{
 "slug": "drawdown-authority-chain",
 "topic_id": "TOPIC-193",
 "cluster": "Government Benefits, Procurement & Public Sector Identity",
 "tier": "Tier B",
 "title": "Grant drawdowns: federal money moving on a portal session",
 "summary": "Drawdowns are requested through payment management systems by users with grantee roles. Authority to request funds is a permission, and the chain to subrecipients is contractual and invisible to the agency.",
 "lede": "A grantee draws federal cash by logging into a payment management system and entering an amount. The authorising official named in the registration is a record updated by correspondence, and the subaward chain beneath them exists only in agreements nobody reads until a single audit.",
 "date": "2024-06-20",
 "category": "Compliance",
 "author_id": "solene-beaumont-adjei",
 "tags": [
  "grant drawdown",
  "Uniform Guidance",
  "subrecipient monitoring",
  "single audit",
  "federal grants",
  "authorised official"
 ],
 "image_title": "Drawdown Authority Chain",
 "schema": "Article",
 "key_takeaways": [
  "Payment systems authenticate users and check award balances. The authorising official is a registration record, not a per-drawdown act.",
  "Subaward authority lives in agreements and is invisible to the agency, which is precisely where GAO's 2026 fraud-risk work points.",
  "Delegation with amount ceilings and expiry makes the escalation the quality agreement already requires into something enforced rather than remembered."
 ],
 "body": [
  {
   "type": "h2",
   "text": "The chain, drawn"
  },
  {
   "type": "diagram",
   "kind": "flow",
   "alt": "From portal session to federal funds",
   "caption": "The authority is a role. The record is a session.",
   "nodes": [
    {
     "label": "User holds a grantee role",
     "note": "a permission"
    },
    {
     "label": "Portal session opens",
     "note": "authenticated once"
    },
    {
     "label": "Drawdown requested",
     "note": "within the award",
     "bad": true
    },
    {
     "label": "Funds disburse",
     "note": "to the account on file",
     "bad": true
    }
   ]
  },
  {
   "type": "p",
   "html": "Federal funds reach a service delivery point through a chain that nobody holds end to end."
  },
  {
   "type": "code",
   "text": "agency award\n   └─ prime grantee            [authorising official on file, registration record]\n        └─ subrecipient A       [subaward agreement]\n             └─ subrecipient B  [sub-subaward agreement]\n                  └─ service delivery"
  },
  {
   "type": "p",
   "html": "The agency has visibility of the first link. The prime has visibility of the second. Nobody has visibility of the third in real time, and the single audit examines it annually in sample."
  },
  {
   "type": "h2",
   "text": "What a drawdown actually requires"
  },
  {
   "type": "p",
   "html": "A user with a grantee role in the payment management system, an award with an available balance, and an amount. The system checks the balance and the role. It does not check whether the person requesting has authority for this amount, or whether the authorising official on file still works there."
  },
  {
   "type": "table",
   "head": [
    "Control",
    "What it checks",
    "What it misses"
   ],
   "rows": [
    [
     "Role-based access",
     "That the user holds a grantee role",
     "Whether they may request this amount"
    ],
    [
     "Award balance check",
     "That funds remain",
     "Whether the drawdown matches actual expenditure"
    ],
    [
     "Registration record",
     "Who the authorising official is",
     "Whether they still hold the role"
    ],
    [
     "Single audit",
     "A sample, annually",
     "The other 99% of transactions and 364 days"
    ]
   ]
  },
  {
   "type": "h2",
   "text": "Where the 2026 attention landed"
  },
  {
   "type": "p",
   "html": "GAO's July 2026 work on managing fraud risks in federally funded programs sharpened attention on how funds move from agencies through grantees to subrecipients. Uniform Guidance at 2 CFR Part 200 already requires prime recipients to monitor subrecipients, and the Framework for Managing Fraud Risks in Federal Programs sets expectations for control design."
  },
  {
   "type": "p",
   "html": "The gap is not in the expectations. It is that monitoring is periodic and authority is unrepresented in any artefact that travels with a transaction."
  },
  {
   "type": "h2",
   "text": "The Drawdown Authority Chain"
  },
  {
   "type": "p",
   "html": "Express authority as a delegation with the three properties a registration record lacks."
  },
  {
   "type": "code",
   "text": "delegation:\n  issuer:   [authorising official, credential]\n  delegate: [named individual who requests drawdowns]\n  scope:    awards = [list]\n            purpose = [cost categories]\n  limits:   max_per_drawdown = [amount]\n            max_per_month = [amount]\n  notAfter: [12 months]\n  depth:    1        # may issue one level of subaward authority"
  },
  {
   "type": "p",
   "html": "Depth one is the substantive control. It permits the prime to delegate to a subrecipient and prevents that subrecipient from re-delegating further without a fresh grant — which is the point at which oversight currently evaporates silently."
  },
  {
   "type": "h2",
   "text": "What the single auditor gains"
  },
  {
   "type": "p",
   "html": "Today a single auditor testing subrecipient monitoring reviews agreements, risk assessments and monitoring documentation, and samples transactions. Establishing who had authority for a specific subaward transaction is a reconstruction exercise."
  },
  {
   "type": "p",
   "html": "With a delegation chain, that question becomes a verification: the transaction references a delegation, the delegation is signed, and the chain terminates at a named authorising official at the prime. Verification is offline and requires no access to any party's systems."
  },
  {
   "type": "h2",
   "text": "A practical sequencing note"
  },
  {
   "type": "p",
   "html": "Do not begin with the whole subaward population. Begin with the awards that carry the most subaward dollars and the deepest chains, which in most portfolios is a small number."
  },
  {
   "type": "ol",
   "items": [
    "Rank awards by subaward dollars passed through.",
    "For the top decile, issue delegations rather than relying on registration records.",
    "Require subrecipients to reference the delegation on drawdown requests.",
    "Hand the resulting artefacts to your single auditor as a pilot and ask whether it shortens their testing."
   ]
  },
  {
   "type": "p",
   "html": "That last step matters. If it does not reduce audit effort, the control is imposing cost without a measurable operational return, and that should change the decision."
  },
  {
   "type": "h2",
   "text": "Two fields, two different controls"
  },
  {
   "type": "table",
   "caption": "The drawdown and the destination",
   "head": [
    "Field",
    "Control today",
    "Control needed"
   ],
   "rows": [
    [
     "Drawdown amount",
     "Bounded by the award",
     "Adequate"
    ],
    [
     "<strong style=\"font-weight:600\">Destination account</strong>",
     "<strong style=\"font-weight:600\">A profile field</strong>",
     "<strong style=\"font-weight:600\">A payment instruction</strong>"
    ],
    [
     "Requesting individual",
     "A role",
     "A named person with a signature"
    ],
    [
     "Purpose and period",
     "Sometimes captured",
     "Bound into the request"
    ]
   ]
  },
  {
   "type": "h2",
   "text": "Objections and honest limits"
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“The award ceiling limits the exposure.”</strong> It limits the amount, not the destination. A drawdown within the ceiling to a changed account is fully authorised and entirely lost."
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“Grantees are known entities.”</strong> The organisation is. The individual holding the role at any moment, and whether their session is theirs, is the open question."
  }
 ],
 "faq": [
  {
   "q": "Does Uniform Guidance require this?",
   "a": "No. It requires subrecipient monitoring and adequate internal control. The delegation chain is one way to evidence authority; it is not prescribed."
  },
  {
   "q": "What about drawdowns for costs already incurred?",
   "a": "The delegation governs who may request and how much, not what the funds are for. Cost allowability remains a separate determination."
  },
  {
   "q": "Do subrecipients need to build anything?",
   "a": "They need a credential and the ability to reference a delegation. Verification is performed by the prime and the agency, not by the subrecipient."
  },
  {
   "q": "How does this interact with the single audit?",
   "a": "It supplies verifiable artefacts for authority testing. Whether it reduces audit effort is testable and should be tested before scaling."
  },
  {
   "q": "Does the award ceiling protect the funds?",
   "a": "It bounds the amount, not the destination. A within-ceiling drawdown to a changed account is fully authorised and entirely lost."
  },
  {
   "q": "What should be gated more tightly than the drawdown?",
   "a": "The destination account. It is the field that redirects every future disbursement."
  },
  {
   "q": "What is the strongest cross-grantee signal?",
   "a": "One bank account receiving drawdowns for several unrelated organisations."
  }
 ],
 "sources": [
  {
   "t": "2 CFR Part 200 — Uniform Administrative Requirements for Federal Awards",
   "u": "https://www.ecfr.gov/current/title-2/subtitle-A/chapter-II/part-200"
  },
  {
   "t": "GAO-15-593SP — A Framework for Managing Fraud Risks in Federal Programs",
   "u": "https://www.gao.gov/products/gao-15-593sp"
  },
  {
   "t": "GAO-26-109100, July 2026 — managing fraud risks in federally funded programs",
   "u": "https://www.gao.gov/products/gao-26-109100"
  },
  {
   "t": "Federal payment management system documentation on drawdown processes."
  },
  {
   "t": "PaymentAccuracy.gov — federal improper payment data",
   "u": "https://www.paymentaccuracy.gov/"
  }
 ],
 "related": [
  {
   "slug": "payment-integrity-control-map",
   "title": "$186 billion in improper payments",
   "category": "Compliance"
  },
  {
   "slug": "effort-certification-evidence",
   "title": "Time-and-effort certification",
   "category": "Compliance"
  },
  {
   "slug": "warrant-as-delegation",
   "title": "Procurement award authority",
   "category": "Compliance"
  }
 ],
 "image": "https://cdn.twc.sh/images/igcache/Drawdown%20Authority%20Chain/1200_630/blog.jpg",
 "wordcount": 852,
 "url": "/blog/drawdown-authority-chain.html",
 "reading_time": "4 min read",
 "meta_description": "Federal drawdowns are requested by users holding grantee roles. Authority to request funds is a permission, and the chain to a person is thin.",
 "hub": {
  "slug": "topics/public-sector-identity",
  "title": "Public sector identity"
 },
 "answer": "A user holding a grantee role in a payment management system. Authority to request federal funds is expressed as a permission, and the chain from a drawdown to a named person with the authority to request that money is thin enough that a compromised portal session completes it.",
 "answer_q": "Who authorised a federal grant drawdown?",
 "glossary": [
  {
   "term": "Drawdown",
   "def": "A grantee's request to receive federal funds already awarded."
  },
  {
   "term": "Payment management system",
   "def": "The federal system through which grantees request and receive award funds."
  },
  {
   "term": "Authorised official",
   "def": "The individual permitted to request funds on the grantee's behalf — a person, currently represented as a role."
  }
 ],
 "checklist": {
  "title": "Binding a drawdown",
  "id": "drawdown",
  "desc": "Four steps.",
  "steps": [
   {
    "name": "Gate the destination account separately.",
    "text": "Higher bar than the drawdown itself."
   },
   {
    "name": "Require a signature from a named authorised official.",
    "text": "Not a role-holder's session."
   },
   {
    "name": "Bind the amount, period and purpose.",
    "text": "So a request rebuilt afterwards fails."
   },
   {
    "name": "Reconcile destinations across grantees.",
    "text": "One account receiving several organisations' funds is the signal."
   }
  ]
 },
 "cta": {
  "title": "Where this fits in Manav",
  "html": "Manav binds the authorising official to the exact release, award or disbursement being authorised, and produces a receipt an inspector general, an auditor or another agency can verify without access to the issuing system.",
  "href": "../docs.html",
  "label": "See authorisation receipts"
 }
}