AI Federal Program Audit — Improper Payment Risk Assessment Playbook
The agency IG is conducting a risk assessment of a $2.1B grant program following a GAO report that cited inadequate pre-award financial capacity reviews and insufficient monitoring of subrecipients. Fourteen grantees have not submitted required quarterly reports. Three grantees have drawn down 90%+ of award funds in the first 60 days of a 24-month performance period.
When to use this playbook
- Use this playbook when the decision looks like the situation above: The agency IG is conducting a risk assessment of a $2.1B grant program following a GAO report that cited inadequate pre-award financial capacity reviews and insufficient monitoring of subrecipients.
- It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Federal Program Audit — Improper Payment Risk Assessment".
- Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.
What you'll need
- Grantee drawdown and reporting status (all 87 grantees) - Pre-award financial capacity review files (sample of 20) - Subrecipient monitoring policy and procedures - GAO report findings and agency management response
Attachments: Documents (Documents)
The Prompt
You are a federal program auditor conducting an improper payment risk assessment under PIIA requirements for a large grant program. I am attaching: - Grantee drawdown and reporting status (all 87 grantees) - Pre-award financial capacity review files (sample of 20) - Subrecipient monitoring policy and procedures - GAO report findings and agency management response Work only from the attached source files. If a conclusion is not supported, say so. Produce: 1. Identify all grantees that exhibit high-risk drawdown or reporting patterns — specifically those with accelerated drawdown relative to performance period elapsed, non-reporting, or both. 2. Review the 20 pre-award financial capacity files and assess whether the reviews meet the standards required under 2 CFR 200 Subpart E — identify specific deficiencies in financial systems assessment, internal controls review, and single audit findings review. 3. Analyze the subrecipient monitoring policy against 2 CFR 200.332 requirements — identify gaps in required monitoring activities, risk-based monitoring thresholds, and on-site review frequency. 4. Cross-reference the GAO findings with the agency management response — assess whether the agency's stated corrective actions are specific, measurable, and on track for completion. 5. Produce a risk-stratified grantee list for targeted monitoring and an improper payment risk estimate for the program under PIIA methodology. Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.
What to expect
- Multi-model consensus on improper payment risk classification per grantee
- Drawdown anomaly register with risk tier assignments
- 2 CFR 200 compliance gap analysis for pre-award files
- Subrecipient monitoring deficiency register
- Improper payment risk estimate and targeted monitoring prioritization list
Review before you act
- Validate this output against source files before relying on it: Identify all grantees that exhibit high-risk drawdown or reporting patterns — specifically those with accelerated drawdown relative to performance period elapsed, non-reporting, or both.
- Validate this output against source files before relying on it: Review the 20 pre-award financial capacity files and assess whether the reviews meet the standards required under 2 CFR 200 Subpart E — identify specific deficiencies in financial systems assessment, internal controls review, and single audit findings review.
- Validate this output against source files before relying on it: Analyze the subrecipient monitoring policy against 2 CFR 200.332 requirements — identify gaps in required monitoring activities, risk-based monitoring thresholds, and on-site review frequency.
- Validate this output against source files before relying on it: Cross-reference the GAO findings with the agency management response — assess whether the agency's stated corrective actions are specific, measurable, and on track for completion.
- Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
- Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
- Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.
Why compare models on this
For Federal Program Audit — Improper Payment Risk Assessment, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface multi-model consensus on improper payment risk classification per grantee; drawdown anomaly register with risk tier assignments; 2 cfr 200 compliance gap analysis for pre-award files; subrecipient monitoring deficiency register. Those are comparison artifacts — they only exist if more than one model runs. Threshold-splitting, sanctions hits, and exam-readiness calls are exactly where models diverge. Record the split and the human resolution.
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

