Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Contents

Table of Contents
outlinetrue
styleNone

Overview

...

Per 2 CFR 200, pass-through entities must evaluate their subrecipient's risk of noncompliance with applicable Federal statutes, regulations, and the Federal award's terms and conditions. The central purpose of the risk assessment is to determine the appropriate level of monitoring of Federally-funded project activities to ensure the subaward objectives and purpose are met; that the subrecipient is in compliance with all applicable Federal requirements;, and that the performance goals of the subaward are achieved. 

top

Authorities

...

2 CFR 200 Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards

§200.1 Pass-through entity.

...

All pass-through entities must: 

[...]

(c) Evaluate each subrecipient's fraud risk and risk of noncompliance with a subaward to determine the appropriate subrecipient monitoring described in paragraph (f) of this section. When evaluating a subrecipient's risk, a pass-through entity should consider the following:

...

(4) The extent and results of any Federal agency monitoring (for example, if the subrecipient also receives Federal awards directly from the Federal agency).

Anchor
cofar
cofar

2 CFR 200 Council on Federal Financial Assistance (COFFA) Compliance Supplement (Frequently Asked Questions—January 2025 publication)

.332-44 Requirements for Pass-Through Entities. Timing of Subrecipient Risk Assessments *

...

A: No. Section 200.332(c) requires risk assessments of subrecipients. While there is no requirement for pass-through entities to perform these assessments before making subawards, pass-through entities are encouraged to conduct the risk assessments prior to making subawards. Doing so before making the subaward helps determine the appropriate monitoring tools pass-through entities should use for their subrecipients. Pass-through entities may use their own judgment regarding the most appropriate timing for the assessments. Regardless of the timing chosen, the pass-through entity should document its procedures for assessing risk.

top

Frequently Asked Questions

...

What is the purpose of having to complete a risk assessment of our subrecipients?

Pass-through entities must complete a risk assessment on each of their subrecipients to help ensure that the Federal award is spent properly and that the subrecipient complies with all applicable Federal statutes, regulations, and the terms and conditions of the Federal award. This is the same reason why Federal agencies must also complete a risk assessment for each of their prime recipients prior to issuing a Federal award. The risk assessment also provides the framework by which the pass-through entity can help to mitigate for any potential risk associated with each subrecipient.  

Am I required to complete a risk assessment of my subrecipients before issuing a subaward?

§200.332(c) requires pass-through entities to conduct a risk assessment of their subrecipients, but does not specify that such assessments be completed prior to issuing the subaward or the subsequent disbursement of funds to the subrecipient.  The Council On Federal Financial Assistance (COFFA)) addressed this question in its FAQs (published January 2025). 

My organization uses only "contracts" as the legal instrument to enter into agreements with both subrecipients and contractors. Therefore we consider all of our relationships as contractors. Do we still have to complete risk assessments? 

Maybe. Many entities, particularly State agencies, call all of their legal instruments "contracts". According to 2 CFR 200.331, "An entity may concurrently receive Federal awards as a recipient, a subrecipient, and a contractor. The pass-through entity is responsible for making case-by-case determinations to determine whether the entity receiving Federal funds is a subrecipient or a contractor." Pass-through entities need to reflect upon the nature of each relationship in order to determine if the partnering entity is a subrecipient or a contractor (see 'Subrecipient vs Contractor Determination'). 

How often do I need to complete a risk assessment of a subrecipient?

Pass-through entities should complete a risk assessment of their subrecipients according to their established and documented policies and procedures.  

Where should I keep the results of our subrecipient risk assessment?

It is a best management practice to keep the results of each subrecipient risk assessment in either their agency's official subrecipient award file or in a centralized subject-matter file. In either the case, the results of the risk assessment should be easily accessible by your program/fiscal staff and auditors if they request it. 

What criteria or factors should a pass-through entity evaluate when conducting a risk assessment on a potential subrecipient?

§200.332(c)(1-4) provides some factors that pass-throughout entities may review when evaluating a subrecipient's potential risk of noncompliance. These factors should not limit a pass-through entity from evaluating additional factors that are above and beyond those listed in § 200.331.  

The FWS has developed its own risk assessment form for evaluating their prime recipients. May we use their form to evaluate our subrecipients?

Pass-through entities who have not developed and implemented their own risk assessment form are welcome to review the Service's risk assessment form for evaluating its prime recipients potential risk of noncompliance.  This form may provide a great starting point for pass-through entities as they begin to develop their own risk assessment.  Pass-through entities should be aware that the Service's risk assessment form was developed specifically to satisfy its requirements under § 200.206(b) Federal agency review of risk posed by applicants-Risk Assessment.  This form was not developed for, nor was it ever intended to be used by, pass-through entities to meet their risk assessment requirements under §200.332(c).  Pass-through entities who use the Service's risk assessment form do so voluntarily and the Service accepts no responsibility or liability should auditors determine that this risk assessment fails to meet the requirements set forth for pass-through entities conducting risk assessments of their subrecipients.   

Are there differences in the requirements for a risk assessment that Federal agencies must complete on their prime recipients compared to the requirements for a risk assessment that pass-through entities must complete on their subrecipients? 

Yes there are differences in the requirements. §200.206(b) requires Federal awarding agencies, for competitive grants and cooperative agreements, have in place a framework for evaluating the risk posed by applicants before they receive Federal awards. In evaluating risks posed by applicants, the Federal agency should consider the following items:

(i) Financial stability. The applicant's record of effectively managing financial risks, assets, and resources;

...

(iii) History of performance. The applicant's record of managing previous and current Federal awards, including compliance with reporting requirements and conformance to the terms and conditions of Federal awards, if applicable;

(iv) Audit reports and findings. Reports and findings from audits performed under subpart F or the reports and findings of any other available audits, if applicable; and

(v) Ability to effectively implement requirements. The applicant's ability to effectively implement statutory, regulatory, or other requirements imposed on recipients of Federal awards.

§200.332(c) requires that pass-through entities evaluate each subrecipient's risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward to determine the appropriate subrecipient monitoring described in paragraph (f) of this section. When evaluating a subrecipient's risk, a pass-through entity should consider the following:

(1) The subrecipient's prior experience with the same or similar subawards;

(2) The results of previous audits. This includes considering whether or not the subrecipient receives a Single Audit in accordance with subpart F and the extent to which the same or similar subawards have been audited as a major program;

...

(4) The extent and results of any Federal agency monitoring (for example, if the subrecipient also receives Federal awards directly from the Federal agency).

How should pass-through entities use the results of their subrecipient's risk assessment?

Pass-through entities should use the results of the risk assessment to help determine the appropriate level of subrecipient monitoring to ensure that the subrecipient complies with Federal statutes, regulations, and the terms and conditions of the subaward. The pass-through entity is responsible for monitoring the overall performance of a subrecipient to ensure that the goals and objectives of the subaward are achieved. In monitoring a subrecipient, a pass-through entity must:

...

(3) Arranging for agreed-upon-procedures engagements as described in § 200.425.

What happens if a pass-through entity rates their subrecipient as low risk, but then determines the subrecipients is a higher risk entity?

If a pass-through entity completes a risk assessment and scores a subrecipient low and then during the award identifies enhanced levels of risk posed by the subrecipient, the pass-through has the ability to amend the subaward to add additional terms/conditions to mitigate this risk. Pass-through entities may also choose to increase their monitoring efforts on such subrecipients to ensure that Federal funds are used effectively. Additionally, pass-through entities then use this information during future awards with the subrecipient to enhance the accuracy of their risk assessments (e.g., perhaps increase their risk level as a result of this prior knowledge of past performance issues).

What happens if a subrecipient is scored as high risk, but the pass-through entity does not impose any special requirements?

Imposing special requirements on high/medium/low risk subrecipients is an effective way for the pass-through entity to mitigate potential risk, ensure that Federal funds are used effectively, and reduce the potential for waste, fraud, and misuse. Pass-through entities should remember that in the unfortunate case where Federal funds may be used inappropriately, or waste, fraud, or abuse has occurred, the Federal agency may seek remedies or legal action against the prime recipient. They will not seek legal action against the subrecipient, this would be the responsibility of the pass-through entity.

What happens if a subrecipient is rated as higher risk, but the pass-through entity fails to follow through on any special requirements?

§200.332 details the requirements of pass-through entities whenever they enter into a financial assistance relationship with a subrecipient using Federal funds. One of the requirements is to conduct a risk assessment of the subrecipient to evaluate that entity's risk potential as it relates to Federal laws, regulations, and the terms and conditions of the prime Federal award. 

The purpose of the risk assessment is to allow pass-through entities to develop monitoring protocols and special terms/conditions to mitigate for potential risk posed by subrecipients and help to ensure that Federal funds are used effectively. §200.339 provides guidance to Federal agencies to remedy noncompliance of their prime recipients.

Can pass-through entities allow their subrecipients to fill out the risk assessment?

§200.332(c) requires pass-through entities to evaluate their subrecipient's risk of noncompliance with Federal statutes, regulations, and the terms and conditions of the subaward. It does not go into detail about what exactly must be included in the risk assessment in order to allow recipients the flexibility to develop their own risk assessment to meet their needs, expectations, and comfort levels.  It also allows pass-through entities to develop grant specific risk assessments to meet the needs of their various financial assistance awards.  It does not specifically address whether the risk assessment may or may not be completed by the subrecipient and subsequently certified by the pass-through entity.

What is the role of the FWS in overseeing implementation of any requirements as result of the risk assessment?

The Service's role in overseeing implementation of the risk assessment is to ensure that its prime recipients follow the requirements of 2 CFR 200 when they receive financial assistance awards.  Department of the Interior OIG auditors may, during their reviews, test whether prime recipients are following the requirements of §200.332 when it has been determined that they are subawarding Federal funds to subrecipients. If prime recipients are found to not comply with the requirements of 2 CFR 200, then the Service may impose additional conditions on prime recipients as outlined in §200.338 in order to meet its Federal stewardship responsibilities.

Am I required to complete a risk assessment of my contractors under the prime Federal award?

Pass-through entities are not required to complete a risk assessment on contractors.

topzz_archive_Risk Assessment Requirements for Pass-Through Entities

Learning Aids

...

topzz_archive_Risk Assessment Requirements for Pass-Through Entities

Related Pages

...

zz_archive_Subrecipient vs Contractor Determination

Subawardtop

zz_archive_Risk Assessment Requirements for Pass-Through Entities

Resources

...

 top

References

...

top