Skip to content
§
§ · build vs buy

Subrecipient Monitoring Software: Build vs Buy

Buy. If you pass through federal money to fewer than about 25 subrecipients under a small number of programmes, AmpliFund or eCivis will carry it and the money is better spent on a compliance hire.

Internal Tools Development software overview illustration for Subrecipient Monitoring Software Build vs Buy Guide.
The short answer

Buy. If you pass through federal money to fewer than about 25 subrecipients under a small number of programmes, AmpliFund or eCivis will carry it and the money is better spent on a compliance hire. Build when your risk assessment lives in one analyst's spreadsheet, when reimbursement review is a portable document format slog, or when a monitoring finding has already produced questioned costs.

Alternatives to a custom build: what AmpliFund and eCivis do well

Pass through entities usually reach this question after an auditor asks how a risk score was derived and nobody can reproduce it. Even so, most agencies should buy, and the products deserve a fair hearing first.

AmpliFund and eCivis both handle the grant lifecycle properly: opportunity tracking, application, award, budget, reporting calendars and document storage. Fluxx sits closer to the philanthropic side and does portfolio management well. All of them give you a place where a subaward exists as a record rather than as a folder, with due dates that generate reminders and a portal that spares your analysts from email attachments.

What buying earns:

  • A subaward record with budget, period of performance and reporting obligations in one place.
  • Deadline tracking that nobody has to maintain by hand in a shared calendar.
  • A subrecipient portal, which alone removes a large share of your inbox.
  • Document retention that satisfies the general expectation under 2 CFR 200 without a separate filing system.
  • Reporting your programme officers can run without asking anyone.

Buy if you administer fewer than about ten subawards under a single programme with one reporting format. At that scale the software is not your constraint, staffing is, and a build would consume the budget for the person you actually need.

Where they stop: monitoring is a judgement you must be able to reproduce

The workflow that generic grant products model badly is risk based monitoring, and it is the exact thing 2 CFR 200.332 requires you to do.

Uniform Guidance requires you to evaluate each subrecipient's risk of noncompliance and to calibrate monitoring to that risk. Products give you a risk field with a dropdown reading low, medium or high. That is a conclusion with no working shown.

What survives an audit is a risk assessment where each factor is a named rule with a weight and a data source: prior single audit findings, whether the subrecipient expended federal awards above the Single Audit threshold, which moved to one million dollars under the 2024 Uniform Guidance revisions, new versus experienced recipient, staff turnover in key financial roles, award size relative to the subrecipient's total budget, and the results of your last site visit. The score has to be recomputable on demand, with the inputs that produced it preserved as at the date it was computed. A dropdown cannot do that, and no vendor will let you define the factors.

The second break is reimbursement review. A subrecipient submits a request with backup, often a scanned ledger and a stack of receipts. Your analyst opens it, reads, and approves or queries. There is no sampling logic, so either everything is reviewed, which does not scale, or nothing is, which is worse. What you need is variance testing against the approved budget, flags for cost categories requiring prior written approval, detection of costs incurred outside the period of performance, and indirect charged above the negotiated rate or above the de minimis rate. Then a sampling rule that reviews more from high risk subrecipients and less from low risk ones, with the sampling method recorded so it can be defended.

The third is follow through. A single audit arrives, findings are noted, corrective actions are agreed, and then the file closes. Nothing tracks whether the corrective action actually happened, and nothing feeds that back into next year's risk score. Meanwhile Federal Funding Accountability and Transparency Act subaward reporting for awards at or above the thirty thousand dollar threshold gets re keyed from the subaward record instead of generated from it, which is both wasted effort and a source of mismatch.

A fourth gap shows up during a site visit. The visit itself is a structured procedure with a scope drawn from the risk assessment, a sample of transactions selected in advance, interviews, and a written report with observations that either become findings or do not. In most agencies the visit lives in a word processing document on a laptop, and the sample was chosen the night before. Nothing connects the transactions tested to the reimbursement requests already approved, so the same expenditures get reviewed twice while others are never touched. A system that draws the sample from live expenditure data, records what was tested and carries observations forward into corrective actions turns the visit from an event into evidence.

The arithmetic: per user licensing versus the cost to build

Products here price per user, per programme, or on total funds administered. Establish which before comparing anything, because the three produce different answers at the same agency.

Take the licence, add implementation amortised over the term, and divide by active subawards. Then add what the licence leaves with you: analyst hours reading reimbursement backup with no sampling, the annual exercise of chasing single audit reports and checking the Federal Audit Clearinghouse, the transparency reporting re keying, and the time spent reconstructing risk rationale when someone asks.

Cost the build the same way. Midpoint of the bands below, plus year two support, over five years, divided by active subawards.

In our delivery experience the crossover sits near 25 active subrecipients, or roughly 120 reimbursement requests a quarter, or the point at which you administer awards from three or more federal agencies with different reporting expectations. The last trigger moves the line down sharply, because each funder adds its own report layout and its own deadline calendar, and that variety is what a product handles worst.

One questioned cost finding changes this arithmetic entirely, and not because of the repayment. It is the monitoring plan you then have to demonstrate and sustain.

What a custom build actually costs

From Digital Heroes delivery experience, a first release covering subrecipient risk assessment, subaward issuance and reimbursement request review with attached backup runs $70,000 to $150,000 and ships in 12 to 18 weeks. A full monitoring system adding single audit collection, corrective action tracking, site visit workflows, transparency subaward reporting and a subrecipient portal runs $180,000 to $400,000 phased over 8 to 14 months.

Data migration is 10 to 25 percent of build cost. Closed awards load cheaply. Open awards are the expense, because each one needs its budget, its period of performance, its prior approvals and its expenditure to date reconstructed and then verified against your financial system, since a mismatch there is a finding rather than a data error.

Year two runs 15 to 20 percent of build cost annually. It buys financial system interface maintenance, whether that is Tyler Munis, Workday or an Oracle platform, plus rule updates when Uniform Guidance is revised. The 2024 revisions changed thresholds that many agencies had hard coded, and agencies that had them as configuration changed a value while others changed code.

The four situations where building wins

  • Regulatory fit. Your monitoring plan must satisfy 2 CFR 200.332, your record retention runs generally three years from submission of the final expenditure report and longer while an audit or litigation is open, and your subrecipient versus contractor determinations under 2 CFR 200.331 need to be documented rather than assumed.
  • Scale economics. Enough subawards and reimbursement volume that per user licensing has passed the amortised cost of owning the system.
  • A monitoring method that is genuinely yours. A weighted risk model with defined factors, a documented sampling rule, and corrective actions that feed back into next year's score.
  • Integration sprawl across three or more systems. Your financial system for expenditure, a document store for backup, the transparency reporting submission path, the Federal Audit Clearinghouse for audit reports, and the shared inbox where everything currently arrives.

One of those true means keep the product and build the risk and sampling engine beside it, writing scores back.

How to decide in a week, ending with a specification you own

Run the reproduction test.

Pick three subrecipients with different risk ratings. Ask the analyst who set each rating to reproduce it from records alone, showing the factors, the weights and the source of each input as at the date it was assessed. Give them two hours. If any of the three cannot be reproduced, you have found the finding an auditor will find, and you found it first.

Then run the sampling test. Take last quarter's reimbursement requests and count how many were reviewed in full, how many were approved on the strength of a summary, and whether any rule decided which was which. If the answer is analyst discretion, write down what that discretion is worth in exposure.

Finish by tracing one prior year corrective action from the finding to the evidence that it was completed. If the trail ends at an email, that is the gap.

If the case holds, buy a discovery phase before a build. At Digital Heroes it ends in a signed product requirements document covering the risk model, the sampling rules and acceptance criteria, and you own it whether or not you continue with us. We hold India LLP, US LLC and UK LTD entities so intellectual property assigns under your own law, run more than fifty specialists across over 2,000 projects, and you meet the named team before signing. We are checkable on Clutch, Trustpilot, Fiverr Vetted Pro and D-U-N-S.

We are the wrong firm for an agency with eight subawards under one programme. Buy AmpliFund, hire the compliance analyst, and you will be better monitored for less.

Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. The median annual wage for U.S. software developers was $133,080 in May 2024, and employment is projected to grow 15% from 2024 to 2034 - a core input to any in-house build-vs-buy TCO model. Source: U.S. Bureau of Labor Statistics (2024) →
  2. A study (led by Prof. Pak-Lok Poon, published in Frontiers of Computer Science, 2024) reviewing decades of spreadsheet-quality research found that about 94% of spreadsheets used in business decision-making contain errors, illustrating the hidden risk of manual spreadsheet workarounds that custom software is built to replace. Source: Central Queensland University / phys.org (Prof. Pak-Lok Poon et al.) (2024) →
  3. Retailers connecting point-of-sale and loyalty data in an omnichannel strategy reported up to 15% lower cost per purchase and nearly 20% higher incremental store revenue. Source: Deloitte (2024) →
  4. Total US training expenditure rose 4.9% to $102.8 billion; learning management systems were used at 89% of organizations (90% of large, 97% of midsize, 84% of small companies), with average training at 40 hours per employee and $874 spent per learner. Source: Training Magazine (2025) →
FAQ

Frequently asked questions

How long does a subrecipient monitoring system take to build?

Twelve to eighteen weeks for a first release covering risk assessment, subaward issuance and reimbursement review. A full monitoring platform with single audit collection, corrective actions, site visits and a subrecipient portal takes eight to fourteen months. Launch at the start of a fiscal year rather than mid cycle, so that a full year of monitoring evidence sits inside one system when your auditor arrives.

Who owns the monitoring records and the code if the developer relationship ends?

You should own the repository, the cloud accounts and every record, agreed in writing before development starts. At Digital Heroes the client owns the code from the first commit. Retention is the reason this matters more here than elsewhere: Uniform Guidance generally requires records for three years from the final expenditure report, and longer while an audit or litigation remains open, regardless of who built your software.

Can we build only the risk assessment and keep our current grant product?

Yes, and it is the sensible first slice. A risk service holds the factors, the weights and the sources, computes a score with the inputs preserved as at the assessment date, and writes the result back into the product as a rating. Your programme staff keep the interface they know, and you gain the thing an auditor asks for, which is the working rather than the conclusion.

What happens if an auditor questions how we set a subrecipient's risk level?

You need to show the factors, the values, their sources and the date, not a rating in a dropdown. That is the single most common gap in this category and it is why agencies build. If your current answer is that an experienced analyst made a judgement, expect a finding on documentation even where the judgement itself was sound, because the requirement is a documented evaluation.

Should a small city with six subawards build anything?

No. At that size a well organised shared drive, a written monitoring plan and a checklist per subrecipient will satisfy the requirement, and a product adds convenience rather than compliance. Spend the money on the person who does the monitoring. Revisit the build question when you pass roughly 25 subrecipients or begin administering awards from several federal agencies at once.

What is the difference between a subrecipient and a contractor?

A subrecipient carries out part of the federal programme, makes programmatic decisions and is subject to the compliance requirements of the award. A contractor provides goods or services within normal business operations to many purchasers. The determination under 2 CFR 200.331 rests on substance rather than the document title, and it decides whether monitoring obligations apply at all, so it belongs on the record with a written rationale.

Can we automate the review of reimbursement backup?

Partly, and the honest scope matters. Machine extraction can pull totals, dates and cost categories from a scanned ledger with a confidence score, then route low confidence items to a human. What should never be automated is the judgement about allowability. Aim for a system that removes transcription and applies budget variance and period of performance tests, leaving analysts to decide the questions that require decisions.

How do we handle a subrecipient that misses its single audit?

Treat the missing audit as a risk factor with a date rather than a note. Your system should track whether the subrecipient expended enough federal awards to require one, whether it was submitted to the Federal Audit Clearinghouse, and escalate when it is overdue. A missed audit raises next year's risk score automatically, which is the behaviour auditors look for and the one spreadsheets never deliver.

What happens to transparency reporting if we build our own system?

Generate it rather than re key it. Subaward reporting under the Federal Funding Accountability and Transparency Act applies at or above the thirty thousand dollar threshold, and the data already exists on your subaward record. Building the submission from that record removes both the effort and the mismatch risk. Confirm the current submission path and format during discovery, since it has changed before.

Is it worth building if we administer awards from several federal agencies?

Usually yes, and sooner than the subrecipient count suggests. Each funder brings its own report layout, deadline calendar and prior approval rules, and that variety is what packaged products handle worst. The value is not in the monitoring workflow, which is broadly common, but in expressing per funder requirements as configuration so a new award does not become a new spreadsheet.

What happens to my software if the agency shuts down or we stop working together?

Nothing dramatic, if the engagement was set up correctly: the code sits in your repository, hosting runs on your cloud account, and a handover document explains how to deploy and operate the system. Any competent replacement team can then take over in days rather than months. If the agency controls the repo, the servers, or the domain, fix that now, because renegotiating access during a dispute is the most expensive place to discover the problem.

What are the most common mistakes companies make when building internal tools?

The three failures Digital Heroes sees most: building for every department at once instead of nailing one workflow, designing without the end users so staff quietly go back to their spreadsheets, and leaving no named owner after launch so small bugs pile up until the tool dies. A subtler fourth is faithfully recreating the old spreadsheet, including its workarounds, instead of fixing the process first. Start with one team's most painful workflow and put the actual users in the room from week one.

Can a custom internal tool connect to QuickBooks, Salesforce, and the other software we already use?

Yes, and integrations are usually the strongest argument for going custom instead of chaining tools together with Zapier. QuickBooks, Salesforce, Shopify, Stripe, Slack, and Google Workspace all have mature APIs, and each integration typically adds $1,500 to $5,000 to a Digital Heroes build depending on how much two-way syncing you need. The honest caveat is legacy industry software without an API, which may need file-based imports instead of a live connection, so list every system in the first conversation.

At what point does Retool cost more than building a custom tool?

The crossover usually lands between 25 and 50 daily users. At Retool's published Business rates of $50 per standard user and $15 per end user monthly, a 40-person deployment with a typical seat mix runs roughly $9,000 to $15,000 per year, every year, while a comparable custom tool built once for $20,000 to $30,000 carries no per-seat fees and costs about 15 to 20 percent of the build price annually to maintain. On a three-year horizon, custom comes out ahead for most growing teams in Digital Heroes engagements.

Should we build the whole internal tool at once or start with an MVP?

Start with a version that fully replaces one workflow, ship it in 4 to 6 weeks, and let real usage set the roadmap. Internal tools have a captive audience, so you learn within days which features matter, and across Digital Heroes projects roughly a third of initially requested features never get built once staff work with version one. Phasing also spreads the spend: a $40,000 vision becomes a $15,000 phase one that starts paying for itself while phase two is scoped.

Is a custom internal tool secure enough for HR records and financial data?

A properly built custom tool is generally safer for sensitive data than the shared spreadsheet it replaces, because you get role-based access, audit logs, encrypted storage, and the ability to cut one person's access instantly. Ask the agency specifically for encryption in transit and at rest, permissions down to the field level, and an audit trail showing who viewed or changed each record. If HIPAA, GDPR, or SOC 2 expectations from enterprise clients apply to you, raise it before the quote, because compliance features add real scope.

Will a custom internal tool scale as our company grows?

Yes, provided it sits on a standard stack with a real database: PostgreSQL comfortably handles millions of records, and adding users costs hosting pennies rather than per-seat fees. The real scaling risks are organizational, not technical: new departments want features, processes change, and the tool needs a budget line to evolve. Set aside a small quarterly improvement budget instead of treating launch as the finish line, and the tool stays useful for a decade rather than getting rebuilt every two years.

Should we build our internal tool in Retool instead of hiring developers?

Retool is the right choice if someone on your team is comfortable with SQL and JavaScript and the audience is a handful of technical users, because a basic CRUD dashboard comes together in days. Hire developers when non-technical staff will use the tool daily, when the logic goes beyond forms sitting on a database, or when per-seat pricing stings, since Retool's Business tier lists at $50 per standard user per month. A pattern Digital Heroes sees often: companies arrive after a year on Retool with a tool nobody can maintain because the one person who built it has left.

Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply