The evidence a reviewer needs, and how to rehearse the review
Doing the work right does not help until you can document it. Here is what that evidence looks like, and how to rehearse the review while there is still time to fix what it finds.
Doing the work right does not help until it is documented, dated and owned by a named person, and the way to learn whether your packet holds is to rehearse the review, in the same format as the real one, before the real one. I have never run a mock validation review without finding something, including for clients I have worked with for many years. That is the reason to run one, and what matters in each finding is what it costs to cure and whether the time is there to cure it.
This article describes URAC's process, the one I know first hand as its former chief operating officer and general counsel. Other accreditors, including ACHC, CARF and NABP, have their own processes, and I do not describe them here; check your own accreditor's published materials for the evidence it expects. In my experience almost every accreditor asks for policies plus some documentation that the policies are implemented, and what counts as that documentation differs. What I say about URAC comes from URAC's published accreditation process page; the mock-review method and every figure of time are my own practice, not an accreditor's requirement.
What evidence does an accreditation reviewer actually need to see?
In my practice, the record that matters is one showing the policy was followed: who did it, when, under which version of the policy, and who approved the policy.
Put another way:
In the world of accreditation, just doing it right doesn't help. You got to do it right and then document that you've done it right.
A policy with no record behind it demonstrates what you intend and nothing more.
URAC describes its process at https://www.urac.org/accreditations-certifications/accreditation-process/ (page opened October 3, 2026). I summarize it here in my own words; check URAC's page for its exact terms. In two of its phases, a reviewer looks at your documents and then at your practice. Desktop review comes first. Your documents go to a URAC reviewer, who records a Met or Not Met result on each standard, depending on what the documents show. Validation review comes second and tests whether your organization does what those submitted documents say it does. Among its activities are interviews of leaders and of staff and a review of documentation and files.
Read together, the two stages judge the same story twice, first as documents and then in practice, so, in my reading, the policy, the operating record and the interview answers should agree. In my experience reviewers tend to be literal, so label each piece of evidence in the standard's own terms and do not make the reviewer translate. On one program I recommended striking "typically" from a sentence that set a check interval, because the word makes the interval advisory. For the list of documents to submit at desktop review, URAC points applicants to the Demonstrating Compliance: Desktop Review sections of the Accreditation Guide. That guide is your list, and this article is not.
How does a reviewer pull a sample, and what makes a file easy to review?
Hand the reviewer logs from which to select the personnel or case files, and never select them for the reviewer; that is what I tell organizations in my on-site mock reviews. Then take the reviewer's seat. The setup I recommend on site is a numbered list of what was requested, one numbered folder or binder per item, and the list posted in the room, so the list leads straight to the folder. Where committee minutes carry the evidence, flag the page and write on the flag the citation it proves, so that a flag reads "QIP Approval" and not just a color. In a virtual review the same test applies to an indexed set of files: can the reviewer open what the list names? Nobody should have to ask where anything is.
What does a ready packet look like next to a not-ready one?
A ready packet lets one named person show who did what and when, which version of the policy applied, and who approved the policy. Take a hypothetical organization to see the difference. The details are invented and the numbers are illustrative; none of it is an accreditor's requirement. The reviewer asks for the complaint-handling policy, the last four quarters of Quality Committee minutes, and a handful of staff files the reviewer picks.
Not ready: the policy says it is "reviewed periodically" and carries one date, with no effective date and no approval authority. The minutes say "complaints: 12" and stop, with no discussion, no goal and no follow-up. Two staff files hold training certificates but no completion date to set against the hire date. Who owns the packet depends on who is in the room that day. Desktop review asks whether the documents show compliance, and the policy and minutes in a packet like this give the reviewer little to mark Met. A standard marked Not Met draws a Request-for-Information, and the desktop review phase allows at most two such rounds.
Ready: the policy shows its original effective date and every review and revision since, and a review that changed nothing is still logged; that is my practice. It names its approval authority. The minutes show the number, the discussion of what it means, a numeric goal in the same units as the baseline, and a dated owner for each follow-up. The staff files are tabbed by item. One named person can say where everything is.
Why rehearse the review, and how close to the real one should the mock be?
Rehearse because accreditation drifts. Standards change and personnel turn over, and a step that was once routine quietly stops. Make the mock as close to the real review as you can. Coming up short in a mock is normal; what matters about each finding is what it costs to cure and whether the time is there to cure it. When I debrief a mock, I ask the team to take the result as useful information, not as an evaluation.
My recommendation is to do in the mock exactly what the accreditor will do: if the reviewer will come on site, rehearse on site, and if the review will be virtual, rehearse virtually. According to URAC, a validation review need not be held in person; a virtual format or a mix of formats is also possible, so work out which format yours will take from the materials your accreditor gives you. Match or exceed the reviewer's rigor: in IHS mock reviews we imagine the most rigid, hyper-detailed, rigorous reviewer we have ever encountered and play that reviewer.
Then prepare the people who will be interviewed, since URAC's validation review includes interviews of both leaders and staff. In one on-site mock review I ran, the person put forward to talk about a standard did not know whether a provision was in the contract, and it cost the organization mandatory elements. What I tell clients over and over is that the best preparation for staff for the validation review is to know exactly what they should be doing and to be able to document that they are doing what the policies say.
When should you schedule the mock, and what do you do with what it finds?
Late enough that your documents are real and early enough that the fixes fit before the review. My rule of thumb, not a standard, is about two months before the real review, because clients generally need a couple of months to fix what a mock turns up. The reason is cost. A finding in the mock is a repair on your own schedule. A Not Met at desktop review is the same repair, made after the review has started, and it puts you into a Request-for-Information round.
Sort what the mock finds by what it will take to cure. Start with findings where the process itself must still be built, because those take longest, and let the findings where the work exists and only the record is missing follow. Then give every fix an owner and an effective date, because a corrective action that names neither is hard to defend. Name one person to own all of it, with clear authority and the backing of senior management. The role does not have to be a full-time job, but the responsibility should be spelled out and not impaired by other duties. I design for systems, not individuals, because a process that depends on whoever happens to remember it fails at the first turnover. If a record does not exist yet, record what is true today and date it today; a record made now that carries an earlier date is a new problem.
What should you do, and by when?
Today, name the person who owns the evidence. This week, pull one policy, one set of minutes and a few staff files the way the reviewer would, and check that each shows who, when, which version and who approved the policy; if the owner cannot produce that quickly, that is where the mock starts. Then get your accreditor's own guidance on what to submit and what the reviewer examines for your program and standards version, and number your folders to match it. About two months before the real review (my rule of thumb, as above), run the mock in the real format and prepare the people who will be interviewed.
What do people ask about evidence and mock reviews?
What is a mock review?
A rehearsal of the accreditor's review, run by someone outside your team in the same format as the real one, that produces findings to fix before the real review.
What evidence do accreditation reviewers want to see?
In my experience, dated, owned records showing each policy was followed. Your accreditor's own guidance covers the specifics; for URAC, the Accreditation Guide's Demonstrating Compliance: Desktop Review sections are what URAC points applicants to when they decide which documents to submit.
Does a mock review guarantee accreditation?
No. Nobody can promise an outcome. A mock shows where you stand while there is time to fix what it finds.
How far ahead of the real review should I run a mock?
My rule of thumb is about two months ahead; it is not a standard.
Will a mock review find problems?
Every mock validation review I have run has. What matters is what each finding costs to cure and whether the time is there to cure it.
Is this different for ACHC, CARF, NABP or another accreditor?
I do not describe other accreditors' evidence lists here; check your own accreditor's published materials. This article describes only URAC's process.
Who inside the organization should own the evidence?
One named person, with senior backing. Prepare the people who run each process to answer for it.
