Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 30.1

Certification Package for Internal Controls (CPIC) Requirements

Last amended: 2021Year: 2021Length: 1,204 wordsOfficial source
30.1 – Certification Package for Internal Controls (CPIC) Requirements (Rev. 11133, Issued:11-30-21, Effective: 10-01-21, Implementation: 12-31-21) NOTE: This section is only applicable to the following listed CMS Contractors: # Contractor Workload 1 DME MAC Jurisdiction A 2 DME MAC Jurisdiction B 3 DME MAC Jurisdiction C 4 DME MAC Jurisdiction D 5 Parts A & B MAC Jurisdiction 5 6 Parts A & B MAC Jurisdiction 6 7 Parts A & B MAC Jurisdiction 8 8 Parts A & B MAC Jurisdiction 15 9 Parts A & B MAC Jurisdiction E 10 Parts A & B MAC Jurisdiction F 11 Parts A & B MAC Jurisdiction H 12 Parts A & B MAC Jurisdiction J 13 Parts A & B MAC Jurisdiction K 14 Parts A & B MAC Jurisdiction L 15 Parts A & B MAC Jurisdiction M 16 Parts A & B MAC Jurisdiction N 17 Specialty MAC Railroad Board (RRB) 18 Pricing, Data Analysis, and Coding (PDAC) Contractor 19 Affordable Care Act Exchange Contractor 20 Benefits Coordination and Recovery Center (BCRC), Medicare Secondary Payer Recovery Contractor (MSPRC) 21 Commercial Repayment Center (CRC), MSPRC 22 Retiree Drug Subsidy (RDS) Part D Contractor The contractor certification process provides CMS with assurance that contractors are in compliance with the FMFIA, OMB Circular A-123, and CFO Act of 1990 by incorporating internal control standards into their operations. The contractor certification process supports the audit of CMS' financial statements by the Office of Inspector General (OIG) and the CMS Administrator's FMFIA assurance statement. This compliance is achieved by an annual certification statement included in its annual CPIC submission. CMS has required each contractor to certify that internal controls are in place to identify and correct areas of weakness in its operations. Contractors are expected to evaluate the effectiveness of their operations against CMS' control objectives discussed above. The control objectives represent the minimum expectations for contractor performance in the area of internal controls. Contractors shall have written policies and procedures regarding their annual CPIC preparation and submission process. Contractors shall also have written policies and procedures to address potential internal control deficiencies identified by employees and managers in the course of their daily operations. This includes the process for reporting issues upward through the appropriate levels of management, tracking and correcting deficiencies, and inclusion in the CPIC submission. The CPIC represents a summary of your internal control environment for the period October 1st through June 30th (the CPIC period), as certified by your organization. It shall include an explicit conclusion as to whether the internal controls over financial reporting are effective (see Section 30.1.1). All material weaknesses identified during this period shall be included in the CPIC submission. Contractors should consider the results of internal and external audits and reviews, such as GAO, OIG, and CFO Act audits, consultant reviews, management control reviews, CPE reviews, SSAE 18 audits, A-123 Appendix A reviews, and other similar activities. These findings should be classified as control deficiencies, significant deficiencies, or material weaknesses based upon the definitions provided in Section 30.6. The contractor shall submit one CPIC report for each type of contract (i.e., A/B, DME, & Specialty MAC workloads, Retiree Drug Subsidy (RDS), and Medicare Secondary Payer Recovery Contractor (MSPRC) workloads). The contractor shall follow these guidelines when submitting the CPIC for A/B, DME, & Specialty MACs: • Contractors with multiple A/B and DME MAC jurisdictions shall submit one CPIC report for each type of contract (i.e., A/B, Durable Medical Equipment (DME), & Specialty MAC workloads). Therefore. Contractors with multiple A/B and DME MACs jurisdiction shall submit a CPIC for each jurisdiction. Example Multiple A/B & DME CPIC Submission Situation: • XYZ Corporation has four (4) A/B and DME MAC jurisdictions A, C, 6, & M. • XYZ Corporation shall submit four (4) separate CPICs for each jurisdiction: o CPIC for DME Jurisdiction A o CPIC for DME Jurisdiction C o CPIC for A/B Jurisdiction 6 o CPIC for A/B Jurisdiction M • The Specialty MAC RRB shall submit a CPIC. • Contractors that transitioned out of the program prior to June 30th, and are not assuming additional workloads are not required to submit a CPIC. Electronic CPIC reports shall be received by CMS within fifteen (15) business days after June 30th. The contractor is not required to submit a hard copy report if it has the capability to insert electronic signatures or if the CPIC is sent from the VP of Operations’ email or the CFO’s email. An electronic version of all documents (including updates) submitted as part of your CPIC submission shall be sent to CMS’ Office of Financial Management (OFM) at internalcontrols@cms.hhs.gov as Microsoft Excel or Word files. Electronic copies shall also be sent as follows: • A/B, DME, and Specialty MACs shall send to the: o The assigned CFO Technical Monitor and the Financial Management (FM) Division Director of that CMS office location area. o Contracting Officer’s Representative (COR) of the A/B, DME, or Specialty MAC. • RDS and MSPRC Contractors shall send to the CMS COR. A hard copy is not required to be submitted. The CPIC Report Package shall include: • Certification Statement, see Section 30.2; • Executive Summary, see Section 30.3; • Description of your Risk Assessment Process, see Section 20.1. This should include a: o Matrix to illustrate the prioritization of risk and exposure factors o Narrative or flowchart that outlines the risk assessment process • CPIC Report of Material Weaknesses, see Section 30.4. Contractors shall submit an update for the period July 1st through September 30th to report any subsequently identified material weaknesses. The update shall be no more than a one page summary of any material weaknesses and the proposed corrective action. If no material weaknesses have been identified, the contractor shall submit the following for each jurisdiction or a combined statement for all jurisdictions: “As of September 30th, no material weaknesses (or no additional material weaknesses) have been identified during the period July 1 through September 30th for Fiscal Year 20XX”. The submission of the update should follow the same guidelines as the initial CPIC. The CPIC update is due within five (5) business days after September 30th. If a material weakness is identified, then a CAP shall be completed in accordance to the guidelines shown at Section 40.1. The file names for all electronic files submitted, as part of your CPIC package should begin with the three, four, or five letter abbreviation assigned to each contractor in Section 40.3. Additionally, in the subject line of your email submission, you shall include the corporate name of the entity submitting the CPIC. Maintain the appropriate and necessary documents to support any assertions and conclusions made during the self-assessment process. In your working papers, you are required to document the respective policies and procedures for each control objective reviewed. These policies and procedures should be in writing, be updated to reflect any changes in operations, and be operating effectively and efficiently within your organization. The supporting documentation and rationale for your certification statement, whether prepared internally or by an external organization, shall be available for review and copying by CMS and its authorized representatives. End Section 30.1 – Certification Package for Internal Controls (CPIC) Requirements: Back to Table of Contents
Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 30.1: Certification Package for Internal Controls (CPIC) Requirements | Justis AI