Eligibility and Organizational Readiness

What internal controls do grant funders require?

Internal Controls for Grant Recipients

Internal controls are the documented processes a grant recipient uses to give reasonable assurance that award funds are managed in compliance with statutes, regulations, and award terms. The Uniform Guidance requires them at 2 CFR 200.303. Funders assume the machinery already exists before the first payment.

Current figures — verified 2026-08-11

ItemValueSource
Single Audit trigger$1,000,000 in federal awards expended per fiscal year2 CFR 200.501(a)
Questioned costs requiring a reported findingGreater than $25,000 for a compliance requirement on a major program2 CFR 200.516(a)(3)
Baseline record retention3 years from submission of the final financial report2 CFR 200.334
Required Single Audit coverage20% of awards expended for a low-risk auditee; 40% otherwise2 CFR 200.518(f)
Questioned-cost ceiling for low-risk auditee status5% of awards expended for a Type A program2 CFR 200.520(e)(3)

These figures change. Verify against the linked source before relying on them. Report an outdated figure

Key takeaways

  • Internal control is required; a specific framework is recommended, not mandated.
  • Tracking spend by award and cost category is the most common structural gap.
  • Small teams cannot segregate every duty. Design compensating controls instead.
  • Undocumented compliance is indistinguishable from noncompliance to an auditor.
  • Control failure raises your risk score with every funder, not one.

What are internal controls for a grant recipient?

Internal controls are the processes an organization designs and operates to give reasonable assurance that its objectives are met — here, the objective of spending award funds in compliance with the rules attached to them. Internal control is a system, not a document, and it is assessed by whether it works, not by whether it is written down attractively. Building one is a core part of organizational readiness.

Six functions do the work in almost every organization. Segregation of duties keeps authorization, custody of assets, and recordkeeping in different hands. Authorization and approval puts someone with delegated authority in front of each transaction. Documentation gives every transaction a source record. Reconciliation compares records independently against an external source, typically the bank statement. Safeguarding of assets covers physical and access control over cash, equipment, and data. Monitoring checks periodically that the other five still operate.

The vocabulary auditors use comes from the five components of internal control: control environment, risk assessment, control activities, information and communication, and monitoring. Both the Government Accountability Office’s Standards for Internal Control in the Federal Government — the Green Book — and the COSO framework are organized around those five components (GAO). Learning the five words is worth the ten minutes; they are the headings under which findings get written.

What does 2 CFR 200.303 require of grant recipients?

The internal control requirement for federal awards sits in 2 CFR 200.303, which directs a recipient and subrecipient to “establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award” (2 CFR 200.303). Four further duties follow: comply with law and award terms; evaluate and monitor compliance; take prompt action on identified noncompliance; and take reasonable cybersecurity and other measures to safeguard information, including protected personally identifiable information.

One word in 2 CFR 200.303 is regularly misread. The section says internal controls “should align” with the Green Book or COSO — and in the Uniform Guidance, “should” is a recommendation rather than a requirement. The OMB Compliance Supplement states the point directly: “the Uniform Guidance is recommending that recipients and subrecipients use either the Green Book or COSO internal control frameworks but does not require it” (OMB Compliance Supplement, Part 6).

The practical consequence is not that frameworks are optional in effect. What is mandatory is effective, documented internal control. The frameworks are what auditors benchmark against, so an organization that describes its controls in Green Book language answers the question in the auditor’s own terms. One with effective controls and no vocabulary for them spends the audit translating.

How does a small organization build internal controls?

A small organization builds internal controls by accepting that full segregation of duties is impossible and designing around it explicitly. The Green Book anticipates exactly this: “If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.”

The Green Book is also direct about what smaller entities should do instead. A smaller entity “faces greater challenges in segregating duties because of its concentration of responsibilities and authorities in the organizational structure,” and “management can respond to this increased risk through the design of the internal control system, for example, by adding additional levels of review for key processes, reviewing randomly selected transactions and their supporting documentation, taking periodic asset counts, or checking supervisor reconciliations” (GAO, Standards for Internal Control in the Federal Government).

Translated into a two-person finance function, five compensating controls do most of the work:

  • Board-level review. A treasurer or finance committee member reviews the bank statement and reconciliation independently of whoever performs it.
  • Dual approval. Payments above a set threshold require a second authorization, ideally electronic and logged.
  • Read-only bank access for a second person. Detection without adding a transaction role.
  • Random transaction sampling. A supervisor pulls a few transactions monthly and traces them to source documents.
  • Periodic asset counts. Equipment inventoried on a schedule, with results signed and dated.

Documenting these choices matters as much as making them. A written note naming which duties cannot be segregated, and which alternative controls address the resulting risk, is the difference between a designed system and an unexamined one.

What must a grant accounting system be able to do?

A grant recipient’s accounting system must be able to identify and report spending by individual award and by cost category. This is the single most common structural gap in organizations new to grant funding, and it is not fixable at reporting time. The financial management requirements at 2 CFR 200.302 call for identification of all federal awards received and expended, records identifying the amount, source, and expenditure of federal funds and supported by source documentation, effective control over funds and assets, and comparison of expenditures with budget amounts for each award (2 CFR 200.302).

In accounting terms this means a chart of accounts with a dimension for the award — a class, fund, project, or grant code — applied to every transaction at entry, not allocated afterward from memory. Payroll must carry the same dimension so salary charges tie to time and effort documentation rather than to a separately maintained spreadsheet.

The test to run before accepting an award is simple. Pick a line: personnel on one award for one month. Can the system produce that number, reconciled to the general ledger, without a manual reconstruction? If producing it requires exporting to a spreadsheet and applying percentages by hand, the organization has a reporting workaround rather than a financial management system, and the gap will surface as a finding or a delayed drawdown.

Which written policies must a grant recipient have?

A federal grant recipient must have written policies in a defined set of areas, some named explicitly in the Uniform Guidance and some implied by the compliance requirements an auditor tests. Seven are non-negotiable in practice:

  • Cash management and payment procedures. Written procedures minimizing the time between drawing federal funds and disbursing them, required by 2 CFR 200.302 and central to how grant cash flow is judged.
  • Allowability of costs. Written procedures for determining whether a cost may be charged; see allowable, allocable, and reasonable costs.
  • Procurement. Documented procedures consistent with the federal procurement standards, including documented competition and price analysis (2 CFR 200.318).
  • Conflict of interest. Written standards of conduct for employees, officers, agents, and board members involved in selecting, awarding, or administering contracts, also required by 2 CFR 200.318.
  • Travel. Rules on rates, documentation, and approval, applied consistently to federal and non-federal activity.
  • Subrecipient monitoring. Risk assessment and monitoring procedures for anyone receiving a subaward; see subrecipient monitoring.
  • Records retention. A schedule reflecting the retention baseline and its extensions, including records kept until litigation, claims, or audit findings are resolved (2 CFR 200.334).

Policies copied from a template and never applied are worse than no policy, because they establish a criterion the organization is then measured against. Write them to describe what the organization does, then improve practice and policy together.

What documentation do grant auditors ask to see?

Auditors ask to see the trail connecting a reported expenditure to the authority that permitted it. The working rule in the profession is blunt: if it isn’t documented, it didn’t happen. Compliant activity with no records still produces a finding, because an auditor can rely only on evidence, and verbal assurance is not evidence.

The trail should survive being walked in a single sitting: from the Schedule of Expenditures of Federal Awards, to the general ledger, to the transaction, to the source document — invoice, timesheet, or labor distribution report — to the approval, to the allowability determination, to the award term that permits the cost. A break anywhere in that chain is where the finding gets written.

Common deficiency areas map closely to the compliance requirements auditors test. GRF CPAs, a firm specializing in nonprofit audits, groups recurring Single Audit deficiencies into nine areas: activities allowed or unallowed, allowable costs and cost principles, cash management, eligibility, equipment and real property management, period of performance, procurement and suspension and debarment, reporting, and subrecipient monitoring (GRF CPAs, September 2025). Nearly all are documentation failures rather than spending failures, which is why maintaining the documentation file beats reconstructing it under examination.

What happens when grant internal controls fail?

A control failure produces consequences in sequence, and none is a single-year event. The first is a questioned cost — an amount the auditor challenges because it violates a rule, lacks documentation, or appears unreasonable. A questioned cost is an allegation, not yet a debt; it becomes a disallowed cost only when the agency or pass-through entity issues a management decision sustaining it.

The second is an audit finding, reported when questioned costs exceed the threshold shown above or when the auditor identifies a significant deficiency, a material weakness, or material noncompliance (2 CFR 200.516). A finding costs money directly and audit coverage indirectly: losing low-risk auditee status doubles the share of federal awards audited as major programs.

The third is specific conditions, which a federal agency or pass-through entity may impose based on compliance history or financial capability. They include reimbursement instead of advance payment, more detailed financial reports, additional monitoring, and additional prior approvals (2 CFR 200.208). Reimbursement-only payment does the quietest damage, because it converts a grant into something the organization must self-fund.

The fourth is escalation. Where noncompliance cannot be remedied by specific conditions, the remedies at 2 CFR 200.339 include withholding payments, disallowing costs, suspending or terminating the award, initiating suspension or debarment, and withholding future funding (2 CFR 200.339).

Findings also persist. GAO reported that $1.17 trillion of $6.97 trillion in direct federal award funds spent by recipients over a five-year period was linked to single audit findings that were both severe and persistent, and that 213 findings first reported in 2015 or earlier remained unresolved (GAO-24-106173). The first finding costs money. The repeat finding costs credibility.

Frequently asked questions

Is the GAO Green Book mandatory for grant recipients?

No. 2 CFR 200.303 says internal controls “should align” with the Green Book or COSO, and in the Uniform Guidance “should” indicates a recommended approach rather than a requirement. Effective, documented internal control is mandatory. Using one of the named frameworks is the most reliable way to demonstrate it.

Do internal control requirements apply below the Single Audit threshold?

Yes. The internal control obligation attaches to the award, not to the audit. Organizations expending less than the Single Audit threshold are exempt from that audit but must still maintain effective internal control, and their records remain available for review by the awarding agency, pass-through entity, and GAO.

How long must grant records be kept?

The baseline retention period appears in the figures above and is extended in several circumstances: unresolved litigation, claims, or audit findings; written notice from an awarding agency or pass-through entity; and property and equipment records, which run from final disposition rather than from the final report.

Do subrecipients have to meet the same internal control standard?

Yes. 2 CFR 200.303 applies to recipients and subrecipients alike. A pass-through entity is separately responsible for assessing subrecipient risk and monitoring accordingly, so a subrecipient’s control weaknesses become the pass-through entity’s problem too.

Does an audit finding disqualify an organization from future grants?

Not automatically. A finding raises the organization’s risk profile in pre-award review and in subrecipient risk assessment, may trigger specific conditions on future awards, and may result in repayment of disallowed costs. Repeat findings are the strongest predictor of escalation.

Sources

  1. Electronic Code of Federal Regulations, 2 CFR 200.303, “Internal controls.” https://www.ecfr.gov/current/title-2/section-200.303 (accessed 2026-08-11)
  2. Electronic Code of Federal Regulations, 2 CFR 200.302, “Financial management.” https://www.ecfr.gov/current/title-2/section-200.302 (accessed 2026-08-11)
  3. Electronic Code of Federal Regulations, 2 CFR 200.318, “General procurement standards.” https://www.ecfr.gov/current/title-2/section-200.318 (accessed 2026-08-11)
  4. Electronic Code of Federal Regulations, 2 CFR 200.334, “Record retention requirements.” https://www.ecfr.gov/current/title-2/section-200.334 (accessed 2026-08-11)
  5. Electronic Code of Federal Regulations, 2 CFR 200.501, “Audit requirements.” https://www.ecfr.gov/current/title-2/section-200.501 (accessed 2026-08-11)
  6. Electronic Code of Federal Regulations, 2 CFR 200.516, “Audit findings.” https://www.ecfr.gov/current/title-2/section-200.516 (accessed 2026-08-11)
  7. Electronic Code of Federal Regulations, 2 CFR 200.518, “Major program determination.” https://www.ecfr.gov/current/title-2/section-200.518 (accessed 2026-08-11)
  8. Electronic Code of Federal Regulations, 2 CFR 200.520, “Criteria for a low-risk auditee.” https://www.ecfr.gov/current/title-2/section-200.520 (accessed 2026-08-11)
  9. Electronic Code of Federal Regulations, 2 CFR 200.208, “Specific conditions.” https://www.ecfr.gov/current/title-2/section-200.208 (accessed 2026-08-11)
  10. Electronic Code of Federal Regulations, 2 CFR 200.339, “Remedies for noncompliance.” https://www.ecfr.gov/current/title-2/section-200.339 (accessed 2026-08-11)
  11. U.S. Government Accountability Office, “The Green Book” (Standards for Internal Control in the Federal Government), overview page. https://www.gao.gov/greenbook (accessed 2026-08-11)
  12. U.S. Government Accountability Office, Standards for Internal Control in the Federal Government, GAO-25-107721. https://www.gao.gov/assets/gao-25-107721.pdf (accessed 2026-08-11)
  13. Office of Management and Budget, Compliance Supplement, Part 6 — Internal Control. https://www.whitehouse.gov/wp-content/uploads/2025/05/Part-6-Internal-Control.pdf (accessed 2026-08-11)
  14. U.S. Government Accountability Office, “Single Audits: Improving Federal Audit Clearinghouse Information and Usability Could Strengthen Federal Award Oversight,” GAO-24-106173, April 22, 2024. https://www.gao.gov/products/gao-24-106173 (accessed 2026-08-11)
  15. Tricia Katebini and John McIntosh, “Common Findings in Single Audits: How Nonprofits Can Strengthen Compliance,” GRF CPAs & Advisors, September 22, 2025 (secondary source; accounting firm analysis). https://www.grfcpa.com/resource/how-nonprofits-can-strengthen-compliance/ (accessed 2026-08-11)

Continue in this section

Reading Is Research. Searching Is Progress.

Put the encyclopedia to work — search every open grant and get matched by eligibility.