Skip to Main Content

More than half of organizations that fall victim to fraud recover nothing—a sign that it remains a persistent and costly risk for financial services organizations. A proactive fraud risk management approach is essential.

Defined contribution plan fiduciaries, especially those overseeing 401(k)s, face ongoing ERISA class actions. Plaintiffs now target routine practices, claiming they raise plan costs or shift expenses to participants. Plan sponsors, committees, and service providers are rechecking long‑standing practices to reduce risk. 

To foster broader adoption of the Community Bank Leverage Ratio framework and maintain strong capital standards for community banks, federal banking agencies revised the framework in a final rule issued on April 23, 2026. 

The Financial Accounting Standards Board (FASB) issued Accounting Standards Update (ASU) 2025-08 in November 2025 to address stakeholder concerns regarding the accounting for acquired financial assets under current US GAAP. This update specifically amends the guidance for purchased loans, aiming to improve comparability, consistency, and decision usefulness in financial reporting. 

Best practices for financial institution contracts with technology providers

As the financial services sector moves in an increasingly digital direction, you cannot overstate the need for robust and relevant information security programs. Financial institutions place more reliance than ever on third-party technology vendors to support core aspects of their business, and in turn place more reliance on those vendors to meet the industry’s high standards for information security. These include those in the Gramm-Leach-Bliley Act, Sarbanes Oxley 404, and regulations established by the Federal Financial Institutions Examination Council (FFIEC).

LIBOR is leaving—is your financial institution ready to make the most of it?

In July 2017, the UK’s Financial Conduct Authority announced the phasing out of the London Interbank Offered Rate, commonly known as LIBOR, by the end of 20211. With less than two years to go, US federal regulators are urging financial institutions to start assessing their LIBOR exposure and planning their transition. Here we offer some general impacts of the phasing out, specific actions your institution can take to prepare, and, finally, some background on how we got here (see Background at right).

Best Practices for Educating Your Financial Institution’s Board of Directors on Cybersecurity

According to Cybersecurity Ventures, cybercrime will account for $6 trillion annually by 2021—that’s more than the global trade of all major illegal drugs combined.  Data breaches and other information security events adversely impact organizations through significant losses in revenue, erosion of customer trust, substantial remediation costs, increased insurance premiums, and more.

In auditing, the concept of professional skepticism is ubiquitous. Just as a Jedi in Star Wars is constantly trying to hone his understanding of the “force”, an auditor is constantly crafting his or her ability to apply professional skepticism. 

All teams experience losing streaks, and all franchise dynasties lose some luster. Nevertheless, the game must go on. 

Reading through the 133-page exposure draft for the Proposed Statement on Auditing Standards (SAS) Forming an Opinion and Reporting on Financial Statements of Employee Benefit Plans Subject to ERISA, issued back in April 2017, and then comparing it to the final 100+ page standard approved in September 2018, may not sound like a fun way to spend a Sunday morning sipping a coffee (or three), but I disagree.

Artificial Intelligence, or AI, is no longer the exclusive tool of well-funded government entities and defense contractors, let alone a plot device in science fiction film and literature. Instead, AI is becoming as ubiquitous as the personal computer. 

The world of professional sports is rife with instability and insecurity. Star athletes leave or become injured; coaching staff make bad calls or public statements. The ultimate strength of a sports team is its ability to rebound. The same holds true for other groups and businesses.

Any sports team can pull off a random great play. Only the best sports teams, though, can pull off great plays consistently — and over time. The secret to this lies in the ability of the coaching staff to manage the team on a day-to-day basis, while also continually selling their vision to the team’s ownership.

A professional sports team is an ever-changing entity. To have a general perspective on the team’s fluctuating strengths and weaknesses, a good coach needs to trust and empower their staff to discover the details. Chapter 5 in BerryDunn’s Cybersecurity Playbook for Management looks at how discovery can help managers understand their organization’s ever-changing IT environment. 

Just as sports teams need to bring in outside resources — a new starting pitcher, for example, or a free agent QB — in order to get better and win more games, most organizations need to bring in outside resources to win the cybersecurity game.

It may be hard to believe some seasons, but every professional sports team currently has the necessary resources — talent, plays, and equipment — to win. The challenge is to identify and leverage them for maximum benefit.

It’s one thing for coaching staff to see the need for a new quarterback or pitcher. Selecting and onboarding this talent is a whole new ballgame. Various questions have to be answered before moving forward: 

For professional baseball players who get paid millions to swing a bat, going through a slump is daunting. The mere thought of a slump conjures up frustration, anxiety and humiliation, and in extreme cases, the possibility of job loss.

On June 16th the FASB issued the final standard for credit losses. We’ve analyzed the new standard and pulled together some key items you’ll need to know:

When last we blogged about the Financial Accounting Standards Board’s (FASB) new “current expected credit losses” (CECL) model for estimating an allowance for loan and lease losses (ALLL), we reviewed the process for developing reasonable and supportable forecasts for use in establishing the ALLL. 

Recently, federal banking regulators released an interagency financial institution letter on CECL, in the form of a Q&A. Read it here

By now, pretty much everyone in the banking industry has heard plenty of talk about CECL – the forthcoming “Current Expected Credit Loss” model of accounting for an institution’s allowance for loan losses (ALL).

Financial fraud by the numbers. In a June 2016 Gallup poll, 72 percent of respondents said they had “very little” or only “some” confidence in banks.

By now you have heard that the Financial Accounting Standards Board’s (FASB) answer to the criticism the incurred-loss model for accounting for the allowance for loan and lease losses faced during the financial crisis has been released in its final form. 

Why it can happen to you and how to protect yourself. We’ve all seen the headlines. Stories about not-for-profit fraud have been popping up in the news, and the statistics confirm what you might have suspected: fraud in the not-for-profit sector is on the rise.

Who this applies to: Broker-dealers and their audit committees/boards. 

The Public Company Accounting Oversight Board (PCAOB) recently released its 2025 Annual Report on the Interim Inspection Program Related to Audits of Brokers and Dealers, providing insight into the quality of broker-dealer audits and attestation engagements performed by PCAOB-registered firms. 

While the PCAOB reported improved inspection results in 2025, many of the deficiencies occurred in areas that remain a focus for SEC, FINRA, and PCAOB oversight. Broker-dealers should view the report as a roadmap to the areas most likely to attract regulatory scrutiny.

Inspection results continue to improve

The PCAOB inspected 61 firms and reviewed 103 broker-dealer audits during 2025. In its review, the PCAOB focused on areas involving heightened risk to investors and the protection of customer assets. Overall, inspection results improved across examination engagements, review engagements, and financial statement audits. 

The PCAOB found the following:

  • Deficiencies in examination engagements (broker-dealers filing compliance reports) decreased to 40%, compared to 59% in 2024. 
  • Deficiencies in review engagements (broker-dealers filing exemption reports) were 41%, generally consistent with the prior year. 
  • Deficiencies related to sufficient or appropriate evidence in financial statement audits declined to 56%, compared to 66% in 2024.

While inspection results improved, deficiencies remain common across broker-dealer audits and attestation engagements. 

Revenue remains the leading source of audit deficiencies 

Revenue testing was once again the area with the highest number of deficiencies. The PCAOB identified revenue-related deficiencies in 38 of 102 audits in which revenue was reviewed (37%).  

Common issues included: 

  • Insufficient testing of commission, underwriting fee, and advisory fee calculations 
  • Inadequate procedures to support revenue recognition under ASC 606, including the evaluation of performance obligations and related disclosures 
  • Overreliance on information provided by broker-dealers or service organizations without sufficient testing 

Revenue is often one of a broker-dealer's most significant accounts and frequently involves management judgment and complex accounting considerations. Deficiencies in this area can result in audit adjustments, disclosure issues, and increased scrutiny from regulators, and they can potentially delay the completion of financial statement audits. Broker-dealers should ensure revenue streams are well documented and supported by controls that demonstrate compliance with ASC 606 and other applicable reporting requirements.

Continued scrutiny of customer protection and compliance requirements 

For broker-dealers that hold customer assets or are subject to customer protection requirements, the PCAOB again identified deficiencies related to compliance examinations. Many of these findings involved insufficient testing of controls over compliance with SEC financial responsibility rules.  

Key observations included:

  • Insufficient testing of controls related to customer reserve calculations and possession or control requirements under the Customer Protection Rule 
  • Failure to adequately evaluate important controls governing customer assets, including management review controls and controls over information used in regulatory calculations 
  • Deficiencies in testing information produced by service organizations and information technology controls 

For broker-dealers subject to SEC Rule 15c3-3 or other financial responsibility requirements, weaknesses in compliance controls can lead to regulatory findings, increased examination activity, and questions about the safeguarding of customer assets. Strong documentation and effective controls are essential not only for audit purposes but also for demonstrating ongoing regulatory compliance. 

Evaluating audit results remains a challenge 

The PCAOB observed an increase in deficiencies related to auditors' evaluation of financial statement presentation and disclosures. Deficiencies in this area were identified in 27 audits (26%), up from 16% in the prior year.  

Examples included failures to identify:

  • Incomplete or inaccurate disclosures related to revenue recognition under ASC 606, including required information about performance obligations 
  • Financial statement presentation and disclosure issues involving cash flows, fair value measurements, and income taxes 
  • Omitted or incomplete disclosures associated with related-party transactions, segment reporting, fair value measurements, and other required GAAP disclosures 

These findings highlight the importance of not only accurate accounting but also thorough disclosure reviews during the financial reporting process. 

Related-party relationships and transactions remain a regulatory focus 

The PCAOB continues to identify deficiencies associated with auditors' evaluation of related-party relationships and transactions. In 2025, deficiencies were identified in five of the 30 audits in which related-party relationships and transactions were reviewed (17%), compared to 36% in 2024. While this represents improvement from prior years, related-party arrangements remain an area of heightened scrutiny due to the unique business structures commonly found within broker-dealer organizations. 

Common findings included: 

  • Insufficient testing of revenue and expense allocations between broker-dealers and affiliated entities 
  • Failure to verify the accuracy and completeness of data used in allocating revenues and expenses between broker-dealers and their affiliates 
  • Inadequate evaluation of whether allocations were consistent with written intercompany agreements 
  • Omitted or incomplete related-party disclosures required under ASC 850 
  • Insufficient communication of related-party matters to those charged with governance

Broker-dealers frequently operate within networks of affiliated entities and may share personnel, facilities, technology platforms, and operating costs across those entities. As a result, expense-sharing arrangements, management fee allocations, clearing relationships, and other affiliated transactions often attract audit and regulatory attention. Management should periodically review related-party agreements, ensure allocation methodologies are consistently applied and supported, and confirm that all required disclosures are complete and accurate.

Fraud-related procedures continue to attract attention 

The PCAOB also identified recurring issues related to journal entry testing and fraud risk considerations.  

Common findings included: 

  • Failure to select journal entries with fraud-related characteristics 
  • Incomplete journal entry populations 
  • Insufficient testing of supporting documentation 
  • Lack of rationale for excluding journal entries from testing 

Broker-dealers should view these findings as a reminder that fraud risk assessment extends beyond the audit process. Strong internal controls, management oversight, and monitoring activities can help identify unusual transactions before they become regulatory or financial reporting issues. Because fraud-related procedures remain a core PCAOB focus, weaknesses in these areas may attract increased attention during both audits and inspections.

Turning inspection findings into action 

The PCAOB's report is more than a summary of audit deficiencies. It provides broker-dealers and those charged with governance with valuable insight into the financial reporting, compliance, and control areas receiving the greatest regulatory attention. By understanding these common inspection findings, management can strengthen controls, improve documentation, enhance disclosures, and better position the organization for audits, examinations, and ongoing regulatory oversight.  

For broker-dealers, the strongest response to the PCAOB's inspection findings is a proactive one: 

  • Identify gaps before the audit begins. 
  • Strengthen controls before regulators identify deficiencies. 
  • Maintain a year-round focus on financial reporting and compliance risks. 

Key takeaways

  • Monitor PCAOB inspection findings to understand which broker-dealer audit and attestation areas are most likely to receive regulatory scrutiny. 
  • Strengthen documentation, controls, and disclosures around revenue recognition, customer protection, related-party transactions, and fraud procedures. 
  • Review audit readiness throughout the year so financial reporting and compliance issues can be addressed before audits, examinations, or inspections.

About BerryDunn

Our financial services team understands the complex regulatory environment that broker-dealers operate in and provides practical solutions to help you stay ahead of requirements. From broker-dealer financial statement audits to tax preparation, compliance, and consulting services, we tailor our services to meet your unique needs. Learn more about our team and services. 

Article
PCAOB 2025 inspection report: Broker-dealer & audit committee insights

Who this applies to: Those responsible for price transparency reporting, revenue cycle/registration, or contracting at an Inpatient Prospective Payment System (IPPS) hospital or in a reimbursement department at a healthcare facility. 

The Centers for Medicare and Medicaid Services (CMS) introduced Worksheet S-12 to Form CMS-2552-10, adding a new reporting requirement for certain IPPS hospitals. Effective for cost reporting periods ending on or after January 1, 2026, applicable hospitals must report the weighted median Medicare Advantage Organization (MAO) payer-specific negotiated charge by Medicare Severity Diagnosis Related Group (MS-DRG) for inpatient discharges during the cost reporting period.

What Worksheet S-12 measures and why it matters 

Although the worksheet refers to negotiated “charges,” the reported amount is better understood as the negotiated payment rate or estimated payment amount associated with a Medicare Advantage contract for a specific MS-DRG. These amounts generally do not tie directly to the actual payment received on each individual claim. Instead, the worksheet is intended to capture a standardized, discharge-weighted median negotiated amount for each applicable MS-DRG. 

CMS created Worksheet S-12 to collect MS-DRG-specific payment data for use in developing a market-based MS-DRG relative weight methodology beginning in FY 2029. Because CMS has stated that they may refine this methodology through future rulemaking before implementation, hospitals should monitor future rules and related guidance for updates.

Who must complete Worksheet S-12? 

Worksheet S-12 applies to subsection (d) hospitals, including applicable IPPS hospitals and subsection (d) Puerto Rico hospitals. The requirement does not apply to Critical Access Hospitals, inpatient psychiatric hospitals, inpatient rehabilitation hospitals, children’s hospitals, and cancer hospitals. CMS instructions also identify other limited exemptions, such as hospitals that do not negotiate payment rates and only receive non-negotiated payments, as well as hospitals paid under the Maryland Total Cost of Care Model during the model’s performance period.  

Hospitals should carefully evaluate whether they are subject to the requirement before preparing the cost report. Failure to complete the worksheet may result in the cost report being rejected, making early assessment and data preparation important. 

Core data needed to complete Worksheet S-12 

  • The hospital’s most recent Hospital Price Transparency Machine-Readable File (MRF) as of the hospital’s cost report filing date, which should include MAO payer-specific negotiated charges 
  • Detailed inpatient discharge data from the hospital’s Electronic Medical Record (EMR) or patient accounting system, organized by payer, plan, and MS-DRG 
  • Identification of capitated and non-capitated Medicare Advantage plans, because capitated arrangements are excluded from the weighted median calculation but may still be needed for reconciliation and audit support 
  • MS-DRG grouping or mapping information, particularly when negotiated charges are not identified directly at the MS-DRG level and must be cross-walked from another classification system 

Why the MFRs matters 

The Hospital Price Transparency MRF is central to Worksheet S-12 because it is the source for the MAO payer-specific negotiated charges. Hospitals should confirm that their file is available, complete, and formatted in a way that allows negotiated charges to be matched to MAO plans and MS-DRGs. If the file is incomplete or difficult to use, the hospital may face significant challenges preparing the worksheet accurately and timely.

Building the discharge detail file 

The discharge detail file should be developed from the hospital’s EMR or patient accounting system and should include one line per inpatient discharge. The file should be based on discharge dates within the hospital’s fiscal year and should include inpatient bill types, such as 11x claims, while allowing the hospital to identify transfers, denied claims, outpatient accounts, and claims pending appeal. 

  • Account number or other unique discharge identifier 
  • Discharge date 
  • Discharge disposition or other indicator used to distinguish true discharges from transfers 
  • Financial class 
  • Payer plan name 
  • Payer plan code 
  • MS-DRG 
  • Capitation indicator 
  • Claim status, including indicators for denied claims, outpatient claims, and claims pending appeal 

A clean discharge detail file is essential because the weighted median calculation depends on matching each applicable Medicare Advantage discharge to the correct negotiated charge. Each discharge should appear on a single line so that the data can be sorted, filtered, reconciled, and matched consistently.

How to calculate the weighted median negotiated charge 

To calculate the weighted median Medicare Advantage payer-specific negotiated charge, the hospital should first isolate inpatient discharges associated with Medicare Advantage plans. The negotiated charge from the MFR should then be matched to each discharge based on the MAO payer and the applicable MS-DRG. If a discharge or negotiated charge is not already identified at the MS-DRG level, the hospital must perform an appropriate crosswalk or grouping process. 

  1. Assign each Medicare Advantage inpatient discharge a payer-specific negotiated charge using the MAO plan and coded MS-DRG. 
  2. If the discharge is not coded to an MS-DRG, map the applicable classification, such as an APR-DRG, to the appropriate MS-DRG for matching. 
  3. Exclude capitated discharges and other accounts that should not be included in the calculation, while retaining them as needed for reconciliation and a solid audit trail. 
  4. Sort the remaining records by MS-DRG and negotiated charge from lowest to highest. 
  5. For each MS-DRG, identify the median negotiated charge. If the number of discharges is odd, use the middle value. If the number of discharges is even, average the two middle values. 
  6. Enter the resulting median negotiated charge on Worksheet S-12 only for MS-DRGs that had applicable discharges during the fiscal year. 

How to prepare for Worksheet S-12 

Hospitals should begin preparing for Worksheet S-12 well before the cost report filing deadline.  

Key steps to take now:  

  1. Validate the hospital’s MRF. 
  2. Confirm Medicare Advantage payer mappings. 
  3. Develop a discharge-level data extract. 
  4. Identify capitated arrangements. 
  5. Test the median calculation process. 

Early preparation can help reduce filing risk, support reconciliation, and avoid last-minute issues with cost report software edits. 

Because Worksheet S-12 connects Hospital Price Transparency data, Medicare Advantage contracting information, and Medicare cost report reporting, the preparation process will likely require coordination among reimbursement, finance, revenue cycle, contracting, and information technology teams.

Key takeaways

  • Determine whether your hospital is required to complete Worksheet S-12 before beginning Medicare cost report preparation. 
  • Validate the hospital’s MRF to confirm Medicare Advantage negotiated charge data is complete and usable. 
  • Build a discharge-level data file that connects Medicare Advantage inpatient discharges to payer plans and MS-DRGs. 
  • Exclude capitated arrangements and other non-applicable accounts from the weighted median calculation while retaining support for reconciliation. 
  • Coordinate across reimbursement, finance, revenue cycle, contracting, and IT teams to reduce filing risk and support timely reporting.

About BerryDunn

BerryDunn’s healthcare reimbursement team can help hospitals prepare for Worksheet S-12 by evaluating applicability, reviewing MRF readiness, developing discharge-level data extracts, mapping Medicare Advantage plans and MS-DRGs, and creating a defensible approach to the weighted median calculation. If your organization has questions about this new Medicare cost report requirement or needs support preparing for implementation, we can help. Learn more about our team and services.

Article
CMS cost reporting Worksheet S-12: What hospitals need to know

Who this article applies to: Compliance officers, revenue integrity directors, clinical documentation improvement specialists, clinical documentation and coding auditors, and healthcare providers at healthcare facilities or medical practices. 

It may feel at times like CPT® (Current Procedural Terminology) coding never changes—until it does. The American Medical Association (AMA) annually updates the CPT code set, with main revisions becoming effective January 1, 2027. These changes often require organizations to rethink documentation, coding, workflows, education, and auditing. CPT coding updates may be sporadic and unique, but early organizational preparation can minimize disruptions.

The impacts of CPT code changes may reverberate well beyond the coding department. Significant CPT revisions can affect the productivity, coding accuracy, denial rates, reimbursement patterns, compliance monitoring, Electronic Health Record (EHR) builds, payer contract assumptions, and audit findings of coding and revenue cycle teams. Even seemingly straightforward code changes can trigger extensive downstream impacts if documentation expectations, charge capture workflows, and system configurations are misaligned. Organizations should therefore approach major CPT updates as cross-functional operational changes, rather than as isolated coding updates, and prepare early. 

One CPT change, organization-wide impact 

The upcoming 2027 obstetric coding changes provide an excellent example of the broad impact code changes can have across an organization. Beginning January 1, 2027, maternity care reporting will undergo one of its most significant changes in decades, bringing an end to the long-used global obstetric package model. The resulting increase in Evaluation and Management (E/M) service reporting will require complete and accurate documentation to support code selection.

This shift to increased E/M coding for obstetric services reinforces an important lesson that is applicable to other service lines. Major CPT revisions, such as for obstetrics, rarely involve code changes alone. In the obstetrical example, use of increased E/M coding will require documentation improvements and EHR template revision, workflow redesign, provider education, and ongoing auditing to ensure compliance with the resulting changes.

Preparation will be especially important for these code sets because many patients receiving antepartum services in 2026 may continue their maternity care into 2027, when the new reporting structure takes effect. Organizations will need to consider how visits, documentation, charge capture, payer requirements, and patient encounters that cross the implementation date will be managed. Without proactive planning, organizations put themselves at increased risk for a cascade of events beginning with incomplete documentation and inconsistent coding, leading to potential delayed claims, payer denials, and confusion among providers and revenue cycle teams. Developing clear guidance before the updated code implementation will help ensure continuity of care, accurate reporting, and a smoother operational transition. 

Six steps to prepare for CPT changes

  1. Start planning early. Identify affected specialties, workflows, payer policies, and EHR implications to allow time for meaningful education and implementation of changes. 
  2. Engage multiple departments. Build a multidisciplinary workgroup that includes coding, compliance, revenue cycle, clinical leaders, operational leaders, and information technology representatives. 
  3. Focus on documentation, not just codes. New codes often introduce new documentation requirements that all clinical staff, coders, providers, and auditors should be aware of. Perform documentation gap assessments to identify where provider education may be needed before the effective date. 
  4. Evaluate technology. Validate EHR templates, charge capture tools, coding edits, payer rules, reporting systems, and analytics dashboards prior to January 1. 
  5. Monitor performance after implementation. Conduct focused post-implementation audits of documentation, coding accuracy, denial trends, and reimbursement patterns to identify improvement opportunities and provide feedback. Use findings to provide timely feedback and make necessary adjustments.  
  6. Communicate consistently. Provide staff and colleagues with regular updates and clear guidance throughout the transition period. Having a clear point of contact gives everyone a reliable resource for questions throughout the transition. 

Plan now for upcoming CPT code changes 

Major CPT revisions rarely involve coding changes alone; rather, they prompt cascading operational changes. Successful implementations occur when coding, documentation, compliance, clinical operations, IT, and revenue cycle teams begin planning well before the effective date. Organizations that start now will be best positioned to maintain compliance, support accurate reimbursement, and minimize operational disruption when the next major CPT update arrives. Now is the time to begin. 

BerryDunn can help  

Our healthcare compliance team can help. We incorporate deep, hands-on knowledge with industry best practices to help your organization manage compliance and revenue integrity risks. Learn more about our healthcare compliance consulting team and services.

Article
Beyond the code: Preparing for the next major CPT® update

Who this applies to: Read this if you are a business owner who accepts credit card payments.

As credit card processing costs continue to rise, many businesses are looking for ways to recover these expenses without significantly affecting profitability. Surcharging, which allows a business to add a fee when a customer pays by credit card, is one option. Dual pricing, which gives customers a choice between a lower cash price and a higher card price, is a second option. Business owners must weigh each option carefully to determine what will best suit their needs.

Surcharging: What you need to know

Most states allow businesses to add a surcharge for credit card payments, provided they comply with card network rules and applicable disclosure requirements. However, surcharging is prohibited or significantly restricted in certain jurisdictions, including Connecticut, Massachusetts, Puerto Rico, and potentially Maine. Several other states, including California, Colorado, New York, Minnesota, New Jersey, Nevada, and Texas, have additional requirements or restrictions that businesses should review before implementing a surcharge. Because surcharge laws continue to evolve through legislation, regulation, and court decisions, businesses should confirm current state requirements before moving forward.

Regardless of state, several card network rules apply. Debit card transactions can never be surcharged. Any surcharge must not exceed the merchant’s actual cost of processing the transaction and is generally capped by the card networks. Businesses must also clearly disclose the surcharge before payment is completed and confirm that their Point-of-Sale (POS) system can properly distinguish between credit and debit card transactions. If your business operates in a state where surcharging is prohibited or heavily regulated, a dual-pricing model may be a viable alternative.

What is dual pricing? 

Dual pricing presents customers with two prices upfront: a lower cash price and a higher card price that reflects the cost of card acceptance. Unlike surcharging, no additional fee is added at checkout. Instead, both prices are disclosed before the customer makes a purchasing decision, allowing the customer to choose their preferred payment method. 

Dual pricing is generally permitted throughout the United States when implemented as a properly disclosed cash-discount program. Businesses should work with their processor and legal counsel to ensure compliance with applicable laws, card-brand rules, and disclosure requirements.

Best practices for dual pricing compliance 

  • Establish the card price as the posted price and offer a clearly labeled cash discount. 
  • Display both prices prominently on shelves, menus, websites, and other customer-facing materials before checkout. 
  • Use consistent signage at entrances, checkout areas, and on receipts. 
  • Ensure receipts clearly show the transaction amount and any applicable cash discount. 
  • Utilize POS software designed to support compliant dual-pricing programs. 
  • Train employees to explain the pricing structure consistently and accurately. 

Customers should always be able to understand the price they are paying and how their choice of payment method affects the final transaction amount.

Addressing rising credit card processing costs 

As credit card processing costs continue to rise, many businesses are looking for ways to manage these expenses without significantly impacting profitability. Both surcharging and dual pricing can help offset processing costs, but each approach comes with specific legal and operational requirements. The key to a successful program is transparency: customers should clearly understand their options and pricing before making a purchase. By working closely with your payment processor, reviewing applicable state laws, and communicating openly with customers, businesses can implement a compliant solution that balances cost recovery with a positive customer experience.

State laws change frequently. Please consult the most current laws for up-to-date information. 

Key takeaways

  • Compare surcharging and dual pricing before choosing a way to recover credit card processing costs. 
  • Review state laws, card network rules, and disclosure requirements before adding a credit card surcharge. 
  • Confirm that your point-of-sale system can distinguish between credit and debit card transactions. 
  • Disclose cash and card prices clearly before checkout so customers understand payment-related costs. 
  • Train employees to explain the pricing structure consistently and accurately. 

About BerryDunn 

BerryDunn’s outsourced accounting services are tailored to the volume of work you have. Whether you need extra help in your office during peak times or interim leadership support during periods of transition, we can help you. We offer the expertise of a fully staffed accounting department for short-term assignments or long-term engagements―so you can focus on your business. Learn more about our team and services.

Article
Surcharging vs. dual pricing: Key insights for business owners

Compliance is more than a checklist: it is the foundation of organizational success. Across Medicaid agencies, health plans, healthcare providers, and community organizations, compliance creates the structure and consistency needed to fulfill the mission, protect those served, safeguard public resources, and earn stakeholder trust.

For Medicaid agencies in particular, the importance of compliance has never been greater. As states manage increasing program complexity, evolving federal requirements, heightened program integrity expectations, and growing scrutiny from oversight entities, compliance provides a critical framework for accountability, transparency, and responsible stewardship of taxpayer dollars.

Many organizations view compliance as a regulatory requirement or cost of doing business. In reality, it provides the framework needed to operate effectively, manage risk, and achieve sustainable success. For state Medicaid agencies, this framework is especially important as they operate under continual oversight from Centers for Medicare and Medicaid Services (CMS), the Office of Inspector General (OIG), state auditors, legislatures, and other stakeholders. A strong compliance program helps agencies proactively identify risks, strengthen controls, support program integrity, and demonstrate responsible stewardship of public funds.

A football game without rules, officials, coaches, or clear expectations would quickly become chaotic. Standards, oversight, and accountability do not hinder performance; they create the structure necessary for success. To achieve their objectives, organizations need clear expectations, defined processes, and effective governance. Compliance provides that foundation.

Without it, organizations face greater risk of errors, inefficiency, fraud, waste, abuse, regulatory violations, and reputational harm. Effective compliance supports sound decision-making, promotes consistency, and creates conditions for long-term success.

Putting compliance into practice

Strong compliance programs integrate governance, risk management, communication, training, monitoring, and continuous improvement into day-to-day operations.

At its best, the compliance function is a trusted advisor helping leaders identify risks, strengthen controls, improve performance, and make informed decisions.

Organizations with mature compliance programs are often better positioned to identify risks, adapt to changes, and maintain public trust. For Medicaid agencies, effective compliance programs can also support audit readiness, strengthen oversight of contractors and providers, improve program integrity efforts, and help identify and address issues before they become findings, corrective actions, or larger program risks.

Turning compliance into action

Organizations seeking to strengthen compliance do not need to address every challenge at once. Meaningful progress begins with a few foundational steps:

  • Establish accountability. Clearly define compliance responsibilities and ensure leaders and employees understand their role in managing risk and supporting organizational objectives.
  • Document expectations. Establish written policies and procedures that provide consistent guidance, support decision-making, and promote operational consistency.
  • Foster a culture of compliance. Encourage employees to ask questions, report concerns, and view compliance as a shared responsibility.
  • Evaluate and improve. Regularly assess risks, monitor performance, and use lessons learned to strengthen processes, controls, and outcomes.

Compliance is about trust

Compliance builds confidence that public funds are used appropriately, services are delivered responsibly, and decisions are made with integrity and transparency. For Medicaid agencies, that confidence extends to beneficiaries, providers, taxpayers, legislators, federal partners, and oversight entities that rely on the agency to be responsible stewards of public resources.

That trust depends on leadership commitment and ongoing investment in oversight, training, communication, monitoring, and continuous improvement. Compliance cannot reside within a single department. It must be embedded throughout an organization.

As organizations navigate increasingly complex regulatory, operational, and financial environments, leaders should periodically step back and ask:

  • Are our compliance activities aligned with our mission and strategic goals?
  • Do we have the people, resources, expertise, and infrastructure needed to manage risk effectively?
  • Are compliance considerations integrated into decision-making across the organization?
  • Does our culture promote accountability, transparency, and continuous improvement?

The answers may reveal vulnerabilities that threaten mission success, as well as opportunities to improve outcomes, strengthen resilience, and better position the organization for the future.

The question for leaders is not whether an organization is compliant today, but whether it has the governance, oversight, and the culture necessary to remain successful tomorrow. When embedded in strategy and operations, compliance becomes a driver of organizational excellence. It transforms mission into action, principles into practice, and strategy into measurable results. Beyond the checklist, compliance enables organizations to lead with integrity, manage uncertainty with confidence, and achieve sustainable success.

The questions posed in this article are intended to start a broader conversation about how compliance supports organizational performance. Future articles will explore practical strategies for strengthening governance, managing risk, developing effective written policies and procedures, and fostering a culture of integrity and accountability. Together, these elements can help organizations move beyond compliance as an obligation and leverage it as a strategic advantage.

Key takeaways

  • Recognize compliance as the foundation for organizational success, not just a regulatory requirement or cost of doing business.
  • Use compliance to create the structure, consistency, and accountability needed to fulfill the mission and safeguard public resources.
  • Integrate governance, risk management, communication, training, monitoring, and continuous improvement into day-to-day operations.
  • Strengthen controls, audit readiness, contractor and provider oversight, and program integrity efforts before issues become findings or corrective actions.
  • Evaluate whether compliance activities are aligned with mission, strategic goals, decision-making, and the culture needed for long-term success.

BerryDunn’s Medicaid Practice Group helps Medicaid agencies improve the health and lives of individuals by empowering, inspiring, and partnering with our clients—we innovate, share deep expertise, and provide an independent perspective to resolve challenges. We are the success partner for Medicaid agencies, building healthier communities and stronger futures. Learn more about our team and services.

Article
Why compliance drives success at Medicaid agencies: Beyond the checklist