How to Build a Subrecipient Risk Matrix That Holds Up
If you pass federal funds through to subrecipients, you've oversight duties you can't delegate away. Here's how to document risk, choose monitoring steps, and separate internal monitoring labels from Single Audit requirements.
Drafted with AI assistance, checked against primary sources, reviewed and approved by Gary Kosman on August 10, 2026.

The job nobody trained you for
You're carrying responsibility that feels bigger than your title.
That feeling is real.
If you run a state service commission, or you're the parent organization passing grant funds to local sites, 2 CFR § 200.332 gives you oversight duties over those subawards. The subrecipient is still responsible for its own compliance. And you, as the pass-through entity, must identify required subaward information, evaluate each subrecipient's fraud risk and risk of noncompliance, monitor as needed, verify that required audits happen, and follow up on audit issues that touch your federal award.
That's the work.
It gets easier when you stop treating monitoring like instinct and start treating it like sequence.
Step one: put the required terms in writing
Before the subaward starts, the pass-through entity must make sure every subaward is clearly identified to the subrecipient as a subaward and includes the information listed in 2 CFR § 200.332(b).
This is where files go thin.
The regulation's list is longer than the shorthand most of us carry around in our heads. It includes Federal Award Identification elements and other required terms, such as:
- the subrecipient's name and UEI
- the federal award date
- the subaward period of performance
- the amount of federal funds obligated by the action, and the total amount obligated to date
- the total amount of the federal award committed to the subrecipient
- the federal award project description, as required to meet the government's transparency rules
- the name of the federal awarding agency, the pass-through entity, and contact information for the awarding official
- the Assistance Listings number and title, if known
- whether the award is research and development
- the applicable indirect cost rate
- all requirements imposed by the pass-through entity so the subrecipient can meet the federal award requirements
- applicable federal requirements and the terms and conditions of the subaward
- a requirement to permit access to records as described in 2 CFR § 200.337
The safest practice is to place these items in the written subaward or in clearly incorporated written award documents.
A kickoff call matters.
It doesn't replace the paperwork.
Step two: evaluate risk before you choose the monitoring plan
Worry shows up here.
You may think, "We know these organizations. We have worked with them for years. Do we really need to score this?"
Yes.
Under 2 CFR § 200.332(c), the pass-through entity must evaluate each subrecipient's fraud risk and risk of noncompliance with a subaward to determine the appropriate monitoring. Both halves matter. A subrecipient can be conscientious about the rules and still sit in a spot where fraud is easy — one person handling every step, no second set of eyes, cash moving quickly at the end of a period. That's a fraud-risk question, and the regulation asks you to look at it.
The regulation says a pass-through entity should consider:
- the subrecipient's prior experience with the same or similar subawards
- the results of previous audits, including whether the subrecipient receives a Single Audit and what that showed
- whether the subrecipient has new personnel or new or substantially changed systems
- the extent and results of any Federal agency monitoring, for example when the subrecipient also receives federal awards directly
That list is what the regulation names. It isn't a ceiling on what you're allowed to look at. Plenty of pass-through entities also weigh what their own prior monitoring turned up, how much money is moving, and how complex the subaward is. Those are sound internal controls — just be clear with yourself and your auditor that they're your additions, not requirements pulled from the regulation.
What doesn't belong on the required-factor list is whether specific conditions are needed. That's a possible response to risk, not one of the named risk factors. If your assessment shows extra guardrails are needed, review 2 CFR § 200.208.
Build a matrix that changes what you do next
A risk matrix isn't the law.
It's your documented method.
That matters because a documented method is easier to defend than a memory. It's also kinder to your staff. Nobody has to guess what "high risk" means in April if you already defined it in October.
Here's one example.
| Risk factor | Low (1) | Medium (2) | High (3) |
|---|---|---|---|
| Prior audit or monitoring issues | None recently | Minor issues, resolved | Repeat or unresolved issues |
| Staff or system changes | Stable team and systems | One major change | Multiple key changes or new systems |
| Subaward size relative to organization | Small share of budget | Moderate share | Large share of budget |
| Program structure | One site, one model | Multiple sites or moving parts | Multiple sites and multiple models |
| Experience as a subrecipient | Several years | Some experience | First year |
| Single Audit history, if applicable | Timely, no relevant findings | Timely with limited issues | Relevant findings or recurring lateness |
Add the scores.
Then assign monitoring steps in advance.
That's the point.
If your matrix doesn't change the monitoring plan, it's decoration.
Common practice is to set internal score bands. For example, a lower score may lead to routine report review with limited supplemental testing, while a higher score may trigger an on-site review, targeted file testing, or added technical assistance. Practice varies. Your own award terms and conditions may also require particular monitoring steps, so check those too.
Know what monitoring is required, and what's optional
This is where precision matters.
Under 2 CFR § 200.332(e), the pass-through entity must monitor subrecipient activities as necessary to ensure the subrecipient complies with federal statutes, regulations, and the terms and conditions of the subaward, and is responsible for monitoring overall performance so the goals and objectives of the subaward are met. That paragraph also spells out four things monitoring must include: reviewing financial and performance reports, ensuring corrective action on significant developments that negatively affect the subaward, issuing a management decision on audit findings that pertain to the subaward, and resolving audit findings specifically related to the subaward.
That required monitoring includes:
- reviewing financial and performance reports required by the pass-through entity
- following up and ensuring the subrecipient takes timely and appropriate action on deficiencies related to the federal award identified through audits, on-site reviews, or other means
- issuing management decisions for audit findings pertaining to the federal award provided to the subrecipient, as required by 2 CFR § 200.521
Then there are additional tools that, depending on the risk you assessed, may be useful under 2 CFR § 200.332(f):
- on-site reviews
- training and technical assistance on program-related matters
- agreed-upon-procedures engagements under 2 CFR § 200.425
- verifying that a subrecipient has an audit required by 2 CFR part 200, subpart F
So no, you can't decide that a low-risk subrecipient gets no monitoring.
You can decide that a lower-risk subrecipient mainly receives timely report review and targeted follow-up, while a higher-risk subrecipient receives deeper testing and more hands-on oversight.
Write down why.
That sentence in the file helps more than the sentence in your head.
Single Audits: what you need to verify, and what triggers a management decision
The threshold changed.
That one detail will trip up a lot of files this year.
A non-federal entity that expends $1,000,000 or more in Federal awards during its fiscal year must have a Single Audit or program-specific audit, as applicable, under 2 CFR § 200.501. That threshold applies to fiscal years beginning on or after October 1, 2024.
For earlier fiscal years, the old $750,000 threshold may still control.
Check the subrecipient's fiscal year before you assume which rule applies.
Verifying that a subrecipient is audited as required by subpart F isn't optional. 2 CFR § 200.332(g) states it as a flat requirement for the pass-through entity, separate from the discretionary tools above.
Under 2 CFR § 200.332(e), the pass-through entity must ensure corrective action on significant developments, issue a management decision on audit findings that pertain to the subaward it made, and resolve audit findings specifically related to that subaward. Cross-cutting findings that reach other federal awards are a different matter — paragraph (e)(4) lets you rely on the subrecipient's cognizant or oversight agency for audit on those, while you stay responsible for the findings tied to your subaward.
For audit findings reported under subpart F that relate to Federal awards it provides, the pass-through entity must issue a management decision under 2 CFR § 200.521. The deadline is within six months of the audit report's acceptance by the Federal Audit Clearinghouse.
That management decision must state whether the finding is sustained, explain the reasons for the decision, and specify the expected auditee action, such as repayment of disallowed costs, financial adjustments, or other corrective action.
Issues you identify through your own monitoring also need follow-up.
But they aren't automatically Subpart F audit findings.
Handle those under the subaward, your written monitoring policy, and any applicable AmeriCorps terms and conditions.
A "concern" is your label. An audit finding has a regulation behind it.
This is where people either overreact or hide.
If you call every small issue a finding, your subrecipients stop hearing you.
If you avoid the word finding because it feels harsh, real noncompliance sits in the dark.
The cleanest answer is this: "concern" is usually an internal monitoring label, not a defined term in 2 CFR part 200. Organizations often use it for issues that need follow-up but aren't being treated as formal monitoring findings.
"Audit finding" is different. That term has a regulatory framework in 2 CFR § 200.516 and 2 CFR § 200.521.
For your own monitoring program, define your terms in policy.
Say what makes something a concern.
Say what makes something a formal monitoring finding.
Say what documentation, corrective action, and follow-up each one requires.
That way your team isn't improvising in the moment, and your subrecipients aren't left guessing what comes next.
Monitoring works best when nobody is surprised by the rules, the records, or the follow-up.
Before publishing a policy or relying on a template, verify the current eCFR text for 2 CFR § 200.332, 2 CFR § 200.501, 2 CFR § 200.516, 2 CFR § 200.521, and 2 CFR § 200.208. Then read those against your current AmeriCorps terms and conditions, because grant terms can add requirements beyond the federal floor.
A quick reminder
AmeriCorps grants can vary from one to the next. If you’re unsure how a rule applies to your program, check with your commission or designated point of contact at the AmeriCorps agency for any additional guidance and clarifications. They know your award terms best.
Questions people ask
- What information must a pass-through entity include in a subaward under 2 CFR 200.332?
Under 2 CFR § 200.332(b), the pass-through entity must ensure every subaward is clearly identified to the subrecipient as a subaward and includes the required Federal Award Identification information and other required terms in writing to the subrecipient. That includes items such as the subrecipient's name and UEI, award date, period of performance, obligated amounts, federal award project description, awarding-agency and pass-through contact information, the Assistance Listings number and title if known, whether the award is R&D, the indirect cost rate, applicable federal requirements and subaward terms, any pass-through requirements needed for the subrecipient to meet the federal award, and a requirement to permit access to records under 2 CFR § 200.337. The safest practice is to put these terms in the written subaward or clearly incorporated written award documents and check the full regulatory list.
- What's the current Single Audit threshold and when did it change?
A non-federal entity that expends $1,000,000 or more in Federal awards during its fiscal year must have a Single Audit or program-specific audit, as applicable, under 2 CFR § 200.501. That $1,000,000 threshold applies to fiscal years beginning on or after October 1, 2024. For earlier fiscal years, the prior $750,000 threshold may still apply, so you need to check the subrecipient's fiscal year.
- What's the difference between a finding and a concern in subrecipient monitoring?
"Concern" is typically an internal monitoring label, not a term defined by 2 CFR part 200. Many pass-through entities use it for issues that need follow-up but aren't being treated as formal monitoring findings. "Audit finding" is a regulated term under 2 CFR § 200.516, and management decisions for relevant Subpart F audit findings are governed by 2 CFR § 200.521. For day-to-day monitoring, define in your written policy what counts as a concern, what counts as a formal monitoring finding, and what follow-up each requires.
- What risk factors does 2 CFR 200.332 say a pass-through entity may consider?
2 CFR § 200.332(c) requires the pass-through entity to evaluate each subrecipient's fraud risk and risk of noncompliance, and says it should consider the subrecipient's prior experience with the same or similar subawards, the results of previous audits (including whether the subrecipient receives a Single Audit and whether similar subawards were audited as a major program), whether the subrecipient has new personnel or new or substantially changed systems, and the extent and results of any Federal agency monitoring. You may weigh additional factors of your own, but the four above are the ones the regulation names. Whether to impose specific conditions is a response to the risk assessment, addressed separately in 2 CFR § 200.208 and 2 CFR § 200.332(d).
- What if my grant comes through a state or territory service commission?
- Check your commission’s current requirements too. They may be stricter than the federal floor, and stricter is what you follow. What a commission can’t do is override controlling federal law, regulation, or your AmeriCorps award terms, and it can grant only the waivers it’s authorized to grant. Read this post alongside your commission’s guidance, your award terms, and your written policies — and when something looks like a real conflict, ask your commission or program officer rather than guessing.
About the author
Gary Kosman is the founder and CEO of America Learns. He has worked with AmeriCorps programs and state service commissions for more than two decades, helping organizations strengthen the systems they use to manage members, grants, reporting, compliance, and impact. Reach him at gary@americalearns.net or 310-689-0542 x101.
Last reviewed August 10, 2026. Regulations change. Verify every citation against the current eCFR text and your own grant terms and conditions before you rely on it.
Looking for another topic?
Browse all compliance topics — from timesheets and member files to financial and progress reporting.
Browse topicsKeep reading on subgrantee monitoring and related topics
Subgrantee Monitoring/August 7, 2026
How to Read a Subgrantee Financial Report Like a Monitor
A clean expenditure report can still hide weak support. Your job as a monitor is to tie each line to the accounting records, payroll or activity records, and match support, then follow every variance until it makes sense.
OIG Findings/September 4, 2026
How Commissions Can Catch Timesheet and Term Errors Early
When education awards are tied to weak time records or unsupported service-term changes, the cost lands late and hard. A commission can catch most of it before exit with a tighter review sequence.
Performance Measurement/September 2, 2026
Your Data-Collection System Is Part of Your Audit Trail
Surveys, logs, and tests can become Federal award records. Federal rules do not require you to keep every draft or form configuration — they require retention of the records and supporting documentation that substantiate what you reported. ([2 CFR § 200.334](https://www.ecfr.gov/current/title-2/section-200.334))
2 CFR 200 Basics/August 18, 2026
When Staff Duties and Timesheets Don’t Match
Salary costs get vulnerable when payroll support, payroll charges, and the role described in your award materials stop lining up. The fix starts with a clean match between supported work, the amount charged, and the staffing picture your award says you funded.
Member Timesheets/August 12, 2026
What AmeriCorps Members Cannot Do on Service Time
The first question is about time and duties. If a member or staff person engages in a prohibited activity while charging time to the AmeriCorps program, accumulating service or training hours, or otherwise performing activities supported by the AmeriCorps program or AmeriCorps, your program should review the record promptly under its written procedures, award terms, and any applicable AmeriCorps or pass-through instructions. Private-citizen participation in the listed activities has its own conditions too, including a logo instruction in the regulation.