Home / Resources / 2 CFR 200.303 explained
Updated August 2026
Five sentences of regulation that get cited in more audit findings than almost anything else in Part 200.
§200.303 is short, vague, and binding. It says you must establish, document and maintain internal control over the federal award, comply with the rules, monitor your own compliance, act promptly when you find problems, and take reasonable cybersecurity measures to protect personal information.
It is five paragraphs. Here is each one, and what it asks of a small organization.
“Establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award.”
Document is the operative word. An organization can have genuinely good habits and still fail this paragraph, because habits are not documentation. If your controls exist only in one person's head, you do not have internal control in the sense the regulation means.
The paragraph adds that these controls should align with the Comptroller General's Standards for Internal Control in the Federal Government, known as the Green Book, or the COSO Internal Control-Integrated Framework. Note the word: should, not must. You are not required to adopt either framework wholesale, which is a relief for a five-person organization. You are expected to be pointed in their direction.
“Comply with the U.S. Constitution, Federal statutes, regulations, and the terms and conditions of the Federal award.”
Nothing to translate. Worth noting only because it makes your award's terms and conditions a compliance requirement in their own right, so a promise in the agreement is enforceable through this section.
“Evaluate and monitor the recipient's or subrecipient's compliance with statutes, regulations, and the terms and conditions of Federal awards.”
You check yourself. Not the auditor, not the funder. A quarterly walk through your own requirements with someone writing down what they found satisfies this far better than an annual scramble.
“Take prompt action when instances of noncompliance are identified.”
This is the paragraph that rewards honesty. A problem you found, documented and fixed is evidence that (c) works. The same problem found by an auditor, with no record that you noticed, is evidence that it does not.
“Take reasonable cybersecurity and other measures to safeguard information including protected personally identifiable information (PII) and other types of information…” including anything the federal agency or pass-through entity designates as sensitive, or that you consider sensitive, consistent with applicable privacy law.
This is the newest duty in the section and the one small nonprofits are least prepared for. If you hold client names, dates of birth, addresses, benefit eligibility or health information in a spreadsheet on a shared drive that everyone can open, that is the gap. “Reasonable” scales with your size, but it is not zero.
Because it is the section an auditor can reach for when something went wrong and no more specific rule quite fits. A late report, a missing determination, an unreconciled payroll charge, a spreadsheet nobody owns: each of those is also an internal control weakness. Strengthening §200.303 is therefore not one project. It is what you get when the rest of your processes are written down.
This is general information, not legal or accounting advice. Federal grant rules change and are applied differently by different agencies and auditors. Check with your auditor, your grant officer, or an attorney before relying on any of it.
The Ember tool for thisEmber Compliance keeps every filing deadline in one calendar with reminders weeks out, not days, with unlimited users on every plan.
Recipients and subrecipients must establish, document and maintain effective internal control over the federal award; comply with the Constitution, federal statutes, regulations and award terms; evaluate and monitor their own compliance; take prompt action on noncompliance; and take reasonable cybersecurity and other measures to safeguard information including PII.
No. 200.303(a) says internal controls should align with the Green Book or COSO. It uses 'should', not 'must', so alignment is expected but wholesale adoption is not required.
Yes. Paragraph (e) requires reasonable cybersecurity and other measures to safeguard information, including protected personally identifiable information and anything the agency, the pass-through entity or you consider sensitive.
Because most specific failures are also internal control weaknesses. When a more precise requirement does not quite fit, 200.303 usually does.
Ember brings your programs, grants, volunteers, and donors into one place, built only for nonprofits, with a free tier and no credit card.
No credit card · Unlimited users included
Sources: 2 CFR Part 200 (eCFR), §200.303. Verified August 2026. Read the section itself before relying on any summary.