In short: A Single Audit is the audit of an organization's financial statements, its internal controls over the accurate reporting of those financial statements, its internal controls over compliance, and its compliance with the direct and material attributes of its federal program. It is required when your organization expends $1,000,000 or more in federal awards during your fiscal year, and it is governed by the Uniform Guidance at 2 CFR Part 200, Subpart F. For Public Housing Authorities (PHAs), Housing Finance Agencies (HFAs), and Nonprofits, it is one of the most consequential compliance events of the year, and most of the difficulty is decided long before the auditors arrive.
If your organization received federal awards to support its mission, the Single Audit is probably the largest compliance obligation on your calendar, and likely one of the most misunderstood. Many finance teams treat it as a year-end event, something that happens to them after the fiscal year closes. In my experience working with PHAs, HFAs, and nonprofits, the organizations that struggle are almost always the ones that started thinking about the audit too late.
This guide explains what a Single Audit is, when it is required for your organization, the components of a Single Audit, and where PHAs, HFAs, and Nonprofits often go wrong. Where a specific rule or threshold matters, I cite the governing regulation directly, so you can verify it yourself.
Single Audit, defined
A Single Audit (sometimes still called a "Uniform Guidance audit") is a single, organization-wide audit that covers two things at once:
- Your financial statements, generally audited under GAAS, along with your internal controls over financial reporting, and
- Your compliance with the direct and material attributes of your federal program, along with your internal controls over that compliance.
The point of the "single" in Single Audit is efficiency. Rather than every federal agency that provides you a federal award sending its own auditors, one audit, performed by an independent auditor of your choosing, satisfies them all.
The rules live in the Uniform Guidance, specifically Title 2 of the Code of Federal Regulations, Part 200, Subpart F (2 CFR 200, Subpart F). If you have been in this field for a while, you may remember the prior framework, OMB Circular A-133. The Uniform Guidance replaced A-133, so an "A-133 audit" in older documents simply means today's Single Audit under Subpart F.
Does your organization need a Single Audit? The $1,000,000 threshold
The trigger is a single number. Under 2 CFR 200.501(a), a non-federal entity that expends $1,000,000 or more in federal awards during its fiscal year must have a Single Audit (or, in narrow cases, a program-specific audit) for that year. An organization that expends less than $1,000,000 is exempt from the federal audit requirement for that year, though its records must still be available for review (2 CFR 200.501(e)).
Two points are worth slowing down on, because this is where organizations miscount.
It is often expended, not received. The test is based on expenditures made during the fiscal year, not what you were awarded or what you have in the bank. An organization can hold a large multi-year award and still fall below the threshold in a given year, or the reverse.
Know what counts as a federal award. For PHAs, HFAs, and Nonprofits, the sources that commonly count toward the threshold include HUD program funds, federal funds from the Treasury, the U.S. Department of Agriculture, or federal funds passed through the state or county.
| Threshold | $1,000,000 in federal awards expended in the fiscal year |
| Below threshold | Exempt from federal audit requirement (records still available for review) |
| Test | Expenditures made during the year, not received or awarded |
| Authority | 2 CFR 200.501 |
A note on the threshold itself: it was raised to $1,000,000 by the 2024 revision of the Uniform Guidance (89 FR 30136). The prior threshold was $750,000. If your organization has historically been just over the old line, it is worth checking whether you still trigger an audit under the current threshold, and confirming which fiscal year the change applies to for you.
Single Audit versus a financial statement audit: they are not the same
This is a frequent source of confusion, especially for board members. A financial statement audit and a Single Audit are different obligations with different drivers.
| Financial statement audit | Single Audit | |
|---|---|---|
| What it covers | Whether the financials are fairly stated | The financials plus compliance with federal program rules |
| What triggers it | Bylaws, lenders, funders, state law | Expending $1,000,000+ in federal awards (2 CFR 200.501) |
| Governing standard | GAAS / GAGAS | Uniform Guidance, 2 CFR 200 Subpart F |
| Key extra deliverable | None | Schedule of Expenditures of Federal Awards (SEFA), plus reports on compliance |
Many PHAs, HFAs, and Nonprofits need both, but the Single Audit does not incorporate the financial statement audit. The added weight of a Single Audit is the GAGAS requirements and compliance testing: the auditor is testing whether you followed the specific rules attached to each major federal program.
What a Single Audit covers
A complete Single Audit reporting package, defined at 2 CFR 200.512(c), includes:
- Your financial statements, the Schedule of Expenditures of Federal Awards (SEFA), and the notes to the SEFA
- The auditor's reports, including an opinion on the financial statements, a report on internal control over financial reporting, and an opinion on compliance for each major federal program
- A summary schedule of prior audit findings
- A corrective action plan for any current-year findings
The auditor does not test every dollar expended. Instead, they use a risk-based approach to identify your major programs and concentrate compliance testing there. The mechanics of that determination are set out in the Uniform Guidance and are worth understanding, because the selected "major" program(s) will shape the entire audit.
Why the SEFA is the linchpin
Of everything in the reporting package, the Schedule of Expenditures of Federal Awards deserves special attention because it drives the rest of the audit. The SEFA lists each federal program by its Assistance Listing Number and the amount your organization expended under each program, and is accompanied by required disclosures. The SEFA is used by the auditor to determine the "major" program(s) which will be tested for compliance. If the SEFA is incomplete or misstated, the auditor may test the wrong programs, and a SEFA error is itself a common audit finding. Completeness of the SEFA is tested by the auditor, and this can be an area of great contention during the audit. As this is such a significant portion of your compliance audit, we assist our clients with building processes and procedures that ensure completeness of the SEFA, and accurate financial reporting, throughout the year.
How the auditor decides what to test: major programs
The compliance side of a Single Audit does not weigh every program equally. The auditor follows the risk-based process at 2 CFR 200.518 to identify your major programs. In broad strokes:
- The auditor sorts programs into Type A (larger) and Type B (smaller). For most PHAs, HFAs, and nonprofits, those with total federal awards expended in excess of $1 million up to $34 million, the Type A threshold is $1,000,000 (2 CFR 200.518(b)). Programs with expenditures in excess of that amount can be Type A; the rest are Type B.
- A Type A program is audited as major unless it qualifies as low-risk, which generally requires that it was audited as a major program in one of the two prior years, with no material weakness, no modified opinion, and questioned costs under 5 percent of the program (2 CFR 200.518(c)).
- Selected higher-risk Type B programs are pulled in as well (2 CFR 200.518(d)).
- A percentage-of-coverage rule sets the floor: together, the major programs must cover at least 20 percent of total federal awards expended for a low-risk auditee, or 40 percent otherwise (2 CFR 200.518(f)).
The practical takeaway for your finance team: which programs become "major" is not arbitrary, and it moves year to year with your audit history. A program with findings last year is more likely to be tested this year. Keeping clean results is what reduces both your testable footprint and audit cost over time.
When is the Single Audit due?
Under 2 CFR 200.512(a)(1), the reporting package and data collection form must be submitted to the Federal Audit Clearinghouse within the earlier of:
- 30 calendar days after you receive the auditor's compliance report, or
- nine months after the end of the audit period.
For most organizations the nine-month deadline binds. A June 30 fiscal year-end means a March 31 submission. Missing it jeopardizes future funding, which is one more reason to start early.
Audit findings and questioned costs
When the auditor identifies a problem, it is reported as an audit finding in the schedule of findings and questioned costs. Under 2 CFR 200.516, the auditor must report, among other things:
- Significant deficiencies and material weaknesses in internal control over major programs
- Material noncompliance with the direct and material attributes of the major program
- Known or likely questioned costs greater than $25,000 for a type of compliance requirement within a major program
- Known or likely fraud affecting a federal award
A "questioned cost" is one the auditor cannot conclude was allowable, often because it was unsupported, charged outside the award period, or contrary to the terms of the award. Once questioned costs reach $25,000 for a major program, they must be reported as a finding (2 CFR 200.516(a)(3)).
Every finding follows a standard structure under 2 CFR 200.516(b): the criteria (the rule), the condition (what was found), the cause, and the effect. This is the same information your team will need to build a credible corrective action plan. The auditor must also flag whether a finding repeats one from a prior year (2 CFR 200.516(b)(9)), and repeat findings carry real weight. They signal to your federal funders that earlier corrective action did not hold, they raise your risk profile, and they make it more likely that the program is tested again the following year.
Where PHAs, HFAs, and Nonprofits go wrong
Here is the part that matters most, and it is the part no regulation can teach you. After many audit cycles with these organizations, the same two mistakes come up again and again, and both happen long before fieldwork begins.
1. Not aligning on how the agency defines success before spending. Organizations receiving new federal awards for the first time do not always fully understand how measurable outcomes are defined within the award documents. Before a dollar is spent, the team needs to align on three things: how they intend to use the funds, how the granting agency intends the funds to be used, and what the agency considers to be significant in maintaining compliance with the federal award. When those three are not aligned before the first federal dollar is expended, the audit becomes much harder than it needs to be, because the organization spends the year operating against its own assumptions rather than the agency's actual requirements.
2. Not building the controls to oversee what the audit will actually test. The second recurring mistake is not having the proper controls in place to ensure appropriate oversight of the direct and material compliance attributes the Single Audit will examine. My recommendation is concrete: check each award against the annual OMB Compliance Supplement. The Supplement tells you, program by program, exactly what the auditors will be looking for. Compared against your award, the Supplement becomes a year-round roadmap for the controls and documentation you will need, rather than something you discover during fieldwork.
The single best safeguard against both mistakes is something simple: a short initial process memo for each new award, written before any of the award's funds are spent. Done up front, the memo forces the organization to answer both questions, how the funds will be used and what the agency will hold you accountable for, and to put the tracking, reporting, and control processes in place from day one. It is a small amount of work at the start that prevents a great deal of difficulty at the end. This is exactly the kind of advisory work our firm is built to help with.
How to prepare
A full preparation checklist deserves its own treatment, and we have written one: see our companion guide on the Single Audit PBC list for the document-by-document detail of what your auditor will request. At a high level, the organizations that have smooth audits tend to do four things:
- Write the initial process memo for each new award before spending begins.
- Maintain the SEFA throughout the year and design financial reporting to ensure completeness of the SEFA, rather than attempting to reconstruct it at year-end.
- Map each major program against the current OMB Compliance Supplement.
- Track and close prior-year findings well before the next cycle starts.
Get ahead of your next Single Audit
The organizations that find Single Audits stressful are almost always the ones that started preparing after year-end. The ones that find them routine put their alignment and controls in place before the first federal dollar was spent.
If your Public Housing Authority, Housing Finance Agency, or nonprofit is approaching a Single Audit, or you are taking on a new federal award and want to start it right, schedule a free consultation. We help PHAs, HFAs, and nonprofits build the process and controls that make the audit cycle go smoothly, and we speak your programs fluently.
