All articles
Audit 8 min read

What Federal Auditors Actually Look For in Nonprofit Financial Records

Single Audit requirements under the Uniform Guidance have specific documentation expectations. Understanding what auditors look for in transaction records helps finance teams prepare year-round, not just in audit season.

Federal grant audit documentation and financial records review

A federal Single Audit is not a general financial audit. It is a compliance audit, and the distinction matters for how nonprofit finance teams should structure their records throughout the year, not just in the weeks before an auditor arrives.

Organizations that expend $750,000 or more in federal awards in a fiscal year are required under 2 CFR Part 200 Subpart F to undergo a Single Audit. The auditor is not primarily asking whether your financial statements are accurate, though that matters too. The auditor is asking whether you spent federal money in the way the federal government authorized you to spend it, and whether your internal controls are sufficient to prevent and detect material noncompliance.

These are distinct questions, and they require distinct types of documentation.

The Schedule of Expenditures of Federal Awards

The audit starts with the Schedule of Expenditures of Federal Awards (SEFA). This is a supplemental schedule to your financial statements that lists each federal program from which you received funding, the Assistance Listings number (formerly CFDA number), the federal awarding agency, the pass-through entity if applicable, and the total expenditures under each award during the fiscal year.

Auditors verify the SEFA against your general ledger to confirm that all federal expenditures are captured and that the amounts match. Missing a program from the SEFA, or miscategorizing a federal pass-through award as a state or local award, is a finding in itself. Maintain a live SEFA throughout the year rather than constructing it from scratch at year-end. When a new federal award arrives, add it immediately.

Transaction-Level Documentation for Major Programs

From the SEFA, the auditor identifies which programs to test as major programs. The determination uses a risk-based approach described in 2 CFR Part 200 Subpart F. Generally, programs with larger dollar amounts and certain risk factors receive additional scrutiny. For most small-to-midsize nonprofits, at least one program will be selected as a major program each audit cycle.

For each major program, the auditor tests compliance with the applicable compliance requirements. These are documented in the Office of Management and Budget's Compliance Supplement, which is updated annually. The compliance requirement types include allowable costs and activities, cash management, eligibility, equipment and real property management, matching, period of performance, procurement, reporting, subrecipient monitoring, and special tests specific to each program.

At the transaction level, the auditor is looking for three things on each sampled expenditure:

Is the cost allowable? Under the grant's specific restrictions and the general cost principles in 2 CFR Part 200 Subpart E, does this type of expense qualify? A training cost charged to a workforce development grant needs to be a training cost actually delivered to program participants, not a staff professional development expense that was miscoded.

Is the cost allocable? Was the expense charged in proportion to the benefit it provided to the federal program? A shared staff member's time charged 60% to a federal grant needs documentation showing that 60% of their time was actually spent on that program's activities.

Is the cost reasonable? Would a prudent person in comparable circumstances incur this cost at this price? This is the hardest to document in advance because it is a judgment call, but market rate comparisons and competitive procurement records help.

What Auditors Want to See in Card Transaction Records

Card transactions get specific attention because they are one of the easiest categories of expenditure to mischarge. When an auditor pulls a sample of card transactions from a major program's general ledger, the documentation package they expect to see for each transaction typically includes:

The date of grant code assignment matters more than most finance teams realize. If transactions are consistently coded to grants weeks after they occur, the auditor notes that as a control weakness. Retroactive coding is not disallowed, but a pattern of it signals that there is no point-of-purchase control preventing mischarges in the first place.

Internal Control Testing

Beyond transaction testing, the auditor evaluates the design and operating effectiveness of your internal controls over federal program compliance. This involves interviews with staff, review of written policies and procedures, and observation of how controls actually work in practice.

The questions auditors ask during control testing include: Who has authority to charge expenses to federal grants? What review happens before a charge posts? What review happens after charges post? Is there a documented process for identifying and correcting mischarges? Who approves reclassifications, and is that approval documented?

An organization that has no written purchasing policy, relies on a single person's institutional knowledge to catch grant coding errors, and makes corrections informally without documentation has weak internal controls. Even if the dollar amounts tested are all correct, weak controls support a finding in the audit report because they represent a risk of future material noncompliance.

We are not suggesting that every small nonprofit needs a formal internal audit function or a 50-page control framework. But having written procedures, documented authorization levels, and a clear remediation process when errors occur is achievable at almost any staffing level and makes a meaningful difference in how an auditor characterizes your control environment.

Period of Performance Compliance

Federal grants have defined start and end dates. Costs charged after the period of performance ends are unallowable regardless of the nature of the expense. Auditors specifically test for charges outside the authorized period, because this category of finding tends to be mechanical rather than intentional: a staff member uses a grant card after the grant ended, the charge posts, and nobody catches it until the auditor does.

The documentation expectation here is that you have a process for identifying when grants are approaching their end dates, communicating that to card users, and disabling or restricting cards associated with expired grants. If your accounting system or card program does not support automated period-of-performance controls, a manual calendar review at the beginning of each month serves the same purpose when it is actually performed and documented.

Subrecipient Monitoring If You Pass Funds Through

If your organization receives federal funds and passes a portion of them through to another nonprofit (a subrecipient), your audit will include a review of your subrecipient monitoring activities. This is a distinct compliance requirement from direct expenditure testing. The federal government holds you, the pass-through entity, responsible for ensuring that subrecipients use the funds appropriately and have adequate internal controls.

For organizations new to pass-through arrangements, this requirement is often underestimated. Your monitoring responsibilities include providing subrecipients with the Assistance Listings number and applicable compliance requirements, reviewing their financial reports, and following up on any findings from their own audits. Documenting this monitoring activity throughout the year, not just at audit time, is required.

How Year-Round Record-Keeping Changes the Audit Experience

Finance directors who treat audit preparation as a year-round activity rather than an annual sprint consistently report a qualitatively different experience when auditors arrive. When transaction documentation is complete, grant code assignments are contemporaneous, and policies are written and followed, the audit becomes a review of existing records rather than a reconstruction project.

The goal is not to prepare for an audit. The goal is to run the organization in a way that is always audit-ready, because the documentation requirements of grant compliance and the documentation required for sound management of restricted funds are the same requirements. You are not doing extra work for the auditor. You are doing the work that the grant requires anyway, and keeping it organized as you go.

Build the audit trail as you spend

KleerCard records grant code, date, and policy match on every transaction at the moment it happens. Request early access to see the audit export format.

Request Early Access