How to Build a Subrecipient Risk Matrix That Actually Holds Up
If you pass federal funds through to subrecipients, you've oversight duties you can't delegate away. Here's how to document risk, choose monitoring steps, and separate internal monitoring labels from Single Audit requirements.

The job nobody trained you for
You're carrying responsibility that feels bigger than your title.
That feeling is real.
If you run a state service commission, or you're the parent organization passing grant funds to local sites, 2 CFR § 200.332 gives you oversight duties over those subawards. The subrecipient is still responsible for its own compliance. And you, as the pass-through entity, must identify required subaward information, evaluate risk, monitor as needed, and follow up on audit issues that touch your federal award.
That's the work.
It gets easier when you stop treating monitoring like instinct and start treating it like sequence.
Step one: put the required terms in writing
Before the subaward starts, the pass-through entity must identify the information required by 2 CFR § 200.332(a) to the subrecipient in writing.
This is where files go thin.
The regulation's list is longer than the shorthand most of us carry around in our heads. It includes Federal Award Identification elements and other required terms, such as:
- the subrecipient's name and UEI
- the federal award date
- the subaward period of performance
- the amount of federal funds obligated by the action, and the total amount obligated to date
- the total amount of the federal award committed to the subrecipient
- the federal award project description, as required to meet the government's transparency rules
- the name of the federal awarding agency, the pass-through entity, and contact information for the awarding official
- the Assistance Listings number and title, if known
- whether the award is research and development
- the applicable indirect cost rate
- all requirements imposed by the pass-through entity so the subrecipient can meet the federal award requirements
- applicable federal requirements and the terms and conditions of the subaward
- a requirement to permit access to records as described in 2 CFR § 200.337
The safest practice is to place these items in the written subaward or in clearly incorporated written award documents.
A kickoff call matters.
It doesn't replace the paperwork.
Step two: evaluate risk before you choose the monitoring plan
Shame shows up here.
You may think, "We know these organizations. We have worked with them for years. Do we really need to score this?"
Yes.
Under 2 CFR § 200.332(b), the pass-through entity must evaluate each subrecipient's risk of noncompliance to determine the appropriate monitoring level.
The regulation says that evaluation may consider:
- the subrecipient's prior experience with the same or similar subawards
- the results of previous audits, including whether the subrecipient receives a Single Audit and what that showed
- whether the subrecipient has new personnel or new or substantially changed systems
- the extent and results of Federal awarding agency monitoring
The regulation also says you may consider other factors. One example it gives is how similar the subaward requirements are to requirements already imposed on your own organization. As another practical example under that nonexclusive approach, many pass-through entities also consider what their own prior monitoring has shown.
What doesn't belong on the required-factor list is whether specific conditions are needed. That's a possible response to risk, not one of the named risk factors. If your assessment shows extra guardrails are needed, review 2 CFR § 200.208.\n\n\n(Note: The Grant Gateway -- America Learns' AmeriCorps Grant Application platform -- comes with a proven risk assessment template so service commissions don't have to start from scratch on this work.)
Build a matrix that changes what you do next
A risk matrix isn't the law.
It's your documented method.
That matters because a documented method is easier to defend than a memory. It's also kinder to your staff. Nobody has to guess what "high risk" means in April if you already defined it in October.
Here's one example.
| Risk factor | Low (1) | Medium (2) | High (3) |
|---|---|---|---|
| Prior audit or monitoring issues | None recently | Minor issues, resolved | Repeat or unresolved issues |
| Staff or system changes | Stable team and systems | One major change | Multiple key changes or new systems |
| Subaward size relative to organization | Small share of budget | Moderate share | Large share of budget |
| Program structure | One site, one model | Multiple sites or moving parts | Multiple sites and multiple models |
| Experience as a subrecipient | Several years | Some experience | First year |
| Single Audit history, if applicable | Timely, no relevant findings | Timely with limited issues | Relevant findings or recurring lateness |
Add the scores.
Then assign monitoring steps in advance.
That's the point.
If your matrix doesn't change the monitoring plan, it's decoration.
Common practice is to set internal score bands. For example, a lower score may lead to routine report review with limited supplemental testing, while a higher score may trigger an on-site review, targeted file testing, or added technical assistance. Practice varies. Your own award terms and conditions may also require particular monitoring steps, so check those too.
Know what monitoring is required, and what's optional
This is where precision matters.
Under 2 CFR § 200.332(d), the pass-through entity must monitor subrecipient activities as necessary to ensure the subaward is used for authorized purposes, complies with federal statutes and regulations, and follows the subaward terms and conditions.
That required monitoring includes:
- reviewing financial and performance reports required by the pass-through entity
- following up and ensuring the subrecipient takes timely and appropriate action on deficiencies related to the federal award identified through audits, on-site reviews, or other means
- issuing management decisions for audit findings pertaining to the federal award provided to the subrecipient, as required by 2 CFR § 200.521
Then there are additional tools the pass-through entity may use under 2 CFR § 200.332(e):
- on-site reviews
- training and technical assistance on program-related matters
- agreed-upon-procedures engagements under 2 CFR § 200.425
- verifying that a subrecipient has an audit required by 2 CFR part 200, subpart F
So no, you can't decide that a low-risk subrecipient gets no monitoring.
You can decide that a lower-risk subrecipient mainly receives timely report review and targeted follow-up, while a higher-risk subrecipient receives deeper testing and more hands-on oversight.
Write down why.
That sentence in the file helps more than the sentence in your head.
Single Audits: what you need to verify, and what triggers a management decision
The threshold changed.
That one detail will trip up a lot of files this year.
A non-federal entity that expends $1,000,000 or more in Federal awards during its fiscal year must have a Single Audit or program-specific audit, as applicable, under 2 CFR § 200.501. That threshold applies to fiscal years beginning on or after October 1, 2024.
For earlier fiscal years, the old $750,000 threshold may still control.
Check the subrecipient's fiscal year before you assume which rule applies.
As an additional monitoring tool, 2 CFR § 200.332(e) permits the pass-through entity to verify that the subrecipient obtained the required audit, when applicable.
Under 2 CFR § 200.332(d), the pass-through entity must follow up on deficiencies and audit findings that pertain to the federal award it passed through.
For audit findings reported under subpart F that relate to Federal awards it provides, the pass-through entity must issue a management decision under 2 CFR § 200.521. The deadline is within six months of the audit report's acceptance by the Federal Audit Clearinghouse.
That management decision must state whether the finding is sustained, explain the reasons for the decision, and specify the expected auditee action, such as repayment of disallowed costs, financial adjustments, or other corrective action.
Issues you identify through your own monitoring also need follow-up.
But they aren't automatically Subpart F audit findings.
Handle those under the subaward, your written monitoring policy, and any applicable AmeriCorps terms and conditions.
A "concern" is your label. An audit finding has a regulation behind it.
This is where people either overreact or hide.
If you call every small issue a finding, your subrecipients stop hearing you.
If you avoid the word finding because it feels harsh, real noncompliance sits in the dark.
The cleanest answer is this: "concern" is usually an internal monitoring label, not a defined term in 2 CFR part 200. Organizations often use it for issues that need follow-up but aren't being treated as formal monitoring findings.
"Audit finding" is different. That term has a regulatory framework in 2 CFR § 200.516 and 2 CFR § 200.521.
For your own monitoring program, define your terms in policy.
Say what makes something a concern.
Say what makes something a formal monitoring finding.
Say what documentation, corrective action, and follow-up each one requires.
That way your team isn't improvising in the moment, and your subrecipients aren't left guessing what comes next.
Monitoring works best when nobody is surprised by the rules, the records, or the follow-up.
Before publishing a policy or relying on a template, verify the current eCFR text for 2 CFR § 200.332, 2 CFR § 200.501, 2 CFR § 200.516, 2 CFR § 200.521, and 2 CFR § 200.208. Then read those against your current AmeriCorps terms and conditions, because grant terms can add requirements beyond the federal floor.
Questions people actually ask
- What information must a pass-through entity include in a subaward under 2 CFR 200.332?
- Under [2 CFR § 200.332(a)](https://www.ecfr.gov/current/title-2/section-200.332), the pass-through entity must provide required Federal Award Identification information and other required terms in writing to the subrecipient. That includes items such as the subrecipient's name and UEI, award date, period of performance, obligated amounts, federal award project description, awarding-agency and pass-through contact information, the [Assistance Listings](https://sam.gov/content/assistance-listings) number and title if known, whether the award is R&D, the indirect cost rate, applicable federal requirements and subaward terms, any pass-through requirements needed for the subrecipient to meet the federal award, and a requirement to permit access to records under [2 CFR § 200.337](https://www.ecfr.gov/current/title-2/section-200.337). The safest practice is to put these terms in the written subaward or clearly incorporated written award documents and check the full regulatory list.
- What's the current Single Audit threshold and when did it change?
- A non-federal entity that expends $1,000,000 or more in Federal awards during its fiscal year must have a Single Audit or program-specific audit, as applicable, under [2 CFR § 200.501](https://www.ecfr.gov/current/title-2/section-200.501). That $1,000,000 threshold applies to fiscal years beginning on or after October 1, 2024. For earlier fiscal years, the prior $750,000 threshold may still apply, so you need to check the subrecipient's fiscal year.
- What's the difference between a finding and a concern in subrecipient monitoring?
- "Concern" is typically an internal monitoring label, not a term defined by [2 CFR part 200](https://www.ecfr.gov/current/title-2/subtitle-A/chapter-II/part-200). Many pass-through entities use it for issues that need follow-up but aren't being treated as formal monitoring findings. "Audit finding" is a regulated term under [2 CFR § 200.516](https://www.ecfr.gov/current/title-2/section-200.516), and management decisions for relevant Subpart F audit findings are governed by [2 CFR § 200.521](https://www.ecfr.gov/current/title-2/section-200.521). For day-to-day monitoring, define in your written policy what counts as a concern, what counts as a formal monitoring finding, and what follow-up each requires.
- What risk factors does 2 CFR 200.332 say a pass-through entity may consider?
- Under [2 CFR § 200.332(b)](https://www.ecfr.gov/current/title-2/section-200.332), the risk evaluation may consider the subrecipient's prior experience with similar subawards, the results of previous audits, whether the subrecipient has new personnel or new or substantially changed systems, and the extent and results of Federal awarding agency monitoring. The regulation also allows other relevant factors; one example it gives is the extent to which the subaward requirements are similar to requirements already imposed on the pass-through entity. Whether to impose specific conditions is a response to the risk assessment, addressed separately in [2 CFR § 200.208](https://www.ecfr.gov/current/title-2/section-200.208).
About the author
Gary Kosman writes AmeriCorps Compliance Central, an independent publication about AmeriCorps grant compliance. He is CEO, America Learns. Reach him at gary@americalearns.net or 310-689-0542 x101.
Last reviewed August 5, 2026. Regulations change. Verify every citation against the current eCFR text and your own grant terms and conditions before you rely on it.