To audit ABA practice foundational registers and control evidence, test service, location, payer, workforce, system, data, control, dependency, segregation-of-duties, and access inventories against current source populations and real workflows. Check ownership, version, source date, scope, evidence, exceptions, change triggers, reconciliation, validation, and decision use. A complete-looking register is unreliable when unsupported rows, missing populations, or stale approvals remain hidden.

Define the foundational register and control-evidence audit

Bruno samples across registers and follows linked configurations end to end. One service offer should connect to a current location, qualified workforce, supported payer path, systems, dependencies, controls, permissions, and evidence. Every row has a stable identifier, owner, custodian, source, effective period, state, evidence, exception, change trigger, next review, and relationship to the decisions it supports.

Choose fields that support the decision

Record audit objective and period, register types, source populations, versions, owners and custodians, expected rows, inclusion and exclusions, sample and targeted tests, source dates, qualified approvals, field completeness, cross-register links, unsupported states, exceptions, changes since review, evidence provenance, control performance, conflicts, user access, dependency tests, findings, consequence, corrective owner, due date, retest, reopened items, decision impact, and current conclusion.

Separate source facts from practice decisions

For each register or control selected for audit, preserve the contract, policy, license, system evidence, owner attestation, or qualified review that supports its recorded state. The practice's supported, held, conditional, retired, or exception state appears in a separate field with an owner and date. A portal result, marketing statement, verbal comment, identifier, or old approval never silently becomes controlling evidence.

Set entry, review, and retirement rules

For each audited row, test what created it, when it became usable, who reviewed it, which changes should have reopened it, and whether retirement was recorded. Source expiry, staff changes, new sites, payer updates, system releases, incidents, audit findings, contract changes, and capacity shifts can trigger review. Historical versions remain available for older transactions and explanations.

Connect fields to real workflow gates

Trace the downstream workflow that relies on every sampled field, including intake, scheduling, clinical work, authorization, billing, payroll, access, safety, and reporting. Software may surface a current state and block a defined release. Authorized roles decide exceptions and qualified clinicians retain clinical judgment. The operational record keeps each decision and author visible.

Make a bounded operating decision

The practice scores what the evidence supports and keeps missing populations separate from failed rows. The auditor traces a sample service configuration across portfolio, location, payer, workforce, system, dependency, control, duty, and access records, then reverses the test from payroll, claims, identity, vendor, and site populations back into the registers. A cross-link can pass while an underlying source is stale, so each layer receives its own result. Findings state the affected decision and immediate safeguard. Retesting uses the corrected population and a fresh sample rather than the same repaired rows alone.

Reconcile independent source populations

Reconcile sampled registers against the source records most likely to expose omissions or stale states, including contracts, licenses, rosters, schedules, claims, systems, invoices, sites, and incidents. Differences receive an owner, consequence, next action, due date, and validation instead of disappearing through manual overwrites.

A fictional example

Bruno locks 50 register rows across ten domains. Thirty-six pass source, owner, currency, evidence, exception, and cross-link tests. Seven repair, three remain open, two are invalid duplicates, and two reference retired systems. The original 50-row cohort stays visible through final disposition. The scenario is synthetic. It tests scope, evidence, state, exception, and denominator logic without establishing legal compliance, clinical quality, coverage, payment, licensure, competence, security, financial accuracy, client satisfaction, or outcome.

Calculate compatible measures

Initial register integrity is 36 of 50, or 72.0%. Forty-three rows validate, or 86.0%. Rows, configurations, registers, source records, controls, exceptions, findings, and corrective actions remain separate.

Control the main risk

A register can be internally consistent and still omit an entire site, payer, vendor, or system. Bruno reconciles each inventory to at least one independent source population and tests high-consequence omissions directly.

Test hard cases

Test new service, closed site, payer termination, role change, shadow system, missing vendor, control exception, unresolved conflict, former-user access, broken dependency, duplicate row, and stale approval. Each case shows the source, owner, current state, affected workflow, immediate safeguard, exception route, correction, validation, and retirement or next-review rule.

Close the review with open work visible

Before closing the review, confirm population completeness, source currency, decision authority, qualified ownership, evidence, cross-register links, exceptions, change triggers, workflow use, validation, unresolved work, and next review. The foundational register and control-evidence audit remains draft until every named reviewer completes the required review.

Use CASP as organizational context

Use the CASP Organizational Guidelines public overview for high-level business, clinical-operations, and risk-management context. CASP sells the detailed guidance. The public page does not prescribe this foundational register and control-evidence audit, prove a row is complete, or grant authority for whether the practice can rely on its operating inventories and control conclusions.

Apply voluntary compliance guidance carefully

When reviewing the foundational-register audit, treat the OIG General Compliance Program Guidance as voluntary and nonbinding. Its discussions of risk assessment, policies, training, reporting, audits, corrective action, incentives, and oversight help test register design. Current law, contract, payer, professional, workforce, privacy, finance, and operational sources control each real decision.

Keep business orientation separate from authority

For broad business context around the foundational-register audit, use the SBA Manage Your Business guide as orientation across finances, employees, compliance, marketing, emergencies, and closure. It gives no ABA clinical, payer, privacy, licensure, facility, credentialing, tax, or legal authority. The register cites current primary sources for every material state.

Preserve clinical decision rights

For professional duties reflected in the foundational-register audit, apply the current BACB Ethics Code only to covered people and professional activities. The Code addresses competence, responsibility, client involvement, documentation, supervision, risk, evaluation, billing, and reporting. BACB has no separate corporate jurisdiction. Organizational ownership and register custody never replace qualified case-specific clinical judgment.

Scope privacy and security fields

For electronic PHI represented in the foundational-register audit, use HHS risk-analysis guidance when a covered entity or business associate must assess risks and vulnerabilities to all electronic protected health information it creates, receives, maintains, or transmits. HHS minimum-necessary guidance informs role-based PHI access when that standard applies. Neither source mandates a particular database, register, score, spreadsheet, or vendor product.

Use cybersecurity and provider identifiers within limits

For cybersecurity and identifier dependencies in the foundational-register audit, the practice can adapt the NIST Cybersecurity Framework as voluntary risk-management guidance while current legal and contractual requirements remain controlling. The CMS NPI fact sheet distinguishes individual and organizational identifiers and states that an NPI does not establish licensure, credentialing, enrollment, or payment. Identifiers connect records; they do not validate the underlying configuration.

Follow mismatches across registers

If the workforce register shows a terminated employee while the access register shows an active account and the evidence register shows a completed review, keep all three facts visible. Confirm source dates, contain any current exposure through the responsible route, and open an attributable issue. The audit should identify which control claim failed and which other populations may be affected, then verify correction through a fresh sample rather than editing the old evidence.

Related resources

Sources