Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & Research SupplyReagents, PPE & instruments — chain-of-custody documented.Fast, traceable sourcing built for regulated research environments, from bench consumables to instrumentation.Shop lac.us CodeCASRAIlac.us

The Single Audit (2 CFR 200 Subpart F): Requirements and Thresholds

The $1,000,000 expenditure threshold, how major programs are determined, what belongs on the SEFA, the Compliance Supplement’s role, questioned-cost reporting, and the Federal Audit Clearinghouse submission deadline under 2 CFR 200 Subpart F.

Ask about The Single Audit (2 CFR 200 Subpart F): Requirements and Thresholds

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

A Single Audit is the organization-wide audit of an entity’s financial statements and its federal awards that a non-federal entity (a state, local government, Indian tribe, institution of higher education, or nonprofit organization) must obtain when it spends federal awards above a set dollar threshold in a fiscal year. It is governed by 2 CFR 200 Subpart F (§§ 200.500–200.521), the audit-requirements subpart of the Uniform Guidance, and it replaced audit-by-audit federal agency review with one consolidated, government-wide audit that covers every federal award an entity received. This guide sets out the current expenditure threshold, how major programs are selected, what the Schedule of Expenditures of Federal Awards (SEFA) must contain, the role of the OMB Compliance Supplement, how audit findings and questioned costs are reported, and the Federal Audit Clearinghouse (FAC) submission deadline — with a single reference table for the thresholds and deadlines that matter most.

Last verified: 16 August 2026, against the current text of 2 CFR 200 Subpart F (eCFR/Cornell LII), fac.gov, and OMB’s pending proposed revision to the Uniform Guidance. See the accuracy note at the end of this guide before relying on any figure here in a live compliance decision — always confirm against the current regulatory text.

What triggers a Single Audit: the expenditure threshold

Under 2 CFR 200.501(a), a non-federal entity that expends $1,000,000 or more in federal awards during its fiscal year must have a Single Audit or a program-specific audit conducted for that year. An entity that expends less than that threshold in a given fiscal year is exempt from the Subpart F audit requirement for that year (though it must still make records available for review by federal agencies and pass-through entities).

This threshold was raised from $750,000 to $1,000,000 by OMB’s April 2024 revision to the Uniform Guidance, and the higher figure applies to non-federal entity fiscal years beginning on or after October 1, 2024. An entity whose fiscal year began before that date is still measured against the older $750,000 threshold for that audit period. Because this is exactly the kind of figure that changes with regulatory revisions, confirm the threshold against the current text of 2 CFR 200.501 before using it to decide whether an audit is required — do not assume either figure without checking the entity’s specific fiscal year.

Single Audit vs. program-specific audit

An entity that meets the expenditure threshold has two options, set out in 2 CFR 200.507:

  • Single Audit (the default): an organization-wide audit covering the entity’s financial statements as a whole plus its federal award expenditures, required whenever the entity expended federal awards under more than one federal program.
  • Program-specific audit: available only when the entity expended federal awards under a single federal program (excluding research and development awards, which are always treated as a cluster) and the federal statutes, regulations, or the terms of the award do not require a financial-statement audit of the entity as a whole. Where a program-specific audit guide exists for that program, the auditor follows it; where none exists, the entity arranges an audit that meets the general Subpart F audit requirements applied to that one program.

In practice the large majority of entities crossing the threshold receive multiple federal awards from different programs and therefore undergo the standard Single Audit rather than a program-specific audit.

How major programs are determined: the risk-based approach

A Single Audit does not test every federal program an entity received — it tests a risk-based subset called major programs, selected under the process in 2 CFR 200.518. The mechanics:

Type A vs. Type B programs

Every federal program (or program cluster) an entity received is first classified as Type A or Type B based on the dollar threshold in the table below, which scales with the entity’s total federal expenditure for the year. A program at or above the applicable Type A dollar threshold is a Type A program; everything below it is Type B.

Risk assessment

Auditors then apply a risk assessment: Type A programs are evaluated for risk (a Type A program not audited as major in either of the two most recent audit periods, or one with certain prior findings, is treated as higher-risk and must be audited as major); Type B programs above a set size are screened for high-risk characteristics, and auditors are not required to identify more high-risk Type B programs for testing than roughly one-quarter of the number of low-risk Type A programs, absent identified material weaknesses or significant compliance issues.

The percentage-of-coverage rule

The programs selected as major must, in total, cover a minimum share of the entity’s total federal expenditure: at least 20 percent for an entity that qualifies as “low-risk” under the auditee criteria in 2 CFR 200.520 (broadly: a track record of unmodified audit opinions, no material weaknesses, and no material Type A program findings on recent audits, among other conditions), or at least 40 percent for any other (“higher-risk”) auditee. The practical effect is that a first-time or previously problematic auditee sees roughly double the share of its federal spending tested compared with an entity with a clean recent audit history.

The Schedule of Expenditures of Federal Awards (SEFA)

The SEFA is the entity-prepared schedule, required by 2 CFR 200.510, that lists every federal award the entity expended during the audit period — it is the document the Single Audit’s compliance testing is built around, and preparing it accurately is management’s responsibility, not the auditor’s. Per 200.510(b), the SEFA must:

  • List individual federal programs by federal awarding agency, using the applicable Assistance Listing number(s) (formerly CFDA numbers) for each;
  • For a program cluster, provide the cluster name and list the individual programs within it, each with its own Assistance Listing number and awarding agency;
  • For research and development awards, show total expenditures either by individual award or by federal agency and major subdivision within the agency;
  • Identify amounts passed through to subrecipients from each federal program, and, for a pass-through entity, the name of the pass-through entity and any identifying number it assigned;
  • For loan and loan guarantee programs, disclose outstanding balances at year-end in the notes;
  • Include notes describing the significant accounting policies used to prepare the schedule (e.g., cash vs. accrual basis) and whether the entity elected to use the de minimis indirect cost rate.

The independent auditor must then render an opinion on whether the SEFA is fairly stated in relation to the entity’s financial statements as a whole — a materially inaccurate or incomplete SEFA is itself a common source of audit findings.

The OMB Compliance Supplement

The Compliance Supplement is an annual publication issued by OMB that tells Single Audit auditors, program by program, which specific compliance requirements (allowable costs, eligibility, matching, reporting, procurement, and others) are actually subject to testing for that federal program, and what the audit procedures for testing them should look like. It is the practical bridge between the general requirements in Subpart F and the hundreds of individual federal programs an auditor might encounter — without it, auditors would have no consistent basis for deciding which of a program’s many statutory and regulatory requirements are “direct and material” enough to test. OMB typically releases an updated Compliance Supplement each spring/summer covering the audit period beginning in the prior federal fiscal year, with a technical-correction addendum sometimes following later in the year; auditors and entities preparing for an upcoming Single Audit should always confirm they are working from the current-year edition rather than a prior year’s supplement, since program-specific testing requirements can and do change annually.

Audit findings and questioned costs

Auditors report the results of their compliance testing as audit findings under 2 CFR 200.516. A finding must be reported when the auditor identifies, among other conditions:

  • A significant deficiency or material weakness in internal control over a major program;
  • Material noncompliance with a federal statute, regulation, or the terms of a federal award related to a major program;
  • Known or likely questioned costs greater than $25,000 for a type of compliance requirement for a major program;
  • Known or likely questioned costs greater than $25,000 for a federal program that was not audited as a major program;
  • Known fraud affecting a federal award, unless clearly inconsequential; and
  • Instances where the SEFA is materially misstated.

Questioned costs are costs the auditor believes may not be allowable, reasonable, allocable, or properly documented under the terms of the award or the cost principles in 2 CFR 200 Subpart E — they are “questioned,” not automatically disallowed; the federal awarding agency or pass-through entity makes the final determination on whether to sustain the finding and require repayment, offset against future draws, or accept the entity’s explanation. Each reported finding must include enough detail for the entity and the federal agency to understand the condition, criteria, cause, effect, and questioned-cost amount (if any), plus the auditor’s recommendation.

Corrective action plans and the summary schedule of prior audit findings

Two follow-up documents, required by 2 CFR 200.511, close the loop on findings:

  • Summary schedule of prior audit findings: prepared by the auditee, reporting the status of corrective action on every finding from the prior audit’s schedule of findings and questioned costs — either that it was fully corrected, partially corrected (with an explanation and planned completion date), or that no corrective action was taken (with a reason).
  • Corrective action plan: prepared by the auditee for the current audit’s findings, identifying a named contact responsible for corrective action, the specific action planned, and an anticipated completion date for each finding.

Both documents are submitted as part of the reporting package alongside the audit itself, and a federal agency reviewing an entity’s audit history will look at the summary schedule specifically for repeat findings — the same finding recurring across multiple audit cycles is itself a signal used in the high-risk auditee determinations described above.

Reporting package submission: the Federal Audit Clearinghouse

The completed reporting package — financial statements, SEFA, schedule of findings and questioned costs, corrective action plan, summary schedule of prior audit findings, and the auditor’s reports — along with a Data Collection Form, must be submitted electronically to the Federal Audit Clearinghouse (FAC) at fac.gov. The FAC is the government-wide repository for Single Audit results; it moved from the U.S. Census Bureau to the General Services Administration (GSA), which launched the current fac.gov submission platform in October 2023. Federal agencies and pass-through entities use the FAC, rather than requesting audit reports directly, to satisfy their own oversight obligations for recipients and subrecipients.

Per 2 CFR 200.512(a)(1), the deadline to submit the reporting package to the FAC is the earlier of:

  • 30 calendar days after the entity receives the auditor’s report(s), or
  • 9 months after the end of the audit period.

Missing this deadline, or failing to have a required audit performed at all, can itself trigger a high-risk designation and additional federal agency scrutiny on future awards — separate from any findings the audit itself produces.

Reference table: Single Audit thresholds and deadlines

Item Current figure Citation
Expenditure threshold triggering a Single Audit $1,000,000 (fiscal years beginning on/after Oct. 1, 2024; $750,000 for earlier fiscal years) 2 CFR 200.501(a)
Type A program threshold, $1M–$34M total federal expenditure $1,000,000 2 CFR 200.518(b)
Type A program threshold, over $34M–$100M Total federal awards expended × 0.03 2 CFR 200.518(b)
Type A program threshold, over $100M–$1B $3,000,000 2 CFR 200.518(b)
Type A program threshold, over $1B–$10B Total federal awards expended × 0.003 2 CFR 200.518(b)
Type A program threshold, over $10B–$20B $30,000,000 2 CFR 200.518(b)
Type A program threshold, over $20B Total federal awards expended × 0.0015 2 CFR 200.518(b)
Major program coverage, low-risk auditee At least 20% of total federal expenditure 2 CFR 200.518(f)(1)
Major program coverage, higher-risk auditee At least 40% of total federal expenditure 2 CFR 200.518(f)(2)
Questioned-cost reporting threshold (per finding type/program) Greater than $25,000 2 CFR 200.516(a)
Reporting package submission deadline (FAC) Earlier of 30 days after receiving the auditor’s report, or 9 months after audit-period end 2 CFR 200.512(a)(1)

Frequently asked questions

What is a SEFA report?

The SEFA (Schedule of Expenditures of Federal Awards) is the entity-prepared schedule listing every federal award expended during the audit period, organized by federal program and Assistance Listing number, that forms the basis for the auditor’s Single Audit testing. See the SEFA section above for exactly what it must contain under 2 CFR 200.510.

Does an organization under the $1,000,000 threshold ever need an audit of its federal awards?

Not a Subpart F Single Audit or program-specific audit — those are not required below the threshold. Individual award terms, a specific federal program’s authorizing statute, or a pass-through entity’s own subrecipient monitoring obligations under 2 CFR 200.332 can still impose other review requirements, so the absence of a Subpart F trigger does not automatically mean no financial oversight applies.

Who actually determines whether questioned costs must be repaid?

The auditor identifies and reports questioned costs; the federal awarding agency (for a direct award) or the pass-through entity (for a subaward) makes the final resolution — sustaining the finding and requiring repayment or an offset, or accepting the entity’s response and clearing it.

Is 2 CFR 200 about to be renamed?

OMB published a proposed rule (Federal Register 2026-10817, May 29, 2026) that would substantially revise the Uniform Guidance and rebrand the informal usage of Part 200 as the “Uniform Grants Regulation” (UGR), reflecting a shift toward treating it as a binding regulation rather than sub-regulatory guidance; the formal Part 200 title itself would not change. As of this guide’s last-verified date, that rule remains proposed, not final — the public comment period closed in July 2026, and OMB has not published a final rule. Confirm current status at the Federal Register before assuming any change to Subpart F’s requirements or thresholds has taken effect.

Related CASRAI resources

Accuracy note: This guide reflects 2 CFR 200 Subpart F as currently in effect and OMB’s Compliance Supplement process as of the last-verified date above. The single-audit expenditure threshold changed in 2024 and OMB has a further, more sweeping revision to the Uniform Guidance under proposal (not yet final) as of this writing — always confirm the applicable threshold and requirements against the current eCFR text of 2 CFR 200 Subpart F and the current-year OMB Compliance Supplement before relying on this guide for a specific compliance determination.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →