From audit finding to verified closure. CMS no longer scores findings, and a validation audit does not measure whether a corrective action plan was implemented. It measures whether the plan achieved its intended result.
The Retired Map
What changed in how CMS classifies a finding
CMS’s current program audit process no longer scores findings, and the classification system behind that score has narrowed. Under the 2021 methodology, an Immediate Corrective Action Required (ICAR) finding counted two points, a Corrective Action Required (CAR) counted one, an Observation counted zero, and an Invalid Data Submission (IDS) counted one point; CMS totaled those points into an overall audit score. The November 2025 process overview keeps three classifications, Observation, CAR, and IDS, with no point values and no overall score attached to any of them.
IDS itself is not new. It existed in the 2021 methodology and carried a point value then, and it still applies today. What actually changed is narrower than “everything changed”: ICAR is gone from the classification list, and the point total that resolved a set of findings into a single score is gone with it. A CAP program still organized around avoiding an ICAR finding, or managing toward an overall audit score, is working from a retired map.
| Classification | 2021Retired | November 2025Current |
|---|---|---|
| Immediate Corrective Action Required (ICAR) | 2 points | RemovedNo longer a classification. |
| Corrective Action Required (CAR) | 1 point | CAP required. Accepted, corrected and validated condition by condition. |
| Invalid Data Submission (IDS) | 1 point | No CAP. The untested universes must still be produced at validation. |
| Observation | 0 points | No CAP. Monitor for ongoing compliance. |
| Overall audit score | Sum of the points above | Removed. Findings no longer total into one number. |
Three of the four classifications survived the change intact in name, and Invalid Data Submission is not new: it existed in 2021 and carried one point. What went away is Immediate Corrective Action Required as a category, and the point total that turned a set of findings into a single score. Classification is set by Program Audit Consistency Teams, the program-area subject matter experts CMS uses to keep classification consistent across audits. Sources: CMS Routine Program Audit Process Overview (updated November 2025), Phase III; CMS 2021 Program Audit Process Overview.
Consider a composite scenario, built from patterns that show up repeatedly across CMS’s own audit findings rather than any single plan’s record. A plan’s provider dispute team starts sending adverse determination notices using an outdated template after a routine system update quietly reverts a form field. Nothing looks wrong from inside the queue: notices go out, cases close, no one downstream flags it. CMS catches the discrepancy during a program audit and cites it as a Corrective Action Required (CAR) finding.
The plan’s response is straightforward: retrain the staff who process disputes on the correct template. CMS accepts the corrective action plan, and because the fix looks like a documentation update, CMS validates it through a review of the corrected template rather than a full audit. The CAP is marked closed.
Nine months later, an unrelated software patch reverts the same field again. Nobody notices, because nothing in the CAP set up a re-test. The plan walks into its next program audit with the identical finding, cited again as the same condition, this time a recurring one.
Three Classifications
What CMS’s finding tiers mean for corrective action
CMS’s current program audit process, laid out in its Routine Program Audit Process Overview, sorts every finding into one of three classifications. An Observation is, in CMS’s words, “a finding of noncompliance that CMS determines does not require submission of a corrective action plan”; sponsoring organizations are encouraged to monitor observations to ensure ongoing compliance with CMS requirements. A Corrective Action Required, or CAR, is “a finding of noncompliance that requires correction to strengthen internal controls, prevent future noncompliance, and/or ensure enrollee impact is resolved.” An Invalid Data Submission, or IDS, is “a finding that is cited when a Sponsoring organization has failed to produce an accurate or complete universe and/or documentation to CMS.”
Only CARs produce a CAP. The Observation definition says so directly, and CMS’s guidance for this phase instructs sponsors to submit CAPs only for conditions requiring corrective action.
IDS is not automatic on the first bad universe. Sponsors get up to three attempts to provide a complete and accurate universe, and CMS uses only the last one submitted. A sponsor that fails to provide accurate and timely universe submissions twice gets that documented as an observation in the audit report. Only after a third failed attempt, or when the sponsor determines earlier that it cannot produce an accurate universe within the specified timeframe, does CMS cite an IDS condition against each element that could not be tested. Three attempts are not always feasible, CMS notes, depending on when data issues are identified; once CMS has shared timeliness test results, for example, resubmission is no longer allowed.
Classification is not left to individual judgment mid-audit. CMS’s Program Audit Consistency Teams, made up of program-area subject matter experts, review classifications specifically to keep them consistent across audits.
The Lifecycle
The corrective action lifecycle, stage by stage
CMS’s process moves through the same operational stages regardless of what triggered the finding, and several of them run on tighter clocks than a quarterly compliance calendar is built to carry.
Root cause analysis comes first. CMS requires a formal root cause analysis for any noncompliance identified during the audit, submitted on CMS’s own template within two business days of CMS’s request and uploaded to HPMS. CMS can ask for it to be revised and resubmitted, and notes the stated cause may evolve as the sponsor investigates further, expecting updated analyses as necessary so the stated cause reflects the total impact identified. This step is separate from, and precedes, the impact analysis.
Impact analysis follows. Within 10 business days of CMS’s request, the sponsor must upload an impact analysis identifying everyone subjected to or affected by the noncompliance, covering the period from the date the impact analysis is requested back through the start date of the audited universe, including the sample cases already cited during the audit. CMS may validate that submission or request a revision. A sponsor that cannot quantify the full scope by the deadline is allowed to estimate, but only on two conditions: it has to keep quantifying the noncompliance, and it has to deliver an updated impact analysis with the total impact by the time it submits comments to the draft audit report. That is a specific, later deadline, not an open-ended promise to keep refining a number. When an impact analysis cannot be produced at all, CMS reports that the scope of the noncompliance could not be fully measured and affected an unknown number of parties across every contract audited.
CAP submission and acceptance follow the final audit report. Sponsors have 30 calendar days from its issuance to submit CAPs for every condition classified as a CAR, and CMS runs a reasonableness review, sending CAPs back for revision until it considers all of them acceptable.
Validation is where CMS decides, condition by condition, how much testing a correction needs. Some findings clear through a webinar or a documentation review; others require a full validation audit, with its own deadline and its own rule for who conducts it. That decision, and what follows it, gets its own section below.
Audit close out depends on what validation finds. If the results support it, CMS closes the audit and refers any remaining isolated issues to the CMS Account Manager for follow-up. If conditions remain uncorrected, the audit stays open: the sponsor submits new CAPs and undergoes additional validation activity, and any conditions requiring another validation audit can be referred to CMS’s Division of Compliance Enforcement to determine whether a civil money penalty, sanction, or contract termination is warranted. This phase alone, CMS notes, can run six months or longer.
The stages are drawn in sequence, not to a shared time scale, because each deadline is anchored to a different event: two of the clocks start when CMS asks, one when the final report issues, one when the last CAP is accepted. The gap between stages 2 and 3 is not fixed either, since the draft report targets 60 calendar days from the exit conference and the sponsor then has 10 business days to comment. Source: CMS Routine Program Audit Process Overview (updated November 2025), Phases II–IV.
| Closure stage | What CMS requires | Where the work concentrates |
|---|---|---|
| Root cause analysis | CMS’s root cause template, uploaded to HPMS within two business days of the request, revised as the investigation develops | Keeping a record of how the stated cause changed as the investigation went deeper, when only the final answer tends to get written down |
| Impact analysis | Everyone affected, from the request date back through the start of the audited universe, within 10 business days | Tying the affected population back to the transactions that evidence the count, against a deadline measured in business days |
| CAP submission | A CAP for every CAR condition within 30 calendar days of the final audit report, revised until CMS’s reasonableness review is satisfied | The revision cycles, which have no fixed number and sit outside the original 30-day window |
| Validation | Correction confirmed on whichever path CMS assigned: a webinar or documentation review, or a full validation audit that tests actual transactions | Not seeing the sixth flagged condition coming, then compressing auditor selection and work-plan approval into the run-up to the window |
| Close out | Validation results sufficient for CMS to determine the conditions were corrected | Uncorrected conditions restart the cycle with new CAPs, and can be referred for enforcement |
The stage requirements are drawn from CMS’s process document. The third column is an editorial observation about where the effort tends to land, not a CMS finding. Source: CMS Routine Program Audit Process Overview (updated November 2025), Phases II–IV.
The Fork
Who conducts the validation audit, and the threshold that decides it
CMS’s final audit report does more than record findings. It also tells the sponsor how each CAR will be validated. Corrections that are straightforward to confirm, such as updating appeal language in a written notification template, do not require a full validation audit; CMS validates those through a webinar or a review of documentation, and can do so as soon as the sponsor reports the fix is in place. Findings CMS considers more complex get flagged in the final audit report as needing a full validation audit, one that tests the correction against actual transactions. A sponsor that was cited an IDS carries an extra obligation into this phase: it has to produce the universes auditors could not test during the original audit, to demonstrate compliance with the requirements those universes cover.
Who conducts that audit depends on volume. A sponsor with more than five conditions flagged for a validation audit has to hire an independent auditor, one with no employment, representation, or FDR relationship to the sponsor under 42 CFR § 422.500 and § 423.501, and free of conflict of interest. With five or fewer, CMS conducts the validation audit itself, under the same authority, 42 CFR § 422.503(d)(2)(iv) and § 423.504(d)(2)(iv), that governs either path. CMS states which path applies directly in the final audit report, so a sponsor knows at that point whether it needs to run a procurement, not later in the process. CMS is explicit that it does not recommend auditors and does not maintain a list of approved firms; it advises sponsors that may need one to solicit proposals and select an auditor as early as possible.
Sponsors have 180 calendar days from the date CMS accepts all CAPs to complete the validation audit, and CMS has to review and approve the audit work plan before any validation work can begin, a gate that quietly consumes part of that window. Sponsors can schedule validation activities within the 180 days as they choose, with one exception: the validation audit report due date itself is fixed. Extensions are available. A sponsor can request one in writing to the CMS validation audit lead, as early in the process as possible, with a new target due date and a justification, and CMS considers each request on a case-by-case basis.
A sponsor learns which path applies when the final audit report issues, which is also the moment the 30-day CAP clock starts. That is well before the 180 days begins, because that window opens only once CMS has accepted every CAP, so an auditor search does not have to run inside it. CMS advises selecting one as early as possible for a specific reason: to leave time for development and approval of the validation audit work plan, which CMS must approve before any validation work is executed. The sponsor also attests in the HPMS Audit Module that the chosen firm is free of conflicts of interest, and the firm has to hold subject matter and clinical expertise in the program areas being audited. Source: CMS Routine Program Audit Process Overview (updated November 2025), Phase IV.
Root Cause
Why “staff training” is often where the analysis stops
CMS is direct about the standard a corrective action has to meet. Sponsor tips accompanying its audit and enforcement report instruct plans to “ensure corrective actions address root causes rather than isolated symptoms.” That distinction matters because “retrain staff” is a familiar answer to write on a CAP, and it is a genuine cause often enough that CMS’s own 2021 definition of a CAR listed inadequate training among the control failures that produce noncompliance. The issue is not that training is never the cause. It is that training is often where a rushed analysis stops, whether or not it is where the noncompliance actually started. A process design that made the error likely regardless of who was doing the work, a system configuration issue, a gap in oversight of how a policy was applied, or a delegate that did not perform as required can all sit underneath a finding that looks, on the surface, like a training gap.
In the scenario above, that is exactly what happened. Retraining the dispute team fixed how people used the template. It did nothing about the system field that kept reverting it, the kind of gap a root cause analysis has to reach if the corrective action is going to hold, and the kind a rushed one is prone to miss.
A staff member applied the wrong template. Corrective action: retrain the team.
“Ensure corrective actions address root causes rather than isolated symptoms.”CMS, sponsor tips, CY 2025 Part C and Part D Program Audit and Enforcement Report
The four categories on the right are an editorial grouping of the kinds of causes CMS’s audit findings describe, not fields on CMS’s root cause analysis template and not a CMS taxonomy. CMS confirms the template exists and that it reserves the right to require a revised analysis, but its published process overview does not enumerate the template’s categories. Training can be a real cause: the 2021 CAR definition listed inadequate training among the control failures that produce noncompliance. The argument here is about where an analysis stops, not about whether training ever belongs in it.
Closure and Effectiveness
Closure is not effectiveness
Closure and effectiveness are two separate events, and a CAP record built only to confirm completion captures the first. Internally, a corrective action tends to be marked closed once the actions are done and the evidence has gone in. Effectiveness is a separate determination, and in CMS’s process it is validation that makes it: like the initial program audit, a validation audit is outcome-focused and tests the compliance of actual transactions wherever possible. In CMS’s own words, it “does not measure or evaluate whether a CAP was fully implemented; it measures whether the CAP achieved its intended result by remediating the noncompliance.” CMS then closes the audit itself on the strength of those validation results, not on the corrective action having been filed.
That is the gap in the scenario above. The record closed because the corrected template was confirmed, which is what the assigned validation path called for, and on the finding as classified that was the right call. Nothing in the record carried a date, an owner, or a re-test for the question of whether the field was still correct nine months later.
Closure and effectiveness are separate events. CMS puts it directly: a validation audit “does not measure or evaluate whether a CAP was fully implemented; it measures whether the CAP achieved its intended result by remediating the noncompliance.” In this scenario the streamlined validation path was the correct one for the finding as classified, and the closure was legitimate. The exposure is what no one owned afterward. Scenario composite; quotation from CMS Routine Program Audit Process Overview (updated November 2025), Phase IV.
Delegates and FDRs
Corrective actions that depend on someone else
CMS is direct about this in its own lesson title: delegation does not transfer accountability. Sponsors are permitted to contract with first-tier, downstream, and related entities to process Part C and Part D benefits on their behalf, and CMS recognizes the value in that arrangement, specialized expertise, added resources, faster decisions among them. But CMS has also observed that sponsors relying on FDRs ran into compliance challenges specifically when oversight processes, communications, or operational controls with those entities were not fully aligned. The stakes are not abstract. When a delegated entity does not administer benefits consistently with a sponsor’s requirements and CMS’s rules, beneficiaries can face delays accessing medically necessary medications, receive incorrect coverage decisions, or experience confusion about their benefits, per CMS.
CMS also states it will consider a sponsor’s good faith effort to monitor its complex organization, including its intricate network of systems and downstream entities. Delegate systems are not outside audit scope by default, either: CMS reviews a sponsor’s live system, and that of its delegated entities, as part of universe integrity testing.
In practice, for a CAP tied to a delegated finding, that means the sponsor is often asking a party it does not directly control to produce evidence, test results, transaction samples, documentation, on the sponsor’s compliance timeline rather than the delegate’s own. That evidence relationship deserves more than a summary here, and it is the problem Inovaare’s delegation oversight module addresses directly.
Managing open CARs right now?
Walk through how a corrective action record holds root cause, evidence and reviewer approval as one traceable chain, mapped to CMS’s current audit phases.
Request a 30-Minute Audit Readiness ReviewEnforcement
What it costs to get this wrong
CMS’s enforcement toolkit sits behind this entire process. Its CY 2025 Part C and Part D Program Audit and Enforcement Report documents 14 civil money penalties totaling $1.54 million across 18 violations, based on oversight activity, program audits, financial audits, and other routine reviews, conducted during 2025; the individual penalty notices themselves are dated into 2026. The two largest penalties were $753,805 against CVS Health Corporation and $380,785 against Centene Corporation; the remaining twelve ranged from $10,458 to $84,190. Recurring themes behind the violations, per CMS: beneficiary cost-sharing errors, payment integrity issues, eligibility processing failures, and breakdowns affecting access to medications.
CMS is explicit that CMP amounts are not intended to reflect a sponsor’s overall performance. Instead, CMS evaluates the impact of a violation on beneficiaries: the number of enrollees affected, the nature and scope of the noncompliance, and the actual or potential harm that resulted. Certain aggravating factors can increase a violation’s severity and the resulting penalty; in 2025, those factors were most often tied to violations causing significant financial harm to beneficiaries or limiting access to medically necessary medications. The scale involved is notable. Eighty-nine percent of violations cited in 2025 CMP actions involved enrollees who experienced financial harm greater than $100. Intermediate sanctions, which can suspend a sponsor’s ability to market to or enroll new Part C or Part D members, or to receive payment for new enrollees, remain a separate and available consequence; CMS imposed some in 2025 for failure to meet Medical Loss Ratio requirements.
CMS’s own enforcement record shows what an extended version of this looks like. PACE4DC LLC, a Program of All-Inclusive Care for the Elderly organization, had its enrollment into PACE contract H9564 suspended on August 23, 2024, after CMS found the organization had not corrected deficiencies identified during its 2024 PACE initial comprehensive review: specifically, that it did not provide all approved services and did not track, document, and monitor service provision across care settings. PACE4DC attested that the violations were corrected as of October 31, 2025. CMS required a validation audit covering all the cited operational areas, under 42 CFR § 460.42(c), before it would lift the suspension; the release notice issued February 26, 2026, roughly eighteen months after the original suspension and roughly four months after the sponsor’s own attestation that the violations were corrected. PACE operates under its own oversight framework, not the CAR process described above, so the procedural rules do not transfer directly. What does transfer is the underlying mechanic: an attested correction and a validated one are treated as two different things, and the distance between them carries a real cost.
The penalty figures come from CMS’s CY 2025 report and cover violations identified through oversight activity conducted in 2025; the individual penalty notices are dated April and May 2026. CMS is explicit that “CMP amounts are not intended to reflect a Sponsor’s overall performance” but instead weigh the number of affected enrollees, the nature and scope of the noncompliance, and the harm that resulted. PACE operates under 42 CFR Part 460, not the Part C and D corrective action framework described above, so it is cited here for the mechanic rather than the procedure. Sources: CMS CY 2025 Part C and Part D Program Audit and Enforcement Report, Appendices B and C; CMS PACE4DC LLC sanction notice (August 23, 2024) and sanction release notice (February 26, 2026).
On the horizon
CMS states it is updating audit protocols to make greater use of existing CMS data, which should reduce duplicative data collection but may increase the importance of ensuring that data submitted to CMS is accurate, complete, and reconcilable to internal systems.
Three focus areas follow that outlook. Prior authorization readiness covers the ability to track expedited and standard requests, monitor timeliness, document denial reasons, and escalate cases before they exceed CMS timeframes; beginning in 2026, sponsors must send prior authorization decisions within 72 hours for expedited requests and 7 calendar days for standard requests. Data integrity and interoperability covers keeping prior authorization, appeals, claims, and encounter data consistent across internal systems, delegated entities, and CMS’s own data sources. Governance and monitoring covers using compliance oversight activities to test whether operational teams and FDRs are applying requirements consistently and correcting issues before they affect beneficiaries. CMS also plans to continue hosting quarterly compliance officer calls to share audit-identified issues.
In Practice
What structured CAP management looks like
The plans that manage this well are not leaning on institutional memory or a general-purpose tracking tool to hold a CAP together. What they have instead is version control on the corrective action as it moves from root cause to accepted to validated, an audit log recording who changed what and when, role-based approval, and escalation that surfaces a CAP approaching its deadline before it becomes a finding rather than after. Inovaare carries those as platform functions across its audit and compliance modules: every action stamped and logged without manual notes, version history recorded and timestamped for traceability in CMS and internal audits, and role-based access separating what each user sees.
CAP Management is built around the structural gap this article has been describing: findings, root cause, evidence, and validation held as one connected, traceable record instead of reconstructed after the fact across disconnected tools and spreadsheets. CAPs are auto-created directly from audit findings into a centralized repository, so there is a single source of truth for every open and closed corrective action. Each CAP carries a root cause analysis workflow embedded in the record itself, rather than as a separate document matched back to the finding later. Closure is gated on reviewed evidence: a CAP cannot be marked closed without supporting evidence attached and accepted by a reviewer. Ownership is role-based, with owners, reviewers, and approvers clearly assigned, and a reviewer validates root cause resolution before accepting or rejecting the submission. Overdue items escalate automatically, with notifications routed to the relevant stakeholders, rather than surfacing only when someone happens to check.
An assist built on the Usher integration summarizes CAPs for leadership reporting, recommends closure steps based on how similar CAPs were resolved before, and flags patterns across CAPs that suggest a recurring deficiency rather than an isolated one. It surfaces and suggests. It does not decide.
Stage names and stage detail are the documented CAP Management workflow. Inputs converge on the same record from internal audit, external audit, policy and procedure violations, delegation oversight, KPI monitoring, SLA misses, compliance reviews, and risk and incident management. Stage 6 is the gate that matters for the argument above: closure requires validated evidence, not a completion date.
That assist sits alongside the structured record rather than in place of it. Whether a recommended closure step is actually sufficient, and whether a flagged pattern reflects a real recurring cause, stays a determination for the compliance team.
The Boundary
What still requires human judgment
A system can enforce sequence and hold the record. It cannot determine why a finding actually occurred, and it cannot decide whether a piece of evidence is sufficient to demonstrate that a fix worked. Those calls stay with the compliance team. What changes is whether the team is making them against a complete, organized record, or reconstructing one under deadline.
Teams heading into a program audit, or managing open CARs right now, can walk through how CAP Management maps to CMS’s current audit phases. Request a 30-minute audit readiness review to see it against your own workflow.
Sources: CMS Routine Program Audit Process Overview, Medicare Parts C and D Oversight and Enforcement Group, Division of Audit Operations, updated November 2025 (Phases I–IV), for all classification definitions, stage deadlines, validation paths, the five-condition threshold, the 180-day window and its extension mechanism, and audit close out. CMS 2021 Program Audit Process Overview for the retired point-based scoring methodology and the ICAR classification. CMS CY 2025 Part C and Part D Program Audit and Enforcement Report, its Lessons Learned and Sponsor Tips sections, Appendices B and C, and the “On the Horizon” outlook, for the root cause and delegation guidance, penalty totals, aggravating factors, intermediate sanctions and CMS’s stated focus areas. CMS PACE4DC LLC enrollment sanction notice (August 23, 2024) and sanction release notice (February 26, 2026). Regulatory citations are to 42 CFR §§ 422.500, 422.503(d)(2)(iv), 423.501, 423.504(d)(2)(iv) and 460.42(c). The provider-dispute scenario is composite, assembled from patterns recurring across CMS audit findings rather than drawn from any single plan’s record.
