Medicare Financial Management Manual (Pub. 100-06), Ch. 7 § 30.1.1
OMB Circular A-123, Appendix A: Internal Controls Over Financial
30.1.1 - OMB Circular A-123, Appendix A: Internal Controls Over Financial
Reporting (ICOFR)
(Rev. 13001, Issued: 12-13-24, Effective: 10-01-24, Implementation: 01-15-25)
CMS contractors, including A/B, DME, and Specialty MACs, MSPRC and RDS, shall use the five steps
below to assess the effectiveness of its internal control over financial reporting. Documentation shall occur
within each of the basic steps, whether documenting the assessment methodology during the planning phase
or documenting key processes and test results during the evaluation and testing steps.
1) Plan and Scope the Evaluation
During this phase, the CMS contractor shall leverage existing internal and external audits/reviews performed
(Such as SSAE 18 audits, A-123 Appendix A Internal Control Reviews, CPIC, 912 Evaluations, Federal
Information Security Management (FISMA), Contractor Performance Evaluations (CPE), etc.) when
conducting its assessment of internal control over financial reporting. Management shall consider the results
of these audits/reviews in order to identify gaps between current control activities and the documentation of
them. The control objectives of A, B, F, G, I, J, K, and L shall be considered, if applicable.
If a CMS contractor had an SSAE 18 audit, or an A-123 Appendix A Internal Control Review in the current
or past two fiscal years, it shall be used as a basis for the statement of assurance combined with other audits
and reviews as appropriate. The contractor shall conduct additional testing for Circular A-123 as deemed
necessary (see A-123 Appendix A Internal Control Review/SSAE 18 Reliance Examples chart). For
example, if the A-123 Appendix A assurance statement was unqualified, then the contractor is not required
to conduct additional testing. Similarly, if the SSAE 18 audit report was unqualified (no findings in Section I
(Opinion Letter)), then the contractor is not required to conduct additional testing. However, if the previous
year’s A-123 Appendix A assurance statement is qualified, then the contractor shall conduct additional
testing on the control deficiencies identified. Similarly, if Section I of the prior year’s SSAE 18 audit report
is qualified (one or more findings that have not been corrected and validated), then the contractor shall
conduct additional testing on the findings identified in Section I and the exceptions identified in Section III
(See A-123 Appendix A Internal Control Review Reliance Examples chart). If other audits and reviews
contradict the SSAE 18 audit or A-123 Appendix A Internal Control Review, then that contradiction shall be
addressed via testing if the issue has not already been corrected and validated.
2) Document Controls and Evaluate Design of Controls
This step begins with the documentation and evaluation of entity-level controls. Consideration must be
given to the five standards of internal control (control environment, risk assessment, control activities,
information and communication, and monitoring) (see Section 10.2.3 – Standards for Internal Control) that
can have a pervasive effect on the risk of error or fraud, and will aid in determining the nature and extent of
internal control testing that may be required at the transaction or process level. The GAO issued an internal
control evaluation tool (The GAO Internal Control Management and Evaluation Tool) to assess the
effectiveness of internal control and identify important aspects of control in need of improvement. This tool
shall be used in conducting your assessment.
Contractors shall prepare cycle memos for financial reporting, accounts receivable, accounts payable, and
claims expense (Note: Contractors may combine related cycles (e.g., accounts payable and claims expense).
These major transaction cycles relate to significant line items on the financial reports. Cycle memos should
identify the key control activities that are relied upon to assure the relevant financial statement assertions are
met:
• Existence and Occurrence: All reported transactions actually occurred during the reporting period
and all assets and liabilities exist as of the reporting date. Recorded transactions represent economic
events that actually occurred during a stated period of time.
• Rights and Obligations: The entity legally owns all its assets collectively and all liabilities are legal
obligations of the entity. Assets and liabilities reported on the Balance Sheet are bona fide rights and
obligations of the entity as of that point in time.
• Completeness: All assets, liabilities, and transactions that should be reported have been included,
and no unauthorized transactions or balances are included. All transactions during a specific period
should have been recorded in that period. No unrecorded assets, liabilities, transactions or omitted
disclosures.
• Valuation or Allocation: Assets, liabilities, revenue, and expenses have been included in the
financial statements at appropriate amounts. Where applicable, all costs have been properly
allocated. Assets and liabilities are recorded at appropriate amounts in accordance with relevant
accounting principles and policies.
• Presentation and Disclosure: The financial report is presented in the proper form and any required
disclosures are present. Financial statement items are properly described, classified and fairly
presented.
Not all assertions will be significant to all accounts. A single key control will often not cover all assertions;
which may necessitate several key controls to support the selected assertions for each line item. However,
each assertion is applicable to every major transaction cycle and all associated assertions must be covered to
avoid any control gaps.
Documenting transaction flows accurately is one of the most important steps in the assessment process, as it
provides a foundation for the A-123 assessment. Thorough, well-written documents and flowcharts can
facilitate the review of key controls. The documentation should reflect an understanding, from beginning to
end, of the underlying processes and document flows involved in each major transaction cycle. This would
include the procedures for initiating, authorizing, recording, processing, and reporting accounts and
transactions that affect the financial reports. The cycle memo shall include Information Technology (IT) key
control activities pertinent to the transaction cycle.
The documentation should start with the collection and review of documentation that already exists. The
following are examples of existing documentation that could be used:
• Existing policy and procedure manuals;
• Existing forms and documents;
• Documentation from independent auditors and the OIG;
• Risk assessments;
• Accounting manuals;
• Memoranda;
• Flowcharts;
• Job descriptions;
• Decision tables;
• Procedural write-ups; and/or
• Self-assessment reports.
Interviews should be conducted with personnel who have knowledge of the relevant operations to validate
that manuals, policies, forms, and documents are accurate and being applied.
A major transaction cycle narrative is a written summary of the transaction process. For each major
transaction cycle, the narrative describes:
• The initiation point;
• The processing type (e.g., automated versus manual, preventative versus detective);
• The completion point;
• Other data characteristics, such as source; receipt; processing; and transmission;
• Key activities/class of transactions within the process;
• Controls in place to mitigate the risk of financial statement errors;
• Supervisor/manager review; process and calculations performed in preparation of financial reporting;
and process outputs;
• Use of computer application controls and controls over spreadsheets used in the preparation of
financial reporting;
• Identification of errors; types of errors found; reporting errors; and resolving errors; and
• Ability of personnel to override the process or controls.
Within the cycle memo, the key controls should be clearly identified by highlighting, bolding, or
underlining. Contractors are responsible for reviewing and updating cycle memos to keep them current.
Control activities are the specific policies, procedures, and activities that are established to manage or
mitigate risks. Key controls are those controls designed to meet the control objectives and support
management’s financial statement assertions. In other words, they are the controls that management relies
upon to prevent and detect material errors and misstatements. For each key control activity, state: (a) the
frequency of performance; (b) the specific steps performed; (c) how exceptions are resolved; and (d) how
the performance of the control activity and related results/disposition are documented.
Examples of control activities that may be identified include:
• Top-level reviews of actual performance;
o Compare major achievements to plans, goals, and objectives
• Reviews by management at the functional or actual level;
o Compare actual performance to planned or expected results
• Management of human capital;
o Match skills to organizational goals
o Manage staff to ensure internal control objectives are achieved
• Controls over information processing;
o Edit checks of data
o Control totals on data files
o Access controls
o Review of audit logs
o Change controls
o Disaster recovery
• Physical controls over vulnerable assets;
o Access controls to equipment or other assets
o Periodic inventory of assets and reconciliation to control records
• Establishment and review of performance measures and indicators;
o Relationship monitoring of data
• Segregation of duties;
• Proper execution of transactions and events
o Communicating names of authorizing officials
o Proper signatures and authorizations
• Accurate and timely recording of transactions and events
o Interfaces to record transactions
o Regular review of financial reports
• Access restrictions to and accountability for resources and records; and
o Periodic reviews of resources and job functions
• Appropriate documentation of transactions and internal control.
o Clear documentation
o Readily available for examination
o Documentation should be included in management directives, policies, or operating manuals
To document management’s understanding of major transaction cycles, management should use a
combination of the following:
• Narratives;
• Flowcharts; and
• Control matrices.
To illustrate this process, we have provided cycle memo guidelines in Section 60. Updated cycle memos
shall be submitted to the CMS Internal Controls mailbox within fifteen business days after December 31.
Note: The cycle memos must be 508 compliant when released to the Internal Controls mailbox. For
information on 508 compliance, please visit the website at the following hyperlink:
Hyperlink: The US Department of Health and Human Services (HHS) Section 508 Compliance Information
In addition, the A/B, DME, and Specialty MAC contractors shall provide updated cycle memos to the SSAE
18 auditors.
3) Test Operating Effectiveness
Testing of the operation of key controls shall be performed and documented (refer to “Plan and Scope the
Evaluation” (above) as well as the chart below with regard to testing applicability), to determine whether the
control is operating effectively, partially effectively, or not effectively. Testing shall address both manual
and automated controls. Ideally, testing should be performed throughout the year. The results of testing
completed prior to June 30th will form the basis of the June 30th assurance statement. As testing continues
into the fourth quarter, the results of that testing, along with any items corrected since the June 30th
assurance statement will be considered in the September 30th assurance statement update. The chart below is
provided to assist contractors in determining when to conduct testing.
A-123 Appendix A Internal Control Review/SSAE 18 Reliance Examples
Scenar
io
Prior Fiscal Year
2
Prior Fiscal Year 1
Current Fiscal Year
Additional Testing
Required or Not
Required*
1
No SSAE 18/A-
123 Appendix A
Review
No SSAE 18/A-123
Appendix A Review
Unqualified
Not Required
2
No SSAE 18/A-
123 Appendix A
Review
Unqualified
No SSAE 18/A-123
Appendix A Review
Not Required
3
Unqualified
No SSAE 18/A-123
Appendix A Review
No SSAE 18/A-123
Appendix A Review
Not Required
4
Qualified
Unqualified
No SSAE 18/A-123
Appendix A Review
Not Required
5
No SSAE 18/A-
123 Appendix A
Review
No SSAE 18/A-123
Appendix A Review
Qualified
Required
6
No SSAE 18/A-
123 Appendix A
Review
Qualified
No SSAE 18/A-123
Appendix A Review
and the Findings are
Corrected and
Validated by CMS
(CAP Closure
Letter Received)
Not Required
7
Unqualified
Qualified
No SSAE 18/A-123
Appendix A Review
and the Findings are
Corrected and
Validated by CMS
(CAP Closure
Letter Received)
Not Required
8
Qualified
No SSAE 18/A-123
Appendix A Review and
the Findings are Corrected
and Validated by CMS
(CAP Closure Letter
Received)
No SSAE 18/A-123
Appendix A Review
Not Required
9
Unqualified
Qualified
No SSAE 18/A-123
Appendix A Review
and the Findings are
NOT Corrected or
Validated by CMS
(No CAP Closure
Letter)
Required
10
No SSAE 18/A-
123 Appendix A
Review
Qualified
No SSAE 18/A-123
Appendix A Review
and the Findings are
NOT Corrected or
Validated by CMS
(No CAP Closure
Letter)
Required
Scenar
io
Prior Fiscal Year
2
Prior Fiscal Year 1
Current Fiscal Year
Additional Testing
Required or Not
Required*
11
Qualified
No SSAE 18/A-123
Appendix A Review and
the Findings are NOT
Corrected or Validated by
CMS (No CAP Closure
Letter)
No SSAE 18/A-123
Appendix A Review
and the Findings are
NOT Corrected or
Validated by CMS
(No CAP Closure
Letter)
Required
Unqualified Report
SSAE 18: No findings in Section I
A-123 Appendix A Internal Control Review: No material weaknesses were noted
Qualified Report
SSAE 18: 1 or More Findings in Section I
A-123 Appendix A Internal Control Review: Material weaknesses were noted, but were not pervasive
*Note:
Assumes other subsequent audits and reviews do not contradict the SSAE 18/A-123 Appendix A Review
or contradictions have been corrected and validated.
4) Identify and Correct Deficiencies
If design or operating deficiencies are noted, the potential impact of control gaps or
deficiencies on financial reporting shall be discussed with management. The magnitude
or significance of the deficiency will determine if it should be categorized as a control
deficiency, a significant deficiency, or a material weakness (see Section 30.6).
Corrective action plans (CAPs) shall be created and implemented to remediate identified
deficiencies (see Section 40). The contractor shall submit corrective action plans for all
deficiencies (control deficiencies, significant deficiencies, and material weaknesses)
identified as a result of A-123 Appendix A reviews and SSAE 18 Section I findings.
5) Report on Internal Controls / Certification Statement
The culmination of the contractor’s assessment will be the assurance statement regarding
its internal control over financial reporting. The statement will be one of three types:
1) Unqualified Statement of Assurance
Each contractor shall submit, as part of the CPIC report, an assurance statement for
internal controls over financial reporting (ICOFR) stating:
“… (Contractor) has effective internal controls over financial reporting (ICOFR) in
compliance with OMB Circular A-123, Appendix A.”
NOTE: The contractor’s statement of assurance should be unqualified if this is consistent
with the A-123 Appendix A Internal Control Review statement per the CPA firm report
(augmented by internal reviews, if necessary). Similarly, if the SSAE 18 audit
(augmented by internal reviews, if necessary) did not result in any Section I findings or
the contractor has not classified any findings as material weaknesses, then an unqualified
statement of assurance would be applicable.
2) Qualified Statement of Assurance
Each contractor shall submit, as part of the CPIC report, an assurance statement for
internal controls over financial reporting stating:
“…(Contractor) has effective internal controls over financial reporting in compliance
with OMB Circular A-123, Appendix A, except for the SSAE 18 Section I finding(s)
and/or material weakness(es) identified in the attached Report of Material Weaknesses.”
Note: The contractor’s statement of assurance should be qualified if this is consistent
with the A-123 Appendix A Internal Control Review statement per the CPA firm report
(augmented by internal reviews, if necessary). Similarly, if a SSAE 18 audit disclosed at
least one Section I finding and/or internal reviews in the current year disclosed a material
weakness, then a qualified statement of assurance (see above) or a statement of no
assurance (see below) would be issued, depending on the pervasiveness of the Section I
findings or material weakness. The results of work performed in other control-related
activities may also be used to support your assertion as to the effectiveness of internal
controls.
3) Statement of No Assurance
Each contractor shall submit, as part of the CPIC report, an assurance statement for
internal controls over financial reporting stating:
“…(Contractor) is unable to provide assurance that its internal control over financial
reporting was operating effectively due to the material weakness(es) identified in the
attached Report of Material Weaknesses.”
or
“…(Contractor) did not fully implement the requirements included in OMB Circular A-
123, Appendix A and therefore cannot provide assurance that its internal control over
financial reporting was operating effectively.”
End Section 30.1.1 – OMB Circular A-123, Appendix A: Internal Controls Over
Financial Reporting (ICOFR): Back to Table of Contents