Bindinglaw

US · guidance

CMS Pub. 100-06, ch. 8, § 80.4

Internal Quality Control

activein force · 2026-08-25 – presentas-observed

The fourth general standard for government auditing is:

"Audit organizations conducting government audits should have an appropriate internal

quality control system in place and participate in an external quality control review

program."

Establish an internal quality control program and provide reasonable assurance that your

Medicare audit department:

• Has established, and is following, adequate audit policies and procedures; and

• Has adopted, and is following, applicable auditing standards.

A – External Quality Control Review (Review of the Internal Quality Control

System)

OIG will perform an external review of your internal quality control system. CMS will

also review your internal quality review program as part of the Audit Quality Review

Program (AQRP) or using other review mechanisms. Any tests of your internal quality

control system must evaluate:

• The existence of such a system;

• Compliance with the system; and

• The effectiveness of the system.

B – Establishment of an Internal Quality Control System

Establish internal quality control policies and procedures for your Medicare audit

department, i.e., all Medicare audit and payment related activities. Communicate these

policies and procedures to Medicare audit personnel. While the objective of internal

quality control systems is always the same, the nature and extent of such systems can

vary based on a number of factors. Normally, documentation of internal quality control

policies and procedures would be expected to be more extensive in a larger contractor

than a smaller contractor, and more extensive in a multi-office contractor than in a single-

office contractor. Therefore, in developing such a system, consider the following factors:

• The size of its Medicare audit department;

• The degree of operating autonomy allowed to your personnel and audit offices;

• The nature of your work;

• Your organizational structure; and

• The cost effectiveness of an internal quality control system.

C – Elements of Internal Quality Control

In addition to the other elements of Generally Accepted Auditing Standards (GAAS),

consider each of the elements of internal quality control listed below, to the extent

applicable to your operating environment, in establishing your internal quality control

policies and procedures. The nine elements of internal quality control taken from the

AICPA Statements of Quality Control Standards are:

• Independence – To be free from financial, business, family, and other

relationships involving the provider when required by the profession's code of

conduct.

• Consultation – To have personnel seek assistance, when necessary, from

competent authorities, so that accounting or auditing issues are resolved properly.

• Assignment of Personnel to Audits – To have personnel on the job who have the

technical training and competence required for the circumstances.

• Supervision – To determine that work is planned and carried out efficiently and in

conformity with professional standards.

• Advancement – To have people at all levels of responsibility that are capable of

handling the responsibilities involved.

• Hiring – To have competent, properly motivated people of integrity involved in

audits.

• Professional Development – To provide staff with the training needed to fulfill

their responsibilities and to keep them abreast of current developments.

• Acceptance and Continuance (fraud and abuse) – To anticipate potential problems

with providers where fraud or abuse is suspected.

• Inspection – To conduct periodic internal reviews to be sure that the other

elements of the internal quality control system are working.

D – Application of the Elements of Internal Quality Control to the Medicare

Environment

(1) Independence

Establish policies and procedures to provide reasonable assurance that all Medicare audit

and reimbursement professional staff maintain their independence so as not to impair, or

appear to impair, your independence in carrying out its Medicare audit responsibilities.

You must:

• Designate an individual or group to provide guidance and to resolve questions of

independence matters.

• Communicate, in writing, the policies and procedures relating to independence to

personnel at all levels.

• Obtain the confirmation of independence of firms engaged to perform audits or

segments of audits. Obtain a separate representation for each audit.

• Obtain from your personnel periodic, written representations of their

independence on an annual basis, stating that:

− They are familiar with your independence policies and procedures.

− Financial interests in providers and related entities are not held and were

not held during the period. Any such financial interests must be listed,

detailing the number of shares or the dollar amounts.

− Personal, professional, or family relationships with providers and related

entities do not exist and did not exist during the period. List any relationships

with an explanation, including the names of the parties to the transaction.

− There were no transactions that might impair the extent of inquiry or

disclosure, or affect audit findings in any way. List any transactions with an

explanation, including the names of the parties to the transaction.

(2) Consultation

Establish policies and procedures to provide reasonable assurance that staff will seek

assistance, to the extent necessary, from persons having the appropriate levels of

knowledge, competence, judgment, and authority. You must:

• Maintain technical manuals (e.g., SAS) and Medicare manuals.

• Issue memoranda or other pertinent material to staff regarding Medicare payment

issues.

• Inform staff of procedures to follow in resolving technical problems, including

referrals to CMS and industry associations.

• Maintain subject files containing the results of consultations for reference and

research purposes.

(3) Assignment of Personnel to Audits

Establish policies and procedures to provide reasonable assurance that persons who are

assigned to perform audits have the degree of technical training and competence required

for the circumstances.

Describe the method used to assign professional personnel to audits, including:

• The basis on which assignments are made;

• How staff are advised of their assignments, whether orally or in writing;

• Who is responsible for making staff assignments on a day-to-day basis; and

• How staff are informed of estimated time requirements and of any special skills or

experience that a given assignment may demand.

(4) Supervision

Establish procedures for supervision that are distinct from responsibilities of individuals

to adequately plan and supervise the work on a particular audit.

Assure that the policies and procedures for planning, performance, and supervision of

audits meet audit standards of quality. You must:

y Provide procedures for planning individual audits in accordance with

Medicare instructions, such as:

− The development of proposed audit programs;

− The determination of staffing requirements and the need for specialized

knowledge; and

− The development of estimates of time required to complete the audit.

y Provide procedures for maintaining standards of quality for work, such as:

− Guidelines for the form and content of working papers;

− Procedures for resolving differences of professional judgment among

members of an audit team; and

− Standard forms, checklists, and questionnaires appropriate to assist in the

performance of audits.

− Provide procedures for reviewing audit working papers and reports.

(5) Hiring

Prepare staff job descriptions and policies and procedures for hiring to provide reasonable

assurance that those employed are able to perform audits competently. It must:

• Plan for staffing needs at all levels;

• Establish quantified hiring objectives based on current workload, anticipated

changes in workload, staff turnover, individual advancement and retirement, and

current Medicare budget; and

• Establish qualifications and guidelines for evaluating potential hires at each

professional level.

(6) Professional Development

Establish policies and procedures for professional development to provide reasonable

assurance that staff will have the knowledge required to enable them to fulfill assigned

responsibilities and to progress within your Medicare audit department. The Professional

Development Standard of internal quality control addresses the appropriateness of the

professional education to the achievement of audit quality. You must:

• Establish a plan for meeting its CET requirements and communicate it to

Medicare audit staff; and

• Provide for on-the-job training, such as varying assignments among audit staff,

assigning staff to different supervisors.

(7) Advancement

Establish policies and procedures for advancing staff to provide reasonable assurance that

those selected for advancement have the qualifications necessary for fulfillment of the

responsibilities assigned. You must:

• Specify qualifications deemed necessary for the various levels of responsibility

within its Medicare audit department; and

• Evaluate the performance of personnel and periodically advise staff of their

progress. Maintain personnel files containing documentation relating to the

evaluation process.

(8) Acceptance and Continuance (Fraud and Abuse)

The usual considerations for acceptance and continuance of clients of CPA firms are not

applicable to the Medicare audit environment. Although the nature of the relationship

with the audit subject is materially different from that experienced by a CPA firm, there

is equivalent concern with a Medicare audit in which fraud and abuse is suspected.

Accordingly, make a full and immediate disclosure to your CMS RO and to the OIG, as

appropriate, of suspected or detected fraud, abuse, illegal acts, or material misstatements

or misrepresentations on the part of any provider, other organization or individual. (See

§140ff of this chapter.)

(9) Inspection

Establish policies and procedures for inspection to provide reasonable assurance that the

procedures relating to the other elements of internal quality control are being effectively

applied. Monitor the effectiveness of inspection policies and procedures. Develop the

procedures for inspection and ensure that inspections are performed by individuals acting

on behalf of your management. You must:

• Prepare instructions and review programs for use in conducting inspection

activities;

• Establish frequency and timing of inspection activities and criteria for selection of

engagements; and

• Provide for reporting inspection findings to the appropriate management levels

and for monitoring actions taken or planned.

History

(Rev. 84, Issued: 11-16-05; Effective Date: 12-05-05; Implementation Date: 12-05- 05)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
89883fa3395f78b909a53a9a26afaf3c8819b5a17bccf83f1bba5bcdf9b5bea1
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.