2 CFR 200 Subpart F — Single Audit preparation

Your Single Audit is coming. Be ready in 30 minutes.

Enter the award, list your subrecipients, link the evidence where it already lives, and generate one printable audit pack. A flat fee, one setup call, and no platform to adopt.

$199 flat, one audit One 20-minute setup call No subscription required

Why this exists

Reconstructing the monitoring file the week before the audit is expensive and risky

You know the pattern. The auditor's request list arrives. Somebody starts a spreadsheet. Somebody else searches two years of email for the subaward agreement and the risk assessment that may or may not have been written down. A program manager who left in March is the only person who knew why the scope changed.

The cost is not only the week of staff time, though that is real. It is that reconstruction produces exactly the artifact an auditor is trained to distrust: a monitoring file assembled after the fact, with no dates, no named reviewer, and no way to show what was known when. Findings in this area are almost never about the money. They are about the absence of a contemporaneous record.

Single Audit in a Box will not invent documentation you never created. What it does is assemble what exists into the shape an auditor asks for, and show you precisely what is missing while there are still weeks to do something about it.

Typical request list

What you will be asked to produce

  • Subaward agreements and the risk assessment for each subrecipient
  • Evidence that monitoring appropriate to that risk actually happened
  • Findings issued, and the corrective action taken on each
  • Performance and financial reports as filed, with their dates
  • Decisions that changed scope, budget or schedule, and who made them
  • Evidence that access to the record was controlled

Each line becomes a section of the generated audit pack.

Four steps

From a scattered folder to a printable audit pack

There is no implementation project and nothing to configure. The whole setup is one call and about half an hour of typing.

  1. Enter the award

    Funder, award number, Assistance Listing (CFDA) number and period of performance — all of it copied from your Notice of Award. Mark whether you passed any of it through to subrecipients, which determines whether the monitoring sections apply to you.

  2. Add your subrecipients

    Legal name, UEI, subaward amount and dates. Then the part auditors actually test: the risk level you assigned, the written basis for that determination, and the monitoring plan that followed from it. If a risk basis is blank, the pack will say so rather than quietly omitting it.

  3. Link the evidence

    Paste links to documents where they already live — your shared drive, your accounting system, your grants portal. Kharazm records the title, the location, who added it and when. It never asks you to upload a second copy of your files, and never becomes a place your documents can be lost.

  4. Generate the audit pack

    One printable PDF plus a CSV: award summary, subrecipient monitoring log, evidence index, decision record with written resolutions, report register showing what was filed and when, and the audit-log extract showing who did what in the workspace. Hand it over, or work through the gaps it exposes first.

Narrow by design

What is in it, and what is deliberately left out

This product does one job. Everything that would slow down a team in acute time pressure has been removed rather than hidden behind a setting.

Single Audit in a Box — scope
Included Excluded
Award record — funder, award number, Assistance Listing, period Ongoing task and project management
Subrecipient monitoring file, assembled from your inputs General program management
Evidence links — URLs only, with attribution and timestamps File storage and document hosting
Decision record — issue, owner, written resolution Budget versus actual, drawdowns, indirect cost
Report register — what was filed, when, and where Pre-award prospecting and proposal management
Audit pack export — one printable PDF plus CSV Time tracking and effort certification
Retention policy reminder under 2 CFR 200.334 Single sign-on and third-party integrations

Pricing

Priced for one audit, not for a year of software

Two ways to pay. Most organizations facing a deadline take the flat fee.

Audit season

$29 per month, annual commitment

Cancel anytime. For organizations whose audit cycle runs long or who want the file open year-round.

  • Everything in the flat fee
  • Keep the file current between audits
  • Add awards as they are made
  • Credit applied if you convert to the full platform

Talk to us

Converting afterwards. If Single Audit in a Box works for you, the full platform is half price for the first year and everything you entered carries over. There is no re-entry and no export-and-import step.

Where this product is today

Early access, stated honestly

Single Audit in a Box is new. We are not going to print a customer count on this page until there is a real one worth printing, and we are not going to show you testimonials we do not have — on a product sold to people who assess evidence for a living, that would be a poor first impression.

What we will tell you: the record model underneath this product is the same one that has been running in Kharazm, the security model is documented in detail on the security page including the gaps we have not yet closed, and setup happens on a call with the person who built it.

If you need a reference before you buy, ask us and we will tell you plainly whether we have one for a situation like yours yet.

Questions

Before you buy

What is the difference between this and the full platform?

Single Audit in a Box is preparation for one audit. It holds a minimal award record, your subrecipient monitoring file, evidence links, decisions and a report register, and produces one printable audit pack. It has no ongoing task or program management, no budget tracking and no reporting cadence. The full platform is for keeping that record continuously across many awards so the next audit is not an event.

Compare the platform tiers

Do you store our documents?

No. You link to evidence where it already lives — your shared drive, your accounting system, your grants portal — and Kharazm records what each item is, who added it and when. Your files stay under your own retention policy and access controls.

Can this fix documentation we never created?

No, and any tool that claims otherwise should worry you. Kharazm assembles and organizes what exists, and shows you clearly what is missing while there is still time to address it. It will not backdate anything, because a record that can be backdated is worth nothing to an auditor.

What happens after the audit?

Your workspace stays readable and exportable. If you convert to the full platform, everything you entered comes with you and the first year is half price. If you do not, you can still export the audit pack for your retention obligation under 2 CFR 200.334.

For audit practitioners

If you perform Single Audits, your clients keep failing the same tests

Subrecipient monitoring and contemporaneous documentation produce findings year after year, and you are usually asked what the client should have been doing instead.

We would rather your clients arrive prepared than have you spend the engagement chasing a monitoring file. If you refer clients, we will set them up directly and keep you out of the software business.

Independence, respected

We are not asking you to recommend software to a client you audit, and we will not put your firm's name on our site without written permission. A referral here means telling a client this exists.

Your independence obligations are yours to judge. We will follow whatever boundary you set.

Get the file assembled before the request list arrives

One call, about thirty minutes of entry, and a pack you can hand over. If we do not think this will help your situation, we will say so on the call.