Compliance Audits (Statutory or regulatory audits)

Helps organizations meet specific regulatory or contractual compliance requirements through specialized audit procedures.

Capabilities
Compliance Audits Offerings
01
Single audits per uniform guidance
Performing audits for organizations that spend federal awards, ensuring compliance with federal regulations and grant agreements.
02
Audits for HUD
Conducting audits specifically for entities receiving funding from the U.S. Department of Housing and Urban Development (HUD), ensuring adherence to their guidelines.
03
Audits for EBP (employee benefit plans) per ERISA
Auditing employee benefit plans to ensure compliance with the Employee Retirement Income Security Act (ERISA) and Department of Labor regulations.
04
Audits for HIPAA
Comprehensive assessments of healthcare data privacy and security controls against HIPAA requirements. Our audits help organizations identify compliance gaps, strengthen safeguards for protected health information (PHI), and reduce regulatory and operational risks.
Our Insights
Real Problems, Real Thinking
A Defined contribution plan  audit is an independent examination of a company's retirement plan financial statements and operations, required under ERISA when a plan crosses certain participant thresholds. Plan sponsors with 100 or more eligible participants at the start of the plan year generally need an audit as part of their Form 5500 filing, performed by a qualified CPA firm independent of the plan sponsor. Audit costs typically range from a few thousand dollars for a small, straightforward plan to well over $25,000 for a large plan with multiple investment options or prior-year errors to remediate. The rest of this guide breaks down the participant-count trigger in detail, what the audit actually examines, and the factors that drive cost up or down. The 100-Participant Rule, Explained Plainly The Employee Retirement Income Security Act (ERISA) requires plans with 100 or more eligible participants at the beginning of the plan year to file as a "large plan" with the Department of Labor, which triggers the independent audit requirement attached to Form 5500. There is an important exception plan sponsors often miss: the 80-120 participant rule. If the number of participants at the beginning of the plan year is between 80 and 120, the plan may file in the same category (large or small) as it filed the prior year. This means a plan that filed as a small plan can continue to do so, without triggering the audit requirement, as long as its beginning-of-year count stays at 120 or below. This buffer exists specifically so growing companies are not forced into an audit the moment they cross 100 participants by a handful of employees. Important recent change: For plan years beginning on or after January 1, 2023, the Department of Labor changed how the 100-participant threshold is counted for defined contribution plans (such as 401(k) plans). Under the prior rule, the count included all eligible employees, whether or not they actually participated. Under the new rule, only participants with an account balance at the beginning of the plan year are counted. This is a significant change. Plans with many eligible-but-non-participating employees may now fall below 100 counted participants and avoid the large-plan audit requirement entirely. The DOL estimated the change would remove the audit requirement for roughly 20,000 defined contribution plans. The 80-120 rule still applies, but now uses this account-balance count. Any assessment of whether a plan needs an audit should use the current account-balance methodology, not the older eligible-employee count. One clarification that prevents miscounts: for defined contribution plans under the current rule, the count is participants with an account balance at the start of the plan year, which includes not just active contributing employees but also terminated or retired employees who still hold a balance in the plan. Sponsors sometimes undercount by looking only at current active contributors. For plan years before 2023, the count was broader still, including all eligible employees regardless of participation. Does Every Growing Plan Trigger an Audit Right Away? Not immediately, because of the 80-120 rule above, but the trigger becomes unavoidable once the plan consistently sits above 120 participants or the sponsor chooses to file as a large plan. A common scenario: a company hires aggressively during a growth year, crosses 100 participants by year's end, and the finance team only realizes the audit requirement applies when preparing the Form 5500 months later, leaving little time to select an auditor and gather records. This is the single most common reason plan sponsors end up paying rush fees or scrambling for an auditor close to the filing deadline. Tracking participant counts each plan year, not just at filing time, avoids this. Filing Deadline: Form 5500 is due the last day of the seventh month after the plan year ends, which is July 31 for a calendar-year plan. A one-time 2.5-month extension to October 15 is available by filing Form 5558 by the original due date. Because the audit report must be attached to a completed Form 5500, the practical deadline for finishing audit fieldwork is tighter than these dates suggest, which is why late auditor selection drives rush fees. What Does a defined contribution plan Auditor Actually Examine? A Defined contribution plan audit,  is not the same as a corporate financial statement audit, even though both result in an opinion. The auditor examines: Plan financial statements, including the statement of net assets available for benefits and changes in those net assets Participant contributions and whether they were remitted to the plan in a timely manner, a frequent source of findings Eligibility and enrollment records, confirming the plan administrator correctly applied plan terms Distributions and loans, checking that they were processed and approved according to the plan document Investment valuations, particularly for plans holding less liquid or non-standard investment options Late remittance of employee contributions is consistently one of the most common findings in EBP audits, since Department of Labor guidance treats delayed deposits as a fiduciary breach even when the delay is short and unintentional. When late remittances are identified, they are correctable. The Department of Labor’s Voluntary Fiduciary Correction Program (VFCP) lets sponsors self-correct delinquent participant contributions by depositing the missed amounts plus lost earnings, and the IRS Employee Plans Compliance Resolution System (EPCRS) covers related qualification failures. Correcting proactively, and documenting the correction, is far less costly than having the issue surface unresolved in an audit or DOL inquiry. Limited Scope Versus Full Scope: A Distinction That Changes the Audit Plan sponsors using a qualifying trustee or custodian, such as a bank or insurance company that certifies investment information, can elect a limited scope audit, where the auditor does not independently verify the certified investment data. A full scope audit requires the auditor to test investment valuations directly, which generally takes more time and costs more. The AICPA  (through SAS 136) has moved away from the term "limited scope" toward "ERISA Section 103(a)(3)(C) audit" under newer auditing standards, but the practical distinction for plan sponsors remains the same: a certified-investment election narrows what the auditor needs to independently test, which affects both audit duration and fee. What Drives the Cost of a ndefined contribution plan Audit? Audit fees vary based on several factors that plan sponsors can usually identify before requesting a proposal: Plan size and complexity: A plan with a single recordkeeper and standard mutual fund investments costs less to audit than one with multiple investment platforms, company stock, or alternative investments. First-year audit versus repeat engagement: A first-time EBP audit typically costs more because the auditor has no prior-year workpapers to build from and needs to understand plan documents and processes from scratch. Audit scope election: A full scope audit, where investment valuations are tested directly rather than relying on trustee certification, generally costs more than a limited scope or Section 103(a)(3)(C) audit. Quality of plan recordkeeping: Plans with clean, well-organized census data, timely contribution records, and an updated plan document typically move through audit fieldwork faster than plans with scattered records across multiple systems or providers. Findings requiring remediation: If the audit uncovers issues like late contribution remittances or eligibility errors, additional time goes into documenting these findings and advising on correction, which adds to the overall fee. For most mid-sized plans, audit fees commonly fall somewhere between $8,000 and $18,000 annually, though this range shifts meaningfully based on the factors above, and sponsors should treat any quote received without a plan census and prior Form 5500 review as a rough estimate at best. What Happens If a Required Audit Is Skipped or Filed Late? Form 5500 filings missing a required audit report, or filed with a qualified or adverse audit opinion that isn't resolved, draw attention from the Department of Labor. The DOL has run targeted enforcement initiatives specifically focused on EBP audit quality, since deficient audits were found across a meaningful share of CPA firms performing this niche audit type in past DOL studies. Selecting a CPA firm with specific Employee Benefit Plan audit experience, rather than a general practice firm doing one occasionally, reduces this exposure. Plan sponsors are personally responsible as fiduciaries for selecting a qualified auditor, so this is not a decision that can be delegated entirely to a recordkeeper or third-party administrator without sponsor oversight. The financial exposure is concrete. Under ERISA Section 502(c)(2), the DOL can assess a civil penalty of up to $2,739 per day, with no maximum, for a late or incomplete Form 5500, and the IRS can separately assess up to $250 per day (capped at $150,000 per plan year). These are two distinct penalties for the same late filing. Sponsors who discover a delinquency before the DOL contacts them can use the Delinquent Filer Voluntary Compliance Program (DFVCP), which caps the penalty at a substantially reduced amount, typically in the range of a few hundred to a few thousand dollars per filing. Where CPA Outsourcing Fits Into This Picture Many CPA firms handling EBP audits face the same constraint every audit season: a narrow filing window, a shortage of staff with EBP-specific training, and a workload that spikes sharply around the same few months. Outsourcing the fieldwork-heavy, repetitive portions of an EBP audit, like testing contribution remittance timing, distribution sampling, and census data reconciliation, to a dedicated outsourcing partner lets the engagement partner focus on judgment-heavy areas and final review. This is the core of what our Assurance & CPA Outsourcing practice supports for US CPA firms: structured EBP audit fieldwork support that follows the engagement partner's methodology and review standards, rather than a generic offshore staffing arrangement. How Pierag Consulting Supports CPA Firms and Plan Sponsors Pierag Consulting works with US CPA firms on Employee Benefit Plan audit fieldwork, financial statement audit support, and compilation engagements through structured CPA outsourcing arrangements. This includes contribution testing, census data reconciliation, and workpaper preparation aligned to the engaging firm's own audit methodology and review process. Frequently Asked Questions How many participants trigger a mandatory defined contribution plan audit? A plan generally needs an audit once it has 100 or more eligible participants at the start of the plan year, though the 80-120 participant rule allows a one-year buffer for plans growing past the 100 mark for the first time. What is the difference between a limited scope and a full scope defined contribution plan audit? A limited scope audit, now often called a Section 103(a)(3)(C) audit, relies on a qualifying trustee's certification of investment data rather than independent testing. A full scope audit requires the auditor to independently verify investment valuations, which generally increases cost and fieldwork time. Why do defined contribution plan audits often find issues with contribution timing? The Department of Labor treats delayed remittance of employee contributions as a fiduciary breach, even for short delays. This is one of the most frequently cited findings in EBP audits because many plan sponsors do not have a documented, consistent remittance timeline. Does a first-year define contribution plan audit cost more than a repeat audit? Yes, typically. A first-year audit requires the auditor to build an understanding of plan documents, processes, and prior history from scratch, since there are no prior-year workpapers to reference, which generally increases the time and cost involved. Who is responsible for selecting a qualified defined contribution plan auditor? The plan sponsor, acting as a fiduciary, is responsible for selecting a qualified, independent auditor. This responsibility cannot be fully delegated to a recordkeeper or third-party administrator without sponsor oversight.
An Employee Benefit Plan (EBP) audit is an independent examination of a retirement or welfare benefit plan's financial statements and operations, required under ERISA for plans with 100 or more eligible participants, and the audit only goes smoothly when every party involved, the plan sponsor, the recordkeeper, HR and payroll, and the auditor, understands exactly what they are responsible for. Most plan sponsors only interact with this process once a year, which is exactly why confusion about who provides what tends to slow the audit down. This guide organizes the entire process by responsibility, not by audit phase, so plan sponsors know precisely what to prepare and who to ask when something is missing. The plan sponsor bears ultimate fiduciary responsibility for the audit's quality, even though much of the work is performed by other parties. Understanding where that responsibility actually sits is the foundation of everything else in this guide. What the Plan Sponsor Is Responsible For The plan sponsor, typically the employer offering the plan, is legally responsible for selecting a qualified, independent auditor and for the overall integrity of the audit process, even when most of the day-to-day coordination is handled by HR, finance, or an outsourced administrator. This responsibility cannot be fully delegated. The Department of Labor has been explicit that fiduciaries who hire an unqualified auditor, or who fail to review the auditor's qualifications and the final report, can be held responsible for resulting deficiencies. Practically, this means the plan sponsor should review the auditor's specific EBP audit experience before engagement, not just their general audit credentials, since a CPA firm with strong general audit experience but limited EBP-specific volume is statistically more likely to produce a deficient audit according to past Department of Labor studies on audit quality across the profession. The plan sponsor should also personally review the final audit report and any management letter before it is filed with Form 5500, rather than treating the auditor's sign-off as the final step requiring no further sponsor involvement. What the Recordkeeper or Third-Party Administrator Handles The recordkeeper or third-party administrator (TPA) maintains the plan's transactional records: contributions received, distributions processed, loan activity, and investment transactions. During an audit, the recordkeeper typically provides the trust statements, transaction detail reports, and participant-level data the auditor needs to test against the plan's records. A common friction point is timing: recordkeepers often have a standard turnaround time for producing audit-specific reports, and if the plan sponsor does not request these reports early in the audit cycle, the recordkeeper's response time becomes the bottleneck that delays the entire engagement. Plan sponsors working with a recordkeeper for the first time, or going through a recordkeeper transition during the plan year, should flag this early, since a mid-year recordkeeper change typically requires reconciling data from two separate systems for the audit period. One responsibility that is easy to overlook sits at the boundary between the recordkeeper and the sponsor: the SOC 1 (System and Organization Controls 1) report. The recordkeeper should provide a SOC 1 report describing the controls at its service organization, which the auditor uses to assess those controls rather than testing them from scratch. That report also lists complementary user entity controls (CUECs), the control activities the plan sponsor is expected to perform on its side depending on the applicability of CUEC. Confirming those user entity controls are actually in place is the sponsor’s responsibility, and a gap here can create a finding even when the recordkeeper’s own controls are sound. What HR and Payroll Need to Prepare HR and payroll functions own the data that connects employee status to plan eligibility: hire dates, termination dates, compensation used for plan contribution calculations, and eligibility determinations. Auditors test a sample of employees against this data to confirm that the plan correctly applied its own eligibility and contribution rules, which means inconsistent or incomplete personnel records create audit findings even when the retirement plan itself was administered correctly. The most frequent issue in this category is a mismatch between the compensation definition used for payroll purposes and the compensation definition specified in the plan document, particularly when bonuses, overtime, or other variable pay components are excluded from contribution calculations inconsistently across employees. Reconciling payroll's compensation definition against the plan document before the audit begins, rather than during fieldwork, avoids a finding that otherwise takes considerable back-and-forth to resolve and document. A practical way to compress the timeline is to assemble the standard audit request list before fieldwork begins. Auditors typically need: the signed plan document and all amendments, the current SOC 1 report from the recordkeeper, trust and custodial statements, the year-end census file, payroll registers reconciled to the plan’s compensation definition, contribution remittance records showing deposit dates, distribution and loan documentation, and the draft Form 5500. Having these ready in one place, reconciled, is the single biggest factor in how smoothly the audit runs. What the Auditor Actually Tests During Fieldwork The auditor's fieldwork centers on five core areas: plan financial statement balances, contribution testing, including timeliness of remittance, distribution and loan testing against plan document terms, eligibility and enrollment testing, and investment valuation, with the depth of investment testing depending on whether the engagement is an  ERISA Section 103(a)(3)(C) audit (Formerly know as limited scope) or Non-ERISA Section 103(a)(3)(C) audit (Formerly known as full scope audit). Contribution remittance timing deserves specific attention because it is consistently one of the most cited findings in EBP audits nationally. The Department of Labor's guidance treats delayed deposit of employee contributions withheld from payroll as a fiduciary breach, and auditors are required to test the actual time elapsed between withholding and deposit against the plan's established remittance pattern, not against a generic regulatory deadline. Plan sponsors who do not have a documented, consistent remittance schedule make this testing area harder to clear cleanly. What Happens After the Audit Report Is Issued The signed audit report and the auditor's opinion are attached to Form 5500 as part of the annual filing. If the auditor issues a qualified, adverse, or disclaimed opinion, or if a management letter identifies operational deficiencies, the plan sponsor needs a documented plan for addressing those findings before the next audit cycle, since unresolved findings carried forward year after year tend to draw additional regulatory scrutiny. Plan sponsors should also use this period to review whether the audit process itself ran efficiently. If specific data requests took unusually long to fulfill, or if the same finding keeps recurring, that is the signal to fix the underlying process, whether it is a payroll reconciliation gap or a recordkeeper reporting delay, well before the next plan year closes, rather than waiting until the next audit surfaces it again. A note for plans undergoing their first audit: a first-year engagement generally requires the auditor to establish that the opening balances are fairly stated, which can mean additional procedures over the prior period that was never audited. This is a common surprise for sponsors and is part of why a first-year audit typically takes more time and costs more than a recurring one. Flagging a first-year plan to the auditor early lets both sides plan for this. Common Fiduciary Mistakes That Lead to DOL Attention A few patterns show up repeatedly in plans that draw additional Department of Labor scrutiny. Hiring an auditor based primarily on price rather than EBP-specific experience is one of the most consequential, since the Department of Labor has specifically flagged audit quality variance tied to how much EBP audit volume a given CPA firm actually handles. Treating the 80-120 participant rule as a permanent exemption rather than a one-time buffer is another, where sponsors assume they remain a small plan indefinitely after using the exception once. Failing to document a consistent contribution remittance schedule and not reviewing the final audit report personally before filing rounds out the most common patterns. None of these mistakes is about dishonesty. They are almost always about treating the audit as an annual compliance task handled entirely by someone else, rather than a fiduciary responsibility the plan sponsor needs to stay actively engaged with. Where CPA Firms Can Get Outsourcing Support for EBP Audit Fieldwork For CPA firms performing these audits, the fieldwork-heavy testing areas described above, contribution remittance testing, distribution sampling, census data reconciliation, and workpaper preparation, are well-suited to structured outsourcing support, particularly during the concentrated filing season when EBP audit volume spikes sharply. This lets the engagement partner focus review time on judgment calls, like evaluating the severity of an exception or assessing investment valuation methodology, rather than the repetitive testing work that consumes most of an EBP engagement's hours. This is the core of what our Assurance & CPA Outsourcing practice supports for US CPA firms managing EBP audit engagements, working within the engaging firm's own methodology and review standards rather than as a generic offshore staffing arrangement. Frequently Asked Questions Who is legally responsible for the quality of an Employee Benefit Plan audit? The plan sponsor, acting as a fiduciary, is responsible for selecting a qualified auditor and reviewing the final audit report, even though the recordkeeper, payroll, and the auditor each handle specific pieces of the process. What is the most common finding in Employee Benefit Plan audits? Delayed remittance of employee contributions withheld from payroll is one of the most frequently cited findings, since the Department of Labor treats inconsistent or delayed deposit timing as a fiduciary breach regardless of intent. Why do payroll records matter so much in an EBP audit? Auditors test employee eligibility and contribution calculations against payroll and HR data. A mismatch between the plan document's compensation definition and how payroll actually calculates contributions creates findings even if the retirement plan itself was administered correctly. What should a plan sponsor do if the auditor issues a qualified or adverse opinion? The plan sponsor needs a documented remediation plan addressing the underlying issue before the next audit cycle, since unresolved findings carried forward year after year tend to draw additional regulatory attention. Can a CPA firm outsource parts of an Employee Benefit Plan audit? Yes. Fieldwork-heavy testing areas like contribution testing, distribution sampling, and workpaper preparation are commonly outsourced to specialized support teams working within the engaging firm's methodology, letting the engagement partner focus on judgment-heavy review work.
A Compilation Engagement involves applying accounting expertise to assist management in preparing and presenting financial information in the form of financial statements, without expressing any assurance on them. These are governed by SRS 4410 (Revised) and are often undertaken for small to mid-sized businesses where a full audit or review engagement is not required. Key considerations while performing a compilation engagement:  Ensure you are independent as required by relevant ethical standards. Gain basic knowledge of the client’s business, industry, and accounting policies to compile relevant and accurate statements. Clarify that management is responsible for the financial statements and the accuracy of the underlying data. Do not perform audit or review procedures such as testing transactions or confirming balances. Always obtain a written engagement letter detailing the nature and limitations of the engagement. If the statements are to be used by third parties, ensure that the users understand no assurance is provided. Clearly state in the compilation report that no assurance is provided.
  • 3-4 Min Read
Standard Setters' Update | 6-8 Min Read Transparent financial reporting depends on more than accurate top-line numbers. Investors, lenders, and other capital providers rely on financial statements to evaluate a company's performance, assess its prospects for future cash flows, and benchmark it against peers, and a critical part of that evaluation is understanding what actually makes up a company's expenses. Expense composition reveals cost structure, operational efficiency, and long-term sustainability in ways that a single aggregated number cannot. Historically, U.S. GAAP did not require consistent disaggregation of income statement expenses, which left companies free to report at very different levels of detail. That inconsistency made it genuinely difficult for investors and analysts to compare financial results across entities and industries, since one company's "operating expenses" line might hide detail another company discloses openly. How the Expense Disaggregation Requirement Came to Be FASB first addressed this gap in July 2023, introducing a proposed Accounting Standards Update titled Income Statement, Reporting Comprehensive Income, Expense Disaggregation Disclosures (Subtopic 220-40): Disaggregation of Income Statement Expenses. After gathering extensive feedback through public comment periods and roundtable discussions with preparers, investors, and auditors, FASB finalized the amendments as ASU 2024-03 in November 2024. The goal is straightforward: enhance the decision-usefulness of financial reporting by requiring companies to disclose disaggregated expense detail within the footnotes of their financial statements, giving users of financial statements a clearer view of cost composition than aggregated income statement line items alone can provide. ASU 2025-01: Clarifying When the Requirement Actually Applies In January 2025, FASB issued ASU 2025-01, Income Statement, Reporting Comprehensive Income, Expense Disaggregation Disclosures (Subtopic 220-40): Clarifying the Effective Date. This update did not change the substance of the disaggregation requirement itself. It resolved confusion about exactly when the requirement takes effect, particularly around how it applies to interim reporting periods. The clarified effective dates are: Annual reporting periods: beginning after December 15, 2026 Interim reporting periods: within annual reporting periods beginning after December 15, 2027 Early adoption is permitted for companies that want to get ahead of the requirement rather than wait for the mandatory effective date. The updates apply to all public business entities, without exception based on size or industry. What This Means for Finance and Reporting Teams Even with effective dates that sit a full reporting cycle or more away, the practical work behind expense disaggregation is not something to defer until the deadline approaches. Building the general ledger structure, cost allocation methodology, and reconciliation process needed to disaggregate expenses credibly, and to reconcile those disaggregated figures back to totals already reported in the financial statements, is a multi-quarter undertaking for most organizations, not a footnote drafted at year-end close. Companies should treat the extended effective date as planning time, not slack in the schedule. Early adopters in particular may find that getting ahead of the requirement gives them a cleaner comparative baseline once the mandatory effective date arrives, rather than a first year of disclosure that reads as rushed against prior periods that used a different level of detail. Frequently Asked Questions What is expense disaggregation under ASU 2024-03? ASU 2024-03 requires public business entities to disaggregate expenses in the income statement into specific categories and reconcile those figures to the totals already reported in the financial statements, disclosed within the footnotes. When does the expense disaggregation requirement take effect? Under ASU 2025-01's clarified effective dates, annual reporting periods beginning after December 15, 2026 must comply, with interim reporting periods within annual reporting periods beginning after December 15, 2027 also required to comply. Early adoption is permitted. What did ASU 2025-01 change compared to ASU 2024-03? ASU 2025-01 did not change the substance of the disaggregation requirement. It clarified the effective date, resolving confusion about how the requirement applied to interim reporting periods specifically. Why did FASB introduce expense disaggregation disclosure requirements? Because U.S. GAAP historically did not require consistent disaggregation of income statement expenses, creating diversity in reporting practices that made it difficult for investors to compare cost structures and operational efficiency across companies and industries. Does the expense disaggregation requirement apply to all companies? It applies to all public business entities, regardless of size or industry, with no exceptions carved out in the standard. Who should be preparing for this requirement now? CFOs, controllers, and financial reporting teams at public business entities, particularly those whose general ledger systems are not currently structured to produce reconciled expense detail at the category level the standard requires. Talk to Our Team Preparing your general ledger and reporting processes for expense disaggregation compliance ahead of the 2026 and 2027 effective dates? Pierag's Accounting Advisory practice helps finance teams build the data structure and reconciliation processes this standard requires, well ahead of the deadline. Talk to our team about your reporting readiness. Related reading: Standard Setters' Updates, H2 2025 Edition | Understanding DISE: Disaggregation of Income Statement Expenses
  • 5-10 Min Read
Point of View | 6-8 Min Read Transparent financial reporting depends on more than accurate top-line numbers. Investors, lenders, and other capital providers rely on financial statements to evaluate a company's performance, assess its prospects for future cash flows, and benchmark it against peers, and a critical part of that evaluation is understanding what actually makes up a company's expenses. Expense composition reveals cost structure, operational efficiency, and long-term sustainability in ways that a single aggregated number cannot. Historically, U.S. GAAP did not require consistent disaggregation of income statement expenses, which left companies free to report at very different levels of detail. That inconsistency made it genuinely difficult for investors and analysts to compare financial results across entities and industries, since one company's "operating expenses" line might hide detail another company discloses openly. This is the gap DISE, the Disaggregation of Income Statement Expenses requirement, was built to close. How DISE Came to Be FASB first addressed this gap in July 2023, introducing a proposed Accounting Standards Update titled Income Statement, Reporting Comprehensive Income, Expense Disaggregation Disclosures (Subtopic 220-40): Disaggregation of Income Statement Expenses. After gathering extensive feedback through public comment periods and roundtable discussions with preparers, investors, and auditors, FASB finalized the amendments as ASU 2024-03 in November 2024. The goal is straightforward: enhance the decision-usefulness of financial reporting by requiring companies to disclose disaggregated expense detail within the footnotes of their financial statements, giving users of financial statements a clearer view of cost composition than aggregated income statement line items alone can provide. ASU 2025-01: Clarifying When DISE Actually Applies In January 2025, FASB issued ASU 2025-01, Income Statement, Reporting Comprehensive Income, Expense Disaggregation Disclosures (Subtopic 220-40): Clarifying the Effective Date. This update did not change the substance of the disaggregation requirement itself. It resolved confusion about exactly when the requirement takes effect, particularly around how it applies to interim reporting periods. The clarified effective dates are: Annual reporting periods: beginning after December 15, 2026 Interim reporting periods: within annual reporting periods beginning after December 15, 2027 Early adoption is permitted for companies that want to get ahead of the requirement rather than wait for the mandatory effective date. The updates apply to all public business entities, without exception, based on size or industry. What DISE Requires in Practice At its core, DISE requires public business entities to disaggregate expenses reported in the income statement into specific, defined categories and to reconcile those disaggregated figures back to the totals already reported in the financial statements. Rather than a single "cost of revenue" or "operating expenses" line, users of the financial statements will be able to see the underlying components that build up to those totals, disclosed within the footnotes. This is a meaningfully different level of transparency than most companies currently provide, which is why the practical implementation work matters more than the disclosure itself. What This Means for Finance and Reporting Teams Even with effective dates that sit a full reporting cycle or more away, the practical work behind DISE compliance is not something to defer until the deadline approaches. Building the general ledger structure, cost allocation methodology, and reconciliation process needed to disaggregate expenses credibly, and to reconcile those disaggregated figures back to totals already reported in the financial statements, is a multi-quarter undertaking for most organizations, not a footnote drafted at year-end close. Companies should treat the extended effective date as planning time, not slack in the schedule. Early adopters in particular may find that getting ahead of the requirement gives them a cleaner comparative baseline once the mandatory effective date arrives, rather than a first year of disclosure that reads as rushed against prior periods that used a different level of detail. Frequently Asked Questions What is DISE in accounting? DISE stands for Disaggregation of Income Statement Expenses, a FASB requirement under ASU 2024-03 that requires public business entities to break down income statement expenses into specific categories and reconcile them to the totals already reported in the financial statements. When does DISE take effect? Under ASU 2025-01's clarified effective dates, annual reporting periods beginning after December 15, 2026, must comply, with interim reporting periods within annual reporting periods beginning after December 15, 2027, also required to comply. Early adoption is permitted. What did ASU 2025-01 change compared to ASU 2024-03? ASU 2025-01 did not change the substance of the DISE requirement. It clarified the effective date, resolving confusion about how the requirement applied to interim reporting periods specifically. Why did FASB introduce the DISE requirement? Because U.S. GAAP historically did not require consistent disaggregation of income statement expenses, creating diversity in reporting practices that made it difficult for investors to compare cost structures and operational efficiency across companies and industries. Does DISE apply to all companies? It applies to all public business entities, regardless of size or industry, with no exceptions carved out in the standard. Who should be preparing for DISE now? CFOs, controllers, and financial reporting teams at public business entities, particularly those whose general ledger systems are not currently structured to produce reconciled expense detail at the category level, the standard requires. Talk to Our Team Preparing your general ledger and reporting processes for DISE compliance ahead of the 2026 and 2027 effective dates? Pierag's Accounting Advisory practice helps finance teams build the data structure and reconciliation processes this standard requires, well ahead of the deadline. Talk to our team about your reporting readiness. Related reading: Standard Setters' Updates, H2 2025 Edition | Audit Trail: Ensuring Financial Integrity and Accountability
  • 5 min Read
Explore how audits empower healthcare providers to tackle AI risks, policy shifts, and pricing reforms with confidence.
  • 10-12 Min Read
Explore the fundamentals and practical relevance of review engagements in today’s financial landscape.
  • 7-9 Min Read
From market trends and HUD updates to our tailored audit approach, discover how you can enhance transparency, mitigate risk, and strengthen investor confidence in today’s real estate landscape.
  • 5-7 Min Read
Point of View | 8-10 Min Read Nonprofit organizations play a vital role in creating impact, but ensuring financial transparency and regulatory compliance remains a genuine, ongoing challenge. Nonprofits must navigate a layered set of financial and regulatory requirements to demonstrate transparency, accountability, and operational efficiency to funders, donors, and regulators alike, and the rules governing that oversight have shifted meaningfully over the past two years. This guide covers the audit types nonprofits most commonly encounter, the federal compliance landscape as it actually stands in 2026, and how organizations can build the readiness to handle both. Financial Statement Audits: The Foundation of Nonprofit Assurance A financial statement audit examines whether an organization's financial statements are fairly presented in accordance with GAAP, along with the strength of the internal controls supporting that reporting. For nonprofits specifically, this means attention to fund accounting, net asset classification, and the accuracy of how restricted and unrestricted funds are tracked and reported, areas that differ meaningfully from for-profit financial reporting. A clean financial statement audit does more than satisfy a compliance requirement. It signals to donors, board members, and funders that the organization's financial reporting can be trusted, which directly affects an organization's ability to secure future grants and major gifts. Uniform Guidance Audits (Single Audits): What Changed and Why It Matters Now For federally funded nonprofits, the Single Audit is the most consequential compliance requirement to understand, and the rules governing it changed significantly in 2024 and continue evolving through 2026. The threshold increased. As of October 1, 2024, the federal Single Audit threshold rose from $750,000 to $1,000,000 in federal awards expended during a fiscal year, the first increase since 2003 and the most significant revision to the Uniform Guidance (2 CFR Part 200) since it was originally issued in 2013. Organizations spending less than $1 million in federal funds annually are no longer required to undergo a Single Audit, though they must still follow all underlying Uniform Guidance requirements, including procurement standards, subrecipient monitoring, and allowable cost principles. Dual compliance is a real, practical issue. Because the new threshold applies only to federal awards issued on or after October 1, 2024, organizations holding a mix of older and newer awards must track which threshold applies to which award. A nonprofit combining an older $750,000-threshold award with a newer $1 million-threshold award could still trigger a Single Audit even while spending less than $1 million in total federal funds, depending on how the awards are structured. This dual-compliance environment is expected to persist through at least 2026 for organizations with multi-year grants that straddle the effective date. The de minimis indirect cost rate increased too. Organizations without a federally negotiated indirect cost rate can now recover 15 percent of modified total direct costs as indirect expenses, up from 10 percent, a change that meaningfully improves cost recovery for smaller and less experienced federal award recipients. Further changes are already in motion. OMB published a proposed overhaul of the Uniform Guidance on May 29, 2026, with a comment period running through July 13, 2026, and a final rule expected around October 1, 2026. The proposal does not change the indirect cost rate or the Single Audit threshold itself, but it would expand federal agencies' authority to terminate awards and add new review and conditions requirements before awards are issued. Nonprofits relying on federal funding should treat this as an active development to monitor, not a settled rule, until the final version is published. Grant Compliance Audits: Best Practices Beyond the Single Audit Threshold Even organizations below the federal Single Audit threshold routinely face grant-specific compliance audits driven by individual funder requirements. Best practices for grant compliance include maintaining accurate financial reporting tied directly to each grant's budget and terms, documenting internal controls over how grant funds are allocated and spent, and ensuring regulatory adherence to program-specific requirements that may exceed general Uniform Guidance standards. Common areas that generate audit findings include time-and-effort reporting that does not meet 2 CFR Part 200 requirements, procurement procedures that bypass competitive bidding thresholds, unallowable costs charged to federal programs, and late or incomplete financial reports to funding agencies. Organizations that build these controls into routine financial operations, rather than reconstructing documentation at audit time, consistently experience fewer findings and faster audit turnaround. The Changing Landscape: Federal Funding and Tax Updates Nonprofits Need to Track in 2026 Beyond the Uniform Guidance changes already discussed, several other 2026 developments affect nonprofit compliance and funding strategy directly. Charitable giving tax changes took effect. Beginning in 2026, taxpayers who do not itemize deductions may deduct certain cash gifts to qualified charities up to IRS limits, a change that could broaden small-dollar donor participation. At the same time, taxpayers who do itemize can now only deduct charitable contributions to the extent those contributions exceed 0.5 percent of adjusted gross income, meaning some larger, itemizing donors may see reduced tax benefit from smaller gifts. Development teams should factor both changes into donor messaging and campaign planning. Executive compensation and endowment excise taxes expanded. The excise tax on compensation exceeding $1 million paid to a nonprofit's five highest-paid employees, retroactive to 2017 under existing law, continues to apply, and colleges with large endowments now face a graduated excise tax schedule on endowment investment income that can reach as high as 14 percent, up from a previous flat 1.4 percent rate. Proposed grant-condition changes remain unresolved. OMB's May 2026 proposed overhaul, alongside separate proposals affecting how federal agencies review and condition grant awards, has drawn concern from nonprofit advocacy groups regarding potential disruption to federally funded community programs. Organizations should treat these as proposals in active comment periods, not finalized policy, and plan primarily around what is currently in force. Future Readiness: Adapting to Shifting Funding and Compliance Demands Nonprofits that are best positioned for what comes next in this landscape share a few common practices: they track federal awards by issue date to correctly apply Uniform Guidance thresholds, they maintain audit-ready documentation year-round rather than reconstructing it during audit season, and they monitor active regulatory proposals like OMB's 2026 Uniform Guidance overhaul closely enough to adjust before a final rule takes effect rather than after. Technology adoption, particularly for grant tracking, cost allocation, and subrecipient monitoring, is increasingly what separates organizations that handle these shifting requirements smoothly from those that scramble each audit cycle. Frequently Asked Questions What is the current federal Single Audit threshold for nonprofits? As of October 1, 2024, the federal Single Audit threshold is $1,000,000 in federal awards expended during a fiscal year, up from the previous $750,000 threshold. Do all nonprofits need a Single Audit? No. Only nonprofits that expend $1,000,000 or more in federal awards during their fiscal year are required to undergo a Single Audit. Organizations below that threshold must still follow Uniform Guidance requirements but are not required to commission the formal audit. What is the de minimis indirect cost rate for nonprofits in 2026? Organizations without a federally negotiated indirect cost rate can recover 15 percent of modified total direct costs as indirect expenses, increased from the previous 10 percent rate. What changes are proposed for the Uniform Guidance in 2026? OMB proposed a further overhaul of the Uniform Guidance on May 29, 2026, with comments accepted through July 13, 2026 and a final rule expected around October 1, 2026. The proposal does not change the Single Audit threshold or indirect cost rate but would expand agencies' authority over award termination and conditions. How does the 2026 charitable giving deduction change affect nonprofits? Non-itemizing taxpayers can now deduct certain cash gifts up to IRS limits, potentially broadening small-dollar donor participation, while itemizing donors can only deduct contributions exceeding 0.5 percent of their adjusted gross income, which may reduce the tax benefit of smaller gifts for some donors. What's the difference between a financial statement audit and a Single Audit? A financial statement audit examines whether an organization's financial statements are fairly presented under GAAP. A Single Audit goes further, testing compliance with the specific requirements attached to each federal program the organization received funding from, in addition to the financial statement audit itself. Get the Full Point of View This overview covers the key aspects of nonprofit audits and the regulatory landscape as it stands in 2026. The complete point of view includes deeper guidance on preparing for each audit type and practical recommendations for building long-term compliance readiness. Navigating the Single Audit threshold, dual-compliance award tracking, or upcoming Uniform Guidance changes? Pierag's  Assurance practice helps nonprofits build audit readiness for the current federal compliance landscape. Talk to our team about your nonprofit audit needs. Related reading: Review Engagements vs Audits: A 2026 Guide | Audit Trail: Ensuring Financial Integrity and Accountability
  • 3-5 Min Read
Point of View | 8-10 Min Read In today's volatile economic environment, companies with outstanding debt are increasingly navigating complex restructuring situations. One of the most significant is a Troubled Debt Restructuring, where a creditor grants a concession to a debtor experiencing financial difficulty that would not normally be offered under standard lending terms. Understanding the accounting, governance, and strategic implications of a TDR can make the real difference between a company's collapse and its comeback. A TDR occurs when a creditor grants a concession to a debtor facing financial difficulty, a concession made to preserve as much of the creditor's investment as possible. The underlying logic is straightforward: receiving partial repayment is better than receiving nothing at all. If modifying the original terms is the only realistic path for a lender to recover any portion of the outstanding debt, the lender may agree to a TDR rather than pursue default or foreclosure. How TDR Accounting Actually Works: Debtor and Creditor Sides Are Different Restructuring debt due to a borrower's financial difficulty creates real accounting complexity, and the two sides of the transaction are governed by different guidance, a distinction worth being precise about. On the debtor's side, a company restructuring its own debt continues to apply ASC 470-60, Debt, Troubled Debt Restructurings by Debtors. This guidance remains active and governs how a debtor accounts for a modification of its own obligations, including situations involving a reduction of stated interest rate, extension of maturity date, reduction of face amount, or reduction of accrued interest. On the creditor's side, the picture changed significantly. FASB issued ASU 2022-02 in 2022, which eliminated the recognition and measurement guidance for TDRs by creditors entirely, for any entity that has adopted the Current Expected Credit Loss standard (ASC 326). This change is now fully implemented across the industry, effective for fiscal years beginning after December 15, 2022 for most entities that had already adopted CECL. Rather than classifying a modification as a TDR, creditors now evaluate loan modifications under ASC 310-20's guidance on loan refinancing and restructuring, determining whether a modification represents a new loan or a continuation of an existing one, while providing enhanced disclosures under ASC 326-20 about modifications made to borrowers experiencing financial difficulty. In practice, this means the term "TDR" itself has largely retired from creditor-side financial reporting, even though the economic substance, a lender making concessions to a distressed borrower, is unchanged. How US GAAP, IFRS, and IGAAP Compare on Debt Restructuring Different accounting frameworks treat borrower distress restructuring in meaningfully different ways, and understanding these differences matters for any company or lender operating across jurisdictions. Framework Terminology Core Approach US GAAP Formally uses "Troubled Debt Restructuring" on the debtor side (ASC 470-60); creditor side now uses modification and impairment guidance (ASC 310-20, ASC 326) following ASU 2022-02 Distinct debtor-specific TDR classification; creditor treatment folded into general modification and credit loss framework IFRS Does not use the term TDR explicitly Addressed through IFRS 9's financial instrument modification and derecognition guidance, testing whether a modification is substantial enough to require derecognition of the original liability and recognition of a new one Indian GAAP (IGAAP) / Ind AS Does not use the term TDR explicitly Addressed through Ind AS 109's modification and derecognition framework, broadly aligned with IFRS 9, alongside sector-specific regulatory frameworks such as RBI's prudential norms on restructuring for regulated lenders The practical takeaway: US GAAP is the only major framework that names and separately codifies TDR treatment, and even within US GAAP, that separate treatment now applies only to the debtor's side of the transaction. IFRS and IGAAP fold economically similar situations into their broader financial instrument modification standards rather than creating a distinct restructuring classification. Why This Distinction Matters for Companies and Lenders For companies preparing to restructure debt, understanding which side of the transaction you sit on, and which guidance actually applies, is not a technicality. A debtor restructuring its own obligations still walks through ASC 470-60's specific criteria and disclosure requirements. A creditor extending concessions no longer classifies that concession as a TDR for recognition and measurement purposes, but still faces meaningful new disclosure obligations under ASC 326-20 about the nature and financial effect of the modification. Companies operating across US GAAP, IFRS, and IGAAP reporting environments simultaneously, such as multinational groups with both US and Indian subsidiaries, need to apply the correct framework-specific test to each entity's restructuring, since the frameworks do not map onto each other cleanly despite addressing similar economic events. Frequently Asked Questions What is a Troubled Debt Restructuring? A TDR occurs when a creditor grants a concession to a debtor experiencing financial difficulty that would not normally be offered under standard lending terms, made to preserve as much of the creditor's investment as possible rather than risk receiving nothing. Does ASC 470-60 govern creditor accounting for TDRs? No. ASC 470-60 governs the debtor's accounting for a troubled debt restructuring. Creditor-side TDR recognition and measurement guidance was eliminated by ASU 2022-02 for entities that have adopted CECL, replaced by modification accounting under ASC 310-20 and disclosures under ASC 326-20. What changed under ASU 2022-02? ASU 2022-02 eliminated troubled debt restructuring recognition and measurement guidance for creditors that have adopted the Current Expected Credit Loss standard, requiring them instead to evaluate modifications under general loan refinancing and restructuring guidance while disclosing enhanced information about modifications to borrowers experiencing financial difficulty. Does IFRS use the term Troubled Debt Restructuring? No. IFRS addresses economically similar situations through IFRS 9's modification and derecognition guidance, testing whether a debt modification is substantial enough to require derecognizing the original liability and recognizing a new one, without a separately named TDR classification. How does Indian GAAP treat debt restructuring for distressed borrowers? Indian GAAP, through Ind AS 109, addresses debt modification through a derecognition and modification framework broadly aligned with IFRS 9, and regulated lenders are additionally subject to RBI's prudential norms on restructuring. Who needs to understand the TDR accounting distinction between debtors and creditors? CFOs and finance teams of companies restructuring their own debt, credit and finance teams at lending institutions extending concessions, and auditors and advisors working across US GAAP, IFRS, and IGAAP reporting environments all need clarity on which side of a restructuring they are accounting for and which guidance applies. Get the Full Point of View This overview covers the key accounting and framework distinctions in debt restructuring. The complete point of view includes deeper guidance on governance considerations, strategic implications, and practical steps for companies navigating a restructuring situation. Navigating a debt restructuring situation or preparing disclosures under the current TDR and modification accounting framework? Pierag's Accounting Advisory practice helps companies and lenders apply the correct guidance across US GAAP, IFRS, and IGAAP reporting environments. Talk to our team about your restructuring and reporting needs. Related reading: Standard Setters' Updates, H2 2025 Edition | Understanding DISE: Disaggregation of Income Statement Expenses
  • 8-9 Min Read
Driving Impact
Our Assurance
Leadership team
cross-icon
Sanchit Gupta
Sanchit Gupta
Partner - COO & Assurance Leader
Carrying experience of over 15 years, Sanchit is a Business Strategist with credentials for setting up innovative and scalable business growth solutions. Having prior work experience with EY and investing 3 years in Houston, Texas on a large SEC filer client in the Oil & Gas sector as part of an international assignment gave Sanchit different perspectives and opportunities to work with professionals from diverse cultural backgrounds from across the globe. Sanchit brings a unique blend of his analytical, management and leadership skills to the table. Working with Pierag Consulting, he is the architect of the business and front lead operating models, firm-level policies, client-level and firm-level standard operating procedures, mobility planning, capacity planning, learning and development to enhance quality delivery, performance evaluation of the team, asset management, review of business performance, firm economics, identification, and Implementation of new technologies. Growing as a good time-manager coupled with a futuristic approach, Sanchit reflects upon his interests to fuel his curiosity with readings on economics, self-help, finance, and leadership. In moments of reflection, Our Director finds solace in the soothing melodies of meditational music in the open air, providing a tranquil escape from the demands of everyday life. Encountering every challenge that comes across through journaling, Sanchit approaches each decision with calculative precision, ensuring success at every turn.He maintains a solution-oriented mindset, an extra inclination towards technology, and goes by a belief that patience combined with smart work leads to triumph. But it’s not all about numbers and the strategy – Sanchit is also a symbol of prevalence and determination, having completed a challenging 10km marathon. And now, amidst the hustle and bustle of professional life, he has reignited his childhood passion for cycling, thus embracing the joy of movement while maintaining a healthy mindset. Outside the office, Our Director embraces life’s simple pleasures, enjoying leisurely walks on weekends, regularly practicing fitment routines, and exploring diverse cuisines. Having explored the fair part of the US, Europe, and India, he extends his desire to travel the world and engage in different cultures and food.
Professional Qualifications and Certifications:
  • Chartered Accountant
  • Certified Public Accountant (AICPA)
  • Company Secretary
  • Chief Financial Analyst
  • Bachelor of Commerce
Expertise:
  • Assurance (Statutory Audits)
  • Data Analytics
  • Client Sectors include Oil & Gas, Technology, Consumer Retail and E-Commerce
cross-icon
Nitin Ahuja
Nitin Ahuja
Associate Director - Assurance
Nitin Ahuja is an Associate Director in the Assurance practice at Pierag Consulting, possessing over a fourteen years of comprehensive experience in auditing practices governed by US GAAP, IFRS, and Indian GAAP. He is widely acknowledged as a distinguished expert in the social sector, with a particular focus on audits of Non-Profit Organizations (NPOs), Single Audits, and Employee Benefit Plans, providing his proficient services to a diverse clientele spanning the United States and India.  In addition to his extensive audit expertise, Nitin has been instrumental in the development of social audit frameworks as a consultant to the Institute of Chartered Accountants of India, demonstrating a profound commitment to advancing the field of social audits in India. His professional engagements are further distinguished by his role as a Faculty Member on the Social Auditors Certification Course at the Institute of Social Auditors of India, where he contributes to the education and certification of social auditors, underscoring his authoritative standing in this specialized domain.  Throughout his tenure at EY Global Delivery Services, Nitin successfully led the Healthcare and Not for Profit sectors within the US-Central region, where he was responsible for formulating and executing strategic audit plans, delivering rigorous regulatory compliance training, and spearheading client pursuit initiatives. His skillset extends to advanced data analytics, implementation of evolving accounting standards, and enhancing project margins, collectively enhancing the value he delivers to his clients.  A qualified Chartered Accountant, Nitin is renowned for his leadership capabilities in managing complex audit assignments and his dedication to the continuous professional development of his teams. His contributions exemplify a blend of technical excellence, strategic foresight, and unwavering commitment to achieving operational excellence and regulatory compliance across varied industry sectors. 
Ready to Enhance Your Financial Integrity and Stakeholder Trust?
Partner with Pierag Consulting for reliable, insightful, and comprehensive assurance solutions.