US · guidance
CMS Pub. 100-16, ch. 21, § 50.6.5
Audit of the Sponsor’s Operations and Compliance Program
42 C.F.R. §§ 422.503(b)(4)(vi)(F), 423.504(b)(4)(vi)(F)
The compliance officer and compliance committee must ensure the implementation of an
audit function appropriate to the sponsor’s size, scope and structure. The audit function
may be performed by a separate audit department or may be performed by the
compliance department. Staff dedicated to the audit function will be responsible for
monitoring and auditing the sponsor’s operational areas to ensure compliance with
Medicare regulations. Adequate resources must be devoted to the audit function
considering factors such as size and scope of the sponsor’s Medicare Part C and D
programs, its compliance history, current compliance risks, and the amount of resources
necessary to meet the goals of its annual work plan.
Participants in the audit function must be knowledgeable about CMS operational
requirements for the areas under review. Auditors may include, as needed, pharmacists,
nurses, physicians, certified public accountants, fraud investigators, SIU staff,
compliance staff with operational backgrounds and other highly skilled staff. These
specific roles need not reside within the audit department or compliance department.
Rather, they may reside in other departments provided their services are accessible to
perform the necessary audit responsibilities.
Sponsors must ensure that auditors are independent and do not engage in self-policing.
Operations staff may assist in audit activities provided the assistance is compatible with
the independence of the audit function. For example, operations staff may gather data for
samples requested by the auditor and may provide other types of information to auditors.
Sponsors must ensure that audit staff have access to the relevant personnel, information,
records and areas of operation under review, including the operational areas at the plan
and FDR level.
Sponsors must audit the effectiveness of the compliance program and the results must be
shared with the governing body. Audits of the compliance program should occur at least
annually. In order to avoid self-policing, sponsors who exclusively use compliance
department staff, including the compliance officer, for their auditing function should train
employees who are not part of the compliance department to perform the audit, or
outsource the audit to external auditors.
While the compliance department staff may not conduct the formal audit of the
effectiveness of the compliance program, it may administer less formal measures of
compliance program effectiveness, such as a self-assessment tool or dashboard or
scorecard in support of the compliance program effectiveness audit.
History
(Chapter 21 - Rev. 109, Issued: 07-27-12, Effective: 07-20-12; Implementation: 07- 20-12)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
2018904aa1a866b419ba892d8bde36a10c0ea0886debf479d9ae94b23498541a
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.