Medicare Financial Management Manual (Pub. 100-06), Ch. 8 § 60.4
Reliance on Work Done by Other Auditors
60.4 – Reliance on Work Done by Other Auditors
(Rev. 27, 12-19-03)
A. General Guidelines
Medicare audits are generally limited to tests of compliance with Medicare
reimbursement policies and procedures. In performing these audits, you generally rely on
the financial statements prepared by independent auditors. This includes the independent
auditors’ review of providers’ accounting systems.
To the extent that an independent auditor issued an unqualified opinion on a provider’s
financial statement and has not identified any material weaknesses in the provider’s
internal control structure, rely on the provider’s system of accounting, including related
computer systems. This does not include reliance on records or systems that are
maintained solely for purposes of completing a Medicare cost report. As mentioned in
§60.3 of this chapter, you may wish to perform substantive tests of the records
maintained solely for Medicare reimbursement purposes.
If an independent auditor issued a qualified opinion, an adverse opinion, or has identified
material weaknesses in the internal control structure, evaluate the effect of the auditor’s
actions on your audit objective. If there has been no audit by an independent auditor,
consider the audit resources available, the audit risk, and the audit objectives in deciding
if there is a need to review the accounting systems. (See §60.3 of this chapter.)
Furthermore, you may rely on work of other auditors (i.e., provider’s internal or
independent auditors and audit organizations established by the Federal and State
Governments for programs other than Medicare) in situations where the scope of this
work relates to issues that you scoped for the Medicare field audit. However, in this
situation, you must still satisfy yourself with the quality of the other auditors’ work by
performing appropriate tests or by other acceptable methods.
B. Obtaining Management Letter and/or Documentation Prepared by Provider's
Independent Auditors
If you determine that it is necessary to gain an understanding of a provider's internal
control structure or any other aspect of the accounting system (see §60.3.B of this
chapter), you may request that the provider furnish you with the management letter or
other documentation relevant to the Medicare audit that was prepared by an independent
auditor or certified public accounting (CPA) firm
Under §§1815(a) and 1833(e) of the Social Security Act, you or CMS may review any
documentation it deems necessary to determine whether payment for reasonable cost to a
particular provider is appropriate. The implementing regulations at 42 CFR 413.20 and
413.24 explain this further. 42 CFR 413.20(e) specifically allows suspension of payment
if the intermediary determines that the provider does not maintain adequate records for
the determination of reasonable costs. Additionally, 42 CFR 405.372(a)(2) provides for
suspension of payment for failure to provide specifically requested information.
However, when the documentation is maintained by an independent auditor or certified
public accounting (CPA) firm rather than by a provider, you or CMS must insist that the
provider obtain the information from that audit entity. Since the law and regulations are
directed to providers, not their auditors or CPA firms, CMS requires the provider to have
the independent auditor release the documentation to CMS or the contractor. The
independent auditor is at a minimum a de facto agent of the provider and should comply
with the request. If the provider is not able to produce the documentation from the
independent auditor/CPA firm, you may disallow all the provider’s cost/reimbursement
associated with the cost report(s) under review or at least suspend payment until the
documentation is provided if an appropriate determination of payment cannot be made
without the documentation. CMS has limited recourse against the independent auditor or
CPA firm if it refuses to comply.
Keep independent auditors’ management letters or other documentation obtained from a
provider or the independent auditors in a secure place. Disclose the contents only to
those directly involved with the audit.