Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us
Dictionary termTrack DProposedv2026.1

Subrecipient Risk Assessment

The evaluation a pass-through entity must perform on each proposed subrecipient before making a subaward of federal funds, under 2 CFR 200.332(c) — considering prior experience with similar subawards, results of previous audits, new or substantially changed personnel/systems, and the extent and results of any federal agency monitoring — performed specifically to set the intensity of the monitoring plan applied once the subaward is active.

ByCASRAI Editorial Board
· Last updated 23 Jul 2026

Examples

Worked examples

  • Is an instance

    A university documents a pre-award risk review of a first-time subrecipient noting its lack of Single Audit history and newly hired grants manager, and assigns it monthly interim reporting plus a kickoff technical-assistance call as a result.

  • Is an instance

    A pass-through entity maintains a standard risk-assessment worksheet, completed and filed for every subrecipient before a subaward agreement is executed, covering all four 2 CFR 200.332(c) factors.

Counter-examples

Looks similar, but isn't

  • Not an instance

    Reviewing only a subrecipient's proposed budget for cost allowability without considering its audit history, prior-award experience, or personnel/systems stability — this is a budget review, not a 2 CFR 200.332(c) risk assessment.

  • Not an instance

    Completing a due-diligence questionnaire that is never actually used to set the resulting monitoring plan.

Editorial commentary

Subrecipient risk assessment is the evaluation a pass-through entity (PTE) is required to perform on each proposed subrecipient before making a subaward of federal funds, under 2 CFR §200.332(c) of the OMB Uniform Guidance. Its purpose is not compliance for its own sake — it exists specifically “for purposes of determining the appropriate subrecipient monitoring” the PTE will apply once the subaward is active. A risk assessment that isn’t tied to an actual monitoring plan doesn’t satisfy the intent of the regulation, even if a document exists.

What makes something a 200.332(c) risk assessment

An evaluation counts as a 200.332(c) subrecipient risk assessment when it is performed before the subaward is issued and considers, at minimum, the four factors the regulation names:

  • Prior experience with the same or similar subawards — has this subrecipient successfully administered comparable federal subawards before, whether from this PTE or another one?
  • Results of previous audits — including whether the subrecipient has undergone a Single Audit and whether prior awards similar to the one being made were part of that audit’s major-program testing.
  • New personnel or new or substantially changed systems — a subrecipient with a recent change in its financial-management system, or in the staff administering federal awards, carries more risk than one with stable, proven systems and personnel.
  • The extent and results of any federal agency monitoring — if the subrecipient also receives funding directly from a federal awarding agency, that agency’s own oversight history is relevant evidence of the subrecipient’s compliance posture.

The regulation does not prescribe a scoring rubric, a required document format, or a minimum number of these factors that must be reviewed — it requires that the PTE actually evaluate risk of noncompliance using these considerations and that the evaluation drive a monitoring decision. A PTE is free to build its own internal risk-scoring tool or checklist, and many sponsored-programs offices do, but the four factors above are the regulatory floor a defensible assessment has to touch.

How risk level determines monitoring intensity

2 CFR 200.332 does not set a single fixed monitoring routine that applies to every subaward — it requires the PTE to monitor a subrecipient’s activities “as necessary to ensure the subaward is used for authorized purposes,” with intensity that scales to the risk level the pre-award assessment produced. In practice:

  • A low-risk subrecipient — an experienced collaborator with a clean audit history, stable systems, and a strong prior-performance record — typically warrants standard periodic review of the financial and performance reports it submits.
  • A higher-risk subrecipient — new to federal funding, carrying a recent unresolved audit finding, or reporting new personnel or newly changed financial systems — typically warrants more frequent report review, targeted follow-up questions, and monitoring tools drawn from 2 CFR 200.332(f), such as additional training and technical assistance, an on-site or virtual programmatic review, or an agreed-upon-procedures engagement under 2 CFR 200.425.

Applying identical, light-touch monitoring to every subrecipient regardless of its documented risk level is itself a compliance gap an auditor or federal awarding agency can flag — the point of the up-front assessment is precisely to justify why one subrecipient gets more oversight attention than another.

Worked example

Illustrative example, not a real institution or award. A research university is about to issue two subawards on the same NIH grant. Subrecipient A is a long-time collaborating university with ten years of subawards from this PTE, a clean Single Audit history, and no personnel changes reported. Subrecipient B is a small nonprofit research organization receiving its first-ever federal subaward, with a newly hired grants manager and no Single Audit history to review (it hasn’t yet crossed the $1,000,000 federal-expenditure threshold that triggers one). Both relationships get a documented pre-award risk assessment against the same four 2 CFR 200.332(c) factors, but the outcomes differ: Subrecipient A is assessed as low risk and placed on standard quarterly report review; Subrecipient B is assessed as higher risk and placed on a monitoring plan that adds a kickoff technical-assistance call, monthly interim reporting for the first two quarters, and a virtual programmatic check-in before the first continuation report is due.

Counter-example

A PTE that reviews a subrecipient’s proposed budget for allowability and reasonableness, but does not consider the subrecipient’s audit history, prior-award experience, or personnel/systems stability, has performed a budget review — not a 2 CFR 200.332(c) risk assessment. Likewise, a generic institutional due-diligence questionnaire that isn’t actually used to set the resulting monitoring plan doesn’t satisfy the regulation’s stated purpose, even if it happens to ask about some of the same factors.

Related terms

See the CASRAI Subaward term for the underlying subaward/subrecipient relationship this risk assessment applies to, and the Subrecipient Monitoring Checklist guide for how this pre-award step fits into a pass-through entity’s full 2 CFR 200.332 obligations, including ongoing monitoring and audit-finding follow-up. For the broader risk-indicator vocabulary this assessment draws on — and how it compares to the separate pre-award risk review a federal awarding agency runs on an applicant under 2 CFR 200.206 — see Risk Indicators and Risk Thresholds.

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Subrecipient Risk Assessment"
      vocab-term-identifier="https://casrai.org/dictionary/term/subrecipient-risk-assessment" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/subrecipient-risk-assessment",
  "name": "Subrecipient Risk Assessment",
  "identifier": "https://casrai.org/dictionary/term/subrecipient-risk-assessment",
  "description": "The evaluation a pass-through entity must perform on each proposed subrecipient before making a subaward of federal funds, under 2 CFR 200.332(c) — considering prior experience with similar subawards, results of previous audits, new or substantially changed personnel/systems, and the extent and results of any federal agency monitoring — performed specifically to set the intensity of the monitoring plan applied once the subaward is active.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/subrecipient-risk-assessment",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-23T08:37:07",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →