A data table behind a shield tick, branching to a pass and a fail marker.

What are the audit procedures for nonprofit organizations?

An auditor plans by assessing risk, tests the controls it intends to rely on, then tests balances and transactions. In a single audit it also tests compliance for each major federal program and the internal control over that compliance, planning the testing to support a low assessed level of control risk (2 CFR 200.514).

Last verified: 2026-09-20 · Every figure links its source.

What are the audit procedures for nonprofit organizations?

  1. Risk assessment. Understand the organization, its funding and its controls; identify where the statements could be materially wrong.
  2. Control testing. Walk through and test the controls the auditor plans to rely on — cash receipts, payroll, purchasing, grant billing.
  3. Substantive testing. Confirm cash, investments and receivables with third parties; sample expenses and payroll; test revenue recognition and donor restrictions; check cut-off around year end.
  4. Compliance testing (single audit only). For each major program, test the compliance requirements that could have a direct and material effect, following the Compliance Supplement.
  5. Follow-up on prior findings, whether or not the program is major this year.
  6. Reporting. Opinions, the schedule of findings and questioned costs, and the data collection form.

Source: 2 CFR 200.514 · 2 CFR 200.515 · OMB Compliance Supplement · Last verified: 2026-09-20

How is materiality determined in a nonprofit audit?

Materiality is the auditor's judgment about how large a misstatement would have to be before it would change a reader's decision, and it drives sample sizes. In a single audit there is a second layer: materiality is applied separately to each major program, not to the organization as a whole (2 CFR 200.514(d)), which is why a small program can produce a finding while the financial statements receive an unmodified opinion.

Source: 2 CFR 200.514 · GAO Government Auditing Standards · Last verified: 2026-09-20

What does the auditor test in a single audit?

The auditor determines whether the organization complied with the federal statutes, regulations and award terms that may have a direct and material effect on each major program. The Compliance Supplement sets out the requirement types and suggested procedures, and part 3 of the Supplement is where the requirement types are described (Compliance Supplement part 3).

Requirement types an auditor may test
AreaTypical question the test answers
Activities allowed or unallowedWas the money spent on what the program permits?
Allowable costs and cost principlesAre the costs allowable, allocable and reasonable?
Cash managementWas cash drawn only as needed?
EligibilityWere the people or entities served eligible?
Equipment and real property managementAre federally funded assets tracked and used for the program?
Matching, level of effort, earmarkingWas the required match actually provided?
Period of performanceWere costs incurred inside the award period?
Procurement, suspension and debarmentWere purchases competed and vendors checked?
Program incomeWas income earned from the program handled correctly?
ReportingDo the federal reports agree with the books?
Subrecipient monitoringWere subrecipients identified and monitored (2 CFR 200.332)?
Special tests and provisionsProgram-specific rules named in the Supplement

Source: 2 CFR 200.514 · Compliance Supplement, part 3 (compliance requirements) · 2 CFR 200.332 · Last verified: 2026-09-20

How do audit findings arise?

A finding is reported when the auditor identifies a significant deficiency or material weakness in internal control over a major program, material noncompliance, known or likely questioned costs above $25,000 for a major program, known questioned costs above $25,000 for a non-major program, a compliance opinion that is other than unmodified, known or likely fraud, or a prior-year finding whose reported status is materially misrepresented (2 CFR 200.516(a)).

For scale: of 22,398 nonprofit single audits for audit year 2024, 3,631 (16.2%) reported at least one finding, 2,088 (9.3%) reported a material weakness and 3,027 (13.5%) reported a significant deficiency (Federal Audit Clearinghouse, data as of 2026-09-20).

Source: 2 CFR 200.516 · Federal Audit Clearinghouse · Last verified: 2026-09-20

Questions and answers

What does the auditor test in a single audit?

Compliance with the federal requirements that could have a direct and material effect on each major program, and the internal control over that compliance, using the Compliance Supplement as the guide.

Why did we get a finding when the financial statements were clean?

Because materiality in a single audit is applied program by program. A control failure inside one major program can be a finding even when the organization's statements are fairly presented.

Want the finding rates for your state? See the statistics pages.

This is public-record information, not accounting or legal advice.