The Compliance Test Arrived
For years, health plans described their risk adjustment programs as “compliance-first.” The language appeared in board presentations, vendor contracts, and investor communications. The problem is that compliance-first was largely untested. When CMS audited a handful of contracts per year, most plans never faced the scrutiny that would reveal whether their compliance claims matched their operational reality.
That era ended. CMS now audits all 550+ MA contracts annually. Payment year 2020 audits launched in February 2026 with quarterly cadence. The agency scaled its review workforce from roughly 40 to approximately 2,000 certified coders, supplemented by AI-assisted pattern detection. Every plan’s coding output is now subject to the examination that only a few faced before.
The results from parallel OIG audits preview what RADV will find. Three organizations audited simultaneously in March 2026 showed error rates between 81% and 91%. The documentation failures were consistent: history-of conditions coded as active, acute diagnoses carried forward without current management evidence, and chronic conditions lacking MEAT support. These are industry-wide patterns, not organization-specific anomalies.
What the Test Reveals
Plans with genuine compliance infrastructure are discovering that their systems work. Their evidence trails are retrievable. Their MEAT validation catches weak documentation before submission. Their two-way review processes have been cleaning submitted data for years. When the audit notification arrives, they execute a documented playbook rather than launching an emergency project.
Plans that described themselves as compliance-first without building the corresponding infrastructure are discovering the gap. Their evidence trails are scattered across disconnected systems. Their coding processes never included systematic MEAT validation. Their retrospective programs ran add-only for years without removing unsupported codes. The compliance language was aspirational. The operations were revenue-optimized.
The distinction between these two groups shows up in audit response quality, timeline adherence, and ultimately, in findings and recoupment exposure. The test isn’t whether the plan said the right things. It’s whether the plan built the right systems.
The Operational Indicators That Predict Outcomes
Three metrics predict RADV outcomes before audit results arrive. First, the plan’s internal error rate from self-assessment audits. Plans that run quarterly mock RADV reviews against their own submitted data know their error rate before CMS calculates it. If internal reviews find 30% or higher error rates in high-risk categories, the RADV results will be similarly unfavorable.
Second, the plan’s deletion rate across retrospective review cycles. A zero or near-zero deletion rate signals an add-only program, which produces the asymmetric coding patterns CMS’s AI is designed to detect. Plans with meaningful deletion rates have been cleaning their submissions, which directly reduces the error rate auditors will find.
Third, the plan’s average time-to-evidence. When a specific HCC for a specific member is queried, how long does it take to produce the complete evidence package (clinical note, MEAT mapping, coding rationale, QA validation)? Plans that produce this in minutes built their evidence infrastructure into the coding process. Plans that need days or weeks to assemble it didn’t.
The Verdict Is in the Infrastructure
The radv audits in 2026 are the first universal test of whether MA plans built compliance programs or compliance narratives. The plans that invested in evidence-first coding, two-way review, pre-submission defensibility scoring, and documented audit response playbooks are passing the test. The plans that invested in compliance language without compliance infrastructure are discovering, under audit pressure, exactly how wide the gap is between what they said and what they built.

