A federal Single Audit is not a general financial audit. It is a compliance audit, and the distinction matters for how nonprofit finance teams should structure their records throughout the year, not just in the weeks before an auditor arrives.
Organizations that expend $750,000 or more in federal awards in a fiscal year are required under 2 CFR Part 200 Subpart F to undergo a Single Audit. The auditor is not primarily asking whether your financial statements are accurate, though that matters too. The auditor is asking whether you spent federal money in the way the federal government authorized you to spend it, and whether your internal controls are sufficient to prevent and detect material noncompliance.
These are distinct questions, and they require distinct types of documentation.
The Schedule of Expenditures of Federal Awards
The audit starts with the Schedule of Expenditures of Federal Awards (SEFA). This is a supplemental schedule to your financial statements that lists each federal program from which you received funding, the Assistance Listings number (formerly CFDA number), the federal awarding agency, the pass-through entity if applicable, and the total expenditures under each award during the fiscal year.
Auditors verify the SEFA against your general ledger to confirm that all federal expenditures are captured and that the amounts match. Missing a program from the SEFA, or miscategorizing a federal pass-through award as a state or local award, is a finding in itself. Maintain a live SEFA throughout the year rather than constructing it from scratch at year-end. When a new federal award arrives, add it immediately.
Transaction-Level Documentation for Major Programs
From the SEFA, the auditor identifies which programs to test as major programs. The determination uses a risk-based approach described in 2 CFR Part 200 Subpart F. Generally, programs with larger dollar amounts and certain risk factors receive additional scrutiny. For most small-to-midsize nonprofits, at least one program will be selected as a major program each audit cycle.
For each major program, the auditor tests compliance with the applicable compliance requirements. These are documented in the Office of Management and Budget's Compliance Supplement, which is updated annually. The compliance requirement types include allowable costs and activities, cash management, eligibility, equipment and real property management, matching, period of performance, procurement, reporting, subrecipient monitoring, and special tests specific to each program.
At the transaction level, the auditor is looking for three things on each sampled expenditure:
Is the cost allowable? Under the grant's specific restrictions and the general cost principles in 2 CFR Part 200 Subpart E, does this type of expense qualify? A training cost charged to a workforce development grant needs to be a training cost actually delivered to program participants, not a staff professional development expense that was miscoded.
Is the cost allocable? Was the expense charged in proportion to the benefit it provided to the federal program? A shared staff member's time charged 60% to a federal grant needs documentation showing that 60% of their time was actually spent on that program's activities.
Is the cost reasonable? Would a prudent person in comparable circumstances incur this cost at this price? This is the hardest to document in advance because it is a judgment call, but market rate comparisons and competitive procurement records help.
What Auditors Want to See in Card Transaction Records
Card transactions get specific attention because they are one of the easiest categories of expenditure to mischarge. When an auditor pulls a sample of card transactions from a major program's general ledger, the documentation package they expect to see for each transaction typically includes:
- The original receipt showing vendor name, date, itemized amounts, and total
- The grant code assignment and the date it was assigned (before or at the time of purchase, not retroactively)
- For any transaction that was reclassified after posting: the original code, the corrected code, the date of correction, the reason for the correction, and who authorized it
- For large purchases or unusual vendors: a brief narrative note explaining how the expense relates to the grant's allowable activities
The date of grant code assignment matters more than most finance teams realize. If transactions are consistently coded to grants weeks after they occur, the auditor notes that as a control weakness. Retroactive coding is not disallowed, but a pattern of it signals that there is no point-of-purchase control preventing mischarges in the first place.
Internal Control Testing
Beyond transaction testing, the auditor evaluates the design and operating effectiveness of your internal controls over federal program compliance. This involves interviews with staff, review of written policies and procedures, and observation of how controls actually work in practice.
The questions auditors ask during control testing include: Who has authority to charge expenses to federal grants? What review happens before a charge posts? What review happens after charges post? Is there a documented process for identifying and correcting mischarges? Who approves reclassifications, and is that approval documented?
An organization that has no written purchasing policy, relies on a single person's institutional knowledge to catch grant coding errors, and makes corrections informally without documentation has weak internal controls. Even if the dollar amounts tested are all correct, weak controls support a finding in the audit report because they represent a risk of future material noncompliance.
We are not suggesting that every small nonprofit needs a formal internal audit function or a 50-page control framework. But having written procedures, documented authorization levels, and a clear remediation process when errors occur is achievable at almost any staffing level and makes a meaningful difference in how an auditor characterizes your control environment.
Period of Performance Compliance
Federal grants have defined start and end dates. Costs charged after the period of performance ends are unallowable regardless of the nature of the expense. Auditors specifically test for charges outside the authorized period, because this category of finding tends to be mechanical rather than intentional: a staff member uses a grant card after the grant ended, the charge posts, and nobody catches it until the auditor does.
The documentation expectation here is that you have a process for identifying when grants are approaching their end dates, communicating that to card users, and disabling or restricting cards associated with expired grants. If your accounting system or card program does not support automated period-of-performance controls, a manual calendar review at the beginning of each month serves the same purpose when it is actually performed and documented.
Subrecipient Monitoring If You Pass Funds Through
If your organization receives federal funds and passes a portion of them through to another nonprofit (a subrecipient), your audit will include a review of your subrecipient monitoring activities. This is a distinct compliance requirement from direct expenditure testing. The federal government holds you, the pass-through entity, responsible for ensuring that subrecipients use the funds appropriately and have adequate internal controls.
For organizations new to pass-through arrangements, this requirement is often underestimated. Your monitoring responsibilities include providing subrecipients with the Assistance Listings number and applicable compliance requirements, reviewing their financial reports, and following up on any findings from their own audits. Documenting this monitoring activity throughout the year, not just at audit time, is required.
How Year-Round Record-Keeping Changes the Audit Experience
Finance directors who treat audit preparation as a year-round activity rather than an annual sprint consistently report a qualitatively different experience when auditors arrive. When transaction documentation is complete, grant code assignments are contemporaneous, and policies are written and followed, the audit becomes a review of existing records rather than a reconstruction project.
The goal is not to prepare for an audit. The goal is to run the organization in a way that is always audit-ready, because the documentation requirements of grant compliance and the documentation required for sound management of restricted funds are the same requirements. You are not doing extra work for the auditor. You are doing the work that the grant requires anyway, and keeping it organized as you go.