US · guidance
CMS Pub. 100-18, ch. 9, § 50.6.5
Audit of the Sponsor’s Operations and Compliance Program
42 C.F.R. §§ 422.503(b)(4)(vi)(F), 423.504(b)(4)(vi)(F)
The compliance officer and compliance committee must ensure the implementation
of an audit function appropriate to the sponsor’s size, scope and structure. The
audit function may be performed by a separate audit department or may be
performed by the compliance department. Staff dedicated to the audit function will
be responsible for monitoring and auditing the sponsor’s operational areas to
ensure compliance with Medicare regulations. Adequate resources must be devoted
to the audit function considering factors such as size and scope of the sponsor’s
Medicare Part C and D programs, its compliance history, current compliance risks,
and the amount of resources necessary to meet the goals of its annual work plan.
Participants in the audit function must be knowledgeable about CMS operational
requirements for the areas under review. Auditors may include, as needed,
pharmacists, nurses, physicians, certified public accountants, fraud investigators,
SIU staff, compliance staff with operational backgrounds and other highly skilled
staff. These specific roles need not reside within the audit department or
compliance department. Rather, they may reside in other departments provided
their services are accessible to perform the necessary audit responsibilities.
Sponsors must ensure that auditors are independent and do not engage in self-policing. Operations staff may assist in audit activities provided the assistance is
compatible with the independence of the audit function. For example, operations
staff may gather data for samples requested by the auditor and may provide other
types of information to auditors. Sponsors must ensure that audit staff have access
to the relevant personnel, information, records and areas of operation under review,
including the operational areas at the plan and FDR level.
Sponsors must audit the effectiveness of the compliance program and the results
must be shared with the governing body. Audits of the compliance program should
occur at least annually. In order to avoid self-policing, sponsors who exclusively use
compliance department staff, including the compliance officer, for their auditing
function should train employees who are not part of the compliance department to
perform the audit, or outsource the audit to external auditors.
While the compliance department staff may not conduct the formal audit of the
effectiveness of the compliance program, it may administer less formal measures of
compliance program effectiveness, such as a self-assessment tool or dashboard or
scorecard in support of the compliance program effectiveness audit.
History
(Chapter 9 - Rev. 15, Issued: 07-27-12, Effective: 07-20-12; Implementation: 07-20 12)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-09-17
- Edition
- iom-2026-09-17
- Content hash
2018904aa1a866b419ba892d8bde36a10c0ea0886debf479d9ae94b23498541a
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.