A nonprofit spent $2.1 million in federal grants last fiscal year: three pass-through awards from HHS, one direct from HUD, one disaster-recovery from FEMA. The CFO asks whether a "regular audit" is enough. The answer is no. The exam question is whether you can identify the major programs, test the twelve compliance requirements against the terms of each award, and issue the four reports on time.
HIGH-FREQUENCY: Under 2 CFR 200.501, a non-federal entity that expends $1,000,000 or more in federal awards during its fiscal year must have a single audit. The trigger is expended, not received.
Federal awards include direct grants, pass-through funds, federal cost-reimbursement contracts, loan and loan guarantee balances outstanding, donated property, and noncash assistance. A program-specific audit may substitute when the entity expended awards under only one federal program.
KEY: The $1,000,000 line is per fiscal year, per non-federal entity, on expenditures across all federal awards combined. Aggregate first; threshold-test second.
HIGH-FREQUENCY: Single audits do not test every program. The auditor identifies major programs under 2 CFR 200.518.
Common mistakes
- Treating the threshold as gross awards rather than expenditures. A grant received in Year 1 and spent across Years 2 and 3 produces $0 of single-audit activity in Year 1. Aggregate expended dollars (including loan and guarantee balances outstanding) and compare to $1,000,000.
- Skipping Step 4 once Steps 1, 3 produce "enough" major programs. Step 4 is a coverage floor, not a substitute for Step 1, 3 mandates. Step 1, 3 mandates also do not satisfy Step 4 if coverage is short. Add programs until the 40% (or 20%) floor is met.
- Testing all 12 compliance requirements for every major program. Test only those that are direct and material. The Compliance Supplement matrix indicates which apply to each program.
Bottom line
- Threshold: $1,000,000 or more in federal awards expended in the fiscal year, aggregated across direct, pass-through, loans outstanding, and noncash awards (2 CFR 200.501).
- Major programs use a four-step risk-based approach: Type A vs Type B, low-risk Type A test, high-risk Type B, and a percentage-of-coverage floor of 40% (20% for low-risk auditees under 2 CFR 200.520).
- Compliance audit tests the 12 compliance requirements in the OMB Compliance Supplement, but only those that are direct and material, via tests of controls and tests of compliance.
- Four reports: in-relation-to opinion on the SEFA, internal control and compliance under Government Auditing Standards, compliance for each major program plus internal control over compliance, and schedule of findings and questioned costs.
Exam shortcut
When a question gives you a fiscal-year expenditure figure, anchor on $1,000,000 expended (not received). Add direct, pass-through, and loans-outstanding balances; ignore the receipt year. When asked which programs are major, run the steps in order: (1) compute the Type A threshold, (2) flag every Type A unless it qualifies as low-risk, (3) add high-risk Type Bs above the floor, (4) confirm the 40% / 20% coverage floor.
The full lesson (about 2,605 words, 17 min read) adds 2 worked examples, all 5 common mistakes, a self-check, free in the app.
Learning objectives
- III.E6
Browse all free CPA AUD lessons or jump into free CPA AUD practice questions.