US · guidance
CMS Pub. 100-18, ch. 9, § 50.6.1
Routine Monitoring and Auditing
42 C.F.R. §§ 422.503(b)(4)(vi)(F), 423.504(b)(4)(vi)(F)
Sponsors must undertake monitoring and auditing to test and confirm compliance
with Medicare regulations, sub-regulatory guidance, contractual agreements, and
all applicable Federal and State laws, as well as internal policies and procedures to
protect against Medicare program noncompliance and potential FWA.
Monitoring activities are regular reviews performed as part of normal operations to
confirm ongoing compliance and to ensure that corrective actions are undertaken
and effective. An audit is a formal review of compliance with a particular set of
standards (e.g., policies and procedures, laws and regulations) used as base
measures.
Sponsors must develop a monitoring and auditing work plan that addresses the
risks associated with the Medicare Parts C and D benefits. The compliance officer
and compliance committee are key participants in this process.
Sponsors must have a system of ongoing monitoring and auditing that is reflective of
its size, organization, risks and resources to assess performance in, at a minimum,
areas identified as being at risk. The monitoring and auditing work plan must be
coordinated, overseen and/or executed by the compliance officer, assisted if desired
by the compliance department staff and/or the compliance committee. The
compliance officer may coordinate with the audit department, if any, in connection
with these activities. The compliance officer must receive regular reports from the
audit department or from those who are conducting the audits regarding the results
of auditing and monitoring and the status and effectiveness of corrective actions
taken. It is the responsibility of the compliance officer or his/her designee to provide
updates on monitoring and auditing results to the compliance committee, the CEO,
senior leadership and the sponsor’s governing body. In addition, for specific work
coordinated with the audit department, the compliance officer and Chief Audit
Executive may share the responsibility to provide updates on monitoring and
auditing results to the compliance committee, the CEO, senior leadership and the
sponsor’s governing body.
History
(Chapter 9 - Rev. 15, Issued: 07-27-12, Effective: 07-20-12; Implementation: 07-20 12)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-09-17
- Edition
- iom-2026-09-17
- Content hash
b4a0fc636a11dcac0ae10493e1894bef947e5fa5d4279c47183b0275ee1b4ea0
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.