8.03

From Corrective Action Plan AZ

Risk Assessment

Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk

Attribute 8.03 - Management identifies risks related to fraud, improper payments, and information security on a periodic and ongoing basis to provide a basis for analyzing risks. Risk assessment is the identification and analysis of risks related to achieving the defined objectives to form a basis for designing risk responses. To determine the scope and frequency of these assessments, management considers the entity's objectives, risk tolerances, any legal or regulatory requirements, and other factors. However, management may determine that the risk assessments need to be performed more frequently than required by legal or regulatory requirements due to the significance of risks or other factors, such as changes to programs. For example, to adequately identify risks related to improper payments for new programs, management may perform improper payment risk assessments for a certain program or activity on a more frequent and recurring basis, regardless of the required frequency in legal or regulatory requirements for such risk assessments.

>>>Navigational Buttons<<<


No Examples