Prepare for Greater Scrutiny of Controls in Your Next Compliance Audit

  • Policy and regulation
  • 9/2/2026
Senior businessman doing a staff meeting in the office

Key insights

  • You may see more detailed auditor questions about internal controls, documentation, and compliance processes as audit firms adjust their approach to the GAS Single Audit Guide.
  • Your internal controls should connect entity-wide practices, such as governance and accountability, with specific control activities tied to federal award compliance requirements.
  • Reviewing risks, control activities, and documentation before fieldwork can help your team respond more efficiently when audit requests become more detailed.
  • Strong audit readiness includes clear policies, documented control performance, and employee training that helps staff understand how controls support compliance.

Review controls to support federal awards compliance.

Talk to an Advisor

Organizations receiving federal funding may notice their auditors asking more detailed questions about internal controls, requesting additional documentation, and spending more time understanding how compliance-related processes operate.

Upcoming changes reflected in the Government Accountability Office’s Single Audit Guide are prompting many audit firms to revisit how they evaluate controls over compliance.

As a result, organizations subject to a single audit may experience increased scrutiny of their internal control environment and should consider reviewing their processes before their next audit cycle.

GAS Single Audit Guide overview

Strong internal controls have always been a cornerstone of regulatory compliance in audits.

The upcoming effective date for the 2025 Government Auditing Standards (GAS) Single Audit Guide, and the corresponding anticipated issuance of the 2026 Guide, are expected to increase emphasis on the components of an entity’s system of internal control. As a result, both auditees and auditors may need to reassess their approach to internal controls over compliance.

Although the Guide focuses on single audits over federal funding, organizations receiving other funds subject to compliance audits may also benefit from reviewing the recommended changes.

The Guide is informational and does not have authoritative status. However, AU-C section 200 requires auditors to consider applicable interpretive publications when planning and performing audits.

Internal controls start with more than policies and procedures

Organizations receiving federal awards are required under Uniform Guidance to establish, document, and maintain effective internal controls over federal programs. An effective system of internal control begins with entity-wide controls, such as governance, oversight, ethics, and accountability, that help create a culture of compliance and prioritize integrity.

Uniform Guidance underwent significant revisions to reduce administrative burden for recipients of federal funds. Learn how these changes may affect your organization.

Those entity-wide controls should be supported by more specific control activities that are directly tied to compliance requirements. For example, an organization may have a robust code of conduct that outlines communication and reporting expectations among staff, management, and those charged with governance when potential noncompliance is identified.

However, noncompliance is often detected through detailed activity-level controls, such as review, approval, or reconciliation procedures, rather than through entity-wide controls alone.

What auditors may ask you to demonstrate

The Guide outlines steps auditors should use during their initial risk assessment procedures to gain an understanding of control activities. As a result, organizations may experience more detailed inquiries early in the audit process and receive requests that focus on specific process risks and compliance-related controls.

Auditors May Focus On Organizations May Need to Provide
Risks of material noncompliance Risk assessments and supporting documentation
Key risk processes Walkthroughs of grant-related activities
Potential failure points Explanations of where errors or noncompliance could occur
Control activities Evidence of reviews, approvals, reconciliations, and monitoring activities
Control design Documentation demonstrating that controls are implemented and operating effectively
 
Read the transcript.

In the past, we may have said, "Okay, we have this instance of noncompliance. So what we're going to do is test more transactions, and then we're going to look at the dollar amount that's attached to that instance of noncompliance and try to project it to the population to help us decide whether we have material noncompliance or not." That approach is now changing.

Auditors are expected to pause and say, "Okay, auditee, we believe we've found an instance of noncompliance. We need your help to do a root cause analysis on this." They may ask whether there was something unique about the transaction, whether it occurred while a responsible employee was on leave, or whether it was associated with a specific location or circumstance.

Once a root cause has been identified, auditors will perform procedures to corroborate that conclusion. The extent of those procedures will depend on auditor judgment and whether sufficient appropriate audit evidence has been obtained to support an opinion on the program. In some cases, that may be enough to conclude the matter.

However, additional procedures will often be necessary. After agreeing on the root cause, auditors may ask the organization to help identify which transactions share similar characteristics with the exception and which do not. Transactions that share characteristics with the identified exception may be grouped into a higher-risk population for further review.

Auditors will then obtain additional evidence, based on professional judgment, to evaluate the potential magnitude of the issue. If the affected population cannot be isolated or disaggregated, auditors may need to evaluate the broader population and perform additional testing.

How to strengthen internal controls before your next audit

Action items your organization can use to strengthen control structures and prepare for increased audit scrutiny include:

  • Perform an initial risk assessment of existing entity-wide and compliance-specific controls. Specifically identify the internal controls that exist to mitigate risks of noncompliance.
  • Develop or strengthen controls that are insufficient, document key controls, and maintain evidence demonstrating that controls are being performed as intended.
  • Develop and maintain clearly written policies and procedures that identify key controls associated with relevant compliance requirements and cost categories. Each distinct activity or process should include a control capable of preventing, detecting, or correcting noncompliance.
  • Use this as an opportunity to strengthen understanding and communication across your organization. Provide training to help employees understand new or updated procedures and reinforce the connection between internal controls and compliance requirements.

What this could mean for your industry

Nonprofits

Smaller organizations have always had to get creative about segregation of duties and internal controls. It is increasingly important for small nonprofits to clearly identify and document distinct individuals involved in the preparation and review of compliance-related activities.

Implementation timeline

The 2025 GAS Single Audit Guide was released in October 2025 and became effective for fiscal years beginning on or after October 1, 2025. The 2026 Guide is anticipated in September 2026.

This means many audit firms are increasing scrutiny of controls for audit periods with fiscal year ends of September 30, 2026, and beyond.

Reviews must be handled internally, so organizations should not assume the granting agency is performing sufficient review. However, engaging a part-time contract accountant or identifying a financially knowledgeable board member to perform review activities may help expand the capabilities of smaller teams.

State and local government

State and local governments may face unique challenges in applying the updated internal control approach because compliance-related activities are often performed at the department or program level rather than through a centralized process.

As a result, the potential failure points associated with a compliance requirement may differ significantly across departments, programs, or locations within the same government entity.

The new emphasis on potential failure points requires both auditors and management to focus on where and how noncompliance could occur within a specific process, including points where information is initiated, collected, transferred, or acted upon.

For example, potential failure points related to allowable costs may exist within a department responsible for payroll processing, while procurement-related risk points may reside within a separate purchasing function.

This more detailed understanding of program- and department-level activities helps auditors identify the controls management has implemented to address specific process risks. It also supports a more targeted evaluation of controls over compliance for major programs.

 
Read the transcript.

I did want to show a high-level example of what happens when an auditor puts all of these new changes together and what that might look like for your organization. In this example, payroll and fringe benefits, which may have previously been grouped together under payroll, are evaluated separately from contractual payments.

The auditor begins by assessing the risk of material noncompliance (RMNC). Obtaining an understanding of the process is not a new requirement; auditors have always been required to do that. They then determine whether the RMNC is low, moderate, or high and evaluate control risk to determine whether reliance on controls is appropriate.

As auditors obtain an understanding of controls, they identify process risk points (PRPs) within each process. For example, within payroll, one PRP may be timesheet approval, while another may be the review of the journal entry used to allocate payroll costs to grants. Each represents a point where something could potentially go wrong.

This example illustrates that a single RMNC may have multiple process risk points. As a result, an organization could have five controls that require testing even though only three RMNCs were identified.

After control testing is completed, substantive testing would then take place.

*RMNC = risk of material noncompliance

*PRP = process risk point

How CLA can help with compliance audit readiness

Organizations receiving federal funding don’t have to wait until audit fieldwork begins to evaluate their internal controls. Reviewing your control environment, documentation, and compliance processes now can help your team respond more effectively to increased audit scrutiny and strengthen grant compliance efforts year-round.

CLA works with organizations to assess internal controls and implement grant management policies and procedures. We also provide single audit preparation services to help organizations evaluate compliance requirements, strengthen documentation, and prepare for upcoming audit requests.

Contact us

Review your controls to support federal awards compliance. Complete the form below to connect with CLA.

Experience the CLA Promise


Subscribe