Research briefs
What the compliance data
actually shows.
We publish numbered briefs covering key compliance requirements for federal grantees. Each brief focuses on a specific area where organizations face the most risk — and what to do about it.
Who we train
The sectors we serve
Regulatory update
EO 14332: What changes and what stays the same
Executive Order 14332, signed August 2025, modifies how federal oversight of grantees works. The core requirements of 2 CFR 200 remain, but reporting structures, risk assessment timelines, and audit resolution processes are changing. Our brief lays out exactly what grantees need to do differently.
All research briefs
An in-depth look at the compliance requirements that carry the most risk for nonprofit, university, and government grantees — with specific documentation gaps and how to address them.
What Executive Order 14332 changes for federal grantees, what remains under 2 CFR 200, and the specific timeline items that need to be on your compliance calendar before the next audit cycle begins.
Subrecipient monitoring under 2 CFR 200.331 through .332 remains one of the most complex compliance requirements. This brief examines the root causes of non-compliance, including risk assessment gaps, monitoring frequency, and documentation requirements.
The procurement provisions in 2 CFR 200.317 through .327 require careful documentation and process controls. This brief maps the key risk points in competitive procurement, sole-source justification, and contract oversight.
Internal controls and financial management: the COSO framework as auditors apply it in single audit fieldwork, and the specific deficiencies that become material weaknesses.
Reporting requirements under 2 CFR 200 Subpart D: understanding your reporting obligations and how to build a compliance calendar that keeps your organization on track.