A grant auditor is an independent accountant who examines how your organization spent federal award money and whether every dollar followed the rules attached to that award. The review combines financial testing with compliance testing, and if your organization spent $1,000,000 or more in federal awards during its fiscal year, it happens as a Single Audit covering all your federal programs at once rather than one grant at a time.1eCFR. 2 CFR 200.501 – Audit Requirements Preparing well means understanding what the auditor is looking for, getting the supporting records in order before they ask, and making sure the controls in your policy manual match what your staff actually does day to day.
What a Grant Auditor Actually Does
A grant auditor is not doing a standard financial statement audit. A financial statement audit asks whether your books fairly present your financial position. A grant audit asks a harder question: did you spend federal money in strict compliance with the specific rules attached to each award? The auditor is combining financial review with compliance testing, checking both the accuracy of your numbers and whether every expenditure followed the regulations.
Compliance testing focuses on whether costs charged to the grant were allowable, meaning reasonable, necessary for the program, and consistent with the cost principles in federal guidance. The auditor also verifies any matching requirements, where your organization agreed to contribute a percentage of non-federal funds toward total project cost. Beyond individual transactions, the auditor evaluates the internal controls you use to manage federal funds. These are the policies and procedures meant to prevent or catch errors and non-compliance before they become systemic.2eCFR. 2 CFR 200.303 – Internal Controls
Internal controls cover everything from who approves purchases to how you track time employees spend on different grants. The auditor isn’t just reading your policy manual. They’re testing whether those controls actually work in practice, and that distinction trips up more organizations than any other part of the process.
The Rules a Grant Auditor Works From
Federal grants operate under the Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards, usually called the Uniform Guidance or 2 CFR Part 200.3eCFR. 2 CFR Part 200 – Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards It covers financial management, procurement, property, record retention, and audit requirements. The Single Audit threshold sits at $1,000,000 in federal expenditures during your fiscal year. Organizations below that threshold are exempt from the federal audit requirement for that year, though the federal agency can still review records directly. The threshold was raised from $750,000 in 2024, so older guidance you find online may reference the lower number.
The audit itself must be conducted under Government Auditing Standards, commonly called the Yellow Book, published by the Government Accountability Office.4U.S. Government Accountability Office. Yellow Book – Government Auditing Standards These standards set requirements for auditor independence, professional judgment, and the quality of audit evidence, and the GAO updated them in 2024 to reflect new quality management standards.5U.S. Government Accountability Office. Government Auditing Standards 2024 Revision
Auditors don’t test compliance from scratch. The Office of Management and Budget publishes a Compliance Supplement each year identifying the specific areas auditors must examine for each major program.6The White House. Compliance Supplement The specific requirements depend on the federal program, so the auditor tailors testing to your particular awards.
Your organization must prepare a Schedule of Expenditures of Federal Awards, known as the SEFA, listing every federal program you participated in during the audit period. The SEFA must identify each program by federal agency, Assistance Listing Number, and total amount spent.7eCFR. 2 CFR 200.510 – Financial Statements Getting the SEFA right is foundational because the auditor uses it to determine which programs qualify as major programs and receive the most intensive testing.
How the Auditor Picks Which Programs to Test
Not every federal program you run gets the same level of scrutiny. The auditor uses a risk-based, multi-step process to determine which programs are “major” and therefore subject to full compliance testing. Organizations with many smaller grants sometimes get surprised here.
The process starts by sorting programs into two categories based on spending. Larger programs, called Type A, are those exceeding a dollar threshold that scales with your total federal expenditures. For organizations spending between $1,000,000 and $34 million in total, every program over $1,000,000 is Type A, and the threshold adjusts upward as total spending grows.8eCFR. 2 CFR 200.518 – Major Program Determination Everything else is Type B.
The auditor then assesses risk within each category. A Type A program recently audited without problems can be classified as low-risk. It loses that status if the most recent audit found material weaknesses, a modified compliance opinion, or questioned costs exceeding five percent of the program’s expenditures.8eCFR. 2 CFR 200.518 – Major Program Determination The auditor also uses professional judgment to flag high-risk Type B programs. At minimum, the auditor must test all Type A programs that aren’t low-risk, all high-risk Type B programs, and enough additional programs to meet the required coverage percentage.
What to Have Ready Before Fieldwork
The single best thing you can do before an audit is get your records organized before the auditor asks for them. Audit readiness means every dollar charged to a federal award can be traced to supporting documentation, and every policy your organization claims to follow exists in writing.
Start with expense records. Every cost claimed under the grant needs backup: vendor invoices, payment records, and general ledger entries that tie the expense to the correct award. The auditor will trace transactions from the ledger back to source documents, so gaps in that chain are immediate red flags.
Personnel Cost Documentation
Payroll is where auditors spend a disproportionate amount of time, especially when employees split their work across multiple funding sources. The Uniform Guidance requires that salary charges to federal awards be supported by records reflecting actual work performed. Those records must be backed by internal controls, incorporated into official records, and cover all of the employee’s compensated activities rather than just the federally funded portion.9eCFR. 2 CFR 200.430 – Compensation, Personal Services
Budget estimates alone won’t satisfy the auditor. If your organization uses estimates for interim accounting, you need a process for periodic after-the-fact reviews that reconcile estimated charges against actual work performed, and you must adjust the final amounts accordingly.9eCFR. 2 CFR 200.430 – Compensation, Personal Services The current rules are more flexible than the older prescriptive time-and-effort certification forms, but the underlying requirement hasn’t changed: you need to prove that time billed to each grant reflects time actually spent on it.
Procurement Records
For purchases, the auditor checks whether you followed your own documented procurement procedures and whether those procedures meet federal standards. Micro-purchases, which fall below a threshold your organization sets based on its own risk assessment, can be made without competitive quotes as long as you document that the price was reasonable.10eCFR. 2 CFR 200.320 – Procurement Methods Above that threshold, the auditor expects to see evidence of competitive bidding or price comparison.
Conflict of Interest Policies
Your organization should maintain a written conflict of interest policy covering employees, volunteers, and board members. The policy should define what constitutes a conflict, establish a process for disclosure and resolution, restrict individuals with financial interests from participating in procurement decisions, and prohibit employees from accepting gifts or favors from contractors. Annual signed conflict of interest statements and regular training are baseline practices that auditors look for.
Internal Control Documentation
Federal regulations require recipients to establish, document, and maintain effective internal controls that provide reasonable assurance of compliance with the terms of each award.2eCFR. 2 CFR 200.303 – Internal Controls In practice, that means written policies covering cash management, financial reporting, approval workflows, and how you handle identified non-compliance. The guidance expects these controls to align with either the Comptroller General’s standards for internal control or the COSO framework. If your policy manual is outdated or doesn’t match what your staff actually does, that gap alone can generate a finding.
Indirect Cost Rate Compliance
Indirect costs are shared expenses that support federal programs but can’t be tied to a single award, like rent, utilities, and administrative salaries. If your organization has a negotiated indirect cost rate with your cognizant federal agency, the auditor verifies that you’re applying the correct rate type (provisional or final) and that the base matches your agreement. Organizations that have never had a negotiated rate can elect a de minimis rate of up to 15 percent of modified total direct costs.11eCFR. 2 CFR 200.414 – Indirect (F&A) Costs The de minimis rate requires no supporting documentation and can be used indefinitely, but once elected it applies to all your federal awards until you choose to negotiate a rate instead. The auditor also checks that you haven’t double-charged costs, meaning the same expense showing up as both a direct charge and part of your indirect cost pool. That’s one of the most common indirect-cost findings.
Subrecipient Monitoring
If your organization passes federal funds through to subrecipients, expect the auditor to spend real time on how you oversee those sub-awards. Pass-through entities must monitor subrecipient activities to ensure funds are used properly and performance goals are met. That includes reviewing subrecipient financial and performance reports, following up on deficiencies found through audits or on-site reviews, and issuing management decisions on relevant audit findings.
The auditor also looks at whether you assessed each subrecipient’s risk of non-compliance before or at the time of the sub-award. Relevant factors include the subrecipient’s prior experience with similar awards, prior audit results, personnel changes, and the extent of federal monitoring. Higher-risk subrecipients should trigger additional oversight, such as on-site reviews or specific award conditions. Treating this as a check-the-box exercise rather than genuine risk management tends to generate findings.
What Happens During Fieldwork
Fieldwork typically begins with an entrance conference where the audit team meets your management. This meeting establishes the scope and timeline, identifies which programs are being tested as major programs, and introduces the people on both sides who’ll exchange documents and answer questions over the coming weeks.
After that meeting, the auditor conducts a risk assessment to determine where to focus testing, then performs two types of testing. Control testing checks whether your internal controls actually function. If your policy says a supervisor must approve every purchase over $5,000, the auditor pulls a sample of those purchases and verifies that each one has the required approval. Substantive testing involves selecting a sample of transactions from the general ledger and tracing them back to source documentation to verify the cost was allowable, the amount was accurate, and it was charged to the right award.
Throughout fieldwork, the auditor issues periodic document requests, sometimes called Prepared By Client lists. Expect interviews with key staff responsible for financial reporting and grant management. The auditor uses these conversations to confirm that the people doing the work actually know and follow the documented procedures. A well-trained staff member who can walk through the process confidently makes a noticeably better impression than one who defers every question to a supervisor.
Choosing a Grant Auditor
You don’t get to pick just anyone for a Single Audit. The auditor must be qualified to perform work under Government Auditing Standards, and your organization must follow its standard procurement procedures when soliciting proposals. When evaluating firms, consider relevant experience, staff qualifications, results of the firm’s peer review, and price.12eCFR. 2 CFR Part 200 Subpart F – Audit Requirements Request a copy of the firm’s peer review report as part of the proposal process.
One important restriction: an auditor who prepared your indirect cost proposal or cost allocation plan cannot perform the Single Audit if your indirect costs recovered in the prior year exceeded $1 million.12eCFR. 2 CFR Part 200 Subpart F – Audit Requirements This conflict-of-interest rule prevents a firm from auditing its own work product.
Findings, Corrective Action, and the Reporting Deadline
Once fieldwork wraps, the auditor communicates preliminary findings in an exit conference. This is your chance to correct misunderstandings or provide additional documentation before anything becomes final. Take it seriously. Findings that could have been resolved with a missing receipt or a clarifying email sometimes get locked into the final report because nobody responded during this window.
Findings fall into several categories of severity:
- Questioned costs are expenditures the auditor flags as potentially unallowable or not adequately supported. They must be reported when known or likely amounts exceed $25,000 for a compliance requirement within a major program. A questioned cost is not the same as a disallowed cost; costs are questioned during the audit, but only disallowed after the federal agency reviews them and confirms they were improper.13eCFR. 2 CFR 200.516 – Audit Findings
- A significant deficiency is a control weakness serious enough to merit attention but not severe enough to be a material weakness.
- A material weakness is a control deficiency where there’s a reasonable possibility that material non-compliance could go undetected. This is the most serious internal control finding and will draw federal agency scrutiny.13eCFR. 2 CFR 200.516 – Audit Findings
The auditor also reports material non-compliance with federal statutes, regulations, or award terms, a modified compliance opinion, or known or likely fraud affecting a federal award.13eCFR. 2 CFR 200.516 – Audit Findings
Your organization must prepare a corrective action plan addressing each finding. The plan names the person responsible for each corrective action, describes what steps will be taken, and includes an anticipated completion date. If you disagree with a finding, the plan must include a detailed explanation of why you believe corrective action is unnecessary.14eCFR. 2 CFR 200.511 – Audit Findings Follow-Up
The complete audit package, including the data collection form and reporting package, must be submitted to the Federal Audit Clearinghouse within 30 calendar days after you receive the auditor’s report or nine months after the end of the audit period, whichever comes first.15eCFR. 2 CFR 200.512 – Report Submission Missing this deadline is itself a compliance issue, and your cognizant agency can grant an extension only if the nine-month timeframe would impose an undue burden. The granting agency or pass-through entity then follows up to confirm you’ve actually implemented the corrective actions you promised.
What Non-Compliance Can Cost You
Audit findings aren’t just paperwork. Federal agencies have a graduated set of enforcement tools, and which ones they deploy depends on how serious the non-compliance is and whether you’ve shown good faith in fixing it.
The most immediate consequence is financial. Questioned costs that the agency later confirms as unallowable become disallowed costs, meaning your organization must repay those funds. For a small nonprofit, even a modest disallowance can threaten operations.
When an agency determines that non-compliance can’t be fixed through specific award conditions alone, it can escalate:
- Withholding payments temporarily until you take corrective action.
- Suspending or terminating the award, partially or completely ending grant funding.
- Withholding future funding by declining continuation awards or new awards for the project.
- Initiating suspension or debarment proceedings that can bar your organization from all federal awards government-wide.16NIH. 8.5.2 Remedies for Noncompliance or Enforcement Actions: Suspension, Termination, and Withholding of Support
If an award is terminated for material non-compliance, that termination gets reported in SAM.gov and remains visible for five years. Any federal agency considering a new award to your organization during that period must factor in the termination when deciding whether you’re qualified to receive funds.16NIH. 8.5.2 Remedies for Noncompliance or Enforcement Actions: Suspension, Termination, and Withholding of Support
Debarment is the most severe outcome. It typically lasts three years and covers all executive branch procurement and non-procurement programs. Triggers include fraud, false statements, destruction of records, and a pattern of failing to perform. Suspension works similarly but is temporary, usually up to twelve months while an investigation or legal proceeding is pending.17GSA. Frequently Asked Questions: Suspension and Debarment Organizations facing suspension or proposed debarment can submit evidence of their current responsibility to the deciding official, and in some cases request a meeting, but the reputational and operational damage from being listed on SAM.gov is often severe even if the action is eventually reversed.