Tribes operate in a uniquely complex audit environment. Wipfli provides the internal audit, compliance assurance, and financial optimization services you need from a team that knows your industry

2026 Indian gaming report
2026 Indian gaming report

 Get an in-depth look at the tribal gaming industry’s financial health and cost dynamics. See where you stand. 

How we help you

As federal funding and regulations continue to evolve, leaders need tribal audit services that can help them not only build trust and protect tribal resources but also improve sustainability. 

Increase transparency and demonstrate responsible management of tribal resources.

Streamline the tribal financial auditing process with a team that knows your industry and operations.

Strengthen your organization by staying ahead of new regulations and funding opportunities.

Gain better visibility into operational risk and implement stronger procedures and controls.

Turn audits into opportunities for meaningful organizational improvements.

More streamlined, valuable audit service 

Having served tribal organizations for decades, Wipfli understands your unique audit requirements. Our relationship-driven approach respects your timelines and minimizes disruption while delivering valuable insights. 

Explore our services

Insights and resources

  • Three professionals collaborating around a laptop.

    ARTICLE

    Why credit card audits are a growing priority for tribal casinos

    Word is spreading that the National Indian Gaming Commission (NIGC) is expecting tribal casinos to focus more on preventing credit card fraud. This is an opportune time for your casino leaders to prioritize strengthening internal controls and establishing audit best practices to reduce fraud and protect tribal assets. Given the regulations and risks tribal casinos face, employee credit card misuse may be overlooked. But even small, unauthorized purchases can accumulate into significant losses over time. And every dollar lost to fraud is a dollar that cannot be used to support tribal programs, services and community development. Learn how your gaming enterprise can implement credit card policies and procedures, along with audit processes, to better prevent and detect card misuse and ultimately avoid financial losses and reputational damage. Why are tribal casinos vulnerable to credit card fraud? Tribal casinos are unique businesses. Your daily operations may create gaps for detecting credit card misuse that aren’t found in other industries you may have worked in. Here are four reasons why: 1. High transaction volume Chances are that your casino sees a high volume of transactions on its company credit card account. For larger organizations, it could easily number in the hundreds each month. With so many purchases, it’s easy for smaller fraudulent charges to go unnoticed. Employees who misuse a company card are likely intentional about keeping the dollar amounts of their purchases small to avoid triggering any automatic approval or review processes your organization may have in place. 2. Limited accounting resources Many tribal casinos operate with lean accounting teams responsible for payments, reconciliations, payroll and compliance tasks. Frequent turnover is another challenge. New accounting employees may still be learning internal processes and may not recognize unusual transactions. Staffing challenges make it difficult to closely review every credit card transaction, increasing the likelihood that misuse goes undetected. 3. Focus on regulatory compliance Most tribal internal audit teams devote significant attention to gaming operations, Tribal Gaming Regulatory Authority requirements and compliance with Minimum Internal Control Standards. Because business credit card usage is generally outside the scope of many traditional gaming audits, it can fall through the cracks. 4. Tight-knit communities Many tribal casinos are located in small rural communities. In these close-knit communities, employees may have known each other for a long time, be neighbors or even be related. These relationships can make individuals less likely to report suspicious activity, allowing misuse to persist longer. What are common fraudulent charges to watch for? Employee credit card abuse often does not involve extravagant purchases. Instead, it often consists of transactions that can appear business-related at first glance. Travel-related expenses : Nonbusiness purchases of gas, hotels and meals are common examples of fraudulent activity. It can be difficult to decipher legitimate travel expenses from fraudulent ones. For example, if an employee charges a hotel room but cannot demonstrate attendance at a conference, training event or business meeting, the transaction deserves additional scrutiny. Personal purchases : Clothing, accessories and other retail items without a clear business purpose. These can be purchases that are easy to overlook. “Business” meals or entertainment : Personal dining expenses and other outings can easily be disguised as business activities. For business meal and outing expenses, information about the attendees and the event’s purpose should be required. What is the impact of credit card fraud on tribal casinos? Credit card fraud is money being stolen from your organization, but the impact can be more than just financial. Here are four more impacts on your business and tribe: 1. Financial loss adds up quickly Low-dollar, high-frequency transactions can accumulate into material losses over time — diverting funds directly from casino operations and tribal revenues. The most obvious impact is the direct loss of tribal funds. Because many external audits focus on materiality thresholds, fraudsters with access to a company card will focus on small purchases. But $25 here and $50 there will add up to substantial losses over time. 2. Damaged workplace culture It takes trust for casino leaders to give an employee access to a company credit card. When that trust is broken, leadership will naturally become more suspicious of its staff. When employees discover that coworkers have been abusing company resources, morale often suffers. Employees may begin questioning the overall quality of your operation, leading to a loss of trust and respect. If you discover that an employee has been misusing a card, it will likely result in termination. Staffing is a challenge for many tribal casinos and abrupt departures only make the problem worse. 3. Reputational harm in your community Tribal casinos are often a prominent amenity in their community. If employees are stealing from you, word will likely spread quickly. Community members may take this as evidence that leadership is asleep behind the wheel. This will not only damage the casino’s reputation, but potentially the entire tribal government’s reputation as well. 4. Reduced benefits to tribal members Your casino has a mission to serve its tribe. Profits are often used to support tribal members through programs such as: Healthcare services Housing projects Educational programs Workforce development Essential services like police and fire Elder services Cultural preservation When funds are misused, those resources are no longer available to benefit tribal members. Protecting corporate credit card accounts is ultimately about protecting the tribe’s ability to invest in its people. What controls can tribal casinos implement to prevent credit card abuse? You need to put strong guardrails in place to prevent credit card fraud. Well-defined policies and procedures will make it harder for fraudulent purchases to occur and easier to spot suspect activity. Key controls to implement include: Preapproval requirements : Require authorization for all credit card purchases, especially above defined thresholds. Spending limits and thresholds : Set appropriate limits and require additional approvals for higher-dollar transactions. Limits can vary for individual employees depending on their responsibilities. Mandatory supporting documentation : Require receipts or invoices for every transaction, with a clearly documented business purpose. Other documentation to collect includes conference registrations and travel itineraries. Clear usage policies : Define exactly what items and services can be bought with a company card and what items are prohibited. Provide your staff with training on the approval procedures and documentation requirements. Limit card access : Only issue cards to employees whose job responsibilities require them. Maintaining a smaller pool of cardholders reduces risk and simplifies oversight. What are effective credit card auditing and monitoring policies? Having strong controls in place is an important starting point. But to prevent fraud from going undetected, you need effective auditing and monitoring procedures to help ensure your controls are working. Consider implementing these four controls: 1. Frequent audits Frequent internal audits are far more effective than reactive investigations. Regular audits allow organizations to identify issues early, reducing risk and proactively protecting tribal assets. Audits can catch more than fraud. They can also detect other unwanted charges, such as auto-renewals and automatic bill payments for services your casino no longer wants or uses. 2. Review individual transactions Auditors should pull credit card statements and examine line-item purchases — not just summary-level data. Sampling should include both high and low-dollar transactions. Be sure to cross-check purchases with approval and business purpose documents. 3. Independent auditors and segregation of duties Independent oversight is essential for identifying irregularities. The people auditing credit card activity cannot be the same people using the credit cards. Auditors must be independent of the employees and departments they review. Proper segregation of duties increases the likelihood of objective evaluations and reduces the prospect of collusion. 4. Monitor trends and anomalies Implement a credit card monitoring program to improve your odds of detecting behavioral changes sooner. Establish baselines and track changes over time. Accounting departments should trigger an investigation into any of the following activities: Sudden increases in spending Higher transaction counts Frequent purchases from unusual vendors or retailers Recurring expenses that lack documentation Trend analysis can help identify emerging problems before they become significant losses. Read more Physical penetration testing is the missing layer for stronger cybersecurity Tribal gaming trends: What’s top of mind for gaming leaders in spring 2026? Tribal leaders are running out of time to qualify for two clean energy tax incentives

  • NP-What is a single audit and when do you trigger one?

    ARTICLE

    What is a single audit and when do you trigger one?

    Organizations that receive significant federal grant funding should be aware that they are required to complete an annual assurance review known as a single audit. This process is typically conducted by a third-party CPA and is meant to provide oversight on how federal money is being spent. If you’re new to receiving federal grants or your funding levels have recently increased, you may be surprised to discover that you’ve triggered the single audit requirement. (This was a frequent source of confusion during the COVID-19 pandemic, when organizations claiming CARES Act or ARP funding were often shocked to find out about audit rules after the fact.) Keep reading to learn more about single audits, who is subject to one and how the audit process works. What is a single audit? Each year, the federal government distributes billions of dollars in grant funding or other federal assistance to non-federal entities like nonprofits. But how is that money actually being spent? Enter the single audit. A single audit is an annual assurance process meant to ensure that non-federal entities are following the rules about when and how they use the federal funding they receive. This process is known as a single audit because it allows you to audit all of your federal grant spending at once, even if you received funding from multiple grants or agencies. Single audit rules were initially established by the Single Audit Act of 1984 but have been amended or adjusted since then. What is the purpose of a single audit? If you receive federal grant funding, the federal government may require that you complete a single audit to prove you are spending that funding appropriately. During this process, a third-party auditor will carefully audit your financial statements and organizational activities to assess how federal funds have been used and whether your organization has maintained compliance with rules and regulations regarding federal grant funding. What is the trigger for a single audit? In both 2025 and 2026, non-federal entities that accept $1 million or more in federal assistance must complete an annual single audit. Before 2025, the single audit threshold was $750,000. Single audit rules apply regardless of whether your organization receives federal funds directly or indirectly. When calculating whether you’ve reached $1 million in federal assistance, you must include both cash and non-cash assistance that you’ve received. How often is a single audit required? The federal government requires annual single audits for organizations that reach or exceed the $1 million audit threshold. However, the government does not conduct single audits directly. Instead, organizations typically hire a third-party attest firm to do the audit before reporting the results to the federal government. Uniform Guidance audit requirements Per Uniform Guidance regulations, here are some additional single audit requirements : Additional internal control processes will be needed to ensure compliance for major programs, and any findings will be disclosed in your financial statements Identification of the funds received and the major programs under which the funds were received via a schedule of expenditures of federal awards (SEFA) Identifying programs as either Type A or Type B Knowledge of federal statutes, regulations and terms and conditions of the federal awards Disclosure in your financial statements of any findings and follow up on any prior-year findings Preparation and submission of a data collection form directly to the Federal Audit Clearinghouse at the completion of the audit What is the difference between a single audit and a regular audit? An audit is a rigorous oversight process that assesses the accuracy of an organization’s books. During an audit, an auditor (who is typically a CPA) will review your financial statements using GAAP or another accounting standard, assess your internal controls and test transactions to ensure that your financial position is what you say it is. A regular audit focuses on your organization’s finances and is meant to assure shareholders, clients, partners, potential investors, government organizations and the public that you are accurately reporting your financial condition. Large and mid-sized organizations routinely undergo regular audits, including for-profit businesses or other entities that do not receive any federal grants or other federal assistance. Single audits also assess your compliance with grant funding rules A single audit is a specific type of audit that is broader in scope than a regular audit. In addition to evaluating the accuracy of your financial statements, an auditor conducting a single audit will also assess your compliance with rules and regulations that govern how organizations can use federal assistance or grant funding. In other words, if a regular audit is about whether your books are correct, a single audit also takes a deeper look at what you actually did with the money. This includes areas like allowable costs and activities, matching requirements and cash management procedures. How should you prepare for a single audit? Don’t try to prepare for a single audit without outside guidance. Any organization receiving federal assistance that risks triggering single audit requirements should seek out an attest and advisory firm that specializes in single audit and compliance work. This advisor can help you understand compliance requirements, assess your existing controls and recommend improvements. Crucially, your advisor should also be able to perform a single audit when necessary. How much does a single audit cost? A single audit will typically cost at least $10,000. However, that sum can go significantly higher depending on factors like the size of your organization, whether you are receiving federal funds from more than one grant or whether those funds come with any additional complexities or restrictions. Read more 5 common GAAP violations you should know Fixed asset accounting: Asset capitalizing rules, do's & don'ts Effective strategies for preventing and detecting expense fraud in your organization

  • TR-AA-Upcoming deadlines for tribal State and Local Fiscal Recovery Funds

    ARTICLE

    Upcoming deadlines for tribal State and Local Fiscal Recovery Funds

    March 29 update to article: On March 27, 2024, the U.S. Treasury released an update extending the April 30, 2024, reporting deadline for administrative costs estimates. The notice stated: “As a reminder, recipients are considered to have incurred an obligation by December 31, 2024, with respect to a requirement under federal law or regulation or a provision of the SLFRF award terms and conditions to which the recipient becomes subject as a result of receiving or expending SLFRF funds. Recipients may submit to Treasury an estimate of SLFRF funds that it will use to cover such costs. Recipients are not required to submit estimates for all administrative costs associated with their projects; rather, they must submit an estimate if they want to cover such costs using SLFRF funds that they would otherwise have to return to Treasury after 2024 as unobligated. Treasury is extending the deadline for recipients to report this estimate of costs to meet legal and administrative requirements to July 31, 2024, for quarterly reporters, or April 30, 2025, for annual reporters . Previously, the deadline was April 30, 2024.” Original article: The U.S. Treasury has released the Obligation Interim Final Rule (IFR) effective November 2023. The IFR is a new regulation issued by the U.S. Treasury that affects how tribal governments can use the State and Local Fiscal Recovery Funds (SLFRF) they received from the American Rescue Plan Act. The IRF addresses the definition of an “obligation” in regard to spending SLFRF, as well as certain deadlines for the obligation of those funds. The revised definition of the term “obligation,” based on the uniform guidance definition, still means an order placed for property or services or contracts, subawards or similar agreements that require a payment. Here’s what your tribal government needs to know to prepare for obligating your SLFRF: Obligation deadline The main deadline to “obligate” the SLFRF funds is December 31, 2024. However, there is one earlier deadline regarding these funds and how these funds are considered obligated. Tribal governments will need to report administrative costs estimates by April 30, 2024. This earlier deadline covers SLFRF funds used for allowable expenditures that are not for hard goods, including all long-term construction projects, including water, sewer or broadband projects. Tribal governments need to comply with the IFR to avoid losing or returning any of the SLFRF money they received. (The IFR did not change the December 31, 2024, and December 31, 2026, deadlines for obligating and spending the SLFRF.) Tribal governments should review the IFR carefully and plan to ensure they obligate and spend their SLFRF funds in accordance with the rules and timelines. Obligation criteria All transactions that meet the definition must be obligated by December 31, 2024. Some examples of an obligation that meets the criteria are: A signed contract for services covering a period of time not to exceed December 31, 2026. A signed construction contract for large construction projects with an explicit price stated for the project. An order placed for materials, like the materials to build a home set for delivery on a set schedule. A subaward granted to a sub-awardee. Indirect costs being charged to the SLFRF funds. Some examples that are not considered an obligation for this purpose include: A purchase order that does not have an actual order of material or services attached. A budget appropriation of funds for a project that has not begun. A budget or allocation of SLFRF funds. The IFR also set a secondary definition of an “obligation” for the following activities: Reporting and compliance requirements, including subrecipient monitoring Single audit costs Record retention and internal control requirements Property standards Environmental compliance requirements Civil rights and nondiscrimination requirements Many of these costs could be payroll and related costs that have yet to be obligated via a contract or similar document. However, the IFR gives recipients a little flexibility in these allowable costs. Each recipient must: Estimate the costs it will use to cover these allowable administrative and compliance-related costs. Document a reasonable justification for the estimate. Report the amount to the U.S. Treasury by April 30, 2024. Report at award closeout the final amount expended for these costs. Keep in mind that all expenditures, excluding administrative expenditures necessary to close out the SLFRF, must be expended by December 31, 2026. Key questions As you navigate these new updates, your tribal government may run into questions including: What happens if my tribal government overestimates the administrative costs? Any unexpended funds must be returned to the Treasury. They cannot be reallocated to another cost. Are tribal governments allowed to reallocate obligated costs after December 31, 2024? In general, no. After December 31, 2024, a recipient is not allowed to re-obligate or obligate additional funds. However, there are a few instances where recipients are allowed to replace a contract or subaward entered into before December 31, 2024. These exceptions include: If a recipient terminates a contract or subaward due to a contractor or subrecipient’s (contractor) default, the contractor goes out of business or if the recipient determines the contractor will be unable to perform The recipient and contractor mutually agree to terminate the contract for convenience The recipient terminated the contract if the contract was improperly awarded. There must be clear evidence the award was improper (i.e., the contractor wasn’t allowed to receive a contract). Next steps As your organization continues moving forward in 2024, it’s important to remember the December 31, 2024, deadline to obligate funds and the April 30, 2024, deadline to report administrative cost estimates to the Treasury. The Treasury has stated that it will update the SLFRF Compliance and Reporting Guidance prior to the first quarter reporting period due no later than April 30, 2024.

Perspective changes everything.

Receive timely industry developments, regulatory changes and other news impacting your success.

Reach out to our team

We’re ready to help your organization strengthen compliance, improve oversight, manage risk and protect resources for future generations. 

Tribal audit services FAQ