Almost nobody gets a federal grant audit finding for stealing money.
That’s the first thing worth understanding about the single audit process. The overwhelming majority of findings issued to nonprofit organizations are not fraud. They’re documentation gaps, allocation methods nobody wrote down, missing signatures, subrecipients who were never monitored, and expenses that were perfectly legitimate but impossible to prove after the fact.
Which is, in a way, worse news. Fraud is rare and preventable through hiring and separation of duties. The real triggers are ordinary operational habits — the kind that feel efficient right up until an auditor asks you to reconstruct a decision made fourteen months ago.
Here’s what actually causes findings, why each one happens, and what has to be true in your systems to prevent it.
First: What Counts as a “Finding”
Under Uniform Guidance (2 CFR Part 200), organizations expending $1 million or more in federal awards during a fiscal year must undergo a single audit. Auditors test both financial statements and compliance with federal requirements across a defined set of compliance areas — allowable costs, cash management, eligibility, reporting, subrecipient monitoring, procurement, and others.
A finding is issued when the auditor identifies noncompliance, a deficiency in internal control, or a questioned cost above the reporting threshold. Findings become part of the public record in the Federal Audit Clearinghouse, feed into your risk profile for future awards, and require a written corrective action plan.
Not all findings are equal. A single missing timesheet is different from a systemic control deficiency. But auditors are trained to look for the pattern behind the exception — one error is an error, three errors is a control failure.
The Nine Most Common Triggers
1. Inadequate time and effort documentation
This is the most frequently cited issue in nonprofit single audits, and it’s rarely close.
Federal rules require that charges for salaries and wages be supported by records that accurately reflect the work performed. If an employee splits time across three grants, budgeted percentages are not sufficient — you need records reflecting actual effort, reviewed by someone in a position to know it’s accurate.
The failure mode is almost always the same: someone sets allocations at the start of the year based on the budget, nothing ever revisits them, and the program reality drifts. When the auditor samples a payroll period and asks for support, what exists is a spreadsheet of intentions rather than a record of activity.
Systems that capture effort at the source — with a documented time and expense trail tied to the user who entered it — turn this from an annual reconstruction project into a routine record.
2. Cost allocation without a documented methodology
Shared costs — rent, utilities, a program director, a shared vehicle — have to be distributed across funding sources on a reasonable, consistently applied basis. Auditors don’t generally object to a particular method. They object to a method nobody can explain.
The trigger is usually this exchange: “How did you arrive at 32% to this award?” followed by silence, or by an answer that differs from what the finance director said the day before.
Prevention requires two things: a written allocation policy, and a system that applies it the same way every period. Systems with rules-based allocation in the general ledger — distributing balances by predefined percentages or statistical bases — produce a consistent, reproducible trail. Manual journal entries reconstructed each month do not.
3. Commingled funds and weak fund separation
Federal awards carry restrictions. If your accounting system treats a grant as a label attached to transactions rather than a fund with its own balances, you eventually cannot answer the basic question: how much of this award remains, and was any of it used for something else?
This surfaces during testing when the auditor tries to trace an expense to a specific award and finds it sitting in a general operating account with a memo field. True fund accounting — where funds have real balances and cash isn’t commingled — makes this a non-question rather than a scramble.
4. Unallowable costs charged to the award
Uniform Guidance defines categories of unallowable costs: lobbying, fundraising, entertainment, certain alcohol and travel expenses, bad debt, and others. These get charged to federal awards constantly, usually without any intent to do anything improper.
The typical path: a staff dinner at a program-related conference is coded to the grant because the conference was grant-funded. Nobody stops to separate the entertainment portion. Multiply by a year of transactions and the auditor has a sample.
Prevention is mostly a matter of coding discipline at entry — but it also depends on whether your system can flag or block a charge against a grant at the point of entry, rather than surfacing it in a report six weeks later.
5. Budget overruns and unapproved deviations
Many federal awards limit how much you can shift between budget categories without prior approval, and cap total spending by line item. Exceeding those limits without written funder approval is a straightforward finding, and often produces questioned costs.
This is one of the most preventable triggers, and one of the most common — because in most organizations, the person spending the money and the person tracking the budget are different people looking at different documents at different times.
Real-time budget management that validates against available funds during data entry catches this before the money leaves. Reporting after the fact only tells you how large the problem already is. Tracking committed-but-unspent obligations through encumbrance accounting closes the remaining gap — a purchase order isn’t an expense yet, but it isn’t available money either.
6. Failure to monitor subrecipients
If you pass federal funds through to another organization, you inherit responsibility for monitoring them. That means risk assessment, clear subaward agreements identifying the funding source and requirements, ongoing monitoring, and follow-up on their audit findings.
Pass-through entities routinely treat subrecipients like vendors — issue the funds, receive the reports, file them. Auditors treat that gap seriously because the federal government’s exposure runs through you.
Organizations managing both incoming and outgoing awards need grant management functionality that handles grantee and grantor roles in one system, rather than tracking subawards in a parallel spreadsheet nobody updates.
7. Procurement noncompliance
Uniform Guidance sets procurement standards — competition requirements above certain thresholds, documented selection rationale, conflict-of-interest policies, and verification that vendors aren’t suspended or debarred.
The classic finding: a sole-source purchase above the micro-purchase threshold with no documentation of why competition wasn’t feasible. Not improper on its face — just unproven.
8. Late or inaccurate reporting
Financial and performance reports have due dates. Missing them, or submitting figures that don’t tie to your general ledger, generates findings independent of whether the underlying spending was proper.
The reconciliation problem is the sneaky one. Reports get assembled in spreadsheets, adjusted for readability, submitted — and then the ledger changes. When the auditor compares the submitted report to the accounting records and finds a variance nobody can explain, that’s a finding about the reliability of your reporting process, not just one number.
9. Missing or unreliable audit trails
Underneath everything above sits a single question: can you prove what happened?
Auditors test whether records can be altered without a trace, whether the person who entered a transaction is identifiable, whether supporting documentation is attached and retrievable, and whether corrections were made through documented adjusting entries rather than quiet edits.
A system where transactions can be deleted, or where the modification history is unavailable, is a control deficiency on its own terms. An enhanced audit trail that captures user IDs, timestamps, prior values, and attached documentation converts most audit requests from an investigation into a lookup.
The Pattern Underneath
Read those nine again and a theme emerges: almost none of them are about whether you spent money appropriately. They’re about whether you can demonstrate it.
That distinction matters when deciding where to invest. Hiring a compliance officer helps. Writing better policies helps. But if the underlying system can’t enforce a budget at entry, can’t apply an allocation rule consistently, and can’t tell you who changed a transaction last March, you’re asking people to compensate manually for something the system should handle structurally — and manual compensation degrades under pressure, which is exactly when auditors are looking.
The organizations that come through single audits cleanly usually aren’t the ones with the most compliance staff. They’re the ones where the compliance evidence is a byproduct of doing the work, not a separate project undertaken once a year.
If your current setup requires reconstructing the record rather than retrieving it, see how NonProfit+ handles federal grant compliance — and bring the finding you’re most worried about repeating.