The Federal Audit Clearinghouse (FAC) is the online system where non-federal entities (states, local governments, universities, nonprofits, and other organizations that spend federal grant funds) submit their Single Audit reporting packages, and where anyone else can search and download those reports once filed. It is a submission portal and public repository, not a separate audit requirement of its own — the underlying audit obligation comes from 2 CFR 200 Subpart F of the OMB Uniform Guidance; the FAC is simply where the paperwork that audit produces has to land. For research administrators, the FAC is the mechanism you actually interact with every audit cycle: it is where your institution’s Data Collection Form and reporting package get certified, uploaded, and made searchable to federal awarding agencies, pass-through entities, and the public.
Who Operates the FAC, and the 2023 Move to GSA
The FAC has changed hands administratively. For decades it was operated by the U.S. Census Bureau. Effective October 2023, operation of the FAC moved to the General Services Administration (GSA), run through GSA’s Technology Transformation Services, on a new platform at fac.gov. This was a genuine platform migration, not a rebrand: GSA’s own guidance is explicit that old Census-FAC login credentials do not carry over to the new system, and auditees/auditors had to re-register. If your institution’s audit or grants-compliance staff has been submitting to the FAC for many years, this is the single most important operational fact to flag internally — workflows, saved credentials, and any internal documentation referencing the old Census-hosted portal need updating.
The statutory and regulatory basis for the FAC itself predates the GSA move by decades: the Single Audit Act of 1984 (amended 1996) established the requirement for a clearinghouse function, and 2 CFR 200 Subpart F (specifically 2 CFR 200.512) is the current regulatory text governing what must be submitted, to whom, and by when.
What Gets Submitted: Data Collection Form and Reporting Package
Under 2 CFR 200.512, an auditee submits two components to the FAC:
- The Data Collection Form (SF-SAC) — an OMB-approved form capturing structured, machine-readable information about the auditee, the federal programs it administered, and the audit results (type of opinion, findings, questioned costs). This is the data that populates the FAC’s public search tool. A senior-level representative of the auditee (not the auditor) must certify that the form was prepared in accordance with 2 CFR 200, that it excludes protected personally identifiable information, and that the FAC is authorized to make it publicly available (subject to a narrower exception for federally recognized Indian Tribes, who may elect not to authorize public release).
- The reporting package, which must include: the auditee’s financial statements and Schedule of Expenditures of Federal Awards (SEFA); a summary schedule of prior audit findings; the auditor’s report(s); and a corrective action plan addressing any current-year findings.
On the current fac.gov platform, GSA refers to the submission materials collectively as SF-SAC workbooks uploaded through the site’s online submission workflow, replacing the older Census-era upload process.
Submission Deadline
2 CFR 200.512(a) sets the deadline as the earlier of two dates: 30 calendar days after the auditee receives the auditor’s report(s), or nine months after the end of the audit period (i.e., nine months after fiscal year-end for most institutions). For an entity with a June 30 fiscal year-end, that nine-month backstop lands on March 31; for a calendar fiscal year, it lands on September 30. A cognizant or oversight agency for audit can grant an extension where the nine-month timeline would create an undue burden on the auditee, but that extension has to be requested and approved — it is not automatic.
Retention and Public Access
The auditee must retain copies of the submitted data collection form and reporting package for three years from the date of submission to the FAC, and must make management letters available to federal agencies or pass-through entities upon request even though those letters are not part of the standard FAC submission. Once submitted, reporting packages are generally subject to public inspection through the FAC’s search tools — fac.gov offers basic search, advanced search, and a separate tribal audit search that respects the Tribe non-disclosure election described above.
Why This Matters for Research Administrators
Two consequences of the FAC’s design are worth calling out specifically for a research-institution audience:
- Pass-through due diligence relies on FAC data. If your institution passes federal funds to subrecipients, subrecipient monitoring obligations under 2 CFR 200.332 commonly involve checking whether a subrecipient’s Single Audit is on file and reviewing any findings reported through the FAC before or during an award period, rather than requesting the audit directly from the subrecipient every time.
- Your own institution’s audit history is a public, searchable record. Prior findings, questioned costs, and corrective action plans submitted through the FAC are visible to any prime federal awarding agency evaluating your institution’s risk profile on a new award, not just to the agency that was cognizant for the audit in question.
The FAC submission itself is a compliance and reporting mechanism — it does not change what the Single Audit tests or how findings are resolved. For the audit’s scope, the SEFA, and how findings drive high-risk designation, see the Single Audit and OMB Compliance Supplement entries; for the broader control environment the audit is testing, see Institutional Internal Controls for Federal Grant Compliance and Uniform Guidance (2 CFR 200).
Frequently Asked Questions
Is the Federal Audit Clearinghouse the same thing as the Single Audit?
No. The Single Audit is the audit itself — an examination of an entity’s financial statements, SEFA, internal controls, and compliance with federal program requirements, required under 2 CFR 200 Subpart F when federal expenditure thresholds are met. The FAC is the submission portal and public database where the resulting reporting package and Data Collection Form get filed and made searchable. You cannot submit to the FAC without having completed a Single Audit (or elected program-specific audit) first.
Who submits to the FAC, the auditee or the auditor?
The auditee (the non-federal entity itself, e.g. the university or research institution) is responsible for the submission and for certifying the Data Collection Form, though in practice audit or grants-compliance staff typically coordinate closely with the external auditor to assemble the reporting package and complete the online submission.
What happens if an institution misses the FAC submission deadline?
A late or missing submission is itself a compliance issue that can affect an entity’s risk assessment by federal awarding and pass-through agencies on current and future awards; extensions exist but must be requested from the cognizant or oversight agency for audit before the deadline, not after.
Did the FAC always run on fac.gov?
No. The FAC was operated by the U.S. Census Bureau for decades before operational responsibility moved to the General Services Administration in October 2023, with a new platform and new login credentials at fac.gov; old Census-FAC accounts do not work on the current system.
References
- 2 CFR 200.512, Report submission (eCFR / Cornell Law School Legal Information Institute).
- GSA, Federal Audit Clearinghouse (fac.gov) — submission platform and public search tools.
- 2 CFR 200 Subpart F (OMB Uniform Guidance), audit requirements.







