Examples
Worked examples
- Is an instance
An auditor performing a university's Single Audit consults the Compliance Supplement's Part 4 entry (or the Research and Development cluster entry in Part 5) for the institution's federal research awards to determine which of the twelve compliance-requirement types apply that audit year and what specific procedures to perform for each.
- Is an instance
OMB adds, removes, or re-selects which of the twelve compliance-requirement types apply to a given federal program between one year's Compliance Supplement and the next, changing an institution's actual Single Audit testing scope even though the underlying 2 CFR 200 regulatory text has not changed.
Counter-examples
Looks similar, but isn't
- Not an instance
An institution's own internal grants-compliance manual or audit-prep checklist, even one closely modeled on the Compliance Supplement's format, is not the Compliance Supplement itself and does not satisfy 2 CFR 200.514's requirement that an auditor follow OMB's own current-year guidance.
Editorial commentary
The OMB Compliance Supplement is the annual publication issued by the US Office of Management and Budget (OMB) — codified as 2 CFR Part 200, Appendix XI — that gives independent auditors the specific compliance requirements and suggested audit procedures to test, program by program, when conducting a Single Audit of a non-federal entity under 2 CFR 200 Subpart F.
It does not create new obligations for grant recipients; it operationalizes obligations that already exist elsewhere in statute, regulation, and each award’s own terms into a program-by-program audit checklist. For research administrators, it is the more specific, more frequently-updated document sitting underneath the Uniform Guidance itself — the one an external auditor actually opens when testing your institution’s federal awards.
What the Compliance Supplement Actually Contains
The current Supplement (2025 edition, released November 2025) is organized into seven parts:
- Part 1 — Background, Purpose, and Applicability. Explains the statutory basis for the Single Audit Act and who the Supplement is written for.
- Part 2 — Matrix of Compliance Requirements. A quick-reference table showing, for each federal program included in that year’s Supplement, which of the twelve compliance-requirement types (below) apply.
- Part 3 — Compliance Requirements. Defines the twelve types of compliance requirement an auditor may test on a federal program: activities allowed/unallowed; allowable costs/cost principles; cash management; eligibility; equipment and real property management; matching, level of effort, and earmarking; period of performance; procurement, suspension, and debarment; program income; reporting; subrecipient monitoring; and special tests and provisions. A given federal awarding agency selects up to six of these twelve as applicable to a specific major program for a given audit year, and that selection can change year to year — which is exactly why the Supplement has to be reissued annually rather than published once.
- Part 4 — Agency Program Requirements. Program-specific guidance from each of roughly 19 federal awarding agencies (including HHS, NSF, DOE, USDA, and NASA) for the individual programs, identified by Assistance Listing number, included in that year’s Supplement.
- Part 5 — Clusters of Programs. Guidance for programs OMB groups together because they share closely related compliance requirements and are, for Single Audit purposes, tested as a single “cluster” rather than individually. The Research and Development (R&D) cluster — combining federal research awards across multiple agencies and Assistance Listing numbers — is the entry most directly relevant to a research university’s or hospital’s sponsored-programs office; the Student Financial Aid cluster is the other major example, relevant mainly to institutions with significant federal financial-aid activity.
- Part 6 — Internal Control. Guidance on evaluating internal controls over federal programs, referencing the same two frameworks — the Comptroller General’s Green Book and COSO’s Internal Control–Integrated Framework — that 2 CFR 200.303 itself points to.
- Part 7 — Guidance for Auditing Programs Not Included in this Supplement. Instructs auditors to use the twelve requirement types from Part 3 as a framework even for programs OMB didn’t specifically write up, by reviewing the award’s own terms and the laws/regulations it cites.
Why Auditors Are Required to Use It
2 CFR 200.514(c) makes use of the Supplement effectively mandatory: for the compliance requirements it covers on a given program, an auditor who follows the Supplement’s guidance satisfies the corresponding Subpart F audit-scope requirement. This is what makes the Supplement operationally more important, day to day, than the Uniform Guidance text alone for anyone preparing for an audit — 2 CFR 200 sets the legal framework and the twelve requirement categories in the abstract; the Compliance Supplement is what tells an auditor, for your institution’s specific federal programs in this specific audit year, which of those categories are actually in scope and what a compliant test of each one looks like. A sponsored-programs or compliance office that reads only the regulation and never checks the current-year Supplement can be caught off guard by a testing scope it didn’t anticipate, even though nothing in the underlying law changed.
Relationship to the Single Audit
The Compliance Supplement exists to serve one specific audit: the Single Audit, the annual organization-wide audit required under 2 CFR 200 Subpart F of any non-federal entity that expends $1,000,000 or more in federal awards in a fiscal year (raised from $750,000 effective for fiscal years beginning on or after October 1, 2024). Where a Single Audit examines an entity’s financial statements, its Schedule of Expenditures of Federal Awards, and its internal controls broadly, the Compliance Supplement is the tool the auditor uses specifically for the compliance half of that engagement — determining which major programs to test (per the risk-based approach in 2 CFR 200.518) and, for each one selected, exactly which of the twelve requirement types to examine and how. An entity that receives federal funds from only one program, and whose program doesn’t itself require a financial statement audit, may instead qualify for a narrower program-specific audit under 2 CFR 200.501(c) — the Compliance Supplement still supplies the requirement types tested in that scenario, just against a single program rather than the full award portfolio.
Why It Matters for Research Administrators Specifically
Two things make this a working document for a sponsored-programs or grants-compliance office, not just background reading for the audit committee:
- It changes every year. Because OMB can add, remove, or re-select which of the twelve requirement types apply to a program, an institution’s actual audit exposure on a given federal award can shift from one audit cycle to the next without any change to the award itself or to 2 CFR 200’s text. Compliance offices that only review the regulation once and never revisit the annual Supplement can miss a newly-added testing area.
- The Research and Development cluster is where most research-institution federal expenditure lands. Because R&D awards from different agencies are tested together as a cluster rather than program by program, understanding Part 5’s cluster-level treatment — not just the Part 4 entry for a single agency’s programs — is usually the more relevant read for a university or academic medical center preparing for its Single Audit.
Findings that surface during this compliance testing — a questioned cost, a control deficiency, a material weakness — become part of the institution’s Single Audit report, which is filed with the Federal Audit Clearinghouse and is publicly searchable. A pattern of findings can also draw the separate attention of a funding agency’s own Office of Inspector General, whose audits and Work Plans operate independently of — but are frequently informed by — what a Single Audit already turned up.
Where to Find the Current Supplement
OMB publishes the current and prior-year Compliance Supplements at whitehouse.gov/omb. The Federal Audit Clearinghouse (fac.gov/compliance) also hosts current and historical editions and is generally the more stable long-term link, since the Supplement’s hosting has moved across administrations in the past.
Frequently Asked Questions
Is the Compliance Supplement a regulation?
It is codified as an appendix to a regulation (2 CFR Part 200, Appendix XI) and its use by auditors is effectively mandatory under 2 CFR 200.514, but it functions as detailed audit guidance rather than as freestanding law — it operationalizes requirements set elsewhere (statute, 2 CFR 200 itself, and individual award terms) rather than creating new substantive obligations on its own.
How often is it updated?
Annually. OMB typically releases a new edition in the second half of the calendar year, ahead of the Single Audit season for entities with fiscal years ending mid-year onward; the 2025 edition was released in November 2025.
Does every federal program appear in the Compliance Supplement?
No. It covers the compliance requirements applicable to the principal federal programs and the largest programs by expenditure. For a program not included, Part 7 directs auditors to use the twelve requirement types from Part 3 as a framework and determine the applicable requirements by reviewing the award’s own terms and the laws and regulations it references.
Is the Compliance Supplement the same thing as the Uniform Guidance?
No. Uniform Guidance (2 CFR 200) is the underlying regulatory framework — cost principles, administrative requirements, and the Single Audit requirement itself. The Compliance Supplement is issued under that framework, specifically to guide auditors in testing compliance program by program, and is reissued every year even though the regulation itself changes far less often.
Related CASRAI Content
See also: Single Audit (US), Uniform Guidance (2 CFR 200), OIG Reports, Institutional Internal Controls for Federal Grant Compliance, Subrecipient monitoring, Federal Grant Compliance Checklist, and the Research Integrity & Compliance pillar.
References
- 2 CFR Part 200, Appendix XI (OMB Compliance Supplement), current and prior editions: whitehouse.gov/omb/information-resources/guidance/compliance-supplement/.
- 2 CFR 200.514 (Standards and scope of audit), Subpart F.
- 2 CFR 200.518 (Major program determination), Subpart F.
- 2 CFR 200.501(c) (Program-specific audit election), Subpart F.
- Federal Audit Clearinghouse: fac.gov/compliance/.
- Single Audit Act, as amended, and its implementing regulations at 2 CFR Part 200 Subpart F.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="OMB Compliance Supplement"
vocab-term-identifier="https://casrai.org/dictionary/term/omb-compliance-supplement" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/omb-compliance-supplement",
"name": "OMB Compliance Supplement",
"identifier": "https://casrai.org/dictionary/term/omb-compliance-supplement",
"description": "The OMB Compliance Supplement is the annual publication, issued by the US Office of Management and Budget and codified as 2 CFR Part 200, Appendix XI, that gives independent auditors the compliance requirements and suggested audit procedures to test, program by program, when conducting a Single Audit of a non-federal entity under 2 CFR 200 Subpart F.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/omb-compliance-supplement",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-30T05:48:37",
"inLanguage": "en"
}






