To audit ABA practice foundational registers and control evidence, test service, location, payer, workforce, system, data, control, dependency, segregation-of-duties, and access inventories against current source populations and real workflows. Check ownership, version, source date, scope, evidence, exceptions, change triggers, reconciliation, validation, and decision use. A complete-looking register is unreliable when unsupported rows, missing populations, or stale approvals remain hidden.
Define the foundational register and control-evidence audit
Bruno samples across registers and follows linked configurations end to end. One service offer should connect to a current location, qualified workforce, supported payer path, systems, dependencies, controls, permissions, and evidence. Every row has a stable identifier, owner, custodian, source, effective period, state, evidence, exception, change trigger, next review, and relationship to the decisions it supports.
Choose fields that support the decision
Record audit objective and period, register types, source populations, versions, owners and custodians, expected rows, inclusion and exclusions, sample and targeted tests, source dates, qualified approvals, field completeness, cross-register links, unsupported states, exceptions, changes since review, evidence provenance, control performance, conflicts, user access, dependency tests, findings, consequence, corrective owner, due date, retest, reopened items, decision impact, and current conclusion.
Separate source facts from practice decisions
For each register or control selected for audit, preserve the contract, policy, license, system evidence, owner attestation, or qualified review that supports its recorded state. The practice's supported, held, conditional, retired, or exception state appears in a separate field with an owner and date. A portal result, marketing statement, verbal comment, identifier, or old approval never silently becomes controlling evidence.
Set entry, review, and retirement rules
For each audited row, test what created it, when it became usable, who reviewed it, which changes should have reopened it, and whether retirement was recorded. Source expiry, staff changes, new sites, payer updates, system releases, incidents, audit findings, contract changes, and capacity shifts can trigger review. Historical versions remain available for older transactions and explanations.
Connect fields to real workflow gates
Trace the downstream workflow that relies on every sampled field, including intake, scheduling, clinical work, authorization, billing, payroll, access, safety, and reporting. Software may surface a current state and block a defined release. Authorized roles decide exceptions and qualified clinicians retain clinical judgment. The operational record keeps each decision and author visible.
Make a bounded operating decision
The practice scores what the evidence supports and keeps missing populations separate from failed rows. The auditor traces a sample service configuration across portfolio, location, payer, workforce, system, dependency, control, duty, and access records, then reverses the test from payroll, claims, identity, vendor, and site populations back into the registers. A cross-link can pass while an underlying source is stale, so each layer receives its own result. Findings state the affected decision and immediate safeguard. Retesting uses the corrected population and a fresh sample rather than the same repaired rows alone.
Reconcile independent source populations
Reconcile sampled registers against the source records most likely to expose omissions or stale states, including contracts, licenses, rosters, schedules, claims, systems, invoices, sites, and incidents. Differences receive an owner, consequence, next action, due date, and validation instead of disappearing through manual overwrites.
A fictional example
Bruno locks 50 register rows across ten domains. Thirty-six pass source, owner, currency, evidence, exception, and cross-link tests. Seven repair, three remain open, two are invalid duplicates, and two reference retired systems. The original 50-row cohort stays visible through final disposition. The scenario is synthetic. It tests scope, evidence, state, exception, and denominator logic without establishing legal compliance, clinical quality, coverage, payment, licensure, competence, security, financial accuracy, client satisfaction, or outcome.
Calculate compatible measures
Initial register integrity is 36 of 50, or 72.0%. Forty-three rows validate, or 86.0%. Rows, configurations, registers, source records, controls, exceptions, findings, and corrective actions remain separate.
Control the main risk
A register can be internally consistent and still omit an entire site, payer, vendor, or system. Bruno reconciles each inventory to at least one independent source population and tests high-consequence omissions directly.
Test hard cases
Test new service, closed site, payer termination, role change, shadow system, missing vendor, control exception, unresolved conflict, former-user access, broken dependency, duplicate row, and stale approval. Each case shows the source, owner, current state, affected workflow, immediate safeguard, exception route, correction, validation, and retirement or next-review rule.
Close the review with open work visible
Before closing the review, confirm population completeness, source currency, decision authority, qualified ownership, evidence, cross-register links, exceptions, change triggers, workflow use, validation, unresolved work, and next review. The foundational register and control-evidence audit remains draft until every named reviewer completes the required review.
Use CASP as organizational context
Use the CASP Organizational Guidelines public overview for high-level business, clinical-operations, and risk-management context. CASP sells the detailed guidance. The public page does not prescribe this foundational register and control-evidence audit, prove a row is complete, or grant authority for whether the practice can rely on its operating inventories and control conclusions.
Apply voluntary compliance guidance carefully
When reviewing the foundational-register audit, treat the OIG General Compliance Program Guidance as voluntary and nonbinding. Its discussions of risk assessment, policies, training, reporting, audits, corrective action, incentives, and oversight help test register design. Current law, contract, payer, professional, workforce, privacy, finance, and operational sources control each real decision.
Keep business orientation separate from authority
For broad business context around the foundational-register audit, use the SBA Manage Your Business guide as orientation across finances, employees, compliance, marketing, emergencies, and closure. It gives no ABA clinical, payer, privacy, licensure, facility, credentialing, tax, or legal authority. The register cites current primary sources for every material state.
Preserve clinical decision rights
For professional duties reflected in the foundational-register audit, apply the current BACB Ethics Code only to covered people and professional activities. The Code addresses competence, responsibility, client involvement, documentation, supervision, risk, evaluation, billing, and reporting. BACB has no separate corporate jurisdiction. Organizational ownership and register custody never replace qualified case-specific clinical judgment.
Scope privacy and security fields
For electronic PHI represented in the foundational-register audit, use HHS risk-analysis guidance when a covered entity or business associate must assess risks and vulnerabilities to all electronic protected health information it creates, receives, maintains, or transmits. HHS minimum-necessary guidance informs role-based PHI access when that standard applies. Neither source mandates a particular database, register, score, spreadsheet, or vendor product.
Use cybersecurity and provider identifiers within limits
For cybersecurity and identifier dependencies in the foundational-register audit, the practice can adapt the NIST Cybersecurity Framework as voluntary risk-management guidance while current legal and contractual requirements remain controlling. The CMS NPI fact sheet distinguishes individual and organizational identifiers and states that an NPI does not establish licensure, credentialing, enrollment, or payment. Identifiers connect records; they do not validate the underlying configuration.
Follow mismatches across registers
If the workforce register shows a terminated employee while the access register shows an active account and the evidence register shows a completed review, keep all three facts visible. Confirm source dates, contain any current exposure through the responsible route, and open an attributable issue. The audit should identify which control claim failed and which other populations may be affected, then verify correction through a fresh sample rather than editing the old evidence.
Related resources
- ABA Practice Service Portfolio Register: Define What Each Program Offers
- ABA Practice Access Review: Role Changes, Least Privilege, and Removal
- ABA Practice Location and Service-Area Register: Sites, Modalities, and Authority
- ABA Practice Segregation of Duties Matrix: Prevent Conflicts and Single-Person Control
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview
- HHS Office of Inspector General, General Compliance Program Guidance
- U.S. Small Business Administration, Manage Your Business
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- U.S. Department of Health and Human Services, Guidance on Risk Analysis
- U.S. Department of Health and Human Services, Minimum Necessary Requirement
- National Institute of Standards and Technology, Cybersecurity Framework
- Centers for Medicare and Medicaid Services, National Provider Identifier Fact Sheet