Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 30.1.1

OMB Circular A-123, Appendix A: Internal Controls Over Financial

Last amended: 2024Year: 2024Length: 2,649 wordsOfficial source
30.1.1 - OMB Circular A-123, Appendix A: Internal Controls Over Financial Reporting (ICOFR) (Rev. 13001, Issued: 12-13-24, Effective: 10-01-24, Implementation: 01-15-25) CMS contractors, including A/B, DME, and Specialty MACs, MSPRC and RDS, shall use the five steps below to assess the effectiveness of its internal control over financial reporting. Documentation shall occur within each of the basic steps, whether documenting the assessment methodology during the planning phase or documenting key processes and test results during the evaluation and testing steps. 1) Plan and Scope the Evaluation During this phase, the CMS contractor shall leverage existing internal and external audits/reviews performed (Such as SSAE 18 audits, A-123 Appendix A Internal Control Reviews, CPIC, 912 Evaluations, Federal Information Security Management (FISMA), Contractor Performance Evaluations (CPE), etc.) when conducting its assessment of internal control over financial reporting. Management shall consider the results of these audits/reviews in order to identify gaps between current control activities and the documentation of them. The control objectives of A, B, F, G, I, J, K, and L shall be considered, if applicable. If a CMS contractor had an SSAE 18 audit, or an A-123 Appendix A Internal Control Review in the current or past two fiscal years, it shall be used as a basis for the statement of assurance combined with other audits and reviews as appropriate. The contractor shall conduct additional testing for Circular A-123 as deemed necessary (see A-123 Appendix A Internal Control Review/SSAE 18 Reliance Examples chart). For example, if the A-123 Appendix A assurance statement was unqualified, then the contractor is not required to conduct additional testing. Similarly, if the SSAE 18 audit report was unqualified (no findings in Section I (Opinion Letter)), then the contractor is not required to conduct additional testing. However, if the previous year’s A-123 Appendix A assurance statement is qualified, then the contractor shall conduct additional testing on the control deficiencies identified. Similarly, if Section I of the prior year’s SSAE 18 audit report is qualified (one or more findings that have not been corrected and validated), then the contractor shall conduct additional testing on the findings identified in Section I and the exceptions identified in Section III (See A-123 Appendix A Internal Control Review Reliance Examples chart). If other audits and reviews contradict the SSAE 18 audit or A-123 Appendix A Internal Control Review, then that contradiction shall be addressed via testing if the issue has not already been corrected and validated. 2) Document Controls and Evaluate Design of Controls This step begins with the documentation and evaluation of entity-level controls. Consideration must be given to the five standards of internal control (control environment, risk assessment, control activities, information and communication, and monitoring) (see Section 10.2.3 – Standards for Internal Control) that can have a pervasive effect on the risk of error or fraud, and will aid in determining the nature and extent of internal control testing that may be required at the transaction or process level. The GAO issued an internal control evaluation tool (The GAO Internal Control Management and Evaluation Tool) to assess the effectiveness of internal control and identify important aspects of control in need of improvement. This tool shall be used in conducting your assessment. Contractors shall prepare cycle memos for financial reporting, accounts receivable, accounts payable, and claims expense (Note: Contractors may combine related cycles (e.g., accounts payable and claims expense). These major transaction cycles relate to significant line items on the financial reports. Cycle memos should identify the key control activities that are relied upon to assure the relevant financial statement assertions are met: • Existence and Occurrence: All reported transactions actually occurred during the reporting period and all assets and liabilities exist as of the reporting date. Recorded transactions represent economic events that actually occurred during a stated period of time. • Rights and Obligations: The entity legally owns all its assets collectively and all liabilities are legal obligations of the entity. Assets and liabilities reported on the Balance Sheet are bona fide rights and obligations of the entity as of that point in time. • Completeness: All assets, liabilities, and transactions that should be reported have been included, and no unauthorized transactions or balances are included. All transactions during a specific period should have been recorded in that period. No unrecorded assets, liabilities, transactions or omitted disclosures. • Valuation or Allocation: Assets, liabilities, revenue, and expenses have been included in the financial statements at appropriate amounts. Where applicable, all costs have been properly allocated. Assets and liabilities are recorded at appropriate amounts in accordance with relevant accounting principles and policies. • Presentation and Disclosure: The financial report is presented in the proper form and any required disclosures are present. Financial statement items are properly described, classified and fairly presented. Not all assertions will be significant to all accounts. A single key control will often not cover all assertions; which may necessitate several key controls to support the selected assertions for each line item. However, each assertion is applicable to every major transaction cycle and all associated assertions must be covered to avoid any control gaps. Documenting transaction flows accurately is one of the most important steps in the assessment process, as it provides a foundation for the A-123 assessment. Thorough, well-written documents and flowcharts can facilitate the review of key controls. The documentation should reflect an understanding, from beginning to end, of the underlying processes and document flows involved in each major transaction cycle. This would include the procedures for initiating, authorizing, recording, processing, and reporting accounts and transactions that affect the financial reports. The cycle memo shall include Information Technology (IT) key control activities pertinent to the transaction cycle. The documentation should start with the collection and review of documentation that already exists. The following are examples of existing documentation that could be used: • Existing policy and procedure manuals; • Existing forms and documents; • Documentation from independent auditors and the OIG; • Risk assessments; • Accounting manuals; • Memoranda; • Flowcharts; • Job descriptions; • Decision tables; • Procedural write-ups; and/or • Self-assessment reports. Interviews should be conducted with personnel who have knowledge of the relevant operations to validate that manuals, policies, forms, and documents are accurate and being applied. A major transaction cycle narrative is a written summary of the transaction process. For each major transaction cycle, the narrative describes: • The initiation point; • The processing type (e.g., automated versus manual, preventative versus detective); • The completion point; • Other data characteristics, such as source; receipt; processing; and transmission; • Key activities/class of transactions within the process; • Controls in place to mitigate the risk of financial statement errors; • Supervisor/manager review; process and calculations performed in preparation of financial reporting; and process outputs; • Use of computer application controls and controls over spreadsheets used in the preparation of financial reporting; • Identification of errors; types of errors found; reporting errors; and resolving errors; and • Ability of personnel to override the process or controls. Within the cycle memo, the key controls should be clearly identified by highlighting, bolding, or underlining. Contractors are responsible for reviewing and updating cycle memos to keep them current. Control activities are the specific policies, procedures, and activities that are established to manage or mitigate risks. Key controls are those controls designed to meet the control objectives and support management’s financial statement assertions. In other words, they are the controls that management relies upon to prevent and detect material errors and misstatements. For each key control activity, state: (a) the frequency of performance; (b) the specific steps performed; (c) how exceptions are resolved; and (d) how the performance of the control activity and related results/disposition are documented. Examples of control activities that may be identified include: • Top-level reviews of actual performance; o Compare major achievements to plans, goals, and objectives • Reviews by management at the functional or actual level; o Compare actual performance to planned or expected results • Management of human capital; o Match skills to organizational goals o Manage staff to ensure internal control objectives are achieved • Controls over information processing; o Edit checks of data o Control totals on data files o Access controls o Review of audit logs o Change controls o Disaster recovery • Physical controls over vulnerable assets; o Access controls to equipment or other assets o Periodic inventory of assets and reconciliation to control records • Establishment and review of performance measures and indicators; o Relationship monitoring of data • Segregation of duties; • Proper execution of transactions and events o Communicating names of authorizing officials o Proper signatures and authorizations • Accurate and timely recording of transactions and events o Interfaces to record transactions o Regular review of financial reports • Access restrictions to and accountability for resources and records; and o Periodic reviews of resources and job functions • Appropriate documentation of transactions and internal control. o Clear documentation o Readily available for examination o Documentation should be included in management directives, policies, or operating manuals To document management’s understanding of major transaction cycles, management should use a combination of the following: • Narratives; • Flowcharts; and • Control matrices. To illustrate this process, we have provided cycle memo guidelines in Section 60. Updated cycle memos shall be submitted to the CMS Internal Controls mailbox within fifteen business days after December 31. Note: The cycle memos must be 508 compliant when released to the Internal Controls mailbox. For information on 508 compliance, please visit the website at the following hyperlink: Hyperlink: The US Department of Health and Human Services (HHS) Section 508 Compliance Information In addition, the A/B, DME, and Specialty MAC contractors shall provide updated cycle memos to the SSAE 18 auditors. 3) Test Operating Effectiveness Testing of the operation of key controls shall be performed and documented (refer to “Plan and Scope the Evaluation” (above) as well as the chart below with regard to testing applicability), to determine whether the control is operating effectively, partially effectively, or not effectively. Testing shall address both manual and automated controls. Ideally, testing should be performed throughout the year. The results of testing completed prior to June 30th will form the basis of the June 30th assurance statement. As testing continues into the fourth quarter, the results of that testing, along with any items corrected since the June 30th assurance statement will be considered in the September 30th assurance statement update. The chart below is provided to assist contractors in determining when to conduct testing. A-123 Appendix A Internal Control Review/SSAE 18 Reliance Examples Scenar io Prior Fiscal Year 2 Prior Fiscal Year 1 Current Fiscal Year Additional Testing Required or Not Required* 1 No SSAE 18/A- 123 Appendix A Review No SSAE 18/A-123 Appendix A Review Unqualified Not Required 2 No SSAE 18/A- 123 Appendix A Review Unqualified No SSAE 18/A-123 Appendix A Review Not Required 3 Unqualified No SSAE 18/A-123 Appendix A Review No SSAE 18/A-123 Appendix A Review Not Required 4 Qualified Unqualified No SSAE 18/A-123 Appendix A Review Not Required 5 No SSAE 18/A- 123 Appendix A Review No SSAE 18/A-123 Appendix A Review Qualified Required 6 No SSAE 18/A- 123 Appendix A Review Qualified No SSAE 18/A-123 Appendix A Review and the Findings are Corrected and Validated by CMS (CAP Closure Letter Received) Not Required 7 Unqualified Qualified No SSAE 18/A-123 Appendix A Review and the Findings are Corrected and Validated by CMS (CAP Closure Letter Received) Not Required 8 Qualified No SSAE 18/A-123 Appendix A Review and the Findings are Corrected and Validated by CMS (CAP Closure Letter Received) No SSAE 18/A-123 Appendix A Review Not Required 9 Unqualified Qualified No SSAE 18/A-123 Appendix A Review and the Findings are NOT Corrected or Validated by CMS (No CAP Closure Letter) Required 10 No SSAE 18/A- 123 Appendix A Review Qualified No SSAE 18/A-123 Appendix A Review and the Findings are NOT Corrected or Validated by CMS (No CAP Closure Letter) Required Scenar io Prior Fiscal Year 2 Prior Fiscal Year 1 Current Fiscal Year Additional Testing Required or Not Required* 11 Qualified No SSAE 18/A-123 Appendix A Review and the Findings are NOT Corrected or Validated by CMS (No CAP Closure Letter) No SSAE 18/A-123 Appendix A Review and the Findings are NOT Corrected or Validated by CMS (No CAP Closure Letter) Required Unqualified Report SSAE 18: No findings in Section I A-123 Appendix A Internal Control Review: No material weaknesses were noted Qualified Report SSAE 18: 1 or More Findings in Section I A-123 Appendix A Internal Control Review: Material weaknesses were noted, but were not pervasive *Note: Assumes other subsequent audits and reviews do not contradict the SSAE 18/A-123 Appendix A Review or contradictions have been corrected and validated. 4) Identify and Correct Deficiencies If design or operating deficiencies are noted, the potential impact of control gaps or deficiencies on financial reporting shall be discussed with management. The magnitude or significance of the deficiency will determine if it should be categorized as a control deficiency, a significant deficiency, or a material weakness (see Section 30.6). Corrective action plans (CAPs) shall be created and implemented to remediate identified deficiencies (see Section 40). The contractor shall submit corrective action plans for all deficiencies (control deficiencies, significant deficiencies, and material weaknesses) identified as a result of A-123 Appendix A reviews and SSAE 18 Section I findings. 5) Report on Internal Controls / Certification Statement The culmination of the contractor’s assessment will be the assurance statement regarding its internal control over financial reporting. The statement will be one of three types: 1) Unqualified Statement of Assurance Each contractor shall submit, as part of the CPIC report, an assurance statement for internal controls over financial reporting (ICOFR) stating: “… (Contractor) has effective internal controls over financial reporting (ICOFR) in compliance with OMB Circular A-123, Appendix A.” NOTE: The contractor’s statement of assurance should be unqualified if this is consistent with the A-123 Appendix A Internal Control Review statement per the CPA firm report (augmented by internal reviews, if necessary). Similarly, if the SSAE 18 audit (augmented by internal reviews, if necessary) did not result in any Section I findings or the contractor has not classified any findings as material weaknesses, then an unqualified statement of assurance would be applicable. 2) Qualified Statement of Assurance Each contractor shall submit, as part of the CPIC report, an assurance statement for internal controls over financial reporting stating: “…(Contractor) has effective internal controls over financial reporting in compliance with OMB Circular A-123, Appendix A, except for the SSAE 18 Section I finding(s) and/or material weakness(es) identified in the attached Report of Material Weaknesses.” Note: The contractor’s statement of assurance should be qualified if this is consistent with the A-123 Appendix A Internal Control Review statement per the CPA firm report (augmented by internal reviews, if necessary). Similarly, if a SSAE 18 audit disclosed at least one Section I finding and/or internal reviews in the current year disclosed a material weakness, then a qualified statement of assurance (see above) or a statement of no assurance (see below) would be issued, depending on the pervasiveness of the Section I findings or material weakness. The results of work performed in other control-related activities may also be used to support your assertion as to the effectiveness of internal controls. 3) Statement of No Assurance Each contractor shall submit, as part of the CPIC report, an assurance statement for internal controls over financial reporting stating: “…(Contractor) is unable to provide assurance that its internal control over financial reporting was operating effectively due to the material weakness(es) identified in the attached Report of Material Weaknesses.” or “…(Contractor) did not fully implement the requirements included in OMB Circular A- 123, Appendix A and therefore cannot provide assurance that its internal control over financial reporting was operating effectively.” End Section 30.1.1 – OMB Circular A-123, Appendix A: Internal Controls Over Financial Reporting (ICOFR): Back to Table of Contents
Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 30.1.1: OMB Circular A-123, Appendix A: Internal Controls Over Financial | Justis AI