In This Analysis
- T-90 Days: Centralize and Reconcile, Continuously
- T-60 Days: Stress-Test Your Highest-Volume, Lowest-Dollar Category
- T-30 Days: Staff the Response Before the Clock Starts
- Submission Day Through the Pre-Publication Review Window
- After Publication: The Five-Year Clock Doesn't Reset
- Make the Runbook the Default, Not the Exception
A checklist tells a compliance team what to do. It doesn't tell them when. The difference matters, because CMS Open Payments audit readiness isn't a single event that happens in the weeks before the March 31 submission deadline; it's a standing operational calendar with distinct work at each phase, and teams that only mobilize once a year are reconstructing the same documentation trail from scratch every twelve months.
This runbook lays out that calendar in four phases: 90 days out, 60 days out, 30 days out, and the stretch from submission through the pre-publication review window and into the five-year retention period. Each phase maps to a specific failure mode in the underlying CMS data, drawn from qordata's analysis of 46.4 million General Payment records, PY2023 to PY2025.
Looking for the practice-level checklist? qordata's CMS Open Payments Audit: Resources & FAQs includes a seven-practice readiness checklist covering documentation, reconciliation, and retention. This runbook builds on those same practices and puts them on a calendar tied to CMS's actual submission and review dates.
T-90 Days: Centralize and Reconcile, Continuously
Ninety days out is early enough to fix a broken process, not just paper over a bad quarter. The first task is a source-system reconciliation: match what your expense platform, CRM, and speaker-program logs show against what's actually been staged for submission, for every category, not just the largest dollar ones. Waiting until the weeks before the deadline to run this reconciliation for the first time all year is the single most common reason a submission ships with errors CMS or a covered recipient later disputes.
The category that breaks this pattern most often isn't the one with the biggest dollar figures. It's the one with the most records.
Payments of $10,000 or more make up only about 0.15% of all General Payment transactions but account for roughly half of all dollars, every year. That means the other half of your dollar exposure lives inside the 99.85% of records that are individually small, food and beverage above all. A reconciliation process built around dollar thresholds will pass every high-dollar review and still miss the volume-driven errors CMS is positioned to catch simply by counting.
T-60 Days: Stress-Test Your Highest-Volume, Lowest-Dollar Category
Royalty and license payments tell the opposite story and deserve their own line item in this phase. They're General Payments' single largest category by dollar value, swinging from $1.20 billion (2023) to $855.1 million (2024) back to $1.20 billion (2025), spread across only 15,000 to 16,000 transactions a year. High dollars, low volume, and a different underlying economic logic than a consulting fee or a meal. Confirm your own submission separates royalty spend from promotional categories cleanly; a blended total can make an accurate filing look volatile when it isn't, and it's the kind of thing a reviewer notices immediately when benchmarking your numbers against the market.
Sixty days out, pull a sample, or better, run a full pass, of your food and beverage and low-dollar travel records specifically. These categories carry the largest share of total transaction volume for most reporting entities, and a modest error rate compounds fast at that scale. Confirm attendance records tie to actual events, that per-person spend calculations are consistent across regions and field teams, and that recipient names and identifiers match CMS's covered-recipient data without manual cleanup at submission time.
This is also the point to check category mix against your own prior years. If consulting or speaker fees are growing faster than your food and beverage spend, in line with the market-wide shift from 1.41 to 1.46 in the consulting-to-meal ratio between 2023 and 2025, confirm that the fair-market-value and needs-assessment documentation for those higher-value arrangements has kept pace with the dollars, not just the compliance calendar.
T-30 Days: Staff the Response Before the Clock Starts
CMS's 2026 proposed rulemaking would formalize a 30-day response window for audit record requests, with civil monetary penalty exposure for missing it. Whether or not that rule finalizes on its current terms, 30 days is already the working standard compliance teams should plan around. That means the response team, records retrieval, legal review, submission, needs to be named and rehearsed before a request arrives, not assembled after one does.
Thirty days out from your own submission deadline is the right moment to run that team through a tabletop exercise: given a hypothetical CMS request for a specific recipient or category, how long would it actually take to produce the contract, the FMV assessment, the attendance record, and the reconciliation file connecting all three back to the submitted record? If the honest answer is longer than 30 days, that's the gap to close now, not during a live response.
Submission Day Through the Pre-Publication Review Window
Submission isn't the finish line. CMS's pre-publication review period, typically April 1 through May 15, extended through May 30 for outstanding disputes, is a second data-quality checkpoint most compliance calendars treat as someone else's problem. It shouldn't be. Every dispute a covered recipient files during that window is a preview of exactly the kind of discrepancy a later audit would also flag, and it's arriving with the recipient's own explanation attached.
Treat the dispute window as a diagnostic. A cluster of disputes tied to one field team, one product line, or one category is a process signal worth tracing back to its source, not just a queue of individual corrections to clear before the May 30 deadline.
After Publication: The Five-Year Clock Doesn't Reset
CMS can request records supporting any Program Year within the five-year retention window, not just the most recently published one. That means your T-90 runbook needs to run every year, on overlapping tracks, for every Program Year still inside that window. A records system that only keeps the current year easily accessible, with prior years archived rather than retrievable, is the single most common reason a response to an older Program Year's audit request takes far longer than 30 days.
This is also where a Name of Study mismatch on a Research Payment record tends to surface, often on a Program Year that closed long ago. CMS checks the submitted study title and, where applicable, its ClinicalTrials.gov identifier against the public registry, and a shorthand name or a drifted title creates a mismatch CMS can flag years later. When that happens, the correction shouldn't stop at the specific records CMS identified: reviewing every Name of Study entry on file, current and prior Program Years, against the registry catches the same naming habit before it produces a second flag.
Make the Runbook the Default, Not the Exception
The teams that clear a CMS audit fastest aren't the ones with the best checklist. They're the ones who never stopped running it. Expense Monitoring & Auditing (EMA) applies continuous, 100%-of-records AI review to expense and payment data specifically, so the T-90 reconciliation and T-60 stress test above happen automatically, all year, rather than as a seasonal sprint. Compliance Central centralizes the documentation trail so a T-30 tabletop exercise stops being hypothetical: every submitted record already links back to its contract, receipt, or approval. For teams building the response protocol itself, Risk Assessment & Management (RAM) structures that risk-assessment work against recognized frameworks rather than an internal spreadsheet built from scratch each year.