Cam SmithCIA · CGAP
◆ Services

Four practices, one discipline.

Federal funding is won on the proposal and kept on the paperwork. Each of these practices exists to make the second part survivable — controls that hold, records that reconcile, and staff who can run both without outside help. Engagements are scoped to end with your team more capable than it started.

i

Grants Management

Supporting the federal grant lifecycle

Support across the entire federal grant lifecycle — pre-award planning through post-award compliance and performance improvement — to secure funding, meet the requirements that come with it, and keep the award audit-ready.

Grant guidance

  • 2 CFR 200 Uniform Guidance — administrative requirements, cost principles, and audit requirements
  • Agency-specific rules and regulations
  • Federal Assistance Listing (formerly CFDA) research
  • NOFO interpretation and requirement mapping

Fiscal management

  • Financial systems evaluation against federal requirements
  • Cost allowability determinations
  • Budget development and management
  • Procurement standards compliance
  • Federal financial reporting

Grant awards

  • Pre- and post-award assistance
  • Proposal development
  • Risk assessment
  • Subaward and subrecipient management
  • Award negotiation and infrastructure readiness

Program management

  • Performance management systems
  • Outcome measurement
  • Ongoing compliance monitoring
  • Performance auditing
  • Business process development
Sample work products
Subrecipient Monitoring ToolkitGrant Readiness QuestionnaireCorrective Action WorksheetMonitoring Report TemplatePrior Approval Request TemplateCost Justification Worksheet
ii

Internal Controls & Audit Readiness

Strengthening compliance and mitigating risk

Designing, implementing, and strengthening internal controls for organizations that receive federal funding. The approach goes past checklists to system-level solutions that keep working after the engagement ends.

Control over compliance

  • GAO Green Book — Standards for Internal Control in the Federal Government
  • COSO Internal Control — Integrated Framework
  • OMB Circular A-123 — enterprise risk management and internal control
  • OMB Compliance Supplement

Controls for federal grants

  • Identifying key compliance requirements under 2 CFR 200.303
  • Developing and documenting effective controls
  • Testing and evaluating control effectiveness
  • Remediating identified deficiencies

Audit readiness

  • Tailored audit support throughout the process
  • Gap analysis
  • Control mapping to compliance requirements
  • Corrective action planning

Systems & data

  • Building and enhancing business systems for ongoing compliance
  • Data validation for audit purposes
  • Reducing administrative burden through system-level design
Sample work products
Risk Assessment FacilitationControl MappingGap AnalysisSubrecipient Monitoring ToolkitCompliance Work Programs
iii

Organizational Design & Training

Building internal capacity for long-term success

Partnering with organizations to build internal capacity and reduce dependence on outside consultants. Compliance should be controlled by the organization it serves — not the other way around.

Organizational design & process development

  • Co-created workflows and operational improvements
  • Staffing plans
  • Surfacing real challenges and addressing root causes
  • A systems-level perspective rooted in public service experience

Training & technical assistance

  • Customized training programs
  • One-on-one support and coaching
  • Ready-to-use tools and resources
  • Job aids, reference guides, and instructional materials

Knowledge transfer

  • Skill development that lets staff manage processes independently
  • Deliverables designed for self-sufficiency
  • Training grounded in real-world practice

Documentation

  • Policy and procedure writing support
  • Review of existing policies for compliance
  • Visual and descriptive process maps
Sample work products
Workflow DesignTraining & Job AidsPolicy + Procedure WritingProcess Maps
iv

Intelligent Systems Design

Audit-defensible by design

AI systems for regulated work, built the way an auditor tests controls. Every conclusion traces to a citable authority; where the authority runs out, the system returns an explicit gap rather than a guess.

Governance-grade instruments

  • Authority-anchored determinations bounded to a cited source
  • Explicit gap reporting where authority is silent
  • Compliance instruments for federal award requirements

Provenance & decision lineage

  • Records of what happened, who authorized it, and under what constraints
  • Lineage design for human-governed, AI-operated processes
  • AI risk triage and governance design

Evaluation & verification

  • Evaluation harnesses — precision/recall, citation accuracy, trace completeness, confidence calibration
  • Human-in-the-loop verification design
  • RAG architectures for regulatory corpora

Regulatory data infrastructure

  • Regulatory ontologies and burden taxonomies
  • Machine-readable statutory and regulatory corpora (USLM / Akoma Ntoso)
  • Burden-identification tooling
Sample work products
Evaluation HarnessProvenance / Lineage ModelRegulatory OntologyAI Risk Triage FrameworkHITL Verification Design
The engagement principle

Every engagement is measured by the capacity it leaves behind — increased internal capability and reduced reliance on outside support. Deliverables are built for knowledge transfer, so the controls, the tools, and the reasoning stay with your team after the work is done.

Discuss an engagement.Get in touch →