When someone says “HUD audit,” they could mean three very different things. Each one has a different scope, different triggers, and different stakes. Most audit and monitoring findings are not about fraud or bad intent. They are documentation and data failures – records that exist but can’t be produced, processes that happen but were never written down, data that is accurate but can’t be reconciled. That means audit readiness is an operational discipline you maintain year-round, not a scramble triggered by a letter.
This article breaks down what the Department of Housing and Urban Development actually reviews, where findings typically come from, and what you can do now to be ready.
This content is informational and does not constitute legal, audit, or accounting advice. Confirm requirements with your auditor, HUD field office, or CoC lead.
Three Different Things People Call a “HUD Audit”
The term “HUD audit” gets used loosely. In practice, it refers to three distinct review types, and knowing which one you are facing changes everything about how you prepare.
HUD monitoring visit. A programmatic and financial review conducted by a HUD CPD field office or a HUD contractor. It examines whether your operations, eligibility determinations, data, and financial management comply with program regulations and your NOFO. HUD audits verify compliance with federal laws and program regulations, and the primary goal is to ensure the efficient and legal use of federal funds. Public housing agencies must undergo HUD audits, and organizations receiving HUD funding are required to have audits as well. HUD audits evaluate public housing agencies’ management of federal housing programs across affordable housing and public housing contexts. Key purposes include accountability and compliance risk detection.
Single Audit of federal awards. An independent audit conducted under 2 CFR Part 200, Subpart F. This is not conducted by HUD. It is performed by certified public accountants or a non-federal auditing team, and the awarding agency or pass-through entity resolves findings. HUD audits include financial audits, compliance reviews, and single audits. Organizations spending $750,000 or more in federal awards need a Single Audit. The audit covers financial statements, the Schedule of Expenditures of Federal Awards, and major program compliance. Annual financial reports must follow generally accepted accounting principles for HUD audits.
HUD OIG audit or investigation. Conducted by the HUD Office of Inspector General, these are focused on high-risk situations, suspected fraud, waste, or abuse, or national initiative priorities. The scope is narrower but often deeper. Findings can include questioned costs and program violations.
What triggers each type
- Monitoring visits are triggered by HUD’s risk-based selection: prior findings, poor system performance, CoC or ESG renewal cycles, or complaints.
- Single audits are triggered automatically when entities spend federal awards totaling the threshold amount in a fiscal year.
- OIG reviews are triggered by referrals, credible allegations of misuse, or targeted government initiatives.
Comparison table
| Category | HUD Monitoring Visit | Single Audit | OIG Audit/Investigation |
|---|---|---|---|
| Who conducts it | HUD CPD field office or contractor | Independent external auditors | HUD Office of Inspector General |
| What triggers it | Risk assessment, renewal cycle, complaints, prior findings | Federal expenditure threshold crossed | Referrals, suspected fraud/waste/abuse, national priorities |
| Primary focus | Programmatic compliance, eligibility, HMIS, financial management, coordinated entry | Financial statements, SEFA, internal controls, major program compliance | Fraud risk, misuse of public funds, systemic issues |
| Key regulations/guidance | CPD Monitoring Handbook (6509.2) , CoC/ESG regulations, 2 CFR 200 | Uniform Guidance (2 CFR 200), OMB Compliance Supplement, Yellow Book | Inspector General Act, program-specific statutes |
| Typical timeline | Scheduled in advance; days to weeks on-site plus remote review | Fieldwork spans weeks; report due months after fiscal year end | Variable; can be intensive and unannounced |
A typical HUD audit takes three to six months to complete. Organizations must submit audits within 90 days of year-end, and audited financial statements must be submitted within 90 days as well.
The Single Audit threshold update
For entity fiscal years beginning on or after October 1, 2024, the Single Audit threshold under 2 CFR 200.501(a) is $1,000,000 in total federal expenditures. Single audits are required for organizations spending $750,000 or more under the prior threshold, and awards issued under the earlier Uniform Guidance may still follow the $750,000 threshold. The 2025 OMB Compliance Supplement splits Part 3 to address both guidance versions, so organizations must tag each award by which version of Uniform Guidance governs it.
Note: Verify these figures against the current Electronic Code of Federal Regulations (eCFR). OMB has pending proposed revisions to the Uniform Guidance, and thresholds may change.
Why it matters which review you are facing:
- The scope differs – monitoring focuses on eligibility, operations, and HMIS data; Single Audit focuses on financial statements, SEFA, and internal controls; OIG zeroes in on fraud and systemic failures.
- Documentation requests differ. You will need program files and client records for monitoring, financial records and cost allocation schedules for a Single Audit.
- The entities you engage differ: HUD field office for monitoring, your external auditors for Single Audit, OIG investigators for their reviews.
What HUD Monitoring Actually Reviews
This section covers HUD monitoring of homeless assistance programs – CoC, ESG, and related HUD funded programs – not property inspections or multi family housing operational audits.
HUD monitoring examines program design, day-to-day operations, financial oversight, and data in HMIS and APRs to test compliance with HUD regulations and NOFO requirements. Compliance reviews verify eligibility determinations and income certifications. HUD audits assess whether housing units meet federal quality standards, review financial practices and budgeting processes, and verify compliance with federal housing regulations. Audits help detect issues like weak controls and improper expenditures early, and HUD audits help prevent misuse of public funds.
Eligibility and enrollment documentation. Monitors examine client files for proof of homelessness under HUD’s definition, disability documentation where applicable, and income verification. Documentation requirements differ for CoC versus ESG, and across project types like PSH, RRH, TH, SSO, and coordinated entry. Internal controls should prevent errors and fraud in public housing agencies, and the same principle applies to non profit homeless assistance providers. The Public Housing Assessment System incorporates performance information from audits in the public housing context.
HMIS and data quality. HMIS is the system of record. Monitors check universal data elements for completeness and accuracy. APRs and system performance measures serve as starting points for monitoring questions. A GAO report found that in FY 2021 only about 20% of CoCs had fully usable LSA data; by FY 2022 that rose to 39%. Many CoCs still have unresolved data quality flags.
Coordinated entry compliance. Written CE policies must align with HUD’s CE Notice and local CoC standards. Monitors look for evidence that prioritization matches published standards and that CE referrals are documented in HMIS or comparable systems.
Financial management and match. Costs must be allowable under 2 CFR 200, with proper cost allocation plans in accordance with fund management guidelines. Drawdown patterns in LOCCS are scrutinized. Match documentation is a common source of findings – match must be properly valued, documented, and not double-counted. HUD audits review rent calculations where applicable to ensure compliance requirements are met.
Subrecipient and contractor oversight. Lead entities must maintain written subrecipient monitoring procedures and risk-based monitoring plans. Monitors request sample subrecipient files, monitoring reports, and evidence that corrective actions from past reviews have been completed.
Recordkeeping and retention. Financial and client records must be retained for required periods and must be retrievable. Many findings are about organization and accessibility – not whether the work happened, but whether you can prove it during a review. Building the operational foundation behind reliable reporting reduces this risk substantially.
Where the Findings Usually Come From
Most HUD monitoring findings are not about fraud. They stem from missing, inconsistent, or unretrievable documentation and data.
Turnover and unwritten processes. Staff who “knew how we do it” leave without written procedures. New hires inherit inconsistent management practices across projects and agencies. Over 21,000 multifamily properties submit audited financial statements to HUD annually, and the same documentation discipline applies to homeless assistance programs – organizations must submit audited financial statements within 90 days, and annual financial reports must be submitted to HUD within 90 days.
Workflow variation across providers. The same CoC standards get applied differently by each subrecipient – different intake packets, different HMIS habits, different CE practices. This leads to uneven compliance across tenant files and client records.
Unclear ownership. When no one is explicitly accountable for HUD compliance across finance, HMIS, and program teams, gaps appear. Each team assumes another is handling a requirement like SEFA reporting, grant drawdowns, or HMIS project setup. HUD audits assess financial strength and regulatory compliance of properties and programs; unclear ownership undermines both. Property owners and operators of housing programs face the same risk.
Reconstruction instead of retrieval. Staff rebuild files or backfill data right before a monitoring visit. Monitors can usually tell – timestamps cluster, forms are inconsistent, HMIS edits appear in bulk. Proper document organization enhances the efficiency of the HUD audit process and prevents this pattern.
Data-related patterns:
- APRs that do not reconcile to internal financial reports
- System performance measures that do not match local understanding of performance
- HMIS exports that contradict written policies and procedures
Cultural issues:
- Treating audits as one-time events instead of ongoing disciplines
- Fear of negative audit findings leading to under-reporting of issues internally rather than fixing them
The Documentation That Gets Requested Most
Entities must prepare financial records accurately for HUD audits. Key steps in HUD audit preparation include planning, documentation, and compliance verification. Below is a practical checklist of what monitors and auditors most commonly request.
Governance and policies:
- Current written policies and procedures for eligibility, housing placement, case management, HMIS, coordinated entry
- Board minutes approving major policy changes related to HUD programs
Client file documentation:
- Homeless and disability eligibility documents
- Signed releases of information and coordinated entry consent forms
- Essential documents include tenant eligibility records and bank statements
- Habitability and housing quality inspections where applicable
Financial and Single Audit documentation:
- General ledger detail for HUD-funded grants
- Cost allocation plans and supporting schedules
- SEFA with correct Assistance Listing numbers for each HUD program
- Invoices, timesheets, payroll allocations
- Annual financial reports following generally accepted accounting principles
HMIS and data documentation:
- HMIS governance charter and participation agreements
- Data quality plan and monitoring reports
- Evidence of periodic UDE completeness and accuracy checks – use the HMIS process checklist as a starting point
Coordinated entry and system-level documentation:
- CE policies, procedures, and prioritization standards
- Assessment tools and training materials
- System performance reports used by the CoC board or committees
Subrecipient monitoring documentation:
- Risk assessment tools and annual monitoring plans
- Completed monitoring reports and follow-up letters
- Corrective action plans and documentation of resolution
Corrective action and prior findings:
- Prior HUD monitoring letters and Single Audit reports
- Documented corrective action plans with timelines and responsible parties
- Evidence of completion: revised policies, training rosters, new reports
Exact requests vary by HUD field office and program. Confirm with your monitoring notice or coordinator.
How Your HMIS Data Becomes an Audit Issue
HMIS is not just a reporting tool. It is a primary source of evidence for compliance and performance during HUD monitoring, and it must support accurate financial reporting.
APRs start the conversation. APRs pull enrollment patterns, exits, destinations, and services from HMIS exports. Missing or inconsistent universal data elements create red flags that monitors follow up on. If your APR numbers do not reconcile with what your organization believes its performance is, expect questions.
System performance measures raise system-level flags. SPMs look across the CoC at metrics like returns to homelessness and length of stay. Outlier patterns – high returns, lengths of stay that do not match project design – trigger deeper review. Understanding common system performance reporting pitfalls helps you catch these before HUD does.
Project setup matters. Correct project type, funding source, and operating dates in HMIS must align with grant agreements. Misconfigured projects create discrepancies between reported numbers and actual expenditures, which looks like financial mismanagement even when it is a configuration error.
Common HMIS documentation weaknesses:
- Case notes and services recorded but not matching what is billed or budgeted
- CE referral pathways not traceable within HMIS
- Data corrections with no documented audit trail
Connect data quality to compliance. Routine data quality checks – UDE completeness, invalid values, cross-project consistency – function as preventive controls. Use data quality dashboards to support subrecipient monitoring and to ensure accuracy in internal reviews.
Year-round HMIS compliance routines:
- Quarterly APR test runs to catch issues early
- Regular reconciliation of HMIS enrollments with finance drawdowns and SEFA totals
- Internal process checks to verify that policies match actual screen-by-screen workflows
Organizations that have invested in this kind of routine have seen results. Read how one CoC approached restoring HUD compliance within one reporting cycle.
A Year-Round Readiness Approach
Real audit preparation is a steady operational rhythm, not an annual panic. Conducting a mock audit helps identify gaps and correct issues proactively. Conduct internal assessments months before scheduled HUD audits to avoid surprises.
Quarterly cadence:
- Q1 and Q3: internal file reviews and HMIS data spot checks for a sample of projects
- Q2 and Q4: finance-program-HMIS reconciliation meetings, SEFA draft updates, review of cost allocation
Cross-functional routines. Set up a standing meeting between finance, HMIS administrators, CoC leadership, and program managers. Share dashboards showing APR metrics, drawdowns, data quality indicators, and match status. Strong partnerships between these functions prevent findings.
Embed compliance in onboarding and supervision. Every new staff member should receive training on HUD requirements, local CoC policies, and HMIS workflows. Supervisors should review a sample of client files monthly. This is how you implement guidelines consistently and allocate resources to where they matter.
Subrecipient habits. Conduct annual risk assessments. Use standard audit checklists when visiting subrecipients or reviewing their HMIS and financial reports. Follow up on every finding.
Documentation upkeep. Review written policies and procedures annually. Apply version control and clear dating so monitors see a coherent history, not a patchwork of undated documents.
Tie readiness to strategy. Use APRs and system performance data in board discussions. Treat corrective action plans as improvement projects, not just compliance tasks.
Nutmeg helps CoCs and non profit organizations build sustainable HMIS and compliance practices that make this kind of readiness routine. Learn more about our HMIS support.
If You’ve Received a Monitoring Notice
You got the letter. Here is what to do.
First week:
- Read the notice carefully. List every requested document and focus area. Confirm dates and logistics with the HUD field office or lead agency.
- Identify an internal point person and assemble a small coordination team: finance, HMIS, program leads, and CoC lead if applicable.
Organize the response:
- Create a centralized folder structure – digital or physical – that mirrors the monitoring request sections.
- Assign document owners for each section. One person owns “financial management,” another owns “HMIS,” another owns “coordinated entry.”
Pre-visit self-review:
- Use the checklist above as an internal test. Conducting a mock audit helps identify gaps and correct issues proactively.
- Note and document any gaps you find before HUD does, along with immediate remediation steps.
During the visit:
- Designate who speaks to which topics. Finance lead handles SEFA and 2 CFR 200 questions. HMIS admin handles data, exports, and APRs. CE lead handles coordinated entry.
- Be transparent about issues. Focus on how you are addressing them. Monitors expect corrective actions, not perfection.
Handling findings:
- A good audit leads to corrective actions to prevent recurring problems. Significant audit findings may require corrective actions with specific timelines.
- Distinguish between findings, concerns, and suggestions. Build a realistic corrective action plan with deadlines and responsible parties. Document completion.
- Non-compliance can lead to funding suspension from HUD. Significant audit findings can lead to funding suspension. Repeated non-compliance can result in permanent ineligibility for HUD assistance. Failure to comply can also lead to financial penalties. Implementing corrective actions promptly protects your organization’s reputation and future federal funding.
- Align any Single Audit responses with HUD monitoring responses where topics overlap so there is one coherent story about corrective actions. Avoid penalties by coordinating across your auditing team.
Consult your own counsel, auditors, HUD field office, or CoC lead to confirm specific requirements and response strategies. If internal capacity is stretched, external audit services and support can help stabilize your data and documentation quickly.
FAQ About HUD Audits, Monitoring, and Single Audits
Q: Is a HUD monitoring visit the same as a Single Audit? No. A monitoring visit is conducted by HUD or its contractor and focuses on programmatic compliance – eligibility, HMIS, coordinated entry, financial management. A Single Audit is conducted by independent auditors under the Uniform Guidance and focuses on financial statements, SEFA, and major program compliance. Different rules, different scope, different process.
Q: When do we need a Single Audit for our HUD grants? When your organization expends $1,000,000 or more in total federal awards during your fiscal year (for fiscal years beginning on or after October 1, 2024). The prior threshold of $750,000 may still apply to awards governed by the earlier Uniform Guidance. Verify against current eCFR text and the latest OMB Compliance Supplement.
Q: What are the most common HUD monitoring findings for homeless programs? Missing or inconsistent eligibility documentation, HMIS data quality lapses (missing UDEs, invalid values), unwritten or outdated coordinated entry policies, weak subrecipient monitoring, and financial issues like unsupported match or cost allocation problems. These are documentation and process failures, not typically fraud.
Q: Can findings cost us our funding? Usually not immediately. Most findings lead to corrective actions and increased oversight. However, unresolved or repeated non-compliance, or fraud findings from OIG investigations, can lead to suspension, debarment, or termination of federal funding.
Q: How far back will HUD or our auditors look? That depends on program rules and record retention requirements. Financial records are typically reviewed for three years after the final expenditure report. Monitoring may cover the current and prior grant years. The monitoring notice will specify the period under review.
Q: Who should own HUD audit readiness in our organization? It should be cross-functional. The executive director or CEO sponsors it. The finance director owns financial compliance and the SEFA. The HMIS administrator owns data quality, project setup, and exports. The CoC or program lead owns eligibility, coordinated entry, and written standards. Assign clear roles and document them.
This FAQ is informational and does not replace advice from your certified public accountants, legal counsel, HUD field office, or CoC lead.
Nutmeg helps CoCs and nonprofits build the operational and data practices that make audit readiness routine – not a crisis. If you want help building HMIS and compliance practices that hold up under review, explore our HMIS support or reach out directly.