US
U.S. Department of Health and Human Services, Office of Inspector General
Published March 2025

North Carolina’s Medicaid Control Environment, Risk Management Practices, and Governing Processes Were Assessed as Moderate Risk

Learn how the AI-generated research projects were created

Overall Conclusion

Overall, the audit determined that North Carolina's Medicaid control environment, risk management practices, and governing processes operate at a moderate risk level, with three risk areas rated high and three rated moderate; the State agency has implemented numerous controls but faces gaps in governance structure, strategic planning, performance management, ERM strategy, and compliance frameworks that could affect program integrity and outcomes.

Source Document

Audit Scope

Scope: The OIG performed a risk assessment of the North Carolina Department of Health and Human Services, Division of Health Benefits (State agency) for SFY 2022 (July 1, 2021 – June 30, 2022), aligning with the launch of managed care in North Carolina. The assessment considered recent data relative to the transformation, identifying 6 risk areas and 25 sub-risk areas using COSO ERM framework, GAO Green Book principles, and Federal Internal Control Requirements under 45 CFR § 75.303. The scope encompassed governance and culture, strategy and objective-setting, performance, review and revision, information, communication, and reporting, and federal internal control requirements; included assessment methodology, questionnaires, documentation review, interviews, and risk heat map; concluded overall risk at moderate and discussed implications for ongoing transition to managed care. It did not test transactions but reviewed program areas across Medicaid, including recipients’ eligibility, provider enrollment, payments, data systems, contract monitoring, and financial management. Appendix D provides the complete risk assessment.

Key Findings Summary

1

Governance and Culture: The state agency established oversight bodies and committees, but several governance and structure controls were not fully defined; two sub-risk areas (Defines Desired Culture and Demonstrates Commitment to Core Values) were low risk, while Exercises Board Risk Oversight and Establishes Operating Structures were moderate risk, and Att…

2

Strategy and Objective-Setting: The sub-risk areas Analyzes Business Context and Defines Risk Appetite were moderate; Evaluates Alternative Strategies and Formulates Business Objectives were high risk due to lack of formal external environment assessments, no defined risk appetite, no documented objectives, and absence of formal performance measures.

3

Performance: The organization identified risk and had formal risk management processes but did not fully implement OCPI’s Compliance Monitoring Program, and did not consistently assess inherent vs residual risk or prioritize risks; lack of formal portfolio view and prioritization hinder risk responses.

View the Findings tab to see all 7 findings

AI-Assisted

Generated by gpt-5-nano

AI Scope Summary

Assess and improve North Carolina’s Medicaid program governance, risk management, and internal controls, focusing on the transition to managed care, to determine risk levels and recommend mitigation actions.

AI-Generated Insight

This audit highlights the challenges states face in aligning the rapid transformation of Medicaid programs with robust governance and risk management. While North Carolina instituted several risk-aware practices during its transition to managed care, gaps in formal ERM strategy, objective-setting, and compliance monitoring left several high-risk areas under-addressed. Implementing an enterprise risk management program and standard internal controls would help NC DHHS strengthen program integrity, ensure regulatory compliance, and improve resource allocation as Medicaid evolves.

Audit Objectives

1

Assess the North Carolina Department of Health and Human Services, Division of Health Benefits’ control environment, risk management practices, and processes governing its Medicaid program.

Audit Findings (7)

1

Governance and Culture: The state agency established oversight bodies and committees, but several governance and structure controls were not fully defined; two sub-risk areas (Defines Desired Culture and Demonstrates Commitment to Core Values) were low risk, while Exercises Board Risk Oversight and Establishes Operating Structures were moderate risk, and Attracts, Develops, and Retains Capable Individuals was high risk due to lack of formal succession, contingency plans, staffing pressures, and inconsistent recruitment, training, mentoring, and retention plans.

2

Strategy and Objective-Setting: The sub-risk areas Analyzes Business Context and Defines Risk Appetite were moderate; Evaluates Alternative Strategies and Formulates Business Objectives were high risk due to lack of formal external environment assessments, no defined risk appetite, no documented objectives, and absence of formal performance measures.

3

Performance: The organization identified risk and had formal risk management processes but did not fully implement OCPI’s Compliance Monitoring Program, and did not consistently assess inherent vs residual risk or prioritize risks; lack of formal portfolio view and prioritization hinder risk responses.

4

Review and Revision: With the transition to managed care, there was no formal ERM strategy or policies governing its ERM; Reviews Risk and Performance and Pursues Improvement in ERM were rated high due to missing formal policies for performance assessment and lack of documented ERM strategy.

5

Information, Communication, and Reporting: Data reliability testing documentation was missing; formal policies governing communication with stakeholders and reporting requirements were incomplete; risks of regulatory reporting not being fully defined or met.

6

Federal Internal Control Requirements: The Federal internal control area was rated high risk; insufficient adoption of an internal control framework, and incomplete controls over compliance; policy gaps for managing findings of noncompliance and safeguarding sensitive information; incomplete documentation of internal controls for monitoring compliance.

7

Controls Over Compliance and Monitoring: There were weaknesses in addressing findings of noncompliance and safeguardingPII; the state did not fully document entity-level policies or formal policies governing monitoring of compliance.

Recommendations (11)

1

Document reliability testing of data used for decision-making and improve data quality controls.

2

Strengthen governance with formal succession planning, contingency planning, and staff wellbeing initiatives; address staffing pressures and retention.

3

Clarify and document board oversight requirements, roles, authorities, and independence; improve operating structure oversight.

4

Develop procedures to assess external factors and substantial changes; implement formal ERM strategy and governance policies.

5

Develop mitigating controls and strategies to lower risk within the identified high- and moderate-risk areas.

6

Adopt a formal enterprise risk management program and invest in staff, policy development, and technology solutions for tracking and reporting.

7

Adopt an internal control framework (GAO Green Book or COSO) and implement standardized controls over compliance.

8

Develop formal policies for managing the resolution of noncompliance and for safeguarding sensitive information; implement procedures for monitoring compliance.

9

Formalize strategic planning policies, define objectives, and establish performance measures; include formal evaluation of external environment and development of risk appetite.

10

Enhance risk management practices by improving severity assessment, risk prioritization, and portfolio risk analysis; implement formal risk responses.

11

Establish formal policies for communicating risk with internal and external stakeholders; ensure reporting requirements are identified and met.