Leaders Insights
Leaders Insights

Stay at the top of your field, a little every day.

DomainsMarketingDataFinanceAI
ResourcesLearnTestToolsBlogGlossary
© 2026 Leaders Insights — All rights reserved.
Tracks/Finance in the public sector/Regulation, risks and checks/The due-diligence checklist before you fund, contract, or merge
4/4+150 XP

Regulation, risks and checks

10The regulatory architecture: who actually governs public money+15011Fraud, waste, and abuse: the risk triangle in public institutions+15012
Reading a single audit and management letter without flinching
+150
13The due-diligence checklist before you fund, contract, or merge+150

The due-diligence checklist before you fund, contract, or merge

# The due-diligence checklist before you fund, contract, or merge

A county finance director once approved a $2 million homeless services contract based on a glossy annual report and a handshake from the nonprofit's board chair. Eighteen months later, a state audit found the subrecipient had commingled restricted funds, paid its executive director's spouse as an undisclosed consultant, and couldn't produce timesheets for half its federally funded staff. The county had to repay the disallowed costs itself. No document trail, no defense.

This lesson walks through the paper trail that would have caught it, and the checklist you run before money moves.

Why due diligence hits differently in the public sector

In corporate M&A, due diligence protects your own shareholders. In government and nonprofit finance, you're often protecting someone else's money: taxpayer funds, restricted grants, donor-designated gifts. The rules are less negotiable and the penalties for getting it wrong (clawbacks, debarment, criminal referral) fall on the funder, not just the recipient.

The core US federal framework is the Uniform Guidance, formally 2 CFR Part 200, issued by the Office of Management and Budget (OMB). It governs how federal grants flow to states, cities, universities, and nonprofits, and how those "pass-through entities" must monitor their own subrecipients. In Europe, the equivalent discipline sits under EU financial regulation and national public procurement law, enforced by bodies like the European Court of Auditors and country-level supreme audit institutions.

Both regimes share one instinct: trust is not a control. Documentation is.

The four document trails you actually pull

1. Segregation-of-duties (SoD) mapmapUsing software to automate repetitive marketing tasks and campaigns, enabling personalisation at scale across channels like email, web, and social.View full definition →

Segregation of duties means no single person can initiate, approve, and record a transaction alone. It's the first thing an auditor checks because it's the cheapest fraud prevention that exists.

Before funding, ask for an org chart showing who requests payments, who approves them, who reconciles the bank account, and who signs checks. If one person does all four, that's not a red flag, that's a stop sign. Small nonprofits (under roughly 10 staff, a common informal threshold) often fail this by necessity; the fix isn't refusal, it's compensating controls like board treasurer co-signature on checks above a set dollar threshold.

2. Conflict-of-interest (COI) disclosures

A conflict of interest exists when a decision-maker has a personal or financial stake in the outcome. US nonprofits filing Form 990 (the annual information return to the Internal Revenue Service) must disclose whether they have a written COI policy, but the form doesn't verify enforcement. Pull the actual signed disclosures, not just the policy PDF.

Concretely: cross-check board member names and immediate family against vendor and payroll lists. This single step catches the "spouse as undisclosed consultant" scenario above.

3. Subrecipient monitoring records

Under 2 CFR 200.332, a pass-through entity (say, a state agency regranting federal workforce development funds to a city nonprofit) must document risk assessments of each subrecipient and monitor them proportionally to that risk. Look for:

  • A written risk assessment (new subrecipient vs. experienced, prior audit findings, size of award)
  • Evidence of at least one on-site or desk review per award cycle
  • Single Audit reports, if the subrecipient spends $1,000,000 or more in federal funds in a fiscal year (the Single Audit threshold, updated periodically by OMB; verify current figure at OMB's Uniform Guidance resource page)

4. Financial statements and the audit opinion

Request three years of audited financial statements if available, or reviewed statements at minimum for smaller entities. Read the auditor's opinion letter first: "unmodified" (clean) is what you want; "qualified," "adverse," or "disclaimer of opinion" means dig deeper before you sign anything.

Also check the Form 990 on GuideStar/Candid or the IRS's own Tax Exempt Organization Search for red flags: declining fund balance year over year, excessive executive compensation relative to budget size, or program expense ratios that seem too good to be true (claims of 98% program spend with no fundraising cost are a classic misstatement).

A worked example: sizing the risk before you contract

Say a city is about to award a $500,000 annual contract to a nonprofit for youth mental health services. The nonprofit's most recent audited financials show:

  • Total annual revenue: $2.1 million
  • Unrestricted net assets: $180,000
  • Total liabilities: $1.4 million

Quick liquidity check: months of unrestricted cash on hand = unrestricted net assets ÷ (annual expenses ÷ 12). If annual expenses are roughly $2 million, that's $180,000 ÷ ($2,000,000/12) = $180,000 ÷ $166,667 ≈ 1.1 months of reserve.

A commonly cited nonprofit sector benchmark (estimate, varies by field) is 3 to 6 months of operating reserve as a marker of financial resilience. At 1.1 months, this organization is thin. That doesn't disqualify them, many mission-driven nonprofits run lean, but it should trigger a contract clause: milestone-based payments rather than a lump sum, so the city isn't exposed if the nonprofit hits a cash crunch mid-year.

Main financial risks to screen for

  • Misappropriation: funds diverted from restricted purpose to general operations or personal use.
  • Related-party transactions: undisclosed deals with board members, staff relatives, or affiliated entities.
  • Going-concern risk: the entity may not survive the contract period; check audit notes for "going concern" language, which auditors are required to flag under US GAAP (Generally Accepted Accounting Principles) when substantial doubt exists.
  • Grant stacking without cost allocation: the same staff time or expense billed to multiple funders, a common Single Audit finding.
  • Procurement conflicts: in government contracting, awarding a no-bid or sole-source contract to a firm with undisclosed ties to a public official violates most state procurement codes and, at the federal level, principles under the Federal Acquisition Regulation (FAR).

Knowledge check

1. In the opening case, the county lost a repayment dispute over disallowed costs primarily because of what underlying failure?

2. Why does the lesson argue that due diligence 'hits differently' in public-sector and nonprofit finance compared to corporate M&A?

3. A funder reviewing a potential subrecipient finds that one program manager has sole authority to initiate purchases, approve invoices, and record the transactions in the accounting system. What concept does this violate, and why does it matter?

MULTIPLE CHOICE

4. Select ALL correct answers about why 'trust is not a control' is a central principle in public-sector due diligence.

Select all the correct answers.

MULTIPLE CHOICE

5. Select ALL correct answers about the role of the Uniform Guidance (2 CFR Part 200) described in the lesson.

Select all the correct answers.

Practical checklist before you sign

Here's the sequence a competent grants or contracts officer runs, roughly in order:

1. Pull the last three years of audited (or reviewed) financial statements and read the opinion letter.

2. Request the Form 990 (US) or equivalent public filing, and cross-check board and vendor names for conflicts.

3. Ask for the written conflict-of-interest policy and actual signed disclosures, not just the policy.

4. Request an org chart or narrative describing segregation of duties over cash receipts, disbursements, and payroll.

5. If federal funds are involved and the recipient is a subrecipient, confirm they've had a Single Audit if required, and review any findings and corrective action plans.

6. Calculate a basic liquidity ratio (reserve months) and a program expense ratio (program costs ÷ total expenses; sector estimate benchmark often cited is 65 to 80%, though this varies enormously by mission type).

7. Check debarment status against the US System for Award Management (SAM.gov exclusions search), which lists entities barred from federal contracts and grants.

8. Structure payment terms (milestones, holdbacks, reimbursement vs. advance) based on the risk level you just found.

None of this requires forensic accounting expertise. It requires reading the documents that already exist and asking for the ones that should.

🎬 [VIDEO: "Understanding Nonprofit Form 990s" - youtube.com - a walkthrough of how to read a nonprofit's public tax filing for financial health and governance red flags]

Key Takeaways

  • Segregation-of-duties maps, signed conflict-of-interest disclosures, and subrecipient monitoring records are the three documents most often missing when public money goes wrong, and the three you should request first.

Previous

Reading a single audit and management letter without flinching

  • The Uniform Guidance (2 CFR 200) sets the US federal baseline for how pass-through entities must assess and monitor subrecipient risk; Europe's equivalent runs through EU financial regulation and national supreme audit institutions.
  • A quick liquidity check (unrestricted net assets ÷ monthly expenses) turns a stack of financial statements into a single, comparable number you can act on.
  • Clean documentation doesn't guarantee good faith, but its absence is itself the strongest predictor of future audit findings.
  • Structure payment terms (milestones, reimbursement basis) to match the risk level you uncover, rather than defaulting to a lump-sum advance.