COMPLIANCE RISK SCANNER
Can You Prove Compliance, Or Just Assume It?
Assessment (Score 0–10)
Answer Yes (1) or No (0)
Policies align with current 2 CFR 200 requirements
1
.
Internal controls are documented and consistently followed
2
.
Procurement processes meet federal standards
3
.
Subrecipient monitoring is structured and documented
4
.
Required documentation is complete and accessible
5
.
Grant expenditures are consistently allowable and allocable
6
.
Reporting timelines are consistently met
7
.
Prior audit findings have been fully resolved
8
.
Roles and responsibilities are clearly defined
9
.
Monitoring is proactive—not reactive
10
.
Scoring
8–10 → Controlled Environment
5–7 → Moderate Risk
0–4 → High Exposure
If you cannot prove compliance, you do not have compliance.
Get a Strategic Assessment
COMPLIANCE RISK SCANNER