The Single Audit: Crossing $1 Million in Federal Awards and What Follows
Receiving a substantial federal award can allow a nonprofit to expand programs, serve more people, hire staff, and invest in essential resources. It also introduces a more demanding compliance environment. Once annual federal award expenditures reach the applicable threshold, an ordinary financial statement audit may no longer be enough. The organisation may become subject to a Single Audit under the federal Uniform Guidance.
The current federal threshold is $1 million in federal awards expended during the organisation’s fiscal year. It was increased from $750,000 as part of the 2024 revisions to the Uniform Guidance, with a government-wide effective date of October 1, 2024. Because implementation can depend on the federal agency, award date, and applicable terms, a nonprofit near the transition should confirm which requirements govern its awards with its awarding agencies, pass-through entities, and an auditor experienced in federal programs.
Crossing the threshold does not simply add another report to the year-end process. It affects accounting records, internal controls, compliance documentation, board oversight, auditor selection, and the way federal expenditures are tracked throughout the year. Preparing early can turn the audit into a manageable compliance process rather than an expensive last-minute emergency.
What Is a Single Audit?
A Single Audit is an organisation-wide examination required under the Single Audit Act and Title 2 of the Code of Federal Regulations, Part 200, Subpart F. It combines an audit of the organisation’s financial statements with testing of federal awards and the compliance requirements that apply to selected major programs. The process is intended to give federal agencies and pass-through entities assurance that federal funds are being managed properly.
The term “single” can be misleading. It does not mean that an auditor performs only one simple test or reviews only one grant. The engagement includes several connected areas of work. The auditor considers the financial statements, the Schedule of Expenditures of Federal Awards, internal control over financial reporting, internal control over major federal programs, and compliance with requirements that could have a direct and material effect on those programs.
A Single Audit also does not replace every other monitoring activity. Federal agencies and pass-through entities may still conduct reviews, request records, perform site visits, or examine specific costs. Award terms may impose additional audit or reporting requirements. The Single Audit creates a standard government-wide framework, but the nonprofit remains responsible for complying with every applicable award condition.
Understanding the $1 Million Single Audit Threshold
Under the current Uniform Guidance, a nonfederal entity that expends $1 million or more in federal awards during its fiscal year generally must obtain a Single Audit or, in limited circumstances, a program-specific audit. An organisation that expends less than $1 million is normally exempt from the federal audit requirement for that year, although its records must remain available for review or audit by appropriate government and pass-through officials.
The single audit threshold nonprofit leaders must monitor is based on expenditures, not simply the face value of awards received. A nonprofit might sign grant agreements with a total potential value of $2 million but expend only $700,000 during its fiscal year. Another organisation might receive several smaller awards across different programs and expend a combined total of more than $1 million. The second organisation could cross the threshold even though no individual award reaches $1 million.
The fiscal year is also important. Expenditures are measured for the period covered by the nonprofit’s financial statements, not automatically by the federal fiscal year or each grant’s period of performance. A nonprofit with a June 30 year-end must examine federal expenditures recorded during its own July through June reporting period.
For this reason, management should not wait until the year-end close to ask whether the organisation is approaching the threshold. A rolling federal award expenditure report can make the situation much clearer. Finance staff can review the total monthly or quarterly and flag an approaching threshold early enough to plan for the additional audit work.
Awards Received and Awards Expended Are Not the Same
Nonprofits sometimes assume that the requirement begins when federal cash deposits exceed $1 million. Cash received, revenue recognised, award value, and federal expenditures are related but different figures. The Uniform Guidance contains rules for determining when federal awards are considered expended, and those rules can vary according to the type of assistance and transaction.
For many cost-reimbursement grants, expenditures generally follow the activity related to the federal award, including allowable costs incurred. Other forms of assistance can require different treatment. Federal loans, loan guarantees, insurance, donated property, food commodities, interest subsidies, and endowment funds may not be counted in the same way as an ordinary grant. Loan programs can be especially complex because continuing compliance requirements may affect the amount reported after the original proceeds are received.
The accounting team should identify every source of federal assistance and determine the correct treatment before calculating the total. Relying only on the general ledger’s grant revenue accounts can omit federal awards passed through state or local governments, universities, foundations, or other nonprofits. It can also include items that should not be counted in the same manner.
Direct Awards and Pass-Through Funding Both Count
Federal funding does not need to arrive directly from a federal agency to count toward the threshold. A nonprofit may be a direct recipient, a subrecipient, or both. If a state agency receives a federal grant and issues a subaward to the nonprofit, the nonprofit’s eligible expenditures under that subaward are generally federal expenditures for Single Audit purposes.
This is why award identification at the beginning of a relationship is essential. Agreements should state whether the organisation is acting as a subrecipient or a contractor. A subrecipient carries out part of a federal program and is subject to federal program requirements. A contractor normally provides goods or services for the recipient’s own use in a procurement relationship. The substance of the arrangement matters, not only the label placed on the agreement.
Pass-through entities are required to communicate specific information about a federal subaward, including identifying details needed for reporting. If an agreement is unclear, the nonprofit should ask for clarification promptly. Waiting until the audit begins can lead to an incomplete expenditure schedule, an incorrect threshold calculation, or unanticipated compliance testing.
A central award register can make this process much easier. It should ideally identify the federal agency, pass-through entity, award number, Assistance Listings number when applicable, period of performance, responsible program staff, and accounting codes used for the award. Keeping this information together reduces the need to search through individual grant agreements when the SEFA or audit preparation begins.
What Happens When the Threshold Is Crossed?
Once the organisation determines that it has expended at least $1 million in applicable federal awards during the fiscal year, management must arrange for the required audit. The nonprofit, not the federal agency or its regular accountant, is responsible for determining whether the requirement applies and ensuring that the work is completed correctly and on time.
The organisation must engage a qualified auditor, prepare its financial statements, complete the Schedule of Expenditures of Federal Awards, provide access to records, and respond to audit findings. It must also prepare a summary schedule addressing prior audit findings and, when current findings exist, a corrective action plan. After completion, the required reporting package and data collection information must be submitted electronically to the Federal Audit Clearinghouse.
The audit should be planned well before year-end. Firms with strong Single Audit experience may have limited availability, particularly during common nonprofit reporting periods. A late search can result in higher costs, scheduling problems, or the selection of an auditor that lacks sufficient experience with the organisation’s federal programs.
A Single Audit Is Different From a Financial Statement Audit
A standard financial statement audit is primarily designed to provide an opinion on whether the financial statements are presented fairly, in all material respects, under the applicable accounting framework. It includes consideration of internal control for planning purposes, but it does not normally provide the detailed federal compliance testing required by a Single Audit.
A Single Audit includes the financial statement audit and additional work performed under the Uniform Guidance and Government Auditing Standards, commonly known as the Yellow Book. The auditor determines which federal programs will be treated as major programs and tests compliance requirements that could have a direct and material effect on those programs.
This difference usually means more documentation requests, employee interviews, transaction testing, and review of policies. The auditor may examine eligibility decisions, payroll allocations, procurement, reporting, subrecipient monitoring, equipment records, matching contributions, program income, cash management, and other requirements relevant to the selected programs. The exact testing depends on the awards and the current OMB Compliance Supplement.
The Schedule of Expenditures of Federal Awards
The Schedule of Expenditures of Federal Awards, usually called the SEFA, is one of management’s central responsibilities. It identifies the federal awards expended during the period covered by the financial statements. The schedule allows auditors, agencies, and pass-through entities to understand the organisation’s federal funding and determine which programs may require audit attention.
A properly prepared SEFA generally includes the federal agency, pass-through entity when applicable, program title, Assistance Listings number, identifying award information, and the amount expended. It must also disclose the total amount provided to subrecipients from each federal program. Certain arrangements, such as federal loans and noncash assistance, can require additional information or special presentation.
The SEFA should be built throughout the year rather than reconstructed after closing the books. Each new award should be entered into a central register and connected to the appropriate general ledger activity. Finance staff should regularly reconcile the schedule with grant records, reimbursement requests, revenue accounts, and expenses. This process also gives management an early warning when expenditures are approaching the single audit threshold nonprofit organisations must monitor.
Another useful step is to assign ownership. Someone in the finance function should be responsible for maintaining the SEFA, while program and grant staff should be responsible for providing information about new awards, amendments, subawards, and changes in funding. A simple monthly review can catch missing awards or coding problems before they become year-end issues.
Major Programs and Risk-Based Selection
The auditor does not necessarily test every federal program as a major program. The Uniform Guidance establishes a risk-based process for selecting programs. The calculation considers the size of the organisation’s federal expenditures, the size of individual programs, prior audit history, oversight activity, the nature of the program, and other risk factors.
Programs are initially separated into larger and smaller categories using formulas found in the Uniform Guidance. The auditor then evaluates risk and selects major programs that provide the required level of audit coverage. A program that represents a large share of federal expenditures is more likely to receive attention, but size is not the only issue. A smaller program with significant control weaknesses or a history of noncompliance may also present risk.
Management should not try to predict the final audit scope and prepare only the programs it expects the auditor to select. Records and internal controls should support every award. The auditor retains responsibility for major-program selection and may need to adjust the plan as information becomes available.
Internal Controls Become a Central Focus
Federal recipients and subrecipients must establish, document, and maintain effective internal control over federal awards. The controls should provide reasonable assurance that awards are managed in compliance with federal statutes, regulations, and award terms. This responsibility exists before the organisation crosses the audit threshold, but the Single Audit subjects relevant controls to closer examination.
Good controls connect written policy with actual practice. A procurement policy has limited value if staff members consistently make purchases without obtaining required quotes or documenting contractor selection. A timekeeping policy is not effective when employees charge federal programs based on budgets rather than the work actually performed. Auditors may interview employees and trace transactions to determine whether stated procedures are operating consistently.
Smaller nonprofits may find segregation of duties difficult because one person handles several accounting functions. The answer is not to ignore the risk. Management can use review and approval controls, board oversight, restricted system access, reconciliations, and documented supervisory review to reduce it. The controls should match the organisation’s size, structure, programs, and level of risk.
It is also worth documenting who performs each control. A control that exists only because “someone in accounting checks it” can be difficult to demonstrate during an audit. Identifying the responsible person, frequency, supporting evidence, and reviewer makes the process easier to follow and easier to test.
Cost Allowability Requires More Than a Receipt
A cost charged to a federal award generally must be necessary, reasonable, allocable, consistently treated, properly documented, and permitted under the Uniform Guidance and award terms. A receipt establishes that money was spent, but it does not by itself prove that the expense belongs to a particular federal program.
The nonprofit should be able to explain why the cost supported the award, how it was allocated when it benefited more than one activity, who approved it, and whether it complied with organisational policy. Expenses that receive special treatment under federal cost principles may require additional review. Award-specific restrictions can be stricter than general federal rules.
Payroll is frequently significant because employee time can account for a large share of program costs. Compensation records must accurately support the work performed. Estimates can be used for certain interim accounting purposes when properly controlled and later adjusted, but a budget alone is not sufficient support for final charges. Consistent timekeeping and review procedures can prevent large corrections during the audit.
Procurement and Subrecipient Monitoring Need Attention
When federal funds are used to purchase goods and services, the nonprofit must follow applicable procurement standards as well as its own documented policies. Records should show the purchasing method, competition or justification, bids or quotations received, contractor selection, cost or price considerations when required, conflicts checks, and required contract provisions.
Subawards create a separate responsibility. A nonprofit that passes federal funds to another organisation must evaluate subrecipient risk, communicate award information, monitor performance and compliance, review reports, follow up on deficiencies, and confirm that required audits are completed. Paying a subrecipient’s invoice does not complete the monitoring obligation.
Confusing contractors with subrecipients can affect the SEFA, contract terms, monitoring, and reporting. Management should make and document each determination when the relationship begins. The analysis should consider the substance of the work and the other party’s responsibility for programmatic decisions rather than relying on the agreement’s title.
Selecting an Auditor With the Right Experience
Single Audits involve specialised standards and should be performed by auditors with appropriate qualifications and experience. Nonprofits should ask potential firms about recent Single Audit engagements, relevant federal programs, Yellow Book requirements, continuing professional education, peer review, staffing, timing, and their approach to communication.
Price matters, but selecting solely on the lowest fee can create risk. An incomplete or poor-quality audit may be rejected or questioned, requiring additional work and expense. The engagement should clearly describe the expected reports, responsibilities, timeline, access to specialists, and assistance management must provide.
Auditor independence must also be considered. A nonprofit may want the auditor to create the SEFA, design controls, correct accounting records, and then audit the same work. Some assistance may be permitted when proper safeguards exist and management retains responsibility, but the auditor cannot take over management’s role. These issues should be discussed before the engagement begins.
Preparing Before the Fiscal Year Closes
Preparation is easier when it is divided across the year. Finance staff should maintain an award register, reconcile federal expenditures, review budgets against actual costs, monitor subrecipients, update equipment records, and collect support for procurement decisions. Program managers should understand which activities are federally funded and what documentation the finance team needs.
Before year-end, management can perform an internal review of higher-risk areas. It should examine unusual journal entries, payroll allocations, late reports, budget overruns, questioned vendor selections, unsupported matching contributions, and expenses near the award’s start or end date. Errors discovered internally can often be corrected and explained more effectively than errors first identified by the auditor.
The board or audit committee should receive an early estimate of the organisation’s federal expenditures and expected audit requirement. This allows time to approve the auditor, understand the cost, monitor progress, and discuss significant issues without delaying submission.
A simple audit-readiness checklist can also help. Before the audit begins, management can confirm that:
- Federal award information is complete and current.
- Federal expenditures reconcile to the accounting records.
- The SEFA has been reviewed internally.
- Procurement files contain required support.
- Payroll allocations and time records are available.
- Subrecipient monitoring documentation is complete.
- Equipment and property records are up to date.
- Prior audit findings have been addressed or tracked.
- Grant reports have been submitted on time.
- Key staff know what documentation the auditor may request.
What the Auditor Reports
The completed reporting package normally contains several auditor reports and schedules. These address the financial statements, internal control and compliance under Government Auditing Standards, compliance for each major program, and the SEFA. The package also includes a schedule of findings and questioned costs.
A finding does not always mean that money must be repaid. Findings can involve internal-control deficiencies, noncompliance, reporting problems, unsupported costs, or questioned costs. The seriousness depends on the nature, cause, amount, frequency, and effect of the issue. Federal agencies and pass-through entities, not the independent auditor, generally make the final management decision concerning questioned costs and corrective action.
The nonprofit should read draft findings carefully and provide accurate context or corrections when appropriate. It should not pressure the auditor to remove a valid finding. A clear response that acknowledges the issue, identifies the cause, and proposes a realistic correction is more useful than a defensive statement that does not address the risk.
Corrective Action and Prior Findings
When the audit identifies findings, the auditee must prepare a corrective action plan. The plan should address each finding, identify responsible officials, and state the corrective action and expected completion date. If management does not agree with a finding or believes that corrective action is unnecessary, it must explain its position.
The organisation must also prepare a summary schedule of prior audit findings. This schedule explains whether earlier corrective actions were completed, remain in progress, or were not implemented. Recurring findings can attract greater attention because they suggest that management did not correct a known weakness.
Corrective action should be practical. Rewriting a policy is not enough if the underlying problem involves training, workload, system access, supervision, or organisational culture. Management should identify the root cause, assign ownership, set milestones, and verify that the revised control works before declaring the issue resolved.
Filing With the Federal Audit Clearinghouse
The nonprofit must submit its data collection form and reporting package electronically to the Federal Audit Clearinghouse. The submission deadline is the earlier of 30 calendar days after receiving the auditor’s reports or nine months after the end of the audit period, unless an authorised extension applies.
Both auditee and auditor representatives participate in the submission and certification process. Current Federal Audit Clearinghouse procedures use Login.gov accounts, online forms, a PDF reporting package, and designated spreadsheet workbooks for the SF-SAC data. The organisation should become familiar with the process before the deadline rather than waiting until the reports are signed.
Single Audit reporting packages are generally publicly available, subject to applicable restrictions. The auditee and auditor must ensure that protected personally identifiable information is not included. Management should review the complete package carefully because donors, lenders, grantmakers, journalists, and members of the public may be able to access it.
Falling Below $1 Million Does Not Remove Compliance Duties
A nonprofit that expends less than $1 million during a fiscal year may be exempt from the federal Single Audit requirement, but it is not exempt from the terms of its awards. It must still maintain records, apply cost principles, follow procurement requirements, protect sensitive information, monitor subrecipients when applicable, submit required reports, and make documentation available for review.
A federal agency or pass-through entity may use other monitoring methods, including site visits, desk reviews, agreed-upon procedures, or examination of selected transactions. State law, grant agreements, lenders, boards, or other funders may also require a financial statement audit even when a Single Audit is not necessary.
The increased single audit threshold nonprofit organisations now follow should therefore be viewed as an audit trigger, not a general compliance exemption. Strong financial management remains necessary at every funding level.
Turning Audit Readiness Into Better Grant Management
The best time to prepare for a Single Audit is before accepting enough funding to trigger one. A nonprofit should evaluate whether its accounting system can identify federal expenditures, whether staff understand federal requirements, whether policies match actual operations, and whether the organisation can meet the administrative cost of managing larger awards.
Crossing $1 million can be a sign of meaningful growth, but it also changes the level of accountability expected from the organisation. Leadership must treat federal compliance as a shared responsibility involving finance, programs, human resources, procurement, information technology, senior management, and the board.
When records are current, controls are followed, and responsibilities are clearly assigned, the audit becomes less disruptive. More importantly, these practices help protect federal resources and support reliable program delivery. The Single Audit should not be approached as a once-a-year paperwork exercise. It is the external examination of financial and compliance systems that should already be operating throughout the year.