Grant Compliance
Mission-driven engagements where donor relationships, program delivery, and governance determine impact.
This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.
Inside this journey
-
Engagement Discovery
Understand the buyer's recent audit findings, compliance priorities, stakeholders, and success criteria for remediation and monitoring.
Discovery Questions
Quick snapshot: where this stands for you today
- Tell me briefly your organization's total annual budget and the approximate percent that comes from government grants
- How many federal or state single audits has your organization completed in the last three fiscal years
- Which of these recent audit findings applies to your organization, select all that apply
- Walk me through the discovery that led to your most recent finding, including the auditor's cited sample or transaction
- Who on your team currently owns audit response and corrective action tracking
- Describe what a successful remediation and monitoring outcome would look like to your board and finance leadership
Where it actually hurts: the real cost and risk
- If a similar finding returned next year, what would that do to your ability to win or keep major grant awards
- How has the finding changed your board's or audit committee's expectations for internal controls and reporting cadence
- What direct costs, such as questioned costs, penalties, or extra audit hours, have you already incurred or do you expect from this issue
- Which program areas or funders are most exposed if documentation or cost allocation errors continue
- What single consequence would make you stop new spending, hiring, or program expansion until controls are fixed
How this actually happens, day to day
- Where does time-and-effort documentation typically break down in practice, on payroll entry, activity reporting, cost allocation, or elsewhere
- Which category of system records your personnel activity and can it export time-and-effort reports for auditors
- How often do program staff complete activity reports and how are those reports reviewed and signed off
- Who verifies allowability and allocability of expenses during month-end, program manager, grants manager, finance, or someone else
- Give an example of a transaction or cost pool auditors challenged recently and what documentation you were able to provide
- If you could not produce compliant documentation for 10 percent of payroll costs on a major grant, what would your immediate path be, self-report, restate, dispute, or pause activities
What's getting in the way of a reliable fix
- What's the single internal obstacle that will most delay remediation, staffing, systems, or leadership buy-in
- Who else must sign off on policy or process changes, program director, CFO, executive director, board audit committee, or legal
- How many staff-hours per month can you realistically allocate to evidence collection and process change without outside support
- Are there pending regulatory reviews, funder conditions, or legal holds that could prevent timely access to records
- Which third-party partners, subrecipients, or vendors regularly hold documentation you need and do those agreements include required flow-down clauses
- If a key subrecipient refuses to provide requested documentation, would you pause their payments, continue payments while escalating, or take another route
Other paths you're weighing right now
- Who are you still considering or already working with to solve this, external consultants, a software vendor, or an internal program
- Which current approach feels closest to solving the problem but still falls short, and why
- Has anyone on staff proposed an in-house program to replace outside help and who would lead that effort
- What would have to be true about your incumbent approach for you to keep it rather than change partners
- Which decision factors matter most when choosing a partner, select up to three
- If a partner could demonstrably prevent the next finding on your highest-risk grant within 90 days, what internal approvals would be needed to sign and proceed
Can your organization actually support the work now
- Which systems, named owners, and access paths must be available on day one for remediation and monitoring to proceed
- Do your finance and grants teams have a single source of truth for chart of accounts and cost pools
- How accessible are payroll timesheets, general ledger entries, and subrecipient agreements, centralized digital, scattered, or paper
- Who in IT or finance would be responsible for providing API access or extracts and do they have bandwidth in the next 30 to 45 days
- Are there contractual, privacy, or funder restrictions that require formal data-access agreements before evidence collection
- If we need API access to payroll or grants systems but IT cannot grant it within 45 days, would you accept a staged approach, a partial manual collection, or must the engagement be delayed
What success looks like and how you decide
- What single outcome or metric would make your CFO sign off on this engagement immediately
- How will your board or audit committee measure remediation success, closed findings, policy updates, or evidence of ongoing monitoring
- Which acceptance criteria must be spelled out in the SOW for you to accept the assessment deliverable
- What timeline constraint from funders, audits, or reporting cycles must we meet to be useful to you
- If a pilot demonstrates 100 percent compliant documentation for a sampled payroll period and a corrected procurement file, what would stop you from expanding the program across similar grants
- What's the best way for us to keep your team accountable during implementation, weekly check-ins, shared ticketing, or a governance cadence
- Are you prepared to commit budget and a named project owner within 30 days if the proposed scope matches your acceptance criteria
-
Engagement Agreement
Sign the SOW, fee schedule, and data-access/authorization documents so fieldwork and evidence collection can begin.
Agreement Modules
- Master Services Agreement (MSA)
- Statement of Work (SOW)
- Fee Schedule & Order Form
- Data Access & Evidence Collection Authorization
- Federal Grants Compliance Addendum (2 CFR 200)
-
Assessment Working Sessions
Conduct interviews, policy and record reviews, and sample testing to identify control gaps and prioritized compliance risks.
Working Sessions
- Fieldwork Kickoff and Evidence Inventory
- Control Interviews and Current-State Mapping
- Sample Testing Workshop and Exception Log
- Findings Prioritization and Remediation Draft
- Collect any missing evidence needed to finalize recommendations and close low-risk exceptions.
- A concrete list of additional samples or evidence to close validation gaps is confirmed.
- Deliver supporting documentation for each exceptioned sample as identified in the exception log.
- Run and provide expanded extracts for any populations selected for additional sampling.
- Update the sample results file with any newly discovered evidence and resubmit for review.
- Recap validated evidence and exception log
- Top findings are prioritized and a remediation sequencing decision is documented.
- Corrective actions, estimated effort, and recommended monitoring cadence are assigned to each prioritized finding.
- A short list of immediate corrective actions that require rapid attention is identified.
- Produce the draft prioritized findings document with root causes, recommended corrective actions, estimated effort, and monitoring cadence.
- Assign role-based owners and target dates for each prioritized remediation task.
- Schedule the first follow-up monitoring checkpoint and define required evidence for that checkpoint.
- Confirm scope, success criteria, and timeline
- A signed fieldwork plan with scope, timeline, and checkpoints is accepted.
- Complete evidence inventory is documented with access method for each item.
- Sampling frames and test methodology are approved and ready to execute.
- Deliver the evidence inventory spreadsheet with locations and access permissions for each document set listed during the session.
- Provide requested system extracts covering the agreed population periods in the specified format.
- Share calendar availability and contact details for each named interview participant.
- Confirm any data access constraints or redaction requirements that will affect sample selection.
- Process walkthroughs by control area
- Validated current-state control maps for each control area are documented.
- Initial prioritized list of suspected control gaps with root-cause hypotheses is produced.
- Concrete evidence requests for validating each suspected gap are agreed.
- Provide the evidence items listed during the session for each suspected gap, organized by control area and date range.
- Export and deliver system logs, approval workflows, and relevant transaction records tied to the documented control points.
- Supply policy and procedure documents, recent training materials, and any prior corrective action plans referenced during the walkthroughs.
- Review sampling methodology and sample list
- A published sample test results file with each sample marked pass or exception is agreed.
- An exception log with preliminary risk ratings and root-cause notes is produced.
- Probe control design and operating evidence
- Examine each sample and supporting evidence
- Present draft findings with corrective recommendations
- Identify stakeholders and evidence access paths
- Prioritize findings by risk and remediation urgency
- Agree sampling frames and methodology
- Classify exceptions and assign preliminary risk levels
- Surface discrepancies and immediate risk indicators
- Agree additional testing or documentation required
- Agree next steps and monitoring cadence
- Agree evidence needed to validate each suspected gap
- Finalize fieldwork schedule and deliverables
-
Assessment Deliverable
Provide a decision-ready assessment report with findings, root causes, a corrective action plan, and recommended monitoring cadence.
- success_criteria
- stakeholders
- gaps
- current_state
- decision_readiness
- desired_state
- current_state
- success_criteria
- decision_readiness
- stakeholders
- desired_state
- gaps
- stakeholders
- current_state
- gaps
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
-
Solution Scope
Define the remediation and ongoing monitoring scope: deliverables, responsibilities, timelines, training, and acceptance criteria.
Scope Configuration
- Create 2 CFR 200-compliant procurement policies
- Draft subrecipient agreements with required flow-downs
- Develop and document cost allocation schedules
- Implement time-and-effort reporting system
- Set up personnel activity reporting templates and payroll mapping
- Migrate grant files to centralized retention repository
- Configure compliance monitoring dashboard
- Perform subrecipient monitoring visits and documentation
- Prepare audit-ready single audit workpapers and schedules
- Remediate single audit findings and draft corrective responses
- Train staff on allowable costs and procurement requirements
- Implement procurement threshold controls and procurement logs
- Conduct quarterly compliance monitoring and issue tracking
Scope Questions
Create 2 CFR 200-compliant procurement policies
- Do you currently have written procurement policies aligned to 2 CFR 200 subpart D and your state single audit requirements?
- Which procurement thresholds do you apply today for micro-purchases, small purchases, and formal procurements, and do thresholds vary by federal funder?
- How are vendor selections documented for purchases above the federal micro-purchase threshold (for example, vendor quotes, written justifications, procurement logs)?
- Who is authorized to approve procurements at each threshold and do you need an approval matrix defined?
- List any state-specific procurement clauses or preferred vendor rules that must be included in your policy (for example local vendor preferences or set-asides).
Draft subrecipient agreements with required flow-downs
- Describe the typical subrecipient relationship: average award size, number of active subawards, and whether awards are cost-reimbursable or fixed-price.
- Provide any existing subaward templates and indicate whether they already contain 2 CFR 200 flow-down clauses (procurement, audit access, records retention).
- Identify which federal funders and CFDA numbers commonly fund your subawards and whether funder-specific terms must be flowed down.
- List the monitoring deliverables you expect from subrecipients (for example single audit reports, financial reports, procurement files) and their required frequency.
- Indicate which monitoring activities you want to retain versus activities you want us to perform (desk review, site visit, sample testing).
Develop and document cost allocation schedules
- Provide the number and names of existing cost pools (for example program direct, administrative, indirect) and the allocation bases currently used.
- Identify which GL account ranges and fund segments must be mapped into each allocation schedule (for example salary expense accounts, rent GL ranges, utility GL codes).
- Specify whether you use the de minimis 10% of modified total direct costs or a negotiated indirect cost rate agreement (NICRA) and supply the current rate or NICRA documentation if available.
- Who maintains your payroll and fringe benefit rates and can you provide a representative payroll register for sample mapping?
- Note any specific cost pools that should be excluded as unallowable under 2 CFR 200 (for example lobbying, entertainment) that must not be allocated.
Implement time-and-effort reporting system
- Do you have an existing payroll or timekeeping system that must integrate with personnel activity reports and can export payroll distributions?
- Specify the reporting cadence you require for effort certification (monthly, per pay period, continuous certification) and whether retrospective adjustments are acceptable.
- What acceptance criteria will confirm the time-and-effort reporting system is implemented successfully (for example automated PAR generation, payroll mapping for 95% of staff, integration test pass)?
- Who in your organization will certify personnel activity reports and do you require role-based electronic signatures or paper signatures?
- Describe how payroll cost objects (employee ID, GL account, program code) should map to effort percentages and whether fringe and overtime are mapped separately.
Set up personnel activity reporting templates and payroll mapping
- Do you require PAR templates for all employee categories and approximately how many employees will require PARs (program staff, shared admin, executives)?
- Specify the mandatory fields on PAR templates (for example employee ID, payroll period, percent effort by award, certifier name) and any dropdown picklists needed.
- Indicate whether payroll-to-PAR mapping must include all pay components (regular, overtime, fringe) and whether you expect automated reconciliation.
- Estimate the percentage of staff whose payroll records already include clear fund coding that can be mapped automatically.
- Attach any sample PAR templates or payroll extracts you want us to use as the basis for template design.
Migrate grant files to centralized retention repository
- Do you need migration of active awards only or both active and closed awards, and how many award folders in total need migration?
- Which document types must be preserved and searchable in the repository (for example contracts, invoices, timesheets, procurement files, subrecipient reports)?
- Describe your required retention schedule per funder or award (for example 3 years after closeout for state funds, 3 years after submission of final expenditure report for federal) and any exceptions.
- Identify naming and metadata conventions you require for migrated folders (for example award ID, CFDA number, fiscal year) to support auditor requests.
- Specify access controls and audit-log requirements for the repository (who can view, who can edit, whether deletion is logged).
Configure compliance monitoring dashboard
- Indicate which KPIs the dashboard must surface (missing PARs, overdue procurements, outstanding subrecipient issues, questioned costs) and which should be shown on the landing view.
- Specify the primary data sources for dashboard widgets (payroll exports, general ledger extracts, repository documents, subrecipient portal) and whether API access is available.
- What acceptance criteria will validate the dashboard (for example data refresh interval, coverage of all open awards, 95% reconciliation to GL, user permissioning in place)?
- Who should receive automated alerts from the dashboard for high-priority items and what escalation path do you require (for example program manager, CFO, audit committee)?
- Describe the visualization and export requirements (for example trend chart for questioned costs, heatmap by program, PDF export for audit committee).
Perform subrecipient monitoring visits and documentation
- Do you anticipate on-site monitoring visits for subrecipients and if so how many visits per year and for which award size thresholds?
- Provide the list of documents you expect to collect from subrecipients for monitoring (for example single audit reports, procurement files, payroll records) and acceptable file formats.
- Identify the sampling method you prefer for transaction testing (statistical, judgmental, dollar-based) and any minimum sample sizes used previously.
- Who will lead or support monitoring visits from your side (grants manager, program director, finance staff) and are travel approvals required?
- Describe the deliverables you expect after each monitoring event (monitoring memo, corrective action plan, follow-up schedule) and the target turnaround time for each deliverable.
Prepare audit-ready single audit workpapers and schedules
- When do your fiscal year end dates occur and which single audit periods must the workpapers cover?
- What acceptance criteria will confirm the workpapers are audit-ready (for example reconciled schedules to GL, supporting invoices for sampled costs, indexed exhibit cross-reference)?
- Identify which federal programs and CFDA numbers require detailed schedules and whether any program is considered high-risk by your auditors.
- Specify whether workpapers should follow auditors' preferred templates (for example AICPA single audit guidance format) or your internal template.
- Detail any prior-year audit findings that must be addressed in the workpapers and the documents you expect to use to demonstrate remediation.
Remediate single audit findings and draft corrective responses
- List the active audit findings to remediate, including finding ID, finding text, fiscal year, and assigned risk level.
- Specify target owners and completion dates for each corrective action and whether remediation documentation will be uploaded to the centralized repository.
- Which corrective actions require policy changes versus operational fixes and which will need board or audit committee approval?
- Indicate the root-cause analysis format you prefer for each finding (for example narrative, fishbone diagram, 5-whys).
- Describe how you prefer to document closure of findings (for example retest results, management attestation, auditor confirmation) and any timelines for follow-up testing.
Train staff on allowable costs and procurement requirements
- Which staff groups should attend training (program managers, grants managers, finance staff, executive leadership, board audit committee) and approximate headcounts for each group?
- Select preferred training formats and durations (live virtual workshop, on-site session, recorded module, job aid) and indicate any scheduling constraints.
- Indicate any funder-specific topics to include in training (for example HHS allowable costs, HUD procurement nuances, DOL cost allocation), and rank them by priority.
- Describe how you want training effectiveness measured (post-training quiz, document spot-checks, reduction in audit findings) and target benchmarks.
- Who will coordinate scheduling and attendance tracking and do you require certificates of completion for participants?
Implement procurement threshold controls and procurement logs
- Which procurement thresholds do you currently enforce for micro-purchases, simplified acquisition, and sealed bidding and do any thresholds differ by funder?
- Do you maintain procurement logs today and what minimum fields must be captured (for example vendor, award ID, amount, procurement method, justification)?
- Specify whether procurement approvals and justifications must be recorded in your ERP, saved in the repository, or both, and the preferred evidence type (signed form, email chain).
- Identify any internal thresholds set lower than federal minima and the reason for the lower thresholds.
- Describe automated procurement controls you want configured (approval flags, duplicate vendor alerts, threshold blocking) and any integration requirements.
-
Implementation
Operationalize corrective actions and monitoring with readiness checks, configuration, and execution.
-
Pre-Implementation Readiness
Confirm named owners, data access, reporting sources, and timeline constraints required to execute remediation and monitoring.
Pre-Deployment Questions
Environment and access
- Which deployment environments will be in-scope for implementation (select all that apply)?
- Is the production environment available now for vendor access and implementation work? (so we can schedule work and access windows)
- If the production environment is not ready, what is the earliest date it will be available for implementation activities? (so we can lock the cutover window)
Data and configuration
- Which data sources/systems are in-scope for remediation and ongoing monitoring? Select all that apply (use categories, not URLs).
- Are source-owners (the person/team who approves mappings and provides extracts) identified for each in-scope data source? (this determines who we coordinate with for data delivery)
- If any data source lacks an identified owner, list the system categories or site names missing owners (so we can assign outreach).
People and ownership
- Designate the named implementation coordinator (role and person) who will approve changes, sign off on milestones, and schedule staff for training.
- Who are the primary operational owners for ongoing monitoring? Select all roles that apply (we'll use this to assign dashboards and alerts).
Timing and constraints
- Are there blackout windows, audit periods, or compliance gates during which system changes or data collection cannot occur? (if yes, we'll plan around these dates)
- If there are blackout windows or other hard constraints, list those dates or describe the constraint (so we can build the project schedule around them).
- What is the target go-live or monitoring commencement date for remediation and ongoing monitoring? (select the closest option or specify a target date below)
- If you selected 'Target date specified' or have additional timing notes, enter the date or details here (this will become the baseline for the deployment timeline).
-
Configuration & Integrations
Lock configuration values, integration endpoints, user roles, and time-and-effort reporting settings the implementation will use.
Configuration Details
Environments & Endpoints
- Select the deployment region for the platform instance (Default: US East).
- Enter the platform instance name to provision (format: lowercase-alphanumeric, max 24 characters; Default: buyer-prod).
- Primary finance/accounting system type that the platform will integrate with (select the single best match).
- Enter your finance/accounting system API base URL (format: https://... ). If none, enter 'N/A'.
Options & Features
- Enable the automated subrecipient monitoring module? (this turns on automated sampling and reminder workflows).
- Default monitoring review cadence (Default: Quarterly).
- Enable time-and-effort automated reminders to employees and managers (email/task reminders tied to missing records)?
Mappings & Roles
- Platform role name to map to the buyer role for 'Compliance Admin' (enter the exact role label your organization uses).
- Platform role name to map to the buyer role for 'Program Manager' (enter the exact role label your organization uses).
- Enter the credential owner role name who will provide non-secret identifiers (client IDs, integration user names) and coordinate secret exchange at kickoff (e.g., 'IT Security Manager').
- Which secure channel will you use to exchange credential secrets at kickoff? (we will NOT accept raw secrets in this form; select the secure channel and the deployment team will coordinate the exchange).
Time-and-Effort Reporting & Policies
- Time-and-effort rounding policy to apply to reported time entries (Default: 15 minutes).
- Required supporting document types for time-and-effort records (select all that apply).
- Time-and-effort record retention period in years (enter numeric value; Default: 7).
-
Implementation Execution
Execute the remediation plan, implement controls and monitoring dashboards, deliver staff training, and hand off operational ownership.
-
-
Success
Review outcomes against success criteria, run recurring monitoring reviews, and track issues and enhancements through a shared ticket channel.
Success Reviews
- Go-live Health Check (weeks 1-4)
- First Measurement Review (weeks 4-10)
- Acceptance Gate Review (around day 90)
- Quarterly Operational Review
Issues & Enhancements
- Publish the quarterly KPI dashboard and a short narrative summarizing progress against Solution Scope targets.
- Formal acceptance decision recorded for each numeric criterion in Solution Scope.
- Remediation plan with owners and resolution dates recorded for any failed criteria.
- Schedule follow-up checkpoints to verify remediation items are closed within agreed timelines.
- Publish the acceptance decision document with criterion-level pass/fail results and the buyer's named signatory recorded.
- Open remediation tickets for failed criteria with firm resolution dates and verification steps.
- Schedule required follow-up reviews to confirm remediation completion before final close-out.
- KPIs and trend review
- Reduce the number of open high-priority corrective actions and tickets quarter over quarter.
- Ensure monitoring coverage meets or improves toward the Solution Scope targets and evidence retrieval time is within the agreed threshold.
- Agree which enhancement requests will be scheduled in the next quarter and which will be deferred.
- Close or assign owners and resolution dates for all high-priority tickets discussed, and update the shared ticket channel accordingly.
- Schedule any agreed refresher training sessions and publish attendee lists and agendas.
- Re-confirm success criteria and owner roster
- Deployment and evidence access validated, with no critical data integrity issues remaining.
- Named owner confirmed for each acceptance criterion and monitoring stream.
- Critical blockers logged with owners and target resolution dates.
- Publish a go-live summary listing validated endpoints, user access status, and any remaining critical issues.
- Archive legacy system data or confirm it will be retained read-only and accessible for 90 days, then document the retention plan.
- Open tickets for each critical blocker with a target resolution date and escalation path.
- Present initial KPI data vs targets
- Agree a corrective action plan for any KPI shortfalls with named owners and deadlines.
- Confirm timeline to the 90-day acceptance gate and prerequisites for the acceptance decision.
- Identify any integration or data fixes required to improve evidence retrieval time and monitoring coverage.
- Publish the first-period KPI report showing corrective action completion rate and percent compliant time-and-effort records versus Solution Scope targets.
- Create remediation tickets for each root cause identified, with target resolution dates tied to the acceptance gate timeline.
- Enable or correct any missing data integrations that prevent automated evidence collection.
- Restate acceptance criteria and numeric targets
- Deployment and data-access validation
- Present outcome data against each acceptance criterion
- Ticket channel triage and persistent issues
- Diagnose root causes for any gaps
- Enhancement backlog and small-scope adjustments
- Agree corrective actions and target dates
- Early adoption signals and user onboarding status
- Document formal acceptance decision
- Review monitoring coverage and evidence retrieval time
- Agree remediation plan for any failed criteria
- Training and process refresh
- Open issues and immediate blockers
- Legacy system wind-down check