Preparing for OMB’s Proposed Uniform Guidance Rewrite: Key Audit and Compliance Considerations for Federal Award Recipients
The Basics
- The proposed rewrite of 2 CFR Part 200, aka Uniform Guidance, would significantly change how federal award recipients manage audit, compliance, and documentation responsibilities.
- Although not yet finalized, the proposed rule indicates that recipients should expect greater scrutiny of how compliance judgments are made, documented, and defended.
- In this article, you’ll learn how the proposed changes may impact your organization’s audit and compliance responsibilities — and what steps you can begin taking now to prepare.
______________________________________________________________________________________________
What May Change, When: An Overview of the Proposed Rewrite of 2 CFR Part 200
On May 29, 2026, the Office of Management and Budget (OMB) released a proposed rewrite of 2 CFR Part 200 that would transform Uniform Guidance from a guidance-based framework into a government-wide regulation under §200.110. That transformation would represent the most significant overhaul of Uniform Guidance since its original implementation in 2014, affecting virtually every aspect of federal grant administration, including subrecipient oversight, cost allowability, internal controls, and Single Audit compliance.
The Timeline: As initially proposed, the revisions would apply to new and renewed awards beginning Oct. 1, 2026. However, the Senate Appropriations Continuing Resolution passed on Aug. 8 would delay implementation of those changes to Dec. 11, 2026. As of the date of this publication, the provisions of that Continuing Resolution remain subject to approval and enactment by the House of Representatives.
Focus on Audit & Compliance Implications: Most commentary surrounding the proposed rewrites to 2 CFR Part 200 has focused on administrative and policy changes, including expanded federal oversight, modified award conditions, and broader agency discretion. Those changes are important, but this article focuses on the audit and compliance implications of the proposal.
While individual provisions may change before a final rule is issued, the proposal points to several trends that recipients should begin evaluating today:
- Greater accountability for pass-through entities.
- More rigorous support for cost allowability decisions.
- Less reliance on prescriptive federal control frameworks.
- Increased emphasis on documentation supporting compliance judgments.
- More responsibility being placed on recipients to demonstrate how compliance conclusions were reached.
Uniform Guidance Becomes Regulation
Most federal recipients rarely think about how Uniform Guidance becomes Uniform Guidance. The proposed revisions to §200.110 would alter that process significantly, replacing what has historically been a guidance-based framework with a more direct regulatory structure. That change matters because future OMB revisions could become effective across federal programs without the same agency-by-agency adoption process recipients have historically relied on.
Under the proposed framework, future OMB revisions would automatically apply government-wide without requiring each federal agency to separately adopt the changes.
This matters because several other provisions in the proposal simultaneously create new compliance expectations while placing greater reliance on recipient judgment. In other words, the proposal becomes more regulatory in nature while, in several key areas, becoming less prescriptive about how recipients achieve compliance.
Payment and Eligibility Requirements
Not every provision in the proposal is open to interpretation. Some of the most immediate implementation challenges are likely to come from requirements that are relatively straightforward and procedural.
Unlike the broad concepts found in the current Uniform Guidance, such as “national interest” or “reputational harm,” the proposed rule introduces requirements that auditors can test directly, such as payment justifications, E-Verify compliance, and eligibility verifications. If the proposed rule is finalized, organizations should be ready to demonstrate they can fulfill those requirements.
The proposed rule introduces payment justification requirements for recipients and subrecipients under §200.305. The requirements would apply to both advance payments and reimbursement requests. Recipients would provide payment justifications to federal agencies, while subrecipients would provide justifications to pass-through entities.
The proposal also introduces eligibility verification requirements. States would perform payment verification through Treasury’s Do Not Pay system or a comparable alternative, while recipients and subrecipients would be required to utilize E-Verify for employees and contractors working on federal awards. Federal agencies would also verify payee eligibility through Do Not Pay.
Recipients should already be considering:
- Who will prepare payment justifications.
- Who will review and approve them.
- How supporting documentation will be retained.
- Whether existing HR processes can support E-Verify compliance.
- How compliance requirements will be communicated to subrecipients.
Whether grant management systems can retain evidence that required procedures were actually performed.
Take action: Organizations that establish clear processes around the new payment justification rules, E-Verify, and Do Not Pay should find implementation well within the capabilities of accounting and HR teams already familiar with Single Audit compliance. However, straightforward requirements often leave little room for interpretation, making consistent execution and documentation critical.
Subrecipient Monitoring Is Becoming a Bigger Compliance Risk
For years, many recipients have viewed subrecipient monitoring as an extension of grant administration. The proposed rule suggests OMB may increasingly view it as a core compliance responsibility. That distinction matters because when compliance failures occur downstream, the proposal places more attention on what the pass-through entity knew, what it monitored, and what it documented along the way.
Under the proposed revisions, all downstream relationships would need to be classified as either subawards or contracts under §200.331. The proposal further extends those requirements to internal transfers involving related entities and requires subawards and contracts to be reported through SAM.gov under §200.332. Noncompliance could serve as grounds for termination under §200.340. The proposal also introduces recipient responsibility for ensuring that downstream activities do not create “reputational harm” for either the recipient or the federal government.
For many governments, schools, housing authorities, and nonprofits, the practical challenge is not SAM.gov reporting itself. The more difficult task is identifying every organization receiving federal funds through the recipient and properly classifying those relationships.
Your organization should start by answering the following questions:
- Has every downstream relationship been documented as either a contractor or subrecipient?
- Are housing authorities, component units, water authorities, related organizations, or affiliated nonprofits receiving federal funds through the primary government?
- Are internal transfers being treated appropriately?
- Would monitoring files withstand a more rules-based monitoring Single Audit scrutiny?
- Do appropriate controls exist around reporting subawards in SAM.Gov?
Take action: If your organization has informal procedures that govern subrecipient monitoring, it’s time to put those procedures into a detailed written policy, and to clearly define and document the organization’s approach to risk assessment and monitoring procedures.
Changes in Cost Principles for Federal Grants
When organizations review major federal regulatory changes, they often focus on new compliance requirements. Auditors know that findings frequently arise somewhere else entirely, such as in routine expenditures that would not have been previously considered controversial. The proposed changes to cost principles may ultimately affect far more recipients than many of the higher-profile provisions receiving attention today.
The proposal introduces a new “general activities of government” cost principle under §200.444 and raises questions regarding advertising, public relations, conferences, memberships, subscriptions, and professional activity costs. The proposal also eliminates fixed-amount awards except where expressly authorized by statute. For example:
- A housing authority sending staff to a national housing conference and charging registration fees, travel costs, and lodging to a federal program.
- A local government allocating subscription costs for a grants management platform across multiple federal programs.
- A school district charging outreach and communication efforts to a federal initiative designed to increase community participation.
By past standards, one of those expenditures might not necessarily be unusual. Under the proposed framework, however, expenditures like these may be subject to questioning: How did management determine that those expenditures directly furthered the objectives of the federal award, and where is that conclusion documented? The proposal does not necessarily make these costs unallowable. Instead, it increases the importance of demonstrating the rationale behind the allowability determination.
Take action: Organizations should evaluate whether their existing approval processes require sufficient documentation to support costs charged to federal awards, particularly in the categories specifically addressed by the proposed Uniform Guidance revisions. If the basis for charging a cost to a federal award exists only as an unwritten decision by a grant manager or program administrator, organizations should formalize that rationale through documented review and approval procedures. In an audit environment, undocumented judgments are often difficult to distinguish from unsupported costs.
The Compliance Supplement: No Longer an Annual Update?
Buried among the proposal’s more visible provisions is a change that will impact every Single Audit performed under Uniform Guidance. While this change may not create an immediate implementation burden, it could significantly alter how recipients and auditors identify applicable compliance requirements over time.
That change: The proposal removes the word “annual” from the Compliance Supplement update requirement under §200.513. As a result, uncertainty exists regarding how often high-risk program information and compliance factors would be updated in the future. While this might feel like a relatively minor technical revision, it has substantial implications.
That’s because for decades, the Compliance Supplement has provided a common framework for identifying compliance requirements and performing Single Audits. It has also helped create consistency across auditors, recipients, and federal programs. Going forward, if updates occur less frequently, recipients and auditors may increasingly rely on award terms, agency guidance, Federal Register updates, and management’s own compliance assessments when determining what requirements apply.
That means responsibility for identifying and interpreting compliance requirements may shift closer to the recipient. And whenever responsibility shifts closer to the recipient, documentation becomes more important.
Internal Controls: The Proposal Removes the Frameworks, Not the Responsibility
Perhaps the most interesting compliance paradox in the proposal appears in §200.303. At a time when OMB is proposing more oversight, more monitoring expectations, and more documentation requirements, it is simultaneously proposing to remove Green Book and COSO as required internal control frameworks.
For years, recipients have had a familiar answer when asked how compliance controls were designed: Green Book, COSO, or some variation of the two. Even when organizations did not formally map every control to those frameworks, they provided a common language for discussing risk assessment, monitoring activities, control design, documentation, and oversight.
If the final rule no longer requires Green Book and/or COSO internal control frameworks, recipients may have more flexibility in how they structure their compliance environment, but they may also have greater responsibility for demonstrating why that environment is effective.
Importantly, the removal of those required frameworks should not be interpreted as a reduction in the importance of internal controls. If anything, the opposite may be true. The proposal places more responsibility on recipients to identify changing requirements, evaluate allowability decisions, oversee subrecipients, support payment requests, and document compliance conclusions. Those activities do not occur effectively without a strong control structure behind them.
Take action: As a practical matter, many organizations may continue aligning their processes with Green Book or COSO principles even if those frameworks are no longer required by regulation. The frameworks remain useful because they provide structure around risk assessment, monitoring, information and communication, documentation, and control activities.
Whether the issue involves payment justifications, E-Verify compliance, subrecipient monitoring, cost allowability, or changing federal requirements, recipients will increasingly need evidence not only that they complied but also demonstrating how they determined they were compliant.
Your Takeaway
Most readers will walk away from the proposed Uniform Guidance rewrite focused on payment justifications, E-Verify requirements, SAM.gov reporting, or discretionary grant terminations.
Those provisions deserve attention. But the broader story may be something different.
Across cost allowability, audit guidance, subrecipient monitoring, and internal controls, the proposal consistently shifts responsibility toward the recipient. In several areas, the rule becomes less prescriptive while expectations for accountability become greater. Recipients may be given more flexibility in how they design compliance processes but less flexibility in explaining compliance failures after the fact.
The recipients best positioned for success will not necessarily be those that simply understand the rules. They will be the organizations that can clearly demonstrate the following:
1. How they interpreted those rules
2. How they built controls around those rules
3. How they monitored compliance throughout the award lifecycle
4. How they documented the judgments made along the way.
In the coming years, that ability to demonstrate and defend compliance may become every bit as important as compliance itself.
If you’re struggling to come up with practical solutions, reach out to your Rehmann advisor. We can help your organization with:
- Evaluating payment and eligibility requirements
- Establishing documentation and approvals for changes in cost principles on new and existing grants
- Creating written policies and procedures for subrecipient monitoring requirements
- Assessing internal control documentation, identifying gaps, and recommending practical control activities to support compliance with new or changing requirements.




