8.04

From Corrective Action Plan AZ

Risk Assessment

Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk

Attribute 8,04 - Management considers the types of fraud, improper payments, and information security breaches that may occur, along with relevant risk factors, when identifying risks related to these areas. While risks may be greater when multiple risk factors are present, the presence of one factor may still indicate a risk. Performing an analysis to identify the root cause of identified internal control deficiencies can assist management in identifying risks.

Navigational Buttons:

The discussion of Attribute 8.04 is from this March 12, 2026 event, under the subheading of Motor Vehicle Department Contract.

This Green Book attribute is fundamentally saying that a single risk factor can be more significant that a list of other risk. The likelihood and consequences from a single risk factor can be significant. This attribute describes how root cause analysis to address internal control deficiencies is good governance. Root cause analysis identifies the organizational risk and Corrective Action Plans mitigate that risk.

Potential Green Book Deviation:

Contrary to the Green Book, MC did not provide me with any objective evidence that demonstrated their interest in investigating election-related anomalies for the purpose of understanding the risk to election outcomes and developing corrective actions where necessary.