To audit ABA practice planning and change portfolio controls, test annual and quarterly plans, initiative intake, resource allocation, constraints, assumptions, scenarios, benefit measures, post-implementation reviews, change load, decision rights, client safeguards, evidence, exceptions, and closure. Trace approved outcomes from source and capacity through delivery and realized results. Keep plans, initiatives, milestones, people, dollars, clients, benefits, and findings separate.

Define the planning and change-portfolio audit

Luz samples both successful and stopped work, mandatory obligations, high-risk changes, scarce-resource conflicts, late carryover, and initiatives whose benefits were never reviewed. The record connects source evidence, decision authority, capacity, cash, client and workforce effects, dependencies, measures, uncertainty, actions, and proof needed for the next state.

Choose fields that support the decision

Record audit objective and period, planning artifacts and versions, eligible populations, annual outcomes, quarterly commitments, required work, initiatives and states, owners and authority, resource capacity, constraints, assumptions and source dates, scenarios and triggers, client and workforce safeguards, approval gates, changes, adoption, benefit definitions, maturity windows, post-implementation decisions, exceptions, open defects, sampling, reviewer conflicts, findings, immediate safeguards, corrective owners, due dates, retest, and conclusion.

Turn the plan into decision gates

Perform forward and reverse traces. Forward, follow an annual outcome into quarterly allocation, initiative gates, launch, adoption, benefit evidence, and final decision. Reverse, start from staff time, vendor invoices, system releases, site changes, incidents, and client effects to find work that bypassed the portfolio. Test whether mandatory work and operational reserves were counted before discretionary starts. Findings show which commitments should pause, which decisions need reopening, and which planning controls require redesign rather than another status field.

Protect current services and required work

An audit of planning controls tests whether proposals identified staff, supervision, cash, systems, facilities, vendors, and leadership capacity already committed elsewhere. Planning begins with net available capacity. A proposed change cannot borrow hidden labor from documentation, supervision, incident response, client communication, payroll, payer deadlines, maintenance, or recovery.

Preserve qualified decisions and direct input

The audit verifies that case-specific clinical choices reached qualified clinicians and domain-specific legal, payer, workforce, privacy, security, finance, and facility choices reached authorized owners. Clients, families, and affected staff receive accessible ways to identify priorities, burdens, access needs, side effects, and workable alternatives. Their input is evidence, not a ceremonial signoff.

Keep versions, assumptions, and open work visible

For every sampled change, preserve the approved scope, baseline, assumptions, decision, resource allocation, workflow version, history, exceptions, defects, and unresolved work. Forecast updates never rewrite the earlier forecast. A closed milestone can link to later validation without pretending that adoption, benefit, payer acceptance, clinical quality, or financial return has already occurred.

Build decision-grade evidence

Define conclusions at the right level. One strong project cannot validate portfolio capacity, and a missed benefit does not prove the planning process failed. Distinguish design, implementation, operating, and outcome findings. Sampling covers different sites, teams, change types, consequence tiers, and states. Every exclusion keeps its reason. The audit report identifies the original population, tested records, evidence limits, immediate safeguards, disputed facts, owner response, corrective action, due date, and retest method. Repeated issues are linked to the shared planning control instead of counted as unrelated project defects.

A fictional example

Luz locks 40 planning and change records. Twenty-nine pass source, owner, capacity, gate, measure, exception, and closure tests. Seven repair, two remain open, one is an unapproved shadow initiative, and one benefit claim lacks a baseline. The original cohort remains 40 through final reporting. The scenario is synthetic. It tests scope, capacity, evidence, state, and denominator logic without establishing clinical quality, legal compliance, payer approval, staffing, funding, safety, client satisfaction, financial return, or outcome.

Calculate compatible measures

Initial control integrity is 29 of 40, or 72.5%. Thirty-six records validate, or 90.0%. Plans, outcomes, initiatives, milestones, resources, assumptions, benefits, findings, and corrective actions remain distinct.

Control the main planning risk

A portfolio can look controlled while untracked changes consume the same resources. The practice reconciles project boards, vendor spend, system releases, training, policy changes, meeting decisions, and staff reports to the approved inventory.

Test hard cases

Test annual plan, quarterly plan, mandatory obligation, shadow project, overallocated role, stale assumption, downside trigger, unmeasured benefit, late review, open defect, stopped initiative, and repeated carryover. Each case states the source, qualified owner, affected cohort, capacity and cash effect, client and workforce safeguard, dependency, decision, evidence, validation, and next review.

Close the review with unresolved work visible

Before closing the review, confirm source currency, authority, scope, capacity, resources, dependencies, assumptions, client and workforce effects, measures, exceptions, side effects, benefit evidence, corrective work, and open decisions. The planning and change-portfolio audit remains draft until every named reviewer completes the required review.

Place the planning method within organizational scope

Use the CASP Organizational Guidelines public overview for high-level business, clinical-operations, and risk-management context. CASP sells the detailed guidance. The public page does not prescribe this planning and change-portfolio audit, set a planning horizon, or authorize whether the practice can rely on its plans, allocations, forecasts, and change conclusions.

Use compliance guidance within its limits

Treat the OIG General Compliance Program Guidance as voluntary and nonbinding. Its discussions of leadership, risk assessment, training, reporting, audits, corrective action, incentives, and oversight inform planning checks. Current law, payer, professional, workforce, privacy, finance, facility, contract, and legal sources control actual obligations. In the portfolio-control audit, use those elements to test whether active changes have named oversight, monitoring, escalation, and corrective-action owners.

Use business-planning sources as orientation

Use the SBA Manage Your Business and Write Your Business Plan pages for broad business orientation. They give no ABA clinical, payer, facility, workforce, tax, privacy, safety, or legal authority. Page-specific sources, qualified owners, operating evidence, and current conditions support every material commitment. For the portfolio as a whole, these pages help reviewers challenge assumptions, resourcing, and business dependencies before leaders approve another change.

Preserve clinical authority and client involvement

Apply the current BACB Ethics Code to covered people and professional activities. It addresses competence, responsibility, client involvement, documentation, supervision, risk, evaluation, billing, and reporting. BACB has no separate corporate jurisdiction. Plans allocate resources and request decisions without transferring qualified clinical judgment to owners or software. The audit should therefore show which portfolio decisions remain with a qualified clinician and which belong to organizational management.

Include leadership and workforce evidence

Use OSHA's management leadership and worker participation pages as general safety-program guidance about goals, resources, accountability, reporting, participation, and response. The pages do not create a universal ABA planning model. Workers need usable routes to surface workload, access, safety, and implementation problems without retaliation. Portfolio review should connect worker reports to the specific change, interim safeguard, decision owner, and follow-up date.

Keep technology-risk planning scoped

The practice may adapt the NIST Cybersecurity Framework as voluntary cybersecurity risk-management guidance for technology and information dependencies. It does not replace HIPAA, state law, payer contracts, clinical authority, or the broader operating plan. Cybersecurity assumptions, risks, controls, incidents, and recovery work remain visible within the portfolio rather than hidden in a separate technical backlog. Technology dependencies stay in the same portfolio record so leaders can see how a cyber control or outage changes the operating plan.

Trace one initiative through every control

Select a completed, paused, and active initiative and follow each from original decision through assumptions, resource allocation, constraints, change approval, implementation, outcome evidence, and unresolved actions. Compare the portfolio view with source records and frontline experience. A green summary does not resolve a missing approval, hidden baseline impact, stale assumption, or untested benefit. Preserve exceptions and assign remediation before closing the audit sample.

Related resources

Sources