30.1 FMFIA Reporting Sections

Key Takeaways

  • When outsourcing operations to shared service providers, management relies on SOC 1 reports (Type 1 design vs. Type 2 operating effectiveness) while retaining legal accountability for Complementary User Entity Controls (CUECs).
  • Internal control deficiencies are categorized into a precise three-tier hierarchy under Yellow Book/GAGAS, OMB Circular A-123, and AICPA standards: Control Deficiency, Significant Deficiency, and Material Weakness.
  • Under FMFIA Section 2 and OMB Circular A-123, agency heads must issue an annual assurance statement categorized as unmodified assurance, modified assurance, or a statement of no assurance.
Last updated: September 2026

FMFIA Reporting Sections

  • FMFIA Section 2: Requires an annual evaluation and assurance statement regarding whether the agency's internal controls over operations, compliance, and reporting comply with GAO Green Book standards.
  • FMFIA Section 4: Requires an annual assurance statement regarding whether the agency's financial management systems conform to government-wide financial system requirements (subsequently reinforced by the Federal Financial Management Improvement Act of 1996 - FFMIA).

The Three Types of Management Assurance Statements

Based on annual internal control assessments, the agency head must render one of three formal assurance statements:

+-----------------------------------------------------------------------------------+
|                     THE THREE ANNUAL MANAGEMENT ASSURANCE STATEMENTS              |
+-----------------------------------------------------------------------------------+
|  1. UNMODIFIED STATEMENT OF ASSURANCE                                             |
|     • Management provides reasonable assurance that internal controls are        |
|       operating effectively across the agency, and NO material weaknesses exist.  |
+-----------------------------------------------------------------------------------+
|  2. MODIFIED STATEMENT OF ASSURANCE                                               |
|     • Management provides reasonable assurance that internal controls are        |
|       effective, EXCEPT for specifically identified and described material        |
|       weaknesses that are undergoing active remediation under CAPs.               |
+-----------------------------------------------------------------------------------+
|  3. STATEMENT OF NO ASSURANCE                                                     |
|     • Management CANNOT provide reasonable assurance because pervasive, systemic  |
|       material weaknesses compromise the entire control structure, or because    |
|       internal control evaluations were not adequately conducted.                 |
+-----------------------------------------------------------------------------------+

CGFM Exam Distinction: Notice that management does not disclaim an opinion. External auditors issue audit opinions (or disclaimers); agency heads issue Assurance Statements (Unmodified, Modified, or No Assurance).


Independent Auditor's Reporting on Internal Control (Yellow Book / GAGAS)

When an independent auditor (e.g., the GAO, an agency Inspector General, or an independent CPA firm) conducts a financial statement audit under Government Auditing Standards (the Yellow Book), the auditor must issue a formal written report titled:

Independent Auditor's Report on Internal Control over Financial Reporting and on Compliance and Other Matters Based on an Audit of Financial Statements Performed in Accordance with Government Auditing Standards

Auditor's Reporting Mandates vs. Integrated Audits

  • Standard Financial Audit: The auditor is engaged to express an opinion on the fairness of the financial statements, not to express an opinion on internal control. The auditor considers internal control solely to design audit procedures. However, the Yellow Book strictly mandates that the auditor must report all identified Significant Deficiencies and Material Weaknesses in the written report.
  • Integrated Audit: If the agency engages the auditor to perform an integrated audit under AICPA/PCAOB standards, the auditor provides an explicit opinion on the effectiveness of internal control over financial reporting.
  • Reporting Deficiencies to Governance: Auditors must communicate Material Weaknesses and Significant Deficiencies in writing to those charged with governance (agency head and audit committee). Minor control deficiencies that do not warrant public disclosure in the audit report are communicated in a separate Management Letter.

Third-Party Vendor & Shared Service Provider Oversight: SOC Reports & CUECs

In modern government, agencies rarely operate entirely in-house financial environments. Agencies frequently outsource complex administrative functions—such as payroll processing (e.g., National Finance Center, Defense Finance and Accounting Service), cloud hosting (FedRAMP authorized cloud providers), or grant administration—to external Shared Service Providers (SSPs) or private contractors.

However, agency management cannot outsource its statutory responsibility for internal control. To verify control efficacy at service organizations, agencies rely on System and Organization Controls (SOC) reports, governed by AICPA Statement on Standards for Attestation Engagements No. 18 (SSAE 18 / AT-C Section 320).

SOC 1 Type 1 vs. SOC 1 Type 2 Reports

+-----------------------------------------------------------------------------------+
|                       SOC 1 TYPE 1 VS. SOC 1 TYPE 2 COMPARISON                    |
+-----------------------------------------------------------------------------------+
|  ATTRIBUTE           | SOC 1 TYPE 1 REPORT        | SOC 1 TYPE 2 REPORT           |
|----------------------|----------------------------|-------------------------------|
|  Scope of Review     | Design of controls ONLY    | Design AND Operating          |
|                      |                            | Effectiveness of controls     |
|  Timeframe Evaluated | As of a SPECIFIC DATE      | Throughout a SPECIFIED PERIOD |
|                      | (a single point in time)   | (specified period, commonly 6–12 months)|
|  Auditor Testing     | Inquires & walkthroughs;   | Rigorous sample testing across|
|                      | no operating sample testing| transactions during period    |
|  Audit Reliability   | Limited; cannot support low| High; supports auditor's      |
|                      | assessed control risk      | reliance on internal controls |
|  Exam Rule           | Insufficient for relying   | Required for relying on third-|
|                      | on control operations      | party operational controls    |
+-----------------------------------------------------------------------------------+

Complementary User Entity Controls (CUECs)

A critical, frequently tested concept is Complementary User Entity Controls (CUECs). A service organization's control environment does not operate in a vacuum; its effectiveness depends on controls that the customer agency (the user entity) must implement.

Every SOC 1 report explicitly identifies required CUECs. For example:

  • A cloud payroll provider's SOC 1 report may state: "Controls assume the user agency reviews monthly payroll change registers, verifies gross-to-net calculations, and promptly notifies the service provider when employees terminate."
  • If the federal agency fails to perform these monthly reconciliations, the service organization's controls are undermined.

Exam Trap: An agency cannot claim its internal controls are sound simply because its third-party service provider received a clean SOC 1 Type 2 report. If the agency fails to implement its assigned CUECs, the agency itself has an internal control deficiency that can rise to the level of a Material Weakness.


Practical Public Finance Scenario: Benefit Disbursement Center Failure, Root-Cause Analysis, and CAP Formulation

Scenario: The Federal Emergency Assistance Agency (FEAA) outsources its $1.2 billion disaster relief direct cash disbursement system to a commercial cloud processor. During the annual financial audit, the Inspector General uncovers:

  1. Duplicate disaster relief disbursements totaling $42,000,000 were processed over an 8-month period.
  2. The external cloud processor provided a SOC 1 Type 1 report dated September 30, but had never undergone a SOC 1 Type 2 audit.
  3. The SOC 1 report listed a mandatory CUEC requiring FEAA to perform daily reconciliations between FEAA eligibility approval batches and bank disbursement settlement files. FEAA staff never performed these reconciliations due to staffing turnover.
  4. In response, FEAA's CFO recommends issuing an Unmodified FMFIA Section 2 Assurance Statement, arguing the error was caused by the commercial processor.

Professional Audit & Management Resolution

  1. Deficiency Classification:

    • Material Weakness: Duplicate payments of $42,000,000 represent a material misstatement of outlays and noncompliance with payment integrity statutes. FEAA's failure to execute the required CUEC reconciliation directly enabled this failure. There was a reasonable possibility (and actual occurrence) of material misstatement.
  2. FMFIA Assurance Statement Determination:

    • The CFO's recommendation must be rejected. FEAA cannot issue an Unmodified Assurance Statement. Because a Material Weakness exists in its primary disbursement function, FEAA must issue a Modified Statement of Assurance (or a Statement of No Assurance if general ledger integrity is compromised), explicitly describing the disbursement deficiency and its remediation plan.
  3. Corrective Action Plan Formulation:

+-----------------------------------------------------------------------------------+
|               FEAA BENEFIT DISBURSEMENT CORRECTIVE ACTION PLAN (CAP)              |
+-----------------------------------------------------------------------------------+
|  ROOT CAUSE ANALYSIS:                                                             |
|  5-Why analysis revealed FEAA lacked written SOPs for CUEC monitoring, had no     |
|  automated reconciliation tool between agency records and processor files, and    |
|  failed to contractually mandate an annual SOC 1 Type 2 audit.                    |
|                                                                                   |
|  EXECUTIVE OWNER: Assistant Chief Financial Officer for Financial Operations      |
+-----------------------------------------------------------------------------------+
|  MILESTONES & TARGET COMPLETION DATES:                                            |
|  • Milestone 1 (30 Days): Contractually mandate vendor deliver annual SOC 1 Type 2.|
|  • Milestone 2 (60 Days): Deploy automated daily batch-to-disbursement tool.      |
|  • Milestone 3 (90 Days): Issue formal SOP and train finance reconciliation team. |
|  • Milestone 4 (180 Days): Complete 90-day operational re-testing and validation. |
+-----------------------------------------------------------------------------------+
Loading diagram...
Deficiency Evaluation, FMFIA Reporting, and Third-Party SOC/CUEC Integration
Test Your Knowledge

At the end of the fiscal year, an agency head reviews internal control evaluation results. The assessment reveals that while controls over human resources and administrative travel are functioning effectively, pervasive material weaknesses exist in the agency's primary financial reporting ledger and grant disbursement systems, preventing the agency from preparing reliable financial records. Under FMFIA Section 2 and OMB Circular A-123, which assurance statement must the agency head issue?

A
B
C
D
Test Your Knowledge

A federal agency contracts with an external shared service provider to manage its multi-billion-dollar retiree payroll disbursements. To assess the service organization's controls, the agency CFO receives a SOC 1 Type 2 report. In evaluating this report, what critical element must the CFO examine to ensure the agency's overall internal control system remains sound?

A
B
C
D