Back to Articles
    Finance & Compliance

    Monitoring Subrecipients With AI

    When you pass federal money to another organization, you take on responsibility for how they spend it. Their unallowable costs can become your finding, their weak controls become your exposure, and their missing single audit becomes your problem. Most pass-through nonprofits know this and monitor anyway with a spreadsheet, good intentions, and one overloaded staff member. AI can make that monitoring genuinely systematic, provided you keep it on the analysis side and out of the judgment.

    Published: August 25, 202615 min readFinance & Compliance
    Nonprofit staff reviewing subrecipient compliance documentation with AI assistance

    Passing money through to partner organizations is how a great deal of federal program delivery actually happens. A statewide coalition receives an award and distributes to twelve local agencies. A large service provider subawards to smaller culturally specific organizations that can reach communities it cannot. A backbone organization in a collective impact effort holds the grant while partners deliver. In every case the entity holding the prime award carries obligations that do not end when the money moves.

    Those obligations are set out in 2 CFR 200.332, and they are more extensive than many pass-through entities realize. You must identify specific required information in every subaward. You must evaluate each subrecipient's risk of noncompliance and calibrate your monitoring to that risk. You must monitor in a way that provides assurance the subaward was used for authorized purposes. You must verify that subrecipients requiring a single audit obtain one, and you must follow up on their findings.

    The tension is that most pass-through nonprofits are not equipped to do this well. Monitoring competes with running your own programs, the staff assigned to it usually have other full-time responsibilities, and the relationship with subrecipients is often collegial in a way that makes rigorous oversight feel adversarial. So monitoring becomes reactive: you find out about the problem when the auditor does.

    This is a strong fit for AI because the underlying work is document-heavy, rule-driven, repetitive, and currently done badly for capacity reasons rather than knowledge reasons. Below we cover what the regulation actually requires, how to build a risk assessment that means something, where AI compresses the monitoring workload, the places it must not substitute for judgment, and how to keep the relationship with your partners intact while doing it properly.

    Your Obligations Start Before the Money Moves

    The first requirement is classification, and getting it wrong invalidates everything downstream. A subrecipient carries out part of a federal program and is subject to the program's compliance requirements. A contractor provides goods or services within its normal business operations to many purchasers. The distinction is about the substance of the relationship rather than what you called the document, and organizations that label a subaward a contract to avoid monitoring obligations have not avoided anything. If the partner is making programmatic decisions, determining eligibility, or delivering the funded service, they are a subrecipient.

    The second is the subaward agreement itself. The regulation lists specific information every subaward must clearly identify, including the federal award identification number, the subrecipient's unique entity identifier, the period of performance, the amount obligated, the assistance listing number and program title, whether the award is for research and development, and the indirect cost rate applicable to the subaward. Missing elements are a common finding and a completely avoidable one, since it is a checklist problem.

    The third is the indirect cost obligation, which pass-through entities frequently get wrong. If a subrecipient has a negotiated rate, you must honor it. If they do not, they may elect the de minimis rate, currently fifteen percent of modified total direct costs following the 2024 revision to the Uniform Guidance. A pass-through entity cannot impose a lower cap as a matter of policy. Organizations that have written a ten percent limit into their standard subaward template are out of compliance and are also underfunding their partners. Our guide to indirect cost rates and the de minimis election covers the mechanics on both sides of that relationship.

    The fourth is the risk assessment, which is the requirement that most organizations treat as a formality and that actually drives everything else. You are required to evaluate each subrecipient's risk of noncompliance in order to determine appropriate monitoring. The regulation names factors to consider: prior experience with the same or similar subawards, results of previous audits, whether the entity has new personnel or substantially changed systems, and the extent of federal monitoring the subrecipient already receives.

    The fifth is ongoing monitoring and audit follow-up. You must review financial and performance reports, follow up to ensure corrective action on deficiencies found through audits, on-site reviews, or other means, and issue management decisions on audit findings relating to the subaward. Where a subrecipient meets the single audit threshold, currently one million dollars in federal expenditures for fiscal years beginning on or after October 1, 2024, you must verify they obtained the required audit.

    Elements every subaward agreement must identify

    A checklist failure here is an easy and common finding

    • Federal award identification number and the subrecipient's unique entity identifier
    • Subaward period of performance start and end dates
    • Amount obligated by this action and total amount of federal funds obligated
    • Assistance listing number and program title, and the awarding federal agency
    • Whether the award is for research and development
    • The indirect cost rate applicable to the subaward
    • All requirements the subrecipient must meet for the pass-through entity to satisfy its own obligations

    A Risk Assessment That Actually Changes What You Do

    The most common failure in subrecipient monitoring is not the absence of a risk assessment. It is a risk assessment that exists as a document, rates everyone medium, and has no connection to the monitoring anyone actually performs. If your assessment does not produce different monitoring for different subrecipients, it is not functioning as a control and it will not persuade an auditor that your monitoring was risk-based.

    Build it around factors that genuinely predict noncompliance. Federal award experience is the strongest single signal: an organization managing its first federal dollars faces a steep learning curve regardless of how competent it is at its actual work. Audit history matters, both whether the subrecipient has a single audit and what it said. Financial condition matters, since an organization under cash pressure is more likely to have allocation problems. Organizational stability matters, particularly turnover in the finance function. And the size of the subaward relative to the subrecipient's total budget matters, because a partner for whom your subaward is most of their revenue is in a very different position from one for whom it is a small addition.

    Be careful about one thing here, because it is an equity problem as well as a methodological one. Small, newer, community-rooted organizations will score higher risk on nearly any scoring model you build. That is often accurate as a statement about compliance infrastructure and completely inaccurate as a statement about program quality or trustworthiness. High risk should mean more support and closer contact, not exclusion from funding. Pass-through entities that use risk scores to narrow their partner pool end up funding the organizations that least need the money and cutting out the ones with the deepest community reach.

    The output of the assessment should be a monitoring plan with specific commitments, not a rating. Low risk might mean annual report review and confirmation of the single audit. Medium might add quarterly financial detail and a mid-year check-in. High might mean monthly reporting, transaction testing on a sample of expenditures, a site visit, and targeted technical assistance on the specific weakness identified. Write the plan down, follow it, and document that you followed it.

    Factors worth weighting

    Signals that correlate with compliance difficulty

    • Prior experience with federal awards, especially this program
    • Single audit history, including repeat findings and their severity
    • Financial condition, liquidity, and reliance on this subaward
    • New personnel in finance or substantially changed accounting systems
    • Extent of monitoring the subrecipient already receives from federal agencies
    • Complexity of the compliance requirements in this particular program

    Assessment antipatterns

    Ways the exercise becomes decorative

    • Everyone rated medium, so nothing about monitoring changes
    • Scores that never update after the first year of the relationship
    • A rating with no documented monitoring plan attached to it
    • Using the score to screen partners out rather than to size support
    • Organization size used as a proxy for trustworthiness
    • A plan written and then not actually executed, with no record either way

    Where AI Removes the Capacity Constraint

    Almost everything in subrecipient monitoring involves reading documents and comparing them against rules. That is precisely where language models are strong, and it is precisely the work that does not get done when the person responsible has four other jobs.

    Reading single audit reports. A single audit report runs well over a hundred pages, and the parts that matter to you as a pass-through entity are scattered: the schedule of expenditures of federal awards, the schedule of findings and questioned costs, the auditor's opinion on compliance for major programs, the summary of prior year findings and their status, and any going concern language. Extracting those elements and flagging anything that touches your program turns a task that gets deferred into one that takes minutes. Doing it across a dozen subrecipients each year is where the value compounds.

    Subaward agreement completeness. Checking every executed subaward against the required elements is a mechanical comparison with a clear answer, and it catches the missing assistance listing number or absent indirect rate before anyone else does. Run it at execution, not at audit.

    Financial report review. When invoices and financial reports come in, comparing reported expenditures against the approved budget, checking spending pace against the period of performance, spotting cost categories that appear without budget authority, and identifying charges that look unallowable on their face is fast analytical work. It produces a list of questions to ask rather than conclusions, which is exactly the right output.

    Cross-report consistency. Subrecipients submit financial reports and programmatic reports, often to different people at your organization, and nobody compares them. When the financial report shows sixty percent of the budget spent and the program report shows a fraction of the planned participants served, that gap is a genuine signal. Systematically checking those two streams against each other is something almost no pass-through entity does by hand and is straightforward to automate.

    Deadline and obligation tracking. Report due dates, period of performance end dates, single audit submission deadlines, corrective action plan milestones, and closeout requirements across a portfolio of subawards are a calendar problem that a spreadsheet handles badly. Our guide to automating grant compliance calendars covers the pattern, and the same infrastructure serves both directions of the relationship.

    Preparing for the conversation. Before a check-in or site visit, having a briefing that pulls together this subrecipient's history, open items, recent reports, prior findings, and the specific questions worth asking makes a thirty-minute call substantially more useful. This is drafting work built on facts you already hold.

    What to extract from every subrecipient single audit

    The five minutes that matter in a hundred-page document

    • Whether your program was tested as a major program
    • The type of opinion issued on compliance, and any modification
    • All findings, their severity, and whether any relate to your subaward
    • Repeat findings from prior years, which signal unresolved weakness
    • Questioned costs and the corrective action plan the subrecipient proposed
    • Going concern language or significant changes in financial position
    • Whether your subaward appears correctly on their schedule of federal expenditures

    What Automation Cannot Do Here

    The regulation asks pass-through entities to obtain assurance that subawards were used for authorized purposes. Assurance is a judgment held by a responsible person, and no volume of automated document review produces it on its own. Everything described above narrows what a human needs to look at. None of it substitutes for the looking.

    The most important limit concerns the management decision on audit findings. When a subrecipient's audit produces a finding that touches your subaward, you are required to issue a management decision, and that decision has consequences for both organizations. It requires understanding what happened, evaluating whether the proposed corrective action is adequate, and deciding whether costs should be disallowed. A model can summarize the finding and draft the letter. The decision belongs to a person with authority, and the reasoning behind it needs to be theirs.

    A second limit is that most serious problems do not appear in documents. Program staff turnover, a subrecipient quietly serving a different population than the one described, deteriorating relationships with the community, or an executive director who has stopped returning calls are all things you learn from contact. Automated monitoring works best when it frees up enough time for the site visits and conversations that surface the rest. If your response to better document review is fewer visits, you have made monitoring worse.

    A third is proportionality. It is now technically easy to demand monthly transaction-level detail from every subrecipient, and doing so would be a mistake. Monitoring imposes real cost on the monitored organization, and a small partner spending twenty hours a month satisfying your requests is spending them instead of on program delivery. Risk-based means less monitoring for lower-risk partners, not uniformly more because it became cheap for you.

    Fourth, be careful with subrecipient data. Financial statements, audit reports, personnel details, and in some programs client-level information all flow through this process. Confirm what your tooling does with that data before routing partner information through it, particularly since you are a custodian of another organization's confidential material rather than your own. Our guide to privacy risk assessment for AI projects is the right starting point.

    Automate the analysis

    Narrowing what a person reviews

    • Extracting the relevant sections of single audit reports
    • Checking agreements against required elements
    • Comparing financial reports to budget and burn rate
    • Reconciling financial reports against programmatic reports
    • Tracking deadlines and open corrective actions across the portfolio

    Keep with people

    Decisions and relationships

    • The management decision on any audit finding
    • Judging whether corrective action is adequate
    • Deciding to disallow costs or withhold payment
    • Site visits and the conversations that reveal what documents do not
    • Setting the monitoring level, including the choice not to escalate

    Monitoring Without Damaging the Partnership

    Pass-through relationships in the nonprofit sector are rarely purely transactional. Your subrecipients are often long-standing partners, sometimes organizations you helped start, frequently groups doing work you could not do yourselves. Rigorous monitoring can feel like a betrayal of that relationship, which is why so much of it is performed apologetically or not at all.

    The reframe that works is that monitoring failures hurt the subrecipient more than they hurt you. A partner who spends two years charging costs incorrectly and then faces disallowance is in far worse shape than one whose error was caught in month three. Small organizations rarely have the reserves to absorb a repayment demand. Catching problems early is a service you provide, and describing it that way is honest rather than diplomatic.

    Be transparent about the process. Tell subrecipients how risk is assessed, what monitoring at their level involves, what you will ask for and when, and what happens if something is found. Uncertainty is what makes oversight feel adversarial. A partner who knows the quarterly report gets checked against the budget and that questions are routine responds very differently from one who receives an unexpected email listing seven discrepancies.

    Pair monitoring with capacity building, which is where the freed-up time should go. If your review consistently finds the same weakness across several partners, that is a training need rather than five separate compliance conversations. Pass-through entities well positioned to help here often find that a single session on cost allocation or time and effort documentation prevents more findings than a year of individual follow-up. Organizations thinking about this at a portfolio level may find our discussion of managing strategic nonprofit partnerships useful.

    And be honest with partners about your use of AI in this process. If subrecipient financial statements and audit reports are being processed through automated tooling, they are entitled to know, particularly since some of that material is confidential. Saying so plainly costs nothing and prevents an uncomfortable discovery later.

    Conclusion

    Subrecipient monitoring is a requirement most pass-through nonprofits meet partially, not because they misunderstand it but because doing it properly has been genuinely unaffordable. Reading twelve single audit reports carefully, checking every agreement against a list of required elements, reconciling financial against programmatic reporting, and tracking a portfolio of deadlines is more work than the staffing allows.

    That constraint has loosened considerably. The document-heavy analytical work at the center of monitoring is exactly what AI handles well, and automating it converts monitoring from a reactive scramble into a routine that runs on schedule. The organizations that benefit most are the ones currently doing least, because the gap between nothing and systematic is enormous.

    Keep the judgment where it belongs. Management decisions on findings, the choice to disallow a cost, and the assessment of whether a partner is actually delivering are yours to make and to own. Use the time automation gives back on site visits and technical assistance rather than on generating more requests. Monitoring done this way protects your organization, protects your partners from findings they cannot absorb, and does not require you to treat the people you fund as suspects.

    Monitor Your Subawards Without Adding Headcount

    We help pass-through nonprofits build compliance processes that run reliably and leave time for the partner conversations that matter.