A nonprofit audit is an independent examination of an organization's financial statements, internal controls and compliance with the rules attached to its funding, carried out by an external CPA. The largest of these are federal Single Audits, and the Federal Audit Clearinghouse processes roughly 40,000 of them each year. An audit is an assurance exercise. Tax filing and fraud investigation are separate jobs.
The word covers more than one thing, which is where confusion starts. Some audits look only at your numbers. Others test whether you followed the rules tied to a grant. This guide explains what each examines, when one is required, and what an auditor will ask you to produce. For the wider view across governance, fundraising and data, see our complete guide to nonprofit compliance.
A nonprofit audit examines three things: whether your financial statements are fairly presented under GAAP, whether your internal controls are sound, and whether you complied with the rules attached to your grants and donor restrictions. An external CPA gathers evidence and forms an opinion on each. The result is reasonable assurance, not a guarantee.
The qualifier "reasonable" does real work here. The auditor's objective is reasonable assurance that the financial statements are free from material misstatement, which the AICPA describes as a high, but not absolute, level of assurance (AU-C 200).
An audit also differs from related tasks. A CPA may surface fraud during the work, but detecting it is not the engagement's purpose, and the audit is not a tax filing.
The people doing the work are independent CPAs, not regulators. They report findings to your board and, where federal funds are involved, into the federal system. Their independence is what gives the opinion its weight.
A federal Single Audit is required only when an organization spends $1 million or more in federal funds in a fiscal year, effective for fiscal years beginning on or after 1 October 2024. Below that line, no federal Single Audit is triggered. Many states and individual funders, however, require an independent audit regardless of the federal figure.
Three caveats keep this from being a clean exemption. An award issued before October 2024 can still carry the old $750,000 threshold, so organizations holding a mix of older and newer awards should track them by issue date rather than assume the new line covers everything.
A Single Audit is also not the only audit that matters. Funders and grantors frequently require an independent audit as a condition of award, and program-specific reviews continue alongside it. State law is a third trigger.
Even after the threshold rose, a large population of organizations remains inside the federal net, so for many groups the question is which type of audit applies, not whether one does.
Many US states require a nonprofit to obtain an independent audit once its annual revenue or contributions cross a set threshold, usually tied to charitable solicitation registration. Thresholds vary widely from state to state, and some states accept a review rather than a full audit below a certain level. These requirements sit separate from the federal Single Audit.
The trigger is typically gross revenue or total contributions, measured for the registration period. The National Council of Nonprofits notes that 39 states and the District of Columbia require charities to register before fundraising, and many require audited financial statements once revenue or contributions cross a state-specific threshold.
Because the figures differ so much, the safe approach is to check your own state's charitable registration rules rather than rely on a national number. If you are getting ready for one, our guide on how to prepare for a nonprofit audit walks through the documentation side in detail.
An independent financial statement audit examines whether your financial statements are accurate and fairly presented. A Single Audit goes further, testing compliance with the specific requirements attached to each federal program you draw funds from, including the internal controls over those programs. An organization can need one, both, or neither.
| Audit type | What it examines | When it applies |
|---|---|---|
| Financial statement audit | Whether financial statements are accurate and fairly presented under GAAP | Triggered by state thresholds, funders, lenders or board bylaws, not the federal figure |
| Single Audit | The financial statements plus compliance and internal controls for each federal program | Required at $1 million or more in federal spending in a fiscal year (fiscal years beginning on or after 1 October 2024) |
| Program-specific audit | One federal program rather than the whole organization | Used when an organization draws from a single federal program rather than many |
The Single Audit is governed by the OMB Uniform Guidance at 2 CFR Part 200, which sets the threshold and the testing requirements. It folds the financial statement opinion and the federal compliance opinion into a single engagement, which is where the name comes from.
The compliance side is where findings cluster. A March 2025 GAO report analyzed 3,680 single audit findings from 2022 to 2024 addressed to recipients that passed funds to subrecipients. It found 36% were primarily tied to three subaward-oversight problems: incomplete subaward reporting, weak subrecipient monitoring, and missing suspension or debarment checks. Diligent subrecipient monitoring is what those findings test.
Beyond these two, program-specific audits form a third category, used when an organization draws from a single federal program rather than many. Knowing which of the three applies to you is the first step in planning a nonprofit audit.
An auditor asks for evidence in a few groups: financial records, governance documents such as board minutes and policies, and the operational trail behind your spending, which is the vendor, subrecipient and contract records. That last group is where lean teams most often scramble. The numbers usually exist; the supporting trail is what goes missing.
The scale explains the scrutiny: the federal government obligated roughly $1.2 trillion in grants in fiscal year 2024 (GAO), much of it passed on to subrecipients. In practice that trail means signed agreements for every material vendor, proof that each was checked before engagement, conflict of interest and related-party disclosures, records showing subrecipients are being monitored, renewal histories, and evidence that contract obligations were met. The same discipline appears in managing contract obligations and compliance, applied here to the audit context.
It helps to be precise about scope. Gatekeeper holds the vendor and contract side of this trail, not your financial statements, and it does not run the audit or make compliance decisions for you. As one unified platform, it keeps your contract and third-party records on a single data model, current as relationships change.
Within that boundary, Gatekeeper's AI agents do the collecting, chasing and monitoring, while your team keeps the judgment calls. On the vendor management platform, third parties are screened at intake, due diligence is gathered, and continuous risk monitoring surfaces changes as they happen rather than during fieldwork.
Internal controls are the policies and procedures that safeguard a nonprofit's assets and ensure transactions are recorded accurately, such as segregation of duties, approval workflows and access restrictions. Auditors evaluate these to identify risk and recommend improvements. Since the 2024 Uniform Guidance revision, controls must also include cybersecurity safeguards.
That revision now requires recipients and subrecipients to build cybersecurity measures into their internal controls, naming safeguards such as data encryption and multi-factor authentication. This is in force, not proposed, and it pulls vendor security into audit scope in a way it was not before.
The reason is that most of a nonprofit's data risk now sits with its third parties. The 2020 Blackbaud breach is the example most sector leaders still remember, because a supplier's breach became the disclosure problem of every organization that used it. Nonprofits sit inside that trend: the Identity Theft Resource Center recorded a record number of US data compromises in 2025, a 79% rise over five years. Evidencing the requirement means showing a third party's current security posture and what you did when one lapsed.
That evidencing is ongoing third-party monitoring, and it is what a system of record holds rather than something it decides for you. The contract records behind these controls sit in contract management software, and continuous oversight of third-party risk runs on the same unified platform, not a separate tool. The human judgment about what an exception means stays with your team.
A nonprofit audit checklist covers four document groups: financial records, governance documents, program and grant compliance evidence, and the vendor, subrecipient and contract trail. Preparing each group in advance means you answer an auditor's request by searching, not scrambling. Below is a usable version you can work from.
The first three groups, and your program decisions, stay with your organization and its CPA. The vendor, subrecipient and contract items in group four are the part a system of record holds and keeps current. For the full preparation walk-through, see our nonprofit audit preparation guide , read how non-profits manage contracts, grants and third-party risk, and take the contract side further with our free contract management ebook.
Organizations such as the YMCA of Greater Seattle use Gatekeeper to keep that vendor and contract evidence in one current record.
No. A federal Single Audit applies only at $1 million or more in federal spending in a fiscal year, for fiscal years beginning on or after 1 October 2024. Many states require an audit above set revenue thresholds, and individual funders can require one regardless. Some nonprofits need none at all.
An audit provides reasonable assurance that financial statements are free from material misstatement and includes testing of internal controls. A review is a lower level of assurance, based mainly on inquiry and analytics, with no controls testing. Some states accept a review below certain revenue thresholds.
Cost varies by organization size, complexity and number of federal programs. A Single Audit costs more than a financial statement audit alone, because it adds compliance testing. Funders sometimes allow audit costs as an allowable grant expense.
Subaward problems are the most common federal finding. A March 2025 GAO report analyzed 3,680 single audit findings from 2022 to 2024 and found 36% were tied to three subaward-oversight problems: incomplete subaward reporting, weak subrecipient monitoring, and missing suspension or debarment checks.
Keep the record continuous rather than annual. A single place holding every vendor and subrecipient, their vetting and monitoring status, and the contracts and obligations tied to them, kept current as things change, makes audit prep a lookup instead of a project. Gatekeeper's AI agents automate the collecting and chasing on the vendor and contract side; the team keeps the decisions.
When the supporting trail stays current, you answer an auditor's request in minutes rather than days.
Book a demo to see how Gatekeeper's AI agents screen, gather and monitor third-party evidence, so your team keeps the decisions.
See how Gatekeeper delivers real-time visibility, jurisdiction-aware processing, and audit-ready evidence.
Before Gatekeeper, our contracts
Anastasiia Sergeeva, Legal Operations Manager, BlaBlaCar
were everywhere and nowhere.
Gatekeeper is that friendly tap on the shoulder,
Donna Roccoforte, Paralegal, Hakkasan Group
to remind me what needs our attention.
Great System. Vetted over 25 other systems
Randall S. Wood, Associate Corporate Counsel, Cricut
and Gatekeeper rose to the top.
Thank you for requesting your demo.
Next Step - Book a Call
Please book a convenient time for a quick call to discuss your requirements.