A Single Audit is required when your organization expends federal awards during a fiscal year above the updated federal threshold effective for fiscal years beginning on or after October 1, 2024. If you’re anywhere near that line, your first moves are simple: draft or verify your Schedule of Expenditures of Federal Awards (SEFA), confirm which spending categories count toward the threshold, and get your auditor on the calendar now. The Federal Audit Clearinghouse (FAC) submission deadline is the earlier of 30 calendar days after you receive your auditor’s report or 9 months after the end of your fiscal year.
TL;DR:
- Organizations that will spend $1 million or more in federal awards during the year must conduct a Single Audit, based on expended funds including subrecipient payments and noncash assistance.
- The single, annual audit includes both a financial statement review and testing of compliance with federal program rules, focusing on internal controls and legal adherence.
- Accurate preparation and monthly reconciliation of the Schedule of Expenditures of Federal Awards (SEFA) can prevent common errors that cause audit findings and delays.
- Audit testing focuses on major programs exceeding specific expenditure thresholds and assesses risk factors like prior findings and program complexity to determine sample scope.
- Even organizations below the threshold or pass-through entities still have monitoring obligations and can be required to submit or review audits or reports at their discretion.
Table of Contents
ToggleUnderstanding Single Audit Requirements: The Legal Basis
Single Audit requirements trace back to the Single Audit Act, implemented today through 2 CFR Part 200 Subpart F of the OMB Uniform Guidance. This isn’t a voluntary best practice or a donor request. It’s a federal mandate that applies uniformly to states, local governments, Indian tribes, and nonprofit organizations that spend federal money above the threshold, regardless of which agency issued the award.
The regulation exists because federal grant dollars flow through thousands of organizations with wildly different accounting systems, internal controls, and financial sophistication. Rather than have every federal agency run its own audit program for every grantee, Congress created a single, unified audit that satisfies all federal awarding agencies at once. One audit, one report, distributed to every agency that gave you money.
A Single Audit actually has two distinct components bundled into one engagement:
- Financial statement audit: your auditor examines your organization’s overall financial statements and issues an opinion on whether they fairly represent your financial position, following generally accepted auditing standards.
- Compliance audit: your auditor tests whether you followed the specific rules attached to each major federal program, covering everything from how you spent the money to how you reported on it.
The auditor’s job isn’t just to check math. Per HHS OIG guidance, the objective is reasonable assurance that your internal controls are functioning and that you complied with the laws, regulations, and award terms governing each program. That distinction trips up a lot of first-time auditees who assume a clean set of books guarantees a clean audit. It doesn’t. An organization can have flawless accounting and still generate findings if procurement files are incomplete or subrecipient monitoring never happened.
Who Must Have a Single Audit? Threshold and Special Cases
The math is more nuanced than “did we receive $1,000,000 in grants.” The threshold is based on federal awards expended, not awarded, received, or budgeted. Under 2 CFR §200.502, “expended” is a specific accounting concept that includes:
- Direct disbursements of federal cash to cover program costs
- Federal program income you used during the year
- Payments made to subrecipients out of federal funds you passed through
- The fair value of noncash federal assistance, such as donated property, food commodities, or insurance
- Certain loan and loan guarantee activity, including new loans made during the audit period
An organization that drew down $600,000 in direct grant funds but also passed $500,000 to subrecipients has expended $1,100,000 for threshold purposes, even though only part of that money ever touched its own bank account. This is the single most common miscalculation finance officers make when self-assessing whether they cross the line.
The threshold jumped from $750,000 to $1,000,000 for fiscal years beginning on or after October 1, 2024, meaning many organizations that needed a Single Audit under the old rule may now fall below it. Do not assume last year’s obligation carries forward automatically.
Program-specific audits offer a narrower, often cheaper alternative, but only under specific conditions. Per NIH’s grants policy guidance, an entity may elect a program-specific audit only when it expended federal awards under a single federal program, excluding research and development clusters, and isn’t otherwise required to have an entity-wide financial statement audit. If you have two or more federal funding streams, you’re locked into a full Single Audit even if the total barely clears $1 million.
Falling under the threshold doesn’t grant blanket immunity from oversight, either. Pass-through entities retain the right to require an audit of a subrecipient regardless of dollar amount, as part of their own subrecipient monitoring obligations under the Uniform Guidance. A state agency passing federal funds to a small nonprofit can contractually require financial reporting or a limited-scope audit even when that nonprofit spends nowhere near $1 million in federal awards for the year.

SEFA and the Reporting Package: What You Must Prepare
Your SEFA is the single most important document you control in this entire process, and it’s entirely your responsibility, not your auditor’s. Auditors test the SEFA; they don’t build it for you.
A complete SEFA must include, at minimum:
- Every federal program you received funding from, listed with its Assistance Listing Number (ALN, formerly called the CFDA number)
- The name of the pass-through entity and any identifying award number, for funds you received indirectly rather than directly from a federal agency
- Total federal awards expended for each individual program, broken out by ALN
- Amounts passed through to subrecipients, shown separately from what you spent directly
- Notes disclosing your indirect cost rate election, whether that’s a negotiated rate or the 10% de minimis rate
Beyond the SEFA itself, the full reporting package your auditor submits to the FAC includes the audited financial statements, the schedule of findings and questioned costs, the auditor’s reports on internal control and compliance, and a corrective action plan if any findings turned up. Auditors compare your SEFA against underlying accounting records, grant agreements, and drawdown reports, looking for programs left off entirely, ALNs that don’t match award documents, and subrecipient amounts that don’t reconcile to what those subrecipients separately reported.
The most common SEFA mistakes are surprisingly mundane: omitting a small grant because someone assumed it was “too small to matter,” misclassifying a subaward as a vendor payment (which changes your monitoring obligations), and using budget figures instead of actual expenditures. None of these are exotic errors. They’re the product of building the SEFA in a rush during fieldwork instead of maintaining it throughout the year.
Pro Tip: Reconcile your SEFA to your general ledger every month, not just at year-end. A quarterly mismatch is a ten-minute fix. A mismatch discovered during fieldwork can cost days of auditor time and turn into a finding.
How Auditors Pick Which Programs to Test
Not every federal program you run gets tested in a given year. Auditors use a two-tier system, Type A and Type B programs, to decide where to focus.
Type A programs are your larger federal programs, defined by a sliding dollar threshold that scales with your total federal expenditures. For most auditees, any program with expenditures exceeding a set floor (roughly $750,000 for organizations spending between $1 million and $25 million total, with different breakpoints as total spending grows) counts as Type A. Everything below that line is Type B. This scaling matters because a $2 million organization and a $50 million organization are held to very different dollar thresholds for what counts as “major.”
From there, the auditor runs a risk assessment. Type A programs aren’t automatically tested every single year; instead, the auditor considers factors like:
- Prior audit findings on that program
- Whether the program has new leadership, new staff, or a new accounting system since the last audit
- Complexity of compliance requirements for that specific program
- Oversight exercised by the federal agency or pass-through entity
Type B programs are generally lower risk by default unless something specific flags them, such as a prior finding or an unusually large increase in spending year over year.
The coverage requirement is where the rubber meets the road. That difference is significant in practice: a low-risk history can mean the difference between two major programs tested and five, which translates directly into fewer fieldwork days and lower audit fees.
Compliance Areas Auditors Test and Common Findings
The OMB Compliance Supplement updates annually and tells auditors exactly which compliance requirements apply to each federal program. For nonprofit auditees, the areas that come up again and again include:
- Allowability of costs: were expenditures charged to the grant actually permitted under the award terms and cost principles?
- Procurement standards: did you follow required competition and documentation rules when buying goods or services with federal funds?
- Period of performance: were costs incurred within the grant’s approved start and end dates?
- Subrecipient monitoring: did you assess subrecipient risk, monitor their spending, and follow up on their own audit findings?
- Reporting: were required federal financial reports and performance reports filed accurately and on time?
- Cash management: did you draw down federal funds only as needed for immediate disbursement, rather than sitting on advances?
The most frequent findings across nonprofit Single Audits tend to cluster around procurement documentation gaps (missing quotes, no documented cost analysis for sole-source purchases) and thin subrecipient monitoring (no risk assessment on file, no evidence anyone reviewed subrecipient reports before payment). Questioned costs often surface when unallowable expenses exceed relatively modest amounts. Even a $25,000 pattern of misclassified costs across a program can trigger a reportable finding, not just a passing note in the management letter.
Every finding requires a corrective action plan (CAP); nonprofits seeking to strengthen their compliance and operational readiness may benefit from specialized marketing for nonprofits and foundations to boost their outreach and support efforts. A defensible CAP names the specific control that failed, describes the corrective steps in concrete terms (not “we will be more careful”), assigns a responsible staff member, and sets a completion date. Auditors and pass-through entities read CAPs closely in the following year’s audit; a repeat finding with the same root cause as last year is a red flag that draws more scrutiny, not less.
Choosing and Working With an Auditor: Requirements and Best Practices
Not every CPA firm can perform a Single Audit. Auditors must follow Generally Accepted Government Auditing Standards (GAGAS), commonly called the Yellow Book, which layer additional independence and continuing education requirements on top of standard auditing rules. Firms performing government audits also undergo mandatory peer review every three years, and you’re entitled to ask to see that peer review report before you sign an engagement letter.
When procuring audit services, nonprofits subject to the Uniform Guidance must follow their own documented procurement policy and generally can’t simply rehire the same firm indefinitely without at least periodically soliciting proposals, depending on your organization’s procurement thresholds and policies.
A well-structured engagement letter should specify:
- The exact scope: financial statement audit, compliance audit, or both
- Which fiscal year and which federal programs are anticipated to be tested as major
- Timeline commitments, including a target date for fieldwork and a firm date for report delivery ahead of your FAC deadline
- Communication protocol for findings as they’re identified, rather than surprises at the exit conference
Pro Tip: Ask your auditor for a fieldwork document request list at least 60 days before fieldwork starts, not the week before. Reviewing it early lets you flag missing items while there’s still time to locate them.
Organizations considering their financial statement audit needs alongside their federal compliance obligations often find it more efficient to coordinate both engagements with the same firm, since much of the underlying documentation overlaps.
Timeline and FAC Submission Mechanics
The submission deadline is fixed by regulation: the earlier of 30 calendar days after you receive your auditor’s report, or nine months after the end of your audit period. There’s no extension mechanism built into the standard rule, so the entire audit timeline has to be planned backward from that date.
Here’s how that plays out for common fiscal year-ends:
- Calendar year-end (December 31): your reporting package is due no later than September 30 of the following year, though if your auditor finishes early, the 30-day clock could bind first.
- June 30 year-end: your deadline lands March 31 of the following year, a common cycle for many state-funded nonprofits and school-affiliated organizations.
- September 30 year-end: your deadline falls June 30 of the following year, aligning closely with the federal fiscal year itself.
Submission happens electronically through Fac, which has served as the government-wide repository for Single Audit reporting packages since the function moved from the Census Bureau. Your auditor typically handles the technical upload of Form SF-SAC and the reporting package, but management certifies the data submitted, so someone on your finance team should review it before it’s finalized. If you hit a technical snag or need to correct a submission, Support walks through resubmission steps and offers direct support contact.
Missing the deadline has real consequences of an awkward email. Federal agencies and pass-through entities also see submission status in the FAC system, and a pattern of late filings can factor into future award and monitoring decisions.
Practical Preparation Checklist and Suggested Calendar
Audit readiness isn’t a fourth-quarter scramble. It’s a habit built across the fiscal year, and the organizations that treat it that way consistently have shorter fieldwork and fewer findings.
60 to 90 days before year-end close:
- Draft your SEFA using year-to-date actuals and reconcile it against the general ledger.
- Inventory every active federal grant and subaward, confirming ALNs and pass-through entity details are current.
- Complete or update subrecipient risk assessments for anyone you passed federal funds to during the year.
At year-end close:
- Finalize the SEFA, including noncash assistance and any loan or loan guarantee activity.
- Compile procurement documentation and payroll backup for federally funded positions and purchases.
- Reconcile program income and any federally funded equipment purchases against your fixed asset records.
During fieldwork:
- Designate a single point of contact to field auditor requests, rather than routing questions to whoever happens to answer the phone.
- Build an indexed document package organized by request number, so auditors aren’t hunting for files.
- Set an internal turnaround target, such as 48 hours, for responding to information requests to keep fieldwork on schedule.
After the audit:
- Draft the corrective action plan for any findings within days of the exit conference, while details are fresh.
- Present results and any findings to your board or audit committee before the FAC deadline.
- Confirm the FAC submission cleared successfully and file the confirmation for your records.
Pro Tip: Build subrecipient monitoring into your grant accounting workflow from the start, using tools like a grant tracking spreadsheet or dedicated fund-accounting software, rather than treating it as a year-end catch-up project. Solid grant accounting setup from the beginning of the fiscal year prevents most of the reconciliation headaches that surface during fieldwork.
Parr & Ibarra CPA: A Practitioner’s Playbook for Audit Readiness
Parr & Ibarra CPA works with Dallas-Fort Worth nonprofits and government grant recipients on the full arc of Single Audit readiness, from compliance audits and SEFA preparation through outsourced CFO advisory support once findings need remediation. The firm’s approach centers on catching problems months before fieldwork, not during it.
In practice, that looks like:
- Monthly SEFA reconciliations tied directly to the general ledger close, so the schedule is never rebuilt from scratch under deadline pressure
- Procurement-file checklists that flag missing documentation, such as competitive quotes or sole-source justifications, as purchases happen rather than a year later
- Subrecipient monitoring templates that standardize risk scoring and follow-up documentation across every subaward, so nothing depends on one staff member’s memory
- Board-ready summary formats that translate audit findings and corrective action plans into language a nonprofit board can act on, not just file away
For organizations that have outgrown a bookkeeper-only setup but aren’t ready for a full-time CFO, this kind of structured support closes the gap between “we filed our audit” and “we understood what our audit found and fixed it.” The firm’s broader team of CPAs brings the same proactive planning philosophy to tax and advisory work that it applies to compliance, treating the Single Audit as one piece of an organization’s overall financial health rather than an isolated annual event.
What the New $1 Million Threshold Really Means for Small Nonprofits
The jump from $750,000 to $1,000,000 sounds like relief, and for organizations sitting right at the old line, it genuinely is. Some nonprofits that scraped past $750,000 will now sit comfortably under the new mark and avoid a Single Audit entirely this cycle. Related Uniform Guidance updates, including changes to the de minimis indirect cost rate and equipment capitalization thresholds, add up to a real compliance-burden reduction for smaller grant recipients.
But treating a higher threshold as permission to relax internal controls misses the point entirely. Pass-through entities still require monitoring regardless of your audit obligation, and boards still bear fiduciary responsibility for federal funds whether or not a Single Audit report exists to catch a problem. The organizations that come out ahead here aren’t the ones celebrating a threshold they no longer have to hit. They’re the ones that keep building SEFA discipline and procurement documentation as standard practice, so that if grant volume grows and they cross $1 million next year, or a pass-through entity asks hard questions this year, nothing catches them flat-footed.
— Adan
Get Single Audit Ready With Parr & Ibarra CPA
Instead of scrambling to rebuild your SEFA and procurement files the month before fieldwork, The firm builds those records into your accounting cycle year-round, so audit season stops being an emergency. Its compliance audit and CFO advisory teams work directly with nonprofits and grant recipients on SEFA preparation, subrecipient monitoring systems, and corrective action plans that hold up to board and pass-through entity review. That means fewer surprises during fieldwork and a clearer picture of your financial health the rest of the year, not just at audit time. If your organization is approaching the $1 million threshold, already past it, or simply tired of last-minute audit prep, connect with the team about tax planning and advisory services built for organizations juggling federal compliance alongside everyday financial management, and get a plan in place before your next fiscal year-end.
Sources
- eCFR: 2 CFR Part 200 Subpart F — Audit requirements
- Federal Audit Clearinghouse (FAC)
- NIH Grants Policy — Program-specific audit guidance
- HHS OIG — Single Audits FAQs and guidance
FAQ
What is the Single Audit threshold for 2026?
The threshold is 1,000,000 dollars in federal awards expended per fiscal year, applicable to fiscal years beginning on or after October 1, 2024, under 2 CFR Part 200 Subpart F.
What is the threshold amount for a Single Audit?
An organization needs a Single Audit once it expends 1,000,000 dollars or more in federal awards in a single fiscal year, counting direct disbursements, subrecipient payments, program income, and noncash federal assistance.
When did the Single Audit threshold change to $1 million?
The threshold jumped from 750,000 dollars to 1,000,000 dollars for fiscal years beginning on or after October 1, 2024, as part of broader Uniform Guidance updates from the OMB.
What are the requirements for a 2 CFR 200 Single Audit?
A Single Audit under 2 CFR Part 200 requires an entity-wide financial statement audit, compliance testing of major federal programs, a completed SEFA, and submission of the reporting package and Form SF-SAC to the FAC within nine months of fiscal year-end or 30 days after receiving the auditor’s report, whichever comes first.
Does Parr & Ibarra CPA prepare organizations for Single Audits?
Yes, Parr & Ibarra CPA supports Dallas-Fort Worth nonprofits and grant recipients with SEFA preparation, compliance audit readiness, and corrective action plan development ahead of Single Audit season.

