Industry guide · Internal Tools

Subrecipient Monitoring Software: How Pass Through Entities Prove They Actually Watched the Money

Subrecipient Monitoring software visual showing payment recovery, file search 2, and shield alert.
The short answer

Expect $70,000 to $150,000 for a first release that ships in 12 to 18 weeks, covering subrecipient risk assessment, subaward issuance and reimbursement request review with attached backup. A full monitoring system adding single audit collection, corrective action tracking, site visit workflows, FFATA subaward reporting and a subrecipient portal runs $180,000 to $400,000 phased across 8 to 14 months. Build when you pass through federal money to more than roughly 25 subrecipients, when your risk assessment lives in one analyst's spreadsheet, or when a monitoring finding has already cost you a questioned cost. Do not build if you administer fewer than ten subawards under a single program with one reporting format. AmpliFund or eCivis will hold that, and the money is better spent on a compliance hire.

Why pass through monitoring falls apart past a dozen subrecipients

You are the grants compliance director at a state agency, a large city, or a nonprofit intermediary. Federal money lands in your accounts and leaves again as subawards to community organisations, county departments, school districts and small nonprofits that have three staff and a bookkeeper who works Thursdays. Under 2 CFR 200.332 you are the pass through entity, which means the federal awarding agency does not chase your subrecipients. It chases you. If a subrecipient charges an unallowable cost, you repay it. If your monitoring was inadequate, the finding is against your organisation, not theirs.

The operational picture is almost always the same. Risk assessment happens once a year in a spreadsheet that scores each subrecipient on prior experience, audit history and dollar value, using weights that made sense to the analyst who built it in 2019 and have never been documented. Subaward agreements are Word templates with the terms and conditions pasted in. Reimbursement requests arrive as emailed PDFs with a scanned general ledger detail behind them, get reviewed by whoever is free, and get approved in an email thread that lives in one person's Outlook. Single audit reports arrive as attachments, sit in a shared drive folder organised by year, and the corrective actions in them are read once and never followed up.

None of that is negligence. It is what happens when the volume grows past what a filing convention can hold. The failure mode is specific: when a federal monitor or your own external auditor asks you to demonstrate that monitoring occurred at the frequency your own risk assessment called for, you cannot produce it as a record. You can produce evidence that work happened. You cannot produce evidence that the work happened on schedule, in a consistent order, against a documented standard. That distinction is the entire finding.

What AmpliFund and eCivis actually do, and where they stop

Both are real products with real customers and you should look at them before you talk to anyone about a build. AmpliFund handles the grant lifecycle well on the recipient side and has genuine subaward capability. eCivis has long roots in state and local grants management and knows public sector procurement. Neither is a bad product.

Where they stop is the same place most grant tools stop, because they were architected around the applicant journey. The centre of gravity is your own award: the application, the budget, the drawdown, your reporting to the federal agency. Monitoring downstream recipients is a module hung off the side of that model. So the risk assessment is a form with fields rather than a scoring engine you control. The monitoring calendar is a set of tasks rather than a rule that says a high risk subrecipient on a construction program gets a desk review every quarter and an onsite visit annually, and that the clock starts on the date of the subaward not the date somebody remembered. Reimbursement review is document upload and approval, not line level cost testing against the approved budget with a sampling rule that varies by risk tier.

The other gap is your own systems. Your subaward obligations sit in your ERP (Enterprise Resource Planning), whether that is Workday, Tyler Munis, Oracle or a state accounting system nobody has fully documented. Payment happens there. If your monitoring tool does not know what has actually been disbursed against each subaward, your monitoring is running on a copy of the numbers, and copies drift.

Problem one: a risk assessment nobody can reproduce

Uniform Guidance requires you to evaluate each subrecipient's risk of noncompliance and to calibrate monitoring to that risk. It deliberately does not tell you how. So every pass through entity invents a scoring model, and the model is where the exposure sits. If you cannot show why a subrecipient scored medium instead of high, you cannot defend the monitoring level that followed from it.

A custom build turns the model into a versioned object. Each risk factor is a named rule with a weight and a data source: prior single audit findings, whether the subrecipient has expended federal awards above the Single Audit threshold, which moved to $1 million under the 2024 Uniform Guidance revisions, months since the last onsite visit, percentage of the subaward drawn in the final 30 days of a period, staff turnover in the finance role, late reports. Scores recompute when the inputs change rather than once a year. Critically, the model is versioned, so when an auditor asks how a 2025 score was produced you replay the 2025 model rather than the current one. That single design decision has saved more monitoring programs than any dashboard.

Problem two: reimbursement review is a PDF slog with no sampling logic

The subrecipient emails a request for $84,000 with a ledger export and 40 receipts. Your reviewer opens each PDF, checks a few against the approved budget line, looks for anything obviously unallowable, and approves. There is no record of which transactions were tested, so next quarter someone tests a different sample and nobody knows the coverage.

What the build must do is make the test itself a record. Reimbursement requests come in as structured lines mapped to approved budget categories, not as an attachment. The system flags variance against the approved budget, cost categories that require prior written approval, costs incurred outside the period of performance, and indirect charged above the negotiated rate or above the de minimis rate, which the 2024 revisions raised to 15 percent of modified total direct costs. Sampling is a rule: high risk subrecipients get every transaction above a threshold tested plus a random draw, low risk get a smaller draw. Each tested item carries the reviewer, the date, the conclusion and the document. When the auditor pulls a request from 14 months ago, the test work comes with it.

Document extraction is the one place machine learning earns its budget here. Subrecipient ledgers and receipts arrive in every format a small nonprofit can produce. An extraction pass that reads a scanned invoice into vendor, date, amount and description, then matches it to the claimed line, removes the transcription work while leaving the judgement with your reviewer. It is not an approval engine and you should refuse to build it as one.

Problem three: single audits and corrective actions that go nowhere

Audit reports are due to the Federal Audit Clearinghouse within nine months of the subrecipient's fiscal year end. Your job is to know which subrecipients were required to have one, to obtain it, to read the findings that relate to your funds, to issue a management decision, and to track the corrective action to completion. Most pass through entities do the first three and stop.

A build makes this a tracked object rather than a folder. Each subrecipient gets an expected audit status derived from their expenditure level. Overdue audits generate escalation. Findings are entered as records with a management decision deadline, an assigned owner and a corrective action plan with milestone dates. The subrecipient uploads evidence of remediation through a portal against the specific milestone. When the finding recurs the following year, the system already knows, and your risk score moves without anyone remembering to move it.

What a custom build must include

The non negotiable pieces: a subrecipient register with entity identifiers, the assurances and certifications on file, and an active check against the federal exclusions list before every subaward and before every payment. Subaward issuance from a clause library, so the terms and conditions that flow down are the ones the specific federal program requires rather than whatever was in the last Word file. FFATA subaward reporting for awards at or above the $30,000 threshold, generated from the subaward record instead of re keyed. A monitoring calendar driven by the risk model. Desk review and onsite visit templates with structured findings. A subrecipient facing portal, because chasing documents by email is where your staff time actually goes. And a write back to your financial system so obligations, disbursements and available balance are one number, not three.

Retention matters more here than in most builds. Uniform Guidance record retention is generally three years from submission of the final expenditure report, longer if litigation or audit is open. Your system needs a legal hold concept and an export that produces a defensible evidence pack per subaward, because the thing you are really building is the ability to answer a monitor in a day rather than a month.

Cost, timeline and what moves the price

In Digital Heroes delivery experience, a first release covering the register, risk model, subaward issuance and reimbursement review with structured testing runs $70,000 to $150,000 and ships in 12 to 18 weeks. Adding single audit tracking, corrective action follow up, site visit workflows, FFATA generation, the subrecipient portal and financial system integration takes the program to $180,000 to $400,000 over 8 to 14 months.

What pushes the number up: the number of distinct federal programs you pass through, because each brings its own flow down terms, reporting cadence and allowable cost quirks. Integration with a state accounting system, which is usually the longest pole and is rarely a documented API. Public sector security review, accessibility conformance to Section 508 for anything a subrecipient touches, and procurement timelines that add months before a line of code exists. What keeps it down: starting with your two largest programs and the subrecipients that carry the most dollars, then extending.

When buying is the right answer

Buy if you run one federal program with under ten subawards, uniform reporting, and a compliance officer who can hold the whole picture. Buy if your organisation cannot commit a product owner for a day a week, because a monitoring build without an internal owner turns into a form nobody fills in. AmpliFund and eCivis both cost far less than a build and both are better than the spreadsheet you have now.

Build when the risk model is genuinely yours and needs to be defensible, when you pass through to 25 or more subrecipients across multiple programs, when your subrecipients are small organisations who will never adapt to a vendor's fixed workflow, or when you have already taken a monitoring finding. The trigger is not volume alone. It is the moment the answer to how do you know monitoring happened has to be a system rather than a person.

How to choose a developer for this

Ask them to explain the difference between a subrecipient and a contractor under 2 CFR 200.331 before you discuss features. If they cannot, they will build you a vendor management tool and you will discover the gap during your next single audit. Ask how they would version the risk model, and listen for whether they understand that historical scores must be reproducible. Ask what they have integrated with on the finance side and get the specific system name, because Tyler, Workday and a bespoke state ledger are three different projects. Ask how they handle evidence retention and legal hold. And settle code and data ownership in writing before kickoff: you should hold the repository, the cloud accounts and the right to bring in anyone else. At Digital Heroes the client owns the code from the first commit, and any developer who resists that is selling you a dependency rather than a system.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Companies in the top quartile of McKinsey's Developer Velocity Index had 2014-18 revenue growth four to five times faster than bottom-quartile peers, showing that software-building capability is a driver of business performance, not just a support function. Source: McKinsey & Company (2020) →
  2. Almost half of all the activities people are paid almost $16 trillion in wages to do in the global economy have the potential to be automated by adapting currently demonstrated technologies. Source: McKinsey Global Institute (2017) →
  3. Across more than 5,400 IT projects studied by McKinsey and the University of Oxford BT Centre, large IT projects ran on average 45% over budget and 7% over schedule while delivering 56% less value than predicted. Source: McKinsey & Company / University of Oxford (BT Centre for Major Programme Management) (2012) →
  4. Sensor Tower's State of Mobile 2026 reports that global users spent 5.3 trillion hours in iOS and Google Play apps in 2025 (+3.8% YoY), roughly 3.6 hours per day per mobile user. (Note: the page does not itself contrast app time vs. mobile-browser time, so the 'overwhelming majority of time in apps vs browsers' framing is not directly supported by this source.). Source: Sensor Tower (2026) →
Ben S. · Senior SEO Strategist · New York

Ben works on search: site structure, technical crawl issues, content planning and the slow business of earning rankings that hold. Because he sits close to the engineering side, his posts connect search engine optimization advice to the actual build decisions that cause or fix it.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom subrecipient monitoring software cost for a state agency?
A first release covering the subrecipient register, a versioned risk model, subaward issuance and structured reimbursement review runs $70,000 to $150,000 and ships in 12 to 18 weeks in Digital Heroes delivery experience. Adding single audit tracking, corrective action follow up, site visits, FFATA generation and a subrecipient portal takes the program to $180,000 to $400,000 over 8 to 14 months. The number of distinct federal programs you pass through moves the price more than the number of subrecipients does.
Is AmpliFund or eCivis enough, or do we need a custom build?
Both are credible products and worth evaluating first, particularly if you run one or two programs with a modest number of subawards. They are architected around the applicant and recipient journey, so downstream monitoring is a module rather than the core, which shows up as fixed risk assessment forms and monitoring tasks instead of a scoring engine and a rules driven calendar you control. If your risk model needs to be defensible and reproducible across years, or your subrecipients span several programs with different flow down terms, a build starts making sense.
What does Uniform Guidance actually require a pass through entity to do?
2 CFR 200.332 requires you to evaluate each subrecipient's risk of noncompliance, monitor accordingly, ensure required audits are performed, issue management decisions on findings relating to your funds, and flow down applicable federal terms in the subaward. It intentionally does not prescribe a scoring method or a monitoring frequency, which is why every pass through entity builds its own and why the model has to be documented. Confirm your specific obligations with your cognisant agency or your auditor rather than relying on any article.
How do we handle the single audit threshold change in a monitoring system?
The 2024 Uniform Guidance revisions raised the Single Audit threshold to $1 million in federal awards expended, so a slice of your subrecipients that previously needed an audit no longer does. A monitoring system should derive expected audit status from each subrecipient's reported expenditure level rather than from a static flag someone set years ago, because that flag will be wrong within one cycle. Subrecipients who drop below the threshold do not become low risk, they become subrecipients you have to monitor with something other than an audit report.
Can subrecipient monitoring software connect to our existing accounting system?
Yes, and it should, because monitoring against a copy of the obligation and disbursement numbers is how balances drift. The realistic difficulty depends entirely on which system you run: a modern Workday or Tyler environment has documented integration paths, while a bespoke state ledger often means a nightly file exchange and a reconciliation report. Ask any developer for the specific systems they have integrated with by name, and treat the finance integration as its own workstream with its own timeline.
How long does it take to build a subrecipient monitoring platform?
A usable first release ships in 12 to 18 weeks. The schedule risk is rarely engineering, it is deciding your own rules: which risk factors count, what weights they carry, what monitoring each tier triggers, and which flow down terms attach to which program. Organisations that already have a written risk assessment methodology move fast, and organisations where the method lives in an analyst's head should budget three to five weeks of discovery to write it down before a build starts.
Where does AI genuinely help with grant compliance monitoring?
Document extraction is the clear win. Subrecipient ledgers, invoices and receipts arrive as scans and exports in every possible layout, and an extraction pass that turns them into vendor, date, amount and description mapped to the claimed budget line removes the transcription work your reviewers hate. Use it to prepare the review, never to make the allowability decision, because a machine approval you cannot explain is worse than no automation at all in front of an auditor.
Do we need a subrecipient portal, or is email enough?
Once you are past roughly 25 subrecipients, email becomes the bottleneck rather than the review itself, because staff time goes into chasing documents rather than testing costs. A portal that shows each subrecipient their subaward terms, their available balance, their outstanding requests and their open corrective actions removes most of that chasing. Keep it deliberately simple, since many subrecipients are three person organisations and a complicated portal just moves the chasing to support calls.
Who owns the code if an agency builds this with an outside developer?
You should own the repository, the cloud infrastructure accounts and the unrestricted right to hire another firm, and it belongs in the contract before kickoff rather than in a renewal negotiation. This matters more in public sector work because procurement cycles are long and the political cost of being locked to one vendor is high. At Digital Heroes the client owns the code from the first commit. Ask this question first, and treat any hedging as the answer.
Can we start on Airtable or Retool now and move to custom software later?
Yes, and it is often the smartest sequence: run the workflow on Airtable or Retool for 6 to 12 months to learn what you actually need, then go custom once the process stabilizes. The no-code version becomes free requirements documentation, and its data exports cleanly into a custom database. The one risk is waiting too long, because teams stack automations and workarounds until migration becomes a project of its own, so set a concrete trigger in advance, such as hitting Airtable's 50,000-record Team plan cap.
How much does a custom internal tool cost to build?
Most custom internal tools cost $8,000 to $40,000 to build, based on Digital Heroes delivery data across 2,000+ client projects. A single-purpose tool like an approval dashboard or inventory tracker sits at the low end, while a multi-department platform with role-based access and several integrations pushes past $40,000. The three biggest cost drivers are the number of user roles, the number of systems the tool must connect to, and custom reporting requirements.
What does it cost to keep an internal tool running after launch, and do we need to hire a developer?
Budget 15 to 20 percent of the build cost per year, so a $25,000 tool runs roughly $300 to $400 a month covering hosting, security patches, dependency updates, and small tweaks, figures drawn from Digital Heroes maintenance contracts. You do not need an in-house developer; a monthly retainer with the agency that built it covers the typical internal tool comfortably. Hosting itself is cheap for internal audiences, often $20 to $100 a month, because you serve dozens of users rather than the open internet.
How do I vet a development agency for an internal tools project?
Ask to see two or three internal tools they have shipped and whether those clients still use them daily, because internal tools fail on adoption, not code quality. Good signs: they ask to see your current spreadsheet or process before quoting, they propose a phased build instead of one big launch, and they spell out who handles training and post-launch changes. Walk away from anyone who gives a fixed price before seeing your actual workflow, since internal tools live or die on process details.
Will an app built for 10 users survive growing to 500?
Yes, if it is built on standard cloud infrastructure with a sound data model, because moving from 10 to 500 users is a hosting configuration change, not a rebuild. The scaling decisions that actually hurt are made early and invisibly: how the database is structured, how accounts and permissions are modeled, and whether background work is queued properly. Ask your agency how the system would handle ten times the load; the right answer is boring and specific, and a promise to cross that bridge later means you will pay for the bridge twice.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?