OMB Compliance Supplement: Single Audit Testing and Findings

The OMB Compliance Supplement is the annual guidance, published as Appendix XI to 2 CFR Part 200, that sets out the Single Audit requirements for any non-federal entity spending $1,000,000 or more in federal awards during a fiscal year.1The White House. Compliance Supplement2eCFR. 2 CFR 200.501 – Audit Requirements It tells you and your auditor which compliance categories apply to each federal program, how those categories should be tested, what internal controls to have in place, and what to submit when the audit is done.

Who Has to Do a Single Audit

The spending threshold is $1,000,000 in federal awards in one fiscal year. Above that, you owe either a Single Audit or a program-specific audit. Below it, you are exempt from federal audit requirements for that year, though records must still be available if a federal agency asks.2eCFR. 2 CFR 200.501 – Audit Requirements The threshold was raised from $750,000 and applies to audit periods beginning on or after October 1, 2024, so it is fully in effect for 2026 fiscal years.3HHS Office of Inspector General. Single Audits FAQs State and local governments, tribal governments, universities, and nonprofits are all covered on the same terms.

The obligation follows the money. A recipient gets funds directly from a federal agency; a subrecipient gets them indirectly through a pass-through entity to carry out part of a federal program. Both face the same audit rules once they cross the threshold. Pass-through entities carry the extra duty of monitoring their subrecipients, and that monitoring is itself a tested compliance area.

How the Supplement Is Laid Out

The Supplement is long, but the structure is predictable once you know where to look.1The White House. Compliance Supplement

  • Part 1 explains the Single Audit Act and the purpose of the guidance.
  • Part 2 is the Matrix of Compliance Requirements, a chart showing which categories apply to each federal program.
  • Part 3 gives the detailed description of each compliance category and how to test it. In the 2025 edition, Part 3.1 covers awards under the pre-October 2024 version of 2 CFR Part 200 and Part 3.2 covers awards under the revised regulations.
  • Part 4 has program-specific requirements, organized by awarding agency.
  • Part 5 lists clusters of related programs that are tested together as one program.
  • Part 6 addresses internal controls, referencing the GAO Green Book and the COSO framework.
  • Part 7 tells the auditor how to handle federal programs that are not specifically listed elsewhere.

The working sequence: find your program’s Assistance Listing Number, check the Part 2 matrix for the compliance categories that apply, then read the Part 3 category descriptions and any program-specific rules in Part 4. If your program is not in Part 4, Part 7 provides the fallback.

The Part 3.1 and 3.2 Split

OMB revised 2 CFR Part 200 with an October 1, 2024 effective date, and the 2025 Supplement runs two parallel tracks in Part 3. Older awards follow Part 3.1; awards under the revised rules follow Part 3.2.4Federal Audit Clearinghouse. 2025 Compliance Supplement Most fiscal 2025 and 2026 audits will use Part 3.2, but carryover awards from earlier periods can still fall under Part 3.1. Your auditor identifies which version governs each award.

What Auditors Test: The Compliance Categories

Part 3 organizes federal compliance into twelve active lettered categories. These are the areas an auditor tests to confirm that federal money was spent lawfully and for its intended purpose.4Federal Audit Clearinghouse. 2025 Compliance Supplement

  • A — Activities Allowed or Unallowed: whether funds went only to activities authorized by the grant.
  • B — Allowable Costs/Cost Principles: whether expenditures are reasonable, necessary, and properly documented under 2 CFR Part 200 Subpart E.5eCFR. 2 CFR Part 200 Subpart E – Cost Principles
  • C — Cash Management: whether the time between drawing federal funds and spending them was minimized.
  • E — Eligibility: whether the beneficiaries receiving program benefits actually meet the legal criteria.
  • F — Equipment and Real Property Management: whether items bought with federal funds are tracked, used for authorized purposes, and disposed of properly.
  • G — Matching, Level of Effort, Earmarking: whether any cost-sharing and spending-level requirements were met.
  • H — Period of Performance: whether funds were spent only within the authorized timeframe.
  • I — Procurement and Suspension and Debarment: whether purchasing rules were followed and contractors checked against the federal exclusion list.
  • J — Program Income: whether income generated by the program was handled correctly.
  • L — Reporting: whether required financial and performance reports were accurate and on time.
  • M — Subrecipient Monitoring: whether the organization adequately oversaw entities it passed funds to.
  • N — Special Tests and Provisions: program-specific requirements that do not fit the other categories.

Not every program is tested against every category. The Part 2 matrix identifies which apply, and the Supplement caps the number of compliance requirements subject to audit at six per program. The Research and Development cluster is the exception, with seven.4Federal Audit Clearinghouse. 2025 Compliance Supplement

Procurement and Debarment

Procurement testing is where organizations most often slip. The federal micro-purchase threshold is $15,000 and the simplified acquisition threshold is $350,000. Below the micro-purchase level, competitive bidding is generally not required. Between the two levels, you need price or rate quotations from an adequate number of sources. Above the simplified acquisition threshold, full competitive procedures apply. Auditors also confirm you checked each contractor against SAM.gov’s exclusion database before awarding a contract or subaward.6SAM.gov. Search – Exclusions

Indirect Costs and the De Minimis Rate

An organization without a federally negotiated indirect cost rate may charge a de minimis rate of up to 15 percent of modified total direct costs, raised from 10 percent as part of the 2024 revisions.7eCFR. 2 CFR 200.414 – Indirect Costs If you take the de minimis rate, apply it consistently across all your federal awards.

Which Programs Actually Get Tested

Not every federal program you run receives full compliance testing. Auditors use a risk-based process to designate certain programs as “major programs,” and those are the ones tested in depth. Programs are first separated into Type A (larger) and Type B (smaller) using a sliding threshold tied to your total federal spending.8eCFR. 2 CFR Part 200 Subpart F – Audit Requirements For an organization at the lower end, at $1 million to $34 million in total federal spending, any single program of $1 million or more is Type A. The threshold scales up from there.

After classifying, the auditor assesses risk. Type A programs recently audited without significant findings may be treated as low-risk. Type B programs that exceed 25 percent of the Type A threshold are evaluated for elevated risk. The result is that a representative set of programs, including any high-risk ones, receives full compliance testing each cycle.

What to Have Ready

Start by pulling the Assistance Listing Number for every federal award you manage, then cross-reference each number against the Part 2 matrix to see which compliance categories will be tested. Build your documentation around those categories.

At a minimum, keep organized and accessible:

  • Financial ledgers showing expenditures by federal program and cost category.
  • Procurement records, including bid documents, contracts, and SAM.gov exclusion checks.
  • Time-and-effort documentation for personnel charged to federal awards.
  • Eligibility files for programs that serve individuals or specific populations.
  • Subrecipient monitoring records if you pass funds through.

Every expenditure should trace back to an invoice, payroll record, or other supporting document. Gaps are the most common source of audit findings, and they are entirely preventable.

Selecting the Auditor

Federal rules require formal procurement of your audit firm. The request for proposals must state the audit’s objectives and scope, and you must obtain the firm’s peer review report.9eCFR. 2 CFR 200.509 – Auditor Selection An auditor who prepared your indirect cost proposal or cost allocation plan cannot perform the audit if your recovered indirect costs exceeded $1 million in the prior year.

Submitting the Results

When the audit is complete, the reporting package and the completed SF-SAC data collection form are uploaded to the Federal Audit Clearinghouse at fac.gov. The SF-SAC summarizes results and lists each federal program by Assistance Listing Number with total expenditures.10General Services Administration. Data Collection Form on Reporting for Single Audits

The deadline is the earlier of 30 calendar days after receiving the auditor’s report or nine months after the end of the audit period.11eCFR. 2 CFR 200.512 – Report Submission If the due date lands on a weekend or federal holiday, the next business day applies. Missing the deadline can get your organization flagged as high-risk for future cycles, which brings increased scrutiny and can lead to more restrictive grant conditions. Once accepted, the report becomes public and is distributed to all relevant federal agencies.

Corrective Action After Findings

When findings are identified, you must prepare a corrective action plan as a separate document from the auditor’s report. Each entry needs the finding’s reference number, the person responsible, the specific steps, and an anticipated completion date. If you disagree with a finding or believe no corrective action is needed, the plan must explain why in detail.12eCFR. 2 CFR 200.511 – Audit Findings Follow-Up

The responsible federal agency or pass-through entity then issues a management decision within six months of the Clearinghouse’s acceptance. That decision states whether the finding is sustained, explains the reasoning, and specifies what the organization must do, which can include repaying disallowed costs.8eCFR. 2 CFR Part 200 Subpart F – Audit Requirements Corrective action should begin when you receive the audit report, not when the management decision arrives.

What Noncompliance Costs

Audit findings are not just paperwork. When a federal agency determines that noncompliance cannot be resolved through specific award conditions, the available remedies include withholding payments until you take corrective action, disallowing costs so that funds must be repaid, suspending or terminating the award in whole or in part, initiating debarment proceedings that can bar the organization from all federal awards, and withholding future funding for the project or program.13eCFR. 2 CFR 200.339 – Remedies for Noncompliance

Auditors must report questioned costs when the known or likely amount exceeds $25,000 for a compliance requirement within a major program, and the same threshold applies to questioned costs in a non-major program.14eCFR. 2 CFR 200.516 – Audit Findings Questioned costs do not automatically become disallowed; the federal agency decides that in its management decision. Either way, resolving them takes time and money you would rather spend running the program.