Subrecipient Monitoring Under 2 CFR 200.332

What a pass-through entity must do for every subrecipient it funds under 2 CFR 200.332: the 14 required subaward data elements, risk assessment, ongoing monitoring, and verifying the subrecipient's audit happened.

If your organization passes federal award money through to another organization — a subgrant, a subcontract under a grant, a pass-through to a partner agency — you're a pass-through entity, and 2 CFR 200.332 spells out exactly what you owe each subrecipient. This isn't optional paperwork — it's the obligation auditors test against every year, and it's where a large share of Single Audit findings originate.

1. The 14 required subaward data elements

Every subaward you issue must clearly identify itself as a subaward (not a vendor contract) and must include the following, per § 200.332(b)(1). Where information isn't available at the time of the subaward, provide the best information available and update it once it is:

  1. Subrecipient's name (must match the name associated with its unique entity identifier)
  2. Subrecipient's unique entity identifier (UEI)
  3. Federal Award Identification Number (FAIN)
  4. Federal award date
  5. Subaward period of performance start and end date
  6. Subaward budget period start and end date
  7. Amount of federal funds obligated in the subaward
  8. Total amount of federal funds obligated to the subrecipient, including the current obligation
  9. Total amount of the federal award committed to the subrecipient
  10. Federal award project description, as required by FFATA
  11. Name of the federal agency, pass-through entity, and awarding official contact information
  12. Assistance Listings title and number, with the dollar amount made available under each
  13. Identification of whether the federal award is for research and development
  14. Indirect cost rate for the federal award, including whether a de minimis rate is used

§ 200.332(b) has additional paragraphs beyond this list covering subaward terms and conditions, closeout requirements, and indirect cost rate negotiation — this list is specifically the "Federal award identification" elements under (b)(1). Paragraph lettering in Part 200 has shifted before and can shift again in future revisions even when the substance stays the same — the count and content here were checked against the current eCFR text as of this writing, but always confirm the letter/number against the live section rather than this page if you're citing it somewhere that matters.

2. Risk assessment

Before and during the subaward, you must evaluate each subrecipient's risk of noncompliance — including fraud risk — to decide how closely to monitor it. Factors typically considered include the subrecipient's prior experience with federal awards, results of previous audits, whether it has new staff or a new system, and the size and complexity of the award. A subrecipient with a clean audit history and experienced staff warrants lighter monitoring than one that's new, has had findings before, or is managing an unusually large award relative to its size.

3. Ongoing monitoring

Monitoring isn't a one-time check at award setup. § 200.332(e) requires you to monitor the subrecipient's activities throughout the award period, which includes:

  • Reviewing financial and performance reports the subrecipient submits
  • Following up when a report reveals significant problems, and ensuring the subrecipient takes appropriate corrective action
  • Issuing a management decision for audit findings that pertain to the subaward you issued
  • Following up to ensure the subrecipient actually resolves audit findings

4. Verify the subrecipient was actually audited

§ 200.332(g) requires you to verify that a subrecipient meeting the Single Audit threshold ($1,000,000 in federal expenditures in a fiscal year) actually got audited as required under Subpart F, and to follow up when it didn't. This is one of the easier checks to automate: the subrecipient's audit history is public in the Federal Audit Clearinghouse under its EIN.

The threshold just moved — fewer subrecipients will show up in the FAC

For fiscal years beginning on or after October 1, 2024, the Single Audit expenditure threshold rose from $750,000 to $1,000,000 (2 CFR 200.501, revised April 2024). A subrecipient whose federal expenditures fall between those two figures no longer triggers a Single Audit at all.

That has a direct consequence for the monitoring obligation above: fewer subrecipients will have a Single Audit for you to verify in the first place. The free, independent assurance a Single Audit used to provide disappears for everyone now under the higher threshold — meaning your own direct monitoring under § 200.332(d)–(e) is doing more of the work it used to share with an auditor.

See it in a real finding

Moraine Valley Community College District Number 524 has an audit finding tagged against this exact requirement. Reading the actual condition and corrective action plan alongside the regulation is often clearer than the regulation alone.

Monitoring more than one subrecipient? The portfolio view shows findings, repeat-finding counts, and management-decision deadlines across a list of EINs at once — paste your subrecipients' EINs to see them all in one table.

Not legal advice. This page explains the regulation in plain language but isn't a substitute for reading the current text of 2 CFR 200.332 at eCFR.gov or consulting your cognizant or oversight agency. Regulatory text changes; always verify against the current version before relying on it.

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.