OIG Findings

The AmeriCorps OIG Findings That Keep Coming Back

Published AmeriCorps OIG reports often point to the same kinds of compliance breakdowns. Here's where the patterns tend to show up, why good organizations still get caught there, and the control that helps.

By Gary Kosman·

July 31, 2026/6 min read

Hand-drawn wheel diagram showing six recurring AmeriCorps OIG finding themes around a center labeled Recurring OIG themes.

Read the findings before they're about you

You can feel the dread before you open the report.

That feeling is real. It doesn't mean you failed. Audits stir up shame, and shame makes smart people hide messy files instead of fixing them. Name that early. It helps.

Published reports available from the AmeriCorps Office of Inspector General website are public and free to read, and they can help you spot compliance risks before an audit lands on your desk.

These trouble spots appear often enough in published oversight work that they deserve your attention. Not because grantees are careless. Because a few requirements collide hard with real life: turnover, dispersed sites, part-time supervisors, and records created at the end of a long service day.

There are three different buckets here.

What the regulation requires. These are binding rules in the current eCFR.

What AmeriCorps award terms and conditions may add. These can be stricter, more specific, or program-specific.

What many experienced operators do as a control. Useful practice. Not the same thing as a regulation.

Verify each requirement against the current eCFR text before you rely on it, especially 2 CFR § 200.1, 2 CFR § 200.303, 2 CFR § 200.306, 2 CFR § 200.430, 2 CFR § 200.332, 2 CFR § 200.339, and the current National Service Criminal History Check regulations in 45 CFR part 2540, subpart B. Then check your own grant terms and conditions.

How an OIG audit usually unfolds

The process itself creates a lot of fear.

For an audit, the sequence commonly includes notice or an entrance conference, document review and interviews, testing of selected files and transactions, some form of draft or preliminary findings where the auditee can respond if the engagement provides for that step, a final report, and then agency resolution.

That last part matters.

The OIG reports findings. The awarding agency handles resolution. Those aren't the same role.

Procedures vary by engagement. Investigations are different from audits, and not every matter follows the same labels or timing.

Questioned costs aren't the same as disallowed costs

People say these two phrases like they mean the same thing. They don't.

Under 2 CFR § 200.1, questioned costs are costs questioned by an auditor because of an alleged violation of law, regulation, or award terms and conditions; because there's not enough documentation; or because the cost appears unreasonable.

Also under 2 CFR § 200.1, disallowed costs are costs charged to a Federal award that the Federal agency or pass-through entity determines aren't allowable.

So the hard-earned insight is this: a questioned cost is a warning signal, not the final allowability decision.

But it isn't nothing.

A questioned cost may be disallowed during resolution. A Federal agency or pass-through entity may apply remedies authorized by the award and applicable rules, including the remedies in 2 CFR § 200.339, as applicable.

The recurring themes

Time and attendance documentation

What the rule requires: For compensation charged to a Federal award, 2 CFR § 200.430(i) requires records that accurately reflect the work performed and are supported by internal controls that provide reasonable assurance charges are accurate, allowable, and properly allocated. 2 CFR § 200.303 sets the broader internal-control requirement.

Why good programs still trip here: Timekeeping is the most decentralized record in the building. It's created by busy people, often after the fact, across multiple sites.

A control that helps: Use one consistent timekeeping process across sites. Set a review schedule based on your risk and your award requirements. Keep an auditable correction trail. If your current process allows silent edits, backdating, or unsigned exceptions, that's the real problem.

Member eligibility documentation

What the rule requires: Member eligibility rules vary by AmeriCorps program, statute, regulation, and award terms. Don't assume one checklist fits every stream. Verify the requirements that apply to your program before enrollment and before service begins where required.

Why good programs still trip here: You're trying to fill slots, start a cohort, answer ten emails, and keep the service site calm. That's exactly when incomplete files slip through.

A control that helps: Use a documented eligibility checklist tied to the specific program. Don't allow service to start until all prerequisites that must be completed before service are verified. If your award allows any post-enrollment documentation deadlines, track those separately and visibly.

National Service Criminal History Check timing and documentation

What the rule requires: Follow the current NSCHC rules in 45 CFR part 2540, subpart B. For covered individuals, the current rules specify required NSCHC components and timing, including a National Sex Offender Public Website check, State criminal-history checks, and an FBI criminal-history check, subject to the subpart's definitions and exceptions. Don't rely on the idea that a check was merely initiated. Timing, documentation, review, and any use of the limited accompaniment exception all have to match the current rule and your award terms.

Why good programs still trip here: The task often sits between program, HR, and site staff. When ownership is split, nobody sees the whole deadline chain.

A control that helps: Name one person responsible for NSCHC tracking. Use a date-based tracker. Require a second review before the person starts work or service. If you use accompaniment, document the basis and dates with unusual care.

Unsupported or unallowable costs and match

What the rule requires: Costs charged to the award must meet the Uniform Guidance cost standards, including allowability and documentation. Match must be verifiable from the recipient's records, and third-party in-kind contributions must be supported by the contributor's records under 2 CFR § 200.306.

Why good programs still trip here: Match often lives in spreadsheets built from memory, goodwill, and end-of-quarter reconstruction. Auditors don't audit goodwill.

A control that helps: Treat match support with the same seriousness as drawdown support. Keep source records or supported summaries that can be traced back to source records. For valuations, write down who set the value, when, and on what basis.

Weak subrecipient monitoring

What the rule requires: A pass-through entity must evaluate each subrecipient's risk of noncompliance, monitor subrecipient activities, and address identified noncompliance under 2 CFR § 200.332. Some monitoring steps will depend on whether the subrecipient is subject to Subpart F and on what your award terms require.

Why good programs still trip here: Monitoring gets deferred when a subrecipient seems competent and the inbox is already on fire.

A control that helps: Put your monitoring plan in writing. Tie it to a risk assessment. Calendar the steps in advance. If practice varies by program or commission, say that in the file and point to the rule or term that supports the difference.

Internal control deficiencies

What the rule requires: 2 CFR § 200.303 requires recipients and subrecipients to establish, document, and maintain effective internal control over Federal awards that provides reasonable assurance of compliance with statutes, regulations, and award terms and conditions.

Why good programs still trip here: Internal control sounds abstract until an auditor asks for the record that proves the policy happened. Then it gets very concrete.

A control that helps: Write the procedure. Follow the procedure. Keep evidence that someone checked whether the procedure was followed. A policy no one can prove is being used is comfort, not control.

Read the reports. Then build the file.

This is the part nobody says out loud.

Some published findings concern inadequate documentation or controls rather than an allegation of fraud.

That can feel unfair when you know the program did real service. It's still the rule environment you're working in.

The finding you read in someone else's report is the one you still have time to test in your own files.

If you want one habit worth keeping, make it small enough to survive a busy month: read one published OIG report or summary from the AmeriCorps OIG website from time to time, note the control gap it describes, and compare it to your own process.

Not to scare yourself.

To make the next audit less surprising.

Questions people actually ask

What's the difference between a questioned cost and a disallowed cost?
Under [2 CFR § 200.1](https://www.ecfr.gov/current/title-2/section-200.1), a questioned cost is a cost questioned by an auditor because of an alleged violation of law, regulation, or award terms and conditions, because it lacks adequate documentation, or because it appears unreasonable. A disallowed cost is a cost that the Federal agency or pass-through entity determines isn't allowable. A questioned cost isn't automatically disallowed, but it can become one after resolution.
What are the main steps of an AmeriCorps OIG audit?
Audit procedures vary, but an OIG audit commonly includes notice or an entrance conference, document requests, interviews, testing of selected records, and a final report. Some engagements also include draft findings or a draft report for factual comment before issuance. After the report, the awarding agency handles resolution of findings and any questioned costs. Investigations follow different procedures.
Where can I read past AmeriCorps OIG reports?
Published audit reports, semiannual reports, and some investigative materials are available on the [AmeriCorps Office of Inspector General website](https://www.americorpsoig.gov/). Don't assume every investigation results in a public report.
What internal control regulation underlies many AmeriCorps compliance findings?
[2 CFR § 200.303](https://www.ecfr.gov/current/title-2/section-200.303) requires recipients and subrecipients to establish, document, and maintain effective internal control over Federal awards that provides reasonable assurance of compliance with statutes, regulations, and the terms and conditions of the Federal award. When auditors cite weak internal controls, they're pointing to a gap in that documented system of compliance.

About the author

Gary Kosman writes AmeriCorps Compliance Central, an independent publication about AmeriCorps grant compliance. He is CEO, America Learns. Reach him at gary@americalearns.net or 310-689-0542 x101.

Last reviewed August 4, 2026. Regulations change. Verify every citation against the current eCFR text and your own grant terms and conditions before you rely on it.