Subrecipient Monitoring Requirements Tracker
Three documents and three sheets that score every subrecipient's risk and separately check its own audit threshold, because one never predicts the other.
Free download · No account needed
Subrecipient monitoring plans nearly all do the same thing: score a subrecipient against the four risk factors named in 2 CFR 200.332(c) and set a monitoring cadence from the result. That answers how closely to watch the relationship. It does not answer a separate, non-negotiable question: whether the subrecipient's own total federal expenditure this year, counting every source, has crossed the dollar line that makes a Single Audit mandatory. An obligations register tracks what the subaward agreement itself requires. Neither one, alone, tells you whether that verification is actually owed.
The two checks measure different things, and a good score on one says nothing about the other. Risk tier is built from prior experience, audit history, personnel and system changes, and other federal oversight, exactly as 200.332(c) lists them. The audit threshold in 2 CFR 200.501(a) is a flat $1,000,000 test on the subrecipient's own fiscal year, and 200.332(g) makes verifying it this organization's job, regardless of the risk score attached to that same subrecipient.
Foothill Youth Alliance passes $1,650,000 of a $2,400,000 federal award to four subrecipients. Riverside Youth Corps scores zero on every one of the four risk factors, the lowest tier possible, and still crosses $1,000,000 once a direct federal award it holds elsewhere is added to its $180,000 subaward. Northgate Community Partners scores High from a prior finding and separately crosses the same line through a second pass-through entity's funding. Half the subrecipients owe Single Audit verification, and only one of the two was already flagged as risky.
What is in the pack
Subrecipient Register
One row per subrecipient, carrying the risk tier from the four federal factors and, on a separate column, the audit-threshold total that tier cannot predict.
Risk Assessment
The four-factor scoring method and the independent threshold test, worked through on Foothill Youth Alliance's own four subrecipients so neither is abstract.
Monitoring Procedure
What monitoring actually happens at each risk tier, and the audit verification line that runs on every subrecipient regardless of tier.
Subaward Agreement Template
The identification, terms and access provisions every subaward needs, structured so the register can pull each one directly.
Monitoring Activity Log
Every review actually performed, dated and tied to a reviewer, so a monitoring plan on paper matches what happened in practice.
Finding and Resolution Tracker
Every finding with a stated corrective action, an owner and a resolution date, whether it came from a report, a site visit or a Single Audit.
How it works
- 1
Send the awards and subawards
The prime award terms, every executed subaward agreement, and whatever you know about each subrecipient's other federal funding from any source.
- 2
Score the risk tier
Each subrecipient scored against the four factors 2 CFR 200.332(c) names, with the reasoning stated for every factor rather than just the total.
- 3
Check the audit threshold separately
Every subrecipient's total federal expenditure compared to $1,000,000, independent of its risk tier, including the ones already scored Low.
- 4
Log monitoring and track findings
Reviews logged against the tier's plan, and any finding moved to a tracker with a corrective action, an owner and a due date.
Frequently asked questions
If a subrecipient scores Low risk, do I still need to check the audit threshold?
Yes. 2 CFR 200.332(g) requires verifying a subrecipient's Single Audit regardless of its risk tier. A Low score describes how closely to watch the relationship day to day, not whether the dollar threshold that triggers a mandatory audit applies to it.
What counts toward the $1,000,000 threshold?
The subrecipient's total federal awards expended in its own fiscal year, per 2 CFR 200.501(a), from every federal source. That includes funding this organization never issued, such as a direct federal award or a subaward from a different pass-through entity.
What are the four risk factors, exactly?
Prior experience with similar subawards, the results of previous audits, whether personnel or systems have recently changed, and the extent of other federal agency monitoring, all named in 2 CFR 200.332(c). None of the four is a dollar figure.
Does a clean risk score mean the subrecipient is exempt from a Single Audit?
No. The two are unrelated. In the worked example, the subrecipient with the lowest possible risk score still owes Single Audit verification, because a separate federal award it holds elsewhere pushes its total expenditure over the threshold.
How is this different from the grant compliance and award terms register?
That register reads your own executed agreements for the obligations they create. This pack is about the subrecipients on the other end of your subawards, their own risk profile and their own separate audit obligation.
Does this replace the subrecipient's Single Audit or my own?
No. A licensed auditor performs and reports the Single Audit independently, for the subrecipient and for this organization alike. This organization's own audit preparation is a separate pack. This one tracks whether the subrecipient's own audit was actually verified as required, not what it found.
Find out which of your subrecipients actually owe a Single Audit
Send your subaward agreements and what you know about each subrecipient's other federal funding. The first thing back is a risk tier and a threshold check for each one, scored separately.
Build my register