Written and maintained by CASRAI Editorial Board
Last updated
The SF-SAC is the Data Collection Form — the OMB-approved form every non-federal entity spending $1,000,000 or more in federal awards in a fiscal year must complete and submit, electronically, to the Federal Audit Clearinghouse (FAC). It is not the audit itself; it is the structured record of the audit’s results — the auditee, the federal programs it ran, and what the auditor found — and it is filed as eight separate online workbooks, not a single PDF. This page covers what those eight sections actually contain, who is legally required to sign the certification, and when the form is due, for the standard Single Audit path under 2 CFR 200.501.
What the SF-SAC Actually Contains: Eight Workbook Sections
On the current fac.gov platform, “the SF-SAC” means eight separate workbooks, uploaded individually. Three of the eight are optional and only apply to a subset of auditees:
| Section | What it captures | Required? |
|---|---|---|
| 1. Federal Awards | Every federal award the auditee received and expended during the audit period | Always |
| 2. Notes to SEFA | Supplementary disclosures explaining the Schedule of Expenditures of Federal Awards figures | Always |
| 3. Federal Awards Audit Findings | Structured, per-finding data on any compliance or internal-control findings the audit turned up | Always (blank if no findings) |
| 4. Federal Awards Audit Findings Text | The narrative write-up behind each finding logged in Section 3 | Always (blank if no findings) |
| 5. Corrective Action Plan | Management’s proposed remedy for each current-year finding | Only if Section 3 has findings |
| 6. Additional UEIs | Unique Entity Identifiers for any additional legal entities covered by the same audit | Optional |
| 7. Secondary Auditors | Identifies any co-auditor firm involved in the engagement | Optional |
| 8. Additional EINs | Employer Identification Numbers for any additional entities beyond the primary auditee | Optional |
Sections 6 through 8 exist because a single audit sometimes covers more than one legal entity or identifier — a university system auditing several campuses under one engagement, for example — and the FAC needs a way to tie all of them to the same submission without forcing separate filings.
Who Signs It, and What They’re Certifying
The data collection form is not the auditor’s document to sign. Under 2 CFR 200.512(b)(1), a senior-level representative of the auditee — a state controller, finance director, chief executive officer, or chief financial officer — must sign a certification statement affirming that:
- the auditee complied with the requirements of 2 CFR 200 Subpart F;
- the data collection form was prepared in accordance with Subpart F;
- the information is accurate and complete in its entirety;
- the form excludes protected personally identifiable information; and
- the auditee authorizes the FAC to make the form and reporting package publicly available.
In practice, audit or grants-compliance staff typically assemble the workbooks with the external auditor, but the signature and the legal responsibility for what it says belong to the auditee’s own senior official, not the audit firm.
When It’s Due
Under 2 CFR 200.512(a)(1), the SF-SAC and the full reporting package are due the earlier of 30 calendar days after the auditee receives the auditor’s report(s), or nine months after the end of the audit period. The deadline mechanics, cognizant-agency extensions, and what a late filing costs an institution’s low-risk-auditee status under the Single Audit rules are covered in full in CASRAI’s Federal Audit Clearinghouse (FAC) guide — this page is about the form itself, that one is about the submission process around it.
The Paper Form Is Obsolete — Everything Is Electronic Workbooks Now
If you find a PDF labeled “SF-SAC” while searching, check the date. GSA’s own forms library lists the standalone SF-SAC form as obsolete, with a note that it “has been replaced with the Federal Audit Clearinghouse (FAC)” and its online workbook system. There is no separate downloadable SF-SAC form to fill out and mail or upload as one document — auditees complete the eight sections above directly in the FAC’s web application at fac.gov.
Where Each of These Requirements Is Written Down
| Requirement | Authority | Where to read it |
|---|---|---|
| $1,000,000 audit threshold | 2 CFR 200.501(a) | eCFR §200.501 |
| 30-day / 9-month FAC submission deadline | 2 CFR 200.512(a)(1) | eCFR §200.512 |
| Data collection form certification requirements | 2 CFR 200.512(b)(1) | eCFR §200.512 |
| 3-year retention of the form and reporting package | 2 CFR 200.512(f) | eCFR §200.512 |
| Program-specific audits also require the data collection form | 2 CFR 200.507(c)(2)–(3) | eCFR §200.507 |
| The eight current workbook sections | GSA / Federal Audit Clearinghouse | fac.gov — SF-SAC workbooks |
| Paper SF-SAC form status (obsolete) | GSA Forms Library | GSA forms record |
What This Page Cannot Tell You
Three things decide which sections you actually complete and how your filing gets handled, and none of them are answered above because they are specific to your audit:
- Whether you’re filing a full Single Audit or an elected program-specific audit — a program-specific audit still requires a data collection form under 2 CFR 200.507(c), but the underlying reporting package follows that program’s own audit guide, not the Single Audit package this page walks through.
- Who your cognizant or oversight agency for audit is — that’s the agency you’d request a deadline extension from, and it’s assigned based on your institution’s federal funding, not fixed by rule.
- Whether Sections 6 and 8 apply to your submission — that depends on whether your audit covers more than one legal entity or Unique Entity Identifier, an institution-specific fact about how your audit was scoped.
Checking this against the current guidance
Whether a program-specific audit changes which of the eight SF-SAC sections you complete depends on the federal program and its own audit guide, and the walkthrough above covers the standard Single Audit path only.
It searches CASRAI’s indexed corpus of research-administration guidance and cites the passage behind each claim, so you can open the source and check it rather than take its word — and it says so when the corpus does not cover something instead of guessing. Two questions a day are free while you are signed out, no account and no card. Everything CASRAI publishes stays free to read. Your first free question is the one in that link — save the second for whichever institution-specific fact from the list above actually applies to your audit.
Frequently asked questions
If an entity has a program-specific audit instead of a full Single Audit, does it still have to file an SF-SAC Data Collection Form, and does the same eight-section structure apply?
Yes, filing is still required. 2 CFR 200.507(c)(2)–(3) requires an auditee completing a program-specific audit to electronically submit a data collection form “prepared in accordance with § 200.512(b)” to the FAC, whether or not a program-specific audit guide exists for that program. What differs is the reporting package underneath it: a program-specific audit follows that program’s own audit guide (or, where none exists, the financial-statement-audit approach described in 200.507(c)(3)) rather than the Single Audit package this page walks through, so exactly which of the eight workbook sections apply in practice depends on the specific federal program governing that audit — not something this page can generalize across every program.
Is the SF-SAC the same thing as the Schedule of Expenditures of Federal Awards (SEFA)?
No. The SEFA is a schedule the auditee’s own financial statements produce, listing federal awards expended during the period; it’s part of the reporting package the audit examines. The SF-SAC is the separate data-collection form that summarizes and certifies information about that audit — Section 2 of the SF-SAC (“Notes to SEFA”) captures supplementary disclosures about the SEFA, but the SEFA itself is a different document produced earlier in the process, not a section of the SF-SAC.
Does the auditor complete and sign the SF-SAC?
No. The auditee’s own senior-level representative — not the audit firm — signs the certification statement required by 2 CFR 200.512(b)(1). Audit and grants-compliance staff commonly work with the auditor to assemble the workbook data, but the signature, and the legal responsibility for the form’s accuracy, sits with the auditee.
What happens if an audit reports zero findings — do Sections 3 through 5 still need to be completed?
Sections 1 (Federal Awards) and 2 (Notes to SEFA) and the certification are required on every submission regardless of outcome. Sections 3 and 4 exist specifically to report findings, so an audit with none has nothing substantive to enter there, and Section 5 (Corrective Action Plan) only applies when Section 3 has a finding to correct — the FAC’s own workbook instructions govern the exact mechanics of recording a no-findings result, which this page does not reproduce.
Is there still a downloadable SF-SAC PDF form?
No. GSA’s forms library lists the standalone SF-SAC form as obsolete, superseded by the Federal Audit Clearinghouse’s online workbook system at fac.gov. The eight sections described above are completed directly in that web application, not on a separate document.
References
- 2 CFR 200.501(a), Audit Requirements (eCFR).
- 2 CFR 200.507(c), Program-specific audits (eCFR).
- 2 CFR 200.512(a), (b), (f), Report submission (eCFR).
- GSA, Federal Audit Clearinghouse (fac.gov) — SF-SAC workbook sections.
- GSA Forms Library — Data Collection Form on Reporting for Single Audits (SF-SAC), status: obsolete.








