Delegated Credentialing: The Operator’s Guide to Passing Pre-Delegation Audits and Staying Continuously Ready
July 15, 2026
On this page
Ready to be survey-ready?
What delegated credentialing is, in one paragraph
Delegated credentialing is a formal, written contract in which a health plan (the delegator) transfers credentialing and recredentialing of practitioners to a qualified healthcare organization (the delegate), while the plan retains full accountability for oversight. The delegate must meet the same standards the plan itself is held to under NCQA Credentialing (CR) and Delegation (DE) standards, CMS Medicare Advantage rules at 42 CFR §422.204, CMS Medicaid Managed Care rules at 42 CFR §438.214, and state Medicaid and insurance department requirements. That means a pre-delegation audit before the ink dries, an annual audit every year after, monthly roster and activity reporting, and a corrective action plan (CAP) loop when findings appear.
The trade is real. A well-run delegate onboards providers faster, controls its own timelines, and stops re-submitting the same application to eight payers. In exchange, the delegate carries the documentation weight the plan used to carry, and NCQA holds the delegating organization responsible for delegated activities and requires oversight that the delegate performs to NCQA requirements.
The regulators actually in the room, and what each one wants
Compliance officers are usually managing four overlapping rulebooks at once. Here is the plain read on each.
- NCQA (CR and DE standards). The delegation agreement must be mutually agreed, dated, and specify the responsibilities of both parties, the delegated activities, reporting cadence, and remedies. Starting July 2024, NCQA Credentialing Accreditation began allowing organizations to delegate over 50% of primary source verification to delegates that are NCQA Accredited or NCQA Certified, which changed how many groups build their vendor stack.
- CMS Medicare Advantage. An MA organization must follow a documented process for initial credentialing that includes written application and verification of licensure or certification from primary sources, and must ensure compliance with the prohibition on contracting with excluded individuals. Delegation does not relieve the MA plan of that duty.
- CMS Medicaid Managed Care. 42 CFR §438.214 requires the state’s MCO contracts to include written policies and procedures for selection and retention of providers that meet the NCQA-equivalent floor.
- The Joint Commission. Hospitals and ambulatory organizations credential under Medical Staff standards (MS.06.01.03 through MS.07.01.03), which run parallel to NCQA and get evaluated during a TJC survey week even when the plan-facing side is delegated.
- HRSA. FQHCs credential and privilege under HRSA Policy Information Notice 2002-22 and Chapter 5 of the Health Center Compliance Manual, which auditors treat as its own animal.
Layer on the OIG LEIE, SAM.gov, NPDB queries, DEA verification, and state licensing boards, and it becomes obvious why compliance officers keep asking for one system of record.
The money and the math: why delegation is worth the audit weight
The financial case for delegation is not abstract. According to a Merritt Hawkins survey cited by MGMA, a one-day delay in provider onboarding can cost a medical group $10,122, and 54% of medical practices reported denials related to provider credentialing had increased in 2021, with some payers taking as much as 100 days to provide an effective date and not allowing retroactive claims. Standard commercial payer credentialing runs 90 to 120 days. A delegated arrangement collapses that window because the plan trusts the delegate’s file and loads the roster on receipt.
As MGMA put it in that same brief:
“Regardless of geographic location, onboarding new providers and completing payer credentialing can be laborious and frustrating for the medical practice team and providers themselves.”
Multiply the delay math across a growing group in Texas, Florida, or California, and delegation stops looking like a nice-to-have. It looks like the difference between a hire who bills in month two and a hire who sits on payroll for four months. That is why NCQA is now the largest accreditor of health plans and why plans routinely give automatic credit on their Accreditation Survey when they delegate credentialing activities to NCQA-Accredited organizations.
The operator playbook: surviving pre-delegation and annual audits
Here is what the compliance officer at a delegate organization should have ready before a plan’s audit team opens the file room. Auditors do not want a story. They want documents, dated, in order, tied to a written policy.
- The delegation agreement itself. Signed, dated, listing the delegated activities, the reporting cadence, the plan’s right to audit, and the remedies if findings are not cured. Delegation activities must be mutually agreed upon in a dated, binding document between the organization and delegate.
- Credentialing policies and procedures. The written program that covers PSV sources, committee composition, decision timelines, and the ongoing monitoring plan for OIG LEIE, SAM.gov, license status, and DEA.
- The credentialing committee minutes. Signed, dated, showing quorum, showing a physician or comparable practitioner leading the review, and showing that decisions were communicated to providers within 60 calendar days.
- The file sample. Plans typically pull a random sample of initial and recredentialed files. Every file needs the application, attestation, PSV outputs (NPDB, license, DEA, board certification, education), work history gaps addressed, and malpractice history reviewed.
- The monthly reporting artifact. Roster adds, terms, and status changes sent to the plan on the agreed cadence, with a reconciliation log showing the plan received it.
- The corrective action plan loop. Findings from last year’s audit, the CAP, the evidence of remediation, and the internal audit that confirmed closure.
What disqualifies a delegate on day one: no committee minutes, PSV performed by unauthorized staff, missing OIG or SAM checks, recredentialing files past the 36-month cycle, or an organization that cannot produce documented annual staff training on information integrity. This is where the single-source-of-truth question becomes urgent. If your credentialing files, roster reporting, and CAP tracking live in three spreadsheets and a shared drive, you will spend the audit hunting instead of demonstrating. We built AccrediCulture so compliance officers can run credentialing, chart audits, policy management, incident and grievance, and corrective action plans in one command center, with real-time visibility into what is due, what is missing, and what has been reported to whom.
Frequently asked questions
What is the difference between delegated credentialing and a CVO arrangement?
A CVO (Credentials Verification Organization) performs the primary source verification pieces (license, NPDB, DEA, education, board certification) and returns the file to you. A delegate takes the whole scope: PSV, committee decisions, ongoing monitoring, and roster reporting to the plan. A CVO can be a subcontractor to a delegate. NCQA certifies CVOs separately, and plans that delegate to an NCQA-Certified CVO are relieved of formal oversight review for the elements the CVO performs.
What does a pre-delegation audit from a health plan actually evaluate?
The plan’s audit team walks through your written policies against NCQA CR and DE elements, samples 8 to 30 credentialing files (initial and recredentialing), reviews committee minutes, tests your OIG/SAM/NPDB query evidence, checks your reporting template, and interviews the credentialing lead. They score you element by element. A passing score is typically 80% or better with no critical findings, though the exact threshold is spelled out in the delegation agreement.
How often must a delegate report roster changes and credentialing activity to the delegator?
Most delegation agreements require monthly reporting of roster adds, terminations, and status changes, plus a quarterly or semiannual credentialing activity summary. Some Medicare Advantage plans require weekly roster updates. Read the agreement, then build your calendar to it. Missed reports are one of the fastest ways to trigger a CAP.
What triggers revocation of a delegated credentialing agreement?
Repeated audit failures with unremediated CAPs, roster reporting gaps, discovery of an excluded provider active on the roster, a lapse in NCQA accreditation or certification, or a state Medicaid finding tied to your files. Revocation usually comes after a written CAP the delegate did not close on time, not out of nowhere.
Can behavioral health, FQHC, or MSO organizations qualify as credentialing delegates?
Yes. Behavioral health groups, FQHCs, and MSOs routinely hold delegated credentialing arrangements with commercial plans, Medicare Advantage plans, and state Medicaid MCOs, provided they meet the NCQA CR framework (or the plan’s equivalent) and can pass the pre-delegation audit. FQHCs additionally must align with HRSA PIN 2002-22, so their delegates need both frameworks in the same file.
References
- eCFR: 42 CFR §422.204 Provider selection and credentialing (Medicare Advantage)
- NCQA Credentialing Accreditation FAQs
- NCQA: A Comprehensive Guide to NCQA Credentialing Programs (2025)
- MGMA Stat: Credentialing-related denials on the rise
- CMS Medicare Managed Care Manual, Chapter 6: Relationships With Providers
- MHR: Preparing for Changes in Credentialing Delegation Agreements