Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Single Audit Report Example: Inside a Reporting Package’s Structure

A Single Audit “report” is really a multi-part reporting package. This guide walks through each required component — SEFA, auditor opinions, Schedule of Findings and Questioned Costs, corrective action plan, and FAC submission — under 2 CFR 200 Subpart F.

When people search for a “single audit report example,” what they usually want is not a single document but a look inside a reporting package — the full set of documents an independent auditor and an auditee jointly produce for a US federal Single Audit. That package is a formal, multi-part deliverable prepared under professional auditing standards, not a short form or template that can be usefully mocked up in a page or two. Fabricating a complete illustrative “sample report” risks looking like an imitation of a real, professionally-attested official document, which is not something this page does.

Instead, this guide walks through what a real Single Audit reporting package actually contains, component by component, citing the specific regulatory requirements behind each piece, with one small illustrative excerpt (clearly labeled as a constructed composite, not a real finding) to show the level of detail a finding entry works at. For the underlying definition and applicability threshold, see the CASRAI Single Audit (US) dictionary term; this guide assumes that background and focuses on structure.

“Single Audit Report” Usually Means a Package, Not One Document

The regulation governing Single Audits — 2 CFR Part 200, Subpart F (the audit requirements of the Uniform Guidance) — does not use the phrase “single audit report” as a defined term. What it defines instead, at 2 CFR 200.512(c), is a reporting package, and it specifies exactly what that package must contain. In practice, “the audit report” is shorthand people use for the whole package, or sometimes for just the auditor’s opinion letters within it. Both usages are informal; the regulation is specific.

The Components of a Single Audit Reporting Package

Per 2 CFR 200.512(c), a complete reporting package consists of the following, submitted together to the Federal Audit Clearinghouse (FAC):

1. Financial Statements and the Schedule of Expenditures of Federal Awards (SEFA)

The auditee’s own financial statements, plus the SEFA — a schedule the auditee (not the auditor) prepares, required under 2 CFR 200.510. The SEFA is the document that actually establishes which federal programs were audited and how much federal money moved through the organization that year. Per 200.510(b), it must include, at minimum:

  • Each federal program listed by federal agency, using the applicable Assistance Listing number (the identifier formerly called the CFDA number)
  • For program clusters, the cluster name and the individual programs within it
  • For funds received as a subrecipient, the name of the pass-through entity and the identifying number it assigned
  • Total federal awards expended for each individual program
  • The total amount provided to subrecipients from each federal program
  • For loan or loan guarantee programs, outstanding balances at period end
  • Notes describing significant accounting policies used to prepare the schedule, and whether the organization elected the 15% de minimis indirect cost rate

See also the CASRAI indirect cost recovery term and the guide to 2 CFR 200 Subpart E cost principles for how the de minimis rate election shows up elsewhere in an award’s financial administration.

2. The Auditor’s Reports

Required under 2 CFR 200.515, this is normally several separate opinion letters, not one, because a Single Audit combines a standard financial statement audit (under Government Auditing Standards, the “Yellow Book”) with a compliance audit layered on top (under the Uniform Guidance). A typical set includes:

  • An opinion on whether the financial statements are fairly presented (the standard audit opinion any organization’s financial statements would receive)
  • A report on whether the SEFA is fairly stated “in relation to” the financial statements as a whole
  • A Government Auditing Standards report on internal control over financial reporting and on compliance, based on the financial statement audit
  • A Uniform Guidance report on compliance for each major program and on internal control over compliance, which is the report specific to the Single Audit itself

Each opinion is expressed on a standard scale — unmodified (the equivalent of “clean”), qualified, adverse, or disclaimer — and a non-unmodified opinion on major-program compliance is itself one of the conditions that triggers a reportable finding under 200.516.

3. Schedule of Findings and Questioned Costs

This is usually the part people actually mean when they picture a “Single Audit report.” 2 CFR 200.516 requires it to be organized in three parts:

  • Part I — Summary of Auditor’s Results: a one-page-style summary of the opinions issued, whether any material weaknesses or significant deficiencies were identified, whether the compliance opinion was unmodified, the dollar threshold used to distinguish Type A from Type B programs, and whether the auditee qualified as a low-risk auditee.
  • Part II — Financial Statement Findings: any findings that relate to the financial statement audit but not to a specific federal program.
  • Part III — Federal Award Findings and Questioned Costs: findings tied to a specific major program, including questioned costs.

Per 200.516, a finding must be reported when there is: a significant deficiency or material weakness in internal control over a major program; material noncompliance with federal statutes, regulations, or award terms for a major program; known or likely questioned costs exceeding $25,000 for a compliance requirement type on a major program; known questioned costs exceeding $25,000 on a program not audited as major; a non-unmodified compliance opinion; known or likely fraud affecting a federal award; or a case where the summary schedule of prior audit findings materially misrepresents a prior finding’s status.

Every individual finding, in turn, is required to document a specific set of elements: the federal program and award identification, criteria (what should have happened), condition (what actually happened), cause, effect or potential effect, the questioned-cost computation where applicable, context (isolated instance or systemic issue), whether it is a repeat of a prior finding, a recommendation, and the views of responsible officials at the auditee. See the related CASRAI term on federal grant audits for how a Single Audit finding differs from an agency-initiated program audit.

Findings are also classified by severity, using standard Government Auditing Standards terminology: a control deficiency means a control’s design or operation doesn’t allow timely prevention, detection, or correction of a misstatement or instance of noncompliance; a significant deficiency is less severe than a material weakness but still important enough to merit attention from those charged with oversight; a material weakness — the most severe classification — means there is a reasonable possibility that a material misstatement or instance of noncompliance will not be prevented, or detected and corrected, on a timely basis. Material weaknesses are the classification most likely to affect a federal awarding agency’s risk assessment of the auditee going forward.

4. Summary Schedule of Prior Audit Findings

Required under 2 CFR 200.511(b), this tracks the status of every finding reported in the prior year’s Single Audit: resolved, still in progress, or no longer valid, with an explanation in each case. It is what lets a reviewer — or a federal awarding agency deciding whether to designate an auditee “high-risk” — see whether an organization is actually fixing what it found last time, rather than accumulating the same finding year after year.

5. Corrective Action Plan

Required under 2 CFR 200.511(c), prepared by the auditee (not the auditor), addressing each current-year finding: what the organization will do about it, who is responsible, and by when. This is the document a federal awarding agency or pass-through entity reviews when it issues its management decision on a finding — required under 2 CFR 200.521 within six months of the FAC accepting the audit report.

6. Data Collection Form (SF-SAC)

Alongside the narrative reporting package, the auditee also submits a structured data collection form (Appendix X to Part 200) summarizing the audit results in a standardized, machine-readable format. This is what lets the FAC and researchers query Single Audit results in aggregate across thousands of auditees, rather than reading each package individually.

Illustrative Excerpt: What a Finding Entry Looks Like

The excerpt below is an illustrative composite constructed for this guide, built only from the required elements listed in 2 CFR 200.516 — it does not describe any real organization, program, audit, or finding, and any resemblance to an actual finding is coincidental.

Finding 2025-001 — Significant Deficiency, Subrecipient Monitoring (repeat of prior-year finding 2024-002)
Federal Program: [Illustrative federal program name], Assistance Listing [illustrative number]
Criteria: The auditee is required to monitor subrecipient activities to provide reasonable assurance that subaward funds are used for authorized purposes, per the applicable subrecipient monitoring requirements.
Condition: For 3 of 15 subawards tested, the auditee could not provide evidence that a risk assessment had been performed prior to issuing the subaward.
Cause: The subrecipient risk-assessment step was not consistently completed before subaward issuance during the audit period.
Effect: Subawards may have been issued without an adequate basis for determining the appropriate level of subsequent monitoring.
Questioned Costs: None identified.
Recommendation: Complete and document a risk assessment for every subrecipient prior to issuance, consistent with the auditee’s own subrecipient monitoring policy.
Views of Responsible Officials: Management concurs and will update its subaward issuance checklist to require a documented risk assessment as a precondition of issuance.

Note how tightly this maps to the required elements in 200.516 — a real finding follows this same structure, just populated with real facts specific to the audit. See the CASRAI guide to internal controls for federal grant compliance and the subrecipient monitoring term for more on the underlying control this illustrative finding concerns.

Where the Package Goes, and When

The completed reporting package, together with the data collection form, must be submitted electronically to the Federal Audit Clearinghouse within 30 calendar days after the auditee receives the auditor’s report(s), or nine months after the end of the audit period, whichever is earlier (2 CFR 200.512). The FAC is the federal government’s repository of record for Single Audit reporting packages — it is also where a research administrator can look up a specific institution’s filing history, and where a pass-through entity checks a subrecipient’s most recent Single Audit status before making a new subaward.

After submission, HHS-OIG and other cognizant or oversight agencies conduct desk reviews and quality control reviews of reporting packages to check compliance with professional auditing standards and to direct their own audit-resource allocation — a separate process from the audit itself, and from any individual finding’s resolution.

Major Program Determination

Not every federal program an auditee receives gets tested in a given year’s Single Audit. Auditors use a risk-based approach set out in the Uniform Guidance to determine which programs are “major” and therefore subject to detailed compliance testing, and the annual OMB Compliance Supplement identifies up to 12 types of compliance requirement an auditor may test — activities allowed/unallowed, allowable costs/cost principles, cash management, eligibility, equipment and real property management, matching/level of effort/earmarking, period of performance, procurement and suspension/debarment, program income, reporting, subrecipient monitoring, and special tests and provisions — with each federal awarding agency selecting up to 6 as applicable to a given major program for a given year. See the 2 CFR 200 procurement standards guide for how one of those twelve requirement types is tested in practice.

Frequently Asked Questions

Is a Single Audit report the same as an auditor’s opinion letter?

No. The auditor’s opinion letters (there are usually several — see above) are one component of the full reporting package. The phrase “Single Audit report” is commonly used loosely to mean either the opinion letters alone or the whole package; the regulation itself only defines the full “reporting package.”

Who prepares the Schedule of Expenditures of Federal Awards — the auditor or the auditee?

The auditee prepares it. The auditor then expresses an opinion on whether it is fairly stated in relation to the financial statements as a whole; the auditor does not construct the schedule itself.

Where can I find a real organization’s Single Audit reporting package to see the full document?

The Federal Audit Clearinghouse (FAC) is the federal repository of record for Single Audit reporting packages and is the authoritative place to look up a specific institution’s actual, filed package rather than a constructed example.

What happens if a Single Audit turns up no findings at all?

Part I of the Schedule of Findings and Questioned Costs still exists and reports the auditor’s results, including that no material weaknesses, significant deficiencies, or non-unmodified opinions were identified; Parts II and III are simply empty or state that no matters were reported. A “clean” Single Audit is still a complete reporting package with all required components — it just has nothing to report in the findings sections.

How does a questioned cost in a Single Audit finding get resolved?

The federal awarding agency or pass-through entity reviews the finding and the auditee’s corrective action plan and issues a management decision — required within six months of the FAC accepting the audit report under 2 CFR 200.521 — determining whether the questioned cost is allowed, disallowed, or requires further documentation.

Related CASRAI Resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →