Before a pass-through entity (PTE) issues a subaward of federal funds — most commonly a lead university subcontracting part of a federal grant to a collaborating institution — it has a regulatory obligation to evaluate that subrecipient’s risk of noncompliance. This isn’t a courtesy check; it’s the step that determines how closely the PTE has to watch the subaward once money starts flowing. This guide walks through what the risk assessment covers, how institutions turn a handful of regulatory factors into an actual score or tier, and how that tier drives the monitoring plan that follows. For the full set of pre- and post-award obligations a PTE carries once the subaward is signed, see the CASRAI Subrecipient Monitoring Checklist; this guide focuses specifically on the pre-award assessment step that checklist covers in brief.
The legal basis: 2 CFR 200.332(c)
The requirement sits in the Uniform Guidance at 2 CFR 200.332, "Requirements for pass-through entities." Paragraph (c) states that before making a subaward, a pass-through entity must evaluate each subrecipient’s risk of noncompliance with federal statutes, regulations, and the terms of the subaward, for purposes of determining the appropriate level of subsequent monitoring. The regulation names four specific factors the PTE must consider:
- The subrecipient’s prior experience with the same or similar subawards — has this organization successfully administered comparable federal subawards before, whether from this PTE or another?
- The results of previous audits — including whether the subrecipient is subject to a Single Audit under 2 CFR Part 200 Subpart F, and whether awards similar to the one being made were tested as a major program in that audit.
- Whether the subrecipient has new personnel or new or substantially changed systems — a recent turnover in financial-management staff or a recent change of accounting system is treated as elevating risk relative to a subrecipient with stable, proven systems.
- The extent and results of any federal agency monitoring — if the subrecipient also receives funding directly from the same federal agency, that agency’s own oversight history is relevant evidence of the subrecipient’s compliance posture.
Note the separate, adjacent citation: 2 CFR 200.331 answers a different question — whether a downstream relationship is a subaward (subrecipient) or a procurement contract in the first place. See the CASRAI comparison Prime Recipient vs. Subrecipient and Subrecipient vs. Contractor vs. Vendor for that threshold determination. Risk assessment under 200.332(c) only applies once 200.331 has already established that the relationship is a subaward.
Who this applies to, and when
The obligation falls on any non-federal entity — typically a university, hospital, or research institute — that passes federal grant or cooperative-agreement funds through to a subaward recipient. It applies before the subaward is issued, not after, and it applies regardless of the subaward’s payment structure (cost-reimbursement or fixed-amount) or dollar size, though as covered below, the intensity of monitoring that follows is explicitly meant to scale with the assessed risk rather than being applied uniformly to every subrecipient. See the CASRAI Pass-Through Entity term for the underlying definition.
Turning four factors into a score
2 CFR 200.332(c) tells a PTE what to consider; it doesn’t prescribe a scoring methodology. In practice, most research institutions operationalize the four regulatory factors — plus, commonly, a few additional practical considerations — through a written risk-assessment tool or matrix completed for every proposed subrecipient before the subaward is issued. These tools vary by institution, but the general shape is consistent: each factor is scored (often on a simple low/moderate/high or numeric scale), the scores are combined into an overall risk rating, and that rating is documented and kept on file alongside the subaward. Several universities publish their risk-assessment matrices as public templates — Rutgers’ Office of Research and Johns Hopkins’ subrecipient risk-rating dashboard are examples of the general approach, illustrative of the pattern rather than a single standardized national tool. Institutions commonly extend the four regulatory factors with:
- Entity type — a state or local government agency, a large research university with an existing federally negotiated indirect-cost rate, a small nonprofit, a for-profit business, and a foreign institution each carry a different baseline risk profile, partly because they’re subject to different audit requirements (a for-profit subrecipient, for example, isn’t covered by the Single Audit Act the way a nonprofit or government entity is).
- Subaward value relative to the prime award — a subaward that represents a large share of the total award, or that itself crosses the Single Audit expenditure threshold, is generally weighted as higher risk than a small, ancillary subaward.
- Relationship history — whether the PTE has an existing track record with this specific subrecipient, distinct from the regulation’s broader "prior experience with similar subawards" factor.
Financial stability: what reviewers look at
Financial stability isn’t named verbatim as one of 200.332(c)’s four factors, but it’s the practical substance behind "results of previous audits" and a routine addition to institutional risk tools, because a subrecipient’s financial condition bears directly on its ability to properly account for and safeguard federal funds. Reviewers typically look at whether the subrecipient has a recent Single Audit or other independent financial-statement audit on file, whether that audit produced any findings (particularly findings related to internal controls over federal awards), and whether the subrecipient’s financial statements show signs of distress — a going-concern qualification from the auditor, or a sustained negative unrestricted net-asset position, for instance. For subrecipients not subject to a Single Audit (a small nonprofit below the expenditure threshold, or a for-profit entity), the PTE typically has to request financial statements or other assurances directly, since there’s no third-party audit to rely on.
Programmatic capacity: what reviewers look at
The second practical dimension institutions commonly assess alongside financial risk is programmatic (or technical) capacity — whether the subrecipient has the staffing, systems, and subject-matter expertise to actually carry out the scope of work described in the subaward, separate from whether it can account for the money correctly. This overlaps with the regulation’s "new personnel or new or substantially changed systems" factor but extends it: reviewers commonly ask whether the subrecipient has performed this type of technical work before, whether key personnel named in the subaward have relevant experience, and whether the subrecipient has the administrative infrastructure (a sponsored-programs office, an effort-reporting system, a cost-accounting system) proportionate to the size and complexity of the subaward being proposed. A subrecipient that is financially sound but programmatically inexperienced with, say, human-subjects research or a specialized instrumentation protocol can still be assessed as higher risk on this dimension.
From risk tier to monitoring plan
The entire point of the pre-award assessment is that its output — typically a low/moderate/high risk designation — directly sets the monitoring plan for the life of the subaward. 2 CFR 200.332(d) requires PTEs to monitor subrecipient activities to ensure the subaward is used for authorized purposes, in compliance with federal statutes and the subaward’s terms, and that performance goals are achieved; the same paragraph makes clear that monitoring should be risk-based rather than uniform. In practice, that typically translates into something like this gradient:
- Low risk — standard periodic financial and technical progress reports, reviewed on receipt, with no additional desk review or site visit built in as a default.
- Moderate risk — standard reporting plus periodic desk reviews of invoices or expenditure detail, and closer follow-up on any reporting delays.
- High risk — more frequent reporting, detailed desk reviews or invoice-level backup documentation required with every payment request, and in some cases an on-site or virtual programmatic and financial site visit during the period of performance.
For the specific monitoring activities, audit-follow-up obligations, and closeout steps that flow from whichever tier a subrecipient lands in, see the CASRAI Subrecipient Monitoring Checklist, which covers the full post-award sequence in detail. This guide’s scope stops at the assessment that sets the plan in motion.
Special cases
Foreign subrecipients. A subrecipient outside the US is not subject to the Single Audit Act, so the "results of previous audits" factor typically has to be satisfied through alternative documentation — audited financial statements prepared under the subrecipient’s home-country standards, or additional certifications the PTE requests directly. Foreign subawards, particularly on NIH awards, have also drawn additional agency-level scrutiny in recent years around subrecipient identification and reporting; see the CASRAI guide NIH Foreign Subawards for the specifics.
For-profit subrecipients. As noted above, for-profit entities fall outside Single Audit coverage entirely, so a PTE assessing one has to rely more heavily on the other three regulatory factors and on financial statements requested directly from the subrecipient.
Repeat subrecipients. Institutions commonly maintain a running risk record for subrecipients they work with often, so a new subaward to an already-assessed, low-risk, long-standing collaborator doesn’t require rebuilding the assessment from scratch — though the assessment should still be revisited periodically and whenever something material changes (a new audit finding, a change in the subrecipient’s financial condition, or a lapse in prior-experience relevance because of a long gap since the last subaward).
Where this fits in the subaward workflow
Risk assessment happens before the subaward agreement is finalized, typically alongside or immediately after the PTE decides to make the subaward and before it negotiates final terms. See Subaward Agreement Negotiation: How It Works for how that negotiation proceeds, and FDP Subaward Templates for the standardized agreement templates many institutions use once the subrecipient has been assessed. The Federal Demonstration Partnership’s Expanded Clearinghouse also lets participating institutions share subrecipient assurance and risk-relevant data with each other, reducing duplicate assessment effort across PTEs assessing the same subrecipient; see the CASRAI guide FDP Expanded Clearinghouse for how that works.
Frequently asked questions
Is a risk assessment required for every subaward, regardless of dollar amount?
Yes. 2 CFR 200.332(c) doesn’t set a dollar threshold below which the assessment can be skipped — it applies to every subaward of federal funds. What scales with risk is the intensity of the monitoring that follows, not whether the initial assessment happens at all.
How is this different from subrecipient monitoring?
Risk assessment happens before the subaward is issued and produces the risk tier that determines the monitoring plan. Subrecipient monitoring is the ongoing activity — reviewing reports, following up on findings, conducting site visits — that happens throughout the period of performance based on that tier. See the CASRAI Subrecipient Monitoring term for the distinction.
Does the risk assessment have to be redone for every new subaward to the same subrecipient?
The regulation doesn’t specify a mandatory refresh cycle, and institutional practice varies. Many institutions carry forward a recent, still-current assessment for an established subrecipient rather than starting over, but revisit it whenever something material changes — a new audit finding, a lapse in Single Audit currency, or a significant change in the subrecipient’s financial condition or key personnel.
Who is responsible for documenting the risk assessment?
The pass-through entity is. 2 CFR 200.332 places the obligation on the PTE, not the subrecipient, and the resulting documentation is generally what a federal auditor or agency reviewer will ask to see as evidence that monitoring intensity was set deliberately rather than applied uniformly.







