Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Institutional Internal Controls for Federal Grant Compliance

What 2 CFR 200.303 requires, the five components of an effective internal control system, and how weak controls surface as Single Audit findings.

2 CFR 200.303 requires federal grant recipients to establish an internal control system that provides reasonable assurance of compliance, to monitor that compliance, to correct noncompliance promptly, and to safeguard award information including PII. Recipients may build the system to either GAO’s Green Book or COSO’s Internal Control–Integrated Framework; auditors weigh actual compliance over which named framework is used.

Under the federal Uniform Guidance, internal controls are not a general-purpose management best practice an institution may adopt at its own discretion — they are a specific, regulatory condition of receiving federal grant funds, codified at 2 CFR 200.303. This guide is a deep dive on that one section: what it requires, why it exists, the practical components an institution builds to satisfy it, and how gaps in those controls turn into Single Audit findings. For the broader regulatory framework 200.303 sits inside, see the companion guide on Uniform Guidance (2 CFR 200).

What “internal controls” means under 2 CFR 200.303

2 CFR 200.303, titled “Internal controls,” sits in Subpart D (Post Federal Award Requirements) of the Uniform Guidance. It applies to any non-federal entity — university, hospital, nonprofit, or state/local government — that receives a federal award directly or as a subrecipient. The section has five operative parts:

  • (a) Establish, document, and maintain effective internal control. The recipient or subrecipient must maintain a system of internal control over the federal award that provides reasonable assurance the entity is managing the award in compliance with federal statutes, regulations, and the award’s own terms and conditions. Notably, the regulation doesn’t mandate a single required framework — it directs entities toward either the Comptroller General’s Standards for Internal Control in the Federal Government (the “Green Book,” GAO-14-704G, revised most recently by GAO in May 2025) or the Committee of Sponsoring Organizations of the Treadway Commission’s (COSO) Internal Control–Integrated Framework. Either is acceptable; what matters to an auditor is whether the entity’s actual system meets the standard, not which named framework it maps to.
  • (b) Comply with federal statutes, regulations, and award terms. The internal control system has to actually produce compliance, not just exist on paper.
  • (c) Evaluate and monitor compliance. The entity must have a mechanism for checking, on an ongoing basis, that its own compliance with statutes, regulations, and award terms is actually happening — not just assume it is.
  • (d) Take prompt corrective action. When noncompliance is identified — whether through internal monitoring, a sponsor site visit, or an audit — the entity must act on it promptly, not defer it.
  • (e) Safeguard information, including PII. Recipients and subrecipients must take “reasonable cybersecurity and other measures” to protect information handled under the award, including protected personally identifiable information. OMB deliberately does not prescribe a specific cybersecurity framework here either — entities retain discretion over the specific measures, so long as they’re reasonable for the sensitivity of the information involved.

Read together, (a)–(e) describe a cycle, not a one-time setup: build a control system aligned to a recognized standard, use it to actually stay compliant, monitor whether it’s working, fix what isn’t, and protect the information that flows through it.

Why institutions must maintain internal controls

Three distinct rationales sit behind 200.303, and they matter for different audiences inside an institution:

  • Safeguarding federal funds. Federal award dollars are public funds administered on trust; internal controls are the mechanism that gives the awarding agency (and, by extension, Congress and taxpayers) reasonable assurance that money appropriated for a specific research or program purpose is actually spent on that purpose, at allowable cost levels, by the entity accountable for it.
  • Ensuring compliance with award terms. Every federal award carries both government-wide requirements (the cost principles in 2 CFR Part 200 Subpart E, for instance) and award-specific terms set by the individual sponsoring agency or program. Internal controls are what operationalizes “we agreed to these terms” into day-to-day practice across every department and every PI managing an award, not just the sponsored-programs office that signed the award document.
  • Preventing waste, fraud, and abuse. Segregation of duties, documented approval chains, and independent monitoring exist specifically to make it structurally harder for a single point of failure — one person’s error, or one person’s deliberate misconduct — to go undetected. This is also the framing GAO’s own Green Book leads with in its most recent (2025) revision, which added expanded guidance specifically on fraud and improper-payment risk.

Practically, this isn’t optional in the way an institution might treat a purely internal management preference: an entity’s internal control environment is itself something a Single Audit examines directly, and a federal awarding agency can factor an institution’s control weaknesses into funding and risk decisions independent of any specific audit finding.

The five components of an effective internal control system

Both frameworks 200.303(a) points to — the GAO Green Book and COSO — are organized around the same five components (the Green Book expresses them as 17 underlying principles). For a research-administration office, they translate into concrete, buildable practices:

Control environment

The tone and structure an institution sets from the top: written delegations of authority for who can approve what dollar amount of spending, a code of conduct, and clear reporting lines between departmental research administrators, the central sponsored-programs office, and institutional leadership. Weak control environment is often the root cause auditors cite behind more specific findings elsewhere.

Risk assessment

A deliberate process — not an assumption — for identifying where an award is most exposed to noncompliance: new PIs unfamiliar with federal requirements, subrecipients in jurisdictions with weaker financial systems, cost categories (like effort/time reporting) that are chronically hard to document accurately, or programs the funding agency itself has flagged as higher-risk in the annual OMB Compliance Supplement. Risk assessment is what determines where monitoring effort and control activities actually get spent, rather than spreading equally thin across every award regardless of real exposure.

Control activities — including segregation of duties and documented policies

Segregation of duties is the most concrete, auditable control activity: the person who approves a purchase on a federal award should not also be the person who reconciles that same account, and the person certifying effort on a grant should not be the same person approving their own payroll charge without independent review. Documented policies and procedures — written, current, and consistently applied — are what let an institution demonstrate a control exists at all; an unwritten practice, even a genuinely good one, is very difficult for an auditor (or a new staff member) to verify. Common examples in a research-administration office include a documented cost-transfer policy, a documented subrecipient risk-assessment and monitoring procedure (see subrecipient monitoring), and a documented cost-accounting practice — some institutions continue to maintain this in DS-2 format even though the standalone federal filing requirement was removed in the 2024 Uniform Guidance revision (see Cost Accounting Standards Disclosure Statement (DS-2)).

Information and communication

Systems (financial, effort-reporting, procurement) that produce accurate, timely, and complete information, and channels that get the right information to the people who need to act on it — a PI approaching an award’s period-of-performance end date, or a compliance office that needs to know a subrecipient missed a required report.

Monitoring

Ongoing checks that the other four components are actually working, distinct from the annual external audit. This includes routine reconciliation of sponsored accounts, periodic internal reviews of higher-risk awards or subrecipients, and management’s own review of exception reports — the kind of ongoing self-check 200.303(c) requires directly, rather than only discovering a problem when an external auditor does.

How weak internal controls surface in Single Audit findings

The Single Audit, required under 2 CFR Part 200 Subpart F of any non-federal entity expending federal awards above the statutory threshold, directly tests an entity’s internal controls as one of its core objectives — alongside the financial statements, the Schedule of Expenditures of Federal Awards (SEFA), and compliance with the specific requirements of each major program tested. The annual OMB Compliance Supplement identifies twelve categories of compliance requirement an auditor may test (activities allowed/unallowed, allowable costs, cash management, eligibility, equipment and real property management, matching/level of effort, period of performance, procurement, program income, reporting, subrecipient monitoring, and special tests and provisions); each federal awarding agency selects up to six of these as applicable to a given major program in a given year.

When testing turns up a problem, auditors classify it on a severity scale, not as a single undifferentiated “finding”:

  • Control deficiency — the design or operation of a control doesn’t allow management or staff to prevent, or detect and correct, misstatements or noncompliance in the normal course of duties. The least severe classification.
  • Significant deficiency — a deficiency, or combination of deficiencies, less severe than a material weakness but important enough to merit attention from those responsible for oversight.
  • Material weakness — a deficiency, or combination of deficiencies, such that there’s a reasonable possibility a material misstatement or material noncompliance won’t be prevented or detected and corrected on a timely basis. The most severe classification, and the one most likely to affect an institution’s standing with a federal awarding agency.

In practice, internal-control findings recur most often around exactly the components above applied unevenly: segregation-of-duties gaps in smaller departmental units; documented-procedure gaps where a practice is real but unwritten or inconsistently applied; time-and-effort reporting, where certifications don’t reconcile to actual payroll charges across all funding sources (see effort reporting methodologies); and subrecipient monitoring, where a pass-through entity hasn’t documented the risk assessment or follow-up 2 CFR 200.332 requires of it (the FDP subaward templates are one practical tool institutions use to standardize that flow-down). A material weakness finding can trigger a federal awarding agency’s high-risk auditee designation, which typically brings additional reporting requirements, closer monitoring, or special award conditions on future funding — consequences that extend well beyond the specific audit finding itself.

Related compliance controls worth cross-referencing

Internal controls over a federal award don’t operate in isolation from an institution’s other compliance infrastructure. Two adjacent areas worth linking to a control system directly: conflict-of-interest disclosure, which is itself a documented, monitored control process; and indirect cost recovery, where consistent, documented cost-allocation practice is both a cost-principles requirement and an internal-control matter in its own right.

Frequently asked questions

Does every institution receiving federal funds need to comply with 2 CFR 200.303?

Yes. Any non-federal entity that receives a federal award directly, or as a subrecipient under a pass-through entity’s award, is subject to 200.303 — it isn’t limited to entities that cross the Single Audit expenditure threshold. The Single Audit is where compliance gets tested and formally reported; the underlying obligation to maintain effective internal controls applies to every recipient and subrecipient, regardless of size.

What’s the difference between a control deficiency, a significant deficiency, and a material weakness?

They describe increasing severity of the same underlying problem — a control that doesn’t prevent or catch a misstatement or instance of noncompliance. A control deficiency is the mildest; a significant deficiency is serious enough to warrant attention from institutional oversight; a material weakness is severe enough that there’s a reasonable possibility material noncompliance would go undetected, and is the classification most likely to trigger additional agency scrutiny.

Does 2 CFR 200.303 require a specific internal control framework, like COSO?

No. It names the GAO Green Book and the COSO Internal Control–Integrated Framework as acceptable reference standards, but doesn’t mandate either one specifically, and doesn’t prohibit an institution from using an equivalent framework so long as its actual control system meets the reasonable-assurance standard the regulation describes.

How do internal controls relate to subrecipient monitoring?

Subrecipient monitoring is one specific application of the broader internal-control obligation: a pass-through entity’s control system has to extend to how it assesses subrecipient risk, monitors subrecipient compliance, and follows up on subrecipient audit findings, per 2 CFR 200.332 — see subrecipient monitoring for the operational detail.

What happens after a Single Audit reports an internal control finding?

The auditee is required to prepare a corrective action plan addressing each finding, and the federal awarding or cognizant agency reviews it as part of audit resolution. A material weakness finding can also factor into an agency’s risk assessment of the institution for future awards, independent of the specific corrective action taken.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →