Background with light gradient and lines

Spend enough federal grant money in a year and a regular financial statement audit is no longer enough. You need a single audit.

For a lot of nonprofits, the first one comes as a surprise. The organization wins a big federal grant, crosses a spending threshold, and suddenly faces a much wider review than the books alone. It checks both your financial statements and how you handled the federal money, all in one engagement.

This guide walks through what a single audit is, who needs one, how the process runs, and where organizations get caught out.

What a single audit is

A single audit is an organization-wide audit of an entity that spends federal awards above a set threshold.

The name comes from the idea of one combined review instead of a separate one for every federal grant. It was created by the Single Audit Act and now runs under the Uniform Guidance, the body of federal rules at 2 CFR 200. The engagement has two halves: a look at your financials, and a look at whether you followed the rules attached to the federal money you spent. Federal programs also pull in government auditing standards, the Yellow Book, on top of the usual rules.

So it is not simply a bigger version of a normal one. It is a different animal, with its own rulebook.

Who needs a single audit

The trigger is simple. It comes down to how much federal money you spend in a year.

A non-federal entity that expends $1 million or more in federal awards during its fiscal year must have one. That sweeps in nonprofits, universities, and state and local governments receiving federal financial assistance. The threshold counts what you actually spend, not what you were awarded, so a multi-year grant only triggers the requirement in the years you draw it down past the line. Stay under $1 million and you generally avoid the requirement entirely.

Watch the spending, not the award letter. That is what decides whether you are in.

The two parts of a single audit

Every one of these engagements really does two jobs at once.

The first is a standard financial statement audit, where the auditor gives an opinion on whether your financials are fairly stated, the same core work behind external financials. The second is a compliance audit, which tests whether you followed the specific rules tied to each major federal program: how you spent the money, who was eligible, what you reported, and how you tracked it. This second piece is what sets it apart from the plain review a private company gets. Both halves land in one reporting package.

One engagement, two opinions: one on the numbers, one on the rules.

Uniform Guidance and allowable costs

The rulebook behind all of this is one federal regulation.

Issued by the Office of Management and Budget, it pulls the administrative requirements, allowable costs, and audit rules into one place at 2 CFR 200. The cost principles decide which costs you can charge to a federal award and which you cannot. Each year, the OMB also puts out a Compliance Supplement that spells out exactly what to test for the biggest programs. Miss a cost principle or a program rule and you create a finding.

Learn the rules that apply to your grants before the auditor arrives, not after.

How the audit process works

The work starts with one document: the schedule of expenditures of federal awards.

This schedule, the SEFA, lists every federal program you spent money on during the year, and it drives the whole engagement. From it, your firm identifies your major federal programs using a risk-based approach, then tests internal control and compliance for those programs. They check whether your controls actually work and whether you met the compliance requirements in the supplement. The bigger and riskier the program, the more testing you should expect, which is why first-time audit prep matters so much.

Get the SEFA right and the rest of the work has a solid foundation. Get it wrong and everything downstream wobbles.

Audit findings and corrective action

Not every engagement comes back clean, and that is normal.

When the review turns up a problem, the firm records an audit finding, often with questioned costs, meaning amounts that may not have been spent according to the rules. For each finding, your organization writes a corrective action plan that explains how you will fix it and by when. Findings are not the end of the world, though ignoring them is, because the same one showing up year after year is what draws real federal attention. A clean plan, acted on, usually settles the matter.

Findings happen. What separates a strong grantee is how fast they fix them.

Submission requirements and deadlines

Once the work is done, it has to be filed in the right place.

The completed package, including the audit report, the financials, the SEFA, and the findings, gets submitted to the Federal Audit Clearinghouse, the central database for these reports. Submission is generally due the earlier of 30 days after you receive the report or nine months after your fiscal year ends. Blow the submission requirements and you risk losing eligibility for future funding. Federal agencies and pass-through entities both pull from that database to confirm you met your obligation.

File it on time, in the right place, every year you cross the threshold.

Where single audits trip up nonprofits

The engagement rewards preparation and punishes the opposite.

Most of the pain traces back to a messy SEFA, thin internal control documentation, or not knowing which rules apply to a given grant. That is the kind of work US CPA firms hand to us at Madras Accountancy. Our offshore team supports audit and assurance engagements, including the schedules, control testing, and workpapers behind the engagement. If a client just crossed the federal threshold, reach out.

Frequently asked questions

What is a single audit? A single audit is an organization-wide audit required when an organization spends federal money above a set threshold. It combines a financial statement audit with a compliance review of how the federal money was used, all under one federal rulebook.

Who is required to have a single audit? Any non-federal entities, such as nonprofits, universities, or local governments, that spend $1 million or more in federal awards in a year. Entities below that level of federal financial assistance generally do not need one.

What is the difference between a single audit and a regular audit? A regular audit only covers your financials. It adds a compliance audit that tests whether you followed the rules attached to each major federal program, so it is broader and more detailed.

What is the single audit threshold? The threshold is $1 million in federal funds spent during the year. It is based on what you actually spend, not what you were awarded, so timing of your spending matters.

What is the Uniform Guidance? It is the set of federal rules at 2 CFR 200, issued by the OMB. It combines administrative requirements, allowable costs, and the audit rules that govern how the engagement is run.

What is the SEFA? It lists every program you spent money on during the year. Your firm uses it to identify major programs and scope the testing, so accuracy here shapes everything.

What happens if a single audit has findings? The auditor reports each audit finding, sometimes with questioned costs, and your organization responds with a corrective action plan. Findings are common and manageable, but repeat findings left unaddressed can put future federal funding at risk.

Where is a single audit submitted? The completed package goes to the Clearinghouse, usually within nine months of your year end. Federal agencies and pass-through entities rely on that submission to confirm you met the requirement.

Table of Contents

Explore More Blogs

Image
Single-Entry vs Double-Entry Bookkeeping: A Simple Guide
Published On:
July 30, 2026

Single-entry vs double-entry bookkeeping made simple: how each accounting system works, the key differences, and which one your small business needs.

Image
CPA vs EA vs Tax Attorney: Which Tax Professional Do You Actually Need?
Published On:
July 30, 2026

CPA vs EA (enrolled agent) vs tax attorney: how each tax professional differs, who can represent you to the IRS, and which fits your tax needs.

Image
Data Breach Response for Tax Professionals: How Preparers Report Data Theft to the IRS
Published On:
July 30, 2026

Learn how tax professionals should respond to a data breach, report theft to the IRS and states, notify clients, meet FTC rules, and prevent future attacks.

View all posts
Icon
Icon