An ABA documentation audit checklist should test a client episode across four domains: clinical quality, compliance, authorization support, and billing support. Review the governing rule, trace evidence from assessment through claim, assign severity and ownership, preserve correction history, and report stated denominators. A signed note can still reveal an authorization or claim-support problem, so each domain needs its own result.

Score four questions separately

One record set can pass one domain and fail another. Give every applicable domain its own pass, fail, not applicable, or unable to determine result.

DomainQuestion the auditor answersQualified decision ownerClinical qualityDoes the record show individualized assessment, a coherent plan, objective measurement, response to care, and reasoned clinical decisions?BCBA quality leader or another clinician qualified for the reviewed serviceComplianceDo the author, consent, supervision, signature, correction, confidentiality, retention, and role details satisfy the applicable authorities and policies?Compliance or privacy lead with clinical and legal input when neededAuthorizationDo the approved client, dates, services, provider types, settings, units, conditions, and continued-care evidence align with delivery?Authorization owner with clinician review of clinical criteriaBilling supportDoes the contemporaneous record support the service, provider, date, location, time or units, participants, and claim submitted?RCM or coding reviewer with a clinician for medical-necessity questions

The BACB Ethics Code for Behavior Analysts addresses accurate service reporting and billing, documentation protection, informed consent, data-based decisions, professional activity records, and supervision records. Its duties apply to covered certificants. Organizational, payer, state, and licensure rules may add different obligations. The BACB ethics resource page advises readers to check current versions and applicable state regulation.

Build the rule library before choosing records

An auditor needs a criterion and a source. For every payer, product, state, service, provider type, and setting in scope, record the source URL or document, section, version, effective dates, exact population, audit criterion, interpretation owner, and next review date. Archive the version that governed the audited date of service.

The CASP session-note project says its templates are independent of individual payer and state requirements. CASP also states that templates require training, monitoring, and internal auditing and cannot guarantee an audit result. Use CASP's public documentation resource list to locate source material. This checklist is independently written and does not reproduce CASP templates or licensed code descriptions.

Named programs show why local mapping matters. The current Texas Medicaid Provider Procedures Manual ABA chapter lists program-specific assessment, treatment-note, caregiver-work, signature, attendance, and recertification documentation. Those Texas Medicaid provisions do not set requirements for another state or commercial plan.

For authorization controls, the CMS Prior Authorization API FAQ says an impacted payer's response must convey approval and duration, denial and reason, or a request for more information. Its timing and reporting provisions cover the payer categories named by the rule. They do not create one nationwide ABA authorization checklist.

The SBA business guide can support broad operating planning. It supplies no ABA clinical or documentation criteria. Keep general business sources outside the audit rule hierarchy.

Select an auditable sample

Define the eligible universe first: service dates, locations, payers, clinicians, service types, and claim statuses. Then draw two samples and report them separately.

  1. Random core sample: Select episodes from the full eligible universe with a reproducible random method. Use this sample for practice-level rates.
  2. Stratified coverage: Ensure the core represents material payer products, services, roles, locations, new staff, and high-volume teams. State any oversampling and weighting.
  3. Targeted sample: Add records triggered by denials, late signatures, overlapping time, unusual units, copy-forward patterns, complaints, authorization gaps, or prior findings. Use this sample to investigate risk, not to estimate the practice-wide defect rate.
  4. Longitudinal episode: Review the assessment, treatment plan, consent, delivered-service records, raw or summarized data, supervision, caregiver work, reassessment, authorization, schedule, and claim for the same client and period. An isolated note cannot establish cross-record consistency.
  5. Reaudit sample: After remediation, select new eligible episodes exposed to the changed control. A corrected old record tests correction completion; a new record tests whether recurrence fell.

Record the random seed or selection method, universe count, inclusion and exclusion rules, sample date, replacements, missing records, and every denominator. Choose sample size with compliance, finance, and statistical advice based on risk and the decision being made. The HHS Office of Inspector General General Compliance Program Guidance describes risk assessment, auditing, monitoring, data analytics, clinical review of medical necessity in claims audits, and short-term monitoring of remediation. OIG labels this guidance voluntary and nonbinding.

Capture evidence instead of impressions

Use one row per criterion per episode. Keep the audit file within the practice's privacy and access controls.

Audit fieldWhat to recordScopeAudit ID, period, location, payer and product, state, service, provider role, and selection stratumRecord keyMinimum client identifier needed for follow-up, date of service, document type, version, and claim or authorization referenceRuleCriterion ID, source, section, version, effective dates, and whether it is clinical, compliance, authorization, or billingTest and evidenceExact question, result, evidence location, observed fact, and reviewer rationale without unnecessary protected informationFindingSeverity, root-cause status, potential scope, related claims or clients, and immediate safeguardActionAccountable owner, due date, approved correction route, training or control change, and escalation pathClosureVerification method, verifier, completion date, new-record reaudit result, and remaining risk

Use unable to determine when evidence is missing or inaccessible. Record why and route the missing-evidence issue. Use not applicable only when a documented rule excludes that criterion from the episode.

Reusable ABA documentation audit checklist

Assessment and treatment plan

  • [ ] Client, author, credentials, assessment dates, version, signatures, consent, and applicable referral or diagnostic inputs are identifiable.
  • [ ] Information sources, direct assessment or observation, baseline data, strengths, needs, preferences, context, and material risks are documented as applicable.
  • [ ] Goals are individualized, observable, measurable, socially meaningful, and linked to assessed need.
  • [ ] Each goal states a measurement method, baseline or starting status, clinical rationale, and decision or review rule.
  • [ ] Procedures, responsible roles, service setting, recommended frequency and duration, caregiver involvement, supervision, safety planning, and coordination are clear when applicable.
  • [ ] Mastery, maintenance, generalization, reassessment, transition, and discharge criteria are addressed at the level required by the governing rule.
  • [ ] The current plan matches what staff implement, what the family understands, and what the authorization supports.

Session notes and service data

  • [ ] Client, date, setting, start and stop or duration, provider, credentials, participants, and service are present when required.
  • [ ] The note identifies plan targets, procedures delivered, objective data or a traceable data source, client response, barriers, material events, and next clinical action.
  • [ ] Time, activities, observations, and data form a coherent account of the service without impossible overlaps.
  • [ ] Entries are specific to the encounter. Copy-forward content has been verified and updated.
  • [ ] Incidents, safety concerns, plan deviations, missed data, or caregiver communications follow the applicable escalation process.

Supervision and caregiver work

  • [ ] Supervision records identify supervisor, supervisee, client or case context, date, duration, modality, observation, content, feedback, and follow-up.
  • [ ] Role qualifications, delegation, supervision structure, performance monitoring, and improvement plans align with current BACB, licensure, payer, and employer requirements.
  • [ ] Caregiver-service records identify the participating caregiver, plan goal, teaching or coaching activity, caregiver response or performance, barriers, data when required, and next step.
  • [ ] The clinical record distinguishes caregiver work, staff supervision, protocol modification, and direct treatment according to the governing service definitions.

Progress reports, reassessments, and authorization

  • [ ] Progress is compared with baseline and prior periods using the defined measurement method.
  • [ ] The clinician explains progress, limited progress, variability, barriers, risks, and clinical changes with supporting data.
  • [ ] Reassessment and continued-care records address current need, goal status, service recommendation, caregiver input, coordination, and transition planning as applicable.
  • [ ] The authorization file has the submitted packet, submission and receipt evidence, requests for information, decision notice, effective dates, approved services, provider types, settings, units, conditions, and appeal history.
  • [ ] Scheduling and utilization controls prevent service outside the applicable authorization limits and surface approaching reassessment or renewal dates.

Signatures, corrections, consistency, and claim support

  • [ ] Each document has the required author, credentials, authentication, date, and co-signature or review.
  • [ ] Late entries, addenda, and corrections identify the change, author, date, reason, and original content under the applicable rule.
  • [ ] Client, provider, date, location, participants, service, time, units, and plan targets agree across schedule, note, data, authorization, and claim.
  • [ ] The billed service is supported by the documented work, rendering role, authorization, and applicable payment rule.
  • [ ] Duplicate claims, overlapping services, impossible travel or time, missing records, and unit conversions have been resolved or escalated.

The BACB Code calls for data collection that supports decisions and continual evaluation of interventions. It also addresses supervision documentation and performance monitoring. These checks therefore require clinical judgment, rather than a search for completed fields alone.

Grade severity and route the finding

The following severity model is an internal starting point. Compliance and counsel should adapt triggers and response times to the practice's obligations.

LevelExample triggerImmediate routeCriticalCredible client-safety threat, suspected fabrication, impermissible disclosure, service by an ineligible person, or a potentially systemic payment-integrity issuePreserve evidence, protect the client, restrict affected record changes, and notify clinical and compliance leadership immediately. Involve privacy, RCM, counsel, payer, regulator, or law enforcement when the governing process requires it.HighMaterial authorization mismatch, unsupported billed service, absent required plan or signature, major assessment or supervision gap, or a repeated defect across staffHold affected claim or scheduling activity when appropriate, assign clinical and compliance owners, test scope, and set a prompt decision date. Preserve care continuity and safety.ModerateA material clarity or process gap with limited current impact and a permitted correction pathRoute to the responsible author or process owner, correct under policy, coach, and include in focused reaudit.LowFormatting, indexing, or minor clarity issue with no identified clinical, authorization, compliance, or payment effectCorrect through ordinary quality workflow and trend if repeated.

Avoid labeling an error as misconduct before investigation. The OIG guidance calls for a documented investigation, evidence preservation, appropriate expertise, root-cause analysis, corrective action, and escalation based on the facts. Assign one accountable owner: the BCBA quality lead for clinical decisions, compliance or privacy for regulatory issues, authorization operations for approval controls, RCM for claim action, credentialing for role status, and counsel for legal interpretation.

Keep corrections inside defined boundaries

The auditor identifies evidence and routes action. The auditor should not rewrite another clinician's account or create evidence that did not exist.

  • The original author or authorized responsible professional makes a correction when the governing rule permits it.
  • The record preserves original content, the change, identity, date, and reason. Approved policy should prohibit backdating and silent overwriting.
  • A correction reflects information known or work performed. It cannot manufacture attendance, time, data, supervision, consent, or clinical reasoning.
  • The organization preserves relevant records when an investigation, request, appeal, audit, or legal hold applies.
  • RCM decides whether to hold, correct, void, refund, disclose, or appeal a claim with compliance and counsel as needed.
  • Clinical leadership protects safe continuity when an authorization or documentation issue affects scheduling.
  • Closure requires verification by someone other than the person who completed the corrective action when risk warrants separation.

CMS's July 2025 Medicare signature fact sheet addresses signed and dated Medicare documentation, author authentication of transcribed entries, and Medicare attestation limits. A separate Medicare Program Integrity Manual transmittal says Medicare review submissions with corrections should identify the correction, date and author while retaining original content. These are Medicare examples of record integrity. Apply a payer's own current correction and signature rules to its ABA records.

Calibrate reviewers and code root causes

Before production auditing, have reviewers independently score a small, deidentified calibration set. Compare item-level agreement, adjudicate differences with a qualified owner, update criterion instructions, and repeat until the team reaches its documented threshold. Recalibrate after a rule, template, system, or service change and when one reviewer becomes an outlier.

Code the verified root cause. Categories include:

  • Knowledge or training.
  • Unclear policy or rule mapping.
  • Workflow, handoff, or ownership.
  • System configuration or access.
  • Staffing capacity, workload, or timing.
  • Upstream data or integration.
  • Authorization, credentialing, or payer setup.
  • Template, copy-forward, or automation design.
  • Supervision or quality-control weakness.
  • Suspected deliberate conduct, pending formal investigation.

Match action to cause. Training may address a knowledge gap. A missing system stop calls for configuration and testing. A recurring handoff failure needs ownership and workflow redesign. Preserve a separate investigation route for suspected misconduct.

Report rates with their denominators

MetricFormulaDomain pass rateEpisodes passing every applicable criterion in the domain / episodes with at least one applicable domain criterionApplicable-item pass ratePassed criteria / (passed criteria + failed criteria)Critical episode rateEpisodes with one or more critical findings / episodes auditedAuthorization consistency rateAuthorized encounters matching all tested approval fields / authorized encounters auditedClaim-support rateClaims supported on every applicable tested element / claims auditedTimely completion rateDocuments completed within the governing deadline / documents subject to that deadlineRecurrence rateNew reaudited episodes repeating the targeted defect / new reaudited episodes exposed to the remediated processItem-level reviewer agreementIdentical independent ratings / criteria independently rated by both reviewers

Show the counts beside the percentage, define how unable to determine is treated, and keep random and targeted samples in separate columns. Finding count per 100 episodes can exceed 100 because one episode may have several findings.

Worked synthetic audit

A fictional two-location practice defines a universe of 240 completed client episodes for one quarter. It selects 20 random episodes across payer, service, role, and location strata. It also selects five late-signature alerts as a separate targeted sample.

In the random sample, 17 of 20 episodes pass all clinical-quality criteria (85%), 18 of 20 pass compliance (90%), 16 of 18 episodes subject to authorization pass that domain (88.9%), and 17 of 20 claims pass billing support (85%). Fourteen of 20 pass every applicable domain (70%). Three episodes have at least one high finding (15%); none has a critical finding (0 of 20).

Episode R-07 has a current plan, objective data, a specific note, and a timely signature. It passes clinical quality and compliance. The service date falls one day after the recorded authorization end date, and the claim was released. It fails authorization and billing support at high severity. Authorization operations owns notice verification and schedule controls; RCM holds claim action; the BCBA confirms a safe continuity plan. The audit does not convert the clean clinical note into an authorization pass.

Three of five targeted late-signature alerts fail the applicable rule (60%). That rate describes the targeted alerts. Combining them with the random sample would overstate a practice-wide estimate. Review finds two configuration gaps and one training gap. After the signature control and training change, eight new exposed episodes are reaudited; seven pass, and one repeats the defect. Recurrence is 1 of 8, or 12.5%, with the remaining case routed for root-cause review.

The compliance owner should report scope, denominators, evidence, severity, accountable actions, due dates, closure, and recurrence to clinical governance. The OIG guidance supports risk-based audit scheduling, monitoring of remediation, and root-cause work. A practice should set its cadence from current risks, obligations, size, and prior results.

Strengthen documentation operations with Finni

Finni supports ABA practice owners as they build clinical, authorization, scheduling, documentation, and revenue-cycle operations. Bring your payer mix, states, service model, audit findings, and growth plan to the conversation.

Related resources

Sources