What "audit-ready" actually means

An audit-ready grant file is one where a competent stranger can answer three questions without asking you anything: what did this award require, what did the organization do and spend, and how do we know?

That framing matters because it is not the same as "we kept everything." Most nonprofits keep almost everything. The gap auditors and program officers find is rarely a missing document — it is a document that exists but cannot be tied to the claim it supports. A stack of invoices proves money moved. It does not, on its own, prove that this $4,180 was charged to this budget line under this award for work inside the period of performance.

This guide is for the person who will be asked for the file — a grants manager, finance lead or executive director at an organization holding restricted awards. It covers structure, naming, retention and the evidence-to-claim link. It is not audit advice; when the question is whether a specific cost was allowable or whether a finding applies to you, that belongs with your auditor or a grants attorney.

Who asks, and what they ask for

Three different reviews reach for the same file, with different depth.

A funder's routine report review wants the deliverable evidence and the financial summary. Shallow, frequent, usually resolved by email.

A funder's site visit or monitoring review wants the award terms, the budget and any revisions, approvals for changes, and a sample of expenditure support. This is where a well-organized file visibly reduces how long people are in your office.

A single audit applies when a non-federal entity expends $1,000,000 or more in federal awards during its fiscal year (2 CFR 200.501). Two details are commonly misread: the test is on federal funds expended in the year, not awarded, and it is measured across the whole entity, not per award. An organization with four federal awards of $300,000 each, all spending in the same year, is over the line.

The single audit is also the reason to build the file continuously rather than at year end. An auditor samples transactions and asks for support on each; the cost of reconstruction falls entirely on whoever kept the records.

The eight-folder structure

One folder per award, eight subfolders, the same eight every time. The value is in the sameness — anyone can find anything, and an empty folder is a visible question rather than an invisible gap.

#FolderWhat lives here
1Award documentsSigned agreement, terms and conditions, any attachments incorporated by reference, notice of award, the approved proposal
2Budget and revisionsThe approved budget, every subsequent revision with its approval, and the current effective version clearly marked
3Approvals and prior consentsWritten approvals for budget changes, scope changes, no-cost extensions, key personnel changes; the request and the response together
4Expenditure supportInvoices, payroll allocations and timesheets, contracts, receipts — organized by period, each tied to a budget line
5Deliverable evidenceAttendance sheets, photographs, outputs, partner confirmations, outcome data — filed against the deliverable it proves
6Reports submittedEach report as submitted, with its submission confirmation and date
7CorrespondenceMaterial exchanges with the funder — anything that changed an obligation, an interpretation or a date
8CloseoutFinal reports, final financial report, disposition of equipment, release or closeout confirmation from the funder

Two rules keep the structure honest. Correspondence that changes an obligation does not stay in email — it gets saved into folder 3 or 7 as a document. And the current effective budget is unmistakable; more findings come from working to a superseded budget than from arithmetic.

Naming so the file explains itself

A file name is metadata that survives being emailed, downloaded and re-uploaded. Use one pattern everywhere:

YYYY-MM-DD_<award-short-code>_<doc-type>_<detail>.<ext>
2026-04-15_HFF2026_invoice_venue-deposit-q2.pdf
2026-07-31_HFF2026_report_q2-narrative-submitted.pdf
2026-02-01_HFF2026_approval_budget-revision-1.pdf

The leading ISO date sorts chronologically in every system. The award code makes a stray file identifiable after it has been moved. The doc-type is what somebody searches for. Avoid "final", "v2", "latest" and "new" — they age badly and they are exactly the words present in every disputed file.

For expenditure support, add the budget line to the detail. That single habit turns "here are our invoices" into "here is the support for line 4," which is the difference the reviews above actually turn on.

Retention: the rule and its exceptions

For federal awards, the base rule is short and specific. Records must be retained for three years from the date of submission of the final financial report (2 CFR 200.334). Note the clock starts at submission, not at the end of the period of performance — and since final reports are due within 120 calendar days of the end of the period of performance (2 CFR 200.344), the two dates are close but not the same. Record the submission date; it is the one the retention period is measured from.

The exceptions extend the period, and they are the part people miss:

Private and foundation awards set their own retention terms, and the agreement controls. Where an agreement is silent, most organizations apply the federal rule as a floor and their own document retention policy on top. Set a destruction date on the folder at closeout rather than keeping everything forever — an indefinite pile is its own liability.

One timing note: a proposed rewrite of 2 CFR part 200 was published in the Federal Register on 29 May 2026, with comments closing 13 July 2026. It is a proposal and not in force; the citations above are the current text. Re-check the sections before relying on them for a decision.

Linking evidence to the claim it supports

This is the practice that converts a complete file into an audit-ready one, and it costs almost nothing if it happens at the moment of filing.

For every reported result, a reviewer should be able to trace one line: claim → evidence → date → award. "We trained 214 people" points to the attendance sheets; the sheets carry dates inside the period of performance; the sessions are identifiable as this award's activity rather than another program's.

Three habits do most of the work:

Software can carry this structure rather than relying on a folder convention. In GrantConsole, evidence is attached to the deliverable that requires it, reporting packets are assembled from those attachments, and an activity history records what changed on the grant and when — which is the part that matters when the person who built the file has moved on. It tracks the obligations and records you enter; it does not interpret your award, judge allowability, or satisfy an audit. The live demo is seeded with two example organizations and eighteen grants if you want to see the evidence model, and grant reporting software for nonprofits covers how packets are assembled.

Before you close the award

Closeout is the last moment the file is cheap to fix, because the people who know things are still available. Work through the grant closeout checklist at that point, and use the post-award grant management checklist to keep the file building itself from the day the award lands.