Home / Resources / 2 CFR 200.303 explained

Plain-English guide · for small nonprofits

2 CFR 200.303, explained in plain English

Updated August 2026

Five sentences of regulation that get cited in more audit findings than almost anything else in Part 200.

The short version

§200.303 is short, vague, and binding. It says you must establish, document and maintain internal control over the federal award, comply with the rules, monitor your own compliance, act promptly when you find problems, and take reasonable cybersecurity measures to protect personal information.

The whole section, translated

It is five paragraphs. Here is each one, and what it asks of a small organization.

(a) Establish, document and maintain

“Establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.”

Document is the operative word. An organization can have genuinely good habits and still fail this paragraph, because habits are not documentation. If your controls exist only in one person's head, you do not have internal control in the sense the regulation means.

The paragraph adds that these controls should align with the Comptroller General's Standards for Internal Control in the Federal Government, known as the Green Book, or the COSO Internal Control-Integrated Framework. Note the word: should, not must. You are not required to adopt either framework wholesale, which is a relief for a five-person organization. You are expected to be pointed in their direction.

(b) Comply

“Comply with the U.S. Constitution, Federal statutes, regulations, and the terms and conditions of the Federal award.”

Nothing to translate. Worth noting only because it makes your award's terms and conditions a compliance requirement in their own right, so a promise in the agreement is enforceable through this section.

(c) Evaluate and monitor

“Evaluate and monitor the recipient's or subrecipient's compliance with statutes, regulations, and the terms and conditions of Federal awards.”

You check yourself. Not the auditor, not the funder. A quarterly walk through your own requirements with someone writing down what they found satisfies this far better than an annual scramble.

(d) Act promptly

“Take prompt action when instances of noncompliance are identified.”

This is the paragraph that rewards honesty. A problem you found, documented and fixed is evidence that (c) works. The same problem found by an auditor, with no record that you noticed, is evidence that it does not.

(e) Safeguard information

“Take reasonable cybersecurity and other measures to safeguard information including protected personally identifiable information (PII) and other types of information…” including anything the federal agency or pass-through entity designates as sensitive, or that you consider sensitive, consistent with applicable privacy law.

This is the newest duty in the section and the one small nonprofits are least prepared for. If you hold client names, dates of birth, addresses, benefit eligibility or health information in a spreadsheet on a shared drive that everyone can open, that is the gap. “Reasonable” scales with your size, but it is not zero.

What “reasonable” looks like for a small organization

Why it appears in so many findings

Because it is the section an auditor can reach for when something went wrong and no more specific rule quite fits. A late report, a missing determination, an unreconciled payroll charge, a spreadsheet nobody owns: each of those is also an internal control weakness. Strengthening §200.303 is therefore not one project. It is what you get when the rest of your processes are written down.

This is general information, not legal or accounting advice. Federal grant rules change and are applied differently by different agencies and auditors. Check with your auditor, your grant officer, or an attorney before relying on any of it.

The Ember tool for this

Ember Compliance

Ember Compliance keeps every filing deadline in one calendar with reminders weeks out, not days, with unlimited users on every plan.

Common questions

What does 2 CFR 200.303 require?

Recipients and subrecipients must establish, document and maintain effective internal control over the federal award; comply with the Constitution, federal statutes, regulations and award terms; evaluate and monitor their own compliance; take prompt action on noncompliance; and take reasonable cybersecurity and other measures to safeguard information including PII.

Do we have to adopt the COSO framework or the Green Book?

No. 200.303(a) says internal controls should align with the Green Book or COSO. It uses 'should', not 'must', so alignment is expected but wholesale adoption is not required.

Does 200.303 apply to cybersecurity?

Yes. Paragraph (e) requires reasonable cybersecurity and other measures to safeguard information, including protected personally identifiable information and anything the agency, the pass-through entity or you consider sensitive.

Why is 200.303 cited in so many audit findings?

Because most specific failures are also internal control weaknesses. When a more precise requirement does not quite fit, 200.303 usually does.

One calm place for all of it

Ember brings your programs, grants, volunteers, and donors into one place, built only for nonprofits, with a free tier and no credit card.

No credit card · Unlimited users included

Keep reading

Sources: 2 CFR Part 200 (eCFR), §200.303. Verified August 2026. Read the section itself before relying on any summary.