An OIG audit of a research grant is a targeted review that a federal funding agency’s own Office of Inspector General conducts of a specific institution’s award activity — distinct from the annual, organization-wide Single Audit every institution above a federal spending threshold must arrange for itself. This guide covers what typically triggers an OIG audit of research-grant activity, how the audit process actually runs, the findings that recur most often at research institutions, and how institutions are expected to respond once a report is issued. For background on what OIG reports are and the other report types OIGs publish (Semiannual Reports, Work Plans, compliance alerts), see the OIG Reports term; this guide focuses specifically on the audit process itself.
What Triggers an OIG Audit of a Research Grant
OIG audit offices — HHS-OIG’s Office of Audit Services is the one most research institutions with NIH or other HHS funding will encounter — do not audit every grantee, and audit selection is rarely random. Several overlapping pathways typically lead to a specific institution or award being selected:
- Risk-based selection. OIGs use data analytics and risk indicators (award size, prior audit history, sector-wide risk patterns identified across the grantee population) to prioritize where a review is likely to find problems, rather than auditing on a fixed rotation.
- Published Work Plan items. Many OIGs, HHS-OIG’s most closely watched among them in the research-funding space, publish a forward-looking Work Plan of audits and reviews currently planned or underway, often organized by topic (for example, a Work Plan cycle focused on effort reporting or subrecipient monitoring across a set of institutions) rather than by named institution up front.
- Complaints and hotline tips. Every OIG operates a public hotline for reporting suspected fraud, waste, or abuse; a credible complaint concerning a specific award or investigator can open an audit or investigation independent of any risk-scoring process.
- Referral from a Single Audit finding. A significant deficiency or finding identified during an institution’s own annual Single Audit (required under 2 CFR Part 200 Subpart F for non-federal entities spending federal funds above the statutory threshold) can prompt the cognizant or oversight agency’s OIG to open a more targeted follow-up review.
- Prior findings or a pattern across awards. An institution with a recent history of disallowed costs, late corrective actions, or repeat findings is a more likely subject for follow-up audit activity than one with a clean compliance record.
Because a Single Audit finding is one of the more common paths into an OIG audit, institutions that treat their own Single Audit seriously — resolving findings promptly and documenting corrective action — reduce, though don’t eliminate, the likelihood of a subsequent targeted OIG review.
The Audit Process, Step by Step
Federal OIG audits, including those conducted under Generally Accepted Government Auditing Standards (GAGAS, the “Yellow Book” issued by GAO), follow a broadly consistent structure across agencies, though specific timeframes vary:
1. Notification and entrance conference
The institution is formally notified that it has been selected for audit, and an entrance conference is held between OIG audit staff and institutional officials (typically the sponsored programs office, the audited department, and often institutional counsel or compliance). The entrance conference sets the audit’s scope and objectives, the period under review, the specific award(s) or activity involved, and the auditors’ initial information requests.
2. Fieldwork and document requests
Auditors review financial records, effort certifications, subaward files, procurement documentation, and internal-control policies against the award terms and applicable regulation (2 CFR Part 200 for most research grants). This stage typically involves formal, itemized document requests, follow-up requests as auditors narrow in on specific transactions or time periods, and interviews with relevant staff — principal investigators, department administrators, and central sponsored-programs or compliance staff. Fieldwork is usually the longest phase of the audit and the one where an institution’s own recordkeeping quality most directly affects the outcome.
3. Exit conference
Once fieldwork concludes, auditors hold an exit conference to walk institutional officials through preliminary findings before the draft report is issued — an opportunity to clarify factual questions or surface documentation the auditors may not have received, though not a substitute for the institution’s formal written response.
4. Draft report and institutional response
OIG issues a draft report stating findings, any questioned costs the auditors believe were improperly charged, and recommendations — typically including a specific disallowance amount the report recommends the awarding agency recover. The institution is given a defined window (commonly on the order of 10-30 days depending on the OIG and the audit’s complexity) to submit written comments, which are then incorporated into, or appended to, the final report.
5. Final report and resolution
OIG issues the final report, including the institution’s response. Resolution — the awarding agency’s final management decision on whether, and how much, to recover — is a separate step from the audit itself: the agency, not OIG, makes that determination. Under 2 CFR 200.521, a Federal awarding agency or pass-through entity must issue a management decision on Single Audit findings within six months of the audit report’s acceptance; OIG-initiated audits of individual awards are generally expected to follow a comparable resolution timeframe under agency-specific audit-resolution policy, though the OIG report itself is not the final word on the amount owed.
Common OIG Findings in Research-Institution Audits
Certain categories of finding recur disproportionately in OIG audits of research grants, largely because they involve judgment calls, estimation, or multi-party recordkeeping rather than a simple invoice match:
- Effort reporting. Certified effort that doesn’t reasonably reflect the work actually performed on a sponsored project — salary charged to a grant for effort that was, in practice, spent on unrelated activity — is one of the single most common finding categories in research-grant audits. See the CASRAI guide on effort reporting methodologies for how institutions structure certification to reduce this risk.
- Cost allocation and allowability. Costs charged directly to an award that should have been treated as facilities-and-administrative (indirect) costs, or costs that fail the basic allowable/allocable/reasonable test under 2 CFR Part 200 Subpart E, are a recurring finding — see the CASRAI guide to Uniform Guidance (2 CFR 200) for the underlying cost-principle framework.
- Subrecipient monitoring. Where a prime recipient passes federal funds to a subrecipient, auditors routinely test whether the prime actually monitored that subrecipient’s spending, risk profile, and single-audit status as required — inadequate subrecipient monitoring of a subaward is a common finding category, particularly where subrecipient documentation was accepted without independent verification. See also the CASRAI guide on subaward agreement negotiation.
- Cost transfers. Late, unexplained, or poorly documented transfers of costs between awards — especially transfers moving costs onto a grant near the end of its budget period — draw auditor attention because they can indicate an attempt to use up remaining award balance rather than reflect the actual project the cost benefited.
- Time-and-effort certification timing and documentation gaps. Certifications completed long after the period they cover, or completed by someone without direct knowledge of the work performed, weaken the underlying evidence even where the effort itself was legitimate.
These same categories are also the ones OIG Work Plans most frequently flag as ongoing areas of focus, which is why compliance offices use published Work Plans and prior audit reports at peer institutions as a proactive testing checklist rather than waiting to be the audit subject themselves.
Institutional Response and the Corrective Action Plan
An OIG audit finding is rarely the end of the process for an institution — it typically opens a corrective action plan (CAP) requirement, separate from any cost repayment. A credible CAP generally addresses:
- Root cause, not just the symptom. Auditors and awarding agencies expect the CAP to identify why the control gap existed (for example, a training gap, an unclear policy, or a missing verification step) rather than describing only the specific transaction corrected.
- Specific, dated remediation steps. Vague commitments to “improve oversight” are weaker than concrete steps with named owners and deadlines — updated policy language, a new verification checkpoint, revised training, or a system control.
- Evidence the fix actually took effect. Institutions are typically expected to demonstrate, not just assert, that the corrective action was implemented — through follow-up testing, a subsequent audit cycle, or periodic status reporting to the awarding agency until the finding is formally closed.
- Coordination with the institution’s broader internal-controls program. A single-award finding often signals a control gap that could affect other awards; institutions that use an OIG finding to test and strengthen controls institution-wide, rather than treating it as an isolated fix, are better positioned if a similar issue arises on a different award. See the CASRAI guide to internal controls for federal grant compliance.
In serious cases — findings involving falsified data, knowing misrepresentation, or a pattern the awarding agency refers for further review — an audit finding can lead to a False Claims Act referral, which carries civil penalties and treble damages well beyond the disallowed cost amount itself. See the CASRAI guide on the False Claims Act in research grant compliance.
OIG Audit vs. Single Audit vs. Programmatic Site Visit
These three oversight mechanisms are often confused but are procedurally distinct:
- A Single Audit is an annual, institution-wide financial-statement and compliance audit every qualifying non-federal entity must arrange for itself, covering all of its federal awards collectively, performed by an independent (non-federal) auditor under 2 CFR Part 200 Subpart F.
- An OIG audit is a targeted review a specific agency’s own Inspector General initiates — of one award, one program, or one institution — and can happen independently of, and in addition to, the institution’s own Single Audit cycle.
- A programmatic site visit (conducted by program staff rather than audit staff) reviews scientific or technical progress and general award administration, not financial compliance in the audit sense, and does not produce questioned costs or a formal audit report.
See also the general Audit (grant) term for the broader definition that covers all three.
Frequently Asked Questions
What triggers an OIG audit of a research grant?
Most commonly, risk-based selection using data analytics, a published Work Plan item, a hotline complaint, referral from a Single Audit finding, or an institution’s prior audit history. Institutions are rarely told the specific trigger, only that they’ve been selected and the scope of review.
How long does an OIG audit of a grant take?
It varies substantially by scope and complexity — fieldwork alone can run months, and the full cycle from entrance conference through final report can take a year or more for a complex, multi-award review. There is no single statutory timeline for the audit itself, though resolution of the findings by the awarding agency is generally subject to its own audit-resolution policy.
What happens after an OIG audit finds a problem?
OIG issues a report with findings, questioned costs, and recommendations; the institution submits a written response (usually incorporated into the final report); and the awarding agency — not OIG — issues the final management decision on recovery, typically alongside a required corrective action plan.
Is an OIG audit the same as a Single Audit?
No. A Single Audit is an annual, institution-wide audit every qualifying entity arranges for itself under 2 CFR Part 200 Subpart F. An OIG audit is a targeted review the agency’s own Inspector General initiates, often (but not always) prompted by something a Single Audit, complaint, or Work Plan surfaced.
Who has to sign off on a corrective action plan?
This varies by institution, but a CAP responding to a federal audit finding typically requires sign-off from the sponsored programs or compliance office and, for significant findings, institutional leadership (a vice president for research or comparable role), since the institution is formally certifying to the federal awarding agency that specific remediation steps will be taken.
Related CASRAI Content
See also: OIG Reports, Single Audit (US), Audit (grant), Subrecipient monitoring, Subaward, Uniform Guidance (2 CFR 200), Institutional Internal Controls for Federal Grant Compliance, Federal Grant Compliance Checklist, Effort Reporting Methodologies, The False Claims Act in Research Grant Compliance, and the Grants Management pillar.
References
- Inspector General Act of 1978, Pub. L. 95-452, as amended.
- 2 CFR Part 200 (Uniform Guidance), including Subpart E (Cost Principles), Subpart F (Audit Requirements), and 200.521 (Management decision).
- Government Accountability Office, Government Auditing Standards (GAGAS / “Yellow Book”).
- HHS Office of Inspector General, Reports and Publications: oig.hhs.gov/reports/.
- HHS Office of Inspector General, Single Audit oversight activities: oig.hhs.gov/compliance/single-audits/hhs-oig-oversight-activities/.
- NSF Office of Inspector General, Reports: oig.nsf.gov/reports-publications/reports.







