Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 20.1

Risk Assessment

Last amended: 2019Year: 2019Length: 1,137 wordsOfficial source
20.1 - Risk Assessment (Rev. 331, Issued: 11-15-19, Effective: 10-01-19, Implementation: 12-17- 19) Risk assessment identifies areas that should be reviewed to determine which components of an organization's operation present the highest probability of waste, loss, or misappropriation. The risk assessment process is the identification, measurement, prioritization, and mitigation of risks. This process is intended to provide the contractors with: • Direction for what areas should get priority attention from management due to the nature, sensitivity, and importance of the area's operations; • A preliminary judgment from managers about the adequacy of existing internal control policies and procedures to minimize or detect problems; and • An early indication of where potential internal control weaknesses exist that should be corrected. The CMS requires contractors to perform an annual risk assessment, to identify the most critical areas and areas of greatest risk to be subjected to a review. Operational managers with knowledge and experience in their particular business area shall perform risk assessments. Outside sources can assist with this process, but should not be solely relied upon (e.g., Internal Audit departments, SSAE 18 audits, OMB Circular A-123 Appendix A reviews, etc.). When performing your yearly risk assessment, you are to consider all results from final reports issued during the fiscal year from internal and external reviews including GAO, OIG, CFO audit, Contractor Performance Evaluation (CPE), CPIC, Contractor’s Monthly Bank Reconciliation Worksheet (CMBRW) and 1522 reviews, A-123 Appendix A reviews and results of your own or CMS-sponsored SSAE 18 audits. Any of these findings could impact your risk assessment and preparation of your certification statement. Your risk assessment process shall provide sufficient documentation to fully explain the reasoning behind and the planned testing methodology for each selected area. The contractor shall submit a description of the risk assessment process to CMS as an attachment with the annual CPIC and maintain sufficient documentation to support the risk assessment process. Examples of sufficient documentation are meeting agendas, meeting notes or minutes, and emails. The documentation should be readily available for CMS review. Below are the elements to include in the description or methodology of your risk assessment process: • Who - List who is involved and state their roles and responsibilities. • Where - List the geographical location(s) for which the certification applies. For multi-site contractors, review and explain the roles for all sites, i.e., do they do their own risk assessment and control objective testing. Describe the certification process for geographical locations. • What – Describe the risk factors and the risk assessment process. • When - List when the risk assessment process was completed. • Why – Prioritize control objectives based upon their level of risk while ensuring high risk areas are reviewed in accordance with the scoring criteria guidelines in Section 20.1. NOTE: The A/B, DME, and Specialty MAC SOW may also include requirements regarding review of CMS control objectives. • How – Describe the scoring methodology and provide a description and definition for each risk and exposure factor. Include specific value ranges used in your scoring methodology. The contractor is encouraged to exceed the risk assessment approach provided below based on its unique operations. The risk assessment process shall at a minimum include the following and shall be submitted as part of the CPIC package: Step 1 - Segment Operations Segment the contractor’s operation into common operational areas of activity that can be evaluated. List the primary components of the unit with consideration to the business purpose, objectives, or goals of the auditable unit. Limit the list to the primary activities designed to achieve the goals and objectives of the auditable unit. Include the CMS control objectives applicable to each auditable unit. Step 2 - Prioritize Risk and Exposure Factors Identify the primary risks and exposure factors that could jeopardize the achievement of the goals and objectives of the unit as well as the organization's ability to achieve the objectives of reliable financial reporting, safeguarding of assets, and compliance with budget, laws, regulations and instructions. Risk and exposure factors can arise due to both internal and external circumstances. Document the definitions and methodology of the risk and exposure factors used in the risk assessment process. Step 3 – Create a Matrix to Illustrate the Prioritization of Risk and Exposure Factors Create a matrix listing on the left axis by operational areas of activity (see Step 1 above). The top axis should list all the risk and exposure factors of concern and determine the weight each column should have. Some columns may weigh more than other columns. Develop a scoring methodology and provide a description and definitions of this methodology used for each risk or exposure factor. This methodology can use an absolute ranking or relative risk identification. Absolute ranking would assign predefined quantifiable measures such as dollars, volume, or some other factor in ranges that would equate to a ranking score such as high, medium or low. Relative risk ranking involves identifying the risk and exposure factors into natural clusters by definition and assigning values to these clusters. Include a legend with the score ranges representing high-risk, medium-risk, and low-risk on the risk matrix. Assign a score to each cell based on the methodology predetermined. Retain notes to support scoring of key risk factors such as “prior audits” and factors that are scored very high or very low. This will assist CMS in evaluating the reasonableness of your risk assessment results. Total the scores for each line item (control objective). The higher scores for each line item will prioritize the risk areas for consideration to be reviewed to support the CPIC. If a high risk control objective is included in a current year Type II SSAE 18 audit, or A-123 Appendix A review, you may rely on the SSAE 18 audit, or A-123 Appendix A review testing and document this as the rationale for excluding it from testing. The CMS considers system security to be a high risk area. Therefore, contractors shall include control objective A.1 in their CPIC each year. All contractors are required to certify their system security compliance. Contractors shall verify that a system's security plan meet CMS’ Minimum Security Requirements as defined by the Business Partners Systems Security Manual (BPSSM). Contractors should write a few paragraphs to self-certify that their organization has successfully completed all required security activities including the security self-assessment of their Medicare IT systems and associated software in accordance with the terms of their Contract. For more details, please see Section 3.4 – Certification of the BPSSM, which can be found at the following hyperlink: Hyperlink: CMS IOM Publication #: 100-17, CMS Business Partners Systems Security Manual, Revision #: 12, Issued: 11/15/2013 [https://www.cms.gov/Regulations-and- Guidance/Guidance/Manuals/Downloads/117_Systems_security.pdf] Also, include the results of the testing of A.1 in the Executive Summary. See Section 30.3. End Section 20.1 – Risk Assessment: Back to Table of Contents
Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 20.1: Risk Assessment | Justis AI