Skip to main content

Auditor & Funder Portal

Published: Last updated: Reviewed: Sources: aicpa-cima.com gao.gov ecfr.gov

TLDR

The Auditor & Funder Portal lets you invite an auditor or funder by email, choose exactly which grants, funds, and documents they can see, and set an expiry date. They get a secure link — no GrantPipe account required. Every view and download is logged in your audit trail so you have a permanent record of what was shared and when.

The Auditor & Funder Portal gives external reviewers exactly what they need and nothing else. You invite them by name, choose which grants, funds, and documents are visible, set an expiry date, and send a link. They never see your donor records, your team settings, or anything outside the scope you defined.

What this feature does

When an audit or funder review is scheduled, the standard response is to pull files and email them as attachments or share a folder that contains far more than the reviewer needs. Neither approach creates a record of what was accessed.

The portal replaces that process. You build a named session, attach the evidence bundle or individual documents, assign the reviewer, and set when access ends. GrantPipe generates a signed link and sends the invitation. The reviewer sees a focused interface with the records you selected. When they open a document or download a file, that action is logged.

How invite and scope work

  1. Go to the Portals section in GrantPipe and create a new session
  2. Name the session (e.g., “Annual Audit FY 2025 — CPA Review”)
  3. Select which grants, restricted funds, and documents to include
  4. Add the reviewer’s name and email address
  5. Set an expiry date — the session ends automatically on that date
  6. Send the invitation; GrantPipe generates the signed link and emails it

The reviewer follows the link and lands on the portal view. They do not need to create an account or log in through the main application.

What reviewers see

Reviewers see the grants, fund summaries, and documents included in the session. For each grant, they can see award terms, restriction details, spending summaries, report submissions, and attached documents. They cannot modify anything, cannot see donor records or campaign data, cannot access team settings, and cannot navigate to records outside the session scope.

How access expires and revokes

Access expires automatically on the date set at invitation time. If you need to end access early — because the review is complete, the scope was wrong, or the relationship changed — go to Settings → Portal access and revoke the session. Revocation is immediate: the link stops working within seconds. Both automatic expiry and manual revocation are logged in the audit trail.

Start a free trial

Start a trial.

Free resource

Get the Auditor Evidence Checklist

What auditors need from nonprofit grantees — organized by section. Build your evidence bundle without missing the documents that typically produce findings. Delivered by email.

We'll email the resource and a short follow-up sequence. Unsubscribe any time.

Email is required because the download link is delivered by email, not on-page.

AICPA Statement on Auditing Standards 145 requires auditors to evaluate IT general controls including access controls and change logging for systems that process financial data

Source: AICPA SAS No. 145

GAO High Risk Series identifies incomplete documentation and inadequate access controls as recurring findings in federal grant audits

Source: U.S. GAO 2024 High Risk Series

Q&A

What is an auditor portal in grant management software?

An auditor portal is a scoped, time-limited access layer that lets a named external reviewer — an auditor, a funder program officer, or a board member — view specific grant records and documents without accessing the full organization account. The portal is separate from team login and is typically accessed through a signed link delivered by email.

Q&A

Why do nonprofits need a dedicated auditor portal instead of a shared drive?

Shared drives give reviewers broader access than they need and produce no view log. A dedicated portal lets the organization define exactly what is visible, set an expiration date, and create a permanent record of what was shared and when. That record matters during the audit itself, not just before it.

Q&A

What is an evidence bundle?

An evidence bundle is a titled, curated package of grant documents, reports, and restriction terms organized for a specific review cycle. Rather than sharing individual files, the organization assembles the relevant evidence once and assigns the bundle to a portal session.

Frequently asked

Frequently Asked Questions

Does the auditor need a GrantPipe account?
No. External reviewers access the portal through a signed link sent by email. They do not need a GrantPipe login, and they cannot see anything outside the scope you defined when you created the invitation.
What can an external reviewer see?
Only what you explicitly included: the grants, restricted funds, and documents you selected when you set up the portal session. Donor records, team settings, billing, and all other areas are not accessible through the portal link.
How does access expire?
Each invitation has an expiry date you set at the time of creation. Access ends automatically when that date passes. You can also revoke access at any time from Settings → Portal access, which immediately invalidates the link.
Is the portal activity logged?
Yes. Every document view and file download is recorded in your organization's audit trail with the reviewer's name, the timestamp, and the specific item accessed. The log is append-only and cannot be modified.
What plan includes the Auditor & Funder Portal?
The portal is available on the Audit-Ready plan and above. It is not included in Starter or Growth.

Next step

See the workflow in GrantPipe.

Start a 1-month free trial and test donor, grant, restricted-fund, and compliance work in one place.

Start your 1-month free trial