Blog

AuditDraw Blog

Notes on housing lotteries, compliance and the AuditDraw platform.

What Auditors Actually Ask For After a Housing Lottery

Nobody runs a housing lottery for the auditor. But the auditor is who the record is for.

Every housing agency lives inside some review cycle. Larger agencies get an annual independent audit: the Single Audit, for agencies spending above the federal threshold (currently $1 million in federal awards). HUD's Office of Public and Indian Housing conducts monitoring reviews. LIHTC properties answer to their state allocating agency. And any agency, any size, can find itself producing records because an applicant complained, an advocate filed a request, or a journalist got curious.

When one of those reviews touches a lottery, the requests are strikingly consistent. I've seen the after-action side of this for seven years, and the same six asks account for nearly everything. An agency that can answer all six from its files will have a short conversation. An agency that can't will have a long one, and the length of that conversation, not the fairness of the original drawing, is usually what determines how bad the experience gets.

Here they are, in the order they usually arrive.

Ask 1: "Show me the policy in effect on the date of the drawing"

Not your current policy. The policy as adopted on that day, because what federal rules actually require is not any particular selection method, but a match between your written policy and your practice.

What satisfies it: the Administrative Plan or ACOP version in force on the drawing date, with the board action that adopted it. If the plan was amended since, you need the old version, which is exactly the version nobody thinks to keep.

Where agencies come up short: the plan on file describes first-come-first-served, or names preferences the notice didn't mention, or was amended three weeks after the opening to describe what the agency had already done. Any mismatch between the document and the practice is a finding, and it doesn't matter which one was "right."

Ask 2: "Show me the public notice, and prove where it ran"

For a waitlist opening, the notice requirements are specific, including the most commonly missed one: publication in a newspaper of general circulation and minority media and other suitable means. Reviewers check this because it's easy to check.

What satisfies it: the notice text, plus proof of every placement: tear sheets, broadcast affidavits, dated photographs, screenshots. A placement log, kept as placements happened.

Where agencies come up short: the notice ran, but nobody kept proof. Eighteen months later, the newspaper's archive is behind a paywall, the radio station has no record, and the community center took the flyer down. Proof of placement is nearly free to collect in the week it happens and nearly impossible to reconstruct afterward.

Ask 3: "Show me the applicant file as it existed when the window closed"

The drawing's input. Not the working list with six months of subsequent edits: the frozen file the lottery actually ran on.

What satisfies it: the preserved, unmodified source file, archived at window close, with the count matching the number of entries the drawing processed.

Where agencies come up short: this is the piece agencies lose most, because the applicant list is a living file right up until the moment it must stop being one. If the only copy is the working list, there is no way to demonstrate what the drawing started from, and every downstream answer inherits that doubt.

Ask 4: "Show me how the order was established"

The heart of it. The reviewer wants to see that a defined random process ran at a specific time and produced this specific order.

What satisfies it: the complete draw order (every position, not just the selections) with per-entry timestamps and a log written during the run. If preferences applied, the record should show tiers or weights operating the way the policy describes. And something should demonstrate the files haven't changed since: a signature derived from the data, or a record generated and held by a neutral third party.

Where agencies come up short: a spreadsheet of results with no log, one timestamp, and no integrity evidence. That's testimony, not documentation: a spreadsheet can't prove its own integrity, and reviewers know it. This ask is where the difference between ran it carefully and can demonstrate it becomes unmissable.

Ask 5: "Show me that offers followed the order"

The drawing establishes the sequence; the following months and years are where the sequence gets used. Reviewers sample: pick positions from the list, then trace each to an offer, a denial with its notice, or a documented removal.

What satisfies it: records connecting list positions to outcomes: offers in order, skip justifications where your policy permits skips, purge documentation applied uniformly, and the written policy language authorizing each.

Where agencies come up short: undocumented skips. There is often a legitimate reason a household was passed (wrong bedroom size for the available unit, no response to contact attempts), but if the reason wasn't recorded at the time, the file shows an agency departing from its own lottery for reasons nobody can now establish.

Ask 6: "Show me you can keep doing this"

Retention. Federal HCV rules require at least three years, and HUD's access rights are written broadly: full and free access to records, with the right to examine and copy. LIHTC and other programs generally require longer.

What satisfies it: the complete lottery record (all of the above) filed together, findable by someone other than the person who filed it, with a retention practice that matches your program's floor.

Where agencies come up short: the records exist but are scattered across a staff member's inbox, a shared drive, and a binder, and that staff member left last spring. Retention failures are rarely deliberate destruction; they're almost always fragmentation plus turnover.

The pattern in all six

Read the asks again and notice what none of them are. None ask whether the drawing was mathematically random. None ask whether staff acted in good faith. Every single one asks for a document, because the audit question is never "were you fair?" but "can you demonstrate it?"

That's also why preparing for these asks costs almost nothing at the time of the drawing and a great deal afterward. Every item above is cheap to capture in the week it's created. The audit-prep checklist turns the six asks into a pull-list you can walk before any review, or better, the week after the drawing itself.

Frequently asked questions

Who actually audits housing lotteries? Independent public accountants during the annual Single Audit, HUD PIH staff during monitoring reviews, state allocating agencies for LIHTC properties, and (less formally but more frequently) attorneys, advocates, and journalists through records requests and appeals. The record has to satisfy the strictest of these, because you don't choose which one arrives.

How far back can a review reach? At least the retention window: three years minimum under federal HCV rules, longer under LIHTC and many state programs. A matter under active dispute extends the horizon indefinitely, which is why records touching a challenge should be kept until it fully resolves.

What's the most common lottery-related finding? Mismatch between the written policy and the observed practice: a notice describing preferences the plan doesn't contain, a selection method the plan doesn't authorize, or skips the policy doesn't provide for. Second is missing proof of notice publication.

Is a lottery run by a third party audited differently? The asks are the same; the answers get shorter. A record generated and held outside the agency's control resolves ask 4's integrity question structurally, and usually arrives already organized against the other five. What it does not do is excuse the agency from asks 1, 2, and 5: policy, notice, and working the list remain the agency's own.

The short version

Six asks: the policy in effect, the notice and its proof, the frozen input, the order and its integrity, offers following the order, and retention. They are knowable in advance, which means they can be satisfied in advance, at the moment each record is created, for close to nothing. The agencies that have hard audits are not the ones that ran bad lotteries. They are the ones that ran good lotteries and kept bad files.


Lenora Castrellon is the founder of AuditDraw, which processes housing lotteries as a neutral third party for housing authorities, municipal housing departments, and affordable-housing organizations, and has been running real housing lotteries since 2019.

Nothing here is legal advice. Program rules vary by jurisdiction and funding source; your counsel and your funder's requirements govern.

The pull-list version of this post is the Lottery Audit-Prep Checklist: every ask as a checkbox, printable, with space to note where each document lives.