CPA AUDITING & ATTESTATION (AUD) • FORMING CONCLUSIONS AND REPORTING

Compliance Reporting — Report On Compliance And Regulatory Requirements

Understanding how auditors evaluate and report on an entity's adherence to laws, regulations, and contractual provisions.

Historical Context & Motivation

The need for formal compliance reporting arose from a fundamental tension in public finance: governments and other funding bodies distribute resources to entities that operate at arm's length, yet those entities must demonstrate they have spent funds in accordance with applicable laws, regulations, and contractual provisions. Without a structured reporting mechanism, oversight bodies had no systematic way to verify that recipients honored the conditions attached to public monies. The evolution of compliance reporting in auditing reflects broader trends in accountability, transparency, and the professionalization of government oversight.

1921
Budget and Accounting Act
The U.S. Congress established the General Accounting Office (now GAO), creating the first formal federal audit function and laying groundwork for government compliance oversight.
1984
Single Audit Act
Congress enacted the Single Audit Act to standardize how entities receiving federal funds are audited, requiring one comprehensive audit rather than separate audits for each federal program—introducing the concept of compliance auditing as a unified discipline.
1996
Single Audit Act Amendments
Amendments raised the threshold for single audit requirements and refined reporting standards, directing auditors to issue explicit opinions on compliance with program requirements.
2003
OMB Circular A-133 Revision
The Office of Management and Budget updated Circular A-133 to clarify auditor responsibilities regarding compliance testing, the Compliance Supplement, and reporting formats—shaping modern compliance audit practice.
2013–2020
Uniform Guidance (2 CFR 200)
The Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards superseded A-133, consolidating compliance audit standards and raising the single audit threshold to $750,000 in federal expenditures.

Against this historical backdrop, a central question emerges: How should an auditor structure, execute, and report on the evaluation of an entity's compliance with laws, regulations, and contractual requirements? The answer lies in a well-defined framework of professional standards—Government Auditing Standards (the Yellow Book), the Uniform Guidance, and AICPA attestation standards—that together prescribe the form and content of the report on compliance and internal control over compliance.

Core Principles & Definitions

Compliance reporting in the context of a single audit requires the auditor to issue two distinct reports beyond the standard financial statement opinion: a report on compliance for each major program and a report on internal control over compliance. These reports operate under the conceptual framework that compliance obligations are measurable criteria against which an entity's transactions can be tested. The auditor's objective is to obtain sufficient appropriate evidence to express an opinion on whether the entity complied, in all material respects, with the types of compliance requirements applicable to each major federal program.

1

Compliance Requirements

The specific laws, regulations, and provisions of contracts or grant agreements that directly affect how federal funds may be spent. These are organized into twelve types of compliance requirements (e.g., activities allowed/unallowed, cash management, eligibility, matching, period of performance, procurement, reporting).
2

Major Program Determination

Not every federal program is tested. The auditor uses a risk-based approach—considering expenditure thresholds, prior audit findings, and inherent risk—to identify major programs that receive detailed compliance testing.
3

Opinion on Compliance

For each major program, the auditor issues an opinion: unmodified (clean), qualified (material but not pervasive noncompliance), adverse (material and pervasive), or disclaimer (insufficient evidence).
4

Internal Control Over Compliance

The auditor must also report on the entity's internal controls designed to ensure compliance. Any significant deficiencies or material weaknesses identified must be communicated in the report.
5

Schedule of Findings & Questioned Costs

Compliance findings are documented in this schedule, which includes the condition, criteria, cause, effect, and recommendation for each finding. Questioned costs represent expenditures that may need to be returned to the federal agency.
KEY TAKEAWAY
Think of the compliance audit like a construction inspector reviewing a building project funded by a government grant. The grant agreement specifies the type of materials, labor standards, and cost limits (compliance requirements). The inspector doesn't examine every nail—she samples key structural elements (major programs). Her report states whether the builder followed the specifications (opinion on compliance) and whether the builder had a reliable quality-control system in place (internal control over compliance). If she finds violations, she documents them and estimates the cost to fix or return (questioned costs).

Visual Explanation — The Compliance Reporting Framework

The diagram traces the compliance reporting workflow from the initial financial statement audit through major program identification, compliance testing, internal control evaluation, opinion formation, and the two final deliverables—the report on compliance and the report on internal control over compliance—both feeding into the schedule of findings and questioned costs.

As illustrated above, the compliance reporting process is layered atop the financial statement audit. The auditor first completes or is concurrently performing the financial statement audit under generally accepted auditing standards (GAAS). From there, the auditor applies the risk-based approach prescribed by the Uniform Guidance (2 CFR 200) to determine which federal programs qualify as major programs. The twelve types of compliance requirements—detailed in the annual Compliance Supplement published by the OMB—form the criteria against which the auditor evaluates the entity's transactions. Notice that the two reports (compliance and internal control over compliance) are distinct but interconnected: deficiencies in internal control frequently give rise to instances of noncompliance, and vice versa.

How It Works — The Mechanics of Compliance Testing

Major Program Determination

The Uniform Guidance establishes a quantitative and qualitative framework for identifying major programs. The auditor categorizes programs as Type A (larger programs, determined by a sliding-scale dollar threshold) or Type B (smaller programs). Only a subset of Type A and high-risk Type B programs become major programs subject to compliance testing. The dollar thresholds are important for candidates preparing for the AUD section of the CPA exam.

TYPE A PROGRAM THRESHOLD
Type A threshold = max($750,000 ; 0.03 × Total Federal Awards Expended)
When total federal awards expended exceed $25 million, more refined thresholds apply. For total expenditures up to $100 million, the threshold is the greater of $750,000 or 3% of total awards. For expenditures between $100 million and $10 billion, the threshold is $3 million. For expenditures exceeding $10 billion, the threshold is $30 million or 0.3% of total awards.

Materiality in Compliance Auditing

Unlike financial statement audits where materiality is typically set as a percentage of a financial benchmark (e.g., 5% of net income), compliance materiality is assessed at the individual major-program level. The auditor determines the amount of noncompliance that would be material to a particular federal program, typically using total program expenditures as the base. Because federal agencies may view any noncompliance as significant, auditors often apply lower materiality thresholds than they would for financial statement work. There is no universally mandated percentage; professional judgment drives the determination, but many practitioners use benchmarks in the range of 3% to 5% of program expenditures.

COMPLIANCE MATERIALITY (ILLUSTRATIVE)
Materiality_program = Benchmark% × Total Program Expenditures
Where Benchmark% typically ranges from 3% to 5% depending on the nature of the program, prior findings, and risk assessment. Performance materiality (the threshold used for designing tests) is set lower—commonly at 50% to 75% of overall compliance materiality.

The Twelve Types of Compliance Requirements

The Compliance Supplement identifies twelve categories of requirements that may apply to federal programs: (A) Activities Allowed or Unallowed, (B) Allowable Costs/Cost Principles, (C) Cash Management, (D) Reserved, (E) Eligibility, (F) Equipment and Real Property Management, (G) Matching/Level of Effort/Earmarking, (H) Period of Performance, (I) Procurement and Suspension and Debarment, (J) Program Income, (L) Reporting, and (M) Subrecipient Monitoring. Not all twelve apply to every program; the Supplement specifies which requirements are direct and material to each Assistance Listing number (formerly CFDA number). The auditor tests only those compliance requirements that have been identified as direct and material for the specific major program under examination.

Detailed Breakdown — Elements of the Compliance Report

Each numbered section represents a required element of the compliance report. The opinion section (element 2) is the heart of the report, while the purpose paragraph (element 7) restricts distribution—a critical distinction from the general-purpose financial statement audit report.

The compliance report follows a structured format that parallels the financial statement audit report but includes several distinctive features. The opinion section now appears first under the revised AICPA reporting standards, consistent with the clarified auditing standards. Critically, the compliance report includes a restricted-use (purpose) paragraph that limits the report's intended audience to the entity's management, those charged with governance, federal awarding agencies, and pass-through entities. This restriction reflects the specialized nature of the report—it is designed for users who need to assess compliance with specific grant or contractual provisions, not the general investing public.

Comparison of the four types of compliance opinions and their characteristic language
Opinion TypeWhen IssuedKey Language
UnmodifiedEntity complied, in all material respects, with compliance requirements"In our opinion, [Entity] complied, in all material respects, with the types of compliance requirements..."
QualifiedMaterial noncompliance exists but is not pervasive to the program"Except for the noncompliance described in the Basis for Qualified Opinion section..."
AdverseNoncompliance is both material and pervasive to the program"Because of the significance of the matter described in the Basis for Adverse Opinion section, [Entity] did not comply..."
DisclaimerAuditor unable to obtain sufficient appropriate evidence"We were not able to obtain sufficient appropriate audit evidence to provide a basis for an audit opinion..."

Worked Example — Evaluating Compliance and Drafting the Report

Consider the following scenario. You are the senior auditor on the single audit engagement for Riverside County, which expended $42 million in federal awards during the fiscal year ended June 30, 20X4. The county administers programs including Medicaid (Assistance Listing 93.778), Highway Planning and Construction (20.205), and several smaller grants. Your task is to determine major programs, set compliance materiality, test compliance, and formulate the report.

Riverside County Single Audit — Compliance Report
1
Step 1 — Determine the Type A Program ThresholdTotal federal awards expended = $42,000,000. Compute 3% of total: 0.03 × $42,000,000 = $1,260,000. Compare with the $750,000 floor. Because $1,260,000 > $750,000, the Type A threshold is $1,260,000. Any program with expenditures at or above $1,260,000 is classified as Type A.
Type A threshold = $1,260,000
2
Step 2 — Classify Programs as Type A or Type BMedicaid expenditures = $28,000,000 → Type A. Highway Planning expenditures = $9,500,000 → Type A. Community Development Block Grant expenditures = $2,200,000 → Type A. All remaining programs (combined $2,300,000) have individual expenditures below $1,260,000 → Type B.
3 Type A programs identified; remaining are Type B
3
Step 3 — Assess Risk and Select Major ProgramsApply the risk-based approach. Type A programs are presumed to be low-risk unless specific criteria are met (e.g., prior findings, new programs, oversight agency concerns). Medicaid had a finding in the prior year → assessed as high-risk Type A → major program. Highway Planning had no prior issues and is considered low-risk, but at least 40% of total federal awards must be covered by major programs (0.40 × $42M = $16.8M). Medicaid alone covers $28M, exceeding the 40% threshold, but best practice and Uniform Guidance encourage testing additional programs. Highway Planning is selected as the second major program. A high-risk Type B program (SNAP benefits, $800,000) is also selected.
Major programs: Medicaid, Highway Planning, SNAP
4
Step 4 — Set Compliance Materiality and TestFor Medicaid ($28M), the auditor sets compliance materiality at 3% × $28,000,000 = $840,000 and performance materiality at 60% of that = $504,000. During testing of eligibility requirements, the auditor discovers that $620,000 in Medicaid payments were made to individuals who did not meet eligibility criteria. This amount exceeds performance materiality ($504,000) but falls below overall compliance materiality ($840,000). The auditor expands testing and determines the projected noncompliance across the population is approximately $950,000—exceeding the $840,000 materiality threshold.
Projected noncompliance ($950,000) exceeds materiality ($840,000) → material noncompliance
5
Step 5 — Formulate the ReportThe auditor evaluates whether the noncompliance is pervasive to the Medicaid program as a whole. Because it is confined to eligibility (one of twelve compliance requirement types) and does not undermine the program's fundamental operations, the noncompliance is considered material but not pervasive. Therefore, the auditor issues a qualified opinion on compliance for Medicaid. Highway Planning and SNAP receive unmodified opinions because no material noncompliance was found. The report includes a Basis for Qualified Opinion paragraph describing the eligibility noncompliance and references the schedule of findings and questioned costs, where the $950,000 is reported as a questioned cost.
Qualified opinion on Medicaid; Unmodified opinions on Highway Planning and SNAP

Compliance Report vs. Financial Statement Report — Strengths & Limitations

Key differences between the financial statement audit report and the compliance report in a single audit
DimensionFinancial Statement Audit ReportCompliance Report (Single Audit)
Subject MatterFair presentation of financial statements under GAAPCompliance with requirements applicable to each major federal program
CriteriaGAAP (U.S. GAAP, GASB, etc.)Laws, regulations, contract/grant provisions identified in the Compliance Supplement
Materiality BaseEntity-wide financial benchmarks (revenues, assets, net income)Individual program expenditures (materiality set per major program)
DistributionGeneral purpose—available to all stakeholdersRestricted use—entity, federal agencies, and pass-through entities
StandardsGAAS (AU-C sections)GAS (Yellow Book), Uniform Guidance (2 CFR 200), GAAS
Internal Control ReportingDeficiencies communicated in writing; separate report under GASSeparate report on internal control over compliance is required
KEY TAKEAWAY
Think of the financial statement audit report as a health checkup for the entire organization—it tells you whether the patient's vital signs (financial position) are accurately measured. The compliance report, by contrast, is like a drug test conducted for a specific purpose: it evaluates whether the entity followed the specific rules attached to a specific funding source. The financial statement opinion tells the world the numbers are reliable; the compliance opinion tells the grantor the money was spent according to the rules. Different audiences, different criteria, different materiality thresholds—but both require the same rigor of evidence gathering.

Connection to Advanced Theory — Government Auditing Standards & Beyond

The compliance report examined in this lesson exists within a layered hierarchy of professional standards. While the Uniform Guidance prescribes the compliance audit requirements for federal awards, the Government Auditing Standards (commonly known as the Yellow Book) issued by the GAO impose additional reporting requirements that go beyond GAAS. These include expanded internal control reporting, reporting on compliance with provisions of laws and regulations that have a direct and material effect on the financial statements (separate from the single audit compliance report), and heightened independence and continuing professional education standards. Understanding how these layers interact is essential for advanced practice and is tested on the AUD section of the CPA exam.

Comparing the single audit compliance report with Yellow Book compliance reporting at the financial statement level
AspectSingle Audit Compliance ReportYellow Book Compliance Reporting
ScopeCompliance with requirements applicable to each major federal programCompliance with laws and regulations that could have a direct and material effect on the financial statements
Opinion vs. ReportAn explicit opinion on compliance is issuedA report on compliance is issued but typically does not include an opinion—results are reported as findings
Internal ControlSeparate report on internal control over compliance (per Uniform Guidance)Report on internal control over financial reporting, with compliance findings integrated
FilingSubmitted to the Federal Audit Clearinghouse (FAC) as part of the reporting packageProvided to the audited entity and relevant oversight bodies as specified by the engagement

Looking forward, the landscape of compliance reporting continues to evolve. The GAO periodically revises Government Auditing Standards, and the OMB has been updating the Compliance Supplement annually to reflect new federal programs (including those arising from pandemic-era legislation such as the CARES Act and the American Rescue Plan Act). For CPA exam candidates, it is worth noting that the exam tests the conceptual framework and general reporting structure rather than specific program details, making a deep understanding of the principles discussed in this lesson more valuable than memorizing individual Assistance Listing numbers.

📝 CPA Exam Tip
On the AUD section, expect questions that test your ability to distinguish between the Yellow Book compliance report (issued as part of a GAS financial statement audit) and the single audit compliance report (issued under the Uniform Guidance). Remember that the single audit compliance report includes an explicit opinion on compliance per major program, whereas the Yellow Book compliance report at the financial statement level is structured as a findings-based report without an opinion on compliance.

Practice Problems

PROBLEM 1CONCEPTUAL
In a single audit, the auditor issues a report on compliance for each major federal program. Explain the conceptual difference between this compliance report and the report on internal control over compliance. Why does the Uniform Guidance require both?
PROBLEM 2BASIC CALCULATION
A county expended $18,000,000 in total federal awards during the fiscal year. Compute the Type A program threshold. If the county's largest program had expenditures of $12,000,000 and the second-largest had $3,200,000, classify each as Type A or Type B.
PROBLEM 3INTERMEDIATE
During a single audit, you identify noncompliance in the eligibility requirements of a major federal program. Total program expenditures are $15,000,000, compliance materiality was set at 4% ($600,000), and projected noncompliance is $520,000. Additionally, you discover a material weakness in internal control over compliance related to eligibility verification procedures. What type of compliance opinion should you issue, and how should you report the internal control finding?
PROBLEM 4APPLIED
Metro City School District expended $55,000,000 in federal awards across 15 programs. The three largest programs are: Title I ($22,000,000), School Lunch ($18,000,000), and IDEA Special Education ($8,000,000). Title I had compliance findings in the prior two years. The auditor must cover at least 40% of total federal awards as major programs (the entity is not considered low-risk because of the prior findings). Determine the Type A threshold, identify which programs are Type A, and explain which programs you would select as major programs and why.
PROBLEM 5CRITICAL THINKING
Consider a scenario in which an auditor discovers that a federal grantee failed to comply with the cash management requirement (drawing down funds significantly in advance of need) for a major program, and the projected noncompliance clearly exceeds materiality. However, the grantee has since repaid the excess interest earned to the federal government and implemented corrective controls. Should the auditor issue an unmodified opinion because the condition has been corrected, or should the opinion be modified? Discuss the professional standards that guide this decision and evaluate how the subsequent remediation should be reflected in the compliance report.

Lesson Summary

The report on compliance in a single audit provides an explicit opinion on whether the entity complied, in all material respects, with the compliance requirements applicable to each major federal program. The auditor determines major programs using a risk-based approach anchored to the Type A/Type B classification system, tests the twelve types of compliance requirements identified in the Compliance Supplement, and sets materiality at the individual program level. The four opinion types—unmodified, qualified, adverse, and disclaimer—mirror the framework used for financial statement opinions but are applied to compliance rather than GAAP presentation.

Alongside the compliance opinion, the auditor issues a companion report on internal control over compliance and documents all findings in the schedule of findings and questioned costs. The compliance report is restricted-use, limited to the entity, federal awarding agencies, and pass-through entities. It is governed by the Uniform Guidance (2 CFR 200) and Government Auditing Standards (Yellow Book), layered on top of GAAS. For the CPA exam, mastering the structure, required elements, and opinion modification logic of the compliance report is critical to success on the AUD section.

Varsity Tutors • CPA Auditing & Attestation (AUD) • Compliance Reporting — Report On Compliance And Regulatory Requirements