Bindinglaw

US · guidance

CMS Pub. 100-16, ch. 21, § 50.6.2

Development of a System to Identify Compliance Risks

activein force · 2026-08-25 – presentas-observed

42 C.F.R. §§ 422.503(b)(4)(vi)(F), 423.504(b)(4)(vi)(F)

Sponsors must establish and implement policies and procedures to conduct a formal

baseline assessment of the sponsor’s major compliance and FWA risk areas, such as

through a risk assessment. The sponsor’s assessment must take into account all Medicare

business operational areas. Each operational area must be assessed for the types and

levels of risks the area presents to the Medicare program and to the sponsor. Factors that

sponsors may consider in determining the risks associated with each area include, but are

not limited to:

• Size of department;

• Complexity of work;

• Amount of training that has taken place;

• Past compliance issues; and

• Budget.

Areas of particular concern for Medicare Parts C and D sponsors include, but are not

limited to, marketing and enrollment violations, agent/broker misrepresentation, selective

marketing, enrollment/disenrollment noncompliance, credentialing, quality assessment,

appeals and grievance procedures, benefit/formulary administration, transition policy,

protected classes policy, utilization management, accuracy of claims processing,

detection of potentially fraudulent claims, and FDR oversight and monitoring.

Risks identified by the risk assessment must be ranked to determine which risk areas will

have the greatest impact on the sponsor, and the sponsor must prioritize the monitoring

and auditing strategy accordingly. Risks change and evolve with changes in the law,

regulations, CMS requirements and operational matters. Therefore, there must be

ongoing review of potential risks of noncompliance and FWA and a periodic re-evaluation of the accuracy of the sponsor’s baseline assessments. Risk areas identified

through CMS audits and oversight, as well as through the sponsor’s own monitoring,

audits and investigations are priority risks. The results of the risk assessment inform the

development of the monitoring and audit work plan.

History

(Chapter 21 - Rev. 109, Issued: 07-27-12, Effective: 07-20-12; Implementation: 07- 20-12)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
6ad965bfc6800499cd1f9af1b41a4baf04ff3c64ae86ab0b54e094f5aba9cf0c
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.