Show me this working in the last ninety days
Almost every compliance program can recite the OIG's seven elements. The binder exists. The policies are signed. The annual training fires off its completion emails. And yet, when a program is tested by an audit, an investigation, or a regulator, the gap between what's documented and what's actually operating is where the exposure lives.
The seven elements, as laid out in the OIG's General Compliance Program Guidance, are not a checklist to be completed once. They describe a system that has to run continuously. A gap analysis worth paying for doesn't ask "do you have this?" It asks "show me this working in the last ninety days."
Here's what that distinction looks like, element by element.
1. Written policies and standards of conduct
On paper: a policy library exists and a code of conduct is posted. In practice: the policies reflect how the organization actually operates today, they're version-controlled, and staff can find the one they need without calling compliance. A library that hasn't been touched since the last accreditation cycle becomes a liability of its own.
2. Compliance officer and committee oversight
A named compliance officer and a committee charter satisfy the documentation. What matters after that is whether the committee meets on schedule, whether its minutes show real decisions rather than status updates, and whether the compliance function reports through a line that doesn't run past the people it may need to investigate.
3. Training and education
Assigning annual training and tracking completion is the easy half. The harder half is making it role-specific, since the revenue-cycle team and the surgeons don't need the same module, and getting attestation rates high enough to mean something. A 70% completion rate isn't a training program; it's the number an auditor will ask you to explain.
4. Effective lines of communication
Almost everyone has a hotline number. Fewer can show that people use it, that reports are triaged on a defined timeline, and that there's documented evidence of non-retaliation. A hotline that never rings is rarely a sign of a clean organization. More often it means staff don't trust it.
5. Auditing and monitoring
This is where most programs thin out. Monitoring is the program watching itself; auditing is an independent check. Both need to be risk-based, scheduled, and (this is the part that gets skipped) followed by action. An audit that surfaces an issue and closes without a corrective action plan is worse than no audit, because now the problem is documented and unaddressed.
6. Enforcement and discipline
On paper: the code says violations carry consequences. In practice: discipline is applied consistently, regardless of how senior or how revenue-generating the individual is. Inconsistent enforcement is one of the first things a regulator looks for, because it reveals whether the program has real authority or is theater.
7. Response and corrective action
An investigation procedure exists in most programs. The test is whether issues get investigated promptly, whether corrective action reaches the root cause rather than the symptom, whether overpayments are returned, and whether the program can produce the paper trail showing all of it happened. The willingness to act on what you find is what converts a compliance program from a cost center into genuine risk protection.
The real question is whether you could prove these were operating on a day you weren't expecting to be asked.
Where this matters most
For organizations operating under a Corporate Integrity Agreement, the distance between paper and practice carries a reporting obligation with a federal monitor attached. The same discipline protects any organization, though. A program built to withstand scrutiny on an ordinary Tuesday is one that rarely has to.
Want a clear read on where your program actually stands?
The Seven Elements self-scoring tool walks the same questions a gap analysis asks, scores each element, and shows you which gaps to close first. Free, and nothing you enter leaves your browser.
Score your program →This article is general information, not legal advice. Brandon Goulter is not an attorney, and reading it creates no professional advisory relationship. Compliance obligations vary by organization and circumstance.