Skip to main content
v2026.11,858 entries · CC-BY 4.0

SF-SAC (Data Collection Form): What Auditees Actually File

The SF-SAC / Data Collection Form has eight workbook sections filed to the FAC, a certification only the auditee (not the auditor) can sign, and a 30-day/9-month deadline under 2 CFR 200.512.

Written and maintained by CASRAI Editorial Board

Last updated

The SF-SAC is the Data Collection Form — the OMB-approved form every non-federal entity spending $1,000,000 or more in federal awards in a fiscal year must complete and submit, electronically, to the Federal Audit Clearinghouse (FAC). It is not the audit itself; it is the structured record of the audit’s results — the auditee, the federal programs it ran, and what the auditor found — and it is filed as eight separate online workbooks, not a single PDF. This page covers what those eight sections actually contain, who is legally required to sign the certification, and when the form is due, for the standard Single Audit path under 2 CFR 200.501.

What the SF-SAC Actually Contains: Eight Workbook Sections

On the current fac.gov platform, “the SF-SAC” means eight separate workbooks, uploaded individually. Three of the eight are optional and only apply to a subset of auditees:

Section What it captures Required?
1. Federal Awards Every federal award the auditee received and expended during the audit period Always
2. Notes to SEFA Supplementary disclosures explaining the Schedule of Expenditures of Federal Awards figures Always
3. Federal Awards Audit Findings Structured, per-finding data on any compliance or internal-control findings the audit turned up Always (blank if no findings)
4. Federal Awards Audit Findings Text The narrative write-up behind each finding logged in Section 3 Always (blank if no findings)
5. Corrective Action Plan Management’s proposed remedy for each current-year finding Only if Section 3 has findings
6. Additional UEIs Unique Entity Identifiers for any additional legal entities covered by the same audit Optional
7. Secondary Auditors Identifies any co-auditor firm involved in the engagement Optional
8. Additional EINs Employer Identification Numbers for any additional entities beyond the primary auditee Optional

Sections 6 through 8 exist because a single audit sometimes covers more than one legal entity or identifier — a university system auditing several campuses under one engagement, for example — and the FAC needs a way to tie all of them to the same submission without forcing separate filings.

Who Signs It, and What They’re Certifying

The data collection form is not the auditor’s document to sign. Under 2 CFR 200.512(b)(1), a senior-level representative of the auditee — a state controller, finance director, chief executive officer, or chief financial officer — must sign a certification statement affirming that:

  • the auditee complied with the requirements of 2 CFR 200 Subpart F;
  • the data collection form was prepared in accordance with Subpart F;
  • the information is accurate and complete in its entirety;
  • the form excludes protected personally identifiable information; and
  • the auditee authorizes the FAC to make the form and reporting package publicly available.

In practice, audit or grants-compliance staff typically assemble the workbooks with the external auditor, but the signature and the legal responsibility for what it says belong to the auditee’s own senior official, not the audit firm.

When It’s Due

Under 2 CFR 200.512(a)(1), the SF-SAC and the full reporting package are due the earlier of 30 calendar days after the auditee receives the auditor’s report(s), or nine months after the end of the audit period. The deadline mechanics, cognizant-agency extensions, and what a late filing costs an institution’s low-risk-auditee status under the Single Audit rules are covered in full in CASRAI’s Federal Audit Clearinghouse (FAC) guide — this page is about the form itself, that one is about the submission process around it.

The Paper Form Is Obsolete — Everything Is Electronic Workbooks Now

If you find a PDF labeled “SF-SAC” while searching, check the date. GSA’s own forms library lists the standalone SF-SAC form as obsolete, with a note that it “has been replaced with the Federal Audit Clearinghouse (FAC)” and its online workbook system. There is no separate downloadable SF-SAC form to fill out and mail or upload as one document — auditees complete the eight sections above directly in the FAC’s web application at fac.gov.

Where Each of These Requirements Is Written Down

Requirement Authority Where to read it
$1,000,000 audit threshold 2 CFR 200.501(a) eCFR §200.501
30-day / 9-month FAC submission deadline 2 CFR 200.512(a)(1) eCFR §200.512
Data collection form certification requirements 2 CFR 200.512(b)(1) eCFR §200.512
3-year retention of the form and reporting package 2 CFR 200.512(f) eCFR §200.512
Program-specific audits also require the data collection form 2 CFR 200.507(c)(2)–(3) eCFR §200.507
The eight current workbook sections GSA / Federal Audit Clearinghouse fac.gov — SF-SAC workbooks
Paper SF-SAC form status (obsolete) GSA Forms Library GSA forms record

What This Page Cannot Tell You

Three things decide which sections you actually complete and how your filing gets handled, and none of them are answered above because they are specific to your audit:

  • Whether you’re filing a full Single Audit or an elected program-specific audit — a program-specific audit still requires a data collection form under 2 CFR 200.507(c), but the underlying reporting package follows that program’s own audit guide, not the Single Audit package this page walks through.
  • Who your cognizant or oversight agency for audit is — that’s the agency you’d request a deadline extension from, and it’s assigned based on your institution’s federal funding, not fixed by rule.
  • Whether Sections 6 and 8 apply to your submission — that depends on whether your audit covers more than one legal entity or Unique Entity Identifier, an institution-specific fact about how your audit was scoped.

Checking this against the current guidance

Whether a program-specific audit changes which of the eight SF-SAC sections you complete depends on the federal program and its own audit guide, and the walkthrough above covers the standard Single Audit path only.

Ask CASRAI: If an entity has a program-specific audit instead of a full Single Audit, does it still have to file an SF-SAC Data Collection Form, and does the same eight-section structure apply?

It searches CASRAI’s indexed corpus of research-administration guidance and cites the passage behind each claim, so you can open the source and check it rather than take its word — and it says so when the corpus does not cover something instead of guessing. Two questions a day are free while you are signed out, no account and no card. Everything CASRAI publishes stays free to read. Your first free question is the one in that link — save the second for whichever institution-specific fact from the list above actually applies to your audit.

Frequently asked questions

If an entity has a program-specific audit instead of a full Single Audit, does it still have to file an SF-SAC Data Collection Form, and does the same eight-section structure apply?

Yes, filing is still required. 2 CFR 200.507(c)(2)–(3) requires an auditee completing a program-specific audit to electronically submit a data collection form “prepared in accordance with § 200.512(b)” to the FAC, whether or not a program-specific audit guide exists for that program. What differs is the reporting package underneath it: a program-specific audit follows that program’s own audit guide (or, where none exists, the financial-statement-audit approach described in 200.507(c)(3)) rather than the Single Audit package this page walks through, so exactly which of the eight workbook sections apply in practice depends on the specific federal program governing that audit — not something this page can generalize across every program.

Is the SF-SAC the same thing as the Schedule of Expenditures of Federal Awards (SEFA)?

No. The SEFA is a schedule the auditee’s own financial statements produce, listing federal awards expended during the period; it’s part of the reporting package the audit examines. The SF-SAC is the separate data-collection form that summarizes and certifies information about that audit — Section 2 of the SF-SAC (“Notes to SEFA”) captures supplementary disclosures about the SEFA, but the SEFA itself is a different document produced earlier in the process, not a section of the SF-SAC.

Does the auditor complete and sign the SF-SAC?

No. The auditee’s own senior-level representative — not the audit firm — signs the certification statement required by 2 CFR 200.512(b)(1). Audit and grants-compliance staff commonly work with the auditor to assemble the workbook data, but the signature, and the legal responsibility for the form’s accuracy, sits with the auditee.

What happens if an audit reports zero findings — do Sections 3 through 5 still need to be completed?

Sections 1 (Federal Awards) and 2 (Notes to SEFA) and the certification are required on every submission regardless of outcome. Sections 3 and 4 exist specifically to report findings, so an audit with none has nothing substantive to enter there, and Section 5 (Corrective Action Plan) only applies when Section 3 has a finding to correct — the FAC’s own workbook instructions govern the exact mechanics of recording a no-findings result, which this page does not reproduce.

Is there still a downloadable SF-SAC PDF form?

No. GSA’s forms library lists the standalone SF-SAC form as obsolete, superseded by the Federal Audit Clearinghouse’s online workbook system at fac.gov. The eight sections described above are completed directly in that web application, not on a separate document.

References

  • 2 CFR 200.501(a), Audit Requirements (eCFR).
  • 2 CFR 200.507(c), Program-specific audits (eCFR).
  • 2 CFR 200.512(a), (b), (f), Report submission (eCFR).
  • GSA, Federal Audit Clearinghouse (fac.gov) — SF-SAC workbook sections.
  • GSA Forms Library — Data Collection Form on Reporting for Single Audits (SF-SAC), status: obsolete.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · included with Regulatory Radar

Ask about SF-SAC (Data Collection Form): What Auditees Actually File

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.