SHARPECPA

Sharpe CPA  /  Government auditing  /  The federal single audit

The federal single audit: who needs one, and what it takes.

One audit that covers both the financial statements and the federal money. Three sets of standards sit on top of each other, the programs to test are chosen by formula, and the report goes to a federal clearinghouse on a deadline.

Use at your own risk. This free tool is provided as is, without warranty, and is not accounting, legal or tax advice. All of the work a CPA performs is subject to that person’s or firm’s judgment. Do your own research and verify that the checklist or protocol you are using is valid and up to date. Built from public sources — see the sources and the terms of use.

Who needs one

$1,000,000 of federal awards expended in the year.

The Single Audit Act and its regulations — 2 CFR Part 200, Subpart F, the audit part of the Uniform Guidance — require a state, local government, tribe, college or nonprofit that expends $1,000,000 or more in federal awards during its fiscal year to have a single audit for that year (§200.501). The threshold was $750,000 until the 2024 revision of the Uniform Guidance; $1,000,000 applies to fiscal years beginning on or after October 1, 2024.

What counts is money expended, not money awarded or received, and it counts whether it came straight from a federal agency or passed through a state or another entity on the way. Below the threshold no federal audit is required, but the records must still be available to the federal agency, the pass-through entity and the GAO.

What counts as expended (§200.502)

  • Grants and cooperative agreements — when the activity occurs: the expenditure, or the disbursement to a subrecipient.
  • Loans and loan guarantees — new loans made or received in the year, plus the opening balance of earlier loans that still carry compliance requirements, plus any interest subsidy or administrative allowance.
  • Noncash assistance — food commodities, donated property and the like, at fair value when received.
  • Not counted — payments received as a contractor for goods and services, and most Medicare and Medicaid payments for patient care.

Subrecipient or contractor (§200.331)

  • A subrecipient carries out part of the federal program: it decides who is eligible, is measured against the program’s objectives and must follow its rules. Its spending is federal awards expended.
  • A contractor sells goods or services in the ordinary course of business to many buyers. What it is paid is not.
  • The substance decides, not what the agreement is called. Getting this wrong is how an entity misses the threshold, or an auditor misses a program.
  • For-profit subrecipients are outside Subpart F; the pass-through entity sets what audit, if any, they must have.
The program-specific alternative. An entity that spends federal awards under only one program (other than research and development), and whose award does not require a financial statement audit, may elect a program-specific audit instead (§200.507).

The three standards

GAAS, then the Yellow Book, then the Uniform Guidance.

Each one adds to the one before. A single audit is performed under all three at once.

LayerIssued byWhat it adds
GAASAICPA Auditing Standards Board — the AU-C sections, with AU-C 935 for compliance audits The financial statement audit itself, and how the auditing standards apply to an audit of compliance.
GAGASThe Comptroller General (GAO) — Government Auditing Standards, the Yellow Book Stricter independence rules for nonaudit services, continuing education in government auditing, peer review, and a written report on internal control over financial reporting and on compliance.
Uniform GuidanceOffice of Management and Budget — 2 CFR 200 Subpart F, with the annual Compliance Supplement Choosing the major programs by risk, testing internal control over compliance and compliance for each, an opinion on compliance, the schedule of findings and questioned costs, and filing with the Federal Audit Clearinghouse.

What the Yellow Book asks of the auditor

  • Continuing education. 80 hours every two years, at least 24 of them directly on government auditing or the government environment, and at least 20 hours in each year.
  • Independence. Nonaudit services are tested against a conceptual framework. Preparing the client’s financial statements or accounting records is a significant threat that needs documented safeguards, and management must have someone with the skill, knowledge and experience to oversee it.
  • Peer review. An external peer review at least every three years; the report is available to the public.
  • Findings. Each one developed with its criteria, condition, cause and effect.

What the Uniform Guidance asks of the auditor (§200.514)

  • The financial statements — an opinion, and whether the schedule of expenditures of federal awards is fairly stated in relation to them.
  • Internal control over compliance — understand it for each major program and plan the testing to support a low assessed level of control risk. Where controls are ineffective, report it and skip the test.
  • Compliance — an opinion on whether each major program complied with the requirements that could have a direct and material effect on it.
  • Follow-up — on the prior year’s findings, and on whether management’s schedule of them is accurate.

The auditee’s part

What management has to produce.

The audit starts from documents that are management’s responsibility, not the auditor’s (§200.508). When the auditor prepares them, that is a nonaudit service under the Yellow Book and has to be treated as one.

DocumentSectionWhat it must contain
Financial statements§200.510(a)Financial position, results of operations or changes in net assets and, where appropriate, cash flows, for the same year as the audit.
SEFA§200.510(b)The schedule of expenditures of federal awards: every program by federal agency with its Assistance Listing number, clusters shown as clusters, the pass-through entity’s name and identifying number, the total expended for each program, the amount passed to subrecipients, loan balances outstanding at year end, and notes on the accounting policies and whether the de minimis indirect cost rate was used.
Prior findings§200.511(b)The summary schedule of prior audit findings: the status of every finding from the prior year — corrected, partly corrected with the reason, or no longer warranting action.
Corrective action plan§200.511(c)For each current finding: the person responsible, the action planned and the expected completion date, on the auditee’s own letterhead and separate from the auditor’s findings. A disagreement is explained here.

Major programs

Which programs get audited: four steps (§200.518).

The auditor does not choose. The regulation does, by size and then by risk, and the working has to be in the file.

Step 1 — Type A or Type B

  • Total the federal awards expended and look up the Type A threshold. A program at or above it is Type A; the rest are Type B.
  • A cluster of programs counts as one program.
  • Large loan programs can distort the threshold; the regulation has a rule for leaving them out of the calculation.

Step 2 — Low-risk Type A programs

  • A Type A program is low-risk only if it was audited as a major program in at least one of the two most recent years, and in the most recent audit had no material weakness in internal control over compliance, no modified opinion, and no known or likely questioned costs above 5% of the program.
  • Federal agency or pass-through oversight, and a program the Compliance Supplement names as higher risk, can also keep it from being low-risk.

Step 3 — High-risk Type B programs

  • Assess risk only for Type B programs larger than 25% of the Type A threshold.
  • The auditor need not identify more high-risk Type B programs than one-fourth of the number of low-risk Type A programs. With no low-risk Type A programs, this step is skipped.

Step 4 — The major programs, and coverage

  • Audit as major: every Type A program that is not low-risk, every high-risk Type B program, and enough more to meet the coverage rule.
  • Major programs must cover at least 40% of total federal awards expended — 20% if the auditee is a low-risk auditee.

The Type A threshold

Total federal awards expendedType A threshold
$1,000,000 to $34 million$1,000,000
Over $34 million to $100 million3% of total federal awards expended
Over $100 million to $1 billion$3 million
Over $1 billion to $10 billion0.3% of total federal awards expended
Over $10 billion to $20 billion$30 million
Over $20 billion0.15% of total federal awards expended
Low-risk auditee (§200.520). For each of the two preceding years: a single audit performed annually and filed with the clearinghouse on time; unmodified opinions on the financial statements and on the SEFA; no material weakness reported under the Yellow Book; no report of substantial doubt about going concern; and no Type A program with a material weakness in internal control over compliance, a modified opinion, or questioned costs above 5% of the program. Miss one and coverage goes to 40%. A first-year single audit is never low-risk.

Compliance testing

Twelve kinds of requirement, and the Compliance Supplement.

OMB’s Compliance Supplement (2 CFR 200, Appendix XI), issued each year, is the auditor’s program. Part 2 is a matrix showing which types of requirement are subject to audit for each federal program — generally no more than six for any one program. Part 3 gives the audit objectives and suggested procedures for each type, Parts 4 and 5 the program-specific requirements and clusters, and Part 6 internal control. For a program not in the Supplement, Part 7 tells the auditor how to work out the requirements from the award itself.

D and K are reserved: earlier requirements were removed and the letters were not reused.

For each requirement that is direct and material to a major program: identify the controls, test them to support a low assessed level of control risk, then test compliance itself. Both have to be documented, and the control testing is what peer reviewers and federal quality reviews most often find missing.

Findings

What has to be reported (§200.516).

Report as a finding

  • Significant deficiencies and material weaknesses in internal control over a major program.
  • Material noncompliance with federal statutes, regulations or the terms of an award, for a major program.
  • Known questioned costs when known or likely questioned costs exceed $25,000 for a type of compliance requirement in a major program — and known questioned costs above $25,000 in a program that is not major, if the auditor comes across them.
  • Why the opinion on a major program is modified, unless another finding already says so.
  • Known or likely fraud affecting a federal award, unless already reported.
  • A summary schedule of prior findings that misstates the status of a prior finding.

What each finding must say

  • The program — Assistance Listing number and title, award number and year, federal agency and any pass-through entity.
  • Criteria — the statute, regulation or award term.
  • Condition — what was found.
  • Cause, and effect or potential effect.
  • Questioned costs and how they were computed.
  • Context — the sample and the population, in number and dollars, and whether the sample was statistical.
  • Whether it repeats a prior finding, with the prior reference number.
  • A recommendation, and the views of responsible officials.
  • A reference number in the form 2026-001.

Reporting

The reports, the package and the deadline.

From the auditor (§200.515)What it says
Report on the financial statementsThe opinion, and an opinion on whether the SEFA is fairly stated in relation to the financial statements as a whole.
Yellow Book reportInternal control over financial reporting, and compliance and other matters, based on the financial statement audit. No opinion on either.
Uniform Guidance reportAn opinion on compliance for each major program, and a report on internal control over compliance.
Schedule of findings and questioned costsThree sections: a summary of the auditor’s results (the opinions, the major programs, the Type A threshold, whether the auditee was low-risk); financial statement findings; and federal award findings and questioned costs.

The reporting package (§200.512)

  • The financial statements and the SEFA.
  • The auditor’s reports and the schedule of findings and questioned costs.
  • The summary schedule of prior audit findings.
  • The corrective action plan.
  • With it, the data collection form (Form SF-SAC), certified by both the auditee and the auditor.

Where and when

  • Where: the Federal Audit Clearinghouse, online at fac.gov. Filings are public.
  • When: within 30 calendar days after the auditee receives the auditor’s report, or nine months after the end of the audit period, whichever is earlier. A June 30 year end is due March 31.
  • Late filing costs the auditee its low-risk status for the next two years.
  • Keep the file: audit documentation is retained at least three years from the date the report is issued (§200.517); your state board and the AICPA standards may require longer.
  • Who oversees: an auditee expending more than $50 million a year has a cognizant agency for audit; everyone else has an oversight agency, the one providing the most direct funding (§200.513).

What is changing

As of October 2026.

In effect now

  • The $1,000,000 threshold and the $1,000,000 Type A floor: fiscal years beginning on or after October 1, 2024. A June 30, 2026 or December 31, 2025 year end is under the new amounts.
  • The 2024 Yellow Book: effective for financial audits of periods beginning on or after December 15, 2025. Its main change is quality management in place of quality control — the firm’s system had to be designed and implemented by December 15, 2025, and its first evaluation is due by December 15, 2026.
  • The 2025 Compliance Supplement, released December 4, 2025, for audits of fiscal years beginning after June 30, 2024. Part 3 is split in two, because agencies adopted the 2024 Uniform Guidance at different times; check which version each award is under.

Watch for

  • The 2026 Compliance Supplement, for fiscal years beginning after June 30, 2025, had not been issued as of mid-September 2026. Planning and the financial statement work can proceed; the compliance work on major programs cannot be finished without it.
  • A proposed revision of the Uniform Guidance was published May 29, 2026. As proposed it leaves the $1,000,000 threshold and the Type A table alone and is aimed mostly at how agencies administer grants. It is proposed, not final — check the Federal Register before relying on either version.
  • Higher-risk programs named in the Supplement change from year to year, and change the major program determination with them.

Tips

Where single audits go wrong.

Before accepting

  • Count the hours first. Every person who plans, directs, performs or reports on the audit needs the Yellow Book continuing education. One missing person is a peer review finding.
  • Decide who prepares the statements and the SEFA. If it is you, document the threat, the safeguards, and who at the client has the skill to take responsibility for them.
  • Ask how many programs, not how many dollars. A small entity with five programs is more work than a large one with a single grant.
  • Read the grant agreements. A pass-through entity can add requirements the Supplement does not list.

During the audit

  • Test the SEFA for completeness. Compare it with the general ledger, the board minutes, the drawdown records and last year. A program left off is a program not considered for major.
  • Document the major program determination every year, including why each Type A program is or is not low-risk.
  • Controls and compliance are two tests. A sample showing the costs were allowable does not show that anyone approved them.
  • Use the right Supplement for the fiscal year, and the right version of the Uniform Guidance for each award.
  • File on time. The nine months is the auditee’s deadline, but a late filing follows the auditor around too.

A summary for convenience, not a substitute for the regulations, the Yellow Book or the Compliance Supplement. Thresholds and dates are as of October 2026; check the current text before relying on it.