32.3 The Single Audit Act & Uniform Guidance (2 CFR 200 Subpart F)

Key Takeaways

  • Low-risk auditee status (achieved through clean audit opinions, no material weaknesses, and timely submissions for the preceding two years) reduces the required major program testing coverage from 40% of total federal awards down to 20%.
  • The complete Single Audit reporting package includes the audited financial statements, Schedule of Expenditures of Federal Awards (SEFA), the Yellow Book report, the Single Audit compliance report, the Schedule of Findings and Questioned Costs (with a $25,000 questioned cost threshold), and the auditee's Corrective Action Plan.
  • For fiscal years beginning on or after October 1, 2024, the Single Audit Act and 2 CFR 200 Subpart F require a non-federal entity that expends $1,000,000 or more in federal awards to undergo a single or program-specific audit.
Last updated: September 2026

16.4 The Single Audit Act & Uniform Guidance (2 CFR 200 Subpart F)

The Evolution and Purpose of the Single Audit

Prior to the 1980s, federal financial assistance to state, local, and nonprofit entities was audited on a disjointed, grant-by-grant basis. A single university or state department administering twenty federal grants might undergo twenty separate audits by twenty different federal audit teams, creating severe administrative gridlock, duplicative testing, and massive oversight gaps.

Congress solved this systemic inefficiency by enacting the Single Audit Act of 1984 (P.L. 98-502), comprehensively updated by the Single Audit Act Amendments of 1996 (P.L. 104-156). The operational rules governing single audits are codified in the Office of Management and Budget (OMB) Uniform Guidance: 2 CFR 200 Subpart F (Audit Requirements).

The single audit replaces fragmented, grant-by-grant audits with one comprehensive, entity-wide annual audit that examines:

  1. The fair presentation of the entity's financial statements;
  2. The accuracy and completeness of the Schedule of Expenditures of Federal Awards (SEFA);
  3. Internal control over financial reporting and compliance; and
  4. Compliance with federal statutes, regulations, and grant terms for each designated major federal program.
+-----------------------------------------------------------------------------------+
|                     THE FOUNDATIONAL SINGLE AUDIT MANDATE                         |
+-----------------------------------------------------------------------------------+
|  PRIMARY STATUTE     | Single Audit Act of 1984 / Amendments of 1996 (31 U.S.C.)  |
|  REGULATORY CODE     | OMB Uniform Guidance (2 CFR 200 Subpart F)                 |
|  APPLICABILITY       | Non-federal entities expending $1,000,000 or more in federal |
|  THRESHOLD           | awards during the entity's fiscal year                     |
|  PROGRAM-SPECIFIC    | Permissible ONLY when an auditee expends awards under a    |
|  AUDIT ELECTION      | single federal program AND is not required to undergo a    |
|                      | financial statement audit by statute or charter            |
+-----------------------------------------------------------------------------------+

The Applicability Threshold: $1,000,000

Any state, local government, Indian tribe, institution of higher education, or non-profit organization that expends $1,000,000 or more in federal awards in a fiscal year is legally required to undergo a Single Audit (or a program-specific audit).

  • Expenditure Basis: The threshold is based strictly on federal awards expended, not awards granted, authorized, or received. Expenditures include direct grant outlays, pass-through grant disbursements, federal loan and loan guarantee drawdowns, interest subsidies, non-cash property, and surplus commodities.
  • Exemption: Entities expending less than $1,000,000 are exempt from federal audit requirements for that year, though records must be maintained for review.

The Risk-Based Approach to Major Program Determination

An auditor cannot audit every federal program administered by an entity every year. Instead, Uniform Guidance (2 CFR 200.518) mandates a four-step, risk-based approach to determine which federal programs must be audited as major programs:

+-----------------------------------------------------------------------------------+
|             THE 4-STEP RISK-BASED MAJOR PROGRAM DETERMINATION PROCESS             |
+-----------------------------------------------------------------------------------+
|  STEP 1: IDENTIFY TYPE A AND TYPE B PROGRAMS                                      |
|  • Calculate the Type A dollar threshold based on total federal awards expended.  |
|  • Larger programs are Type A; all other smaller programs are Type B.             |
+-----------------------------------------------------------------------------------+
|  STEP 2: IDENTIFY LOW-RISK TYPE A PROGRAMS                                        |
|  • Evaluate whether Type A programs meet criteria for low risk (audited in last 2 |
|    years without modified major-program opinions, material weaknesses, or questioned costs above the applicable five-percent criterion).   |
+-----------------------------------------------------------------------------------+
|  STEP 3: IDENTIFY HIGH-RISK TYPE B PROGRAMS                                       |
|  • Perform risk assessments on larger Type B programs; identify high-risk B's.   |
+-----------------------------------------------------------------------------------+
|  STEP 4: SELECT MAJOR PROGRAMS & VERIFY PERCENTAGE-OF-COVERAGE                    |
|  • Audit all high-risk Type A programs and all identified high-risk Type B's.    |
|  • Ensure total major programs tested satisfy the 20% or 40% coverage rule.       |
+-----------------------------------------------------------------------------------+

Step 1: Establishing Type A and Type B Thresholds

For fiscal years beginning on or after October 1, 2024, the Single Audit applicability threshold is $1,000,000. Earlier audit periods used the former $750,000 amount, so always match the threshold to the auditee's fiscal-year beginning date. Programs are divided into Type A (larger dollar programs) and Type B (smaller dollar programs) using a sliding statutory scale based on total federal awards expended:

+-----------------------------------------------------------------------------------+
|               SLIDING SCALE FOR TYPE A PROGRAM THRESHOLD (2 CFR 200.518)          |
+-----------------------------------------------------------------------------------+
|  TOTAL FEDERAL AWARDS EXPENDED             | TYPE A PROGRAM THRESHOLD             |
|--------------------------------------------|--------------------------------------|
|  $1,000,000 to $34,000,000                   | $1,000,000                           |
|  Over $34,000,000 to $100,000,000          | 3% of total federal awards expended  |
|  Over $100,000,000 to $1,000,000,000       | $3,000,000                           |
|  Over $1,000,000,000 to $10,000,000,000    | 0.3% of total federal awards expended|
|  Over $10,000,000,000 to $20,000,000,000  | $30,000,000                          |
|  Over $20,000,000,000                     | 0.15% of total federal awards expended|
+-----------------------------------------------------------------------------------+

Step 2: Evaluating Low-Risk Type A Programs

For a Type A program to be considered low-risk, it must have been audited as a major program in at least one of the two preceding audit periods, and in the most recent audit period, it must have had:

  • No internal control deficiencies identified as a material weakness;
  • An unmodified audit opinion on compliance;
  • No known or likely questioned costs exceeding 5% of the total federal awards expended for that program; and
  • No significant changes in personnel or operational systems that would elevate risk.

Step 3: Evaluating High-Risk Type B Programs

The auditor must perform a risk assessment on Type B programs whose expenditures exceed a statutory screening threshold (typically 25% of the Type A threshold). If a Type B program has weak controls, major system changes, or complex compliance requirements, the auditor classifies it as high-risk.

Step 4: Final Major Program Selection

At a minimum, the auditor must audit as major programs:

  1. All high-risk Type A programs;
  2. All identified high-risk Type B programs; and
  3. Additional programs if necessary to satisfy the percentage-of-coverage rule.

Low-Risk Auditee Status and Percentage-of-Coverage Rules

A pivotal determination in every Single Audit is whether the auditee qualifies as a low-risk auditee (2 CFR 200.520).

Criteria for Low-Risk Auditee Qualification

To qualify as a low-risk auditee, the entity must meet all of the following conditions for each of the preceding two audit periods under 2 CFR 200.520:

  1. Annual, Timely Single Audits: Single audits were performed annually, and the data collection form and reporting package were submitted to the FAC on time; biennial audits do not qualify.
  2. Unmodified Opinions: Both the financial-statement opinion (under GAAP or an allowed state-law special-purpose framework) and the in-relation-to opinion on the SEFA were unmodified.
  3. No GAGAS Material Weaknesses: No internal control deficiencies were identified as material weaknesses under GAGAS.
  4. No Going-Concern Substantial Doubt: The auditor did not report substantial doubt about the auditee's ability to continue as a going concern.
  5. Clean Type A Program History: For programs classified as Type A in either preceding period, there was no major-program internal-control material weakness, modified major-program opinion, or known or likely questioned costs exceeding 5% of that Type A program's awards expended.

The Percentage-of-Coverage Mandate

Qualifying as a low-risk auditee drastically reduces audit burden and expense:

+-----------------------------------------------------------------------------------+
|                      THE PERCENTAGE-OF-COVERAGE MANDATE                           |
+-----------------------------------------------------------------------------------+
|  AUDITEE RISK STATUS | MINIMUM PERCENTAGE OF FEDERAL AWARDS TESTED AS MAJOR       |
|----------------------|------------------------------------------------------------|
|  LOW-RISK AUDITEE    | At least 20% of total federal awards expended              |
|----------------------|------------------------------------------------------------|
|  STANDARD / HIGH-RISK| At least 40% of total federal awards expended              |
|  AUDITEE             |                                                            |
+-----------------------------------------------------------------------------------+

Auditing Compliance & Internal Control: The OMB Compliance Supplement

For each major program selected, the auditor must test compliance and internal control over compliance. The auditor relies on the annual OMB Compliance Supplement (2 CFR 200 Appendix XI), which identifies the specific compliance requirements applicable to federal programs across twelve core areas:

+-----------------------------------------------------------------------------------+
|                  THE 12 UNIFORM GUIDANCE COMPLIANCE REQUIREMENTS                  |
+-----------------------------------------------------------------------------------+
|  A. Activities Allowed or Unallowed      | G. Matching, Level of Effort, Earmarking|
|  B. Allowable Costs / Cost Principles    | H. Period of Performance               |
|  C. Cash Management                      | I. Procurement, Suspension & Debarment |
|  D. Reserved                             | J. Program Income                      |
|  E. Eligibility                          | L. Reporting (Financial & Performance) |
|  F. Equipment & Real Property Management | M. Subrecipient Monitoring             |
|                                          | N. Special Tests and Provisions        |
+-----------------------------------------------------------------------------------+
Test Your Knowledge

A city government expends $32,000,000 in federal grant awards during its fiscal year. The city has qualified as a low-risk auditee for the past two consecutive audit cycles under Uniform Guidance (2 CFR 200.520). What is the minimum percentage of total federal awards expended that the independent auditor must test as major programs, and what is the dollar threshold for defining Type A programs for this city?

A
B
C
D