<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://arizonacitizenvoice.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Kelly</id>
	<title>Corrective Action Plan AZ - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://arizonacitizenvoice.com/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Kelly"/>
	<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php/Special:Contributions/Kelly"/>
	<updated>2026-08-19T23:34:35Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=MediaWiki:Sidebar&amp;diff=1127</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=MediaWiki:Sidebar&amp;diff=1127"/>
		<updated>2026-08-17T21:00:38Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Navigation&lt;br /&gt;
** mainpage|Home&lt;br /&gt;
** The Story|The Story&lt;br /&gt;
** The Anomalies|The Anomalies&lt;br /&gt;
** Governance Analysis|Governance Analysis&lt;br /&gt;
** Concerns|Concerns&lt;br /&gt;
&lt;br /&gt;
* About&lt;br /&gt;
** About Us|About Us&lt;br /&gt;
** Author Bio|About the Author&lt;br /&gt;
** What is a CAP?|What is a CAP?&lt;br /&gt;
** About the Green Book|About the Green Book&lt;br /&gt;
** Acronyms &amp;amp; Definitions|Acronyms &amp;amp; Definitions&lt;br /&gt;
&lt;br /&gt;
* Tools&lt;br /&gt;
** recentchanges-url|Recent changes&lt;br /&gt;
** specialpages-url|Special pages&lt;br /&gt;
** demo-page|Demo page&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=About_Us&amp;diff=1126</id>
		<title>About Us</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=About_Us&amp;diff=1126"/>
		<updated>2026-08-17T20:58:11Z</updated>

		<summary type="html">&lt;p&gt;Kelly: Blanked the page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=1125</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=1125"/>
		<updated>2026-08-17T20:57:43Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Corrective Action Plan (CAP) for Arizona (AZ) Governance Gaps =&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
__FORCETOC__&lt;br /&gt;
&lt;br /&gt;
=== Purpose ===&lt;br /&gt;
The purpose of this website is to inform the Arizona citizens of governance gaps at the county level and ask for your support to resolve these weaknesses with changes to the [https://www.azleg.gov/ARStitle/ Arizona Revised Statutes (A.R.S.).]&lt;br /&gt;
&lt;br /&gt;
=== Objective ===&lt;br /&gt;
Present a bill to the Arizona Legislature that will change the A.R.S. (&#039;&#039;Arizona Law&#039;&#039;) by December 2026. Create a new statute or revise an old statute to hold Arizona counties accountable to a process that allows citizens to file complaints, which will be addressed or resolved by a Compliance Review and Corrective Action Framework. This bill promotes transparency, accountability, consistency, and continuous improvement while strengthening public confidence in local/county/state government. &lt;br /&gt;
&lt;br /&gt;
=== Vision ===&lt;br /&gt;
Arizona Counties are benchmarked by other counties in other states to understand how citizens can be utilized to improve county operations. &lt;br /&gt;
&lt;br /&gt;
=== Methodology ===&lt;br /&gt;
An outline of the steps taken and to be taken to obtain Legislative support to change the A.R.S. are as follows: &lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;[[Observations of Poor Governance]]&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;[[Comparison of Observations to a Standard]]&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;[[Identification of Deviations from the Standard]]&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;[[Develop a Case for Action from the Deviations]]&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;[[Propose a Bill for Consideration by the Arizona Legislature]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== About Me ===&lt;br /&gt;
This project was created by &#039;&#039;&#039;[[Author Bio|Jamie Weinhauer Martin]]&#039;&#039;&#039;, a retired Corrective Action Plan (CAP) professional with extensive experience investigating performance anomalies and driving systemic improvement in regulated industries. After observing recurring governance gaps in Maricopa County, Jamie applied the same disciplined CAP approach used in the private sector to public administration.&lt;br /&gt;
&lt;br /&gt;
I began this journey with somewhat of a partisan perspective. I didn&#039;t seek to change election outcomes. I wanted to know what actions Maricopa County had taken to address the numerous election-related anomalies reported in 2020, 2022, 2024 and 2025 elections. This is consistent with my CAP experience.&lt;br /&gt;
My focus shifted towards the lack of an effective method to file complaints with Maricopa County. My scope grew to all Arizona counties when my peers in other Arizona counties echoed by concerns about the less than adequate responsiveness to citizen&#039;s concerns. &lt;br /&gt;
&lt;br /&gt;
This became a bipartisan issue when I realized the tendency for counties to stonewall it citizens is widespread and most complaints do not have partisan origins. I am seeking bipartisan support for this bill for the benefit of all Arizona citizens. Citizens only have a voice if the County gives thoughtful consideration to their concerns. &lt;br /&gt;
&lt;br /&gt;
=== About Us ===&lt;br /&gt;
In November 2025, Neil Thibodaux joined my earlier efforts to determine how MC was going to prevent recurrence of these repetitive election-related anomalies. He had extensive experience with CAP, but in a different industry than my experience. Our belief in CAP united us in the pursuit of improvements. Neil also had experience with organizational effectiveness reviews, which was helpful when my emphasis shifted from addressing election-related anomalies to addressing an even bigger problem with MC governance gaps. He had been trained in using the [https://www.nri.eu.com/NRI1.pdf Management Oversight and Risk Tree] analysis process to find the organizational causes to significant events, with emphasis on preventing a recurrence of the same and similar events. &lt;br /&gt;
&lt;br /&gt;
We would like to bring other volunteers into this initiative. Please contact me [&#039;&#039;&#039;&amp;lt;big&amp;gt;Jamie needs a separate email account for CAPAZ]&amp;lt;/big&amp;gt;&#039;&#039;&#039; if you think you can help. We need to people to perform research, review content, and maintain this website. After reading this website, you may see a need we haven&#039;t even thought about. Please consider joining our team.  &lt;br /&gt;
&lt;br /&gt;
=== About CAPAZ ===&lt;br /&gt;
&#039;&#039;&#039;Corrective Action Plan Arizona&#039;&#039;&#039; (CAPAZ) is an independent citizen-base, public-interest project that applies proven CAP methodology. This is a volunteer effort. We do not receive funds from any outside entity. Please contact me [&#039;&#039;&#039;&amp;lt;big&amp;gt;Jamie needs a separate email account for CAPAZ]&amp;lt;/big&amp;gt;&#039;&#039;&#039; if you like what you see and want to join this team for positive change.&lt;br /&gt;
&lt;br /&gt;
CAP is not new to government, considering the following:&lt;br /&gt;
&lt;br /&gt;
* US Government Departments and Agencies routinely require some nongovernmental companies to implement CAP, which is then used by the government as an oversight tool&lt;br /&gt;
* US Government requires government entities to implement CAP if receiving entity receives funds in accordance with [https://www.ecfr.gov/current/title-2/subtitle-A/chapter-II/part-200/subpart-F/subject-group-ECFRc3bd6ae97de5a40/section-200.511 2 CFR 200.511 (c),] which is illustrated the [https://gao.az.gov/sites/default/files/2024-07/CAP%20guidance.pdf Arizona Government Accounting Office&#039;s CAP].&lt;br /&gt;
* US Government Accountability Office&#039;s [https://www.gao.gov/assets/gao-25-107721.pdf Standards for Internal Control in the Federal Government] has requirements for federal executive branch agencies to establish a process that management must implement to properly assess and improve internal control, which includes CAP-like attributes in [https://guides.gaoinnovations.gov/greenbook/2025/principle-17-evaluate-issues-and-remediate-deficiencies/ Principle 17 - Evaluate Issues and Remediate Deficiencies.]&lt;br /&gt;
&lt;br /&gt;
=== About You ===&lt;br /&gt;
Your voice is important. Abraham Lincoln made these remarks in this Gettysburg Address:&amp;lt;blockquote&amp;gt;&#039;&#039;&amp;quot;...that this nation, under God, shall have a new birth of freedom—and that government of the people, by the people, for the people, shall not perish from the earth.&amp;quot;&#039;&#039;&amp;lt;/blockquote&amp;gt;You may be able to help me with a case for action. I need justification to gain legislative support for a new Arizona law that will establish a process to review citizen complaints for governance gaps and implement corrective actions when appropriate. The problem becomes more significant with more examples.  How can you help? &amp;lt;blockquote&amp;gt;Send me details about a frustrating encounter with your county government. With your consent, I would use your unpleasant experience as data in support of a case for action. Your help will be needed to ensure your governance gap is a deviation from a standard. If you dive into this website, you will gain knowledge of the standards for good governance. ￼ &amp;lt;/blockquote&amp;gt;&lt;br /&gt;
You can help keep this idea in front of your Arizona Senator and Representatives. How can you help?&amp;lt;blockquote&amp;gt;&lt;br /&gt;
Following the November 2026 election, send your Senator and Representatives a message. Tell them you want to hold County government accountable to its Citizens. Ask them to support the proposed Bill.&amp;lt;/blockquote&amp;gt;The effort to get the bill approved by the Legislature and signed by the governor is being delayed until after the November 2026 election to allow you to vote for the candidates that you feel will support this effort. The delay will give us some time to draft the bill. The sense of urgency begins after the elections because the Legislature begins their annual review of Legislative initiatives in January 2027.&lt;br /&gt;
&lt;br /&gt;
=== Our Prayer ===&lt;br /&gt;
I hope you can join me in an effort to find the right words, said at the right time, to allow others to see how the proposed bill serves citizens and government. It is a desire to promote positive outcomes from a freedom to exchange ideas.&amp;lt;blockquote&amp;gt;&#039;&#039;Lord, we believe the County leaders and employees can be fair and just if guided towards a process that seeks to understand before judgments are made. We have felt injustice from County and believe others have had similar experiences.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;We are trying to be faithful to your desire for each of us to love you and love our neighbors.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;We seek a process that facilitates cooperation between the State, Counties and their citizens.&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;Please grant us the knowledge and wisdom to advance this idea with faith and humbleness. Lord, please let us choose the right words for each opportunity to share our vision with others. We pray that our goal serves you. Amen.&#039;&#039;&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Start Your Journey ==&lt;br /&gt;
Choose your path:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[The Story|📖 Read The Story]]&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[Governance Analysis|📊 Explore Governance Analysis]]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Follow the chronological narrative of events &amp;lt;br&amp;gt;that revealed governance gaps.&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Dive into structured analysis&amp;lt;br&amp;gt;using the Green Book framework.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | 🏠 &#039;&#039;&#039;Main Page&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=MediaWiki:Sidebar&amp;diff=1124</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=MediaWiki:Sidebar&amp;diff=1124"/>
		<updated>2026-08-17T20:40:19Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* navigation&lt;br /&gt;
** mainpage|Home&lt;br /&gt;
** The Story|The Story&lt;br /&gt;
** The Anomalies|The Anomalies&lt;br /&gt;
** Governance Analysis|Governance Analysis&lt;br /&gt;
** Concerns|Concerns&lt;br /&gt;
&lt;br /&gt;
* about&lt;br /&gt;
** About Us|About Us&lt;br /&gt;
** Author Bio|About the Author&lt;br /&gt;
** What is a CAP?|What is a CAP?&lt;br /&gt;
** About the Green Book|About the Green Book&lt;br /&gt;
** Acronyms &amp;amp; Definitions|Acronyms &amp;amp; Definitions&lt;br /&gt;
&lt;br /&gt;
* tools&lt;br /&gt;
** recentchanges-url|Recent changes&lt;br /&gt;
** specialpages-url|Special pages&lt;br /&gt;
** demo-page|Demo page&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=2020:_The_Event&amp;diff=1121</id>
		<title>2020: The Event</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=2020:_The_Event&amp;diff=1121"/>
		<updated>2026-08-17T20:15:16Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The November 2020 general election was the event that led me on a long&lt;br /&gt;
tortuous path of discovery. Ultimately, I concluded there is governance&lt;br /&gt;
problem within the Arizona Counties.&lt;br /&gt;
&lt;br /&gt;
Like a lot of people nationwide, I watched in amazement as Maricopa&lt;br /&gt;
County took weeks to count the ballots following the election. Then&lt;br /&gt;
there was the audit count, canvasing, allegations, and lawsuits. When&lt;br /&gt;
was it going to end?&lt;br /&gt;
&lt;br /&gt;
Regardless of your political beliefs, most people could agree that&lt;br /&gt;
Maricopa County’s Election Performance was anomalous, even if you&lt;br /&gt;
thought the outcome was fair or unfair. Most people focused on the&lt;br /&gt;
election outcome as a measure of fairness.&lt;br /&gt;
&lt;br /&gt;
Some people might consider me strange; I was more interested in the&lt;br /&gt;
anomalies than the outcome. I keep pondering about what the county was&lt;br /&gt;
going to do with those anomalies? Or, were they simply going to ignore&lt;br /&gt;
them.&lt;br /&gt;
&lt;br /&gt;
My interest in those election anomalies was influenced by my career. I&lt;br /&gt;
had retired before the 2020 general election. I worked for a large&lt;br /&gt;
company, which operated in the financial sector. My last position&lt;br /&gt;
involved Corrective Action Plans (CAP). In my role, CAP was a process&lt;br /&gt;
used to investigate financial anomalies to ensure that my company wasn’t&lt;br /&gt;
sued by a client or fined by a regulator.&lt;br /&gt;
&lt;br /&gt;
CAP became a regulatory requirement following the Sarbanes-Oxley Act of&lt;br /&gt;
2002 (SOX). The bill was enacted because of accounting scandals in major&lt;br /&gt;
publicly traded companies, including Enron, Tyco International,&lt;br /&gt;
Adelphia, Peregrine Systems, and WorldCom. These scandals cost investors&lt;br /&gt;
billions of dollars when the share prices of affected companies&lt;br /&gt;
collapsed. Lawmakers intervened to restore public confidence in the&lt;br /&gt;
stock markets.&lt;br /&gt;
&lt;br /&gt;
The SOX Act sought to ensure investors could make appropriate trading&lt;br /&gt;
decisions by improving financial reporting accuracy, establishing strict&lt;br /&gt;
internal controls, and holding corporate executives personally&lt;br /&gt;
accountable. It focused heavily on executive responsibility, auditor&lt;br /&gt;
independence, and criminal penalties to prevent fraudulent practices.&lt;br /&gt;
&lt;br /&gt;
Initially, my company did not embrace CAP when the process was rolled&lt;br /&gt;
out. For many employees, it seemed like an unnecessary burden. It was&lt;br /&gt;
just more documentation to do what they would have done anyway. The&lt;br /&gt;
culture failed to immediately recognize that this roll out was a federal&lt;br /&gt;
obligation, Under the law, a formal means to document deviations from&lt;br /&gt;
standards was necessary so the problem could be evaluated for&lt;br /&gt;
compliance, investigated for cause and corrective action plans&lt;br /&gt;
established to resolve the problem. CAP became the term used to describe&lt;br /&gt;
how problems were identified and resolved.&lt;br /&gt;
&lt;br /&gt;
Federal regulators identified poor CAP implementation problem. A fine&lt;br /&gt;
ensued, which was followed by an awakening. Federal regulators were&lt;br /&gt;
using CAP as an oversight tool to ensure financial fraud would not&lt;br /&gt;
recur. Soon thereafter, CAP was relied upon to consistently resolve&lt;br /&gt;
issues that warranted attention; CAP became a way of doing business and&lt;br /&gt;
was no longer considered an obstacle.&lt;br /&gt;
&lt;br /&gt;
I saw CAP transform a culture from “let’s just get this done” to “let’s&lt;br /&gt;
do this the right way.”&lt;br /&gt;
&lt;br /&gt;
I began to see problems differently; they became CAP opportunities. What&lt;br /&gt;
can we learn from this problem to improve performance.&lt;br /&gt;
&lt;br /&gt;
Though retired, I dwelled on these election anomalies. I wanted to&lt;br /&gt;
understand what happened.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Deviation #1: [[Principle 1 - Demonstrate Commitment to Integrity and Ethical Values#1.01|Principle #1 - 1.01]]&lt;br /&gt;
&lt;br /&gt;
== Timeline ==&lt;br /&gt;
&lt;br /&gt;
# [[Preface]] — Author&#039;s introduction&lt;br /&gt;
# [[2020: The Event]] — The November 2020 general election anomalies&lt;br /&gt;
# [[2001: The Journey Begins]] — Starting to ask questions about lessons learned&lt;br /&gt;
# [[November 2024: Midterm Election]] — The Katie Hobbs situation&lt;br /&gt;
# [[December 2024: Gaining Support]] — Resolution submission&lt;br /&gt;
# [[April 15, 2025: Public Records Request]] — Public Records Request process&lt;br /&gt;
# [[May 15, 2025: Let’s Play Hot Potato]] — Public Records Request runaround&lt;br /&gt;
# [[August 3, 2026: Submitted Complaint]] — Formal complaint submission&lt;br /&gt;
&lt;br /&gt;
== Navigation ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Main Page|🏠 Main Page]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Related Governance Principles ==&lt;br /&gt;
&lt;br /&gt;
* [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
* [[What is a CAP?|❓ What is a CAP?]]&lt;br /&gt;
* [[About the Green Book|📗 About the Green Book]]&lt;br /&gt;
* [[Author Bio|✍️ About the Author]]&lt;br /&gt;
__FORCETOC__&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_1_-_Demonstrate_Commitment_to_Integrity_and_Ethical_Values&amp;diff=420</id>
		<title>Principle 1 - Demonstrate Commitment to Integrity and Ethical Values</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_1_-_Demonstrate_Commitment_to_Integrity_and_Ethical_Values&amp;diff=420"/>
		<updated>2026-08-14T02:34:09Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Principle 1: Demonstrate Commitment to Integrity and Ethical Values ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-1-demonstrate-commitment-to-integrity-and-ethical-values/ External Link to US GAO Green Book Principle 1.]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.01&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body and management should demonstrate a commitment to integrity and ethical values.&lt;br /&gt;
&lt;br /&gt;
=== Tone at the Top ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.02&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body and management demonstrate the importance of integrity and ethical values through their directives, attitudes, and behavior.&lt;br /&gt;
 &#039;&#039;&#039;November 2024: Midterm Election&#039;&#039;&#039;&lt;br /&gt;
 &lt;br /&gt;
 Katie Hobbs managed the statewide election process as the Arizona Secretary of State while she was campaigning for Arizona Governor.&lt;br /&gt;
 &lt;br /&gt;
 Contrary to the Green Book, Katie created an ethical question by managing the statewide election process while also being a candidate in the same election she was overseeing. It’s important that we consider the objective of this Green Book Attribute. &lt;br /&gt;
 &lt;br /&gt;
 This isn’t about Katie Hobbs&#039;&#039;&#039;; this attribute is about the tone (or example) Katie is setting for the employees under her control, either directly as a state employee or indirectly as a county employees.&lt;br /&gt;
 &lt;br /&gt;
 Why is this important? There are two possible outcomes for subordinates that may encounter ethical issues (unintentionally or purposefully). Leaders that demonstrate or push the&#039;&#039;&#039; limits of unethical behaviors may encourage unethical behavior by seeing no adverse consequences for this behavior. Meanwhile, a leader’s unethical behavior may shutdown ethical employees that become unwilling to bring up ethical issues knowing that unethical behavior is tolerated.&lt;br /&gt;
 &lt;br /&gt;
 Contrary to the Green Book, Katie created an ethical question by managing the statewide election process while also being a candidate in the same election she was overseeing. It’s important that we consider the objective of this Green Book Attribute.&lt;br /&gt;
 &lt;br /&gt;
 This isn’t about Katie Hobbs; this attribute is about the tone (or example) Katie is setting for the employees under her control, either directly as a state employee or indirectly as a county employees.&lt;br /&gt;
 &lt;br /&gt;
 Why is this important? There are two possible outcomes for subordinates that may encounter ethical issues (unintentionally or purposefully). Leaders that demonstrate or push the limits of unethical behaviors may encourage unethical behavior by seeing no adverse consequences for this behavior. Meanwhile, a leader’s unethical behavior may shutdown ethical employees that become unwilling to bring up ethical issues knowing that unethical behavior is tolerated.&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.03&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body and management lead by an example that demonstrates the organization’s values, philosophy, and operating style. The oversight body and management set the tone at the top and throughout the organization by their example, which is fundamental to an effective internal control system. In larger entities, the various layers of management in the organizational structure may also set the “tone in the middle.” Although it is the oversight body and management’s responsibility to set the tone at the top, other personnel throughout the entity play an important role in supporting the tone that permeates the organizational culture.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.04&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body’s and management’s directives, attitudes, and behaviors reflect the integrity and ethical values expected throughout the entity. The oversight body and management reinforce the commitment to doing what is right, not just maintaining a minimum level of performance necessary to comply with applicable laws and regulations, so that these priorities are understood by all stakeholders, such as regulators, service organizations, employees, and the public.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.05&#039;&#039;&#039; ====&lt;br /&gt;
Tone at the top can be either a driver, as shown in the preceding paragraphs, or a barrier to internal control. Without a strong tone at the top to support an internal control system, the entity’s risk identification may be incomplete, risk responses may be inappropriate, control activities may not be appropriately designed or implemented, information and communication may falter, and results of monitoring may not be understood or acted upon to remediate deficiencies.&lt;br /&gt;
 &#039;&#039;&#039;[[May 15, 2025: Let’s Play Hot Potato]]&#039;&#039;&#039; - Contrary to the Green Book, multiple Maricopa County departments apparently believed that act of closing out of Public Records Request was culturally more important that resolving the citizen’s request.&lt;br /&gt;
 &lt;br /&gt;
 After the Procurement Department supplied four documents per the original PRR, three other PRRs were generated to transfer the (???)&lt;br /&gt;
&lt;br /&gt;
=== Standards of Conduct ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.06&#039;&#039;&#039; ====&lt;br /&gt;
Management establishes standards of conduct to communicate expectations concerning integrity and ethical values. The entity uses ethical values to balance the needs and concerns of different stakeholders, such as regulators, service organizations, employees, and the public. The standards of conduct guide the directives, attitudes, and behaviors of the organization in achieving its objectives.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.07&#039;&#039;&#039; ====&lt;br /&gt;
Management, with oversight from the oversight body, defines the organization’s expectations of ethical values in the standards of conduct. Management may consider using policies, operating principles, guidelines, or training to regularly communicate and reinforce the standards of conduct to the organization.&lt;br /&gt;
&lt;br /&gt;
=== Adherence to Standards of Conduct ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.08&#039;&#039;&#039; ====&lt;br /&gt;
Management establishes processes to evaluate performance against the entity’s expected standards of conduct and address any deviations in a timely manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.09&#039;&#039;&#039; ====&lt;br /&gt;
Management uses established standards of conduct as the basis for evaluating adherence to integrity and ethical values across the organization. Management evaluates the adherence to standards of conduct across all levels of the entity. To gain assurance that the entity’s standards of conduct are implemented effectively, management evaluates the directives, attitudes, and behaviors of individuals and teams. Evaluations may consist of ongoing monitoring or separate evaluations. Individual personnel can also report issues through reporting lines, such as regular staff meetings, upward feedback processes, a whistleblowing program, or an ethics hotline. The oversight body evaluates management’s adherence to the standards of conduct as well as the overall adherence by the entity.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.10&#039;&#039;&#039; ====&lt;br /&gt;
Management determines tolerance levels for deviations from standards of conduct. For instance, management may determine that the entity will have zero tolerance for deviations from certain expected standards of conduct, while deviations from others may be addressed with warnings to personnel. Management establishes a process for evaluations of individual and team adherence to standards of conduct that escalates and remediates deviations timely and consistently. Management, with oversight from the entity’s oversight body and with consideration of applicable laws and regulations, takes appropriate actions to remediate deviations.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_1_-_Demonstrate_Commitment_to_Integrity_and_Ethical_Values&amp;diff=419</id>
		<title>Principle 1 - Demonstrate Commitment to Integrity and Ethical Values</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_1_-_Demonstrate_Commitment_to_Integrity_and_Ethical_Values&amp;diff=419"/>
		<updated>2026-08-14T02:32:30Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Principle 1: Demonstrate Commitment to Integrity and Ethical Values ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-1-demonstrate-commitment-to-integrity-and-ethical-values/ External Link to US GAO Green Book Principle 1.]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.01&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body and management should demonstrate a commitment to integrity and ethical values.&lt;br /&gt;
&lt;br /&gt;
=== Tone at the Top ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.02&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body and management demonstrate the importance of integrity and ethical values through their directives, attitudes, and behavior.&lt;br /&gt;
 &#039;&#039;&#039;November 2024: Midterm Election&#039;&#039;&#039;&lt;br /&gt;
 &lt;br /&gt;
 Katie Hobbs managed the statewide election process as the Arizona Secretary of State while she was campaigning for Arizona Governor.&lt;br /&gt;
 &lt;br /&gt;
 Contrary to the Green Book, Katie created an ethical question by managing the statewide election process while also being a candidate in the same election she was overseeing. It’s important that we consider the objective of this Green Book Attribute. &lt;br /&gt;
 &lt;br /&gt;
 This isn’t about Katie Hobbs&#039;&#039;&#039;; this attribute is about the tone (or example) Katie is setting for the employees under her control, either directly as a state employee or indirectly as a county employees.&lt;br /&gt;
 &lt;br /&gt;
 Why is this important? There are two possible outcomes for subordinates that may encounter ethical issues (unintentionally or purposefully). Leaders that demonstrate or push the&#039;&#039;&#039; limits of unethical behaviors may encourage unethical behavior by seeing no adverse consequences for this behavior. Meanwhile, a leader’s unethical behavior may shutdown ethical employees that become unwilling to bring up ethical issues knowing that unethical behavior is tolerated.&lt;br /&gt;
&amp;lt;blockquote&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Contrary to the Green Book, Katie created an ethical question by managing the statewide election process while also being a candidate in the same election she was overseeing. It’s important that we consider the objective of this Green Book Attribute. &lt;br /&gt;
&lt;br /&gt;
This isn’t about Katie Hobbs; this attribute is about the tone (or example) Katie is setting for the employees under her control, either directly as a state employee or indirectly as a county employees.&lt;br /&gt;
&lt;br /&gt;
Why is this important? There are two possible outcomes for subordinates that may encounter ethical issues (unintentionally or purposefully). Leaders that demonstrate or push the limits of unethical behaviors may encourage unethical behavior by seeing no adverse consequences for this behavior. Meanwhile, a leader’s unethical behavior may shutdown ethical employees that become unwilling to bring up ethical issues knowing that unethical behavior is tolerated.&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.03&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body and management lead by an example that demonstrates the organization’s values, philosophy, and operating style. The oversight body and management set the tone at the top and throughout the organization by their example, which is fundamental to an effective internal control system. In larger entities, the various layers of management in the organizational structure may also set the “tone in the middle.” Although it is the oversight body and management’s responsibility to set the tone at the top, other personnel throughout the entity play an important role in supporting the tone that permeates the organizational culture.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.04&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body’s and management’s directives, attitudes, and behaviors reflect the integrity and ethical values expected throughout the entity. The oversight body and management reinforce the commitment to doing what is right, not just maintaining a minimum level of performance necessary to comply with applicable laws and regulations, so that these priorities are understood by all stakeholders, such as regulators, service organizations, employees, and the public.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.05&#039;&#039;&#039; ====&lt;br /&gt;
Tone at the top can be either a driver, as shown in the preceding paragraphs, or a barrier to internal control. Without a strong tone at the top to support an internal control system, the entity’s risk identification may be incomplete, risk responses may be inappropriate, control activities may not be appropriately designed or implemented, information and communication may falter, and results of monitoring may not be understood or acted upon to remediate deficiencies.&lt;br /&gt;
 &#039;&#039;&#039;[[May 15, 2025: Let’s Play Hot Potato]]&#039;&#039;&#039; - Contrary to the Green Book, multiple Maricopa County departments apparently believed that act of closing out of Public Records Request was culturally more important that resolving the citizen’s request.&lt;br /&gt;
 &lt;br /&gt;
 After the Procurement Department supplied four documents per the original PRR, three other PRRs were generated to transfer the (???)&lt;br /&gt;
&lt;br /&gt;
=== Standards of Conduct ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.06&#039;&#039;&#039; ====&lt;br /&gt;
Management establishes standards of conduct to communicate expectations concerning integrity and ethical values. The entity uses ethical values to balance the needs and concerns of different stakeholders, such as regulators, service organizations, employees, and the public. The standards of conduct guide the directives, attitudes, and behaviors of the organization in achieving its objectives.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.07&#039;&#039;&#039; ====&lt;br /&gt;
Management, with oversight from the oversight body, defines the organization’s expectations of ethical values in the standards of conduct. Management may consider using policies, operating principles, guidelines, or training to regularly communicate and reinforce the standards of conduct to the organization.&lt;br /&gt;
&lt;br /&gt;
=== Adherence to Standards of Conduct ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.08&#039;&#039;&#039; ====&lt;br /&gt;
Management establishes processes to evaluate performance against the entity’s expected standards of conduct and address any deviations in a timely manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.09&#039;&#039;&#039; ====&lt;br /&gt;
Management uses established standards of conduct as the basis for evaluating adherence to integrity and ethical values across the organization. Management evaluates the adherence to standards of conduct across all levels of the entity. To gain assurance that the entity’s standards of conduct are implemented effectively, management evaluates the directives, attitudes, and behaviors of individuals and teams. Evaluations may consist of ongoing monitoring or separate evaluations. Individual personnel can also report issues through reporting lines, such as regular staff meetings, upward feedback processes, a whistleblowing program, or an ethics hotline. The oversight body evaluates management’s adherence to the standards of conduct as well as the overall adherence by the entity.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.10&#039;&#039;&#039; ====&lt;br /&gt;
Management determines tolerance levels for deviations from standards of conduct. For instance, management may determine that the entity will have zero tolerance for deviations from certain expected standards of conduct, while deviations from others may be addressed with warnings to personnel. Management establishes a process for evaluations of individual and team adherence to standards of conduct that escalates and remediates deviations timely and consistently. Management, with oversight from the entity’s oversight body and with consideration of applicable laws and regulations, takes appropriate actions to remediate deviations.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Governance_Analysis&amp;diff=405</id>
		<title>Governance Analysis</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Governance_Analysis&amp;diff=405"/>
		<updated>2026-08-14T01:20:51Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Governance Analysis =&lt;br /&gt;
&lt;br /&gt;
This section provides a structured analysis of governance performance gaps using the &#039;&#039;&#039;Green Book&#039;&#039;&#039; — &#039;&#039;Standards for Internal Control in the Federal Government&#039;&#039; (May 2025) published by the United States Government Accountability Office.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related ==&lt;br /&gt;
&lt;br /&gt;
See [[The Story]] for the chronological narrative that provides context for these gaps.&lt;br /&gt;
&lt;br /&gt;
== Navigation ==&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Main Page|🏠 Main Page]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=404</id>
		<title>Principle 10 - Design Control Activities</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=404"/>
		<updated>2026-08-14T01:17:50Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 10.0 Design Control Activities ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-10-design-control-activities/ External Link to US GAO Green Book Principle 10]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should design control activities to mitigate risks to achieving the entity’s objectives to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.1 Response to Risks ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities in response to risks to achieve an effective internal control system. Control activities are the actions management establishes through policies and procedures to specifically mitigate risks to achieving the entity’s objectives to acceptable levels. Control activities support all the components of internal control but are particularly aligned with the risk assessment component. As part of periodic and ongoing risk assessments, management identifies objectives; the risks related to the entity and its objectives, including its service organizations; the entity’s risk tolerance; and risk responses. Management designs control activities or modifies existing control activities to mitigate risks to acceptable levels within management’s defined risk tolerance. Typically, control activities are needed when an entity chooses to either reduce or share a risk. The nature and extent of the risk response and any associated control activities will depend, at least in part, on management’s defined risk tolerance.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.2 Design of Appropriate Types of Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.03&#039;&#039;&#039; ====&lt;br /&gt;
Management designs appropriate types of control activities for the entity’s internal control system, including the entity’s information technology, by considering all aspects of its internal control components, relevant business processes, and operating environment. An entity’s internal control is flexible to allow management to tailor control activities to meet the entity’s unique needs. The specific control activities used by a given entity may be different from those used by others based on several factors. These factors could include specific threats the entity faces and the risks involved, differences in objectives, managerial judgment, size and complexity of the entity, operational environment, and sensitivity and value of data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.04&#039;&#039;&#039; ====&lt;br /&gt;
The common categories of control activities listed illustrate the range and variety of control activities that may be useful to management. &lt;br /&gt;
&lt;br /&gt;
The list is not all inclusive and may not include all categories of control activities that an entity may need.&lt;br /&gt;
&lt;br /&gt;
==== Common Categories of Control Activities ====&lt;br /&gt;
* Top-level reviews of actual performance&lt;br /&gt;
* Reviews by management at the functional or activity level&lt;br /&gt;
* Establishment and review of performance measures and indicators&lt;br /&gt;
* Management of human capital&lt;br /&gt;
* Control activities over information processing&lt;br /&gt;
* Physical control activities over vulnerable assets&lt;br /&gt;
* Access restrictions to and accountability for resources and records&lt;br /&gt;
* Authorization of transactions&lt;br /&gt;
* Control activities over complete, accurate, and timely recording of valid transactions&lt;br /&gt;
* Appropriate documentation of transactions and control activities&lt;br /&gt;
* Oversight of entity business processes assigned to service organizations&lt;br /&gt;
* Segregation of duties&lt;br /&gt;
* Program-related control activities&lt;br /&gt;
* Fraud-related control activities&lt;br /&gt;
* Improper-payment-related control activities&lt;br /&gt;
* Compliance-related control activities&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.3 Design of Automated and Manual Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.05&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be designed and implemented in an automated, partially automated, or a manual manner. Automated control activities may be wholly or partially performed using the entity’s information technology. Manual control activities are performed by individuals without relying on the entity’s information technology. Automated control activities tend to be more reliable because they are less susceptible to human error and are typically more efficient.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.06&#039;&#039;&#039; ====&lt;br /&gt;
Management designs information technology control activities to support the operation and security of the entity’s information technology and automated business processes. Information technology control activities consist of general, application, and user control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.07&#039;&#039;&#039; ====&lt;br /&gt;
Application and user control activities rely on the entity’s information technology. Application control activities are automated control activities that are incorporated directly into application software to achieve the completeness, accuracy, and validity of transactions and data. Application control activities include control activities over the input, processing, and output of data. User control activities, sometimes referred to as information technology-dependent controls, are partially automated control activities that are performed by individuals using the entity’s information technology or by relying on the information processed through technology. For example, management may authorize a transaction as part of an automated workflow or may respond to incidents flagged in system log reports.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.08&#039;&#039;&#039; ====&lt;br /&gt;
General control activities are designed to mitigate information security risks and are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. General control activities support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. General control activities can be designed and implemented in either an automated or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.09&#039;&#039;&#039; ====&lt;br /&gt;
Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need.[[File:10.09-fig-7.png|center|1000x1000px|thumb|&#039;&#039;&#039;Figure 7:&#039;&#039;&#039; Common Categories of Information Technology Control Activities]]&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.4&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.4 Design of Preventive and Detective Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.10&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be either preventive or detective. The main difference between preventive and detective control activities is timing, that is, when the control activity occurs within an entity’s operations. A preventive control activity is designed to avoid an unintended event or result before it occurs. A detective control activity is designed to discover and timely correct an unintended event or result after it occurs. The effectiveness of a detective control activity depends on timeliness of the corrective action to address the unintended event or result. Corrective action may address the event that occurred or may correct the deficiencies in the process that led to the event.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.11&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates the purpose of the control activity as well as the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives. Management may design both preventive and detective control activities to effectively mitigate the risks to achieving the objectives, particularly in circumstances where the risk of an unintended event or result occurring is high. Generally, the higher the risk of an unintended event or result occurring, the stronger or more robust the control activities need to be to effectively mitigate the higher risk to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.12&#039;&#039;&#039; ====&lt;br /&gt;
Management designs an appropriate mix of preventive and detective control activities to mitigate risks to an acceptable level, prioritizing preventive control activities where appropriate. When designing control activities, management first considers preventive control activities, as they generally offer the most cost-efficient use of resources and are generally effective at mitigating fraud and improper payment risks. Management next considers detective control activities and may design both preventive and detective control activities when necessary to mitigate a particular risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.13&#039;&#039;&#039; ====&lt;br /&gt;
There may be rare situations where management determines through its evaluation that a preventive control activity would better mitigate a particular risk but is unable to implement it. In these situations, management strengthens and expedites detective control activities and may also expedite monitoring activities to enable the entity to effectively mitigate the risk to acceptable levels, considering the risk related to the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.5&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.5 Design of Control Activities at Various Levels ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.14&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities at the appropriate levels in the organizational structure.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.15&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities for appropriate mitigation of risks in the entity’s business processes. Business processes transform inputs into outputs through a series of transactions or activities to achieve the entity’s objectives. Management designs entity-level control activities, business process-level control activities (commonly referred to as transaction control activities), or both depending on the level of precision needed so that the entity mitigates risks to an acceptable level related to its business processes. Entity-level and transaction control activities can be implemented in an automated, partially automated, or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.16&#039;&#039;&#039; ====&lt;br /&gt;
Entity-level control activities are controls designed to mitigate risks that have a pervasive effect on an entity’s internal control system and may pertain to multiple components. Entity-level control activities may include controls related to the entity’s risk assessment process, control environment, service organizations, management override, and performance or analytical reviews.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.17&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.17&#039;&#039;&#039; ====&lt;br /&gt;
Transaction control activities are controls that directly mitigate information processing risks in the entity’s business processes. The term transaction tends to be associated with business processes addressing reporting objectives (e.g., financial transactions), while the term activity is more often associated with business processes addressing operations or compliance objectives. In the Green Book, “transactions” and “transaction control activities” can cover both transactions and activities. Management may design a variety of transaction control activities for business processes, which may include verifications, reconciliations, authorizations and approvals, physical control activities, and supervisory control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.18&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.18&#039;&#039;&#039; ====&lt;br /&gt;
When designing transaction control activities, management evaluates information processing objectives to meet the entity’s objectives and mitigate related risks.&lt;br /&gt;
&lt;br /&gt;
Information processing objectives may include the following:&lt;br /&gt;
&lt;br /&gt;
* Completeness - All transactions and events that occur have been properly recorded.&lt;br /&gt;
* Accuracy - Data relating to transactions and events are properly and timely recorded.&lt;br /&gt;
* Validity - All recorded transactions and events actually occurred, are related to the entity, and were executed according to prescribed procedures.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.19&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.19&#039;&#039;&#039; ====&lt;br /&gt;
While the information processing objectives are most often associated with financial processes and transactions, information processing objectives can be applied to any activity in an organization. For example, information processing objectives and related control activities can be applied to management’s decision-making processes that use non-financial data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.20&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.20&#039;&#039;&#039; ====&lt;br /&gt;
When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity’s objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is closely linked to the entity’s risk tolerance for a particular objective; a lower risk tolerance will require a more precise control activity. In determining the necessary level of precision for a control activity, management evaluates the following:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Level of aggregation&#039;&#039;&#039; - A control activity that is performed at a more granular level generally is more precise than one performed at a higher level. For example, an analysis of obligations by budget object class normally is more precise than an analysis of total obligations for the entity.&lt;br /&gt;
* &#039;&#039;&#039;Consistency and timing of performance&#039;&#039;&#039; - A control activity that is performed routinely, consistently, and timely generally is more precise than one performed sporadically.&lt;br /&gt;
* &#039;&#039;&#039;Correlation to relevant business processes&#039;&#039;&#039; - A control activity that is directly related to a business process generally is more likely to prevent or detect and correct an error than a control activity that is only indirectly related.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.6&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.6 Segregation of Duties ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.21&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.21&#039;&#039;&#039; ====&lt;br /&gt;
Management considers segregation of duties in designing control activities so that incompatible duties are segregated. Where such segregation is not practical, management designs alternative control activities to mitigate the risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.22&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.22&#039;&#039;&#039; ====&lt;br /&gt;
Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity’s business processes. Segregation of duties can mitigate the risk of management override. Management override circumvents existing control activities and increases risk of fraud, waste, and abuse. Management mitigates this risk through segregation of duties but cannot absolutely prevent it because of the risk of collusion, where two or more employees act together to commit fraud, waste, or abuse.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.23&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.23&#039;&#039;&#039; ====&lt;br /&gt;
If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2020: The Event|🗳️ 2020: The Event]]&lt;br /&gt;
* [[May 15, 2025: Let&#039;s Play Hot Potato|🥔 May 2025: PRR Issues]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=403</id>
		<title>Principle 10 - Design Control Activities</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=403"/>
		<updated>2026-08-14T01:17:05Z</updated>

		<summary type="html">&lt;p&gt;Kelly: /* 10.04 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 10.0 Design Control Activities ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-10-design-control-activities/ External Link to US GAO Green Book Principle 10]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should design control activities to mitigate risks to achieving the entity’s objectives to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.1 Response to Risks ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities in response to risks to achieve an effective internal control system. Control activities are the actions management establishes through policies and procedures to specifically mitigate risks to achieving the entity’s objectives to acceptable levels. Control activities support all the components of internal control but are particularly aligned with the risk assessment component. As part of periodic and ongoing risk assessments, management identifies objectives; the risks related to the entity and its objectives, including its service organizations; the entity’s risk tolerance; and risk responses. Management designs control activities or modifies existing control activities to mitigate risks to acceptable levels within management’s defined risk tolerance. Typically, control activities are needed when an entity chooses to either reduce or share a risk. The nature and extent of the risk response and any associated control activities will depend, at least in part, on management’s defined risk tolerance.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.2 Design of Appropriate Types of Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.03&#039;&#039;&#039; ====&lt;br /&gt;
Management designs appropriate types of control activities for the entity’s internal control system, including the entity’s information technology, by considering all aspects of its internal control components, relevant business processes, and operating environment. An entity’s internal control is flexible to allow management to tailor control activities to meet the entity’s unique needs. The specific control activities used by a given entity may be different from those used by others based on several factors. These factors could include specific threats the entity faces and the risks involved, differences in objectives, managerial judgment, size and complexity of the entity, operational environment, and sensitivity and value of data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.04&#039;&#039;&#039; ====&lt;br /&gt;
The common categories of control activities listed illustrate the range and variety of control activities that may be useful to management. &lt;br /&gt;
&lt;br /&gt;
The list is not all inclusive and may not include all categories of control activities that an entity may need.&lt;br /&gt;
&lt;br /&gt;
===== Common Categories of Control Activities =====&lt;br /&gt;
&lt;br /&gt;
* Top-level reviews of actual performance&lt;br /&gt;
* Reviews by management at the functional or activity level&lt;br /&gt;
* Establishment and review of performance measures and indicators&lt;br /&gt;
* Management of human capital&lt;br /&gt;
* Control activities over information processing&lt;br /&gt;
* Physical control activities over vulnerable assets&lt;br /&gt;
* Access restrictions to and accountability for resources and records&lt;br /&gt;
* Authorization of transactions&lt;br /&gt;
* Control activities over complete, accurate, and timely recording of valid transactions&lt;br /&gt;
* Appropriate documentation of transactions and control activities&lt;br /&gt;
* Oversight of entity business processes assigned to service organizations&lt;br /&gt;
* Segregation of duties&lt;br /&gt;
* Program-related control activities&lt;br /&gt;
* Fraud-related control activities&lt;br /&gt;
* Improper-payment-related control activities&lt;br /&gt;
* Compliance-related control activities&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.3 Design of Automated and Manual Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.05&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be designed and implemented in an automated, partially automated, or a manual manner. Automated control activities may be wholly or partially performed using the entity’s information technology. Manual control activities are performed by individuals without relying on the entity’s information technology. Automated control activities tend to be more reliable because they are less susceptible to human error and are typically more efficient.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.06&#039;&#039;&#039; ====&lt;br /&gt;
Management designs information technology control activities to support the operation and security of the entity’s information technology and automated business processes. Information technology control activities consist of general, application, and user control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.07&#039;&#039;&#039; ====&lt;br /&gt;
Application and user control activities rely on the entity’s information technology. Application control activities are automated control activities that are incorporated directly into application software to achieve the completeness, accuracy, and validity of transactions and data. Application control activities include control activities over the input, processing, and output of data. User control activities, sometimes referred to as information technology-dependent controls, are partially automated control activities that are performed by individuals using the entity’s information technology or by relying on the information processed through technology. For example, management may authorize a transaction as part of an automated workflow or may respond to incidents flagged in system log reports.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.08&#039;&#039;&#039; ====&lt;br /&gt;
General control activities are designed to mitigate information security risks and are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. General control activities support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. General control activities can be designed and implemented in either an automated or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.09&#039;&#039;&#039; ====&lt;br /&gt;
Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need.[[File:10.09-fig-7.png|center|1000x1000px|thumb|&#039;&#039;&#039;Figure 7:&#039;&#039;&#039; Common Categories of Information Technology Control Activities]]&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.4&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.4 Design of Preventive and Detective Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.10&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be either preventive or detective. The main difference between preventive and detective control activities is timing, that is, when the control activity occurs within an entity’s operations. A preventive control activity is designed to avoid an unintended event or result before it occurs. A detective control activity is designed to discover and timely correct an unintended event or result after it occurs. The effectiveness of a detective control activity depends on timeliness of the corrective action to address the unintended event or result. Corrective action may address the event that occurred or may correct the deficiencies in the process that led to the event.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.11&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates the purpose of the control activity as well as the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives. Management may design both preventive and detective control activities to effectively mitigate the risks to achieving the objectives, particularly in circumstances where the risk of an unintended event or result occurring is high. Generally, the higher the risk of an unintended event or result occurring, the stronger or more robust the control activities need to be to effectively mitigate the higher risk to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.12&#039;&#039;&#039; ====&lt;br /&gt;
Management designs an appropriate mix of preventive and detective control activities to mitigate risks to an acceptable level, prioritizing preventive control activities where appropriate. When designing control activities, management first considers preventive control activities, as they generally offer the most cost-efficient use of resources and are generally effective at mitigating fraud and improper payment risks. Management next considers detective control activities and may design both preventive and detective control activities when necessary to mitigate a particular risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.13&#039;&#039;&#039; ====&lt;br /&gt;
There may be rare situations where management determines through its evaluation that a preventive control activity would better mitigate a particular risk but is unable to implement it. In these situations, management strengthens and expedites detective control activities and may also expedite monitoring activities to enable the entity to effectively mitigate the risk to acceptable levels, considering the risk related to the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.5&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.5 Design of Control Activities at Various Levels ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.14&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities at the appropriate levels in the organizational structure.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.15&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities for appropriate mitigation of risks in the entity’s business processes. Business processes transform inputs into outputs through a series of transactions or activities to achieve the entity’s objectives. Management designs entity-level control activities, business process-level control activities (commonly referred to as transaction control activities), or both depending on the level of precision needed so that the entity mitigates risks to an acceptable level related to its business processes. Entity-level and transaction control activities can be implemented in an automated, partially automated, or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.16&#039;&#039;&#039; ====&lt;br /&gt;
Entity-level control activities are controls designed to mitigate risks that have a pervasive effect on an entity’s internal control system and may pertain to multiple components. Entity-level control activities may include controls related to the entity’s risk assessment process, control environment, service organizations, management override, and performance or analytical reviews.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.17&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.17&#039;&#039;&#039; ====&lt;br /&gt;
Transaction control activities are controls that directly mitigate information processing risks in the entity’s business processes. The term transaction tends to be associated with business processes addressing reporting objectives (e.g., financial transactions), while the term activity is more often associated with business processes addressing operations or compliance objectives. In the Green Book, “transactions” and “transaction control activities” can cover both transactions and activities. Management may design a variety of transaction control activities for business processes, which may include verifications, reconciliations, authorizations and approvals, physical control activities, and supervisory control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.18&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.18&#039;&#039;&#039; ====&lt;br /&gt;
When designing transaction control activities, management evaluates information processing objectives to meet the entity’s objectives and mitigate related risks.&lt;br /&gt;
&lt;br /&gt;
Information processing objectives may include the following:&lt;br /&gt;
&lt;br /&gt;
* Completeness - All transactions and events that occur have been properly recorded.&lt;br /&gt;
* Accuracy - Data relating to transactions and events are properly and timely recorded.&lt;br /&gt;
* Validity - All recorded transactions and events actually occurred, are related to the entity, and were executed according to prescribed procedures.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.19&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.19&#039;&#039;&#039; ====&lt;br /&gt;
While the information processing objectives are most often associated with financial processes and transactions, information processing objectives can be applied to any activity in an organization. For example, information processing objectives and related control activities can be applied to management’s decision-making processes that use non-financial data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.20&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.20&#039;&#039;&#039; ====&lt;br /&gt;
When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity’s objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is closely linked to the entity’s risk tolerance for a particular objective; a lower risk tolerance will require a more precise control activity. In determining the necessary level of precision for a control activity, management evaluates the following:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Level of aggregation&#039;&#039;&#039; - A control activity that is performed at a more granular level generally is more precise than one performed at a higher level. For example, an analysis of obligations by budget object class normally is more precise than an analysis of total obligations for the entity.&lt;br /&gt;
* &#039;&#039;&#039;Consistency and timing of performance&#039;&#039;&#039; - A control activity that is performed routinely, consistently, and timely generally is more precise than one performed sporadically.&lt;br /&gt;
* &#039;&#039;&#039;Correlation to relevant business processes&#039;&#039;&#039; - A control activity that is directly related to a business process generally is more likely to prevent or detect and correct an error than a control activity that is only indirectly related.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.6&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.6 Segregation of Duties ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.21&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.21&#039;&#039;&#039; ====&lt;br /&gt;
Management considers segregation of duties in designing control activities so that incompatible duties are segregated. Where such segregation is not practical, management designs alternative control activities to mitigate the risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.22&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.22&#039;&#039;&#039; ====&lt;br /&gt;
Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity’s business processes. Segregation of duties can mitigate the risk of management override. Management override circumvents existing control activities and increases risk of fraud, waste, and abuse. Management mitigates this risk through segregation of duties but cannot absolutely prevent it because of the risk of collusion, where two or more employees act together to commit fraud, waste, or abuse.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.23&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.23&#039;&#039;&#039; ====&lt;br /&gt;
If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2020: The Event|🗳️ 2020: The Event]]&lt;br /&gt;
* [[May 15, 2025: Let&#039;s Play Hot Potato|🥔 May 2025: PRR Issues]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=401</id>
		<title>Principle 10 - Design Control Activities</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=401"/>
		<updated>2026-08-14T01:16:05Z</updated>

		<summary type="html">&lt;p&gt;Kelly: /* 10.04 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 10.0 Design Control Activities ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-10-design-control-activities/ External Link to US GAO Green Book Principle 10]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should design control activities to mitigate risks to achieving the entity’s objectives to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.1 Response to Risks ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities in response to risks to achieve an effective internal control system. Control activities are the actions management establishes through policies and procedures to specifically mitigate risks to achieving the entity’s objectives to acceptable levels. Control activities support all the components of internal control but are particularly aligned with the risk assessment component. As part of periodic and ongoing risk assessments, management identifies objectives; the risks related to the entity and its objectives, including its service organizations; the entity’s risk tolerance; and risk responses. Management designs control activities or modifies existing control activities to mitigate risks to acceptable levels within management’s defined risk tolerance. Typically, control activities are needed when an entity chooses to either reduce or share a risk. The nature and extent of the risk response and any associated control activities will depend, at least in part, on management’s defined risk tolerance.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.2 Design of Appropriate Types of Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.03&#039;&#039;&#039; ====&lt;br /&gt;
Management designs appropriate types of control activities for the entity’s internal control system, including the entity’s information technology, by considering all aspects of its internal control components, relevant business processes, and operating environment. An entity’s internal control is flexible to allow management to tailor control activities to meet the entity’s unique needs. The specific control activities used by a given entity may be different from those used by others based on several factors. These factors could include specific threats the entity faces and the risks involved, differences in objectives, managerial judgment, size and complexity of the entity, operational environment, and sensitivity and value of data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.04&#039;&#039;&#039; ====&lt;br /&gt;
The common categories of control activities listed in table 1 [omitted] illustrate the range and variety of control activities that may be useful to management. &lt;br /&gt;
&lt;br /&gt;
The list is not all inclusive and may not include all categories of control activities that an entity may need.&lt;br /&gt;
&lt;br /&gt;
===== Common Categories of Control Activities =====&lt;br /&gt;
&lt;br /&gt;
* Top-level reviews of actual performance&lt;br /&gt;
* Reviews by management at the functional or activity level&lt;br /&gt;
* Establishment and review of performance measures and indicators&lt;br /&gt;
* Management of human capital&lt;br /&gt;
* Control activities over information processing&lt;br /&gt;
* Physical control activities over vulnerable assets&lt;br /&gt;
* Access restrictions to and accountability for resources and records&lt;br /&gt;
* Authorization of transactions&lt;br /&gt;
* Control activities over complete, accurate, and timely recording of valid transactions&lt;br /&gt;
* Appropriate documentation of transactions and control activities&lt;br /&gt;
* Oversight of entity business processes assigned to service organizations&lt;br /&gt;
* Segregation of duties&lt;br /&gt;
* Program-related control activities&lt;br /&gt;
* Fraud-related control activities&lt;br /&gt;
* Improper-payment-related control activities&lt;br /&gt;
* Compliance-related control activities&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.3 Design of Automated and Manual Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.05&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be designed and implemented in an automated, partially automated, or a manual manner. Automated control activities may be wholly or partially performed using the entity’s information technology. Manual control activities are performed by individuals without relying on the entity’s information technology. Automated control activities tend to be more reliable because they are less susceptible to human error and are typically more efficient.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.06&#039;&#039;&#039; ====&lt;br /&gt;
Management designs information technology control activities to support the operation and security of the entity’s information technology and automated business processes. Information technology control activities consist of general, application, and user control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.07&#039;&#039;&#039; ====&lt;br /&gt;
Application and user control activities rely on the entity’s information technology. Application control activities are automated control activities that are incorporated directly into application software to achieve the completeness, accuracy, and validity of transactions and data. Application control activities include control activities over the input, processing, and output of data. User control activities, sometimes referred to as information technology-dependent controls, are partially automated control activities that are performed by individuals using the entity’s information technology or by relying on the information processed through technology. For example, management may authorize a transaction as part of an automated workflow or may respond to incidents flagged in system log reports.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.08&#039;&#039;&#039; ====&lt;br /&gt;
General control activities are designed to mitigate information security risks and are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. General control activities support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. General control activities can be designed and implemented in either an automated or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.09&#039;&#039;&#039; ====&lt;br /&gt;
Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need.[[File:10.09-fig-7.png|center|1000x1000px|thumb|&#039;&#039;&#039;Figure 7:&#039;&#039;&#039; Common Categories of Information Technology Control Activities]]&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.4&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.4 Design of Preventive and Detective Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.10&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be either preventive or detective. The main difference between preventive and detective control activities is timing, that is, when the control activity occurs within an entity’s operations. A preventive control activity is designed to avoid an unintended event or result before it occurs. A detective control activity is designed to discover and timely correct an unintended event or result after it occurs. The effectiveness of a detective control activity depends on timeliness of the corrective action to address the unintended event or result. Corrective action may address the event that occurred or may correct the deficiencies in the process that led to the event.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.11&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates the purpose of the control activity as well as the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives. Management may design both preventive and detective control activities to effectively mitigate the risks to achieving the objectives, particularly in circumstances where the risk of an unintended event or result occurring is high. Generally, the higher the risk of an unintended event or result occurring, the stronger or more robust the control activities need to be to effectively mitigate the higher risk to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.12&#039;&#039;&#039; ====&lt;br /&gt;
Management designs an appropriate mix of preventive and detective control activities to mitigate risks to an acceptable level, prioritizing preventive control activities where appropriate. When designing control activities, management first considers preventive control activities, as they generally offer the most cost-efficient use of resources and are generally effective at mitigating fraud and improper payment risks. Management next considers detective control activities and may design both preventive and detective control activities when necessary to mitigate a particular risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.13&#039;&#039;&#039; ====&lt;br /&gt;
There may be rare situations where management determines through its evaluation that a preventive control activity would better mitigate a particular risk but is unable to implement it. In these situations, management strengthens and expedites detective control activities and may also expedite monitoring activities to enable the entity to effectively mitigate the risk to acceptable levels, considering the risk related to the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.5&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.5 Design of Control Activities at Various Levels ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.14&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities at the appropriate levels in the organizational structure.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.15&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities for appropriate mitigation of risks in the entity’s business processes. Business processes transform inputs into outputs through a series of transactions or activities to achieve the entity’s objectives. Management designs entity-level control activities, business process-level control activities (commonly referred to as transaction control activities), or both depending on the level of precision needed so that the entity mitigates risks to an acceptable level related to its business processes. Entity-level and transaction control activities can be implemented in an automated, partially automated, or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.16&#039;&#039;&#039; ====&lt;br /&gt;
Entity-level control activities are controls designed to mitigate risks that have a pervasive effect on an entity’s internal control system and may pertain to multiple components. Entity-level control activities may include controls related to the entity’s risk assessment process, control environment, service organizations, management override, and performance or analytical reviews.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.17&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.17&#039;&#039;&#039; ====&lt;br /&gt;
Transaction control activities are controls that directly mitigate information processing risks in the entity’s business processes. The term transaction tends to be associated with business processes addressing reporting objectives (e.g., financial transactions), while the term activity is more often associated with business processes addressing operations or compliance objectives. In the Green Book, “transactions” and “transaction control activities” can cover both transactions and activities. Management may design a variety of transaction control activities for business processes, which may include verifications, reconciliations, authorizations and approvals, physical control activities, and supervisory control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.18&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.18&#039;&#039;&#039; ====&lt;br /&gt;
When designing transaction control activities, management evaluates information processing objectives to meet the entity’s objectives and mitigate related risks.&lt;br /&gt;
&lt;br /&gt;
Information processing objectives may include the following:&lt;br /&gt;
&lt;br /&gt;
* Completeness - All transactions and events that occur have been properly recorded.&lt;br /&gt;
* Accuracy - Data relating to transactions and events are properly and timely recorded.&lt;br /&gt;
* Validity - All recorded transactions and events actually occurred, are related to the entity, and were executed according to prescribed procedures.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.19&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.19&#039;&#039;&#039; ====&lt;br /&gt;
While the information processing objectives are most often associated with financial processes and transactions, information processing objectives can be applied to any activity in an organization. For example, information processing objectives and related control activities can be applied to management’s decision-making processes that use non-financial data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.20&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.20&#039;&#039;&#039; ====&lt;br /&gt;
When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity’s objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is closely linked to the entity’s risk tolerance for a particular objective; a lower risk tolerance will require a more precise control activity. In determining the necessary level of precision for a control activity, management evaluates the following:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Level of aggregation&#039;&#039;&#039; - A control activity that is performed at a more granular level generally is more precise than one performed at a higher level. For example, an analysis of obligations by budget object class normally is more precise than an analysis of total obligations for the entity.&lt;br /&gt;
* &#039;&#039;&#039;Consistency and timing of performance&#039;&#039;&#039; - A control activity that is performed routinely, consistently, and timely generally is more precise than one performed sporadically.&lt;br /&gt;
* &#039;&#039;&#039;Correlation to relevant business processes&#039;&#039;&#039; - A control activity that is directly related to a business process generally is more likely to prevent or detect and correct an error than a control activity that is only indirectly related.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.6&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.6 Segregation of Duties ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.21&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.21&#039;&#039;&#039; ====&lt;br /&gt;
Management considers segregation of duties in designing control activities so that incompatible duties are segregated. Where such segregation is not practical, management designs alternative control activities to mitigate the risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.22&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.22&#039;&#039;&#039; ====&lt;br /&gt;
Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity’s business processes. Segregation of duties can mitigate the risk of management override. Management override circumvents existing control activities and increases risk of fraud, waste, and abuse. Management mitigates this risk through segregation of duties but cannot absolutely prevent it because of the risk of collusion, where two or more employees act together to commit fraud, waste, or abuse.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.23&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.23&#039;&#039;&#039; ====&lt;br /&gt;
If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2020: The Event|🗳️ 2020: The Event]]&lt;br /&gt;
* [[May 15, 2025: Let&#039;s Play Hot Potato|🥔 May 2025: PRR Issues]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=400</id>
		<title>Principle 10 - Design Control Activities</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=400"/>
		<updated>2026-08-14T01:12:10Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 10.0 Design Control Activities ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-10-design-control-activities/ External Link to US GAO Green Book Principle 10]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should design control activities to mitigate risks to achieving the entity’s objectives to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.1 Response to Risks ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities in response to risks to achieve an effective internal control system. Control activities are the actions management establishes through policies and procedures to specifically mitigate risks to achieving the entity’s objectives to acceptable levels. Control activities support all the components of internal control but are particularly aligned with the risk assessment component. As part of periodic and ongoing risk assessments, management identifies objectives; the risks related to the entity and its objectives, including its service organizations; the entity’s risk tolerance; and risk responses. Management designs control activities or modifies existing control activities to mitigate risks to acceptable levels within management’s defined risk tolerance. Typically, control activities are needed when an entity chooses to either reduce or share a risk. The nature and extent of the risk response and any associated control activities will depend, at least in part, on management’s defined risk tolerance.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.2 Design of Appropriate Types of Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.03&#039;&#039;&#039; ====&lt;br /&gt;
Management designs appropriate types of control activities for the entity’s internal control system, including the entity’s information technology, by considering all aspects of its internal control components, relevant business processes, and operating environment. An entity’s internal control is flexible to allow management to tailor control activities to meet the entity’s unique needs. The specific control activities used by a given entity may be different from those used by others based on several factors. These factors could include specific threats the entity faces and the risks involved, differences in objectives, managerial judgment, size and complexity of the entity, operational environment, and sensitivity and value of data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.04&#039;&#039;&#039; ====&lt;br /&gt;
The common categories of control activities listed in table 1 [omitted] illustrate the range and variety of control activities that may be useful to management. &lt;br /&gt;
&lt;br /&gt;
The list is not all inclusive and may not include all categories of control activities that an entity may need.&lt;br /&gt;
&lt;br /&gt;
(ADD TABLE)&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.3 Design of Automated and Manual Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.05&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be designed and implemented in an automated, partially automated, or a manual manner. Automated control activities may be wholly or partially performed using the entity’s information technology. Manual control activities are performed by individuals without relying on the entity’s information technology. Automated control activities tend to be more reliable because they are less susceptible to human error and are typically more efficient.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.06&#039;&#039;&#039; ====&lt;br /&gt;
Management designs information technology control activities to support the operation and security of the entity’s information technology and automated business processes. Information technology control activities consist of general, application, and user control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.07&#039;&#039;&#039; ====&lt;br /&gt;
Application and user control activities rely on the entity’s information technology. Application control activities are automated control activities that are incorporated directly into application software to achieve the completeness, accuracy, and validity of transactions and data. Application control activities include control activities over the input, processing, and output of data. User control activities, sometimes referred to as information technology-dependent controls, are partially automated control activities that are performed by individuals using the entity’s information technology or by relying on the information processed through technology. For example, management may authorize a transaction as part of an automated workflow or may respond to incidents flagged in system log reports.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.08&#039;&#039;&#039; ====&lt;br /&gt;
General control activities are designed to mitigate information security risks and are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. General control activities support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. General control activities can be designed and implemented in either an automated or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.09&#039;&#039;&#039; ====&lt;br /&gt;
Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need.[[File:10.09-fig-7.png|center|1000x1000px|thumb|&#039;&#039;&#039;Figure 7:&#039;&#039;&#039; Common Categories of Information Technology Control Activities]]&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.4&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.4 Design of Preventive and Detective Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.10&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be either preventive or detective. The main difference between preventive and detective control activities is timing, that is, when the control activity occurs within an entity’s operations. A preventive control activity is designed to avoid an unintended event or result before it occurs. A detective control activity is designed to discover and timely correct an unintended event or result after it occurs. The effectiveness of a detective control activity depends on timeliness of the corrective action to address the unintended event or result. Corrective action may address the event that occurred or may correct the deficiencies in the process that led to the event.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.11&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates the purpose of the control activity as well as the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives. Management may design both preventive and detective control activities to effectively mitigate the risks to achieving the objectives, particularly in circumstances where the risk of an unintended event or result occurring is high. Generally, the higher the risk of an unintended event or result occurring, the stronger or more robust the control activities need to be to effectively mitigate the higher risk to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.12&#039;&#039;&#039; ====&lt;br /&gt;
Management designs an appropriate mix of preventive and detective control activities to mitigate risks to an acceptable level, prioritizing preventive control activities where appropriate. When designing control activities, management first considers preventive control activities, as they generally offer the most cost-efficient use of resources and are generally effective at mitigating fraud and improper payment risks. Management next considers detective control activities and may design both preventive and detective control activities when necessary to mitigate a particular risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.13&#039;&#039;&#039; ====&lt;br /&gt;
There may be rare situations where management determines through its evaluation that a preventive control activity would better mitigate a particular risk but is unable to implement it. In these situations, management strengthens and expedites detective control activities and may also expedite monitoring activities to enable the entity to effectively mitigate the risk to acceptable levels, considering the risk related to the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.5&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.5 Design of Control Activities at Various Levels ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.14&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities at the appropriate levels in the organizational structure.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.15&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities for appropriate mitigation of risks in the entity’s business processes. Business processes transform inputs into outputs through a series of transactions or activities to achieve the entity’s objectives. Management designs entity-level control activities, business process-level control activities (commonly referred to as transaction control activities), or both depending on the level of precision needed so that the entity mitigates risks to an acceptable level related to its business processes. Entity-level and transaction control activities can be implemented in an automated, partially automated, or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.16&#039;&#039;&#039; ====&lt;br /&gt;
Entity-level control activities are controls designed to mitigate risks that have a pervasive effect on an entity’s internal control system and may pertain to multiple components. Entity-level control activities may include controls related to the entity’s risk assessment process, control environment, service organizations, management override, and performance or analytical reviews.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.17&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.17&#039;&#039;&#039; ====&lt;br /&gt;
Transaction control activities are controls that directly mitigate information processing risks in the entity’s business processes. The term transaction tends to be associated with business processes addressing reporting objectives (e.g., financial transactions), while the term activity is more often associated with business processes addressing operations or compliance objectives. In the Green Book, “transactions” and “transaction control activities” can cover both transactions and activities. Management may design a variety of transaction control activities for business processes, which may include verifications, reconciliations, authorizations and approvals, physical control activities, and supervisory control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.18&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.18&#039;&#039;&#039; ====&lt;br /&gt;
When designing transaction control activities, management evaluates information processing objectives to meet the entity’s objectives and mitigate related risks.&lt;br /&gt;
&lt;br /&gt;
Information processing objectives may include the following:&lt;br /&gt;
&lt;br /&gt;
* Completeness - All transactions and events that occur have been properly recorded.&lt;br /&gt;
* Accuracy - Data relating to transactions and events are properly and timely recorded.&lt;br /&gt;
* Validity - All recorded transactions and events actually occurred, are related to the entity, and were executed according to prescribed procedures.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.19&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.19&#039;&#039;&#039; ====&lt;br /&gt;
While the information processing objectives are most often associated with financial processes and transactions, information processing objectives can be applied to any activity in an organization. For example, information processing objectives and related control activities can be applied to management’s decision-making processes that use non-financial data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.20&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.20&#039;&#039;&#039; ====&lt;br /&gt;
When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity’s objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is closely linked to the entity’s risk tolerance for a particular objective; a lower risk tolerance will require a more precise control activity. In determining the necessary level of precision for a control activity, management evaluates the following:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Level of aggregation&#039;&#039;&#039; - A control activity that is performed at a more granular level generally is more precise than one performed at a higher level. For example, an analysis of obligations by budget object class normally is more precise than an analysis of total obligations for the entity.&lt;br /&gt;
* &#039;&#039;&#039;Consistency and timing of performance&#039;&#039;&#039; - A control activity that is performed routinely, consistently, and timely generally is more precise than one performed sporadically.&lt;br /&gt;
* &#039;&#039;&#039;Correlation to relevant business processes&#039;&#039;&#039; - A control activity that is directly related to a business process generally is more likely to prevent or detect and correct an error than a control activity that is only indirectly related.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.6&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.6 Segregation of Duties ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.21&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.21&#039;&#039;&#039; ====&lt;br /&gt;
Management considers segregation of duties in designing control activities so that incompatible duties are segregated. Where such segregation is not practical, management designs alternative control activities to mitigate the risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.22&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.22&#039;&#039;&#039; ====&lt;br /&gt;
Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity’s business processes. Segregation of duties can mitigate the risk of management override. Management override circumvents existing control activities and increases risk of fraud, waste, and abuse. Management mitigates this risk through segregation of duties but cannot absolutely prevent it because of the risk of collusion, where two or more employees act together to commit fraud, waste, or abuse.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.23&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.23&#039;&#039;&#039; ====&lt;br /&gt;
If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2020: The Event|🗳️ 2020: The Event]]&lt;br /&gt;
* [[May 15, 2025: Let&#039;s Play Hot Potato|🥔 May 2025: PRR Issues]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=399</id>
		<title>Principle 10 - Design Control Activities</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=399"/>
		<updated>2026-08-14T01:10:47Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 10.0 Design Control Activities ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-10-design-control-activities/ External Link to US GAO Green Book Principle 10]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should design control activities to mitigate risks to achieving the entity’s objectives to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.1 Response to Risks ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities in response to risks to achieve an effective internal control system. Control activities are the actions management establishes through policies and procedures to specifically mitigate risks to achieving the entity’s objectives to acceptable levels. Control activities support all the components of internal control but are particularly aligned with the risk assessment component. As part of periodic and ongoing risk assessments, management identifies objectives; the risks related to the entity and its objectives, including its service organizations; the entity’s risk tolerance; and risk responses. Management designs control activities or modifies existing control activities to mitigate risks to acceptable levels within management’s defined risk tolerance. Typically, control activities are needed when an entity chooses to either reduce or share a risk. The nature and extent of the risk response and any associated control activities will depend, at least in part, on management’s defined risk tolerance.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.2 Design of Appropriate Types of Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.03&#039;&#039;&#039; ====&lt;br /&gt;
Management designs appropriate types of control activities for the entity’s internal control system, including the entity’s information technology, by considering all aspects of its internal control components, relevant business processes, and operating environment. An entity’s internal control is flexible to allow management to tailor control activities to meet the entity’s unique needs. The specific control activities used by a given entity may be different from those used by others based on several factors. These factors could include specific threats the entity faces and the risks involved, differences in objectives, managerial judgment, size and complexity of the entity, operational environment, and sensitivity and value of data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.04&#039;&#039;&#039; ====&lt;br /&gt;
The common categories of control activities listed in table 1 [omitted] illustrate the range and variety of control activities that may be useful to management. &lt;br /&gt;
&lt;br /&gt;
The list is not all inclusive and may not include all categories of control activities that an entity may need.&lt;br /&gt;
&lt;br /&gt;
(ADD TABLE)&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.3 Design of Automated and Manual Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.05&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be designed and implemented in an automated, partially automated, or a manual manner. Automated control activities may be wholly or partially performed using the entity’s information technology. Manual control activities are performed by individuals without relying on the entity’s information technology. Automated control activities tend to be more reliable because they are less susceptible to human error and are typically more efficient.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.06&#039;&#039;&#039; ====&lt;br /&gt;
Management designs information technology control activities to support the operation and security of the entity’s information technology and automated business processes. Information technology control activities consist of general, application, and user control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.07&#039;&#039;&#039; ====&lt;br /&gt;
Application and user control activities rely on the entity’s information technology. Application control activities are automated control activities that are incorporated directly into application software to achieve the completeness, accuracy, and validity of transactions and data. Application control activities include control activities over the input, processing, and output of data. User control activities, sometimes referred to as information technology-dependent controls, are partially automated control activities that are performed by individuals using the entity’s information technology or by relying on the information processed through technology. For example, management may authorize a transaction as part of an automated workflow or may respond to incidents flagged in system log reports.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.08&#039;&#039;&#039; ====&lt;br /&gt;
General control activities are designed to mitigate information security risks and are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. General control activities support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. General control activities can be designed and implemented in either an automated or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.09&#039;&#039;&#039; ====&lt;br /&gt;
Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need.[[File:10.09-fig-7.png|center|800x800px|thumb|&#039;&#039;&#039;Figure 7:&#039;&#039;&#039; Common Categories of Information Technology Control Activities]]&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.4&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.4 Design of Preventive and Detective Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.10&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be either preventive or detective. The main difference between preventive and detective control activities is timing, that is, when the control activity occurs within an entity’s operations. A preventive control activity is designed to avoid an unintended event or result before it occurs. A detective control activity is designed to discover and timely correct an unintended event or result after it occurs. The effectiveness of a detective control activity depends on timeliness of the corrective action to address the unintended event or result. Corrective action may address the event that occurred or may correct the deficiencies in the process that led to the event.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.11&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates the purpose of the control activity as well as the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives. Management may design both preventive and detective control activities to effectively mitigate the risks to achieving the objectives, particularly in circumstances where the risk of an unintended event or result occurring is high. Generally, the higher the risk of an unintended event or result occurring, the stronger or more robust the control activities need to be to effectively mitigate the higher risk to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.12&#039;&#039;&#039; ====&lt;br /&gt;
Management designs an appropriate mix of preventive and detective control activities to mitigate risks to an acceptable level, prioritizing preventive control activities where appropriate. When designing control activities, management first considers preventive control activities, as they generally offer the most cost-efficient use of resources and are generally effective at mitigating fraud and improper payment risks. Management next considers detective control activities and may design both preventive and detective control activities when necessary to mitigate a particular risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.13&#039;&#039;&#039; ====&lt;br /&gt;
There may be rare situations where management determines through its evaluation that a preventive control activity would better mitigate a particular risk but is unable to implement it. In these situations, management strengthens and expedites detective control activities and may also expedite monitoring activities to enable the entity to effectively mitigate the risk to acceptable levels, considering the risk related to the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.5&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.5 Design of Control Activities at Various Levels ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.14&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities at the appropriate levels in the organizational structure.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.15&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities for appropriate mitigation of risks in the entity’s business processes. Business processes transform inputs into outputs through a series of transactions or activities to achieve the entity’s objectives. Management designs entity-level control activities, business process-level control activities (commonly referred to as transaction control activities), or both depending on the level of precision needed so that the entity mitigates risks to an acceptable level related to its business processes. Entity-level and transaction control activities can be implemented in an automated, partially automated, or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.16&#039;&#039;&#039; ====&lt;br /&gt;
Entity-level control activities are controls designed to mitigate risks that have a pervasive effect on an entity’s internal control system and may pertain to multiple components. Entity-level control activities may include controls related to the entity’s risk assessment process, control environment, service organizations, management override, and performance or analytical reviews.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.17&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.17&#039;&#039;&#039; ====&lt;br /&gt;
Transaction control activities are controls that directly mitigate information processing risks in the entity’s business processes. The term transaction tends to be associated with business processes addressing reporting objectives (e.g., financial transactions), while the term activity is more often associated with business processes addressing operations or compliance objectives. In the Green Book, “transactions” and “transaction control activities” can cover both transactions and activities. Management may design a variety of transaction control activities for business processes, which may include verifications, reconciliations, authorizations and approvals, physical control activities, and supervisory control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.18&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.18&#039;&#039;&#039; ====&lt;br /&gt;
When designing transaction control activities, management evaluates information processing objectives to meet the entity’s objectives and mitigate related risks.&lt;br /&gt;
&lt;br /&gt;
Information processing objectives may include the following:&lt;br /&gt;
&lt;br /&gt;
* Completeness - All transactions and events that occur have been properly recorded.&lt;br /&gt;
* Accuracy - Data relating to transactions and events are properly and timely recorded.&lt;br /&gt;
* Validity - All recorded transactions and events actually occurred, are related to the entity, and were executed according to prescribed procedures.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.19&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.19&#039;&#039;&#039; ====&lt;br /&gt;
While the information processing objectives are most often associated with financial processes and transactions, information processing objectives can be applied to any activity in an organization. For example, information processing objectives and related control activities can be applied to management’s decision-making processes that use non-financial data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.20&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.20&#039;&#039;&#039; ====&lt;br /&gt;
When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity’s objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is closely linked to the entity’s risk tolerance for a particular objective; a lower risk tolerance will require a more precise control activity. In determining the necessary level of precision for a control activity, management evaluates the following:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Level of aggregation&#039;&#039;&#039; - A control activity that is performed at a more granular level generally is more precise than one performed at a higher level. For example, an analysis of obligations by budget object class normally is more precise than an analysis of total obligations for the entity.&lt;br /&gt;
* &#039;&#039;&#039;Consistency and timing of performance&#039;&#039;&#039; - A control activity that is performed routinely, consistently, and timely generally is more precise than one performed sporadically.&lt;br /&gt;
* &#039;&#039;&#039;Correlation to relevant business processes&#039;&#039;&#039; - A control activity that is directly related to a business process generally is more likely to prevent or detect and correct an error than a control activity that is only indirectly related.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.6&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.6 Segregation of Duties ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.21&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.21&#039;&#039;&#039; ====&lt;br /&gt;
Management considers segregation of duties in designing control activities so that incompatible duties are segregated. Where such segregation is not practical, management designs alternative control activities to mitigate the risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.22&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.22&#039;&#039;&#039; ====&lt;br /&gt;
Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity’s business processes. Segregation of duties can mitigate the risk of management override. Management override circumvents existing control activities and increases risk of fraud, waste, and abuse. Management mitigates this risk through segregation of duties but cannot absolutely prevent it because of the risk of collusion, where two or more employees act together to commit fraud, waste, or abuse.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.23&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.23&#039;&#039;&#039; ====&lt;br /&gt;
If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2020: The Event|🗳️ 2020: The Event]]&lt;br /&gt;
* [[May 15, 2025: Let&#039;s Play Hot Potato|🥔 May 2025: PRR Issues]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_1_-_Demonstrate_Commitment_to_Integrity_and_Ethical_Values&amp;diff=398</id>
		<title>Principle 1 - Demonstrate Commitment to Integrity and Ethical Values</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_1_-_Demonstrate_Commitment_to_Integrity_and_Ethical_Values&amp;diff=398"/>
		<updated>2026-08-14T01:05:21Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Principle 1: Demonstrate Commitment to Integrity and Ethical Values ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-1-demonstrate-commitment-to-integrity-and-ethical-values/ External Link to US GAO Green Book Principle 1.]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.01&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body and management should demonstrate a commitment to integrity and ethical values.&lt;br /&gt;
&lt;br /&gt;
=== Tone at the Top ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.02&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body and management demonstrate the importance of integrity and ethical values through their directives, attitudes, and behavior.&lt;br /&gt;
&lt;br /&gt;
=== November 2024: Midterm Election ===&lt;br /&gt;
Katie Hobbs managed the statewide election process as the Arizona Secretary of State while she was campaigning for Arizona Governor.&lt;br /&gt;
 Contrary to the Green Book, Katie created an ethical question by managing the statewide election process while also being a candidate in the same election she was overseeing. It’s important that we consider the objective of this Green Book Attribute. &lt;br /&gt;
 &lt;br /&gt;
 This isn’t about Katie Hobbs&#039;&#039;&#039;; this attribute is about the tone (or example) Katie is setting for the employees under her control, either directly as a state employee or indirectly as a county employees.&lt;br /&gt;
 &lt;br /&gt;
 Why is this important? There are two possible outcomes for subordinates that may encounter ethical issues (unintentionally or purposefully). Leaders that demonstrate or push the&#039;&#039;&#039; limits of unethical behaviors may encourage unethical behavior by seeing no adverse consequences for this behavior. Meanwhile, a leader’s unethical behavior may shutdown ethical employees that become unwilling to bring up ethical issues knowing that unethical behavior is tolerated.&lt;br /&gt;
&amp;lt;blockquote&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Contrary to the Green Book, Katie created an ethical question by managing the statewide election process while also being a candidate in the same election she was overseeing. It’s important that we consider the objective of this Green Book Attribute. &lt;br /&gt;
&lt;br /&gt;
This isn’t about Katie Hobbs; this attribute is about the tone (or example) Katie is setting for the employees under her control, either directly as a state employee or indirectly as a county employees.&lt;br /&gt;
&lt;br /&gt;
Why is this important? There are two possible outcomes for subordinates that may encounter ethical issues (unintentionally or purposefully). Leaders that demonstrate or push the limits of unethical behaviors may encourage unethical behavior by seeing no adverse consequences for this behavior. Meanwhile, a leader’s unethical behavior may shutdown ethical employees that become unwilling to bring up ethical issues knowing that unethical behavior is tolerated.&amp;lt;/blockquote&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.03&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body and management lead by an example that demonstrates the organization’s values, philosophy, and operating style. The oversight body and management set the tone at the top and throughout the organization by their example, which is fundamental to an effective internal control system. In larger entities, the various layers of management in the organizational structure may also set the “tone in the middle.” Although it is the oversight body and management’s responsibility to set the tone at the top, other personnel throughout the entity play an important role in supporting the tone that permeates the organizational culture.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.04&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body’s and management’s directives, attitudes, and behaviors reflect the integrity and ethical values expected throughout the entity. The oversight body and management reinforce the commitment to doing what is right, not just maintaining a minimum level of performance necessary to comply with applicable laws and regulations, so that these priorities are understood by all stakeholders, such as regulators, service organizations, employees, and the public.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.05&#039;&#039;&#039; ====&lt;br /&gt;
Tone at the top can be either a driver, as shown in the preceding paragraphs, or a barrier to internal control. Without a strong tone at the top to support an internal control system, the entity’s risk identification may be incomplete, risk responses may be inappropriate, control activities may not be appropriately designed or implemented, information and communication may falter, and results of monitoring may not be understood or acted upon to remediate deficiencies.&lt;br /&gt;
 &#039;&#039;&#039;[[May 15, 2025: Let’s Play Hot Potato]]&#039;&#039;&#039; - Contrary to the Green Book, multiple Maricopa County departments apparently believed that act of closing out of Public Records Request was culturally more important that resolving the citizen’s request.&lt;br /&gt;
 &lt;br /&gt;
 After the Procurement Department supplied four documents per the original PRR, three other PRRs were generated to transfer the (???)&lt;br /&gt;
&lt;br /&gt;
=== Standards of Conduct ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.06&#039;&#039;&#039; ====&lt;br /&gt;
Management establishes standards of conduct to communicate expectations concerning integrity and ethical values. The entity uses ethical values to balance the needs and concerns of different stakeholders, such as regulators, service organizations, employees, and the public. The standards of conduct guide the directives, attitudes, and behaviors of the organization in achieving its objectives.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.07&#039;&#039;&#039; ====&lt;br /&gt;
Management, with oversight from the oversight body, defines the organization’s expectations of ethical values in the standards of conduct. Management may consider using policies, operating principles, guidelines, or training to regularly communicate and reinforce the standards of conduct to the organization.&lt;br /&gt;
&lt;br /&gt;
=== Adherence to Standards of Conduct ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.08&#039;&#039;&#039; ====&lt;br /&gt;
Management establishes processes to evaluate performance against the entity’s expected standards of conduct and address any deviations in a timely manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.09&#039;&#039;&#039; ====&lt;br /&gt;
Management uses established standards of conduct as the basis for evaluating adherence to integrity and ethical values across the organization. Management evaluates the adherence to standards of conduct across all levels of the entity. To gain assurance that the entity’s standards of conduct are implemented effectively, management evaluates the directives, attitudes, and behaviors of individuals and teams. Evaluations may consist of ongoing monitoring or separate evaluations. Individual personnel can also report issues through reporting lines, such as regular staff meetings, upward feedback processes, a whistleblowing program, or an ethics hotline. The oversight body evaluates management’s adherence to the standards of conduct as well as the overall adherence by the entity.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;1.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;1.10&#039;&#039;&#039; ====&lt;br /&gt;
Management determines tolerance levels for deviations from standards of conduct. For instance, management may determine that the entity will have zero tolerance for deviations from certain expected standards of conduct, while deviations from others may be addressed with warnings to personnel. Management establishes a process for evaluations of individual and team adherence to standards of conduct that escalates and remediates deviations timely and consistently. Management, with oversight from the entity’s oversight body and with consideration of applicable laws and regulations, takes appropriate actions to remediate deviations.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=396</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=396"/>
		<updated>2026-08-14T00:49:20Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Arizona Compliance Review and Corrective Action Framework =&lt;br /&gt;
&lt;br /&gt;
The purpose of this framework is to describe the key elements of an effective citizen complaint, compliance review, and corrective action process for Arizona counties which may include state entities. It presents a practical governance framework that promotes transparency, accountability, consistency, and continuous improvement while strengthening public confidence in local/county/state government.&lt;br /&gt;
&lt;br /&gt;
Rather than creating new compliance standards, this framework applies well-established compliance review principles already used throughout government and private industry to citizen-identified governance concerns. It describes the essential components of an objective compliance review process, outlines the lifecycle of an effective complaint and corrective action program, and establishes the governance principles necessary to ensure significant citizen concerns are evaluated consistently, documented objectively, and resolved through a structured process.&lt;br /&gt;
&lt;br /&gt;
== Start Your Journey ==&lt;br /&gt;
Choose your path:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[The Story|📖 Read The Story]]&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[Governance Analysis|📊 Explore Governance Analysis]]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Follow the chronological narrative of events &amp;lt;br&amp;gt;that revealed governance gaps.&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Dive into structured analysis&amp;lt;br&amp;gt;using the Green Book framework.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{About}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | 🏠 &#039;&#039;&#039;Main Page&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=395</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=395"/>
		<updated>2026-08-14T00:48:42Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Arizona Compliance Review and Corrective Action Framework =&lt;br /&gt;
&lt;br /&gt;
The purpose of this framework is to describe the key elements of an effective citizen complaint, compliance review, and corrective action process for Arizona counties which may include state entities. It presents a practical governance framework that promotes transparency, accountability, consistency, and continuous improvement while strengthening public confidence in local/county/state government.&lt;br /&gt;
&lt;br /&gt;
Rather than creating new compliance standards, this framework applies well-established compliance review principles already used throughout government and private industry to citizen-identified governance concerns. It describes the essential components of an objective compliance review process, outlines the lifecycle of an effective complaint and corrective action program, and establishes the governance principles necessary to ensure significant citizen concerns are evaluated consistently, documented objectively, and resolved through a structured process.&lt;br /&gt;
&lt;br /&gt;
== Start Your Journey ==&lt;br /&gt;
Choose your path:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[The Story|📖 Read The Story]]&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[Governance Analysis|📊 Explore Governance Analysis]]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Follow the chronological narrative of events that revealed governance gaps.&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Dive into structured analysis using the Green Book framework.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{About}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | 🏠 &#039;&#039;&#039;Main Page&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=394</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=394"/>
		<updated>2026-08-14T00:47:55Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Arizona Compliance Review and Corrective Action Framework =&lt;br /&gt;
&lt;br /&gt;
The purpose of this framework is to describe the key elements of an effective citizen complaint, compliance review, and corrective action process for Arizona counties which may include state entities. It presents a practical governance framework that promotes transparency, accountability, consistency, and continuous improvement while strengthening public confidence in local/county/state government.&lt;br /&gt;
&lt;br /&gt;
Rather than creating new compliance standards, this framework applies well-established compliance review principles already used throughout government and private industry to citizen-identified governance concerns. It describes the essential components of an objective compliance review process, outlines the lifecycle of an effective complaint and corrective action program, and establishes the governance principles necessary to ensure significant citizen concerns are evaluated consistently, documented objectively, and resolved through a structured process.&lt;br /&gt;
&lt;br /&gt;
== Start Your Journey ==&lt;br /&gt;
Choose your path:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[The Story|📖 Read The Story]]&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[Governance Analysis|📊 Explore Governance Analysis]]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Follow the chronological narrative of events&lt;br /&gt;
that revealed governance gaps.&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Dive into structured analysis&lt;br /&gt;
using the Green Book framework.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{About}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | 🏠 &#039;&#039;&#039;Main Page&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=File:Capaz-logo.png&amp;diff=386</id>
		<title>File:Capaz-logo.png</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=File:Capaz-logo.png&amp;diff=386"/>
		<updated>2026-08-13T23:20:25Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=385</id>
		<title>Principle 10 - Design Control Activities</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=385"/>
		<updated>2026-08-13T23:16:43Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 10.0 Design Control Activities ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-10-design-control-activities/ External Link to US GAO Green Book Principle 10]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should design control activities to mitigate risks to achieving the entity’s objectives to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.1 Response to Risks ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities in response to risks to achieve an effective internal control system. Control activities are the actions management establishes through policies and procedures to specifically mitigate risks to achieving the entity’s objectives to acceptable levels. Control activities support all the components of internal control but are particularly aligned with the risk assessment component. As part of periodic and ongoing risk assessments, management identifies objectives; the risks related to the entity and its objectives, including its service organizations; the entity’s risk tolerance; and risk responses. Management designs control activities or modifies existing control activities to mitigate risks to acceptable levels within management’s defined risk tolerance. Typically, control activities are needed when an entity chooses to either reduce or share a risk. The nature and extent of the risk response and any associated control activities will depend, at least in part, on management’s defined risk tolerance.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.2 Design of Appropriate Types of Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.03&#039;&#039;&#039; ====&lt;br /&gt;
Management designs appropriate types of control activities for the entity’s internal control system, including the entity’s information technology, by considering all aspects of its internal control components, relevant business processes, and operating environment. An entity’s internal control is flexible to allow management to tailor control activities to meet the entity’s unique needs. The specific control activities used by a given entity may be different from those used by others based on several factors. These factors could include specific threats the entity faces and the risks involved, differences in objectives, managerial judgment, size and complexity of the entity, operational environment, and sensitivity and value of data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.04&#039;&#039;&#039; ====&lt;br /&gt;
The common categories of control activities listed in table 1 [omitted] illustrate the range and variety of control activities that may be useful to management. &lt;br /&gt;
&lt;br /&gt;
The list is not all inclusive and may not include all categories of control activities that an entity may need.&lt;br /&gt;
&lt;br /&gt;
(ADD TABLE)&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.3 Design of Automated and Manual Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.05&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be designed and implemented in an automated, partially automated, or a manual manner. Automated control activities may be wholly or partially performed using the entity’s information technology. Manual control activities are performed by individuals without relying on the entity’s information technology. Automated control activities tend to be more reliable because they are less susceptible to human error and are typically more efficient.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.06&#039;&#039;&#039; ====&lt;br /&gt;
Management designs information technology control activities to support the operation and security of the entity’s information technology and automated business processes. Information technology control activities consist of general, application, and user control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.07&#039;&#039;&#039; ====&lt;br /&gt;
Application and user control activities rely on the entity’s information technology. Application control activities are automated control activities that are incorporated directly into application software to achieve the completeness, accuracy, and validity of transactions and data. Application control activities include control activities over the input, processing, and output of data. User control activities, sometimes referred to as information technology-dependent controls, are partially automated control activities that are performed by individuals using the entity’s information technology or by relying on the information processed through technology. For example, management may authorize a transaction as part of an automated workflow or may respond to incidents flagged in system log reports.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.08&#039;&#039;&#039; ====&lt;br /&gt;
General control activities are designed to mitigate information security risks and are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. General control activities support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. General control activities can be designed and implemented in either an automated or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.09&#039;&#039;&#039; ====&lt;br /&gt;
Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Figure 7:&#039;&#039;&#039; Common Categories of Information Technology Control Activities&lt;br /&gt;
[[File:10.09-fig-7.png|center|800x800px]]&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.4&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.4 Design of Preventive and Detective Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.10&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be either preventive or detective. The main difference between preventive and detective control activities is timing, that is, when the control activity occurs within an entity’s operations. A preventive control activity is designed to avoid an unintended event or result before it occurs. A detective control activity is designed to discover and timely correct an unintended event or result after it occurs. The effectiveness of a detective control activity depends on timeliness of the corrective action to address the unintended event or result. Corrective action may address the event that occurred or may correct the deficiencies in the process that led to the event.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.11&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates the purpose of the control activity as well as the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives. Management may design both preventive and detective control activities to effectively mitigate the risks to achieving the objectives, particularly in circumstances where the risk of an unintended event or result occurring is high. Generally, the higher the risk of an unintended event or result occurring, the stronger or more robust the control activities need to be to effectively mitigate the higher risk to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.12&#039;&#039;&#039; ====&lt;br /&gt;
Management designs an appropriate mix of preventive and detective control activities to mitigate risks to an acceptable level, prioritizing preventive control activities where appropriate. When designing control activities, management first considers preventive control activities, as they generally offer the most cost-efficient use of resources and are generally effective at mitigating fraud and improper payment risks. Management next considers detective control activities and may design both preventive and detective control activities when necessary to mitigate a particular risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.13&#039;&#039;&#039; ====&lt;br /&gt;
There may be rare situations where management determines through its evaluation that a preventive control activity would better mitigate a particular risk but is unable to implement it. In these situations, management strengthens and expedites detective control activities and may also expedite monitoring activities to enable the entity to effectively mitigate the risk to acceptable levels, considering the risk related to the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.5&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.5 Design of Control Activities at Various Levels ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.14&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities at the appropriate levels in the organizational structure.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.15&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities for appropriate mitigation of risks in the entity’s business processes. Business processes transform inputs into outputs through a series of transactions or activities to achieve the entity’s objectives. Management designs entity-level control activities, business process-level control activities (commonly referred to as transaction control activities), or both depending on the level of precision needed so that the entity mitigates risks to an acceptable level related to its business processes. Entity-level and transaction control activities can be implemented in an automated, partially automated, or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.16&#039;&#039;&#039; ====&lt;br /&gt;
Entity-level control activities are controls designed to mitigate risks that have a pervasive effect on an entity’s internal control system and may pertain to multiple components. Entity-level control activities may include controls related to the entity’s risk assessment process, control environment, service organizations, management override, and performance or analytical reviews.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.17&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.17&#039;&#039;&#039; ====&lt;br /&gt;
Transaction control activities are controls that directly mitigate information processing risks in the entity’s business processes. The term transaction tends to be associated with business processes addressing reporting objectives (e.g., financial transactions), while the term activity is more often associated with business processes addressing operations or compliance objectives. In the Green Book, “transactions” and “transaction control activities” can cover both transactions and activities. Management may design a variety of transaction control activities for business processes, which may include verifications, reconciliations, authorizations and approvals, physical control activities, and supervisory control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.18&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.18&#039;&#039;&#039; ====&lt;br /&gt;
When designing transaction control activities, management evaluates information processing objectives to meet the entity’s objectives and mitigate related risks.&lt;br /&gt;
&lt;br /&gt;
Information processing objectives may include the following:&lt;br /&gt;
&lt;br /&gt;
* Completeness - All transactions and events that occur have been properly recorded.&lt;br /&gt;
* Accuracy - Data relating to transactions and events are properly and timely recorded.&lt;br /&gt;
* Validity - All recorded transactions and events actually occurred, are related to the entity, and were executed according to prescribed procedures.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.19&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.19&#039;&#039;&#039; ====&lt;br /&gt;
While the information processing objectives are most often associated with financial processes and transactions, information processing objectives can be applied to any activity in an organization. For example, information processing objectives and related control activities can be applied to management’s decision-making processes that use non-financial data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.20&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.20&#039;&#039;&#039; ====&lt;br /&gt;
When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity’s objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is closely linked to the entity’s risk tolerance for a particular objective; a lower risk tolerance will require a more precise control activity. In determining the necessary level of precision for a control activity, management evaluates the following:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Level of aggregation&#039;&#039;&#039; - A control activity that is performed at a more granular level generally is more precise than one performed at a higher level. For example, an analysis of obligations by budget object class normally is more precise than an analysis of total obligations for the entity.&lt;br /&gt;
* &#039;&#039;&#039;Consistency and timing of performance&#039;&#039;&#039; - A control activity that is performed routinely, consistently, and timely generally is more precise than one performed sporadically.&lt;br /&gt;
* &#039;&#039;&#039;Correlation to relevant business processes&#039;&#039;&#039; - A control activity that is directly related to a business process generally is more likely to prevent or detect and correct an error than a control activity that is only indirectly related.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.6&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.6 Segregation of Duties ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.21&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.21&#039;&#039;&#039; ====&lt;br /&gt;
Management considers segregation of duties in designing control activities so that incompatible duties are segregated. Where such segregation is not practical, management designs alternative control activities to mitigate the risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.22&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.22&#039;&#039;&#039; ====&lt;br /&gt;
Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity’s business processes. Segregation of duties can mitigate the risk of management override. Management override circumvents existing control activities and increases risk of fraud, waste, and abuse. Management mitigates this risk through segregation of duties but cannot absolutely prevent it because of the risk of collusion, where two or more employees act together to commit fraud, waste, or abuse.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.23&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.23&#039;&#039;&#039; ====&lt;br /&gt;
If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2020: The Event|🗳️ 2020: The Event]]&lt;br /&gt;
* [[May 15, 2025: Let&#039;s Play Hot Potato|🥔 May 2025: PRR Issues]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=File:10.09-fig-7.png&amp;diff=384</id>
		<title>File:10.09-fig-7.png</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=File:10.09-fig-7.png&amp;diff=384"/>
		<updated>2026-08-13T23:11:40Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Demo-page&amp;diff=382</id>
		<title>Demo-page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Demo-page&amp;diff=382"/>
		<updated>2026-08-13T23:00:34Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Link to In-Page Headings ===&lt;br /&gt;
[[Principle 1 - Demonstrate Commitment to Integrity and Ethical Values#1.07|This is linked to Principle #1, section 1.07]]&lt;br /&gt;
&lt;br /&gt;
[[Principle 11 - Design General Control Activities over Information#11.15|This is linked to Principle #11, section 11.15]]&lt;br /&gt;
&lt;br /&gt;
=== Colored Text ===&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#009999&amp;quot;&amp;gt; This sentence has a cyan-colored text...&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;background:#00FF00&amp;quot;&amp;gt; This sentence has a lime-colored background...&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#FFFFFF; background:#FF69B4&amp;quot;&amp;gt; This sentence has white-colored text and a Hot Pink-colored background....&amp;lt;/span&amp;gt;&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Demo-page&amp;diff=381</id>
		<title>Demo-page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Demo-page&amp;diff=381"/>
		<updated>2026-08-13T22:59:05Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Link to In-Page Headings ===&lt;br /&gt;
[[Principle 1 - Demonstrate Commitment to Integrity and Ethical Values#1.07|This is linked to Principle #1, section 1.07]]&lt;br /&gt;
&lt;br /&gt;
=== Colored Text ===&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#009999&amp;quot;&amp;gt; This sentence has a cyan-colored text...&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;background:#00FF00&amp;quot;&amp;gt; This sentence has a lime-colored background...&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#FFFFFF; background:#FF69B4&amp;quot;&amp;gt; This sentence has white-colored text and a Hot Pink-colored background....&amp;lt;/span&amp;gt;&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Demo-page&amp;diff=380</id>
		<title>Demo-page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Demo-page&amp;diff=380"/>
		<updated>2026-08-13T22:55:41Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Colored Text ===&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#009999&amp;quot;&amp;gt; This sentence has a cyan-colored text...&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;background:#00FF00&amp;quot;&amp;gt; This sentence has a lime-colored background...&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#FFFFFF; background:#FF69B4&amp;quot;&amp;gt; This sentence has white-colored text and a Hot Pink-colored background....&amp;lt;/span&amp;gt;&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Demo-page&amp;diff=379</id>
		<title>Demo-page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Demo-page&amp;diff=379"/>
		<updated>2026-08-13T22:55:09Z</updated>

		<summary type="html">&lt;p&gt;Kelly: Created page with &amp;quot;&amp;lt;span style=&amp;quot;color:#009999&amp;quot;&amp;gt; This sentence has a cyan-colored text...&amp;lt;/span&amp;gt; &amp;lt;span style=&amp;quot;background:#00FF00&amp;quot;&amp;gt; This sentence has a lime-colored background...&amp;lt;/span&amp;gt; &amp;lt;span style=&amp;quot;color:#FFFFFF; background:#FF69B4&amp;quot;&amp;gt; This sentence has white-colored text and a Hot Pink-colored background....&amp;lt;/span&amp;gt;&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;span style=&amp;quot;color:#009999&amp;quot;&amp;gt; This sentence has a cyan-colored text...&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;background:#00FF00&amp;quot;&amp;gt; This sentence has a lime-colored background...&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#FFFFFF; background:#FF69B4&amp;quot;&amp;gt; This sentence has white-colored text and a Hot Pink-colored background....&amp;lt;/span&amp;gt;&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=MediaWiki:Sidebar&amp;diff=378</id>
		<title>MediaWiki:Sidebar</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=MediaWiki:Sidebar&amp;diff=378"/>
		<updated>2026-08-13T22:53:27Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* navigation&lt;br /&gt;
** mainpage|Home&lt;br /&gt;
** The Story|The Story&lt;br /&gt;
** Governance Analysis|Governance Analysis&lt;br /&gt;
** Concerns|Concerns&lt;br /&gt;
&lt;br /&gt;
* about&lt;br /&gt;
** About Us|About Us&lt;br /&gt;
** Author Bio|About the Author&lt;br /&gt;
** What is a CAP?|What is a CAP?&lt;br /&gt;
** About the Green Book|About the Green Book&lt;br /&gt;
** Acronyms &amp;amp; Definitions|Acronyms &amp;amp; Definitions&lt;br /&gt;
&lt;br /&gt;
* tools&lt;br /&gt;
** recentchanges-url|Recent changes&lt;br /&gt;
** specialpages-url|Special pages&lt;br /&gt;
** demo-page|Demo page&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=377</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=377"/>
		<updated>2026-08-13T22:50:08Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Arizona Compliance Review and Corrective Action Framework =&lt;br /&gt;
&lt;br /&gt;
The purpose of this framework is to describe the key elements of an effective citizen complaint, compliance review, and corrective action process for Arizona counties which may include state entities. It presents a practical governance framework that promotes transparency, accountability, consistency, and continuous improvement while strengthening public confidence in local/county/state government.&lt;br /&gt;
&lt;br /&gt;
Rather than creating new compliance standards, this framework applies well-established compliance review principles already used throughout government and private industry to citizen-identified governance concerns. It describes the essential components of an objective compliance review process, outlines the lifecycle of an effective complaint and corrective action program, and establishes the governance principles necessary to ensure significant citizen concerns are evaluated consistently, documented objectively, and resolved through a structured process.&lt;br /&gt;
&lt;br /&gt;
== Start Your Journey ==&lt;br /&gt;
Choose your path:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[The Story|📖 Read The Story]]&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[Governance Analysis|📊 Explore Governance Analysis]]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Follow the chronological narrative of events that revealed governance gaps.&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Dive into structured analysis using the Green Book framework.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{About}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | 🏠 &#039;&#039;&#039;Main Page&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=376</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=376"/>
		<updated>2026-08-13T22:48:14Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Arizona Compliance Review and Corrective Action Framework =&lt;br /&gt;
&lt;br /&gt;
The purpose of this framework is to describe the key elements of an effective citizen complaint, compliance review, and corrective action process for Arizona counties which may include state entities. It presents a practical governance framework that promotes transparency, accountability, consistency, and continuous improvement while strengthening public confidence in local/county/state government.&lt;br /&gt;
&lt;br /&gt;
Rather than creating new compliance standards, this framework applies well-established compliance review principles already used throughout government and private industry to citizen-identified governance concerns. It describes the essential components of an objective compliance review process, outlines the lifecycle of an effective complaint and corrective action program, and establishes the governance principles necessary to ensure significant citizen concerns are evaluated consistently, documented objectively, and resolved through a structured process.&lt;br /&gt;
&lt;br /&gt;
== Start Your Journey ==&lt;br /&gt;
Choose your path:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[The Story|📖 Read The Story]]&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[Governance Analysis|📊 Explore Governance Analysis]]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Follow the chronological narrative of events that revealed governance gaps.&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Dive into structured analysis using the Green Book framework.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{About}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | 🏠 &#039;&#039;&#039;Main Page&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Principle_11_-_Design_General_Control_Activities_over_Information#11.11|link]]&lt;br /&gt;
[[File:test.jpg]]&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=375</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=375"/>
		<updated>2026-08-13T22:47:48Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Arizona Compliance Review and Corrective Action Framework =&lt;br /&gt;
&lt;br /&gt;
The purpose of this framework is to describe the key elements of an effective citizen complaint, compliance review, and corrective action process for Arizona counties which may include state entities. It presents a practical governance framework that promotes transparency, accountability, consistency, and continuous improvement while strengthening public confidence in local/county/state government.&lt;br /&gt;
&lt;br /&gt;
Rather than creating new compliance standards, this framework applies well-established compliance review principles already used throughout government and private industry to citizen-identified governance concerns. It describes the essential components of an objective compliance review process, outlines the lifecycle of an effective complaint and corrective action program, and establishes the governance principles necessary to ensure significant citizen concerns are evaluated consistently, documented objectively, and resolved through a structured process.&lt;br /&gt;
&lt;br /&gt;
== Start Your Journey ==&lt;br /&gt;
Choose your path:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[The Story|📖 Read The Story]]&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[Governance Analysis|📊 Explore Governance Analysis]]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Follow the chronological narrative of events that revealed governance gaps.&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Dive into structured analysis using the Green Book framework.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{About}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | 🏠 &#039;&#039;&#039;Main Page&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Principle_11_-_Design_General_Control_Activities_over_Information#11.11|link]]&lt;br /&gt;
[[File:File.jpg]]&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=374</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=374"/>
		<updated>2026-08-13T22:47:13Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Arizona Compliance Review and Corrective Action Framework =&lt;br /&gt;
&lt;br /&gt;
The purpose of this framework is to describe the key elements of an effective citizen complaint, compliance review, and corrective action process for Arizona counties which may include state entities. It presents a practical governance framework that promotes transparency, accountability, consistency, and continuous improvement while strengthening public confidence in local/county/state government.&lt;br /&gt;
&lt;br /&gt;
Rather than creating new compliance standards, this framework applies well-established compliance review principles already used throughout government and private industry to citizen-identified governance concerns. It describes the essential components of an objective compliance review process, outlines the lifecycle of an effective complaint and corrective action program, and establishes the governance principles necessary to ensure significant citizen concerns are evaluated consistently, documented objectively, and resolved through a structured process.&lt;br /&gt;
&lt;br /&gt;
== Start Your Journey ==&lt;br /&gt;
Choose your path:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[The Story|📖 Read The Story]]&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[Governance Analysis|📊 Explore Governance Analysis]]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Follow the chronological narrative of events that revealed governance gaps.&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Dive into structured analysis using the Green Book framework.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{About}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | 🏠 &#039;&#039;&#039;Main Page&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Principle_11_-_Design_General_Control_Activities_over_Information#11.11|link]]&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_17_-_Evaluate_Issues_and_Remediate_Deficiencies&amp;diff=369</id>
		<title>Principle 17 - Evaluate Issues and Remediate Deficiencies</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_17_-_Evaluate_Issues_and_Remediate_Deficiencies&amp;diff=369"/>
		<updated>2026-08-13T22:28:15Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 17.0 Evaluate Issues and Remediate Deficiencies ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-17-evaluate-issues-and-remediate-deficiencies/ External Link to US GAO Green Book Principle 17]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should remediate identified internal control deficiencies on a timely basis.&lt;br /&gt;
&lt;br /&gt;
=== 17.1 Reporting of Issues ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.02&#039;&#039;&#039; ====&lt;br /&gt;
Personnel report internal control issues through established reporting lines to the appropriate internal and external parties on a timely basis to enable the entity to promptly evaluate those issues and complete corrective action to remediate issues that rise to the level of internal control deficiencies.&lt;br /&gt;
 I don’t think we can support a deviation for this because we didn’t ask for CAP documents in the original PRR. Did you ask for CAP documents?&lt;br /&gt;
 &lt;br /&gt;
 If so, who, what, when, where, how?&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.03&#039;&#039;&#039; ====&lt;br /&gt;
Personnel may identify internal control issues while performing their assigned internal control responsibilities. Personnel communicate these issues internally to the person in the key role responsible for the internal control or associated process and, when appropriate, to at least one level of management above that individual. Depending on the nature of the issues, personnel may consider reporting certain issues to the oversight body or an established hotline. Such issues may include&lt;br /&gt;
&lt;br /&gt;
* issues that cut across the organizational structure or extend outside the entity to service organizations, contractors, or suppliers and issues that may not be remediated because of the interests of management, such as sensitive information regarding fraud or other illegal acts.&lt;br /&gt;
&lt;br /&gt;
 We have no documentation of this, but the Covid-19 Pandemic likely caused issues that cut across organizational boundaries&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.04&#039;&#039;&#039; ====&lt;br /&gt;
Depending on the entity’s regulatory or compliance requirements, the entity may also be required to report issues externally to appropriate external parties, such as the legislators, regulators, and standard-setting.&lt;br /&gt;
 I don’t think we have a deviation here.&lt;br /&gt;
&lt;br /&gt;
=== 17.2 Evaluation of Issues ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.05&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates and documents internal control issues and determines appropriate corrective actions for internal control deficiencies, including those reported from internal and external audits and evaluations, on a timely basis [documentation requirement]. Management evaluates issues identified through monitoring activities or reported by personnel to determine whether any of the issues rise to the level of an internal control deficiency. Internal control deficiencies require further evaluation and remediation by management. An internal control deficiency can be in the design, implementation, or operating effectiveness of the internal control and its related process. Management determines from the type of internal control deficiency the appropriate corrective actions to remediate it on a timely basis.&lt;br /&gt;
 &#039;&#039;&#039;April 15, 2025: Public Records Request&#039;&#039;&#039; – There was no objective evidence was found to confirm an Maricopa evaluated any of the election anomalies that necessitated portions of the contracts to be stricken through and amendments added.&lt;br /&gt;
 &lt;br /&gt;
 Contrary to the Green Book, there was no documentation of the evaluation of the unexpected Covid-19 pandemic conditions that necessitate contract revisions.&lt;br /&gt;
&lt;br /&gt;
=== 17.3 Corrective Actions ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.06&#039;&#039;&#039; ====&lt;br /&gt;
Management completes and documents corrective actions to remediate internal control deficiencies, including those reported from internal and external audits and evaluations, on a timely basis [documentation requirement]. Depending on the nature of the deficiency, either the oversight body or management oversees the prompt remediation of deficiencies by communicating the corrective actions to the appropriate level of the organizational structure and delegating authority for completing corrective actions to appropriate personnel. Documentation of corrective actions may include&lt;br /&gt;
&lt;br /&gt;
* root cause analysis,&lt;br /&gt;
* planned actions,&lt;br /&gt;
* interim milestones,&lt;br /&gt;
* completion dates,&lt;br /&gt;
* measurable indicators of compliance and remediation to assess and validate progress throughout the remediation process, and the entity official responsible for monitoring the status of the corrective actions.&lt;br /&gt;
&lt;br /&gt;
 &#039;&#039;&#039;April 15, 2025: Public Records Request&#039;&#039;&#039; – It could be debated as to whether the election-related contracts were revised as Corrective Action. However, no documentation was found to suggest these changes were implemented as corrective action to a formal evaluation.&lt;br /&gt;
 &lt;br /&gt;
 Contrary to the Green Book, no documentation was found to attribute the contract changes as corrective action to a formal evaluation.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.07&#039;&#039;&#039; ====&lt;br /&gt;
Corrective actions may include changes to controls within each of the five components of internal control, such as providing training on identified risks or modifying or adding control activities. Management also updates the entity’s periodic risk assessment based on the results of monitoring activities and may consider performing ongoing risk assessments when internal control deficiencies are identified.&lt;br /&gt;
 This will not make the list of Green Book deviations; it’s a permissive statement, “corrective actions may…”&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.08&#039;&#039;&#039; ====&lt;br /&gt;
Corrective actions also include remediating audit and evaluation findings. The remediation process begins when audit or other review results are reported to management. It is completed only after action has been taken that (1) corrects identified deficiencies, (2) produces improvements, or (3) demonstrates that the findings and recommendations do not warrant management action. Management, with oversight from the oversight body, monitors the status of remediation efforts so that they are completed on a timely basis.&lt;br /&gt;
 I can’t see this being a deviation&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins — No Corrective Actions]]&lt;br /&gt;
* [[December 2024: Gaining Support|📋 December 2024: Seeking Remediation]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_17_-_Evaluate_Issues_and_Remediate_Deficiencies&amp;diff=368</id>
		<title>Principle 17 - Evaluate Issues and Remediate Deficiencies</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_17_-_Evaluate_Issues_and_Remediate_Deficiencies&amp;diff=368"/>
		<updated>2026-08-13T22:28:01Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 17.0 Evaluate Issues and Remediate Deficiencies ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-17-evaluate-issues-and-remediate-deficiencies/ External Link to US GAO Green Book Principle 17]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should remediate identified internal control deficiencies on a timely basis.&lt;br /&gt;
&lt;br /&gt;
=== 17.1 Reporting of Issues ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.02&#039;&#039;&#039; ====&lt;br /&gt;
Personnel report internal control issues through established reporting lines to the appropriate internal and external parties on a timely basis to enable the entity to promptly evaluate those issues and complete corrective action to remediate issues that rise to the level of internal control deficiencies.&lt;br /&gt;
 I don’t think we can support a deviation for this because we didn’t ask for CAP documents in the original PRR. Did you ask for CAP documents?&lt;br /&gt;
 &lt;br /&gt;
 If so, who, what, when, where, how?&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.03&#039;&#039;&#039; ====&lt;br /&gt;
Personnel may identify internal control issues while performing their assigned internal control responsibilities. Personnel communicate these issues internally to the person in the key role responsible for the internal control or associated process and, when appropriate, to at least one level of management above that individual. Depending on the nature of the issues, personnel may consider reporting certain issues to the oversight body or an established hotline. Such issues may include&lt;br /&gt;
&lt;br /&gt;
* issues that cut across the organizational structure or extend outside the entity to service organizations, contractors, or suppliers and issues that may not be remediated because of the interests of management, such as sensitive information regarding fraud or other illegal acts.&lt;br /&gt;
&lt;br /&gt;
 We have no documentation of this, but the Covid-19 Pandemic likely caused issues that cut across organizational boundaries&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.04&#039;&#039;&#039; ====&lt;br /&gt;
Depending on the entity’s regulatory or compliance requirements, the entity may also be required to report issues externally to appropriate external parties, such as the legislators, regulators, and standard-setting.&lt;br /&gt;
 I don’t think we have a deviation here.&lt;br /&gt;
&lt;br /&gt;
=== 17.2 Evaluation of Issues ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.05&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates and documents internal control issues and determines appropriate corrective actions for internal control deficiencies, including those reported from internal and external audits and evaluations, on a timely basis [documentation requirement]. Management evaluates issues identified through monitoring activities or reported by personnel to determine whether any of the issues rise to the level of an internal control deficiency. Internal control deficiencies require further evaluation and remediation by management. An internal control deficiency can be in the design, implementation, or operating effectiveness of the internal control and its related process. Management determines from the type of internal control deficiency the appropriate corrective actions to remediate it on a timely basis.&lt;br /&gt;
 &#039;&#039;&#039;April 15, 2025: Public Records Request&#039;&#039;&#039; – There was no objective evidence was found to confirm an Maricopa evaluated any of the election anomalies that necessitated portions of the contracts to be stricken through and amendments added.&lt;br /&gt;
 &lt;br /&gt;
 Contrary to the Green Book, there was no documentation of the evaluation of the unexpected Covid-19 pandemic conditions that necessitate contract revisions.&lt;br /&gt;
&lt;br /&gt;
=== 17.3 Corrective Actions ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.06&#039;&#039;&#039; ====&lt;br /&gt;
Management completes and documents corrective actions to remediate internal control deficiencies, including those reported from internal and external audits and evaluations, on a timely basis [documentation requirement]. Depending on the nature of the deficiency, either the oversight body or management oversees the prompt remediation of deficiencies by communicating the corrective actions to the appropriate level of the organizational structure and delegating authority for completing corrective actions to appropriate personnel. Documentation of corrective actions may include&lt;br /&gt;
&lt;br /&gt;
* root cause analysis,&lt;br /&gt;
* planned actions,&lt;br /&gt;
* interim milestones,&lt;br /&gt;
* completion dates,&lt;br /&gt;
* measurable indicators of compliance and remediation to assess and validate progress throughout the remediation process, and the entity official responsible for monitoring the status of the corrective actions.&lt;br /&gt;
&lt;br /&gt;
 &#039;&#039;&#039;April 15, 2025: Public Records Request&#039;&#039;&#039; – It could be debated as to whether the election-related contracts were revised as Corrective Action. However, no documentation was found to suggest these changes were implemented as corrective action to a formal evaluation.&lt;br /&gt;
 &lt;br /&gt;
 Contrary to the Green Book, no documentation was found to attribute the contract changes as corrective action to a formal evaluation.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.07&#039;&#039;&#039; ====&lt;br /&gt;
Corrective actions may include changes to controls within each of the five components of internal control, such as providing training on identified risks or modifying or adding control activities. Management also updates the entity’s periodic risk assessment based on the results of monitoring activities and may consider performing ongoing risk assessments when internal control deficiencies are identified.&lt;br /&gt;
 This will not make the list of Green Book deviations; it’s a permissive statement, “corrective actions may…”&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.08&#039;&#039;&#039; ====&lt;br /&gt;
Corrective actions also include remediating audit and evaluation findings. The remediation process begins when audit or other review results are reported to management. It is completed only after action has been taken that (1) corrects identified deficiencies, (2) produces improvements, or (3) demonstrates that the findings and recommendations do not warrant management action. Management, with oversight from the oversight body, monitors the status of remediation efforts so that they are completed on a timely basis.&lt;br /&gt;
 I can’t see this being a deviation&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
=== Related Story Events ===&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins — No Corrective Actions]]&lt;br /&gt;
* [[December 2024: Gaining Support|📋 December 2024: Seeking Remediation]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_17_-_Evaluate_Issues_and_Remediate_Deficiencies&amp;diff=367</id>
		<title>Principle 17 - Evaluate Issues and Remediate Deficiencies</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_17_-_Evaluate_Issues_and_Remediate_Deficiencies&amp;diff=367"/>
		<updated>2026-08-13T22:27:13Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 17.0 Evaluate Issues and Remediate Deficiencies ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-17-evaluate-issues-and-remediate-deficiencies/ External Link to US GAO Green Book Principle 17]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should remediate identified internal control deficiencies on a timely basis.&lt;br /&gt;
&lt;br /&gt;
=== 17.1 Reporting of Issues ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.02&#039;&#039;&#039; ====&lt;br /&gt;
Personnel report internal control issues through established reporting lines to the appropriate internal and external parties on a timely basis to enable the entity to promptly evaluate those issues and complete corrective action to remediate issues that rise to the level of internal control deficiencies.&lt;br /&gt;
 I don’t think we can support a deviation for this because we didn’t ask for CAP documents in the original PRR. Did you ask for CAP documents?&lt;br /&gt;
 &lt;br /&gt;
 If so, who, what, when, where, how?&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.03&#039;&#039;&#039; ====&lt;br /&gt;
Personnel may identify internal control issues while performing their assigned internal control responsibilities. Personnel communicate these issues internally to the person in the key role responsible for the internal control or associated process and, when appropriate, to at least one level of management above that individual. Depending on the nature of the issues, personnel may consider reporting certain issues to the oversight body or an established hotline. Such issues may include&lt;br /&gt;
&lt;br /&gt;
* issues that cut across the organizational structure or extend outside the entity to service organizations, contractors, or suppliers and issues that may not be remediated because of the interests of management, such as sensitive information regarding fraud or other illegal acts.&lt;br /&gt;
&lt;br /&gt;
 We have no documentation of this, but the Covid-19 Pandemic likely caused issues that cut across organizational boundaries&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.04&#039;&#039;&#039; ====&lt;br /&gt;
Depending on the entity’s regulatory or compliance requirements, the entity may also be required to report issues externally to appropriate external parties, such as the legislators, regulators, and standard-setting.&lt;br /&gt;
 I don’t think we have a deviation here.&lt;br /&gt;
&lt;br /&gt;
=== 17.2 Evaluation of Issues ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.05&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates and documents internal control issues and determines appropriate corrective actions for internal control deficiencies, including those reported from internal and external audits and evaluations, on a timely basis [documentation requirement]. Management evaluates issues identified through monitoring activities or reported by personnel to determine whether any of the issues rise to the level of an internal control deficiency. Internal control deficiencies require further evaluation and remediation by management. An internal control deficiency can be in the design, implementation, or operating effectiveness of the internal control and its related process. Management determines from the type of internal control deficiency the appropriate corrective actions to remediate it on a timely basis.&lt;br /&gt;
 &#039;&#039;&#039;April 15, 2025: Public Records Request&#039;&#039;&#039; – There was no objective evidence was found to confirm an Maricopa evaluated any of the election anomalies that necessitated portions of the contracts to be stricken through and amendments added.&lt;br /&gt;
 &lt;br /&gt;
 Contrary to the Green Book, there was no documentation of the evaluation of the unexpected Covid-19 pandemic conditions that necessitate contract revisions.&lt;br /&gt;
&lt;br /&gt;
=== 17.3 Corrective Actions ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.06&#039;&#039;&#039; ====&lt;br /&gt;
Management completes and documents corrective actions to remediate internal control deficiencies, including those reported from internal and external audits and evaluations, on a timely basis [documentation requirement]. Depending on the nature of the deficiency, either the oversight body or management oversees the prompt remediation of deficiencies by communicating the corrective actions to the appropriate level of the organizational structure and delegating authority for completing corrective actions to appropriate personnel. Documentation of corrective actions may include&lt;br /&gt;
&lt;br /&gt;
* root cause analysis,&lt;br /&gt;
* planned actions,&lt;br /&gt;
* interim milestones,&lt;br /&gt;
* completion dates,&lt;br /&gt;
* measurable indicators of compliance and remediation to assess and validate progress throughout the remediation process, and the entity official responsible for monitoring the status of the corrective actions.&lt;br /&gt;
&lt;br /&gt;
 &#039;&#039;&#039;April 15, 2025: Public Records Request&#039;&#039;&#039; – It could be debated as to whether the election-related contracts were revised as Corrective Action. However, no documentation was found to suggest these changes were implemented as corrective action to a formal evaluation.&lt;br /&gt;
 &lt;br /&gt;
 Contrary to the Green Book, no documentation was found to attribute the contract changes as corrective action to a formal evaluation.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.07&#039;&#039;&#039; ====&lt;br /&gt;
Corrective actions may include changes to controls within each of the five components of internal control, such as providing training on identified risks or modifying or adding control activities. Management also updates the entity’s periodic risk assessment based on the results of monitoring activities and may consider performing ongoing risk assessments when internal control deficiencies are identified.&lt;br /&gt;
 This will not make the list of Green Book deviations; it’s a permissive statement, “corrective actions may…”&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;17.08&#039;&#039;&#039; ====&lt;br /&gt;
Corrective actions also include remediating audit and evaluation findings. The remediation process begins when audit or other review results are reported to management. It is completed only after action has been taken that (1) corrects identified deficiencies, (2) produces improvements, or (3) demonstrates that the findings and recommendations do not warrant management action. Management, with oversight from the oversight body, monitors the status of remediation efforts so that they are completed on a timely basis.&lt;br /&gt;
 I can’t see this being a deviation&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins — No Corrective Actions]]&lt;br /&gt;
* [[December 2024: Gaining Support|📋 December 2024: Seeking Remediation]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_16_-_Perform_Monitoring_Activities&amp;diff=366</id>
		<title>Principle 16 - Perform Monitoring Activities</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_16_-_Perform_Monitoring_Activities&amp;diff=366"/>
		<updated>2026-08-13T22:24:34Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 16.0 Perform Monitoring Activities ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-16-perform-monitoring-activities/ External Link to US GAO Green Book Principle 16]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results.&lt;br /&gt;
&lt;br /&gt;
=== 16.1 Establishment of a Baseline ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.02&#039;&#039;&#039; ====&lt;br /&gt;
Monitoring activities evaluate whether each of the five components of internal control, including controls to effect the principles within each component, is present and functioning or if change is needed. Management establishes a baseline to monitor the internal control system. The baseline is the current state of the internal control system compared against management’s design of the internal control system. The baseline represents the difference between the criteria for the design of the internal control system and the condition of the internal control system at a specific point in time. In other words, the baseline consists of issues and deficiencies identified in an entity’s internal control system.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.03&#039;&#039;&#039; ====&lt;br /&gt;
Once established, management can use the baseline as criteria in evaluating the internal control system and make changes to reduce the difference between the criteria and condition. Management reduces this difference in one of two ways. Management either changes the design of the internal control system to better address the objectives and risks of the entity or improves the operating effectiveness of the internal control system. As part of monitoring, management determines when to revise the baseline to reflect changes in the internal control system.&lt;br /&gt;
&lt;br /&gt;
=== 16.2 Internal Control System Monitoring ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.04&#039;&#039;&#039; ====&lt;br /&gt;
Management monitors the internal control system through ongoing monitoring and separate evaluations. Ongoing monitoring is built into the entity’s operations, performed continually, and responsive to change. Separate evaluations are performed periodically and may provide feedback on the effectiveness of ongoing monitoring. Many of the methods and tools described below may be used for both ongoing monitoring and separate evaluations, depending on when and how they are implemented.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.05&#039;&#039;&#039; ====&lt;br /&gt;
Management performs ongoing monitoring of the design and operating effectiveness of the internal control system as part of the normal course of operations. Ongoing monitoring includes regular management and supervisory activities, comparisons, reconciliations, trend analysis, data analytics, activities to identify improper payments or potential fraud, testing, and other routine actions. Ongoing monitoring may include automated tools, which can increase objectivity and efficiency by electronically compiling evaluations of controls and transactions or by automating data analytics.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.06&#039;&#039;&#039; ====&lt;br /&gt;
Management uses separate evaluations to monitor the design and operating effectiveness of the overall internal control system at a specific time or of a specific function or process. The scope and frequency of separate evaluations depend primarily on the assessment of risks, risk responses, evolving technology, identification of new risks or deficiencies, results of ongoing monitoring, and rate of change within the entity and its environment. Management may also increase the frequency of separate evaluations when management rapidly implements a new program or substantially changes an existing one, such as emergency assistance programs. Separate evaluations include observations, inquiries, reviews, improper payment estimates, and other examinations, as appropriate. These evaluate whether controls to effect principles across the entity are designed, implemented, and operating effectively. Separate evaluations may also take the form of self-assessments, which include crossoperating unit or cross-functional evaluations.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.07&#039;&#039;&#039; ====&lt;br /&gt;
Management also uses the results of separate evaluations performed in connection with internal and external audits, investigations, and other evaluations that may involve the review of internal control design and testing of internal controls to help identify issues in the internal control system. These audits and other evaluations may be mandated by law and are performed by internal auditors, external auditors, inspectors general, and other reviewers. Separate evaluations provide greater objectivity when performed by reviewers who do not have responsibility for the activities being evaluated.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.08&#039;&#039;&#039; ====&lt;br /&gt;
Management retains responsibility for monitoring the effectiveness of controls performed by service organizations that are necessary for the entity to achieve its control objectives. Management uses ongoing monitoring, separate evaluations, or a combination of the two to obtain reasonable assurance of the operating effectiveness of a service organization’s internal controls over the assigned process. Monitoring activities related to service organizations may include the use of work performed by external parties, such as service auditors, and reviewed by management.&lt;br /&gt;
&lt;br /&gt;
=== 16.3 Evaluation of Results ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.09&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates and documents the results of ongoing monitoring and separate evaluations to identify internal control issues &#039;&#039;&#039;[documentation requirement].&#039;&#039;&#039; Management uses this evaluation to determine the effectiveness of the internal control system. Differences between the results of monitoring activities and the previously established baseline may indicate internal control issues, including undocumented changes in the internal control system or potential internal control deficiencies.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.10&#039;&#039;&#039; ====&lt;br /&gt;
Management identifies changes in the internal control system that either have occurred or are needed because of changes in the entity and its environment. External parties can also help management identify issues in the internal control system. For example, complaints from the public, regulator comments, and findings from investigations may indicate areas in the internal control system that need improvement. Other external parties that interact with the entity, including relevant suppliers, contractors, and service organizations, may collaborate with management to identify and respond to issues in the entity’s business processes and related internal controls. Management considers whether current controls address the identified issues and modifies controls if necessary.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
=== Related Story Events ===&lt;br /&gt;
* [[2020: The Event|🗳️ 2020: The Event — Election Monitoring]]&lt;br /&gt;
* [[November 2024: Midterm Election|⚠️ November 2024: Midterm Election]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_16_-_Perform_Monitoring_Activities&amp;diff=365</id>
		<title>Principle 16 - Perform Monitoring Activities</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_16_-_Perform_Monitoring_Activities&amp;diff=365"/>
		<updated>2026-08-13T22:23:50Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 16.0 Perform Monitoring Activities ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-16-perform-monitoring-activities/ External Link to US GAO Green Book Principle 16]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results.&lt;br /&gt;
&lt;br /&gt;
=== 16.1 Establishment of a Baseline ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.02&#039;&#039;&#039; ====&lt;br /&gt;
Monitoring activities evaluate whether each of the five components of internal control, including controls to effect the principles within each component, is present and functioning or if change is needed. Management establishes a baseline to monitor the internal control system. The baseline is the current state of the internal control system compared against management’s design of the internal control system. The baseline represents the difference between the criteria for the design of the internal control system and the condition of the internal control system at a specific point in time. In other words, the baseline consists of issues and deficiencies identified in an entity’s internal control system.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.03&#039;&#039;&#039; ====&lt;br /&gt;
Once established, management can use the baseline as criteria in evaluating the internal control system and make changes to reduce the difference between the criteria and condition. Management reduces this difference in one of two ways. Management either changes the design of the internal control system to better address the objectives and risks of the entity or improves the operating effectiveness of the internal control system. As part of monitoring, management determines when to revise the baseline to reflect changes in the internal control system.&lt;br /&gt;
&lt;br /&gt;
=== 16.2 Internal Control System Monitoring ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.04&#039;&#039;&#039; ====&lt;br /&gt;
Management monitors the internal control system through ongoing monitoring and separate evaluations. Ongoing monitoring is built into the entity’s operations, performed continually, and responsive to change. Separate evaluations are performed periodically and may provide feedback on the effectiveness of ongoing monitoring. Many of the methods and tools described below may be used for both ongoing monitoring and separate evaluations, depending on when and how they are implemented.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.05&#039;&#039;&#039; ====&lt;br /&gt;
Management performs ongoing monitoring of the design and operating effectiveness of the internal control system as part of the normal course of operations. Ongoing monitoring includes regular management and supervisory activities, comparisons, reconciliations, trend analysis, data analytics, activities to identify improper payments or potential fraud, testing, and other routine actions. Ongoing monitoring may include automated tools, which can increase objectivity and efficiency by electronically compiling evaluations of controls and transactions or by automating data analytics.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.06&#039;&#039;&#039; ====&lt;br /&gt;
Management uses separate evaluations to monitor the design and operating effectiveness of the overall internal control system at a specific time or of a specific function or process. The scope and frequency of separate evaluations depend primarily on the assessment of risks, risk responses, evolving technology, identification of new risks or deficiencies, results of ongoing monitoring, and rate of change within the entity and its environment. Management may also increase the frequency of separate evaluations when management rapidly implements a new program or substantially changes an existing one, such as emergency assistance programs. Separate evaluations include observations, inquiries, reviews, improper payment estimates, and other examinations, as appropriate. These evaluate whether controls to effect principles across the entity are designed, implemented, and operating effectively. Separate evaluations may also take the form of self-assessments, which include crossoperating unit or cross-functional evaluations.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.07&#039;&#039;&#039; ====&lt;br /&gt;
Management also uses the results of separate evaluations performed in connection with internal and external audits, investigations, and other evaluations that may involve the review of internal control design and testing of internal controls to help identify issues in the internal control system. These audits and other evaluations may be mandated by law and are performed by internal auditors, external auditors, inspectors general, and other reviewers. Separate evaluations provide greater objectivity when performed by reviewers who do not have responsibility for the activities being evaluated.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.08&#039;&#039;&#039; ====&lt;br /&gt;
Management retains responsibility for monitoring the effectiveness of controls performed by service organizations that are necessary for the entity to achieve its control objectives. Management uses ongoing monitoring, separate evaluations, or a combination of the two to obtain reasonable assurance of the operating effectiveness of a service organization’s internal controls over the assigned process. Monitoring activities related to service organizations may include the use of work performed by external parties, such as service auditors, and reviewed by management.&lt;br /&gt;
&lt;br /&gt;
=== 16.3 Evaluation of Results ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.09&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates and documents the results of ongoing monitoring and separate evaluations to identify internal control issues &#039;&#039;&#039;[documentation requirement].&#039;&#039;&#039; Management uses this evaluation to determine the effectiveness of the internal control system. Differences between the results of monitoring activities and the previously established baseline may indicate internal control issues, including undocumented changes in the internal control system or potential internal control deficiencies.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;16.10&#039;&#039;&#039; ====&lt;br /&gt;
Management identifies changes in the internal control system that either have occurred or are needed because of changes in the entity and its environment. External parties can also help management identify issues in the internal control system. For example, complaints from the public, regulator comments, and findings from investigations may indicate areas in the internal control system that need improvement. Other external parties that interact with the entity, including relevant suppliers, contractors, and service organizations, may collaborate with management to identify and respond to issues in the entity’s business processes and related internal controls. Management considers whether current controls address the identified issues and modifies controls if necessary.{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2020: The Event|🗳️ 2020: The Event — Election Monitoring]]&lt;br /&gt;
* [[November 2024: Midterm Election|⚠️ November 2024: Midterm Election]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_15_-_Communicate_Externally&amp;diff=364</id>
		<title>Principle 15 - Communicate Externally</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_15_-_Communicate_Externally&amp;diff=364"/>
		<updated>2026-08-13T22:21:24Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 15.0 Communicate Externally ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-15-communicate-externally/ External Link to US GAO Green Book Principle 15]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should communicate relevant and quality information with appropriate external parties regarding matters impacting the functioning of the internal control system.&lt;br /&gt;
&lt;br /&gt;
=== 15.1 Communication with External Parties ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.02&#039;&#039;&#039; ====&lt;br /&gt;
Management communicates with, and obtains relevant and quality information from, appropriate external parties using established reporting lines. Open two-way external reporting lines allow for this communication. External parties may include service organizations, suppliers, contractors, regulators, regulated entities, external auditors, federal entities, state and local governments, grantees, and the public.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.03&#039;&#039;&#039; ====&lt;br /&gt;
Management communicates relevant and quality information externally through reporting lines so that appropriate external parties can help the entity achieve its objectives, address related risks, and support its internal control system. Information communicated by management includes significant matters relating to the entity’s events and activities that impact its internal control system. For instance, information communicated to service organizations may include information on the entity’s objectives and ethical values, identified risks, internal control practices to consider, and performance metrics. Information communicated for the entity to achieve program-related objectives may include information on eligibility, reporting, and audit requirements for recipients of federal financial assistance and legal and regulatory requirements to regulated entities.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.04&#039;&#039;&#039; ====&lt;br /&gt;
Management obtains information through reporting lines from external parties. Information communicated to management includes significant matters relating to risks, changes, or issues that impact the entity’s internal control system. Communication may also include information for the entity to achieve program-related objectives. These communications are necessary for the effective operation of internal control. Management evaluates external information obtained against the characteristics of quality information and information processing objectives and takes any necessary actions so that the information is quality information.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.05&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body obtains information through reporting lines from external parties. Information communicated to the oversight body includes significant matters relating to risks, changes, and issues that impact the entity’s internal control system. This communication is necessary for the effective oversight of internal control.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.06&#039;&#039;&#039; ====&lt;br /&gt;
External parties use separate reporting lines when external reporting lines are compromised. Laws and regulations may require entities to establish separate lines of communication, such as whistleblower and ethics hotlines, for communicating confidential information. Management informs external parties of these separate reporting lines, how they operate, how they are to be used, and how the information will remain confidential.&lt;br /&gt;
&lt;br /&gt;
=== 15.2 Appropriate Methods of Communication ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.07&#039;&#039;&#039; ====&lt;br /&gt;
Management selects appropriate methods for communicating externally. Management considers a variety of factors in selecting an appropriate method of communication. &lt;br /&gt;
&lt;br /&gt;
Some factors to consider follow:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Audience&#039;&#039;&#039; - The intended recipients of the communication.&lt;br /&gt;
* &#039;&#039;&#039;Nature of information&#039;&#039;&#039; - The purpose and type of information being communicated.&lt;br /&gt;
* &#039;&#039;&#039;Availability&#039;&#039;&#039; - Information readily available to the audience when needed.&lt;br /&gt;
* &#039;&#039;&#039;Cost&#039;&#039;&#039; - The resources used to communicate the information.&lt;br /&gt;
* &#039;&#039;&#039;Legal or regulatory requirements&#039;&#039;&#039; - Requirements in laws and regulations that may impact communication.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.08&#039;&#039;&#039; ====&lt;br /&gt;
Based on consideration of the factors, management selects appropriate methods of communication. Management evaluates the entity’s methods of communication on a periodic and ongoing basis so that the organization has the appropriate tools to communicate quality information throughout and outside of the entity on a timely basis.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.09&#039;&#039;&#039; ====&lt;br /&gt;
Government entities not only report to the head of the government, legislators, and regulators but to the public as well. In the federal government, entities not only report to the President and Congress but also to the public. Entities consider appropriate methods for communicating with such a broad audience.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
=== Related Story Events ===&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins — Citizen Inquiries]]&lt;br /&gt;
* [[December 2024: Gaining Support|📋 December 2024: Gaining Support]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_15_-_Communicate_Externally&amp;diff=363</id>
		<title>Principle 15 - Communicate Externally</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_15_-_Communicate_Externally&amp;diff=363"/>
		<updated>2026-08-13T22:20:53Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 15.0 Communicate Externally ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-15-communicate-externally/ External Link to US GAO Green Book Principle 15]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should communicate relevant and quality information with appropriate external parties regarding matters impacting the functioning of the internal control system.&lt;br /&gt;
&lt;br /&gt;
=== 15.1 Communication with External Parties ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.02&#039;&#039;&#039; ====&lt;br /&gt;
Management communicates with, and obtains relevant and quality information from, appropriate external parties using established reporting lines. Open two-way external reporting lines allow for this communication. External parties may include service organizations, suppliers, contractors, regulators, regulated entities, external auditors, federal entities, state and local governments, grantees, and the public.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.03&#039;&#039;&#039; ====&lt;br /&gt;
Management communicates relevant and quality information externally through reporting lines so that appropriate external parties can help the entity achieve its objectives, address related risks, and support its internal control system. Information communicated by management includes significant matters relating to the entity’s events and activities that impact its internal control system. For instance, information communicated to service organizations may include information on the entity’s objectives and ethical values, identified risks, internal control practices to consider, and performance metrics. Information communicated for the entity to achieve program-related objectives may include information on eligibility, reporting, and audit requirements for recipients of federal financial assistance and legal and regulatory requirements to regulated entities.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.04&#039;&#039;&#039; ====&lt;br /&gt;
Management obtains information through reporting lines from external parties. Information communicated to management includes significant matters relating to risks, changes, or issues that impact the entity’s internal control system. Communication may also include information for the entity to achieve program-related objectives. These communications are necessary for the effective operation of internal control. Management evaluates external information obtained against the characteristics of quality information and information processing objectives and takes any necessary actions so that the information is quality information.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.05&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body obtains information through reporting lines from external parties. Information communicated to the oversight body includes significant matters relating to risks, changes, and issues that impact the entity’s internal control system. This communication is necessary for the effective oversight of internal control.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.06&#039;&#039;&#039; ====&lt;br /&gt;
External parties use separate reporting lines when external reporting lines are compromised. Laws and regulations may require entities to establish separate lines of communication, such as whistleblower and ethics hotlines, for communicating confidential information. Management informs external parties of these separate reporting lines, how they operate, how they are to be used, and how the information will remain confidential.&lt;br /&gt;
&lt;br /&gt;
=== 15.2 Appropriate Methods of Communication ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.07&#039;&#039;&#039; ====&lt;br /&gt;
Management selects appropriate methods for communicating externally. Management considers a variety of factors in selecting an appropriate method of communication. &lt;br /&gt;
&lt;br /&gt;
Some factors to consider follow:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Audience&#039;&#039;&#039; - The intended recipients of the communication.&lt;br /&gt;
* &#039;&#039;&#039;Nature of information&#039;&#039;&#039; - The purpose and type of information being communicated.&lt;br /&gt;
* &#039;&#039;&#039;Availability&#039;&#039;&#039; - Information readily available to the audience when needed.&lt;br /&gt;
* &#039;&#039;&#039;Cost&#039;&#039;&#039; - The resources used to communicate the information.&lt;br /&gt;
* &#039;&#039;&#039;Legal or regulatory requirements&#039;&#039;&#039; - Requirements in laws and regulations that may impact communication.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.08&#039;&#039;&#039; ====&lt;br /&gt;
Based on consideration of the factors, management selects appropriate methods of communication. Management evaluates the entity’s methods of communication on a periodic and ongoing basis so that the organization has the appropriate tools to communicate quality information throughout and outside of the entity on a timely basis.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;15.09&#039;&#039;&#039; ====&lt;br /&gt;
Government entities not only report to the head of the government, legislators, and regulators but to the public as well. In the federal government, entities not only report to the President and Congress but also to the public. Entities consider appropriate methods for communicating with such a broad audience.{{Principles}}&lt;br /&gt;
&lt;br /&gt;
=== Related Story Events ===&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins — Citizen Inquiries]]&lt;br /&gt;
* [[December 2024: Gaining Support|📋 December 2024: Gaining Support]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_14_-_Communicate_Internally&amp;diff=362</id>
		<title>Principle 14 - Communicate Internally</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_14_-_Communicate_Internally&amp;diff=362"/>
		<updated>2026-08-13T22:18:11Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 14.0 Communicate Internally ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-14-communicate-internally/ External Link to US GAO Green Book Principle 14]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should internally communicate relevant and quality information, including objectives and responsibilities for internal control, necessary to support the functioning of the internal control system.&lt;br /&gt;
&lt;br /&gt;
=== 14.1 Communication Throughout the Entity ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.02&#039;&#039;&#039; ====&lt;br /&gt;
Management communicates relevant and quality information throughout the entity using established reporting lines. Communication is the continual, iterative process of providing, sharing, and obtaining necessary information. Quality information is communicated down, across, up, and around reporting lines to all levels of the entity.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.03&#039;&#039;&#039; ====&lt;br /&gt;
Management communicates relevant and quality information down and across reporting lines to enable personnel to understand and perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. Communications support the functioning of all five components of internal control and the achievement of the entity’s objectives. Communications may include legal and regulatory requirements, ethical values, the entity’s objectives, identified risks, policies and procedures that support personnel in performing their internal control responsibilities, and the results of monitoring activities that may include corrective actions to remediate internal control deficiencies.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.04&#039;&#039;&#039; ====&lt;br /&gt;
Management obtains relevant and quality information about the entity’s business processes that flows up the reporting lines from personnel to help management achieve the entity’s objectives. Information communicated by personnel may include internal control issues; this communication helps management identify internal control deficiencies and take corrective action.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.05&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body obtains relevant and quality information that flows up the reporting lines from management and other personnel. Information relating to internal control communicated to the oversight body includes significant matters about adherence to, changes in, or issues arising from the internal control system. This upward communication is necessary for the effective oversight of internal control.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.06&#039;&#039;&#039; ====&lt;br /&gt;
Personnel use separate reporting lines to go around upward reporting lines when these lines are compromised. Laws and regulations may require entities to establish separate lines of communication, such as whistleblower and ethics hotlines, for communicating confidential information. Management informs employees of these separate reporting lines, how they operate, how they are to be used, and how the information will remain confidential.&lt;br /&gt;
&lt;br /&gt;
=== 14.2 Appropriate Methods of Communication ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.07&#039;&#039;&#039; ====&lt;br /&gt;
Management selects appropriate methods for communicating internally. Management considers a variety of factors in selecting an appropriate method of communication. &lt;br /&gt;
&lt;br /&gt;
Some factors to consider follow:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Audience&#039;&#039;&#039; - The intended recipients of the communication.&lt;br /&gt;
* &#039;&#039;&#039;Nature of information&#039;&#039;&#039; - The purpose and type of information being communicated.&lt;br /&gt;
* &#039;&#039;&#039;Availability&#039;&#039;&#039; - Information readily available to the audience when needed.&lt;br /&gt;
* &#039;&#039;&#039;Cost&#039;&#039;&#039; - The resources used to communicate the information.&lt;br /&gt;
* &#039;&#039;&#039;Legal or regulatory requirements&#039;&#039;&#039; - Requirements in laws and regulations that may impact communication.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.08&#039;&#039;&#039; ====&lt;br /&gt;
Based on consideration of the factors, management selects appropriate methods of communication. Management evaluates the entity’s methods of communication on a periodic and ongoing basis so that the organization has the appropriate tools to communicate quality information throughout the entity on a timely basis.{{Principles}}&lt;br /&gt;
&lt;br /&gt;
=== Related Story Events ===&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins]]&lt;br /&gt;
* [[December 2024: Gaining Support|📋 December 2024: Resolution Submission]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_14_-_Communicate_Internally&amp;diff=361</id>
		<title>Principle 14 - Communicate Internally</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_14_-_Communicate_Internally&amp;diff=361"/>
		<updated>2026-08-13T22:17:44Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 14.0 Communicate Internally ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-14-communicate-internally/ External Link to US GAO Green Book Principle 14]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should internally communicate relevant and quality information, including objectives and responsibilities for internal control, necessary to support the functioning of the internal control system.&lt;br /&gt;
&lt;br /&gt;
=== 14.1 Communication Throughout the Entity ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.02&#039;&#039;&#039; ====&lt;br /&gt;
Management communicates relevant and quality information throughout the entity using established reporting lines. Communication is the continual, iterative process of providing, sharing, and obtaining necessary information. Quality information is communicated down, across, up, and around reporting lines to all levels of the entity.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.03&#039;&#039;&#039; ====&lt;br /&gt;
Management communicates relevant and quality information down and across reporting lines to enable personnel to understand and perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. Communications support the functioning of all five components of internal control and the achievement of the entity’s objectives. Communications may include legal and regulatory requirements, ethical values, the entity’s objectives, identified risks, policies and procedures that support personnel in performing their internal control responsibilities, and the results of monitoring activities that may include corrective actions to remediate internal control deficiencies.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.04&#039;&#039;&#039; ====&lt;br /&gt;
Management obtains relevant and quality information about the entity’s business processes that flows up the reporting lines from personnel to help management achieve the entity’s objectives. Information communicated by personnel may include internal control issues; this communication helps management identify internal control deficiencies and take corrective action.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.05&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body obtains relevant and quality information that flows up the reporting lines from management and other personnel. Information relating to internal control communicated to the oversight body includes significant matters about adherence to, changes in, or issues arising from the internal control system. This upward communication is necessary for the effective oversight of internal control.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.06&#039;&#039;&#039; ====&lt;br /&gt;
Personnel use separate reporting lines to go around upward reporting lines when these lines are compromised. Laws and regulations may require entities to establish separate lines of communication, such as whistleblower and ethics hotlines, for communicating confidential information. Management informs employees of these separate reporting lines, how they operate, how they are to be used, and how the information will remain confidential.&lt;br /&gt;
&lt;br /&gt;
=== 14.2 Appropriate Methods of Communication ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.07&#039;&#039;&#039; ====&lt;br /&gt;
Management selects appropriate methods for communicating internally. Management considers a variety of factors in selecting an appropriate method of communication. &lt;br /&gt;
&lt;br /&gt;
Some factors to consider follow:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Audience&#039;&#039;&#039; - The intended recipients of the communication.&lt;br /&gt;
* &#039;&#039;&#039;Nature of information&#039;&#039;&#039; - The purpose and type of information being communicated.&lt;br /&gt;
* &#039;&#039;&#039;Availability&#039;&#039;&#039; - Information readily available to the audience when needed.&lt;br /&gt;
* &#039;&#039;&#039;Cost&#039;&#039;&#039; - The resources used to communicate the information.&lt;br /&gt;
* &#039;&#039;&#039;Legal or regulatory requirements&#039;&#039;&#039; - Requirements in laws and regulations that may impact communication.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.08&#039;&#039;&#039; ====&lt;br /&gt;
Based on consideration of the factors, management selects appropriate methods of communication. Management evaluates the entity’s methods of communication on a periodic and ongoing basis so that the organization has the appropriate tools to communicate quality information throughout the entity on a timely basis.{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins]]&lt;br /&gt;
* [[December 2024: Gaining Support|📋 December 2024: Resolution Submission]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_14_-_Communicate_Internally&amp;diff=360</id>
		<title>Principle 14 - Communicate Internally</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_14_-_Communicate_Internally&amp;diff=360"/>
		<updated>2026-08-13T22:17:30Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 14.0 Communicate Internally ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-14-communicate-internally/ External Link to US GAO Green Book Principle 14]&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should internally communicate relevant and quality information, including objectives and responsibilities for internal control, necessary to support the functioning of the internal control system.&lt;br /&gt;
&lt;br /&gt;
=== 14.1 Communication Throughout the Entity ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.02&#039;&#039;&#039; ====&lt;br /&gt;
Management communicates relevant and quality information throughout the entity using established reporting lines. Communication is the continual, iterative process of providing, sharing, and obtaining necessary information. Quality information is communicated down, across, up, and around reporting lines to all levels of the entity.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.03&#039;&#039;&#039; ====&lt;br /&gt;
Management communicates relevant and quality information down and across reporting lines to enable personnel to understand and perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. Communications support the functioning of all five components of internal control and the achievement of the entity’s objectives. Communications may include legal and regulatory requirements, ethical values, the entity’s objectives, identified risks, policies and procedures that support personnel in performing their internal control responsibilities, and the results of monitoring activities that may include corrective actions to remediate internal control deficiencies.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.04&#039;&#039;&#039; ====&lt;br /&gt;
Management obtains relevant and quality information about the entity’s business processes that flows up the reporting lines from personnel to help management achieve the entity’s objectives. Information communicated by personnel may include internal control issues; this communication helps management identify internal control deficiencies and take corrective action.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.05&#039;&#039;&#039; ====&lt;br /&gt;
The oversight body obtains relevant and quality information that flows up the reporting lines from management and other personnel. Information relating to internal control communicated to the oversight body includes significant matters about adherence to, changes in, or issues arising from the internal control system. This upward communication is necessary for the effective oversight of internal control.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.06&#039;&#039;&#039; ====&lt;br /&gt;
Personnel use separate reporting lines to go around upward reporting lines when these lines are compromised. Laws and regulations may require entities to establish separate lines of communication, such as whistleblower and ethics hotlines, for communicating confidential information. Management informs employees of these separate reporting lines, how they operate, how they are to be used, and how the information will remain confidential.&lt;br /&gt;
&lt;br /&gt;
=== 14.2 Appropriate Methods of Communication ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.07&#039;&#039;&#039; ====&lt;br /&gt;
Management selects appropriate methods for communicating internally. Management considers a variety of factors in selecting an appropriate method of communication. &lt;br /&gt;
&lt;br /&gt;
Some factors to consider follow:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Audience&#039;&#039;&#039; - The intended recipients of the communication.&lt;br /&gt;
* &#039;&#039;&#039;Nature of information&#039;&#039;&#039; - The purpose and type of information being communicated.&lt;br /&gt;
* &#039;&#039;&#039;Availability&#039;&#039;&#039; - Information readily available to the audience when needed.&lt;br /&gt;
* &#039;&#039;&#039;Cost&#039;&#039;&#039; - The resources used to communicate the information.&lt;br /&gt;
* &#039;&#039;&#039;Legal or regulatory requirements&#039;&#039;&#039; - Requirements in laws and regulations that may impact communication.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;14.08&#039;&#039;&#039; ====&lt;br /&gt;
Based on consideration of the factors, management selects appropriate methods of communication. Management evaluates the entity’s methods of communication on a periodic and ongoing basis so that the organization has the appropriate tools to communicate quality information throughout the entity on a timely basis.{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins]]&lt;br /&gt;
* [[December 2024: Gaining Support|📋 December 2024: Resolution Submission]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_14_-_Communicate_Internally&amp;diff=359</id>
		<title>Principle 14 - Communicate Internally</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_14_-_Communicate_Internally&amp;diff=359"/>
		<updated>2026-08-13T22:15:45Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 14.0 Communicate Internally ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-14-communicate-internally/ External Link to US GAO Green Book Principle 14]&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;14.01&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Management should internally communicate relevant and quality information, including objectives and responsibilities for internal control, necessary to support the functioning of the internal control system.&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== 14.1 Communication Throughout the Entity ===&lt;br /&gt;
&#039;&#039;&#039;14.02&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Management communicates relevant and quality information throughout the entity using established reporting lines.&#039;&#039;&#039; Communication is the continual, iterative process of providing, sharing, and obtaining necessary information. Quality information is communicated down, across, up, and around reporting lines to all levels of the entity.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;14.03&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Management communicates relevant and quality information down and across reporting lines to enable personnel to understand and perform key roles in achieving objectives, addressing risks, and supporting the internal control system.&#039;&#039;&#039; In these communications, management assigns the internal control responsibilities for key roles. Communications support the functioning of all five components of internal control and the achievement of the entity’s objectives. Communications may include legal and regulatory requirements, ethical values, the entity’s objectives, identified risks, policies and procedures that support personnel in performing their internal control responsibilities, and the results of monitoring activities that may include corrective actions to remediate internal control deficiencies.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;14.04&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Management obtains relevant and quality information about the entity’s business processes that flows up the reporting lines from personnel to help management achieve the entity’s objectives.&#039;&#039;&#039; Information communicated by personnel may include internal control issues; this communication helps management identify internal control deficiencies and take corrective action.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;14.05&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;The oversight body obtains relevant and quality information that flows up the reporting lines from management and other personnel.&#039;&#039;&#039; Information relating to internal control communicated to the oversight body includes significant matters about adherence to, changes in, or issues arising from the internal control system. This upward communication is necessary for the effective oversight of internal control.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;14.06&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Personnel use separate reporting lines to go around upward reporting lines when these lines are compromised.&#039;&#039;&#039; Laws and regulations may require entities to establish separate lines of communication, such as whistleblower and ethics hotlines, for communicating confidential information. Management informs employees of these separate reporting lines, how they operate, how they are to be used, and how the information will remain confidential.&lt;br /&gt;
&lt;br /&gt;
=== 14.2 Appropriate Methods of Communication ===&lt;br /&gt;
&#039;&#039;&#039;14.07&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Management selects appropriate methods for communicating internally. Management considers a variety of factors in selecting an appropriate method of communication.&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
Some factors to consider follow:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Audience&#039;&#039;&#039; - The intended recipients of the communication.&lt;br /&gt;
* &#039;&#039;&#039;Nature of information&#039;&#039;&#039; - The purpose and type of information being communicated.&lt;br /&gt;
* &#039;&#039;&#039;Availability&#039;&#039;&#039; - Information readily available to the audience when needed.&lt;br /&gt;
* &#039;&#039;&#039;Cost&#039;&#039;&#039; - The resources used to communicate the information.&lt;br /&gt;
* &#039;&#039;&#039;Legal or regulatory requirements&#039;&#039;&#039; - Requirements in laws and regulations that may impact communication.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;14.08&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Based on consideration of the factors, management selects appropriate methods of communication.&#039;&#039;&#039; Management evaluates the entity’s methods of communication on a periodic and ongoing basis so that the organization has the appropriate tools to communicate quality information throughout the entity on a timely basis.{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins]]&lt;br /&gt;
* [[December 2024: Gaining Support|📋 December 2024: Resolution Submission]]&lt;br /&gt;
* [[May 15, 2025: Let&#039;s Play Hot Potato|🥔 May 2025: PRR Runaround]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_13_-_Use_Quality_Information&amp;diff=358</id>
		<title>Principle 13 - Use Quality Information</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_13_-_Use_Quality_Information&amp;diff=358"/>
		<updated>2026-08-13T22:14:12Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 13.0 Use Quality Information ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-13-use-quality-information/ External Link to US GAO Green Book Principle 13]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should obtain or generate relevant, quality information and use it to support the functioning of the internal control system.&lt;br /&gt;
&lt;br /&gt;
=== 13.1 Identification of Information Requirements ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs a process that uses the entity’s objectives and related risks to identify the information requirements needed to support the internal control system. Information requirements consider the needs of both internal and external users. Management defines the identified information requirements at the relevant level and requisite specificity for appropriate personnel.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.03&#039;&#039;&#039; ====&lt;br /&gt;
Management identifies information requirements in an iterative and ongoing process that occurs throughout the design, implementation, and operation of an effective internal control system. An entity’s controls within the five components of internal control establish information requirements. As change in the entity and its objectives and risks occurs, management changes information requirements as needed to meet these modified objectives and address these modified risks. Management establishes information requirements through policies and procedures, with clear responsibility and accountability for the quality of information. These information requirements are communicated both internally and externally, such as with service organizations.&lt;br /&gt;
&lt;br /&gt;
=== 13.2 Relevant Data from Reliable Sources ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.04&#039;&#039;&#039; ====&lt;br /&gt;
Management obtains or generates relevant data from reliable internal and external sources in a timely manner based on the identified information requirements. Relevant data have a logical connection with, or bearing upon, the identified information requirements. Reliable internal and external sources provide data that are reasonably free from error and bias and faithfully represent what they purport to represent. Management evaluates both internal and external sources of data for reliability. Management obtains relevant data through a variety of forms, including using manual input or compilation, using information technology, or coordinating with other entities to obtain or access data.[1] Sources of data can be operational, reporting, or compliance related. Management obtains data on a timely basis so that they can be used for effective monitoring.&lt;br /&gt;
&lt;br /&gt;
=== 13.3 Data Processed into Quality Information ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.05&#039;&#039;&#039; ====&lt;br /&gt;
Management processes relevant data obtained or generated from reliable sources into quality information through the entity’s information system. The entity’s information system comprises the people, processes, data, and information technology that management uses to obtain, generate, communicate, or dispose of information to support the entity’s business processes.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.06&#039;&#039;&#039; ====&lt;br /&gt;
Management develops the entity’s information system to obtain, generate, and process relevant data into quality information to meet the identified information requirements needed to support the internal control system. Information processing can be manual, automated through the use of information technology, or a combination of both.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.07&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates the processed information to determine whether it is quality information. Quality information meets the identified information requirements when relevant data from reliable sources are used. Quality information is appropriate, current, complete, accurate, accessible, verifiable, retained as appropriate, and provided on a timely basis. Management considers these characteristics and the information processing and information security objectives in evaluating processed information, and makes revisions when necessary, so that the information is quality information. Management uses the quality information to make informed decisions and evaluate the entity’s performance in achieving key objectives, addressing risks, and fulfilling internal control responsibilities.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
=== Related Story Events ===&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins — Information Gaps]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_13_-_Use_Quality_Information&amp;diff=357</id>
		<title>Principle 13 - Use Quality Information</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_13_-_Use_Quality_Information&amp;diff=357"/>
		<updated>2026-08-13T22:13:55Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 13.0 Use Quality Information ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-13-use-quality-information/ External Link to US GAO Green Book Principle 13]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should obtain or generate relevant, quality information and use it to support the functioning of the internal control system.&lt;br /&gt;
&lt;br /&gt;
=== 13.1 Identification of Information Requirements ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs a process that uses the entity’s objectives and related risks to identify the information requirements needed to support the internal control system. Information requirements consider the needs of both internal and external users. Management defines the identified information requirements at the relevant level and requisite specificity for appropriate personnel.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.03&#039;&#039;&#039; ====&lt;br /&gt;
Management identifies information requirements in an iterative and ongoing process that occurs throughout the design, implementation, and operation of an effective internal control system. An entity’s controls within the five components of internal control establish information requirements. As change in the entity and its objectives and risks occurs, management changes information requirements as needed to meet these modified objectives and address these modified risks. Management establishes information requirements through policies and procedures, with clear responsibility and accountability for the quality of information. These information requirements are communicated both internally and externally, such as with service organizations.&lt;br /&gt;
&lt;br /&gt;
=== 13.2 Relevant Data from Reliable Sources ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.04&#039;&#039;&#039; ====&lt;br /&gt;
Management obtains or generates relevant data from reliable internal and external sources in a timely manner based on the identified information requirements. Relevant data have a logical connection with, or bearing upon, the identified information requirements. Reliable internal and external sources provide data that are reasonably free from error and bias and faithfully represent what they purport to represent. Management evaluates both internal and external sources of data for reliability. Management obtains relevant data through a variety of forms, including using manual input or compilation, using information technology, or coordinating with other entities to obtain or access data.[1] Sources of data can be operational, reporting, or compliance related. Management obtains data on a timely basis so that they can be used for effective monitoring.&lt;br /&gt;
&lt;br /&gt;
=== 13.3 Data Processed into Quality Information ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.05&#039;&#039;&#039; ====&lt;br /&gt;
Management processes relevant data obtained or generated from reliable sources into quality information through the entity’s information system. The entity’s information system comprises the people, processes, data, and information technology that management uses to obtain, generate, communicate, or dispose of information to support the entity’s business processes.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.06&#039;&#039;&#039; ====&lt;br /&gt;
Management develops the entity’s information system to obtain, generate, and process relevant data into quality information to meet the identified information requirements needed to support the internal control system. Information processing can be manual, automated through the use of information technology, or a combination of both.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.07&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates the processed information to determine whether it is quality information. Quality information meets the identified information requirements when relevant data from reliable sources are used. Quality information is appropriate, current, complete, accurate, accessible, verifiable, retained as appropriate, and provided on a timely basis. Management considers these characteristics and the information processing and information security objectives in evaluating processed information, and makes revisions when necessary, so that the information is quality information. Management uses the quality information to make informed decisions and evaluate the entity’s performance in achieving key objectives, addressing risks, and fulfilling internal control responsibilities.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
==== Related Story Events ====&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins — Information Gaps]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_13_-_Use_Quality_Information&amp;diff=356</id>
		<title>Principle 13 - Use Quality Information</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_13_-_Use_Quality_Information&amp;diff=356"/>
		<updated>2026-08-13T22:13:06Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 13.0 Use Quality Information ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-13-use-quality-information/ External Link to US GAO Green Book Principle 13]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should obtain or generate relevant, quality information and use it to support the functioning of the internal control system.&lt;br /&gt;
&lt;br /&gt;
=== 13.1 Identification of Information Requirements ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs a process that uses the entity’s objectives and related risks to identify the information requirements needed to support the internal control system. Information requirements consider the needs of both internal and external users. Management defines the identified information requirements at the relevant level and requisite specificity for appropriate personnel.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.03&#039;&#039;&#039; ====&lt;br /&gt;
Management identifies information requirements in an iterative and ongoing process that occurs throughout the design, implementation, and operation of an effective internal control system. An entity’s controls within the five components of internal control establish information requirements. As change in the entity and its objectives and risks occurs, management changes information requirements as needed to meet these modified objectives and address these modified risks. Management establishes information requirements through policies and procedures, with clear responsibility and accountability for the quality of information. These information requirements are communicated both internally and externally, such as with service organizations.&lt;br /&gt;
&lt;br /&gt;
=== 13.2 Relevant Data from Reliable Sources ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.04&#039;&#039;&#039; ====&lt;br /&gt;
Management obtains or generates relevant data from reliable internal and external sources in a timely manner based on the identified information requirements. Relevant data have a logical connection with, or bearing upon, the identified information requirements. Reliable internal and external sources provide data that are reasonably free from error and bias and faithfully represent what they purport to represent. Management evaluates both internal and external sources of data for reliability. Management obtains relevant data through a variety of forms, including using manual input or compilation, using information technology, or coordinating with other entities to obtain or access data.[1] Sources of data can be operational, reporting, or compliance related. Management obtains data on a timely basis so that they can be used for effective monitoring.&lt;br /&gt;
&lt;br /&gt;
=== 13.3 Data Processed into Quality Information ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.05&#039;&#039;&#039; ====&lt;br /&gt;
Management processes relevant data obtained or generated from reliable sources into quality information through the entity’s information system. The entity’s information system comprises the people, processes, data, and information technology that management uses to obtain, generate, communicate, or dispose of information to support the entity’s business processes.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.06&#039;&#039;&#039; ====&lt;br /&gt;
Management develops the entity’s information system to obtain, generate, and process relevant data into quality information to meet the identified information requirements needed to support the internal control system. Information processing can be manual, automated through the use of information technology, or a combination of both.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.07&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates the processed information to determine whether it is quality information. Quality information meets the identified information requirements when relevant data from reliable sources are used. Quality information is appropriate, current, complete, accurate, accessible, verifiable, retained as appropriate, and provided on a timely basis. Management considers these characteristics and the information processing and information security objectives in evaluating processed information, and makes revisions when necessary, so that the information is quality information. Management uses the quality information to make informed decisions and evaluate the entity’s performance in achieving key objectives, addressing risks, and fulfilling internal control responsibilities.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins — Information Gaps]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_13_-_Use_Quality_Information&amp;diff=355</id>
		<title>Principle 13 - Use Quality Information</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_13_-_Use_Quality_Information&amp;diff=355"/>
		<updated>2026-08-13T22:12:51Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 13.0 Use Quality Information ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-13-use-quality-information/ External Link to US GAO Green Book Principle 13]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should obtain or generate relevant, quality information and use it to support the functioning of the internal control system.&lt;br /&gt;
&lt;br /&gt;
=== 13.1 Identification of Information Requirements ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs a process that uses the entity’s objectives and related risks to identify the information requirements needed to support the internal control system. Information requirements consider the needs of both internal and external users. Management defines the identified information requirements at the relevant level and requisite specificity for appropriate personnel.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.03&#039;&#039;&#039; ====&lt;br /&gt;
Management identifies information requirements in an iterative and ongoing process that occurs throughout the design, implementation, and operation of an effective internal control system. An entity’s controls within the five components of internal control establish information requirements. As change in the entity and its objectives and risks occurs, management changes information requirements as needed to meet these modified objectives and address these modified risks. Management establishes information requirements through policies and procedures, with clear responsibility and accountability for the quality of information. These information requirements are communicated both internally and externally, such as with service organizations.&lt;br /&gt;
&lt;br /&gt;
=== 13.2 Relevant Data from Reliable Sources ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.04&#039;&#039;&#039; ====&lt;br /&gt;
Management obtains or generates relevant data from reliable internal and external sources in a timely manner based on the identified information requirements. Relevant data have a logical connection with, or bearing upon, the identified information requirements. Reliable internal and external sources provide data that are reasonably free from error and bias and faithfully represent what they purport to represent. Management evaluates both internal and external sources of data for reliability. Management obtains relevant data through a variety of forms, including using manual input or compilation, using information technology, or coordinating with other entities to obtain or access data.[1] Sources of data can be operational, reporting, or compliance related. Management obtains data on a timely basis so that they can be used for effective monitoring.&lt;br /&gt;
&lt;br /&gt;
=== 13.3 Data Processed into Quality Information ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.05&#039;&#039;&#039; ====&lt;br /&gt;
Management processes relevant data obtained or generated from reliable sources into quality information through the entity’s information system. The entity’s information system comprises the people, processes, data, and information technology that management uses to obtain, generate, communicate, or dispose of information to support the entity’s business processes.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.06&#039;&#039;&#039; ====&lt;br /&gt;
Management develops the entity’s information system to obtain, generate, and process relevant data into quality information to meet the identified information requirements needed to support the internal control system. Information processing can be manual, automated through the use of information technology, or a combination of both.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;13.07&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates the processed information to determine whether it is quality information. Quality information meets the identified information requirements when relevant data from reliable sources are used. Quality information is appropriate, current, complete, accurate, accessible, verifiable, retained as appropriate, and provided on a timely basis. Management considers these characteristics and the information processing and information security objectives in evaluating processed information, and makes revisions when necessary, so that the information is quality information. Management uses the quality information to make informed decisions and evaluate the entity’s performance in achieving key objectives, addressing risks, and fulfilling internal control responsibilities.{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2001: The Journey Begins|❓ 2001: The Journey Begins — Information Gaps]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_12_-_Implement_Control_Activities&amp;diff=354</id>
		<title>Principle 12 - Implement Control Activities</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_12_-_Implement_Control_Activities&amp;diff=354"/>
		<updated>2026-08-13T22:09:43Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 12.0 Implement Control Activities ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-12-implement-control-activities/ External Link to US GAO Green Book Principle 12]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;12.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should implement control activities through policies and procedures.&lt;br /&gt;
&lt;br /&gt;
=== 12.1 Documentation of Control Activities Through Policies and Procedures ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;12.02&#039;&#039;&#039; ====&lt;br /&gt;
Management establishes control activities by documenting in policies what is expected and in procedures specified actions that implement policies, to mitigate risks to achieving the entity’s objectives to acceptable levels &#039;&#039;&#039;[documentation requirement].&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;12.03&#039;&#039;&#039; ====&lt;br /&gt;
Management documents in policies and procedures for each unit within the entity’s organizational structure its responsibility for a business process’s objectives and related risks and control activity design, implementation, and operating effectiveness. Each unit, with guidance from management, determines the policies necessary to operate the business process based on the objectives and related risks. Each unit also documents policies and procedures in the appropriate level of detail to allow management to effectively monitor the control activity. The documentation may appear in various forms, such as management directives, administrative policies, or operating manuals.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;12.04&#039;&#039;&#039; ====&lt;br /&gt;
Those in key roles for the unit may further define policies through day-to-day procedures, depending on the rate of change in the operating environment and complexity of the business process. Procedures may include the timing of when a control activity occurs and any follow-up corrective actions to be performed by competent personnel if deficiencies are identified. Management communicates the policies and procedures entity-wide so that personnel can implement the control activities for their assigned responsibilities.&lt;br /&gt;
&lt;br /&gt;
=== 12.2 Periodic Review of Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;12.05&#039;&#039;&#039; ====&lt;br /&gt;
Management reviews policies, procedures, and related control activities on a periodic and ongoing basis for continued relevance and effectiveness in achieving the entity’s objectives or mitigating related risks. If there is a significant change in an entity’s process, management reviews this process in a timely manner after the change to determine that the control activities are designed and implemented appropriately. Changes may occur in personnel, business processes, or information technology. A new law or regulation may change an entity’s objectives or how an entity is to achieve an objective. Further, in the federal environment, this may occur through government-wide policy or guidance issued by entities like the Office of Management and Budget, Office of Personnel Management, and the Department of the Treasury. Management considers these changes in its periodic and ongoing reviews. Management also considers the results of its monitoring activities to determine whether control activities are designed and implemented effectively.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2020: The Event|🗳️ 2020: The Event]]&lt;br /&gt;
* [[December 2024: Gaining Support|📋 December 2024: Gaining Support]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_12_-_Implement_Control_Activities&amp;diff=353</id>
		<title>Principle 12 - Implement Control Activities</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_12_-_Implement_Control_Activities&amp;diff=353"/>
		<updated>2026-08-13T22:09:18Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 12.0 Implement Control Activities ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-12-implement-control-activities/ External Link to US GAO Green Book Principle 12]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;12.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should implement control activities through policies and procedures.&lt;br /&gt;
&lt;br /&gt;
=== 12.1 Documentation of Control Activities Through Policies and Procedures ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;12.02&#039;&#039;&#039; ====&lt;br /&gt;
Management establishes control activities by documenting in policies what is expected and in procedures specified actions that implement policies, to mitigate risks to achieving the entity’s objectives to acceptable levels &#039;&#039;&#039;[documentation requirement].&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;12.03&#039;&#039;&#039; ====&lt;br /&gt;
Management documents in policies and procedures for each unit within the entity’s organizational structure its responsibility for a business process’s objectives and related risks and control activity design, implementation, and operating effectiveness. Each unit, with guidance from management, determines the policies necessary to operate the business process based on the objectives and related risks. Each unit also documents policies and procedures in the appropriate level of detail to allow management to effectively monitor the control activity. The documentation may appear in various forms, such as management directives, administrative policies, or operating manuals.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;12.04&#039;&#039;&#039; ====&lt;br /&gt;
Those in key roles for the unit may further define policies through day-to-day procedures, depending on the rate of change in the operating environment and complexity of the business process. Procedures may include the timing of when a control activity occurs and any follow-up corrective actions to be performed by competent personnel if deficiencies are identified. Management communicates the policies and procedures entity-wide so that personnel can implement the control activities for their assigned responsibilities.&lt;br /&gt;
&lt;br /&gt;
=== 12.2 Periodic Review of Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;12.05&#039;&#039;&#039; ====&lt;br /&gt;
Management reviews policies, procedures, and related control activities on a periodic and ongoing basis for continued relevance and effectiveness in achieving the entity’s objectives or mitigating related risks. If there is a significant change in an entity’s process, management reviews this process in a timely manner after the change to determine that the control activities are designed and implemented appropriately. Changes may occur in personnel, business processes, or information technology. A new law or regulation may change an entity’s objectives or how an entity is to achieve an objective. Further, in the federal environment, this may occur through government-wide policy or guidance issued by entities like the Office of Management and Budget, Office of Personnel Management, and the Department of the Treasury. Management considers these changes in its periodic and ongoing reviews. Management also considers the results of its monitoring activities to determine whether control activities are designed and implemented effectively.{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2020: The Event|🗳️ 2020: The Event]]&lt;br /&gt;
* [[December 2024: Gaining Support|📋 December 2024: Gaining Support]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=352</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=352"/>
		<updated>2026-08-13T22:06:38Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Arizona Compliance Review and Corrective Action Framework =&lt;br /&gt;
&lt;br /&gt;
The purpose of this framework is to describe the key elements of an effective citizen complaint, compliance review, and corrective action process for Arizona counties which may include state entities. It presents a practical governance framework that promotes transparency, accountability, consistency, and continuous improvement while strengthening public confidence in local/county/state government.&lt;br /&gt;
&lt;br /&gt;
Rather than creating new compliance standards, this framework applies well-established compliance review principles already used throughout government and private industry to citizen-identified governance concerns. It describes the essential components of an objective compliance review process, outlines the lifecycle of an effective complaint and corrective action program, and establishes the governance principles necessary to ensure significant citizen concerns are evaluated consistently, documented objectively, and resolved through a structured process.&lt;br /&gt;
&lt;br /&gt;
== Start Your Journey ==&lt;br /&gt;
Choose your path:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[The Story|📖 Read The Story]]&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[Governance Analysis|📊 Explore Governance Analysis]]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Follow the chronological narrative of events that revealed governance gaps.&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Dive into structured analysis using the Green Book framework.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{About}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | 🏠 &#039;&#039;&#039;Main Page&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Principle_11_-_Design_General_Control_Activities_over_Information#11.11|link]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=351</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Main_Page&amp;diff=351"/>
		<updated>2026-08-13T22:05:09Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Arizona Compliance Review and Corrective Action Framework =&lt;br /&gt;
&lt;br /&gt;
The purpose of this framework is to describe the key elements of an effective citizen complaint, compliance review, and corrective action process for Arizona counties which may include state entities. It presents a practical governance framework that promotes transparency, accountability, consistency, and continuous improvement while strengthening public confidence in local/county/state government.&lt;br /&gt;
&lt;br /&gt;
Rather than creating new compliance standards, this framework applies well-established compliance review principles already used throughout government and private industry to citizen-identified governance concerns. It describes the essential components of an objective compliance review process, outlines the lifecycle of an effective complaint and corrective action program, and establishes the governance principles necessary to ensure significant citizen concerns are evaluated consistently, documented objectively, and resolved through a structured process.&lt;br /&gt;
&lt;br /&gt;
== Start Your Journey ==&lt;br /&gt;
Choose your path:&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[The Story|📖 Read The Story]]&lt;br /&gt;
! style=&amp;quot;width: 50%; text-align: center; font-size: 1.2em;&amp;quot; | [[Governance Analysis|📊 Explore Governance Analysis]]&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Follow the chronological narrative of events that revealed governance gaps.&lt;br /&gt;
| style=&amp;quot;text-align: center;&amp;quot; | Dive into structured analysis using the Green Book framework.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{About}}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
! colspan=&amp;quot;3&amp;quot; | Quick Navigation&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | 🏠 &#039;&#039;&#039;Main Page&#039;&#039;&#039;&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[The Story|📖 The Story]]&lt;br /&gt;
| style=&amp;quot;width: 33%; text-align: center;&amp;quot; | [[Governance Analysis|📊 Governance Analysis]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Principle_11_-_Design_General_Control_Activities_over_Information#11.01|link]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_11_-_Design_General_Control_Activities_over_Information&amp;diff=350</id>
		<title>Principle 11 - Design General Control Activities over Information</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_11_-_Design_General_Control_Activities_over_Information&amp;diff=350"/>
		<updated>2026-08-13T22:04:06Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 11.0 Design General Control Activities over Information ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-11-design-general-control-activities-over-information-technology/ External Link to US GAO Green Book Principle 11]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should design general control activities over information technology to mitigate risks to achieving the entity’s objectives to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
=== 11.1 Response to Risks ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs general control activities over the entity’s information technology to mitigate risks to information security. Information security is the protection of information or information technology from unauthorized access, use, disclosure, disruption, modification, or destruction to provide confidentiality, integrity, and availability. The reliability of information technology used within business processes, including automated controls, depends on the selection, development, and implementation of general control activities over information technology.&lt;br /&gt;
&lt;br /&gt;
=== 11.2 Design of the Entity’s Information Technology ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.03&#039;&#039;&#039; ====&lt;br /&gt;
Management designs information technology to support the entity’s information system and business processes. The entity’s information system includes both manual and automated processes. Automated processes are wholly or partially performed using information technology.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.04&#039;&#039;&#039; ====&lt;br /&gt;
Management designs the entity’s use of information technology in the information system by considering the defined information requirements for each of the entity’s business processes. Information technology incorporated into business processes enables information related to those processes to become available to the entity on a timelier basis. Additionally, information technology may be incorporated into control activities to enhance internal control over the processing and security of information. Although information technology implies specific types of control activities, information technology is not a “stand-alone” control consideration. It is an integral part of most control activities.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.05&#039;&#039;&#039; ====&lt;br /&gt;
Information technology consists of the infrastructure, platforms, and software used to automate processes. Infrastructure comprises the physical information technology resources necessary to run software, including the hardware and devices used for information processing, data storage, and network communication. Infrastructure also includes the logical information technology resources necessary to run multiple virtual machines on shared physical information technology resources. Platforms comprise the logical information technology resources necessary to run application software, including operating systems and related computer programs, tools, and utilities. Software comprises application software, access control software, and other software used to perform specific functions of the entity’s business processes.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.06&#039;&#039;&#039; ====&lt;br /&gt;
Management designs the information technology infrastructure to support the entity’s business processes. Information technology requires a physical infrastructure in which to operate, including communication networks for linking information technologies, computing resources for software and platforms to operate, and electricity to power the information technology. An entity’s information technology infrastructure can be complex. It may be owned and operated by the entity, shared by different units within the entity, or outsourced either to service organizations or to location-independent technology (e.g., cloud computing and storage) services. In designing the information technology infrastructure, management considers factors such as the expertise required to develop and maintain the information technology, costs to develop information technology internally or outsource, desired level of control over resources, and impact on continuity of operations.&lt;br /&gt;
&lt;br /&gt;
=== 11.3 Design of Appropriate Types of General Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.07&#039;&#039;&#039; ====&lt;br /&gt;
Management designs appropriate types of general control activities to mitigate information security risks. General control activities are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. They support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. When designing general control activities, management evaluates information security objectives to meet the defined information requirements. General control activities are designed to achieve one or more of the following information security objectives:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Confidentiality&#039;&#039;&#039; - Preserving authorized restrictions on information access and disclosure, including means for protecting privacy and sensitive information.&lt;br /&gt;
* &#039;&#039;&#039;Integrity&#039;&#039;&#039; - Guarding against improper information modification or destruction, which includes ensuring information’s non-repudiation and authenticity.&lt;br /&gt;
* &#039;&#039;&#039;Availability&#039;&#039;&#039; - Ensuring timely and reliable access to and use of information, thus preventing the disruption of access to or use of information or information technology.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.08&#039;&#039;&#039; ====&lt;br /&gt;
The nature, timing, and precision of general control activities will depend on various factors, such as the complexity of the technology, sensitivity of information, use of service organizations, use of shared service or data centers, and risk of the underlying business process being supported.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.09&#039;&#039;&#039; ====&lt;br /&gt;
&#039;&#039;&#039;General control activities may be applied at the entity, system, and business process levels.&#039;&#039;&#039; &lt;br /&gt;
&lt;br /&gt;
General control activities include the following:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Security management&#039;&#039;&#039; - A separate process, addressing all components of internal control, for responding to risks related to information security.&lt;br /&gt;
* &#039;&#039;&#039;Logical and physical access&#039;&#039;&#039; - Control activities that restrict access to information technology to authorized users.&lt;br /&gt;
* &#039;&#039;&#039;Configuration management&#039;&#039;&#039; - Control activities to develop and maintain the operating and security features of information technology and control changes to their configuration.&lt;br /&gt;
* &#039;&#039;&#039;Segregation of duties&#039;&#039;&#039; - Separating control activity responsibilities related to information technology to prevent individuals from controlling all critical stages of a process or overriding automated processes.&lt;br /&gt;
* &#039;&#039;&#039;Contingency planning&#039;&#039;&#039; - Control activities that maintain the continuity of operations and rely on information technology, including contingency plans for recovery after a disruption of service.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.10&#039;&#039;&#039; ====&lt;br /&gt;
Security management is the ongoing process for mitigating information security risks as part of the entity’s overall internal control system (sometimes referred to as a security management program). This ongoing process covers all components of internal control related to information security risks.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.11&#039;&#039;&#039; ====&lt;br /&gt;
Logical and physical access control activities include restricting access or detecting inappropriate access to information and information technology. They protect information technology resources against unauthorized access, use, disclosure, disruption, modification, or destruction, whether from malicious intent or error. Logical access control activities require users to authenticate themselves and restrict them to the applications or functions commensurate with their assigned responsibilities, supporting an appropriate segregation of duties. Management may grant different permissions to employees and end users, including the rights to create, read, edit, or delete a file; execute a program; and retrieve or update information in a database. Management designs other control activities to promptly update access rights when employees change job functions or leave the entity. Physical access control activities involve restricting physical access to information and information technology, including the physical infrastructure, and protecting it from intentional or unintentional loss or impairment.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.12&#039;&#039;&#039; ====&lt;br /&gt;
Configuration management control activities involve the identification and management of operating and security features for information technology (i.e., infrastructure, platforms, and software) throughout the technology development process. Management may use a technology development methodology to provide a structure for a new information technology design by outlining specific phases and documenting requirements, approvals, and checkpoints within control activities over the development, maintenance, and change of technology. Management evaluates the objectives and risks of the new technology in designing control activities over its technology development methodology.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.13&#039;&#039;&#039; ====&lt;br /&gt;
Control activities for developing information technology, commonly referred to as systems development controls, prevent the use of unauthorized or untested systems. Management may internally develop information technology, acquire it from suppliers, or outsource its development to service organizations. Management incorporates methodologies for acquisition into its development process and designs control activities over the selection, ongoing development, and maintenance of information technology. For a system developed internally, management designs control activities to mitigate risks in outsourced technology before it is incorporated into the entity’s business processes. Management evaluates the unique risks that using a service organization, search engine, or artificial intelligence software present to the completeness, accuracy, and validity of information submitted to and received from the organization or software system.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.14&#039;&#039;&#039; ====&lt;br /&gt;
Control activities for maintaining information technology include identifying vulnerabilities to patch and other functional updates to be made. Management continuously monitors the entity’s information technology to establish a baseline for evaluating performance, detecting underlying deficiencies before they negatively impact users, collecting data when risks occur, and enabling continuous improvement. Vulnerability management is the process of identifying system vulnerabilities where change may be necessary for remediation. Management may identify vulnerabilities through continuous monitoring of characteristics such as the type of technology used, physical entry points, and trends in user activity. Management may use monitoring software that automatically notifies appropriate personnel when a breach or irregularity is identified. Management may also perform penetration testing of the system to identify vulnerabilities that a hacker might exploit. Patch management is the process of applying platform and software updates to close security vulnerabilities and improve functionality. Management implements control activities to periodically or automatically update antivirus software, apply patches to correct security issues, and scan for and remove unauthorized access points.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.15&#039;&#039;&#039; ====&lt;br /&gt;
Control activities for changing information technology prevent unauthorized or untested modifications to existing systems. To reasonably assure that changes to the configuration of information technology are necessary, work as intended, and do not cause loss of data or program integrity, changes go through a formal change management process in which they are authorized, documented, tested, and independently reviewed. This may involve requiring authorization of change requests; reviewing the changes, approvals, and testing results; and designing protocols to determine whether changes are made properly. Depending on the size and complexity of the entity, initial development or acquisition of information technology and subsequent changes to the information technology may be included in one methodology or two separate methodologies.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.16&#039;&#039;&#039; ====&lt;br /&gt;
Segregation of duties control activities help prevent fraud, waste, and abuse from being executed using information technology in the internal control system and mitigate the risk of management override of automated processes. Management considers the need to separate responsibilities for control activities related to the entity’s information technology so that one individual does not control all critical stages of a process. This may include separating responsibilities for designing, testing, and implementing new systems or for processing transactions and managing databases.&lt;br /&gt;
&lt;br /&gt;
==== &#039;&#039;&#039;11.17&#039;&#039;&#039; ====&lt;br /&gt;
Contingency planning protects critical and sensitive data against loss and allows for critical operations to continue without disruption or be promptly resumed when unexpected events occur. Maintaining technology through contingency planning often includes backup and recovery procedures, as well as continuity of operations plans, depending on the risks and consequences of a full or partial power systems outage or other disruption of service. Recovery plans are tested periodically in disaster simulation exercises to determine whether they will work as intended.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
	<entry>
		<id>https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=346</id>
		<title>Principle 10 - Design Control Activities</title>
		<link rel="alternate" type="text/html" href="https://arizonacitizenvoice.com/index.php?title=Principle_10_-_Design_Control_Activities&amp;diff=346"/>
		<updated>2026-08-13T21:59:04Z</updated>

		<summary type="html">&lt;p&gt;Kelly: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 10.0 Design Control Activities ==&lt;br /&gt;
[https://guides.gaoinnovations.gov/greenbook/2025/principle-10-design-control-activities/ External Link to US GAO Green Book Principle 10]&lt;br /&gt;
&lt;br /&gt;
=== Overview ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.01&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.01&#039;&#039;&#039; ====&lt;br /&gt;
Management should design control activities to mitigate risks to achieving the entity’s objectives to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.1&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.1 Response to Risks ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.02&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.02&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities in response to risks to achieve an effective internal control system. Control activities are the actions management establishes through policies and procedures to specifically mitigate risks to achieving the entity’s objectives to acceptable levels. Control activities support all the components of internal control but are particularly aligned with the risk assessment component. As part of periodic and ongoing risk assessments, management identifies objectives; the risks related to the entity and its objectives, including its service organizations; the entity’s risk tolerance; and risk responses. Management designs control activities or modifies existing control activities to mitigate risks to acceptable levels within management’s defined risk tolerance. Typically, control activities are needed when an entity chooses to either reduce or share a risk. The nature and extent of the risk response and any associated control activities will depend, at least in part, on management’s defined risk tolerance.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.2&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.2 Design of Appropriate Types of Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.03&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.03&#039;&#039;&#039; ====&lt;br /&gt;
Management designs appropriate types of control activities for the entity’s internal control system, including the entity’s information technology, by considering all aspects of its internal control components, relevant business processes, and operating environment. An entity’s internal control is flexible to allow management to tailor control activities to meet the entity’s unique needs. The specific control activities used by a given entity may be different from those used by others based on several factors. These factors could include specific threats the entity faces and the risks involved, differences in objectives, managerial judgment, size and complexity of the entity, operational environment, and sensitivity and value of data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.04&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.04&#039;&#039;&#039; ====&lt;br /&gt;
The common categories of control activities listed in table 1 [omitted] illustrate the range and variety of control activities that may be useful to management. &lt;br /&gt;
&lt;br /&gt;
The list is not all inclusive and may not include all categories of control activities that an entity may need.&lt;br /&gt;
&lt;br /&gt;
(ADD TABLE)&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.3&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.3 Design of Automated and Manual Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.05&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.05&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be designed and implemented in an automated, partially automated, or a manual manner. Automated control activities may be wholly or partially performed using the entity’s information technology. Manual control activities are performed by individuals without relying on the entity’s information technology. Automated control activities tend to be more reliable because they are less susceptible to human error and are typically more efficient.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.06&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.06&#039;&#039;&#039; ====&lt;br /&gt;
Management designs information technology control activities to support the operation and security of the entity’s information technology and automated business processes. Information technology control activities consist of general, application, and user control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.07&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.07&#039;&#039;&#039; ====&lt;br /&gt;
Application and user control activities rely on the entity’s information technology. Application control activities are automated control activities that are incorporated directly into application software to achieve the completeness, accuracy, and validity of transactions and data. Application control activities include control activities over the input, processing, and output of data. User control activities, sometimes referred to as information technology-dependent controls, are partially automated control activities that are performed by individuals using the entity’s information technology or by relying on the information processed through technology. For example, management may authorize a transaction as part of an automated workflow or may respond to incidents flagged in system log reports.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.08&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.08&#039;&#039;&#039; ====&lt;br /&gt;
General control activities are designed to mitigate information security risks and are the actions established through policies and procedures that apply to all or a large segment of an entity’s information technology. General control activities support the proper operation of the entity’s information technology by creating a suitable environment for effective operation of application and user control activities. General control activities can be designed and implemented in either an automated or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.09&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.09&#039;&#039;&#039; ====&lt;br /&gt;
Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7. The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to management. This list is not all inclusive and may not include all information technology control activities that an entity may need.&lt;br /&gt;
&lt;br /&gt;
(FIGURE 7)&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.4&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.4 Design of Preventive and Detective Control Activities ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.10&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.10&#039;&#039;&#039; ====&lt;br /&gt;
Control activities can be either preventive or detective. The main difference between preventive and detective control activities is timing, that is, when the control activity occurs within an entity’s operations. A preventive control activity is designed to avoid an unintended event or result before it occurs. A detective control activity is designed to discover and timely correct an unintended event or result after it occurs. The effectiveness of a detective control activity depends on timeliness of the corrective action to address the unintended event or result. Corrective action may address the event that occurred or may correct the deficiencies in the process that led to the event.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.11&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.11&#039;&#039;&#039; ====&lt;br /&gt;
Management evaluates the purpose of the control activity as well as the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives. Management may design both preventive and detective control activities to effectively mitigate the risks to achieving the objectives, particularly in circumstances where the risk of an unintended event or result occurring is high. Generally, the higher the risk of an unintended event or result occurring, the stronger or more robust the control activities need to be to effectively mitigate the higher risk to acceptable levels.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.12&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.12&#039;&#039;&#039; ====&lt;br /&gt;
Management designs an appropriate mix of preventive and detective control activities to mitigate risks to an acceptable level, prioritizing preventive control activities where appropriate. When designing control activities, management first considers preventive control activities, as they generally offer the most cost-efficient use of resources and are generally effective at mitigating fraud and improper payment risks. Management next considers detective control activities and may design both preventive and detective control activities when necessary to mitigate a particular risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.13&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.13&#039;&#039;&#039; ====&lt;br /&gt;
There may be rare situations where management determines through its evaluation that a preventive control activity would better mitigate a particular risk but is unable to implement it. In these situations, management strengthens and expedites detective control activities and may also expedite monitoring activities to enable the entity to effectively mitigate the risk to acceptable levels, considering the risk related to the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.5&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.5 Design of Control Activities at Various Levels ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.14&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.14&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities at the appropriate levels in the organizational structure.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.15&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.15&#039;&#039;&#039; ====&lt;br /&gt;
Management designs control activities for appropriate mitigation of risks in the entity’s business processes. Business processes transform inputs into outputs through a series of transactions or activities to achieve the entity’s objectives. Management designs entity-level control activities, business process-level control activities (commonly referred to as transaction control activities), or both depending on the level of precision needed so that the entity mitigates risks to an acceptable level related to its business processes. Entity-level and transaction control activities can be implemented in an automated, partially automated, or a manual manner.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.16&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.16&#039;&#039;&#039; ====&lt;br /&gt;
Entity-level control activities are controls designed to mitigate risks that have a pervasive effect on an entity’s internal control system and may pertain to multiple components. Entity-level control activities may include controls related to the entity’s risk assessment process, control environment, service organizations, management override, and performance or analytical reviews.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.17&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.17&#039;&#039;&#039; ====&lt;br /&gt;
Transaction control activities are controls that directly mitigate information processing risks in the entity’s business processes. The term transaction tends to be associated with business processes addressing reporting objectives (e.g., financial transactions), while the term activity is more often associated with business processes addressing operations or compliance objectives. In the Green Book, “transactions” and “transaction control activities” can cover both transactions and activities. Management may design a variety of transaction control activities for business processes, which may include verifications, reconciliations, authorizations and approvals, physical control activities, and supervisory control activities.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.18&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.18&#039;&#039;&#039; ====&lt;br /&gt;
When designing transaction control activities, management evaluates information processing objectives to meet the entity’s objectives and mitigate related risks.&lt;br /&gt;
&lt;br /&gt;
Information processing objectives may include the following:&lt;br /&gt;
&lt;br /&gt;
* Completeness - All transactions and events that occur have been properly recorded.&lt;br /&gt;
* Accuracy - Data relating to transactions and events are properly and timely recorded.&lt;br /&gt;
* Validity - All recorded transactions and events actually occurred, are related to the entity, and were executed according to prescribed procedures.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.19&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.19&#039;&#039;&#039; ====&lt;br /&gt;
While the information processing objectives are most often associated with financial processes and transactions, information processing objectives can be applied to any activity in an organization. For example, information processing objectives and related control activities can be applied to management’s decision-making processes that use non-financial data.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.20&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.20&#039;&#039;&#039; ====&lt;br /&gt;
When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity’s objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is closely linked to the entity’s risk tolerance for a particular objective; a lower risk tolerance will require a more precise control activity. In determining the necessary level of precision for a control activity, management evaluates the following:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Level of aggregation&#039;&#039;&#039; - A control activity that is performed at a more granular level generally is more precise than one performed at a higher level. For example, an analysis of obligations by budget object class normally is more precise than an analysis of total obligations for the entity.&lt;br /&gt;
* &#039;&#039;&#039;Consistency and timing of performance&#039;&#039;&#039; - A control activity that is performed routinely, consistently, and timely generally is more precise than one performed sporadically.&lt;br /&gt;
* &#039;&#039;&#039;Correlation to relevant business processes&#039;&#039;&#039; - A control activity that is directly related to a business process generally is more likely to prevent or detect and correct an error than a control activity that is only indirectly related.&lt;br /&gt;
&lt;br /&gt;
=== &amp;lt;span id=&amp;quot;10.6&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;10.6 Segregation of Duties ===&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.21&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.21&#039;&#039;&#039; ====&lt;br /&gt;
Management considers segregation of duties in designing control activities so that incompatible duties are segregated. Where such segregation is not practical, management designs alternative control activities to mitigate the risk.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.22&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.22&#039;&#039;&#039; ====&lt;br /&gt;
Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity’s business processes. Segregation of duties can mitigate the risk of management override. Management override circumvents existing control activities and increases risk of fraud, waste, and abuse. Management mitigates this risk through segregation of duties but cannot absolutely prevent it because of the risk of collusion, where two or more employees act together to commit fraud, waste, or abuse.&lt;br /&gt;
&lt;br /&gt;
==== &amp;lt;span id=&amp;quot;10.23&amp;quot;&amp;gt;&amp;lt;/span&amp;gt;&#039;&#039;&#039;10.23&#039;&#039;&#039; ====&lt;br /&gt;
If segregation of duties is not practical within a business process because of limited personnel or other factors, management designs alternative control activities to mitigate the risk of fraud, waste, or abuse in the business process.&lt;br /&gt;
&lt;br /&gt;
{{Principles}}&lt;br /&gt;
&lt;br /&gt;
== Related Story Events ==&lt;br /&gt;
&lt;br /&gt;
* [[2020: The Event|🗳️ 2020: The Event]]&lt;br /&gt;
* [[May 15, 2025: Let&#039;s Play Hot Potato|🥔 May 2025: PRR Issues]]&lt;/div&gt;</summary>
		<author><name>Kelly</name></author>
	</entry>
</feed>