Program design

The Seven Elements in practice, not on paper

Almost every compliance program can recite the OIG's seven elements. The binder exists. The policies are signed. The annual training fires off its completion emails. And yet, when a program is tested by an audit, an investigation, or a regulator, the gap between what's documented and what's actually operating is where the exposure lives.

The seven elements, as laid out in the OIG's General Compliance Program Guidance, are not a checklist to be completed once. They describe a system that has to run continuously. A gap analysis worth paying for doesn't ask "do you have this?" It asks "show me this working in the last ninety days."

Here's what that distinction looks like, element by element.

1. Written policies and standards of conduct

On paper: a policy library exists and a code of conduct is posted. In practice: the policies reflect how the organization actually operates today, they're version-controlled, and staff can find the one they need without calling compliance. A library that hasn't been touched since the last accreditation cycle is a liability, not a defense.

2. Compliance officer and committee oversight

On paper: there's a named compliance officer and a committee charter. In practice: the committee meets on schedule, its minutes show real decisions rather than status updates, and the compliance function has a reporting line that doesn't run through the people it may need to investigate.

3. Training and education

On paper: annual training is assigned and completion is tracked. In practice: training is role-specific (the revenue-cycle team and the surgeons don't need the same module) and attestation rates are high enough to mean something. A 70% completion rate isn't a training program; it's a finding waiting to happen.

4. Effective lines of communication

On paper: there's a hotline number. In practice: people use it, reports are triaged on a defined timeline, and, critically, there's documented evidence of non-retaliation. A hotline that never rings is rarely a sign of a clean organization; more often it signals that staff don't trust it.

5. Auditing and monitoring

This is where most programs thin out. Monitoring is the program watching itself; auditing is an independent check. Both need to be risk-based, scheduled, and (this is the part that gets skipped) followed by action. An audit that surfaces an issue and closes without a corrective action plan is worse than no audit, because now the problem is documented and unaddressed.

6. Enforcement and discipline

On paper: the code says violations carry consequences. In practice: discipline is applied consistently, regardless of how senior or how revenue-generating the individual is. Inconsistent enforcement is one of the first things a regulator looks for, because it reveals whether the program has real authority or is theater.

7. Response and corrective action

On paper: there's an investigation procedure. In practice: issues are investigated promptly, root causes (not just symptoms) are addressed, overpayments are returned, and the program can produce a paper trail showing it did so. The willingness to act on what you find is what converts a compliance program from a cost center into genuine risk protection.

The question is never whether you have the seven elements. It's whether you could prove they were operating on a day you weren't expecting to be asked.

Where this matters most

For organizations operating under a Corporate Integrity Agreement, the difference between paper and practice isn't academic. It's a reporting obligation with a federal monitor attached. But the same discipline protects any organization. A program built to withstand scrutiny on an ordinary Tuesday is one that rarely has to.

Want a clear read on where your program actually stands?

The Seven Elements self-scoring tool walks the same questions a gap analysis asks, scores each element, and shows you which gaps to close first. Free, and nothing you enter leaves your browser.

Score your program

This article is general information, not legal advice. Brandon Goulter is not an attorney, and reading it creates no professional advisory relationship. Compliance obligations vary by organization and circumstance.