Skip to main content
v2026.11,858 entries · CC-BY 4.0
Dictionary termTrack DProposedv2026.1

Subrecipient Risk Assessment

The evaluation a pass-through entity must perform on each proposed subrecipient before making a subaward of federal funds, under 2 CFR 200.332(c) — considering prior experience with similar subawards, results of previous audits, new or substantially changed personnel/systems, and the extent and results of any federal agency monitoring — performed specifically to set the intensity of the monitoring plan applied once the subaward is active.

ByCASRAI Editorial Board
· Last updated 5 Sept 2026
Share this

Ask CASRAI · included with Regulatory Radar

Ask about Subrecipient Risk Assessment

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Examples

Worked examples

  • Is an instance

    A university documents a pre-award risk review of a first-time subrecipient noting its lack of Single Audit history and newly hired grants manager, and assigns it monthly interim reporting plus a kickoff technical-assistance call as a result.

  • Is an instance

    A pass-through entity maintains a standard risk-assessment worksheet, completed and filed for every subrecipient before a subaward agreement is executed, covering all four 2 CFR 200.332(c) factors.

Counter-examples

Looks similar, but isn't

  • Not an instance

    Reviewing only a subrecipient's proposed budget for cost allowability without considering its audit history, prior-award experience, or personnel/systems stability — this is a budget review, not a 2 CFR 200.332(c) risk assessment.

  • Not an instance

    Completing a due-diligence questionnaire that is never actually used to set the resulting monitoring plan.

Editorial commentary

Subrecipient risk assessment is the evaluation a pass-through entity (PTE) is required to perform on each proposed subrecipient before making a subaward of federal funds, under 2 CFR §200.332(c) of the OMB Uniform Guidance. Its purpose is not compliance for its own sake — it exists specifically “for purposes of determining the appropriate subrecipient monitoring” the PTE will apply once the subaward is active. A risk assessment that isn’t tied to an actual monitoring plan doesn’t satisfy the intent of the regulation, even if a document exists.

What makes something a 200.332(c) risk assessment

An evaluation counts as a 200.332(c) subrecipient risk assessment when it is performed before the subaward is issued and considers, at minimum, the four factors the regulation names:

  • Prior experience with the same or similar subawards — has this subrecipient successfully administered comparable federal subawards before, whether from this PTE or another one?
  • Results of previous audits — including whether the subrecipient has undergone a Single Audit and whether prior awards similar to the one being made were part of that audit’s major-program testing.
  • New personnel or new or substantially changed systems — a subrecipient with a recent change in its financial-management system, or in the staff administering federal awards, carries more risk than one with stable, proven systems and personnel.
  • The extent and results of any federal agency monitoring — if the subrecipient also receives funding directly from a federal awarding agency, that agency’s own oversight history is relevant evidence of the subrecipient’s compliance posture.

The regulation does not prescribe a scoring rubric, a required document format, or a minimum number of these factors that must be reviewed — it requires that the PTE actually evaluate risk of noncompliance using these considerations and that the evaluation drive a monitoring decision. A PTE is free to build its own internal risk-scoring tool or checklist, and many sponsored-programs offices do, but the four factors above are the regulatory floor a defensible assessment has to touch.

How risk level determines monitoring intensity

2 CFR 200.332 does not set a single fixed monitoring routine that applies to every subaward — it requires the PTE to monitor a subrecipient’s activities “as necessary to ensure the subaward is used for authorized purposes,” with intensity that scales to the risk level the pre-award assessment produced. In practice:

  • A low-risk subrecipient — an experienced collaborator with a clean audit history, stable systems, and a strong prior-performance record — typically warrants standard periodic review of the financial and performance reports it submits.
  • A higher-risk subrecipient — new to federal funding, carrying a recent unresolved audit finding, or reporting new personnel or newly changed financial systems — typically warrants more frequent report review, targeted follow-up questions, and monitoring tools drawn from 2 CFR 200.332(f), such as additional training and technical assistance, an on-site or virtual programmatic review, or an agreed-upon-procedures engagement under 2 CFR 200.425.

Applying identical, light-touch monitoring to every subrecipient regardless of its documented risk level is itself a compliance gap an auditor or federal awarding agency can flag — the point of the up-front assessment is precisely to justify why one subrecipient gets more oversight attention than another.

Worked example

Illustrative example, not a real institution or award. A research university is about to issue two subawards on the same NIH grant. Subrecipient A is a long-time collaborating university with ten years of subawards from this PTE, a clean Single Audit history, and no personnel changes reported. Subrecipient B is a small nonprofit research organization receiving its first-ever federal subaward, with a newly hired grants manager and no Single Audit history to review (it hasn’t yet crossed the $1,000,000 federal-expenditure threshold that triggers one). Both relationships get a documented pre-award risk assessment against the same four 2 CFR 200.332(c) factors, but the outcomes differ: Subrecipient A is assessed as low risk and placed on standard quarterly report review; Subrecipient B is assessed as higher risk and placed on a monitoring plan that adds a kickoff technical-assistance call, monthly interim reporting for the first two quarters, and a virtual programmatic check-in before the first continuation report is due.

Counter-example

A PTE that reviews a subrecipient’s proposed budget for allowability and reasonableness, but does not consider the subrecipient’s audit history, prior-award experience, or personnel/systems stability, has performed a budget review — not a 2 CFR 200.332(c) risk assessment. Likewise, a generic institutional due-diligence questionnaire that isn’t actually used to set the resulting monitoring plan doesn’t satisfy the regulation’s stated purpose, even if it happens to ask about some of the same factors.

When this last changed, and how you find out next time

The $1,000,000 Single Audit threshold referenced above is current as of 1 October 2024. It is not permanent: OMB revised 2 CFR 200 on 22 April 2024, published in the Federal Register at 89 FR 30046, raising the threshold from $750,000, and the four 200.332(c) risk factors above were carried through that revision.

OMB publishes every change to the Uniform Guidance in the Federal Register, and the Federal Register is one of the sources Regulatory Radar checks every day — so 2 CFR 200 is one of the few subjects where CASRAI reads the primary publication venue itself rather than waiting for somebody’s summary. It does not watch the NIH Guide, and it does not watch private accreditors.

Ask CASRAI how to score a subrecipient risk assessment when one of the four 200.332(c) factors has no evidence — it answers from an indexed corpus it re-checks daily and cites the passage it used, so you can open the source and check it. Two questions a day are free while you are signed out, no account and no card. Regulatory Radar is $29 a month for 150 a day, a subscriber dashboard, API keys and MCP access. Everything CASRAI publishes, including this page, stays free to read.

Frequently asked questions

Our subrecipient has never crossed the $1,000,000 Single Audit threshold, so there is no audit history to review under 2 CFR 200.332(c) — does that absence count as a risk factor on its own, or just leave that one factor blank?

2 CFR 200.332(c) does not prescribe how to score an absent factor, which is exactly why the regulation requires evaluating all four factors together rather than any one in isolation. A subrecipient with no Single Audit history because it has never crossed the $1,000,000 threshold is not automatically higher risk on that basis alone — the worked example in this entry treats a first-time subrecipient’s lack of audit history as one input alongside its new grants manager, not as a disqualifying gap. The PTE’s own risk-scoring tool has to decide how much weight an absent factor carries, and that decision is exactly the kind of documented judgment call an auditor expects to see recorded, not silently defaulted to either “no evidence of risk” or “treat as maximum risk.”

Can a PTE use the same risk-assessment document across an entire subaward relationship, or does it have to happen again each year?

2 CFR 200.332(c) requires the assessment before the subaward is issued, and the regulation’s four factors — prior experience, audit results, personnel/systems stability, and federal agency monitoring history — are inherently time-sensitive. A multi-year subaward relationship where the subrecipient’s grants manager changes, or where a new Single Audit finding is issued, has a materially different risk profile than the one assessed at the original award. Nothing in 200.332 fixes a reassessment cadence, but relying on a stale pre-award assessment through a change that clearly bears on one of the four named factors is difficult to defend as a genuine evaluation “for purposes of determining the appropriate subrecipient monitoring” once that monitoring plan no longer reflects current facts.

Does a subrecipient’s clean Single Audit automatically make it low risk?

Not on its own. A clean Single Audit satisfies only one of the four named factors — it says nothing about whether the subrecipient has new personnel, a substantially changed financial system, or a thin prior-experience record with this type of subaward. The worked example’s Subrecipient A is assessed low risk because all four factors line up favorably (ten years of history, clean audit, no personnel changes); a subrecipient with a clean audit but a brand-new grants manager and no prior experience with this PTE would need the other three factors weighed, not a pass granted on the audit result alone.

What is the difference between this assessment and the pre-award risk review a federal agency runs on an applicant?

They are separate reviews performed by different parties at different points. This entry describes the review a pass-through entity runs on a proposed subrecipient under 2 CFR 200.332(c), before issuing a subaward. A federal awarding agency’s own applicant risk review under 2 CFR 200.206 happens earlier, when the agency is deciding whether to make the award to the prime recipient in the first place. See risk indicators and risk thresholds for the broader vocabulary both reviews draw on.

If the risk assessment flags a subrecipient as higher risk, what can the PTE actually require — can it just refuse the subaward?

2 CFR 200.332(f) gives the PTE specific tools proportionate to the assessed risk, not a binary award/refuse choice: additional training and technical assistance, an on-site or virtual programmatic review, and an agreed-upon-procedures engagement under 2 CFR 200.425. A PTE can decline to issue a subaward on other grounds, but the risk assessment’s regulatory purpose is to calibrate monitoring intensity, not to serve as a pass/fail gate on whether the subaward proceeds at all.

Related terms

See the CASRAI Subaward term for the underlying subaward/subrecipient relationship this risk assessment applies to, and the Subrecipient Monitoring Checklist guide for how this pre-award step fits into a pass-through entity’s full 2 CFR 200.332 obligations, including ongoing monitoring and audit-finding follow-up. For the broader risk-indicator vocabulary this assessment draws on — and how it compares to the separate pre-award risk review a federal awarding agency runs on an applicant under 2 CFR 200.206 — see Risk Indicators and Risk Thresholds. For the practical, step-by-step version of scoring and documenting this same pre-award assessment, see the CASRAI guide Subrecipient Risk Assessment: How Pass-Through Entities Score Subrecipients Before Award.

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Subrecipient Risk Assessment"
      vocab-term-identifier="https://casrai.org/dictionary/term/subrecipient-risk-assessment" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/subrecipient-risk-assessment",
  "name": "Subrecipient Risk Assessment",
  "identifier": "https://casrai.org/dictionary/term/subrecipient-risk-assessment",
  "description": "The evaluation a pass-through entity must perform on each proposed subrecipient before making a subaward of federal funds, under 2 CFR 200.332(c) — considering prior experience with similar subawards, results of previous audits, new or substantially changed personnel/systems, and the extent and results of any federal agency monitoring — performed specifically to set the intensity of the monitoring plan applied once the subaward is active.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/subrecipient-risk-assessment",
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "author": {
    "@id": "https://casrai.org/#editorial-team"
  },
  "datePublished": "2026-07-23T08:37:07",
  "dateModified": "2026-09-05T21:11:03",
  "inLanguage": "en-GB",
  "isAccessibleForFree": true
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.