Subgrantee Monitoring

How to Build a Subrecipient Risk Matrix That Holds Up

If you pass federal funds through to subrecipients, you've oversight duties you can't delegate away. Here's how to document risk, choose monitoring steps, and separate internal monitoring labels from Single Audit requirements.

By Gary Kosman·

July 30, 2026/7 min read

Drafted with AI assistance, checked against primary sources, reviewed and approved by Gary Kosman on August 10, 2026.

Hand-drawn style infographic of a subrecipient risk matrix with scored factors feeding into a documented monitoring plan.

The job nobody trained you for

You're carrying responsibility that feels bigger than your title.

That feeling is real.

If you run a state service commission, or you're the parent organization passing grant funds to local sites, 2 CFR § 200.332 gives you oversight duties over those subawards. The subrecipient is still responsible for its own compliance. And you, as the pass-through entity, must identify required subaward information, evaluate each subrecipient's fraud risk and risk of noncompliance, monitor as needed, verify that required audits happen, and follow up on audit issues that touch your federal award.

That's the work.

It gets easier when you stop treating monitoring like instinct and start treating it like sequence.

Step one: put the required terms in writing

Before the subaward starts, the pass-through entity must make sure every subaward is clearly identified to the subrecipient as a subaward and includes the information listed in 2 CFR § 200.332(b).

This is where files go thin.

The regulation's list is longer than the shorthand most of us carry around in our heads. It includes Federal Award Identification elements and other required terms, such as:

  • the subrecipient's name and UEI
  • the federal award date
  • the subaward period of performance
  • the amount of federal funds obligated by the action, and the total amount obligated to date
  • the total amount of the federal award committed to the subrecipient
  • the federal award project description, as required to meet the government's transparency rules
  • the name of the federal awarding agency, the pass-through entity, and contact information for the awarding official
  • the Assistance Listings number and title, if known
  • whether the award is research and development
  • the applicable indirect cost rate
  • all requirements imposed by the pass-through entity so the subrecipient can meet the federal award requirements
  • applicable federal requirements and the terms and conditions of the subaward
  • a requirement to permit access to records as described in 2 CFR § 200.337

The safest practice is to place these items in the written subaward or in clearly incorporated written award documents.

A kickoff call matters.

It doesn't replace the paperwork.

Step two: evaluate risk before you choose the monitoring plan

Worry shows up here.

You may think, "We know these organizations. We have worked with them for years. Do we really need to score this?"

Yes.

Under 2 CFR § 200.332(c), the pass-through entity must evaluate each subrecipient's fraud risk and risk of noncompliance with a subaward to determine the appropriate monitoring. Both halves matter. A subrecipient can be conscientious about the rules and still sit in a spot where fraud is easy — one person handling every step, no second set of eyes, cash moving quickly at the end of a period. That's a fraud-risk question, and the regulation asks you to look at it.

The regulation says a pass-through entity should consider:

  • the subrecipient's prior experience with the same or similar subawards
  • the results of previous audits, including whether the subrecipient receives a Single Audit and what that showed
  • whether the subrecipient has new personnel or new or substantially changed systems
  • the extent and results of any Federal agency monitoring, for example when the subrecipient also receives federal awards directly

That list is what the regulation names. It isn't a ceiling on what you're allowed to look at. Plenty of pass-through entities also weigh what their own prior monitoring turned up, how much money is moving, and how complex the subaward is. Those are sound internal controls — just be clear with yourself and your auditor that they're your additions, not requirements pulled from the regulation.

What doesn't belong on the required-factor list is whether specific conditions are needed. That's a possible response to risk, not one of the named risk factors. If your assessment shows extra guardrails are needed, review 2 CFR § 200.208.

Build a matrix that changes what you do next

A risk matrix isn't the law.

It's your documented method.

That matters because a documented method is easier to defend than a memory. It's also kinder to your staff. Nobody has to guess what "high risk" means in April if you already defined it in October.

Here's one example.

Risk factorLow (1)Medium (2)High (3)
Prior audit or monitoring issuesNone recentlyMinor issues, resolvedRepeat or unresolved issues
Staff or system changesStable team and systemsOne major changeMultiple key changes or new systems
Subaward size relative to organizationSmall share of budgetModerate shareLarge share of budget
Program structureOne site, one modelMultiple sites or moving partsMultiple sites and multiple models
Experience as a subrecipientSeveral yearsSome experienceFirst year
Single Audit history, if applicableTimely, no relevant findingsTimely with limited issuesRelevant findings or recurring lateness

Add the scores.

Then assign monitoring steps in advance.

That's the point.

If your matrix doesn't change the monitoring plan, it's decoration.

Common practice is to set internal score bands. For example, a lower score may lead to routine report review with limited supplemental testing, while a higher score may trigger an on-site review, targeted file testing, or added technical assistance. Practice varies. Your own award terms and conditions may also require particular monitoring steps, so check those too.

Know what monitoring is required, and what's optional

This is where precision matters.

Under 2 CFR § 200.332(e), the pass-through entity must monitor subrecipient activities as necessary to ensure the subrecipient complies with federal statutes, regulations, and the terms and conditions of the subaward, and is responsible for monitoring overall performance so the goals and objectives of the subaward are met. That paragraph also spells out four things monitoring must include: reviewing financial and performance reports, ensuring corrective action on significant developments that negatively affect the subaward, issuing a management decision on audit findings that pertain to the subaward, and resolving audit findings specifically related to the subaward.

That required monitoring includes:

  • reviewing financial and performance reports required by the pass-through entity
  • following up and ensuring the subrecipient takes timely and appropriate action on deficiencies related to the federal award identified through audits, on-site reviews, or other means
  • issuing management decisions for audit findings pertaining to the federal award provided to the subrecipient, as required by 2 CFR § 200.521

Then there are additional tools that, depending on the risk you assessed, may be useful under 2 CFR § 200.332(f):

  • on-site reviews
  • training and technical assistance on program-related matters
  • agreed-upon-procedures engagements under 2 CFR § 200.425
  • verifying that a subrecipient has an audit required by 2 CFR part 200, subpart F

So no, you can't decide that a low-risk subrecipient gets no monitoring.

You can decide that a lower-risk subrecipient mainly receives timely report review and targeted follow-up, while a higher-risk subrecipient receives deeper testing and more hands-on oversight.

Write down why.

That sentence in the file helps more than the sentence in your head.

Single Audits: what you need to verify, and what triggers a management decision

The threshold changed.

That one detail will trip up a lot of files this year.

A non-federal entity that expends $1,000,000 or more in Federal awards during its fiscal year must have a Single Audit or program-specific audit, as applicable, under 2 CFR § 200.501. That threshold applies to fiscal years beginning on or after October 1, 2024.

For earlier fiscal years, the old $750,000 threshold may still control.

Check the subrecipient's fiscal year before you assume which rule applies.

Verifying that a subrecipient is audited as required by subpart F isn't optional. 2 CFR § 200.332(g) states it as a flat requirement for the pass-through entity, separate from the discretionary tools above.

Under 2 CFR § 200.332(e), the pass-through entity must ensure corrective action on significant developments, issue a management decision on audit findings that pertain to the subaward it made, and resolve audit findings specifically related to that subaward. Cross-cutting findings that reach other federal awards are a different matter — paragraph (e)(4) lets you rely on the subrecipient's cognizant or oversight agency for audit on those, while you stay responsible for the findings tied to your subaward.

For audit findings reported under subpart F that relate to Federal awards it provides, the pass-through entity must issue a management decision under 2 CFR § 200.521. The deadline is within six months of the audit report's acceptance by the Federal Audit Clearinghouse.

That management decision must state whether the finding is sustained, explain the reasons for the decision, and specify the expected auditee action, such as repayment of disallowed costs, financial adjustments, or other corrective action.

Issues you identify through your own monitoring also need follow-up.

But they aren't automatically Subpart F audit findings.

Handle those under the subaward, your written monitoring policy, and any applicable AmeriCorps terms and conditions.

A "concern" is your label. An audit finding has a regulation behind it.

This is where people either overreact or hide.

If you call every small issue a finding, your subrecipients stop hearing you.

If you avoid the word finding because it feels harsh, real noncompliance sits in the dark.

The cleanest answer is this: "concern" is usually an internal monitoring label, not a defined term in 2 CFR part 200. Organizations often use it for issues that need follow-up but aren't being treated as formal monitoring findings.

"Audit finding" is different. That term has a regulatory framework in 2 CFR § 200.516 and 2 CFR § 200.521.

For your own monitoring program, define your terms in policy.

Say what makes something a concern.

Say what makes something a formal monitoring finding.

Say what documentation, corrective action, and follow-up each one requires.

That way your team isn't improvising in the moment, and your subrecipients aren't left guessing what comes next.

Monitoring works best when nobody is surprised by the rules, the records, or the follow-up.

Before publishing a policy or relying on a template, verify the current eCFR text for 2 CFR § 200.332, 2 CFR § 200.501, 2 CFR § 200.516, 2 CFR § 200.521, and 2 CFR § 200.208. Then read those against your current AmeriCorps terms and conditions, because grant terms can add requirements beyond the federal floor.

A quick reminder

AmeriCorps grants can vary from one to the next. If you’re unsure how a rule applies to your program, check with your commission or designated point of contact at the AmeriCorps agency for any additional guidance and clarifications. They know your award terms best.

Questions people ask

What information must a pass-through entity include in a subaward under 2 CFR 200.332?

Under 2 CFR § 200.332(b), the pass-through entity must ensure every subaward is clearly identified to the subrecipient as a subaward and includes the required Federal Award Identification information and other required terms in writing to the subrecipient. That includes items such as the subrecipient's name and UEI, award date, period of performance, obligated amounts, federal award project description, awarding-agency and pass-through contact information, the Assistance Listings number and title if known, whether the award is R&D, the indirect cost rate, applicable federal requirements and subaward terms, any pass-through requirements needed for the subrecipient to meet the federal award, and a requirement to permit access to records under 2 CFR § 200.337. The safest practice is to put these terms in the written subaward or clearly incorporated written award documents and check the full regulatory list.

What's the current Single Audit threshold and when did it change?

A non-federal entity that expends $1,000,000 or more in Federal awards during its fiscal year must have a Single Audit or program-specific audit, as applicable, under 2 CFR § 200.501. That $1,000,000 threshold applies to fiscal years beginning on or after October 1, 2024. For earlier fiscal years, the prior $750,000 threshold may still apply, so you need to check the subrecipient's fiscal year.

What's the difference between a finding and a concern in subrecipient monitoring?

"Concern" is typically an internal monitoring label, not a term defined by 2 CFR part 200. Many pass-through entities use it for issues that need follow-up but aren't being treated as formal monitoring findings. "Audit finding" is a regulated term under 2 CFR § 200.516, and management decisions for relevant Subpart F audit findings are governed by 2 CFR § 200.521. For day-to-day monitoring, define in your written policy what counts as a concern, what counts as a formal monitoring finding, and what follow-up each requires.

What risk factors does 2 CFR 200.332 say a pass-through entity may consider?

2 CFR § 200.332(c) requires the pass-through entity to evaluate each subrecipient's fraud risk and risk of noncompliance, and says it should consider the subrecipient's prior experience with the same or similar subawards, the results of previous audits (including whether the subrecipient receives a Single Audit and whether similar subawards were audited as a major program), whether the subrecipient has new personnel or new or substantially changed systems, and the extent and results of any Federal agency monitoring. You may weigh additional factors of your own, but the four above are the ones the regulation names. Whether to impose specific conditions is a response to the risk assessment, addressed separately in 2 CFR § 200.208 and 2 CFR § 200.332(d).

What if my grant comes through a state or territory service commission?
Check your commission’s current requirements too. They may be stricter than the federal floor, and stricter is what you follow. What a commission can’t do is override controlling federal law, regulation, or your AmeriCorps award terms, and it can grant only the waivers it’s authorized to grant. Read this post alongside your commission’s guidance, your award terms, and your written policies — and when something looks like a real conflict, ask your commission or program officer rather than guessing.

About the author

Gary Kosman is the founder and CEO of America Learns. He has worked with AmeriCorps programs and state service commissions for more than two decades, helping organizations strengthen the systems they use to manage members, grants, reporting, compliance, and impact. Reach him at gary@americalearns.net or 310-689-0542 x101.

Last reviewed August 10, 2026. Regulations change. Verify every citation against the current eCFR text and your own grant terms and conditions before you rely on it.

Looking for another topic?

Browse all compliance topics — from timesheets and member files to financial and progress reporting.

Browse topics

Keep reading on subgrantee monitoring and related topics

Member Timesheets/August 12, 2026

What AmeriCorps Members Cannot Do on Service Time

The first question is about time and duties. If a member or staff person engages in a prohibited activity while charging time to the AmeriCorps program, accumulating service or training hours, or otherwise performing activities supported by the AmeriCorps program or AmeriCorps, your program should review the record promptly under its written procedures, award terms, and any applicable AmeriCorps or pass-through instructions. Private-citizen participation in the listed activities has its own conditions too, including a logo instruction in the regulation.