A Single Audit finding usually doesn’t start during the audit.
It starts months earlier when a grant report gets filed without being reconciled to the general ledger. Or when an employee’s salary gets charged to a federal program without anyone documenting why. Or when a new subrecipient is paid and nobody circles back to complete the required monitoring.
By the time the auditors arrive, we are simply finding the problem.
That distinction matters because many of the most common Single Audit findings are preventable. The organizations that have the smoothest audits aren’t necessarily the ones with the biggest accounting departments. They are the ones that build grant compliance into their normal monthly processes instead of trying to reconstruct it at year-end.
Here are seven areas I would look at before your next Single Audit.
The Schedule of Expenditures of Federal Awards, or SEFA, is the starting point for your Single Audit.
And it is not simply a report your accountant should create at year-end.
Your organization needs to know which awards are federal, which agency provided the funding, whether funds came directly from the federal government or through a pass-through entity, and how much was actually expended during the fiscal year.
One of the biggest problems we see is organizations trying to build the SEFA after the books are closed by digging through grant agreements, deposits and old spreadsheets.
That is much harder than maintaining the information as grants are awarded and expenditures occur.
Prevent it: Maintain a federal awards schedule throughout the year and reconcile it to the general ledger before year-end. For every federal award, track the funding source, Assistance Listing number, pass-through information when applicable, award period and expenditures.
Your SEFA should come from your accounting records—not from detective work performed the week before the audit.
An expense can be completely legitimate and still create an audit problem if the organization cannot support it.
An auditor selecting an expenditure may need to see more than the invoice. Depending on the transaction, support might include the invoice, approval, proof of payment, grant agreement, purchase documentation and evidence showing why the expenditure belongs to that particular federal program.
The question isn’t only:
“Did we spend the money?”
It is also:
“Can we demonstrate that the expenditure was allowable and properly charged to this award?”
That second question is where organizations get into trouble.
Prevent it: Store grant documentation in a way that lets someone other than the person who processed the transaction understand what happened. Before charging an unusual or significant expenditure to a federal award, ask whether the file contains enough information to explain both the expense and its connection to the grant.
If your auditor has to ask three people why an expense was charged to a program, the documentation probably wasn’t strong enough to begin with.
Payroll is often one of the largest costs charged to federal programs, which makes it an obvious area for audit testing.
The problem isn’t necessarily payroll processing. The problem is allocating payroll among programs.
An employee may work partly on one federal award, partly on another program and partly on general administration. If the organization simply charges the employee according to the grant budget every payroll without comparing that allocation to the work actually performed, there may be a problem.
A budget tells you what you expected to happen. It doesn’t prove what actually happened.
Prevent it: Have a consistent method for supporting payroll allocations and periodically review whether those allocations still reflect employees’ actual work. When roles change, grant responsibilities change or employees begin working across multiple programs, update the allocation methodology instead of waiting until year-end.
This is especially important for executive directors, finance staff, program managers and other employees whose time naturally crosses programs.
Procurement findings often happen because an organization purchased something reasonably—but didn’t document the process.
Federal grant requirements can impose specific procurement standards, and the appropriate procedure varies depending on the nature and size of the purchase. Your own procurement policy matters too.
A common problem is having a written procurement policy that says one thing while staff members routinely do something else.
Maybe competitive quotes were required but weren’t retained. Maybe there was a legitimate sole-source reason, but nobody documented it. Maybe management followed its normal purchasing process without recognizing that federal dollars were involved.
Prevent it: Make federal procurement requirements part of the purchasing workflow, not something finance reviews months later. Before a significant purchase is approved, identify the funding source and determine what documentation is required.
And don’t create a procurement policy so complicated that your staff cannot realistically follow it. A good policy should protect the organization and actually match how purchasing decisions are made.
Giving federal funds to another organization does not transfer all of your responsibility for those funds.
If your nonprofit is a pass-through entity and makes subawards, you have responsibilities for evaluating and monitoring those subrecipients.
This is an area that can easily fall through the cracks because everyone is focused on the organization’s own compliance.
The organization may have a signed subaward agreement and copies of reports from the subrecipient—but little evidence that anyone actually reviewed what was submitted, evaluated risk, followed up on problems or performed the required monitoring.
Simply collecting documents is not the same thing as monitoring.
Prevent it: Create a subrecipient file for each organization receiving federal funds. Document the initial risk assessment, required reporting, monitoring performed, review of applicable audit results and follow-up on identified issues.
Most importantly, assign responsibility for the process to a specific person. “Finance thought programs was handling it” is not a strong internal control.
This one sounds simple, which is exactly why it causes so many problems.
A program manager prepares a report for the grantor. Finance has the accounting records. Someone makes an adjustment. Another report is filed. Months pass.
Then the auditors compare the reports submitted to the granting agency with the general ledger—and the numbers don’t agree.
Sometimes there is a perfectly reasonable explanation. But if nobody can produce the reconciliation showing that explanation, the organization is left reconstructing it during the audit.
Prevent it: Reconcile financial reports to the general ledger before they are submitted to the grantor. Keep the reconciliation with the submitted report.
If there is a timing difference, accrual, adjustment or other reconciling item, document it then—not a year later.
This is one of those controls that takes a few minutes when performed routinely and can take hours to recreate during an audit.
The general reply is:
“We do that. We just don’t have it written down.”
That is better than not having a control at all, but it still creates problems.
Under a Single Audit, auditors are looking at internal control over compliance for the federal programs being tested. We need to understand not only what your organization is supposed to do but what it actually does.
Who reviews grant expenditures? Who approves draw requests? Who reconciles reports? Who reviews eligibility? Who monitors subrecipients? What happens when the person who normally performs the control is unavailable?
Organizations often have good processes living entirely in the heads of one or two employees.
That creates both an audit risk and an operational risk.
Prevent it: Document your major grant-compliance processes and identify who performs and reviews each control. Then make sure the written process reflects reality.
You don’t need a 200-page policy manual nobody reads. You need clear procedures showing that important compliance responsibilities have been identified, assigned and consistently performed.
There is a pattern running through all seven of these issues.
None of them are really “audit problems.”
They are accounting, documentation and compliance problems that the audit eventually exposes.
That is why waiting for the auditor’s request list to begin preparing for a Single Audit is too late.
A better approach is to review federal grant compliance during the year. Reconcile your SEFA. Tie grant reports to the ledger. Review payroll allocations. Check procurement documentation. Complete subrecipient monitoring. Make sure your internal controls are actually being performed.
Then when the auditors arrive, you aren’t trying to reconstruct twelve months of activity.
You are handing them documentation that already exists.
And that is exactly what a well-run Single Audit should feel like: not a fire drill, but the final review of work your organization has been doing correctly all year.
Rose Group CPAs works with nonprofit organizations receiving federal funding, including organizations subject to Single Audits and Government Auditing Standards. If your organization is preparing for an upcoming audit—or isn’t sure whether its federal grant records are ready—our audit team can help you understand what to expect and identify issues before fieldwork begins. Contact us to talk through what your organization needs before fieldwork begins.