Bindinglaw

US · guidance

CMS Pub. 100-06, ch. 7, § 40

Corrective Action Plans

activein force · 2026-08-25 – presentas-observed

CMS contractors are subject to various financial management and information

technology (IT) audits/reviews performed by the OIG, GAO, independent CPA firms,

and the CMS staff to provide reasonable assurance that contractors have developed and

implemented internal controls. The results of these audits/reviews indicate whether the

contractors’ internal controls are operating as designed. Correcting these deficiencies is

essential to improving financial management and internal control. Therefore, audit

resolution remains a top priority at CMS.

The CMS has established policies and procedures to ensure that the contractors have

appropriate CAPs for addressing findings identified through the following:

• CFO financial or information technology (IT) audits related to annual CFO

Financial Statement audits, which may include network vulnerability

assessment/security testing (NVA/ST);

• SSAE 18 audits;

• Health & Human Services (HHS), OIG Information Technology (IT) Controls

Assessments;

• Financial reviews conducted by the GAO;

• CMS’ 1522 and CMBRW workgroup reviews;

• CMS’ CPIC reviews; and

• OMB Circular A-123 Appendix A reviews.

Administrative cost audits, provider audits conducted by the OIG, the contractor initiated

systems security annual compliance audits, and system penetration tests are excluded

from these procedures. The word “finding” includes control deficiency, significant

deficiency, and material weakness. For SSAE 18 audits, CAPs to be submitted to CMS

are required for findings noted in the opinion letter only (Section I), not those reported in

Section III/IV of the SSAE 18 report. Section III/IV findings are not required to be

included on the Initial and Quarterly CAP Reports. Section III/IV findings shall be

tracked internally and corrected. Contractors are required to prepare and maintain

documentation to support the status and corrective actions taken on Section III/IV

findings. It shall be available for review and submitted to CMS central and/or IFM

office, upon request. For A-123 Appendix A reviews, the contractor shall submit

corrective action plans for all deficiencies: control deficiencies, significant deficiencies,

and material weaknesses.

Back to Table of Contents

History

(Rev. 10614, Issued: 03-23-21, Effective: 10-01-20, Implementation: 04-22-21)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
ae4eaccf5a64c7e3c6e26900cdd80ac4e586ea436e3882a451b420cae5a768f6
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.