Bindinglaw

US · guidance

CMS Pub. 100-16, ch. 21, § 50.2.3

Governing Body

activein force · 2026-08-25 – presentas-observed

42 C.F.R. §§ 422.503(b)(4)(vi)(B), 423.504(b)(4)(vi)(B)

The sponsor’s governing body (e.g., Board of Directors or Board of Trustees) must

exercise reasonable oversight with respect to the implementation and effectiveness of the

sponsor’s compliance program. The governing body of the organization that contracted

with CMS or its parent company may oversee the Medicare compliance program. When

compliance issues are presented to the sponsor’s governing body, it should make further

inquiry and take appropriate action to ensure the issues are resolved.

The sponsor’s governing body may delegate compliance program oversight to a specific

committee of the governing body (e.g., Board Audit Committee or Board compliance

committee), but the governing body as a whole remains accountable for reviewing the

status of the compliance program. The scope of the delegation from the full governing

body to the governing body committee must be clear in the committee’s charter and

reporting.

The governing body must receive training and education as to the structure and operation

of the compliance program. The governing body should be knowledgeable about

compliance risks and strategies, should understand the measurements of outcome, and

should be able to gauge effectiveness of the compliance program.

Reasonable oversight by the governing body (assisted by a committee, if desired)

includes, but is not limited to:

• Approving the Standards of Conduct (this should be performed by the full

governing body and not a committee);

• Understanding the compliance program structure;

• Remaining informed about the compliance program outcomes, including results

of internal and external audits;

• Remaining informed about governmental compliance enforcement activity such

as Notices of Non-Compliance, Warning Letters and/or more formal sanctions;

• Receiving regularly scheduled, periodic updates from the compliance officer and

compliance committee; and

• Reviewing the results of performance and effectiveness assessments of the

compliance program.

The following are examples of activities in which the governing body, or a governing

body committee, may wish to have involvement. Alternatively, the governing body may

delegate some or all of these activities to senior management or to the compliance

committee:

• Development, implementation and annual review of compliance policies and

procedures;

• Approval of compliance policies and procedures;

• Review and approval of compliance and FWA training;

• Review and approval of compliance risk assessment;

• Review of internal and external audit work plans and audit results;

• Review and approval of corrective action plans resulting from audits;

• Review and approval of appointment of the compliance officer;

• Review and approval of performance goals for the compliance officer;

• Evaluation of the senior management team’s commitment to ethics and the

compliance program; and

• Review of dashboards, scorecards, self-assessment tools, etc., that reveal

compliance issues.

The governing body should collect and review measurable evidence that the compliance

program is detecting and correcting Medicare program noncompliance on a timely basis.

It is a best practice for the governing body to be provided with data showing that the

program has reduced the risks of program noncompliance and FWA. Some indicators of

an effective compliance program are:

• Use of quantitative measurement tools (e.g., scorecards, dashboard reports, key

performance indicators) to report, and track and compare over time, compliance

with key Medicare Parts C and D operations such as enrollment, appeals and

grievances, prescription drug benefit administration;

• Use of monitoring to track and review open/closed corrective action plans, FDR

compliance, Notices of Non-Compliance, warning letters, CMS sanctions,

marketing material approval rates, training completion/pass rates, etc.;

• Implementation of new or updated Medicare requirements (e.g., tracking HPMS

memo from receipt to implementation) including monitoring or auditing and

quality control measures to confirm appropriate and timely implementation;

• Increase or decrease in number and/or severity of complaints from employees,

FDRs, providers, beneficiaries through customer service calls or the Complaint

Tracking Module (CTM), marketing misrepresentations, Parts A and B issues,

etc.;

• Timely response to reported noncompliance and potential FWA, and effective

resolution (i.e., non-recurring issues);

• Consistent, timely and appropriate disciplinary action; and

• Detection of noncompliance and FWA issues through monitoring and auditing:

o Whether root cause was determined and corrective action appropriately

and timely implemented and tested for effectiveness;

o Detection of FWA trends and schemes via daily claims reviews, outlier

reports, pharmacy audits, etc.; and

o Actions taken in response to compliance reports submitted by FDRs.

The sponsor should ensure that CMS is able to validate, through review of governing

body meeting minutes or other documentation, the active engagement of the governing

body in the oversight of the Medicare compliance program. A governing body that is

appropriately engaged asks questions, requires follow-up on issues and takes action when

necessary.

History

(Chapter 21 - Rev. 109, Issued: 07-27-12, Effective: 07-20-12; Implementation: 07- 20-12)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
f92050fe4ddd85636c5e39dab49da564b677f489cab2d4f01b2d0c30573ac59a
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.
CMS Pub. 100-16, ch. 21, § 50.2.3 — Governing Body · binding.law