Audit and assurance for government
Your audit and assurance support should do more than just help your government agency maintain compliance. Discover how an effective audit process creates greater trust with constituents, leads to smarter financial decisions and uncovers ways to improve operations.
How we help you
Get a smooth, effective audit process to satisfy regulators, adapt to changing requirements and build confidence in your agency’s operations and results.
Confidently complete financial statement audits
Get Uniform Guidance audit support
Strengthen your internal controls
Add other attestations when needed
Make your audits into organizational assets
Wipfli’s state and local government audit services can help you overcome compliance challenges with support that not only understands the unique needs of government entities but also delivers efficient, committed service.
Explore our audit and assurance government services
Wipfli combines deep audit experience, financial know-how and practicality to provide clients with efficient audit support. We apply a risk-based approach customized to your organization, with procedures focused on your critical issues. We also bring new tools and a depth of knowledge to financial reporting so that we can streamline the process for your internal staff and leverage the time-saving tools of big data.
Wipfli’s team of uniform guidance and single audit specialists work closely with your team to help deliver a smooth audit process. We can support your organization with services including:
- TIF audits
- State single audits
- Federal single audits
Strengthen internal controls at your organization with Wipfli’s internal controls study and fraud risk assessment services. We can help you mitigate the risk of fraud by reviewing your processes and providing practical recommendations for improving them.
Wipfli can provide third-party validation with agreed-upon procedures and other attest services. Our team focuses on streamlining the process, removing doubt and offering validity.
Perspective changes everything.
Receive timely industry developments, regulatory changes and other news impacting your success.
Insights and resources
- Learn More
ARTICLE
What is a single audit and when do you trigger one?
Organizations that receive significant federal grant funding should be aware that they are required to complete an annual assurance review known as a single audit. This process is typically conducted by a third-party CPA and is meant to provide oversight on how federal money is being spent. If you’re new to receiving federal grants or your funding levels have recently increased, you may be surprised to discover that you’ve triggered the single audit requirement. (This was a frequent source of confusion during the COVID-19 pandemic, when organizations claiming CARES Act or ARP funding were often shocked to find out about audit rules after the fact.) Keep reading to learn more about single audits, who is subject to one and how the audit process works. What is a single audit? Each year, the federal government distributes billions of dollars in grant funding or other federal assistance to non-federal entities like nonprofits. But how is that money actually being spent? Enter the single audit. A single audit is an annual assurance process meant to ensure that non-federal entities are following the rules about when and how they use the federal funding they receive. This process is known as a single audit because it allows you to audit all of your federal grant spending at once, even if you received funding from multiple grants or agencies. Single audit rules were initially established by the Single Audit Act of 1984 but have been amended or adjusted since then. What is the purpose of a single audit? If you receive federal grant funding, the federal government may require that you complete a single audit to prove you are spending that funding appropriately. During this process, a third-party auditor will carefully audit your financial statements and organizational activities to assess how federal funds have been used and whether your organization has maintained compliance with rules and regulations regarding federal grant funding. What is the trigger for a single audit? In both 2025 and 2026, non-federal entities that accept $1 million or more in federal assistance must complete an annual single audit. Before 2025, the single audit threshold was $750,000. Single audit rules apply regardless of whether your organization receives federal funds directly or indirectly. When calculating whether you’ve reached $1 million in federal assistance, you must include both cash and non-cash assistance that you’ve received. How often is a single audit required? The federal government requires annual single audits for organizations that reach or exceed the $1 million audit threshold. However, the government does not conduct single audits directly. Instead, organizations typically hire a third-party attest firm to do the audit before reporting the results to the federal government. Uniform Guidance audit requirements Per Uniform Guidance regulations, here are some additional single audit requirements : Additional internal control processes will be needed to ensure compliance for major programs, and any findings will be disclosed in your financial statements Identification of the funds received and the major programs under which the funds were received via a schedule of expenditures of federal awards (SEFA) Identifying programs as either Type A or Type B Knowledge of federal statutes, regulations and terms and conditions of the federal awards Disclosure in your financial statements of any findings and follow up on any prior-year findings Preparation and submission of a data collection form directly to the Federal Audit Clearinghouse at the completion of the audit What is the difference between a single audit and a regular audit? An audit is a rigorous oversight process that assesses the accuracy of an organization’s books. During an audit, an auditor (who is typically a CPA) will review your financial statements using GAAP or another accounting standard, assess your internal controls and test transactions to ensure that your financial position is what you say it is. A regular audit focuses on your organization’s finances and is meant to assure shareholders, clients, partners, potential investors, government organizations and the public that you are accurately reporting your financial condition. Large and mid-sized organizations routinely undergo regular audits, including for-profit businesses or other entities that do not receive any federal grants or other federal assistance. Single audits also assess your compliance with grant funding rules A single audit is a specific type of audit that is broader in scope than a regular audit. In addition to evaluating the accuracy of your financial statements, an auditor conducting a single audit will also assess your compliance with rules and regulations that govern how organizations can use federal assistance or grant funding. In other words, if a regular audit is about whether your books are correct, a single audit also takes a deeper look at what you actually did with the money. This includes areas like allowable costs and activities, matching requirements and cash management procedures. How should you prepare for a single audit? Don’t try to prepare for a single audit without outside guidance. Any organization receiving federal assistance that risks triggering single audit requirements should seek out an attest and advisory firm that specializes in single audit and compliance work. This advisor can help you understand compliance requirements, assess your existing controls and recommend improvements. Crucially, your advisor should also be able to perform a single audit when necessary. How much does a single audit cost? A single audit will typically cost at least $10,000. However, that sum can go significantly higher depending on factors like the size of your organization, whether you are receiving federal funds from more than one grant or whether those funds come with any additional complexities or restrictions. Read more 5 common GAAP violations you should know Fixed asset accounting: Asset capitalizing rules, do's & don'ts Effective strategies for preventing and detecting expense fraud in your organization
- Learn More
ARTICLE
Expense fraud prevention and monitoring
Expense reporting is a common and necessary business practice. It’s also commonly abused and, in extreme cases, used to conduct expense fraud. In the 2024 report by the Association of Certified Fraud Examiners (ACFE), the estimated median loss from expense reimbursement fraud was $33,000. In addition, ACFE findings show that individuals perpetrate such schemes for an average of 18 months to two years before being discovered. This highlights the critical need for robust fraud detection systems and fraud prevention platforms in organizations. When you also consider that nearly every employee within a business can submit expense reports for reimbursements, you begin to further understand the magnitude of this threat and its potential financial impact on organizations. Fraudulent disbursements through expense report fraud can significantly affect a company’s bottom line, making the implementation of effective fraud detection tools and financial services fraud detection crucial. Monitoring the expense reporting process Expense fraud can be difficult to monitor and manage, even for the most sophisticated companies. Internal controls can break down, people get busy. Sometimes the controls are not designed properly in the first place (the process lacks a step for review and approval). Other times, they are not operating properly (someone who is supposed to review dates and the validity of charges isn’t doing so). Layoffs and short-staffed situations in accounting and internal audit departments can mean fewer employees are available to verify expense reports and conduct thorough expense audits. Relying on manual systems introduces further risk for human error or misappropriation, as does a too-high minimum threshold for receipt requirements. Minimum threshold requirements for reimbursement should be as low as $25 or $50, depending on the nature of the business and the types of expenses being reimbursed. Implementing robust expense tracking and fraud detection systems can significantly mitigate these risks. Advanced solutions like Expensify reimbursement and Navan reimbursement platforms can streamline the process while enhancing security. When there is a breakdown in controls, several fraudulent schemes can take hold, leading to substantial financial losses for companies. It’s crucial to be aware of the red flags for expense reimbursement schemes to catch potential fraud early. Fraud detection techniques such as anomaly detection, real-time data analysis and machine learning algorithms can help identify suspicious patterns in expense reports, reducing the risk of false positives in fraud detection. The many tactics of expense fraud Today’s scanners and laser printers have made it easier to fake and alter receipts, leading to an increase in receipt fraud. This underscores the need for rigorous receipt verification processes and methods for detecting fake receipts. Beyond fake receipts, there are numerous examples of expense fraud and ways to cheat an employer through expense account abuse and mischaracterized expenses. These expense reimbursement schemes include: Double billing In this scheme, employees charge something to the corporate credit card for reimbursement and submit a personal expense reimbursement with a receipt attached for the same charge. Or they submit the same charge twice but in different time periods, six months apart for instance. By using automated expense management software, a company can implement controls that will automatically send alerts about duplicate submissions. Reporting more than actual costs A taxi ride, for instance, is only $10 but is submitted in a reimbursement request for $15. Internal expense policies may require receipts only for amounts over $25; therefore, no receipt is available for scrutiny in this case. This is often referred to as padding fraud or overstated expenses. Claiming non-business-related charges It’s not uncommon when employees who are required to travel believe their companies “owe” them for being on the road. They then justify personal or indulgent purchases, like buying sweatshirts for the kids or splurging on an excessively large and expensive dinner. This is a form of travel expense fraud that can be detected through advanced fraud management software and behavioral biometrics analysis. Over-purchasing, then returning The scenario goes like this: An employee buys an abundance of office supplies and submits the purchase for reimbursement but holds onto the receipt. They are reimbursed yet also return the office supplies for a refund or store credit. Falsification of expenses and faked business trip expenses Another common fraud scheme involves purchasing a first-class ticket and then cashing it in for two coach tickets to take a family member or friend along. A similar scheme is falsifying who was present at a business dinner by claiming business associates were present when, in fact, a significant other was present. These fraudulent claims, including falsified claim expense fraud and inflated claims expense fraud, can lead to significant expense reimbursement fraud, impacting a company’s bottom line and highlighting the importance of understanding expense fraud risks. Implementing fraud detection solutions that use behavior analytics platforms and device intelligence can help identify unusual patterns in employee behavior related to expense submissions. Expense policies to help mitigate the risks There are several controls and policies companies can adopt to combat expense fraud, starting with defined travel and expense policies and enforceable ramifications for expense policy violations. A common best practice is a pre-trip approval for all estimated costs, including food and non-flight/lodging costs. This can be facilitated through customizable workflows in fraud prevention software and identity verification solutions. Companies should further take advantage of data analytics and technology by integrating apps with corporate credit cards and having receipts electronically submitted directly from hotels, for example, so they become harder to alter. The same can be done with smartphones that immediately upload receipts to prevent them from being lost or altered, reducing the risk of receipt alteration. These processes can be enhanced through automated data extraction and optical character recognition technologies Other automated expense management systems and spend management tools can be used to integrate corporate card data and allow for quicker reconciliation and reimbursement. This makes it harder to falsify charges, especially when using a mandated corporate card program. Companies can also consider integrating a booking tool with an expensing tool for added checks and balances. Monitoring for fraud detection Monitoring activities are also critical for expense fraud detection. For companies that allow a minimum charge threshold before requiring a receipt, run reports on the travelers with the largest number of below-the-line charges. Think about whether those employees are the heavy travelers, then investigate accordingly. Conduct regular expense audits after the fact. Automated travel and expense reporting software can flag out-of-policy reports, which can be investigated and resolved accordingly. Implementing robust approval workflows, conducting regular compliance checks and providing comprehensive expense fraud training for employees on expense policies are all crucial fraud prevention measures. By combining these strategies with advanced expense fraud prevention technologies, companies can significantly reduce the risk of fictitious expenses, inflated expenses and other forms of expense manipulation. Compliance teams play a crucial role in overseeing these processes and ensuring that expense fraud policies are followed consistently. They can also help identify potential expense fraud schemes and implement measures to prevent them, thereby reducing the cost of fraud. Transaction monitoring and rule-based systems can be employed to automate much of this process while credential intelligence can enhance security measures. Wipfli can help with expense fraud prevention Expense fraud remains a significant challenge for businesses, but with the right combination of policies, technologies and oversight, it’s possible to minimize its occurrence and financial impact. By staying vigilant and employing a multifaceted approach to expense fraud prevention, organizations can protect their bottom line and maintain financial integrity. For more information visit our audit and assurance service page and speak to a professional. Or continue reading on: Understanding variable interest entities (VIEs) in accounting Navigating the NAIC’s revised standards for bond accounting An introduction to share-based compensation
- Learn More
ARTICLE
What nonprofits need to know about emergency Economic Injury Disaster Loans (EIDLs)
As of April 16, the SBA reported that it has exhausted Economic Injury Disaster Loan funding. EIDL applicants who have already submitted their applications will continue to be processed on a first-come, first-served basis. Signed into law on March 27, 2020, the Coronavirus Aid, Relief, and Economic Security Act (CARES Act) contains relief in the form of a loan called the Economic Injury Disaster Loan (EIDL). The CARES Act also provides advances on these loans in the form of a grant of up to $10,000. EIDLs are available to small businesses and nonprofit organizations that have suffered a substantial economic injury as of result of COVID-19. The loans and advances are intended to be used for payroll, rent and mortgage payments, as well as cover increased costs from supply chain disruptions and other expenses arising due to the crisis. Who can apply for an EIDL? A wide range of organizations can benefit from this opportunity, including most private non-profits, 501(c)(19) veterans organizations, faith-based organizations and tribal businesses (sec. 31(b)(2)(c) of Small Business Act) with under 500 employees, that have suffered substantial economic injury as of result of the crisis. An additional requirement to apply for the emergency grant and loans is that the organization must have been in business as of January 31, 2020. Getting into the nitty-gritty EIDL details Before your organization decides to apply, there are some details to be aware of: The CARES Act waives the requirement to seek credit elsewhere before applying for EIDLs. The loans are available based on the applicant’s credit score. There is no need to submit a tax return. There is no collateral necessary for loans less than $25,000. For loans from $25,000-$200,000 a general security interest in business assets maybe used. Applicants can be approved for loans up to $200,000 without a personal guarantee. The maximum loan amount is $2 million. If requesting the advance, the applicant must self-certify on penalty of perjury that it is eligible for an EIDL. The advance must be used for EIDL purposes and should be disbursed within three days of requesting the advance. The loan interest rate for nonprofit organizations is 2.75%, and loans have maturities up to 30 years. Payments on the loan may be deferred for one year; however, interest still accrues during this time period. How does the Paycheck Protection Program factor into EIDLs? If, after applying for an EIDL, the applicant subsequently applies for a Paycheck Protection Program (PPP) loan, the EIDL will be refinanced into its PPP loan, and the advance will reduce the forgivable portion of the PPP. EIDLs are not forgivable except for the $10,000 advance grant. If the EIDL is denied, the $10,000 grant does not have to be returned, but it does need to be spent on EIDL purposes. If your organization is considering applying, you can do so at covid19relief.sba.gov . If you need assistance going over EIDL requirements or considering whether the PPP is a better option for your organization, contact Wipfli. We’ve also put together a COVID-19 resource center to help organizations navigate COVID-19’s impact.
Reach out to our team
We deliver audit and attestation services that go beyond reporting or compliance requirements to help you find opportunities to work more effectively or better serve your constituents. Let's talk about your needs and how we can help.


LET'S CONNECT
Wipfli is ready to help your organization overcome disruption, navigate uncertainty and serve more effectively.
