Grant drawdowns: federal money moving on a portal session
A grantee draws federal cash by logging into a payment management system and entering an amount. The authorising official named in the registration is a record updated by correspondence, and the subaward chain beneath them exists only in agreements nobody reads until a single audit.
Who authorised a federal grant drawdown?
A user holding a grantee role in a payment management system. Authority to request federal funds is expressed as a permission, and the chain from a drawdown to a named person with the authority to request that money is thin enough that a compromised portal session completes it.
- Payment systems authenticate users and check award balances. The authorising official is a registration record, not a per-drawdown act.
- Subaward authority lives in agreements and is invisible to the agency, which is precisely where GAO's 2026 fraud-risk work points.
- Delegation with amount ceilings and expiry makes the escalation the quality agreement already requires into something enforced rather than remembered.
Part of Public sector identity
The chain, drawn
Federal funds reach a service delivery point through a chain that nobody holds end to end.
agency award
└─ prime grantee [authorising official on file, registration record]
└─ subrecipient A [subaward agreement]
└─ subrecipient B [sub-subaward agreement]
└─ service delivery
The agency has visibility of the first link. The prime has visibility of the second. Nobody has visibility of the third in real time, and the single audit examines it annually in sample.
What a drawdown actually requires
A user with a grantee role in the payment management system, an award with an available balance, and an amount. The system checks the balance and the role. It does not check whether the person requesting has authority for this amount, or whether the authorising official on file still works there.
| Control | What it checks | What it misses |
|---|---|---|
| Role-based access | That the user holds a grantee role | Whether they may request this amount |
| Award balance check | That funds remain | Whether the drawdown matches actual expenditure |
| Registration record | Who the authorising official is | Whether they still hold the role |
| Single audit | A sample, annually | The other 99% of transactions and 364 days |
Where the 2026 attention landed
GAO's July 2026 work on managing fraud risks in federally funded programs sharpened attention on how funds move from agencies through grantees to subrecipients. Uniform Guidance at 2 CFR Part 200 already requires prime recipients to monitor subrecipients, and the Framework for Managing Fraud Risks in Federal Programs sets expectations for control design.
The gap is not in the expectations. It is that monitoring is periodic and authority is unrepresented in any artefact that travels with a transaction.
The Drawdown Authority Chain
Express authority as a delegation with the three properties a registration record lacks.
delegation:
issuer: [authorising official, credential]
delegate: [named individual who requests drawdowns]
scope: awards = [list]
purpose = [cost categories]
limits: max_per_drawdown = [amount]
max_per_month = [amount]
notAfter: [12 months]
depth: 1 # may issue one level of subaward authority
Depth one is the substantive control. It permits the prime to delegate to a subrecipient and prevents that subrecipient from re-delegating further without a fresh grant — which is the point at which oversight currently evaporates silently.
What the single auditor gains
Today a single auditor testing subrecipient monitoring reviews agreements, risk assessments and monitoring documentation, and samples transactions. Establishing who had authority for a specific subaward transaction is a reconstruction exercise.
With a delegation chain, that question becomes a verification: the transaction references a delegation, the delegation is signed, and the chain terminates at a named authorising official at the prime. Verification is offline and requires no access to any party's systems.
A practical sequencing note
Do not begin with the whole subaward population. Begin with the awards that carry the most subaward dollars and the deepest chains, which in most portfolios is a small number.
- Rank awards by subaward dollars passed through.
- For the top decile, issue delegations rather than relying on registration records.
- Require subrecipients to reference the delegation on drawdown requests.
- Hand the resulting artefacts to your single auditor as a pilot and ask whether it shortens their testing.
That last step matters. If it does not reduce audit effort, the control is imposing cost without a measurable operational return, and that should change the decision.
Two fields, two different controls
| Field | Control today | Control needed |
|---|---|---|
| Drawdown amount | Bounded by the award | Adequate |
| Destination account | A profile field | A payment instruction |
| Requesting individual | A role | A named person with a signature |
| Purpose and period | Sometimes captured | Bound into the request |
Objections and honest limits
“The award ceiling limits the exposure.” It limits the amount, not the destination. A drawdown within the ceiling to a changed account is fully authorised and entirely lost.
“Grantees are known entities.” The organisation is. The individual holding the role at any moment, and whether their session is theirs, is the open question.
Binding a drawdown
- Gate the destination account separately. Higher bar than the drawdown itself.
- Require a signature from a named authorised official. Not a role-holder's session.
- Bind the amount, period and purpose. So a request rebuilt afterwards fails.
- Reconcile destinations across grantees. One account receiving several organisations' funds is the signal.
Terms used here
- Drawdown
- A grantee's request to receive federal funds already awarded.
- Payment management system
- The federal system through which grantees request and receive award funds.
- Authorised official
- The individual permitted to request funds on the grantee's behalf — a person, currently represented as a role.
Frequently asked questions
Does Uniform Guidance require this? No. It requires subrecipient monitoring and adequate internal control. The delegation chain is one way to evidence authority; it is not prescribed.
What about drawdowns for costs already incurred? The delegation governs who may request and how much, not what the funds are for. Cost allowability remains a separate determination.
Do subrecipients need to build anything? They need a credential and the ability to reference a delegation. Verification is performed by the prime and the agency, not by the subrecipient.
How does this interact with the single audit? It supplies verifiable artefacts for authority testing. Whether it reduces audit effort is testable and should be tested before scaling.
Does the award ceiling protect the funds? It bounds the amount, not the destination. A within-ceiling drawdown to a changed account is fully authorised and entirely lost.
What should be gated more tightly than the drawdown? The destination account. It is the field that redirects every future disbursement.
What is the strongest cross-grantee signal? One bank account receiving drawdowns for several unrelated organisations.
Where this fits in Manav
Manav binds the authorising official to the exact release, award or disbursement being authorised, and produces a receipt an inspector general, an auditor or another agency can verify without access to the issuing system.
Sources and further reading
- 2 CFR Part 200 — Uniform Administrative Requirements for Federal Awards
- GAO-15-593SP — A Framework for Managing Fraud Risks in Federal Programs
- GAO-26-109100, July 2026 — managing fraud risks in federally funded programs
- Federal payment management system documentation on drawdown processes.
- PaymentAccuracy.gov — federal improper payment data