River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Subrecipient Monitoring Requirements Tracker

Three documents and three sheets that score every subrecipient's risk and separately check its own audit threshold, because one never predicts the other.

Free download  ·  No account needed

Subrecipient monitoring plans nearly all do the same thing: score a subrecipient against the four risk factors named in 2 CFR 200.332(c) and set a monitoring cadence from the result. That answers how closely to watch the relationship. It does not answer a separate, non-negotiable question: whether the subrecipient's own total federal expenditure this year, counting every source, has crossed the dollar line that makes a Single Audit mandatory. An obligations register tracks what the subaward agreement itself requires. Neither one, alone, tells you whether that verification is actually owed.

The two checks measure different things, and a good score on one says nothing about the other. Risk tier is built from prior experience, audit history, personnel and system changes, and other federal oversight, exactly as 200.332(c) lists them. The audit threshold in 2 CFR 200.501(a) is a flat $1,000,000 test on the subrecipient's own fiscal year, and 200.332(g) makes verifying it this organization's job, regardless of the risk score attached to that same subrecipient.

Foothill Youth Alliance passes $1,650,000 of a $2,400,000 federal award to four subrecipients. Riverside Youth Corps scores zero on every one of the four risk factors, the lowest tier possible, and still crosses $1,000,000 once a direct federal award it holds elsewhere is added to its $180,000 subaward. Northgate Community Partners scores High from a prior finding and separately crosses the same line through a second pass-through entity's funding. Half the subrecipients owe Single Audit verification, and only one of the two was already flagged as risky.

Two subrecipients cross the audit threshold. Only one of them was already flagged risky.

The risk score, the independent audit-threshold check, the monitoring log and the finding tracker behind it.

Subrecipient Register

Illustrative, for a fictional pass-through entity called Foothill Youth Alliance. Risk tier and audit threshold, scored independently for four subrecipients.

SubrecipientSubawardRisk tierOther federal $Total federal $Crosses $1M?
Riverside Youth Corps$180,000Low (0)$1,000,000$1,180,000Yes
Delridge Family Services$420,000Moderate (3)$0$420,000No
Northgate Community Partners$950,000High (6)$310,000$1,260,000Yes
Bright Path Mentoring$100,000Moderate (3)$25,000$125,000No
Total passed through$1,650,000$2,985,0002 of 4

Riverside scores the lowest possible risk tier and still crosses the audit threshold. Northgate scores the highest risk tier and also crosses it. The two checks agree on Northgate and disagree on Riverside, which is exactly why both run on every subrecipient rather than only the ones the risk score already flagged.

Monitoring Activity Log

What was actually reviewed, tied to the tier each subrecipient scored.

DateSubrecipientActivityFinding
2026-01-15Riverside Youth CorpsQ4 desk review (Low tier)None
2026-01-29Northgate Community PartnersMonthly desk review (High tier)Prior finding still open
2026-02-05Northgate Community PartnersSite visit, finance reviewCorrective action approved
2026-03-01Riverside Youth CorpsSingle Audit verification, FY2025Received, no finding on this subaward
2026-03-10Northgate Community PartnersSingle Audit verification, FY2025Received, prior finding resolved

Riverside's audit verification lands on the same log as its lightest monitoring plan. The two obligations run on separate tracks, and the log carries both.

Finding and Resolution Tracker

Every finding with a stated corrective action, an owner and a resolution date, not a bare note in a log.

SubrecipientFindingOpenedStatus
Northgate Community PartnersAllowable-costs finding, prior Single Audit2025-11-18Resolved 2026-02-05
Riverside Youth CorpsSingle Audit verification pending past $1M threshold2026-01-15Resolved 2026-03-01
Bright Path MentoringNew accounting software, no transition check on file2026-01-05Resolved 2026-02-12

Riverside's finding is not a risk problem. Its risk tier never changed. It is a verification duty the dollar threshold created on its own.

What is in the pack

01

Subrecipient Register

One row per subrecipient, carrying the risk tier from the four federal factors and, on a separate column, the audit-threshold total that tier cannot predict.

02

Risk Assessment

The four-factor scoring method and the independent threshold test, worked through on Foothill Youth Alliance's own four subrecipients so neither is abstract.

03

Monitoring Procedure

What monitoring actually happens at each risk tier, and the audit verification line that runs on every subrecipient regardless of tier.

04

Subaward Agreement Template

The identification, terms and access provisions every subaward needs, structured so the register can pull each one directly.

05

Monitoring Activity Log

Every review actually performed, dated and tied to a reviewer, so a monitoring plan on paper matches what happened in practice.

06

Finding and Resolution Tracker

Every finding with a stated corrective action, an owner and a resolution date, whether it came from a report, a site visit or a Single Audit.

How it works

  1. 1

    Send the awards and subawards

    The prime award terms, every executed subaward agreement, and whatever you know about each subrecipient's other federal funding from any source.

  2. 2

    Score the risk tier

    Each subrecipient scored against the four factors 2 CFR 200.332(c) names, with the reasoning stated for every factor rather than just the total.

  3. 3

    Check the audit threshold separately

    Every subrecipient's total federal expenditure compared to $1,000,000, independent of its risk tier, including the ones already scored Low.

  4. 4

    Log monitoring and track findings

    Reviews logged against the tier's plan, and any finding moved to a tracker with a corrective action, an owner and a due date.

Frequently asked questions

If a subrecipient scores Low risk, do I still need to check the audit threshold?

Yes. 2 CFR 200.332(g) requires verifying a subrecipient's Single Audit regardless of its risk tier. A Low score describes how closely to watch the relationship day to day, not whether the dollar threshold that triggers a mandatory audit applies to it.

What counts toward the $1,000,000 threshold?

The subrecipient's total federal awards expended in its own fiscal year, per 2 CFR 200.501(a), from every federal source. That includes funding this organization never issued, such as a direct federal award or a subaward from a different pass-through entity.

What are the four risk factors, exactly?

Prior experience with similar subawards, the results of previous audits, whether personnel or systems have recently changed, and the extent of other federal agency monitoring, all named in 2 CFR 200.332(c). None of the four is a dollar figure.

Does a clean risk score mean the subrecipient is exempt from a Single Audit?

No. The two are unrelated. In the worked example, the subrecipient with the lowest possible risk score still owes Single Audit verification, because a separate federal award it holds elsewhere pushes its total expenditure over the threshold.

How is this different from the grant compliance and award terms register?

That register reads your own executed agreements for the obligations they create. This pack is about the subrecipients on the other end of your subawards, their own risk profile and their own separate audit obligation.

Does this replace the subrecipient's Single Audit or my own?

No. A licensed auditor performs and reports the Single Audit independently, for the subrecipient and for this organization alike. This organization's own audit preparation is a separate pack. This one tracks whether the subrecipient's own audit was actually verified as required, not what it found.

Find out which of your subrecipients actually owe a Single Audit

Send your subaward agreements and what you know about each subrecipient's other federal funding. The first thing back is a risk tier and a threshold check for each one, scored separately.

Build my register