17.5 Government Auditing Standards (Yellow Book / GAGAS) & Uniform Guidance Single Audits

Key Takeaways

  • Government Auditing Standards (GAGAS / the 'Yellow Book'), issued by the Comptroller General of the United States / GAO, incorporates AICPA GAAS and imposes additional ethical principles, CPE requirements, and reporting mandates for governmental and recipient audits.
  • Auditors performing GAGAS engagements must complete at least 80 hours of Continuing Professional Education (CPE) every two years, with at least 24 hours directly related to government auditing, the government environment, or the unique environment in which the auditee operates.
  • In a GAGAS financial audit, the auditor issues: (1) an opinion on the financial statements, and (2) a Yellow Book Report on Internal Control Over Financial Reporting and on Compliance; this report describes the scope of testing and identifies significant deficiencies and material weaknesses, but does NOT express an opinion on internal control.
  • Under the Uniform Guidance (2 CFR 200 Subpart F), non-federal entities expending $1,000,000 or more in federal awards in a fiscal year beginning on or after October 1, 2024 must have a Single Audit ($750,000 earlier).
  • Single Audits utilize a risk-based approach to select major programs, requiring 20% expenditure coverage for low-risk auditees and 40% coverage for non-low-risk auditees, with the auditor expressing an explicit audit OPINION on compliance for each major program and reporting questioned costs exceeding $25,000.
Last updated: September 2026

17.5 Government Auditing Standards (Yellow Book / GAGAS) & Uniform Guidance Single Audits

Core Principle: Auditing entities that receive and expend public funds—including state and local governments, school districts, universities, and non-profit organizations—requires adherence to a multi-tiered regulatory framework. Audits must comply not only with standard AICPA Generally Accepted Auditing Standards (GAAS), but also with Government Auditing Standards (GAGAS), commonly referred to as the Yellow Book, issued by the Comptroller General of the United States / Government Accountability Office (GAO), and the Uniform Guidance (2 CFR 200 Subpart F) Single Audit requirements.


1. The Government Auditing Hierarchy: GAAS vs. GAGAS vs. Single Audit

The regulatory demands on the auditor expand significantly depending on the engagement mandate:

+---------------------------------------------------------------------------------------------------------+
|                                 THE GOVERNMENT AUDITING ASSURANCE HIERARCHY                              |
|                                                                                                         |
|   LEVEL 1: AICPA GAAS (AU-C Sections)                                                                   |
|   - Applies to ALL audits of non-issuers (commercial, non-profit, governmental).                         |
|   - Objective: Express an opinion on whether financial statements conform to GAAP in all material respects.|
|                                                                                                         |
|   LEVEL 2: GAGAS / Yellow Book (GAO Standards)                                                           |
|   - Applies whenever mandated by statute, regulation, contract, or grant agreement.                     |
|   - Incorporates ALL of GAAS, plus additional ethical, CPE, and reporting standards.                    |
|   - Requires a written report on internal control over financial reporting and compliance.             |
|   - Does NOT require expressing an opinion on internal control.                                         |
|                                                                                                         |
|   LEVEL 3: Uniform Guidance Single Audit (2 CFR 200 Subpart F)                                          |
|   - Applies to non-federal entities expending $1,000,000 or more in federal awards in a fiscal year.       |
|   - Incorporates GAAS and GAGAS in full.                                                                |
|   - Requires risk-based major program audits, testing internal control over compliance,                |
|     and expressing an OPINION on major program compliance.                                              |
+---------------------------------------------------------------------------------------------------------+

Current Edition: The 2024 revision of Government Auditing Standards is effective for financial audits, attestation engagements, and reviews of financial statements for periods beginning on or after December 15, 2025. Its main change replaces quality control with a risk-based system of quality management. GAGAS engagements include financial audits, attestation engagements, reviews of financial statements, and performance audits (economy, efficiency, effectiveness, internal control, compliance, and prospective analyses).

2. GAGAS Ethical Principles & Professional Standards

The Yellow Book establishes five foundational ethical principles that guide professional conduct when auditing in the public sector environment:

  1. The Public Interest: Observing the public interest requires auditors to adhere to the core values of transparency, accountability, and stewardship of public resources.
  2. Integrity: Conducting work with truthfulness, honesty, and professional candor without compromising ethical values for personal or institutional gain.
  3. Objectivity: Maintaining intellectual honesty, impartiality, and freedom from conflicts of interest in forming judgments and recommendations.
  4. Proper Use of Government Information, Resources, and Positions: Safeguarding government data and preventing the unauthorized use of government equipment, facilities, or positions for personal benefit.
  5. Professional Behavior: Complying with applicable laws, regulations, and standards, and avoiding any conduct that would discredit the auditing profession.

General Standards: Independence & Non-Audit Services

GAGAS establishes an independence framework utilizing a threats and safeguards approach:

  • Self-Review Threat: If an auditor performs non-audit services (such as bookkeeping or payroll preparation), GAGAS imposes strict limits. The auditor cannot assume management responsibilities.
  • SKE Requirement: Before an auditor provides non-audit services, the audited entity's management must assign an individual with suitable Skill, Knowledge, and/or Experience (SKE) to oversee the non-audit service, evaluate the adequacy of the service, and accept full responsibility for the results. If the entity lacks personnel with suitable SKE, the auditor's independence is impaired.

Continuing Professional Education (CPE) Mandate

Auditors performing audits in accordance with GAGAS must comply with strict biennial education thresholds:

  • Total Requirement: At least 80 hours of CPE every two years.
  • Government Auditing Focus: Of those 80 hours, at least 24 hours must be directly related to government auditing, the government environment, or the specific or unique environment in which the audited entity operates.
  • Annual Minimum: At least 20 hours of the 80 total hours must be earned in each individual year of the two-year cycle.

3. GAGAS Reporting Requirements for Financial Audits

In a financial statement audit conducted under GAGAS, the auditor must prepare and issue two reports (which may be issued separately or combined into a single report):

  1. Report on the Financial Statements: Contains the auditor's opinion on whether the financial statements are presented fairly, in all material respects, in conformity with the applicable financial reporting framework (U.S. GAAP).
  2. Report on Internal Control Over Financial Reporting and on Compliance (The Yellow Book Report): A written report addressing internal control over financial reporting and compliance with laws, regulations, contracts, and grant agreements.
+---------------------------------------------------------------------------------------------------------+
|                           THE GAGAS YELLOW BOOK INTERNAL CONTROL REPORT                                 |
|                                                                                                         |
|   WHAT THE REPORT MUST CONTAIN:              WHAT THE REPORT DOES NOT CONTAIN:                          |
|   ----------------------------------------   --------------------------------------------------------   |
|   - Description of the scope of testing      - The auditor DOES NOT express an opinion on the           |
|     of internal control and compliance.        effectiveness of internal control over financial         |
|   - Identification of SIGNIFICANT              reporting (unless separately engaged to do so).          |
|     DEFICIENCIES and MATERIAL WEAKNESSES.    - Explicit statement: "The purpose of this report is       |
|   - Instances of fraud, illegal acts, and      solely to describe the scope of our testing... and not   |
|     material noncompliance with contracts.     to provide an opinion on internal control."              |
+---------------------------------------------------------------------------------------------------------+

Reporting Fraud, Noncompliance, and Abuse

  • Direct Reporting to Outside Parties: Under GAGAS, the auditor must communicate fraud, noncompliance, or abuse to management and governance. If management fails to report an illegal act or material fraud to the appropriate federal funding agency or regulator after being informed, the auditor is professionally obligated to report the matter directly to the external authority.
  • Abuse: GAGAS explicitly addresses abuse (behavior that is deficient or improper compared with the behavior that a prudent person would consider reasonable). While not requiring auditors to specifically design audits to detect abuse, if auditors become aware of abuse that could be quantitatively or qualitatively material, they apply procedures to determine its effect and consider whether and how to communicate it.

4. The Single Audit Act & Uniform Guidance (2 CFR 200 Subpart F)

Prior to the Single Audit Act of 1984, federal agencies conducted overlapping, disjointed, grant-by-grant audits of recipient entities. The Single Audit Act (administered through the OMB Uniform Guidance, 2 CFR 200 Subpart F) replaced this piecemeal approach with a single, comprehensive entity-wide audit.

Applicability & The $1,000,000 Expenditure Threshold

  • Applicability: Applies to non-federal entities (state governments, local governments, Indian tribes, higher education institutions, and non-profit organizations) that receive and expend federal financial assistance.
  • Audit Threshold: A non-federal entity that expends $1,000,000 or more in federal awards during its fiscal year must have a single (or program-specific) audit. The 2024 Uniform Guidance revisions raised the threshold from $750,000 for fiscal years beginning on or after October 1, 2024.
  • Below Threshold: Entities expending less than $1,000,000 in federal awards are exempt from federal audit requirements for that year, though they must maintain records available for review.

5. Major Program Determination: The Risk-Based Approach

Auditors do not audit every federal program an entity operates. Instead, the Uniform Guidance prescribes a rigorous four-step risk-based approach to determine which federal grant programs must be audited as major programs:

                                  MAJOR PROGRAM DETERMINATION WORKFLOW

        +-----------------------------------------------------------------------+
        | Step 1: Categorize Programs into Type A and Type B Programs           |
        | - Type A: Larger programs meeting sliding dollar threshold            |
        |   (e.g., $1,000,000 when total awards are $1M to $34M). |
        | - Type B: Smaller programs not meeting the Type A dollar threshold.   |
        +-----------------------------------------------------------------------+
                                            |
                                            v
        +-----------------------------------------------------------------------+
        | Step 2: Identify Low-Risk Type A Programs                             |
        | - Audited as a major program in at least 1 of the last 2 years.       |
        | - No material weaknesses in internal control over compliance.         |
        | - Unmodified compliance opinion; questioned costs did not exceed 5%.  |
        +-----------------------------------------------------------------------+
                                            |
                                            v
        +-----------------------------------------------------------------------+
        | Step 3: Identify High-Risk Type B Programs                            |
        | - Perform risk assessments on Type B programs; classify high-risk.    |
        +-----------------------------------------------------------------------+
                                            |
                                            v
        +-----------------------------------------------------------------------+
        | Step 4: Select Major Programs & Verify Percentage-of-Coverage         |
        | - Must audit ALL high-risk Type A programs and selected high-risk B.  |
        | - Verify coverage: 20% for Low-Risk Auditee; 40% for Non-Low-Risk.    |
        +-----------------------------------------------------------------------+

Type A Threshold Table (2 CFR 200.518)

Total federal awards expendedType A threshold
$1,000,000 to $34 million$1,000,000
Over $34 million to $100 million3% of total federal awards expended
Over $100 million to $1 billion$3 million
Over $1 billion to $10 billion0.3% of total federal awards expended
Over $10 billion to $20 billion$30 million
Over $20 billion0.15% of total federal awards expended

Risk assessments are required only for Type B programs that exceed 25% of the Type A threshold.

The Percentage-of-Coverage Rule

Once major programs are selected, the auditor must ensure that the total federal awards expended under the selected major programs satisfy the mandatory percentage-of-coverage rule:

+---------------------------------------------------------------------------------------------------------+
|                                 SINGLE AUDIT PERCENTAGE-OF-COVERAGE RULES                               |
|                                                                                                         |
|   AUDITEE STATUS:             MINIMUM EXPENDITURE COVERAGE:     CRITERIA TO QUALIFY:                    |
|   ---------------------------------------------------------------------------------------------------   |
|   LOW-RISK AUDITEE            At least 20% of total federal     - Annual single audits for prior 2 yrs. |
|                               awards expended                   - Unmodified financial statement op.    |
|                                                                 - Unmodified major program opinions.    |
|                                                                 - No internal control material weakness.|
|                                                                 - No going-concern doubt reported; no Type A questioned costs over 5%.     |
|                                                                                                         |
|   NON-LOW-RISK AUDITEE        At least 40% of total federal     - Any entity failing to meet ALL        |
|                               awards expended                     low-risk auditee criteria.            |
+---------------------------------------------------------------------------------------------------------+

Exam Watch: Candidates must memorize the coverage numbers: 20% for low-risk auditees and 40% for non-low-risk auditees. If the initial selection of major programs covers only 32% of total federal awards for a non-low-risk auditee, the auditor must add additional programs until the 40% threshold is reached.


6. The Single Audit Reporting Package

A completed Single Audit requires the submission of a comprehensive reporting package to the Federal Audit Clearinghouse (FAC) within the earlier of 30 calendar days after receiving the reports or 9 months after the close of the auditee's fiscal year.

Components of the Single Audit Reporting Package

  1. Financial Statements: Audited basic financial statements and the Schedule of Expenditures of Federal Awards (SEFA).
  2. Financial Statement Report: Auditor's report on the financial statements and in-relation-to opinion on the SEFA.
  3. GAGAS Yellow Book Report: Auditor's report on internal control over financial reporting and on compliance (describes testing scope; expresses no opinion on ICFR).
  4. Single Audit Compliance Report: Auditor's report on compliance for each major federal program and on internal control over compliance (the compliance audit follows AU-C 935 together with the Uniform Guidance). CRITICAL: This report expresses an explicit OPINION on compliance with major program requirements!
  5. Schedule of Findings and Questioned Costs: Contains three distinct sections:
    • Section I: Summary of Auditor's Results (type of report issued on FS, internal control deficiencies noted, compliance opinion on major programs, dollar threshold used to distinguish Type A/B, and auditee low-risk status).
    • Section II: Financial Statement Findings (findings required to be reported under GAGAS).
    • Section III: Federal Award Findings and Questioned Costs (significant deficiencies, material weaknesses, and compliance violations regarding major federal programs).
  6. Auditee Corrective Action Plan (CAP): Management's detailed plan addressing each reported finding.
  7. Summary Schedule of Prior Audit Findings: Auditee's reporting on the status of previous audit findings.

The Questioned Costs Reporting Threshold

Under the Uniform Guidance, an auditor must explicitly report known questioned costs that are greater than $25,000 for a compliance requirement of a major program. The auditor must also report known questioned costs when likely questioned costs are greater than $25,000.


7. Master Comparison Matrix: GAAS vs. GAGAS vs. Single Audit

FeatureAICPA GAASGAGAS (Yellow Book)Uniform Guidance Single Audit
Governing BodyAICPA (ASB)GAO (Comptroller General)OMB / Federal Government
TriggerContractual agreementLaw, grant, or regulationExpending >= $1,000,000 in federal awards
Opinion on Financial Statements?YESYESYES
Opinion on ICFR?NO (Unless under AU-C 940)NO (Only reports scope & findings)NO
Opinion on Legal/Grant Compliance?NONO (Only reports scope & findings)YES (Opinion on Major Programs)
CPE RequirementState Board of Accountancy80 hours/2 yrs (24 hrs govt)GAGAS rules apply
Questioned Costs Reporting?NoneNot explicitly quantifiedRequired for costs > $25,000

8. Realistic Exam Scenarios & Traps

Scenario 1: Mistaking the GAGAS Internal Control Report for an Opinion

  • Trap: An exam question presents an auditor performing a Yellow Book financial audit of a city government. The question asks what form of opinion the auditor should express on internal control over financial reporting.
  • Resolution: The correct response is that no opinion is expressed on internal control. The Yellow Book report describes the scope of testing of internal control and compliance and identifies significant deficiencies and material weaknesses, but explicitly disclaims an opinion on internal control effectiveness.

Scenario 2: Compliance Opinion under Single Audit

  • Trap: A question asks whether an opinion on compliance is ever expressed in a governmental audit.
  • Resolution: Yes! While GAGAS does not express an opinion on compliance, the Uniform Guidance Single Audit explicitly requires an audit OPINION on whether the auditee complied with federal statutes, regulations, and terms of federal awards for each major program (Unmodified, Qualified, or Adverse).
Test Your Knowledge

Under Government Auditing Standards (GAGAS / Yellow Book), which of the following statements correctly describes the auditor's reporting responsibilities regarding internal control over financial reporting in a financial statement audit?

A
B
C
D
Test Your Knowledge

Under the Uniform Guidance (2 CFR 200 Subpart F), what is the annual expenditure threshold of federal financial awards that triggers a mandatory Single Audit for a non-federal entity?

A
B
C
D
Test Your Knowledge

When conducting a Single Audit under the Uniform Guidance for an entity that qualifies and is determined to be a 'low-risk auditee,' what minimum percentage of total federal awards expended must be covered by the auditor's testing of major programs?

A
B
C
D
Test Your Knowledge

During the performance of a Single Audit under the Uniform Guidance, an auditor uncovers an instance of noncompliance resulting in an unallowable cost charged to a major federal grant. Above what dollar threshold must this known questioned cost be explicitly reported in the Schedule of Findings and Questioned Costs?

A
B
C
D
Congratulations!

You've completed this section

Continue exploring other exams