On July 6, 2026, CMS published a Federal Register notice (document 2026-13603) seeking OMB approval for a revised information collection tied to the Medicare Part C and Part D Program Audit Protocols, docketed as CMS-10717. The notice includes CMS’s responses to 315 industry comments and opens a new comment period that closes August 5, 2026. This is a proposed information collection, not a finalized rule. CMS could still revise details before the 2027 audit cycle begins.
That caveat matters, but so does the direction of travel. Across the proposal, CMS is signaling less interest in whether a plan can produce the right document on request, and more interest in whether its compliance program actually catches problems, fixes them, and keeps them from coming back.
The core shift
How the proposal reframes what “audit-ready” means
Moving away from
Producing the right document on request
Moving toward
Proving the control worked and the fix held
For compliance officers, that shift changes what “audit-ready” needs to mean, well before any protocol is finalized. Below are the questions a CCO or VP of Compliance is likely asking heading into 2027 planning.
What is CMS actually proposing for 2027 program audits?
CMS is proposing a package of changes: a redesigned Compliance Program Effectiveness (CPE) review, reduced data-collection burden, an eventual (not immediate) shift toward Service-Level Data for Part C audits, broader use of desk reviews alongside live webinar audits, a proposed three-tier validation framework, capped sample sizes, and more audits per year. Each program area, Formulary Administration (FA), Coverage Determinations, Appeals and Grievances for Part D (CDAG), Organization Determinations, Appeals and Grievances for Part C (ODAG), and Special Needs Plan Care Coordination (SNPCC), is affected differently. The common thread is a move from document production toward operational effectiveness and beneficiary impact.
Why is CMS redesigning Compliance Program Effectiveness (CPE) review?
CMS is proposing to eliminate CPE as a stand-alone audit area and evaluate compliance effectiveness inside each program-area audit instead. The apparent aim: the current tracer-based approach did little to demonstrate whether a compliance program actually works. Under that model, CPE reviews compliance risk assessments, audit workplans, and sample case “tracers” largely in isolation from the other audit areas.
CPE, redesigned
What the proposal would retire, and what replaces it
Proposed to retire
- Traditional CPE tracer review
- Compliance risk assessment submission
- Audit workplan submission
- Stand-alone compliance testing
- FWA oversight as a separate area
Evaluated instead, in every program area
- How issues were identified
- How compliance monitored operations
- Speed and effectiveness of remediation
- Whether issues recurred after correction
- Ongoing discussions with the Compliance Officer
Auditors would hold ongoing discussions with Compliance Officers during fieldwork rather than reviewing pre-selected tracer cases. The CPE COA universe would also narrow, from every oversight activity compliance performed to the specific activities tied to the program areas under audit.
CMS’s proposed changes to Impact Analysis requests reinforce the same point. Rather than a general narrative, Impact Analysis would need to describe how the noncompliance affected the organization: its effect on entities, systems, and processes, plus any potential impact on enrollees. That framing does two things for CMS: it surfaces enrollee impact directly, and it checks whether the plan ran a full root-cause investigation rather than a partial fix aimed only at the symptom CMS happened to catch.
Under this proposal, a monitoring report alone would not be persuasive. The evidence trail needs to show that an issue was found, fixed, validated, and did not recur.
What data-collection burden is CMS proposing to cut?
CMS is proposing to eliminate four entire audit universes and shorten a fifth. Depending on organization size, the ODAG Table 3 universe timeframe would shrink to two or four weeks of data.
Audit universes proposed for removal
Four universes eliminated across three program areas
Within CDAG specifically, the sampling and estimated response burden drop meaningfully, while removing the Drug Management Program as a distinct testing element.
CDAG: proposed reductions
Current protocol vs. proposed, by measure (each measure scaled to its own current value)
Will CMS still collect ODAG universes in 2027, or is service-level data replacing them?
CMS confirmed in the notice that it intends to eventually stop collecting ODAG Tables 1 through 3 once Service Level Initial Determinations and Appeals data collection is fully operational. CMS also stated plainly that it does not anticipate service-level data being available before 2028. That means for the 2027 audit cycle, sponsors should still expect to produce traditional ODAG universes in the format CMS currently requires.
Service-level data: the transition CMS signals
Traditional ODAG universes remain the standard for now
The implication is worth acting on now rather than waiting. Compliance and operations teams responsible for ODAG readiness have a window to correct that mapping now, before it becomes the audit’s foundation rather than a side project.
What are desk reviews, and how do they change audit preparation?
Desk reviews are a document-based format CMS is proposing to use more broadly alongside live webinar audits, not necessarily in place of them. CMS has indicated the change would not uniformly replace webinar reviews.
Desk reviews: a new readiness clock
From
“Can we pull this file live on the call?”
To
“Can we submit a complete, defensible package?”
How is CMS proposing to expand ODAG’s scope?
CMS is proposing to broaden what counts as a substantive coverage decision for ODAG universe purposes, with new focus on concurrent reviews. ODAG universes would need to capture concurrent review decisions, service reductions, coverage terminations, and post-acute care terminations, alongside the organization determination and appeal universes plans already track. CMS also proposes a new field identifying whether a service required prior authorization, which the agency would use to evaluate prior-authorization compliance under the newer Medicare Advantage requirements.
Under the proposal, ODAG audits would assess compliance with the internal coverage criteria and utilization management requirements established under CMS-4201-F. That means UM governance, internal clinical criteria, and denial-rationale documentation should be treated as audit-relevant artifacts, not internal UM records reviewed only as needed.
What is the proposed risk-based validation framework for corrective actions?
Starting with the 2027 cycle, CMS is proposing that validation of corrective actions run through one of three pathways, rather than defaulting to a full validation audit every time. What actually changes is how CMS chooses among them: rather than requiring the most intensive pathway for every corrective action regardless of severity, CMS would select based on risk.
Three validation pathways, selected by risk
Escalating intensity — not applied uniformly to every finding
Streamlined review
Documentation review or webinar.
Lowest burdenCMS-led audit
Validation conducted by CMS.
Moderate burdenIndependent audit
External validation audit.
~$200,000 est. external costIs CMS planning to audit more health plans?
Yes. CMS is proposing to increase parent-organization audit volume, while continuing its parent-organization strategy of targeting broad coverage of Medicare Advantage and Part D enrollment.
More audits, same reach strategy
Enrollment targeted by CMS’s parent-level audit strategy
Are sample sizes capped, and what’s changing for SNP and D-SNP audits?
Yes to sample caps: CMS is proposing that protocols generally specify a maximum number of samples it will select, pulling additional samples only when investigating specific concerns that arise during the audit. That gives compliance and audit-prep teams more predictability in staffing an audit response.
Separately, CMS is proposing added attention to Special Needs Plan (SNP) and Dual-Eligible Special Needs Plan (D-SNP) requirements: integrated Health Risk Assessments (HRAs), Medicaid assistance coordination, facility admission notifications, and person-centered care planning tied to Model of Care expectations. Within SNPCC, CMS is proposing a new Individualized Care Plan (ICP) timeliness requirement, a new face-to-face encounter criterion, and universe fields capturing Initial ICP Creation Date and Hospital/SNF Admission indicators. Organizations with large D-SNP portfolios should treat this as a reason to review integration documentation now, ahead of any audit notification.
What should compliance teams do now?
This is a proposed collection with a comment period open through August 5, 2026, so the goal now is preparation, not compliance with a finalized rule:
- Read the proposed protocols directly, not just summaries, and route them to audit leads and business owners in FA, CDAG, ODAG, and SNPCC operations. The redesign changes how each area gets evaluated, not just the compliance function.
- Inventory your CPE evidence trail against the “found it, fixed it, validated it, prevented recurrence” standard the proposal implies, rather than the current tracer-and-monitoring-report model.
- Start reconciling service-level data now, even though CMS doesn’t expect availability before 2028. The data mapping and accuracy work behind future service-level-based audits will take time to get right.
- Structure UM and denial-rationale documentation for ODAG’s expanded scope, including concurrent review and prior-authorization fields, so it is audit-ready rather than assembled after the fact.
- Stress-test case-file retrieval against a roughly five-business-day desk-review timeline. The proposal points toward a documentation-package standard rather than a live-pull one.
Where to go from here
This proposal is not final. The comment period on the CMS-10717 information collection closes August 5, 2026, and CMS’s eventual protocols may differ from what’s summarized here.
Agency Information Collection Activities: Submission for OMB Review; Comment Request — Medicare Part C and Part D Program Audit Protocols (CMS-10717)
Make sure your audit team and the business owners in each program area read the proposed protocols directly, and consider subscribing to CMS program audit updates so changes between now and the 2027 cycle don’t arrive as a surprise.
