Why One Certification at the Start Is Not “Ongoing” Monitoring
Every July, a pass-through entity collects a subrecipient certification packet – signed forms asserting that policies are in place, financial controls exist, and the organization understands its compliance requirements. The packet goes into a folder. Nobody opens it again until an auditor asks about subrecipient monitoring eighteen months later.
That packet satisfies part of the pre-award requirements under 2 CFR 200.332. It does not satisfy the ongoing monitoring obligation. The regulation expects documented oversight throughout the period of performance: before, during, and after the subaward. A signed certification in July tells an auditor nothing about what happened between August and June.
Here is the argument this article makes: most organizations are doing enough monitoring in practice and documenting it poorly. You are probably reviewing invoices, taking calls with subrecipient staff, checking data quality, and following up on problems. But only the documentation shows up in an audit. Effective subrecipient monitoring requires active oversight frameworks, and subrecipient monitoring must be risk-based and documented. If it is not written down with a date, it did not happen – at least not for purposes of the people reviewing your files. Pass-through entities are legally responsible for ensuring subrecipients use funds properly, and proving that responsibility was met is the harder half of the job.
This article is written from Nutmeg Consulting’s perspective, based on our work with nonprofits, Continuums of Care, and human services agencies in Connecticut and along the East Coast.
What 2 CFR 200.332 Actually Requires (In Three Phases)
2 CFR 200.332, “Requirements for pass-through entities,” sits in Subpart D, “Subrecipient Monitoring and Management.” It has nine subsections. Rather than listing them a through i, it helps to group them into three phases.
Before the subaward. Verify that the subrecipient is not excluded or disqualified via SAM.gov. Ensure the subaward instrument clearly identifies federal award identification details – the federal award identification number, the assistance listings title, the subaward budget period start and end dates, the federal funds obligated, and a federal award project description. Include the indirect cost rate, the name of the awarding official, the subrecipient’s unique entity identifier, and all applicable compliance requirements. Subrecipients must be notified of compliance obligations in writing. Then conduct a documented risk assessment under 200.332(c). Monitoring plans should incorporate measurable objectives and reporting schedules within agreements so expectations are clear from the outset.
During the period of performance. Apply specific conditions where the risk assessment warrants them. Monitor subrecipient monitoring activities by reviewing financial and performance reports from subrecipients, ensuring corrective action on findings, and issuing a management decision on audit findings – pass-through entities must issue management decisions on audit findings within six months. Choose monitoring tools proportionate to the subrecipient’s risk rather than running every entity through the same process.
After the period. Verify that any required single audit under 2 CFR 200.501 has been completed. Subrecipients expending over $1,000,000 in federal awards must undergo a single audit, using the threshold for fiscal years beginning on or after October 1, 2024. Single audit requirements must be reviewed for compliance and deficiencies. Consider whether audit findings require adjustments to your own records. Consider enforcement actions under 2 CFR 200.339 only when noncompliance persists.
These are not suggestions. Each phase is a requirement. What varies is the intensity, and that intensity flows from the risk assessment.
Risk Assessment Is the Step That Sets Everything Else
Under 2 CFR 200.332(c), the risk assessment is not a formality. It is the foundation that justifies your monitoring intensity, your monitoring tools, and your frequency. Pass-through entities must evaluate subrecipient compliance risk before the subaward is made and revisit it when circumstances change.
The regulation names the specific factors to evaluate:
- The subrecipient’s prior experience with the same or similar subawards
- Results of previous audits, including whether the subrecipient had a single audit and whether similar awards were audited as a major program
- Whether the subrecipient has new personnel or substantially changed systems
- The extent of federal agency monitoring already in place
Risk assessments consider prior experience and audit results. A formal risk assessment should document the financial stability of each subrecipient. Risk assessments categorize subrecipients as low, medium, or high risk, and subrecipients must be monitored based on their risk assessment results. Establishing the right monitoring approach should depend on the subrecipient’s assessed risk level.
The practical point is this: a pass-through entity that cannot show when and how it assigned a risk level – for example, “Moderate risk, assessed January 2025: new to CoC funding, no recent single audit report, finance director replaced in September” – will struggle to explain why it chose the monitoring level it did. That is an unsupported decision, not a paperwork gap.
Turn these factors into a simple, repeatable scoring tool that fits on one page. Rate each factor on a 1-to-3 scale, total the scores, and assign a tier. Add a short narrative justification and a date. Store completed assessments in a single location – a shared drive, a grant management system, or a consistent folder structure. If your data management setup does not make this easy, that is worth fixing before the next award cycle.
“Monitoring” Is a Verb, and It Has Evidence Attached
Sections 200.332(e) and (f) describe concrete actions, not aspirations. The monitoring process includes reviewing financial and performance reports, confirming that subrecipients take timely corrective action on findings, and issuing management decisions on audit findings when required. Regular reviews of financial and programmatic performance are essential to verify compliance.
Evidence for each action looks like this:
- A dated note on an invoice or report showing what was reviewed and by whom
- A summary email from a monitoring call with date, attendees, and issues discussed
- A formal letter requiring corrective action, with a deadline
- A follow-up document or email confirming the corrective action was completed
The distinction that matters for audits: a corrective action plan stating “we will revise our travel policy by June 30” is not the same artifact as proof that the travel policy was actually revised by June 30. The regulation asks for the second. Most files contain only the first. Corrective action plans should be implemented when performance issues arise, and the implementation must be confirmed in writing.
Under 200.332(f), the following monitoring tools can be scaled to risk: targeted training and technical assistance, on-site visits, and agreed-upon procedures engagements. Training and technical assistance can enhance subrecipient compliance capabilities, especially for newer subrecipients handling federal funds for the first time. Policies for monitoring should ensure clear communication of compliance expectations to subrecipients throughout the award. It is crucial to maintain documentation of all monitoring activities and corrective actions taken.
When we provide nonprofit IT support, compliance-related training sessions and remote reviews are logged as part of the service record. Your organization should treat similar technical assistance activities the same way – as monitoring evidence worth preserving.
The Part Nobody Budgets For: Capturing Evidence While You Work
Most real monitoring happens informally. A quick call to clarify a confusing subrecipient invoice. A Teams message about a late performance report. An impromptu screen share to check data quality in an HMIS instance. None of these produces a neat PDF for the file by default.
Evidence hides in predictable places:
- Notes locked in one staff member’s personal notebook
- Calendar events with no attached minutes
- Email threads where the confirmation of a corrective action sits three replies deep
- Screenshots of a data fix saved to a desktop that nobody else can access
Without light but deliberate documentation habits, year-end and audit preparation become reconstruction projects. Staff search inboxes, recreate decisions from memory, and piece together timelines under pressure. The monitoring efforts were real. The evidence is not.
The fix is low-friction. After a monitoring call, save a one-paragraph summary into the subrecipient’s folder. After an HMIS data correction, capture a screenshot of the before and after. Forward key decisions to a shared mailbox designated for monitoring purposes. None of these steps takes long individually. Across a portfolio of awards, they add up to an audit file that already exists when the auditor arrives.
Our experience implementing HMIS systems for CoC programs confirms this pattern: the data work gets done, but evidence of the oversight often lives nowhere findable. Simple workflow tweaks and shared repositories change that.
What an Auditor Actually Asks For (Four Questions)
Auditors typically select a subrecipient, pick a fiscal year, and ask four questions. Each can be answered in a sentence if the records exist. Each may take days to reconstruct if they do not.
“What was your risk assessment for this subrecipient, and when did you complete it?” A dated risk assessment document with a risk tier and narrative immediately answers this. Without one, you are explaining from memory why you monitored the way you did.
“What did you review, and when?” This is where dated artifacts matter. Invoices reviewed in March. A quarterly performance report reviewed in April. An HMIS data extract pulled and checked in June. The item and the date together form the evidence. Performance measured against program objectives should be visible in these records.
“What did you find, and what did you require?” Auditors look for documented findings – unsupported travel costs, missing participant documentation, late reporting – and the specific corrective actions you required. A general note that “things looked fine” is weaker than a brief written summary identifying no material issues on a given date.
“How did you confirm it was implemented?” Walk the auditor through the sequence: finding identified, corrective action required by a deadline, and a later email, revised policy, or checklist entry confirming the change occurred. The audit report should reflect that the loop was closed.
Designing a Quarterly Subrecipient Monitoring Checklist
A one-screen checklist, updated quarterly and stored consistently for each fiscal year, can serve as both your monitoring plan and your evidence map.
Columns worth including:
| Column | Purpose |
|---|---|
| Subrecipient name | Identifies the entity |
| Risk tier | Current rating from the most recent risk assessment |
| Last review date | When you last performed a documented review |
| Type of review | Invoice sample, program report, onsite visit, HMIS data extract |
| Open findings | Issues identified but not yet resolved |
| Corrective action confirmed | Date and method of confirmation |
| Next planned review date | Keeps the schedule visible |
| Single audit required? | Whether expenditures exceed the $1,000,000 threshold |
Finance and program staff can review this checklist during standing quarterly meetings. It gives everyone a shared view of the subrecipient’s program operations, open items, and upcoming obligations. When an auditor asks for your monitoring plan, you hand them this.
Subrecipient Monitoring, Cybersecurity, and Data Systems
Under 2 CFR 200.303(e), recipients must take reasonable measures to safeguard information, including protected PII. This is a continuous obligation – not something that begins on the day of an audit.
For CoC and human services programs using HMIS and case management systems, pass-through entities often rely on subrecipients to protect client data and maintain system access controls. Part of subrecipient monitoring can include verifying that cybersecurity basics are in place:
- User access reviews conducted periodically
- Multi-factor authentication enabled where feasible
- Documented incident response procedures for systems that handle federal program data
- Data backups and retention consistent with federal requirements
These checks do not require a full cybersecurity audit. Finance and program leads can ask a few targeted questions about who has access, how access is removed when staff leave, and what happens if a breach occurs. Documenting the answers strengthens your monitoring file.
Our IT compliance and funding risk advisory work frequently surfaces gaps at this intersection of technology, monitoring, and grant compliance. When systems break or are misconfigured, federal funding accountability and data integrity both suffer.
Subrecipient vs Contractor: Getting the Line Right Before You Monitor
Subrecipient determination and contractor determinations under 2 CFR 200.331 matter because the subrecipient monitoring requirements of 2 CFR 200.332 apply only to subrecipients, not to contractors. Pass-through entities must determine if an entity is a subrecipient or contractor before deciding what oversight is appropriate.
The distinction:
- Subrecipients carry out a portion of a federal award. They are responsible for programmatic decision-making, subject to applicable federal program requirements, and accountable under the authorizing statute, federal statutes, and cost principles of the uniform guidance.
- Contractors provide goods and services for the recipient’s use. They operate in a competitive environment for services, perform work within their normal business operations, and are not subject to the same compliance requirements that flow from sponsored programs and federal assistance.
Grey areas exist. A data hosting vendor for an HMIS platform, for instance, may look like a contractor in most respects – providing technology services rather than making programmatic decisions. But if the vendor is making decisions about how data is collected, reported to HUD, or used for performance measured against program goals, the relationship may lean toward a subaward. A clear, dated determination memo – even a single page – is often the only thing an auditor will ask to see.
Misclassifying a contractor as a subrecipient creates unnecessary monitoring work. Misclassifying a subrecipient as a contractor leaves a gap where oversight should exist. Neither is a good outcome.
Building a Subrecipient Monitoring Policy That Holds Up in 2026 and Beyond
A durable subrecipient monitoring policy includes a few core elements: clear roles for finance, program, and compliance staff; a defined risk assessment method; standard monitoring tools by risk tier; and expectations for documentation and retention. The policy should describe who reviews what, how often, and where evidence is stored. It should also address how the organization handles entities that concurrently receive federal awards from multiple sources and how the current financial obligation for each subaward is tracked.
OMB proposed a significant Uniform Guidance overhaul on May 29, 2026, with a comment period that closed July 13, 2026. As of this writing, the proposed rule – which includes eliminating fixed-amount subawards, strengthening SAM.gov reporting, and expanding pass-through entity obligations – has not been finalized. The direction of travel, however, points toward more transparency, more documentation, and tighter risk-based oversight. The final updated policy guidance, when it comes, will likely reinforce what diligent organizations already do.
Keep your policy high-level and durable. Attach procedures and templates – risk assessment forms, checklists, sample corrective action letters – as appendices that can be updated more frequently. Review the policy every two to three years, document the review date, and note any changes. This review itself becomes evidence of institutional commitment.
If internal capacity is thin, outside support can help. We often work with agencies to align their grant monitoring, HMIS workflows, and data management practices into a coherent system.
From “We Did It” to “We Can Prove It”: Closing the Documentation Gap
For most finance and CoC teams, the operational risk is not that monitoring is absent. It is that there is no clean record of what was done, when, and with what result.
The practical fixes are not complicated: a documented risk assessment tied to each subrecipient, a simple quarterly checklist, specific evidence of monitoring actions saved to a shared location, and enough discipline to close the loop on corrective actions in writing. A non-federal entity receiving federal funds and passing them through does not need a perfect system. It needs a consistent one.
The organizations that handle subrecipient monitoring well are not the ones monitoring hardest. They are the ones who can produce the evidence on request.
If you want a second set of eyes on your subrecipient monitoring policy, risk assessment tool, or HMIS-related oversight practices, reach out through our IT compliance page or review the HMIS compliance case study for a practical example of what this looks like in operation. Small, consistent documentation habits now are far easier than reconstructing the story of your monitoring during a future audit.
FAQ
What is subrecipient monitoring?
Subrecipient monitoring is the set of risk-based activities a pass-through entity performs during the life of a subaward to oversee financial performance and programmatic compliance, ensure that federal regulations and applicable federal program requirements are met, and document that oversight in a way that can be produced during audits. It includes reviewing reports, conducting site visits, requiring corrective actions, and verifying their implementation.
What does 2 CFR 200.332 require?
2 CFR 200.332 requires pass-through entities to verify subrecipient eligibility, communicate all federal award terms, assess the subrecipient’s risk of noncompliance, monitor activities using tools proportionate to that risk, review financial and performance reports, verify required audits, issue management decisions on findings, and document each step. It applies to all requirements for federal awards passed through to subrecipients.
How often does subrecipient monitoring need to happen?
The regulation does not prescribe a fixed schedule. Most organizations use at least quarterly reviews for higher-risk subrecipients, with lighter-touch oversight for low-risk ones. The chosen frequency must be justified by the documented risk assessment. Monitoring should happen in a timely manner throughout the period of performance, not just at the beginning or end.
What is the difference between a subrecipient and a contractor?
A subrecipient carries out part of a federal program and is subject to programmatic compliance requirements, uniform administrative requirements cost principles, and audit requirements for federal awards. A contractor sells goods or services in its normal business operations within a competitive environment and is not subject to the same oversight. Only subrecipients trigger the monitoring obligations of 2 CFR 200.332.
What do auditors look for in subrecipient monitoring?
Auditors typically seek evidence of four things: a documented risk assessment with a date and risk tier, specific monitoring activities tied to that assessed risk, identified findings along with the corrective actions required, and proof that those corrective actions were actually implemented. They also verify that required single audit reports were obtained and that any relevant findings were reflected in the pass-through entity’s own records. Provide technical assistance and document it as well – auditors view it as evidence of oversight.