Bindinglaw

US · guidance

CMS Pub. 100-06, ch. 7, § 20.1

Risk Assessment

activein force · 2026-08-25 – presentas-observed

Risk assessment identifies areas that should be reviewed to determine which components of an

organization's operation present the highest probability of waste, loss, or misappropriation. The risk

assessment process is the identification, measurement, prioritization, and mitigation of risks. This process is

intended to provide the contractors with:

• Direction for what areas should get priority attention from management due to the nature, sensitivity,

and importance of the area's operations;

• A preliminary judgment from managers about the adequacy of existing internal control policies and

procedures to minimize or detect problems; and

• An early indication of where potential internal control weaknesses exist that should be corrected.

The CMS requires contractors to perform an annual risk assessment, to identify the most critical areas and

areas of greatest risk to be subjected to a review. Operational managers with knowledge and experience in

their particular business area shall perform risk assessments. Outside sources can assist with this process, but

should not be solely relied upon (e.g., Internal Audit departments, SSAE 18 audits, OMB Circular A-123

Appendix A reviews, etc.).

When performing your yearly risk assessment, you are to consider all results from final reports issued during

the fiscal year from internal and external reviews including GAO, OIG, CFO audit, Contractor Performance

Evaluation (CPE), CPIC, Contractor’s Monthly Bank Reconciliation Worksheet (CMBRW) and 1522

reviews, A-123 Appendix A reviews and results of your own or CMS-sponsored SSAE 18 audits. Any of

these findings could impact your risk assessment and preparation of your certification statement. Your risk

assessment process shall provide sufficient documentation to fully explain the reasoning behind and the

planned testing methodology for each selected area.

The contractor shall submit a description of the risk assessment process to CMS as an attachment with the

annual CPIC and maintain sufficient documentation to support the risk assessment process. Examples of

sufficient documentation are meeting agendas, meeting notes or minutes, and emails. The documentation

should be readily available for CMS review.

Below are the elements to include in the description or methodology of your risk assessment process:

• Who - List who is involved and state their roles and responsibilities.

• Where - List the geographical location(s) for which the certification applies. For multi-site

contractors, review and explain the roles for all sites, i.e., do they do their own risk assessment and

control objective testing. Describe the certification process for geographical locations.

• What – Describe the risk factors and the risk assessment process.

• When - List when the risk assessment process was completed.

• Why – Prioritize control objectives based upon their level of risk while ensuring high risk areas are

reviewed in accordance with the scoring criteria guidelines in Section 20.1.

NOTE: The A/B, DME, and Specialty MAC SOW may also include requirements regarding review

of CMS control objectives.

• How – Describe the scoring methodology and provide a description and definition for each risk and

exposure factor. Include specific value ranges used in your scoring methodology.

The contractor is encouraged to exceed the risk assessment approach provided below based on its unique

operations. The risk assessment process shall at a minimum include the following and shall be submitted as

part of the CPIC package:

Step 1 - Segment Operations

Segment the contractor’s operation into common operational areas of activity that can be evaluated. List the

primary components of the unit with consideration to the business purpose, objectives, or goals of the

auditable unit. Limit the list to the primary activities designed to achieve the goals and objectives of the

auditable unit. Include the CMS control objectives applicable to each auditable unit.

Step 2 - Prioritize Risk and Exposure Factors

Identify the primary risks and exposure factors that could jeopardize the achievement of the goals and

objectives of the unit as well as the organization's ability to achieve the objectives of reliable financial

reporting, safeguarding of assets, and compliance with budget, laws, regulations and instructions. Risk and

exposure factors can arise due to both internal and external circumstances. Document the definitions and

methodology of the risk and exposure factors used in the risk assessment process.

Step 3 – Create a Matrix to Illustrate the Prioritization of Risk and Exposure Factors

Create a matrix listing on the left axis by operational areas of activity (see Step 1 above). The top axis

should list all the risk and exposure factors of concern and determine the weight each column should have.

Some columns may weigh more than other columns. Develop a scoring methodology and provide a

description and definitions of this methodology used for each risk or exposure factor. This methodology can

use an absolute ranking or relative risk identification. Absolute ranking would assign predefined quantifiable

measures such as dollars, volume, or some other factor in ranges that would equate to a ranking score such

as high, medium or low. Relative risk ranking involves identifying the risk and exposure factors into natural

clusters by definition and assigning values to these clusters. Include a legend with the score ranges

representing high-risk, medium-risk, and low-risk on the risk matrix.

Assign a score to each cell based on the methodology predetermined. Retain notes to support scoring of key

risk factors such as “prior audits” and factors that are scored very high or very low. This will assist CMS in

evaluating the reasonableness of your risk assessment results. Total the scores for each line item (control

objective). The higher scores for each line item will prioritize the risk areas for consideration to be reviewed

to support the CPIC. If a high risk control objective is included in a current year Type II SSAE 18 audit, or

A-123 Appendix A review, you may rely on the SSAE 18 audit, or A-123 Appendix A review testing and

document this as the rationale for excluding it from testing.

The CMS considers system security to be a high risk area. Therefore, contractors shall include control

objective A.1 in their CPIC each year. All contractors are required to certify their system security

compliance. Contractors shall verify that a system's security plan meet CMS’ Minimum Security

Requirements as defined by the Business Partners Systems Security Manual (BPSSM). Contractors should

write a few paragraphs to self-certify that their organization has successfully completed all required security

activities including the security self-assessment of their Medicare IT systems and associated software in

accordance with the terms of their Contract. For more details, please see Section 3.4 – Certification of the

BPSSM, which can be found at the following hyperlink:

Hyperlink: CMS IOM Publication #: 100-17, CMS Business Partners Systems Security Manual, Revision

#: 12, Issued: 11/15/2013 [https://www.cms.gov/Regulations-and-

Guidance/Guidance/Manuals/Downloads/117_Systems_security.pdf]

Also, include the results of the testing of A.1 in the Executive Summary. See Section 30.3.

End Section 20.1 – Risk Assessment: Back to Table of Contents

History

(Rev. 331, Issued: 11-15-19, Effective: 10-01-19, Implementation: 12-17- 19)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
09c4dde4f88427a76f5d7ffaf5b6808a6040a7ca94b9f7e91270ed2e5c958aa8
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.