Finding Text
Finding 2022-001: Subrecipient Risk Assessment Federal Program: ALN 59.077 Criteria or Specific Requirement: As stated in 2 CFR 200.331 part (b), all pass-through entities must evaluate each subrecipient?s risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward for purposes of determining the appropriate subrecipient monitoring procedures to prescribe to each individual subrecipient. Condition: The Organization did not document the pre-award risk assessment process on its subrecipients that detailed monitoring procedures based on the assessed level of risk. While we noted that the Institute performed an internal pre-award review of all sub-awardees UG audits, and the institute performed monitoring procedures, those procedures were not linked to the initial risk assessment as detailed in a formal policy. Cause: The Organization does not have a formal subaward policy that details the risk assessment process for potential subrecipients. Effect or Potential Effect: The Organization could inadvertently engage in relationships with subrecipients of higher risk without the appropriate level of oversight (i.e. monitoring) to ensure subrecipients are expending funds in accordance with the provisions and terms of the subaward. Questioned Costs: None noted. Context: The Organization did not document the pre-award risk assessment procedures. Our audit work in this area consisted of substantive testwork over a sample of subrecipient expenditures that were selected based on a defined threshold. We consider our sample to be representative of the populations, and thus, is a statistically valid sample. The issue is deemed to be systemic. Identification as a Repeat Finding: Not applicable. Recommendation: We recommend the Organization establish subaward policy and ensure the risk assessment procedures over its subrecipients are performed and documented prior to engagement. Based on these risk assessments, the Organization should assign a risk level to each, and then determine the monitoring tools to apply based on these risk levels.