US · guidance
CMS Pub. 100-06, ch. 7, § 40
Corrective Action Plans
CMS contractors are subject to various financial management and information
technology (IT) audits/reviews performed by the OIG, GAO, independent CPA firms,
and the CMS staff to provide reasonable assurance that contractors have developed and
implemented internal controls. The results of these audits/reviews indicate whether the
contractors’ internal controls are operating as designed. Correcting these deficiencies is
essential to improving financial management and internal control. Therefore, audit
resolution remains a top priority at CMS.
The CMS has established policies and procedures to ensure that the contractors have
appropriate CAPs for addressing findings identified through the following:
• CFO financial or information technology (IT) audits related to annual CFO
Financial Statement audits, which may include network vulnerability
assessment/security testing (NVA/ST);
• SSAE 18 audits;
• Health & Human Services (HHS), OIG Information Technology (IT) Controls
Assessments;
• Financial reviews conducted by the GAO;
• CMS’ 1522 and CMBRW workgroup reviews;
• CMS’ CPIC reviews; and
• OMB Circular A-123 Appendix A reviews.
Administrative cost audits, provider audits conducted by the OIG, the contractor initiated
systems security annual compliance audits, and system penetration tests are excluded
from these procedures. The word “finding” includes control deficiency, significant
deficiency, and material weakness. For SSAE 18 audits, CAPs to be submitted to CMS
are required for findings noted in the opinion letter only (Section I), not those reported in
Section III/IV of the SSAE 18 report. Section III/IV findings are not required to be
included on the Initial and Quarterly CAP Reports. Section III/IV findings shall be
tracked internally and corrected. Contractors are required to prepare and maintain
documentation to support the status and corrective actions taken on Section III/IV
findings. It shall be available for review and submitted to CMS central and/or IFM
office, upon request. For A-123 Appendix A reviews, the contractor shall submit
corrective action plans for all deficiencies: control deficiencies, significant deficiencies,
and material weaknesses.
Back to Table of Contents
History
(Rev. 10614, Issued: 03-23-21, Effective: 10-01-20, Implementation: 04-22-21)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
ae4eaccf5a64c7e3c6e26900cdd80ac4e586ea436e3882a451b420cae5a768f6
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.