Subrecipient monitoring · 2 CFR 200.332

You're required to monitor them.
Prove that you did.

Every subrecipient needs a documented risk assessment and a monitoring plan that matches the risk. Most offices run this on one spreadsheet nobody trusts. Score one in 30 seconds.

Subrecipient risk assessment

Scope: this implements the risk factors named in 2 CFR 200.332(b) and produces a monitoring plan proportional to the score. It is a starting point for your documented assessment, not a substitute for your institution's subrecipient monitoring policy — and thresholds change, so confirm the current Single Audit threshold before you rely on it.

Why this exists

"We monitor them" isn't evidence

At audit, the question isn't whether you monitored — it's whether you can show the assessment, the plan, and the record that you followed it. That's three artifacts most offices don't have.

Pricing

One finding costs more than this

$399/mo

per department · unlimited subrecipients

  • Documented risk assessment per subrecipient
  • Monitoring plan scaled to risk
  • Invoice review checkpoints
  • Single Audit expiry tracking
  • Audit-ready monitoring file, exportable
Request a pilot

More tools like this

Built by the same team, free to try.