Historical Context & Motivation
The need for formal compliance reporting arose from a fundamental tension in public finance: governments and other funding bodies distribute resources to entities that operate at arm's length, yet those entities must demonstrate they have spent funds in accordance with applicable laws, regulations, and contractual provisions. Without a structured reporting mechanism, oversight bodies had no systematic way to verify that recipients honored the conditions attached to public monies. The evolution of compliance reporting in auditing reflects broader trends in accountability, transparency, and the professionalization of government oversight.
Against this historical backdrop, a central question emerges: How should an auditor structure, execute, and report on the evaluation of an entity's compliance with laws, regulations, and contractual requirements? The answer lies in a well-defined framework of professional standards—Government Auditing Standards (the Yellow Book), the Uniform Guidance, and AICPA attestation standards—that together prescribe the form and content of the report on compliance and internal control over compliance.
Core Principles & Definitions
Compliance reporting in the context of a single audit requires the auditor to issue two distinct reports beyond the standard financial statement opinion: a report on compliance for each major program and a report on internal control over compliance. These reports operate under the conceptual framework that compliance obligations are measurable criteria against which an entity's transactions can be tested. The auditor's objective is to obtain sufficient appropriate evidence to express an opinion on whether the entity complied, in all material respects, with the types of compliance requirements applicable to each major federal program.
Compliance Requirements
Major Program Determination
Opinion on Compliance
Internal Control Over Compliance
Schedule of Findings & Questioned Costs
Visual Explanation — The Compliance Reporting Framework
As illustrated above, the compliance reporting process is layered atop the financial statement audit. The auditor first completes or is concurrently performing the financial statement audit under generally accepted auditing standards (GAAS). From there, the auditor applies the risk-based approach prescribed by the Uniform Guidance (2 CFR 200) to determine which federal programs qualify as major programs. The twelve types of compliance requirements—detailed in the annual Compliance Supplement published by the OMB—form the criteria against which the auditor evaluates the entity's transactions. Notice that the two reports (compliance and internal control over compliance) are distinct but interconnected: deficiencies in internal control frequently give rise to instances of noncompliance, and vice versa.
How It Works — The Mechanics of Compliance Testing
Major Program Determination
The Uniform Guidance establishes a quantitative and qualitative framework for identifying major programs. The auditor categorizes programs as Type A (larger programs, determined by a sliding-scale dollar threshold) or Type B (smaller programs). Only a subset of Type A and high-risk Type B programs become major programs subject to compliance testing. The dollar thresholds are important for candidates preparing for the AUD section of the CPA exam.
Materiality in Compliance Auditing
Unlike financial statement audits where materiality is typically set as a percentage of a financial benchmark (e.g., 5% of net income), compliance materiality is assessed at the individual major-program level. The auditor determines the amount of noncompliance that would be material to a particular federal program, typically using total program expenditures as the base. Because federal agencies may view any noncompliance as significant, auditors often apply lower materiality thresholds than they would for financial statement work. There is no universally mandated percentage; professional judgment drives the determination, but many practitioners use benchmarks in the range of 3% to 5% of program expenditures.
The Twelve Types of Compliance Requirements
The Compliance Supplement identifies twelve categories of requirements that may apply to federal programs: (A) Activities Allowed or Unallowed, (B) Allowable Costs/Cost Principles, (C) Cash Management, (D) Reserved, (E) Eligibility, (F) Equipment and Real Property Management, (G) Matching/Level of Effort/Earmarking, (H) Period of Performance, (I) Procurement and Suspension and Debarment, (J) Program Income, (L) Reporting, and (M) Subrecipient Monitoring. Not all twelve apply to every program; the Supplement specifies which requirements are direct and material to each Assistance Listing number (formerly CFDA number). The auditor tests only those compliance requirements that have been identified as direct and material for the specific major program under examination.
Detailed Breakdown — Elements of the Compliance Report
The compliance report follows a structured format that parallels the financial statement audit report but includes several distinctive features. The opinion section now appears first under the revised AICPA reporting standards, consistent with the clarified auditing standards. Critically, the compliance report includes a restricted-use (purpose) paragraph that limits the report's intended audience to the entity's management, those charged with governance, federal awarding agencies, and pass-through entities. This restriction reflects the specialized nature of the report—it is designed for users who need to assess compliance with specific grant or contractual provisions, not the general investing public.
| Opinion Type | When Issued | Key Language |
|---|---|---|
| Unmodified | Entity complied, in all material respects, with compliance requirements | "In our opinion, [Entity] complied, in all material respects, with the types of compliance requirements..." |
| Qualified | Material noncompliance exists but is not pervasive to the program | "Except for the noncompliance described in the Basis for Qualified Opinion section..." |
| Adverse | Noncompliance is both material and pervasive to the program | "Because of the significance of the matter described in the Basis for Adverse Opinion section, [Entity] did not comply..." |
| Disclaimer | Auditor unable to obtain sufficient appropriate evidence | "We were not able to obtain sufficient appropriate audit evidence to provide a basis for an audit opinion..." |
Worked Example — Evaluating Compliance and Drafting the Report
Consider the following scenario. You are the senior auditor on the single audit engagement for Riverside County, which expended $42 million in federal awards during the fiscal year ended June 30, 20X4. The county administers programs including Medicaid (Assistance Listing 93.778), Highway Planning and Construction (20.205), and several smaller grants. Your task is to determine major programs, set compliance materiality, test compliance, and formulate the report.
Compliance Report vs. Financial Statement Report — Strengths & Limitations
| Dimension | Financial Statement Audit Report | Compliance Report (Single Audit) |
|---|---|---|
| Subject Matter | Fair presentation of financial statements under GAAP | Compliance with requirements applicable to each major federal program |
| Criteria | GAAP (U.S. GAAP, GASB, etc.) | Laws, regulations, contract/grant provisions identified in the Compliance Supplement |
| Materiality Base | Entity-wide financial benchmarks (revenues, assets, net income) | Individual program expenditures (materiality set per major program) |
| Distribution | General purpose—available to all stakeholders | Restricted use—entity, federal agencies, and pass-through entities |
| Standards | GAAS (AU-C sections) | GAS (Yellow Book), Uniform Guidance (2 CFR 200), GAAS |
| Internal Control Reporting | Deficiencies communicated in writing; separate report under GAS | Separate report on internal control over compliance is required |
Connection to Advanced Theory — Government Auditing Standards & Beyond
The compliance report examined in this lesson exists within a layered hierarchy of professional standards. While the Uniform Guidance prescribes the compliance audit requirements for federal awards, the Government Auditing Standards (commonly known as the Yellow Book) issued by the GAO impose additional reporting requirements that go beyond GAAS. These include expanded internal control reporting, reporting on compliance with provisions of laws and regulations that have a direct and material effect on the financial statements (separate from the single audit compliance report), and heightened independence and continuing professional education standards. Understanding how these layers interact is essential for advanced practice and is tested on the AUD section of the CPA exam.
| Aspect | Single Audit Compliance Report | Yellow Book Compliance Reporting |
|---|---|---|
| Scope | Compliance with requirements applicable to each major federal program | Compliance with laws and regulations that could have a direct and material effect on the financial statements |
| Opinion vs. Report | An explicit opinion on compliance is issued | A report on compliance is issued but typically does not include an opinion—results are reported as findings |
| Internal Control | Separate report on internal control over compliance (per Uniform Guidance) | Report on internal control over financial reporting, with compliance findings integrated |
| Filing | Submitted to the Federal Audit Clearinghouse (FAC) as part of the reporting package | Provided to the audited entity and relevant oversight bodies as specified by the engagement |
Looking forward, the landscape of compliance reporting continues to evolve. The GAO periodically revises Government Auditing Standards, and the OMB has been updating the Compliance Supplement annually to reflect new federal programs (including those arising from pandemic-era legislation such as the CARES Act and the American Rescue Plan Act). For CPA exam candidates, it is worth noting that the exam tests the conceptual framework and general reporting structure rather than specific program details, making a deep understanding of the principles discussed in this lesson more valuable than memorizing individual Assistance Listing numbers.
Practice Problems
Lesson Summary
The report on compliance in a single audit provides an explicit opinion on whether the entity complied, in all material respects, with the compliance requirements applicable to each major federal program. The auditor determines major programs using a risk-based approach anchored to the Type A/Type B classification system, tests the twelve types of compliance requirements identified in the Compliance Supplement, and sets materiality at the individual program level. The four opinion types—unmodified, qualified, adverse, and disclaimer—mirror the framework used for financial statement opinions but are applied to compliance rather than GAAP presentation.
Alongside the compliance opinion, the auditor issues a companion report on internal control over compliance and documents all findings in the schedule of findings and questioned costs. The compliance report is restricted-use, limited to the entity, federal awarding agencies, and pass-through entities. It is governed by the Uniform Guidance (2 CFR 200) and Government Auditing Standards (Yellow Book), layered on top of GAAS. For the CPA exam, mastering the structure, required elements, and opinion modification logic of the compliance report is critical to success on the AUD section.