Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 20.2
Internal Control Objectives
20.2 - Internal Control Objectives
(Rev. 308, Issued: 10-26-18 Effective: 09- 01- 18, Implementation: 11-27-18)
Internal control objectives are established to identify risk and vulnerabilities. Control objectives may be set
for an entity as a whole, or be targeted to specific activities within the entity. Generally, objectives fall into
three categories:
1. Operations - relating to effective and efficient use of the organization's resources.
2. Financial Reporting - relating to preparation of reliable financial statements.
3. Compliance - relating to the organization's compliance with applicable laws and regulations.
An acceptable internal control system can be expected to provide reasonable assurance of achieving
objectives relating to the reliability of operations, financial reporting and compliance. Achievement of those
objectives depends on how activities within the organization's control are performed.
Section 50 lists the minimum set of control objectives. The contractor may add to the CMS control
objective list. For the respective operational areas selected for review in Step 2 of the Risk Assessment
discussion, cross-reference the high risk operational areas to CMS' or the contractor’s unique control
objectives on a work sheet. Some control objectives will apply to more than one operational area selected
for review. The control objectives identified in this step shall be validated by documentation of the control
activities (see Section 10.2.3.3) used as well as testing (see Section 20.4) that supports the control
objectives.
Reminder: Excessive control is costly and counterproductive. Too little control presents undue risk. There
should be a conscious effort made to achieve an appropriate balance.
End Section 20.2 – Internal Control Objectives: Back to Table of Contents