Multiple funding sources turn state audits into compliance nightmares for lenders. CDBG grants have one set of compliance rules. EDA loans have another. Private capital has its own income allocation requirements and administrative fee caps.Receiving that 30-day notice means proving fund separation, income allocation, and borrower eligibility across every loan.
In this blog, I’ve outlined what auditors really look for, the five documents you must produce in 48 hours, and how to prepare whether you’re doing it manually or with automated fund tracking.
Auditors don’t care about your operational challenges. They care about five things, and they’ll ask for documentation within the first 48 hours.
1. Fund Separation Proof
They want to see that you never commingled restricted funds with general operating dollars. The test question sounds simple: “Show me loan #2847’s funding source breakdown.”
If you can’t produce a loan register tagged by fund source instantly, they’ll dig deeper. That’s when spreadsheet reconciliations fall apart.
2. Use Restriction Compliance
Federal grants like CDBG must serve low- and moderate-income borrowers. Auditors sample 10-20 loans and verify that you documented income eligibility before disbursement.
Missing income verification for even one CDBG loan? That’s an automatic finding.
Administrative Fee Calculations
CDBG limits administrative costs to 20% of the grant plus program income. Auditors recalculate your allocation to verify you didn’t overcharge.
Common finding: charging the same flat admin fee to all loans regardless of which fund paid for them. That math rarely works out when funds have different percentage caps.
Interest Income Allocation
Interest earned on grant-funded loans must return to the source fund. If your CDBG loans generated $15,000 in interest last year, auditors will verify that $15,000 stayed in the CDBG fund.
Depositing all interest into your general operating account? Red flag.
Complete Audit Trail
Every transaction needs a documented path: fund receipt → loan disbursement → borrower payment → fund replenishment. One broken link in that chain becomes an audit finding.
Manual spreadsheet updates don’t provide audit trails. Formula errors don’t either.
Now you know what auditors ask for. Here’s what you need to have ready.
QUICK TAKE:
When that audit notice arrives, you’ll need to produce 5 specific documents within 48 hours:
Your auditors ask for specific deliverables. Here’s what they want and why you can’t fake it.
1. Loan Register by Funding Source
A complete list of every loan with its fund source clearly tagged. Format matters less than accuracy. Auditors cross-reference this against your fund disbursement records.
Can’t produce it? They assume you don’t actually know which fund paid for which loan.
2. Payment Application Breakdown
How each borrower payment split between principal, interest, and fees by fund source. This proves income allocated correctly back to restricted funds.
If your system dumps all payments into one account and you manually allocate later, good luck proving accuracy under audit scrutiny.
3. Administrative Cost Allocation Schedule
Staff time and overhead costs charged to each fund with percentage calculations. Auditors recalculate these against actual costs to verify you stayed within allowable limits.
The $500 flat admin fee you charge every loan? It probably violates CDBG’s 20% cap on some of them.
4. Fund Balance Reconciliation
Beginning balance + receipts – disbursements = ending balance, calculated separately for each fund source. Auditors verify this reconciles to your bank statements to the penny.
Monthly Excel updates with three different versions floating around won’t pass this test.
5. Borrower Eligibility Documentation
Income verification, business certifications, and eligibility criteria documentation for every loan made with restricted funds. Auditors sample loans and check files.
Missing documents from 2+ years ago? Track them down now or document why you can’t. “We didn’t keep that” isn’t acceptable.
Having these five documents is baseline compliance. But there are warning signs that turn 30-day prep into months of panic. Here’s what to fix now.
Self-assess your readiness. Each red flag adds days to your prep timeline.
Missing Fund Tags on Historical Loans
Loans from 2-3 years ago don’t show which fund paid for them. You’ll need to pull historical disbursement records and retroactively tag every loan. Document your methodology if the source isn’t crystal clear.
Manual Spreadsheet Reconciliations
Your fund balances live in Excel, updated monthly. Formula errors compound. Version control fails. No audit trail exists for who changed what when.
Fix: Move to a system that tracks fund-level data automatically, or at minimum, lock spreadsheet cells and maintain rigorous version control with change tracking enabled.
Can’t Trace Dollars from Source to Loan
You deposited your CDBG grant into your general operating account and made loans from that same account. Auditors can’t verify fund separation.
This requires restructuring how you handle fund receipts and disbursements going forward.
Interest Income Goes to General Operating
Interest from grant-funded loans gets deposited with your regular revenue. Calculate interest by fund source, transfer it to the correct accounts, and set up automated allocation for future payments.
No Documentation of Borrower Eligibility
You approved CDBG loans without income verification on file. Review loan files now for documentation gaps. Collect missing docs if borrowers are accessible. Document what you can’t recover.
Spotted red flags in your system? Here’s your week-by-week manual remediation plan.
Week 1: Assessment
Document the gaps in writing. Assign owners for each fix.
Week 2: Data Cleanup
Test your work: Can you produce any requested report in under 10 minutes?
Week 3: Documentation Prep
Have all supporting documents ready but don’t send them unless requested. Auditors want answers first, backup second.
Week 4: Dry Run
The goal isn’t perfection. It’s demonstrating you have a documented, defensible system.
That’s the manual approach. It works, but it’s exhausting. Here’s why some municipal lenders handle audits in minutes instead of weeks.
Most municipal lenders start with Excel. It works until auditors arrive. Here’s what breaks and how Bryt fixes it.
You can’t prove who changed fund balances or when. Formula errors cascade across sheets. Multiple versions exist with no way to know which is current.
Salt Lake City Corporation dealt with this before switching. Inaccurate payment schedules and workflow inefficiencies made audit prep a nightmare.
Bryt’s Register Tracking logs every transaction with user attribution and timestamps. Changed a fund balance? Waived a fee? Modified loan terms? The system tracked who did it, when, and why.
The Advanced Register maintains complete transaction histories at the loan level, creating an unbreakable audit trail from receipt of funds through disbursement to repayment.
Pull complete audit trails in minutes, not days of spreadsheet archaeology.
You can’t filter loans by fund without manual data manipulation. Retroactively tagging historical loans means pulling old disbursement records and guessing which fund paid for what.
Bryt’s Custom User Fields (CUF) Module lets you tag each loan with its funding source (CDBG, EDA, private capital) at origination. The tag follows the loan through its entire lifecycle.
Payment processing through Bryt’s Custom Waterfall Module automatically allocates income by fund source based on rules you configure once. Principal from a CDBG loan goes to the CDBG fund. Interest follows the same waterfall allocation you defined.Filter your entire portfolio by funding source in seconds using Custom Reports. Export clean, auditor-ready reports without touching Excel.
Balances get updated monthly, but auditors want today’s numbers. Manual reconciliation means your fund balance snapshot is already outdated by the time you finish calculating it.
Bryt’s Reports 2.0 calculates fund balances in real-time without manual reconciliation. No month-end updates. No formula errors. No version control issues.
The Dashboard provides instant visibility into portfolio performance, while the Custom Reports Module lets you build fund-specific reports that refresh automatically.
Pull instant reports filtered by any fund combination. CDBG loans from Q3? Done. Interest income by fund for the year? Done. Administrative costs as percentage of each grant? Done.
After implementing Bryt, Salt Lake City Corporation went from managing 30 loans with payment inaccuracies to over 100 loans with complete fund visibility and 10% increase in operational efficiency.
When auditors arrive now, they pull filtered reports instantly instead of compiling spreadsheets for days.
The principle: The system should make audit-ready reporting automatic, not require special preparation.
That 30-day notice will arrive. The question is whether you’ll spend those 30 days scrambling or simply pulling reports you already maintain.
Start with the five documents. If you can’t produce them today, work backward through the red flags to understand what needs fixing.
Most municipalities discover the problem isn’t their loan program, it’s their tracking system. When your current tools require manual reconciliation or can’t filter by fund source instantly, audit prep will always be stressful.
The time to fix this isn’t during audit season. It’s today.