing number and federal award identification number; if it does not, ask the state agency in writing.
Is a Single Audit the same as an A-133 audit?
Yes, in substance. The requirements formerly published as OMB Circular A-133 were consolidated into Subpart F of 2 CFR Part 200. Older award terms, state manuals, and vendor documentation still say A-133; the governing text is now the Uniform Guidance audit requirements.
Does a finding mean the organization has to repay money?
Not by itself. A questioned cost is the auditor’s allegation that a cost may be unallowable or unsupported. Repayment is owed only after the federal agency or pass-through entity issues a management decision sustaining the finding and determining the cost is disallowed.
Are for-profit companies subject to the Single Audit?
No. Subpart F does not apply to for-profit organizations. Where a for-profit is a subrecipient, the pass-through entity must establish its own compliance assurance through the subaward terms, and may use pre-award audits, ongoing monitoring, or post-award audits.
Can an organization choose a program-specific audit to save money?
Only if it qualifies. The election requires that the entity expend awards under a single federal program excluding research and development, and that no financial statement audit is otherwise required by the program’s rules or award terms. Most organizations with more than one funder do not meet the test.
Related topics
- Managing the Award — the hub for post-award compliance, reporting, and closeout
- Internal Controls for Grant Recipients
- Allowable, Allocable, and Reasonable Costs
- Closing Out a Grant
Sources
- Electronic Code of Federal Regulations, 2 CFR 200.501, “Audit requirements.” https://www.ecfr.gov/current/title-2/section-200.501 (accessed 2026-08-11)
- Electronic Code of Federal Regulations, 2 CFR 200.502, “Basis for determining Federal awards expended.” https://www.ecfr.gov/current/title-2/section-200.502 (accessed 2026-08-11)
- Electronic Code of Federal Regulations, 2 CFR 200.507, “Program-specific audits.” https://www.ecfr.gov/current/title-2/section-200.507 (accessed 2026-08-11)
- Electronic Code of Federal Regulations, 2 CFR 200.511, “Audit findings follow-up.” https://www.ecfr.gov/current/title-2/section-200.511 (accessed 2026-08-11)
- Electronic Code of Federal Regulations, 2 CFR 200.512, “Report submission.” https://www.ecfr.gov/current/title-2/section-200.512 (accessed 2026-08-11)
- Electronic Code of Federal Regulations, 2 CFR 200.514, “Standards and scope of audit.” https://www.ecfr.gov/current/title-2/section-200.514 (accessed 2026-08-11)
- Electronic Code of Federal Regulations, 2 CFR 200.516, “Audit findings.” https://www.ecfr.gov/current/title-2/section-200.516 (accessed 2026-08-11)
- Electronic Code of Federal Regulations, 2 CFR 200.518, “Major program determination.” https://www.ecfr.gov/current/title-2/section-200.518 (accessed 2026-08-11)
- Electronic Code of Federal Regulations, 2 CFR 200.519, “Criteria for Federal program risk.” https://www.ecfr.gov/current/title-2/section-200.519 (accessed 2026-08-11)
- Electronic Code of Federal Regulations, 2 CFR 200.520, “Criteria for a low-risk auditee.” https://www.ecfr.gov/current/title-2/section-200.520 (accessed 2026-08-11)
- Electronic Code of Federal Regulations, 2 CFR 200.521, “Management decisions.” https://www.ecfr.gov/current/title-2/section-200.521 (accessed 2026-08-11)
- Electronic Code of Federal Regulations, 2 CFR Appendix XI to Part 200, “Compliance Supplement.” https://www.ecfr.gov/current/title-2/appendix-Appendix%20XI%20to%20Part%20200 (accessed 2026-08-11)
- Office of Management and Budget, “Compliance Supplement.” https://www.whitehouse.gov/omb/information-resources/guidance/compliance-supplement/ (accessed 2026-08-11)
- U.S. General Services Administration, Federal Audit Clearinghouse. https://www.fac.gov/ (accessed 2026-08-11)
- U.S. Government Accountability Office, “Single Audits: Improving Federal Audit Clearinghouse Information and Usability Could Strengthen Federal Award Oversight,” GAO-24-106173, April 22, 2024. https://www.gao.gov/products/gao-24-106173 (accessed 2026-08-11)
- U.S. Government Accountability Office, “Government Auditing Standards” (Yellow Book). https://www.gao.gov/yellowbook (accessed 2026-08-11)