The Single Audit, required by the Single Audit Act and regulated under Uniform Guidance (2 CFR 200, Subpart F), serves as a critical mechanism for oversight of federal funds. Ensuring the quality of these audit reports is essential for federal agencies, pass-through entities, and the public. A robust quality control (QC) review process is the primary defense against audit deficiencies and non-compliance.
A structured QC review of a Single Audit report aims to verify that the auditor has performed the engagement in accordance with Generally Accepted Government Auditing Standards (GAGAS) and the requirements of the Uniform Guidance. Key objectives include:
The reviewer must ensure the auditor applied the correct materiality levels for compliance testing. Unlike financial statement audits, Single Audits require materiality to be determined at the individual major program level. The reviewer should check if the auditor properly identified "Type A" and "Type B" programs and whether the risk-based approach was applied correctly.
The SEFA is the foundation of the Single Audit. A quality review involves reconciling the SEFA to the auditees general ledger and the federal grant records. Reviewers should look for proper identification of federal programs, including Assistance Listing numbers (formerly CFDA), pass-through entity information, and the total amount of awards expended during the fiscal period.
Auditors must perform sufficient testing to support an opinion on internal controls over compliance. The QC review must verify that the auditor not only tested the design of controls but also tested their operating effectiveness. Any noted control deficiencies must be evaluated for their severity and properly reported in the Schedule of Findings and Questioned Costs.
A rigorous review focuses on the clarity and completeness of audit findings. Each finding must be specific, providing enough context for the auditee to understand the nature of the non-compliance. The reviewer should confirm that the auditees Corrective Action Plan (CAP) is included and that it addresses the specific findings reported.
To conduct an effective quality control review, audit firms and organizations should adopt the following practices:
Inadequate documentation of the risk assessment process is a frequent oversight. Reviewers often find that the auditor failed to document why a specific program was or was not considered a high-risk major program. Additionally, failing to verify the proper classification of subrecipient versus contractor relationships is a common source of audit errors. Addressing these areas during the QC review significantly reduces the likelihood of federal rejection or audit failure.
Quality control is not merely a compliance checkbox but a vital process for maintaining the integrity of federal financial assistance. By focusing on the rigorous application of Uniform Guidance, clear documentation of findings, and independent verification of the audit process, practitioners can ensure that their Single Audit reports withstand the scrutiny of oversight agencies and provide stakeholders with the assurance they require.
