The audit notice arrives and suddenly everyone is pulling files, rewriting minutes, and wondering if the re-credentialing they postponed last quarter is going to be a problem.
Sound familiar?
Delegation oversight audits don’t have to be stressful events. For organizations that manage their credentialing programs proactively, an audit is largely a confirmation of what they already know. Here’s how to get to that place.
What a Delegation Oversight Audit Actually Is
A payer delegation oversight audit is the mechanism by which a health plan confirms that your organization is fulfilling its obligations under the delegation agreement. They gave you authority to credential providers on their behalf — the audit is how they verify you’re doing it correctly.
Most audits occur annually or semi-annually. The payer typically gives advance notice, though the timeframe varies. They will review:
- A sample of provider credentialing files (usually 10–30 files)
- Credentialing committee minutes (typically the past 12 months or at least 3)
- Your credentialing and re-credentialing policies
- Evidence of ongoing sanction and exclusion monitoring; complaints and adverse events
- Turnaround time metrics
- Your compliance with the specific terms of the delegation agreement
90 Days Before the Audit: Get Your House in Order
1. Use our delegated credentialing audit checklist to guide your internal file review process. Don’t wait for the payer to find problems. Select 15–20 files at random and review each one against your policies and NCQA standards. Document what you find. Fix what you can. For anything you can’t fix retroactively, prepare a clear explanation.
2. Review your committee minutes for the past 12 months. Are they complete? Do they reflect which providers were reviewed, an actual documented discussion, what the decision was, and any conditions or deferrals? Thin or incomplete minutes are one of the most common audit findings — and one of the easiest to prevent going forward.
3. Run a re-credentialing report. Identify every provider whose re-credentialing is due in the next 6 months. Prioritize the ones that are overdue. An overdue re-credentialing file is a finding; many overdue files suggest a systemic problem. This can cause you to be put on a CAP if overdue files are noted in an audit.
4. Confirm your policies are current. Policies should be reviewed and updated annually and approved by appropriate leadership. If your policies haven’t been touched in two or more years, they need attention before any auditor sees them.
5. Confirm your policies are NCQA compliant. If you haven’t updated them to include the required elements, this will be found by the auditor.
30 Days Before the Audit: Final Preparation
1. Organize your documentation. Know exactly where everything is. If the auditor asks for a specific provider’s file, you should be able to produce it quickly. Disorganized files — even if technically complete — create a poor impression and slow the audit process.
2. Brief your team. Anyone who might interact with the auditor should understand the scope of the audit, what to expect, and how to respond to questions. Auditors are not adversaries, but your staff should be prepared to answer questions accurately and professionally.
3. Prepare your metrics. Most delegation agreements require you to track turnaround times. Know your numbers. Be ready to show that credentialing is being completed within the required timeframes. If your metrics reveal delays, be prepared to explain contributing factors and what you’ve done to address them.
4. Review your delegation agreement. It sounds obvious, but many organizations don’t regularly re-read the agreement they’re operating under. Confirm that your program is compliant with every term — including any that may have been updated at your last oversight audit.
During the Audit: How to Present Well
- Be present and available. Designate a single point of contact for the auditor.
- Answer questions directly and honestly. If you don’t know the answer, say so — then find it.
- Don’t volunteer information about problems that aren’t asked about, but don’t hide findings either. Auditors respect transparency.
- Take notes on every finding or area of concern the auditor raises.
After the Audit: Responding to Findings
Most audits produce some findings. That’s normal. What matters is how you respond.
Payers typically require a written corrective action plan (CAP) within 30–60 days of receiving the audit report. Your CAP should:
- Acknowledge each finding specifically
- Describe the root cause (not just the symptom)
- Outline the corrective action you’ve taken or will take
- Include a realistic timeline for implementation
- Identify who is responsible for the correction
Vague or boilerplate CAPs frustrate payers. Specific, credible, time-bound responses demonstrate that your organization takes its delegation responsibilities seriously.
The Best Audit Preparation Is Year-Round
The organizations that handle oversight audits most smoothly aren’t the ones who prepare the hardest in the 30 days before. They’re the ones who run their programs consistently all year — auditing their own files regularly, keeping their policies current, staying on top of re-credentialing timelines, and documenting everything.
If your program isn’t there yet, we can help you build the systems and habits that make audits uneventful.