Free checklist · Pass-through entities

What a 2 CFR 200.332 monitoring file must contain

Subrecipient monitoring produces findings year after year, and almost never because money went missing. It is because the file cannot show that a risk assessment happened, that monitoring matched the risk, or that findings were followed up. This is what belongs in the file.

Before the checklist: the determination that comes first

Under 2 CFR 200.331 you must first decide whether the organization receiving your money is a subrecipient or a contractor. It matters because monitoring obligations attach to subrecipients and not to contractors. A subrecipient carries out part of your programme and is measured against its objectives; a contractor supplies goods or services in a competitive market. Write down which one you decided and why — that determination is itself a document auditors ask for, and it is frequently missing.

The checklist

Nine items, and the evidence that satisfies each

Subrecipient monitoring file — contents and acceptable evidence
Item Why it is tested Evidence that satisfies it
1. Subrecipient vs. contractor determination Establishes that monitoring obligations apply at all (200.331). A dated written determination naming the decider and the reasoning.
2. Executed subaward agreement Must carry the required data elements and all applicable terms (200.332(a)). Signed agreement including the federal award identification, Assistance Listing number, period, amount, indirect rate and closeout terms.
3. Written risk assessment Monitoring must be proportionate to assessed risk — with no assessment there is no defensible basis (200.332(b)). A dated assessment naming the assessor, stating the risk level and the specific reasoning behind it.
4. Monitoring plan that follows from the risk A high-risk subrecipient monitored like a low-risk one is a finding on its own. A written plan stating what monitoring will occur, how often, and by whom.
5. Evidence monitoring actually happened The most common failure: a plan exists, execution cannot be shown. Dated records of desk reviews, site visits, invoice reviews and technical assistance, each naming who performed it.
6. Financial report and invoice review Demonstrates costs were reviewed for allowability before payment. Reviewed invoices with reviewer, date and disposition — approved, queried, partially paid.
7. Single Audit report review, where applicable If the subrecipient expends above the Single Audit threshold, you must review their report and act on findings (200.332(f)). Evidence you obtained the report, reviewed it, and issued a management decision on findings within the required period.
8. Findings, management decisions and corrective action Issuing a finding without documented follow-up is treated as no follow-up. Each finding with a written management decision, corrective action required, and dated verification that it was completed.
9. Closeout record Final reports, final invoice and release of remaining obligations. Dated closeout documentation and confirmation that final reports were received and accepted.

The three failures that produce most findings

The risk assessment exists only in someone's head. A programme officer genuinely assessed the risk and genuinely monitored accordingly — but nothing was written down, so nothing is testable. The fix costs ten minutes per subrecipient and is almost always deferred.

Monitoring happened but left no dated trace. Calls were held, invoices were queried, problems were solved. None of it was recorded with a date and a name, so at audit it did not happen.

Findings were raised and quietly resolved. The problem was fixed, everyone moved on, and there is no management decision or verification of corrective action in the file. Auditors treat the loop as open.

All three share a cause: the record was expected to be assembled later, from memory and email. It never survives that.

This material is provided for general information and is not legal, accounting or audit advice. Requirements vary by awarding agency, programme and award terms. Confirm your obligations with your awarding agency and your auditor.

Keep this file as you go, not in audit week

Kharazm gives each subrecipient a written risk basis, a monitoring plan and a dated log — and generates the file as a printable pack.