Subpart D: Post-award requirements 2024 Uniform Guidance · effective Oct 1, 2024

2 CFR 200.303: Internal controls

2 CFR 200.303 sets 2 requirements for organizations that receive federal grants and cooperative agreements. Applies while you manage a federal award.

Shows up in your application: Organizational capacityData management plan

What 2 CFR 200.303 requires

1. Financial management

What you must do

Establish, document, and maintain effective internal control over the Federal award providing reasonable assurance of management in compliance with Federal statutes, regulations, and award terms and conditions (aligned with the GAO Green Book or COSO framework); evaluate and monitor compliance; and take prompt action when noncompliance is identified.

When it applies

All Federal awards, effective at award acceptance.

Organizational capacity
2. Records

What you must do

Take reasonable cybersecurity and other measures to safeguard information, including protected personally identifiable information (PII), information the agency or pass-through entity designates as sensitive, and other information the recipient considers sensitive, consistent with applicable Federal, State, local, and tribal privacy and confidentiality laws.

When it applies

The project involves collecting, storing, or handling PII or designated sensitive information.

Data management planOrganizational capacity
Grantable compliance database

Ask what 2 CFR 200.303 means for your award

Upload your award terms and ask what you owe and when. Grantable answers from its compliance database of federal, agency and state rules, with citations.

Sections that refer to 2 CFR 200.303

Regulation text of 2 CFR 200.303

+

The recipient and subrecipient must:

(a) Establish, document, and maintain effective internal control over the Federal award that provides reasonable assurance that the recipient or subrecipient is managing the Federal award in compliance with Federal statutes, regulations, and the terms and conditions of the Federal award. These internal controls should align with the guidance in “Standards for Internal Control in the Federal Government” issued by the Comptroller General of the United States or the “Internal Control-Integrated Framework” issued by the Committee of Sponsoring Organizations of the Treadway Commission (COSO).

(b) Comply with the U.S. Constitution, Federal statutes, regulations, and the terms and conditions of the Federal award.

(c) Evaluate and monitor the recipient's or subrecipient's compliance with statutes, regulations, and the terms and conditions of Federal awards.

(d) Take prompt action when instances of noncompliance are identified.

(e) Take reasonable cybersecurity and other measures to safeguard information including protected personally identifiable information (PII) and other types of information. This also includes information the Federal agency or pass-through entity designates as sensitive or other information the recipient or subrecipient considers sensitive and is consistent with applicable Federal, State, local, and tribal laws regarding privacy and responsibility over confidentiality.

Source: eCFR · checked Sep 17, 2026

Questions about 2 CFR 200.303

What does 2 CFR 200.303 require?

Establish, document, and maintain effective internal control over the Federal award providing reasonable assurance of management in compliance with Federal statutes, regulations, and award terms and conditions (aligned with the GAO Green Book or COSO framework); evaluate and monitor compliance; and take prompt action when noncompliance is identified. Take reasonable cybersecurity and other measures to safeguard information, including protected personally identifiable information (PII), information the agency or pass-through entity designates as sensitive, and other information the recipient considers sensitive, consistent with applicable Federal, State, local, and tribal privacy and confidentiality laws.

When does 2 CFR 200.303 apply?

All Federal awards, effective at award acceptance. The project involves collecting, storing, or handling PII or designated sensitive information.

Plain-English summaries for information only, not legal advice. Always check the regulation text, your award terms and your agency’s guidance.