Blog · 5 Aug 2026 · 11 min read
Seven elements of an effective compliance program: what OIG actually calls them now
§ Live · Compliance scan
No signup. Nothing you pick is stored.
Sample register · fintech, US · what a scan returns
- § 01 Written AML program with a named officer
- § 02 KYC and customer due diligence
- § 03 Sanctions screening lists Changed
- § 04 PCI DSS v4.0 validation
The short answer: the seven elements of an effective compliance program, as the HHS Office of Inspector General names them in its General Compliance Program Guidance, are written policies and procedures; compliance leadership and oversight; training and education; effective lines of communication with the compliance officer and disclosure programs; enforcing standards, consequences and incentives; risk assessment, auditing and monitoring; and responding to detected offenses and developing corrective action initiatives.
Those are not the names most people know. The list circulating in training decks, consultant slides and vendor collateral is the 1998 version. OIG published the General Compliance Program Guidance on 6 November 2023, and it renamed two elements, promoted risk assessment into a named element, and changed the order. This piece walks each element as OIG now words it, explains what actually changed, and sets out the evidence each element has to produce. Checked against the guidance document itself in August 2026.
What are the seven elements of an effective compliance program?
Section III of the GCPG is titled Compliance Program Infrastructure: The Seven Elements. In OIG's own numbering they run:
- Written Policies and Procedures
- Compliance Leadership and Oversight
- Training and Education
- Effective Lines of Communication with the Compliance Officer and Disclosure Programs
- Enforcing Standards: Consequences and Incentives
- Risk Assessment, Auditing, and Monitoring
- Responding to Detected Offenses and Developing Corrective Action Initiatives
Read that against whatever list your organization currently uses. If element five is described as disciplinary guidelines and element six as internal monitoring and auditing, you are working from the older framing, and two of the differences carry real weight.
Where does the seven elements list come from?
It did not originate in healthcare. The structure comes from the Federal Sentencing Guidelines, whose chapter eight sets out the steps an organization must take to have an effective compliance and ethics program, and which courts consider when calculating a corporate sentence. OIG adapted that structure into its healthcare compliance program guidance beginning in 1998, publishing separate documents for hospitals, home health agencies, clinical laboratories and other segments over the following decade.
That is why the seven elements show up almost identically across industries that otherwise share nothing. A bank AML program, a defense contractor ethics program and a hospital compliance program are all descendants of the same sentencing framework. The bank version has diverged furthest and is now usually described as five pillars, which is covered separately in our piece on the anti money laundering program.
What changed in the 2023 OIG guidance?
Three things, and only the first is cosmetic.
The order moved. In most older lists, monitoring and auditing sat at position five and enforcement at six. The GCPG reverses them. If your compliance committee charter, your annual work plan or your board reporting pack is organized against the old numbering, the mapping to what OIG now expects is not one to one, and anyone reading your documentation against the current guidance will notice.
Enforcement now includes incentives. Element five is Enforcing Standards: Consequences and Incentives. The older framing covered discipline only, usually phrased as well-publicized disciplinary guidelines. OIG's current text says an organization should establish appropriate consequences for instances of noncompliance as well as incentives for compliance, and that both are important to enforcing compliance. It also draws a distinction inside consequences themselves: they may be educational and remedial rather than punitive, and intentional or reckless noncompliance should attract significant sanctions. A program that can evidence sanctions but has never built any incentive for compliance performance is answering half the element.
Risk assessment became part of a named element. Element six is Risk Assessment, Auditing, and Monitoring. In the older seven-element lists, risk assessment was an implied prerequisite: obviously you would assess risk before deciding what to audit, but it was not on the face of the list and so it was frequently undocumented. Now it is named. In practice this is the most common structural gap we see, because a great many organizations have a perfectly respectable annual audit plan that was copied forward from the previous year with no dated risk assessment driving its scope.
Element by element, and the evidence each one needs
The test for every element is the same. Not whether you do it, but whether you can show a third party that you did it, on a date, with a named owner.
Element 1, written policies and procedures. A code of conduct plus the policies and procedures that implement it. The evidence is approved versions with effective dates and a record of who attested to which version. The usual failure is not absence but staleness: a policy set that was excellent when written and has not been revisited since a merger, a new service line or a rule change. Tying each document to the obligation it satisfies is what makes that detectable, which is the argument for policy compliance software over a shared drive.
Element 2, compliance leadership and oversight. OIG is unusually direct here. Every entity should designate a compliance officer with the authority, stature, access and resources to lead the program. That officer should be empowered and independent of other functions, and should not simultaneously provide the entity with legal or financial advice or supervise anyone who does. The arrangement most often questioned is a compliance officer reporting into the general counsel, because it collapses exactly the separation the guidance asks for. Evidence lives in the reporting line, the committee charter and board minutes that show escalations were received and acted on.
Element 3, training and education. Completion records by role, tied to a content version and a date. The weak pattern is one generic annual course issued to clinicians, billing staff and executives alike, which satisfies a completion metric and almost nothing else. Role-specific training is more work and is the only version that survives a question about whether the people making coding decisions were trained on coding risk.
Element 4, effective lines of communication and disclosure programs. A reporting channel people will actually use, including anonymously, plus a record of what happened to each report. The gap here is rarely the hotline. It is disposition: reports arrive, get handled informally by whoever knows the area, and leave no intake-to-closure trail. A regulator or a monitor will ask for the trail, not for the phone number.
Element 5, enforcing standards, consequences and incentives. A published framework setting out what happens after noncompliance, applied consistently across seniority. Consistency is the part that gets tested, because selective enforcement is more damaging to a program's credibility than a lenient standard applied evenly. And, per the 2023 change, some evidence that compliance performance is rewarded and not merely audited.
Element 6, risk assessment, auditing and monitoring. A dated risk assessment, an audit plan whose scope visibly derives from it, and monitoring that runs between audits. Monitoring and auditing are not synonyms: monitoring is ongoing and usually done by the process owner, auditing is periodic and independent. Programs that conflate them typically end up with neither. This is also the element where measuring the program itself belongs, and organizations that go beyond checklist self-assessment tend to score their compliance culture and process maturity rather than count completed tasks, because the count says nothing about whether people would actually speak up.
Element 7, responding to detected offenses and corrective action. An investigation file, a documented remediation, a root cause that was actually closed, and where relevant a decision on repayment or disclosure. The recurring failure is that the immediate issue gets fixed and the cause does not, so the same finding reappears two audit cycles later. That repetition is far more damaging than the original issue, because it converts a mistake into a pattern.
Are the seven elements required by law?
OIG's compliance program guidance is voluntary and non-binding, and OIG says so plainly. The practical pressure comes from elsewhere. Program adequacy shapes settlement negotiations and whether a corporate integrity agreement is imposed. Medicare Advantage organizations face CMS compliance program requirements directly. Skilled nursing facilities carry a statutory obligation dating to the Affordable Care Act. And the Federal Sentencing Guidelines route means an effective program can reduce a criminal fine calculation. Voluntary is accurate as a description of the guidance, and misleading as a description of the risk.
How do the OIG seven elements relate to the DOJ framework?
They are different documents doing different jobs, and confusing them is common. The Department of Justice publishes its Evaluation of Corporate Compliance Programs, which prosecutors use when deciding how to treat a company under investigation. It is not a seven-element list. It is organized around three fundamental questions: whether the program is well designed, whether it is adequately resourced and empowered to function effectively, and whether it works in practice.
The useful way to hold both is that OIG's seven elements describe the structure you build, and DOJ's three questions describe how someone will interrogate it afterwards. A program can satisfy all seven elements on paper and fail the third DOJ question badly, because paper is exactly what that question is designed to see through.
Which OIG guidance applies to my organization?
There are now two layers, and this trips people up because the older documents are still findable. The General Compliance Program Guidance applies to everyone in the healthcare industry. On top of it sit Industry Segment-Specific Compliance Program Guidances, tailored to the fraud and abuse risks of one segment. Two ICPGs exist as of August 2026: the Nursing Facility ICPG published 20 November 2024, and the Medicare Advantage ICPG published 3 February 2026.
An ICPG sits on top of the GCPG rather than replacing it, so an affected organization reads both. The older segment CPGs going back to 1998 are archived, though still available, once an ICPG covers their segment. One further change is worth knowing if you monitor rulemaking: OIG stated that it will no longer publish updated or new compliance program guidance in the Federal Register, and that current guidance lives on its website instead. Watching the Register for this material will quietly return less and less.
How to test your own program against the current list
Take one real issue your organization detected in the last year and trace it across all seven elements. Which policy covered it, and what version was in force on the day. Whether the people involved had been trained on that specific risk. How it was reported and what the disposition record says. What consequence followed and whether a comparable issue at a different level of seniority drew the same response. Whether the risk assessment had identified this area, and whether the audit plan covered it. What the corrective action was, and whether the root cause is closed today.
Almost every program has two or three places in that chain where the answer is a person's memory rather than a record. Those are the gaps worth fixing first, and they are the same gaps a monitor would find. Structuring the whole register against the current element names, so the mapping is maintained continuously rather than reconstructed under pressure, is the job of healthcare compliance software. The auditing and monitoring half is covered in more depth on audit management software, and keeping the underlying rules current on regulatory change management software.
General regulatory information, not legal advice. Written by the team at ComplianceOfficer building Complianceofficer; verify anything consequential with qualified counsel.