US · guidance
CMS Pub. 100-06, ch. 7, § 30.1
Certification Package for Internal Controls (CPIC) Requirements
NOTE: This section is only applicable to the following listed CMS Contractors:
# Contractor Workload
1 DME MAC Jurisdiction A
2 DME MAC Jurisdiction B
3 DME MAC Jurisdiction C
4 DME MAC Jurisdiction D
5 Parts A & B MAC Jurisdiction 5
6 Parts A & B MAC Jurisdiction 6
7 Parts A & B MAC Jurisdiction 8
8 Parts A & B MAC Jurisdiction 15
9 Parts A & B MAC Jurisdiction E
10 Parts A & B MAC Jurisdiction F
11 Parts A & B MAC Jurisdiction H
12 Parts A & B MAC Jurisdiction J
13 Parts A & B MAC Jurisdiction K
14 Parts A & B MAC Jurisdiction L
15 Parts A & B MAC Jurisdiction M
16 Parts A & B MAC Jurisdiction N
17 Specialty MAC Railroad Board (RRB)
18 Pricing, Data Analysis, and Coding (PDAC) Contractor
19 Affordable Care Act Exchange Contractor
20 Benefits Coordination and Recovery Center (BCRC),
Medicare Secondary Payer Recovery Contractor (MSPRC)
21 Commercial Repayment Center (CRC), MSPRC
22 Retiree Drug Subsidy (RDS) Part D Contractor
The contractor certification process provides CMS with assurance that contractors are in compliance with
the FMFIA, OMB Circular A-123, and CFO Act of 1990 by incorporating internal control standards into
their operations. The contractor certification process supports the audit of CMS' financial statements by the
Office of Inspector General (OIG) and the CMS Administrator's FMFIA assurance statement.
This compliance is achieved by an annual certification statement included in its annual CPIC submission.
CMS has required each contractor to certify that internal controls are in place to identify and correct areas of
weakness in its operations. Contractors are expected to evaluate the effectiveness of their operations against
CMS' control objectives discussed above. The control objectives represent the minimum expectations for
contractor performance in the area of internal controls.
Contractors shall have written policies and procedures regarding their annual CPIC preparation and
submission process. Contractors shall also have written policies and procedures to address potential internal
control deficiencies identified by employees and managers in the course of their daily operations. This
includes the process for reporting issues upward through the appropriate levels of management, tracking and
correcting deficiencies, and inclusion in the CPIC submission.
The CPIC represents a summary of your internal control environment for the period October 1st through
June 30th (the CPIC period), as certified by your organization. It shall include an explicit conclusion as to
whether the internal controls over financial reporting are effective (see Section 30.1.1). All material
weaknesses identified during this period shall be included in the CPIC submission. Contractors should
consider the results of internal and external audits and reviews, such as GAO, OIG, and CFO Act audits,
consultant reviews, management control reviews, CPE reviews, SSAE 18 audits, A-123 Appendix A
reviews, and other similar activities. These findings should be classified as control deficiencies, significant
deficiencies, or material weaknesses based upon the definitions provided in Section 30.6.
The contractor shall submit one CPIC report for each type of contract (i.e., A/B, DME, & Specialty MAC
workloads, Retiree Drug Subsidy (RDS), and Medicare Secondary Payer Recovery Contractor (MSPRC)
workloads). The contractor shall follow these guidelines when submitting the CPIC for A/B, DME, &
Specialty MACs:
• Contractors with multiple A/B and DME MAC jurisdictions shall submit one CPIC report for each
type of contract (i.e., A/B, Durable Medical Equipment (DME), & Specialty MAC workloads).
Therefore. Contractors with multiple A/B and DME MACs jurisdiction shall submit a CPIC for each
jurisdiction.
Example Multiple A/B & DME CPIC Submission Situation:
• XYZ Corporation has four (4) A/B and DME MAC jurisdictions A, C, 6, & M.
• XYZ Corporation shall submit four (4) separate CPICs for each jurisdiction:
o CPIC for DME Jurisdiction A
o CPIC for DME Jurisdiction C
o CPIC for A/B Jurisdiction 6
o CPIC for A/B Jurisdiction M
• The Specialty MAC RRB shall submit a CPIC.
• Contractors that transitioned out of the program prior to June 30th, and are not assuming additional
workloads are not required to submit a CPIC.
Electronic CPIC reports shall be received by CMS within fifteen (15) business days after June 30th. The
contractor is not required to submit a hard copy report if it has the capability to insert electronic signatures
or if the CPIC is sent from the VP of Operations’ email or the CFO’s email.
An electronic version of all documents (including updates) submitted as part of your CPIC submission shall
be sent to CMS’ Office of Financial Management (OFM) at internalcontrols@cms.hhs.gov as Microsoft
Excel or Word files. Electronic copies shall also be sent as follows:
• A/B, DME, and Specialty MACs shall send to the:
o The assigned CFO Technical Monitor and the Financial Management (FM) Division Director
of that CMS office location area.
o Contracting Officer’s Representative (COR) of the A/B, DME, or Specialty MAC.
• RDS and MSPRC Contractors shall send to the CMS COR.
A hard copy is not required to be submitted.
The CPIC Report Package shall include:
• Certification Statement, see Section 30.2;
• Executive Summary, see Section 30.3;
• Description of your Risk Assessment Process, see Section 20.1. This should include a:
o Matrix to illustrate the prioritization of risk and exposure factors
o Narrative or flowchart that outlines the risk assessment process
• CPIC Report of Material Weaknesses, see Section 30.4.
Contractors shall submit an update for the period July 1st through September 30th to report any
subsequently identified material weaknesses. The update shall be no more than a one page summary of any
material weaknesses and the proposed corrective action. If no material weaknesses have been identified, the
contractor shall submit the following for each jurisdiction or a combined statement for all jurisdictions: “As
of September 30th, no material weaknesses (or no additional material weaknesses) have been identified
during the period July 1 through September 30th for Fiscal Year 20XX”. The submission of the update
should follow the same guidelines as the initial CPIC. The CPIC update is due within five (5) business days
after September 30th. If a material weakness is identified, then a CAP shall be completed in accordance to
the guidelines shown at Section 40.1.
The file names for all electronic files submitted, as part of your CPIC package should begin with the three,
four, or five letter abbreviation assigned to each contractor in Section 40.3. Additionally, in the subject line
of your email submission, you shall include the corporate name of the entity submitting the CPIC.
Maintain the appropriate and necessary documents to support any assertions and conclusions made during
the self-assessment process. In your working papers, you are required to document the respective policies
and procedures for each control objective reviewed. These policies and procedures should be in writing, be
updated to reflect any changes in operations, and be operating effectively and efficiently within your
organization.
The supporting documentation and rationale for your certification statement, whether prepared internally or
by an external organization, shall be available for review and copying by CMS and its authorized
representatives.
End Section 30.1 – Certification Package for Internal Controls (CPIC) Requirements: Back to Table of
Contents
History
(Rev. 11133, Issued:11-30-21, Effective: 10-01-21, Implementation: 12-31-21)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
2705215c00d3e2383a8a4100021737dc71e3a219000deb4b52944bf437778d35
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.