A Medicare Advantage and Part D compliance program is the set of written measures a Medicare Advantage (MA) organization or Part D plan sponsor must adopt to prevent, detect and correct noncompliance with CMS program requirements and fraud, waste and abuse, including oversight of its first tier, downstream and related entities (FDRs). It is required by 42 CFR 422.503(b)(4)(vi) and 423.504(b)(4)(vi). Integral Healthcare Solutions (IHS) assesses your program against those rules and the CMS compliance program guidelines, then drafts the program documents and FDR oversight procedures for your compliance officer and counsel to approve.
Last reviewed: October 2026. Regulation text checked against the eCFR as current on September 30, 2026.
What is a Medicare Advantage and Part D compliance program?
The requirement sits in the contract qualification rules for MA organizations and Part D sponsors. Each must "Adopt and implement an effective compliance program, which must include measures that prevent, detect, and correct non-compliance with CMS' program requirements as well as measures that prevent, detect, and correct fraud, waste, and abuse" (42 CFR 422.503(b)(4)(vi)). The Part D text at 42 CFR 423.504(b)(4)(vi) reads the same.
The regulation then sets out the program's parts. Three examples from the MA text:
- The compliance officer "must be an employee of the MA organization, parent organization or corporate affiliate" and "may not be an employee of the MA organization's first tier, downstream or related entity" (422.503(b)(4)(vi)(B)(1)).
- Compliance training "must occur at a minimum annually and must be made a part of the orientation for a new employee and new appointment to a chief executive, manager, or governing body member" (422.503(b)(4)(vi)(C)(2)).
- The monitoring and auditing system "should include internal monitoring and audits and, as appropriate, external audits, to evaluate the MA organization, including first tier entities', compliance with CMS requirements and the overall effectiveness of the compliance program" (422.503(b)(4)(vi)(F)).
CMS's operating guidance is the combined Medicare Managed Care Manual Chapter 21 and Prescription Drug Benefit Manual Chapter 9, "Compliance Program Guidelines" (Chapter 21 Rev. 110 and Chapter 9 Rev. 16, both dated 01-11-13) (CMS PDF). The CMS Compliance Program Policy and Guidance page, last modified September 10, 2024, still links both chapters as current guidance (CMS). Because the chapters date from 2012 and 2013, IHS checks each guideline against the current regulation text before relying on it.
Who needs it and what triggers it
Every MA organization and Part D sponsor with a CMS contract needs the program. FDRs are pulled in through the sponsor's contracts. A first tier entity is "any party that enters into an acceptable written arrangement with an MA organization or contract applicant to provide administrative services or health care services for a Medicare eligible individual" (42 CFR 422.500).
The sponsor cannot hand off its responsibility: "the MA organization maintains ultimate responsibility for adhering to and otherwise fully complying with all terms and conditions of its contract with CMS" (42 CFR 422.504(i)(1)), and each FDR contract "must specify that the performance of the parties is monitored by the MA organization on an ongoing basis" (422.504(i)(4)(iii)).
Reasons to start include these (IHS's reading, not a CMS statement):
- A new MA or Part D contract, or a new line of business under an existing contract.
- A new compliance officer who needs to know where the program stands.
- Growth in delegated functions, so the FDR inventory and contracts no longer match what vendors do.
- An expected CMS program audit. See CMS program audit readiness.
How IHS helps
- Gap assessment. IHS sends questionnaires to your compliance officer and measures the program against 42 CFR 422.503(b)(4)(vi) or 423.504(b)(4)(vi), 422.504(i) and Chapter 21 / Chapter 9.
- Document and evidence mapping. Each requirement is mapped to the document or record that shows it: standards of conduct, committee charters and minutes, training records, hotline logs, the FDR inventory, delegation agreements and the monitoring and auditing work plan.
- Drafting. IHS drafts or revises the compliance program description, policies and procedures, FDR oversight procedures and the annual work plan, for your compliance officer and counsel to approve.
- Mock review. IHS tests the program against the mapped evidence and runs a practice compliance officer interview.
- Readiness support. IHS prepares the follow-up list and walkthrough material for the people who own each element.
What your organization supplies: the current program documents and evidence listed above, your FDR inventory and contracts, and the time of your compliance officer, who must be your own, your parent's or a corporate affiliate's employee.
The limit: your compliance officer and counsel make every decision, including whether a vendor is an FDR and whether anything is self-reported. Your organization submits anything that goes to CMS. IHS drafts; it gives no legal advice and no opinion on any fraud and abuse statute.
Related IHS pages: Compliance Services, Compliance Program Development and Exclusion screening program.
What to have ready
These items shorten the gap assessment. Each ties to the regulation (eCFR current as of September 30, 2026) or to Chapter 21 / Chapter 9.
- Your compliance program description, showing measures to "prevent, detect, and correct" noncompliance and fraud, waste and abuse (422.503(b)(4)(vi)).
- The compliance officer's job description and employer of record (422.503(b)(4)(vi)(B)(1)).
- Compliance committee charter and the last year of minutes.
- Training records for the last year, including orientation for new employees, executives, managers and governing body members (422.503(b)(4)(vi)(C)(2)).
- Your monitoring and auditing work plan, including any audits of first tier entities (422.503(b)(4)(vi)(F)).
- A current FDR inventory, with the services each entity provides (422.500 definitions).
- Your FDR contracts and delegation agreements, checked for the ongoing monitoring clause (422.504(i)(4)(iii)).
- Evidence of FDR monitoring. Chapter 21 / Chapter 9 says "Sponsors must conduct specific monitoring of first tier entities to ensure they fulfill the compliance program requirements" (section 50.6.6).
- Exclusion screening records for employees, governing body members and FDRs. The guidelines call for review of the OIG LEIE and the GSA exclusion list "prior to the hiring or contracting" and "monthly thereafter" (section 50.6.8). The manual names the older EPLS system; GSA moved EPLS into SAM in July 2012 (OIG bulletin), so IHS builds screening against SAM.gov. That is IHS's reading; the manual and the current regulation text at 42 CFR 455.436 still name EPLS.
- A list of any compliance functions handled outside the sponsor, its parent or a corporate affiliate (section 40).
If you would like to go through the list with IHS, book the introductory call below.
How it compares
Sponsors usually weigh these routes. They are not exclusive.
| Route | What the sources say |
|---|---|
| Compliance run by plan staff, without a written FDR oversight program | The guidelines state the sponsor "maintains the ultimate responsibility" for its CMS contract and "CMS may hold the sponsor accountable for the failure of its FDRs" (section 40). How often CMS cites this gap was not found in the sources we reviewed. |
| An accreditation program used in place of the regulatory elements | The regulation text we reviewed contains no accreditation substitute for the 422.503(b)(4)(vi) elements. That is IHS's reading of the text as of October 2026, not a CMS statement. |
| Using vendors for compliance work | Chapter 21 / Chapter 9 allows FDRs for "monitoring, auditing, and training" but not for compliance program administrative functions such as the compliance officer or committee (section 40). |
| IHS gap assessment and drafting | The crosswalk, drafted program documents and FDR procedures, and a mock review. It does not replace your compliance officer or counsel. |
What it costs
No CMS fee attaches to adopting a compliance program; it is a contract requirement, not an accreditation. CMS does not publish a fee schedule for this work on the pages we reviewed; costs depend on scope, such as the number of contracts, lines of business and FDRs. IHS scopes each engagement after a free introductory call.
What this is not
- This page is not legal advice. IHS is a consulting firm, not a law firm, and gives no opinion on any fraud and abuse statute.
- IHS does not act as your compliance officer or compliance committee.
- IHS does not contact, submit to or speak for your organization to CMS. IHS drafts; your organization submits.
Frequently asked questions
What does a Medicare Advantage or Part D compliance program have to contain?
42 CFR 422.503(b)(4)(vi) and 423.504(b)(4)(vi) require an effective compliance program with measures that prevent, detect and correct noncompliance with CMS program requirements and fraud, waste and abuse. The regulation then lists the program's parts, including a compliance officer, training and education, and a system for monitoring and auditing. CMS describes each part in Chapter 21 / Chapter 9 of its manuals.
Who counts as a first tier, downstream or related entity?
Under 42 CFR 422.500, a first tier entity is any party with an acceptable written arrangement with an MA organization or contract applicant to provide administrative or health care services for a Medicare eligible individual. The same section defines downstream and related entities. Whether a given vendor meets a definition is a decision for your compliance officer and counsel; IHS organizes the facts for that decision.
Can we delegate our compliance officer or compliance committee to a vendor?
No. The regulation requires the compliance officer to be an employee of the MA organization, its parent or a corporate affiliate, and not of an FDR. Chapter 21 / Chapter 9 says sponsors may not delegate compliance program administrative functions to anyone other than a parent or corporate affiliate, but may use FDRs for monitoring, auditing and training.
What must our FDR contracts say about monitoring?
42 CFR 422.504(i)(4)(iii) requires each contract to specify that the MA organization monitors the parties' performance on an ongoing basis. Section 422.504(i) sets other contract terms as well. IHS checks your contracts against the full section and lists the gaps for your counsel.
Does using FDRs move responsibility away from the plan?
No. Under 42 CFR 422.504(i)(1), the MA organization keeps ultimate responsibility for complying with its CMS contract, whatever its relationships with FDRs. Chapter 21 / Chapter 9 adds that CMS may hold the sponsor accountable for the failure of its FDRs.
How do we show that our FDR monitoring works?
The guidelines say sponsors must conduct specific monitoring of first tier entities to ensure they meet the compliance program requirements. IHS's reading is that this calls for a written monitoring plan, records of the monitoring done, and follow-up on what it found. IHS drafts the plan and the record templates and tests them in the mock review.
How often must compliance training happen?
The regulation requires training at a minimum annually and as part of orientation for new employees and for new appointments to chief executive, manager or governing body roles. The 2012-2013 manual text also discusses FDR training, and the current 422.503(b)(4)(vi)(C) text (checked September 30, 2026) names employees, the chief executive, senior administrators, managers and governing body members but not FDRs. Whether CMS still expects FDR training is not settled in the sources we reviewed; that is IHS's reading of the two texts. Until your counsel decides, keep any FDR training you already run, since that holds under either reading.
How often do we screen against exclusion lists?
Chapter 21 / Chapter 9 calls for checking the OIG LEIE and the GSA exclusion list before hiring or contracting and monthly after that, for employees, temporary employees, volunteers, consultants, governing body members and FDRs. The manual still names the EPLS system, which GSA moved into SAM.gov in July 2012.
Is the CMS compliance guidance current?
The CMS Compliance Program Policy and Guidance page, last modified September 10, 2024, links Chapter 21 and Chapter 9 as the guidance. The chapters themselves are dated 2012 and 2013. IHS reads each guideline against the regulation text as current on the eCFR and flags where the two differ.
