US · guidance
CMS Pub. 100-06, ch. 7, § 20.1
Risk Assessment
Risk assessment identifies areas that should be reviewed to determine which components of an
organization's operation present the highest probability of waste, loss, or misappropriation. The risk
assessment process is the identification, measurement, prioritization, and mitigation of risks. This process is
intended to provide the contractors with:
• Direction for what areas should get priority attention from management due to the nature, sensitivity,
and importance of the area's operations;
• A preliminary judgment from managers about the adequacy of existing internal control policies and
procedures to minimize or detect problems; and
• An early indication of where potential internal control weaknesses exist that should be corrected.
The CMS requires contractors to perform an annual risk assessment, to identify the most critical areas and
areas of greatest risk to be subjected to a review. Operational managers with knowledge and experience in
their particular business area shall perform risk assessments. Outside sources can assist with this process, but
should not be solely relied upon (e.g., Internal Audit departments, SSAE 18 audits, OMB Circular A-123
Appendix A reviews, etc.).
When performing your yearly risk assessment, you are to consider all results from final reports issued during
the fiscal year from internal and external reviews including GAO, OIG, CFO audit, Contractor Performance
Evaluation (CPE), CPIC, Contractor’s Monthly Bank Reconciliation Worksheet (CMBRW) and 1522
reviews, A-123 Appendix A reviews and results of your own or CMS-sponsored SSAE 18 audits. Any of
these findings could impact your risk assessment and preparation of your certification statement. Your risk
assessment process shall provide sufficient documentation to fully explain the reasoning behind and the
planned testing methodology for each selected area.
The contractor shall submit a description of the risk assessment process to CMS as an attachment with the
annual CPIC and maintain sufficient documentation to support the risk assessment process. Examples of
sufficient documentation are meeting agendas, meeting notes or minutes, and emails. The documentation
should be readily available for CMS review.
Below are the elements to include in the description or methodology of your risk assessment process:
• Who - List who is involved and state their roles and responsibilities.
• Where - List the geographical location(s) for which the certification applies. For multi-site
contractors, review and explain the roles for all sites, i.e., do they do their own risk assessment and
control objective testing. Describe the certification process for geographical locations.
• What – Describe the risk factors and the risk assessment process.
• When - List when the risk assessment process was completed.
• Why – Prioritize control objectives based upon their level of risk while ensuring high risk areas are
reviewed in accordance with the scoring criteria guidelines in Section 20.1.
NOTE: The A/B, DME, and Specialty MAC SOW may also include requirements regarding review
of CMS control objectives.
• How – Describe the scoring methodology and provide a description and definition for each risk and
exposure factor. Include specific value ranges used in your scoring methodology.
The contractor is encouraged to exceed the risk assessment approach provided below based on its unique
operations. The risk assessment process shall at a minimum include the following and shall be submitted as
part of the CPIC package:
Step 1 - Segment Operations
Segment the contractor’s operation into common operational areas of activity that can be evaluated. List the
primary components of the unit with consideration to the business purpose, objectives, or goals of the
auditable unit. Limit the list to the primary activities designed to achieve the goals and objectives of the
auditable unit. Include the CMS control objectives applicable to each auditable unit.
Step 2 - Prioritize Risk and Exposure Factors
Identify the primary risks and exposure factors that could jeopardize the achievement of the goals and
objectives of the unit as well as the organization's ability to achieve the objectives of reliable financial
reporting, safeguarding of assets, and compliance with budget, laws, regulations and instructions. Risk and
exposure factors can arise due to both internal and external circumstances. Document the definitions and
methodology of the risk and exposure factors used in the risk assessment process.
Step 3 – Create a Matrix to Illustrate the Prioritization of Risk and Exposure Factors
Create a matrix listing on the left axis by operational areas of activity (see Step 1 above). The top axis
should list all the risk and exposure factors of concern and determine the weight each column should have.
Some columns may weigh more than other columns. Develop a scoring methodology and provide a
description and definitions of this methodology used for each risk or exposure factor. This methodology can
use an absolute ranking or relative risk identification. Absolute ranking would assign predefined quantifiable
measures such as dollars, volume, or some other factor in ranges that would equate to a ranking score such
as high, medium or low. Relative risk ranking involves identifying the risk and exposure factors into natural
clusters by definition and assigning values to these clusters. Include a legend with the score ranges
representing high-risk, medium-risk, and low-risk on the risk matrix.
Assign a score to each cell based on the methodology predetermined. Retain notes to support scoring of key
risk factors such as “prior audits” and factors that are scored very high or very low. This will assist CMS in
evaluating the reasonableness of your risk assessment results. Total the scores for each line item (control
objective). The higher scores for each line item will prioritize the risk areas for consideration to be reviewed
to support the CPIC. If a high risk control objective is included in a current year Type II SSAE 18 audit, or
A-123 Appendix A review, you may rely on the SSAE 18 audit, or A-123 Appendix A review testing and
document this as the rationale for excluding it from testing.
The CMS considers system security to be a high risk area. Therefore, contractors shall include control
objective A.1 in their CPIC each year. All contractors are required to certify their system security
compliance. Contractors shall verify that a system's security plan meet CMS’ Minimum Security
Requirements as defined by the Business Partners Systems Security Manual (BPSSM). Contractors should
write a few paragraphs to self-certify that their organization has successfully completed all required security
activities including the security self-assessment of their Medicare IT systems and associated software in
accordance with the terms of their Contract. For more details, please see Section 3.4 – Certification of the
BPSSM, which can be found at the following hyperlink:
Hyperlink: CMS IOM Publication #: 100-17, CMS Business Partners Systems Security Manual, Revision
#: 12, Issued: 11/15/2013 [https://www.cms.gov/Regulations-and-
Guidance/Guidance/Manuals/Downloads/117_Systems_security.pdf]
Also, include the results of the testing of A.1 in the Executive Summary. See Section 30.3.
End Section 20.1 – Risk Assessment: Back to Table of Contents
History
(Rev. 331, Issued: 11-15-19, Effective: 10-01-19, Implementation: 12-17- 19)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
09c4dde4f88427a76f5d7ffaf5b6808a6040a7ca94b9f7e91270ed2e5c958aa8
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.