Principle 16 - Perform Monitoring Activities
16.0 Perform Monitoring Activities
External Link to US GAO Green Book Principle 16
Overview
16.01
Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results.
16.1 Establishment of a Baseline
16.02
Monitoring activities evaluate whether each of the five components of internal control, including controls to effect the principles within each component, is present and functioning or if change is needed. Management establishes a baseline to monitor the internal control system. The baseline is the current state of the internal control system compared against management’s design of the internal control system. The baseline represents the difference between the criteria for the design of the internal control system and the condition of the internal control system at a specific point in time. In other words, the baseline consists of issues and deficiencies identified in an entity’s internal control system.
16.03
Once established, management can use the baseline as criteria in evaluating the internal control system and make changes to reduce the difference between the criteria and condition. Management reduces this difference in one of two ways. Management either changes the design of the internal control system to better address the objectives and risks of the entity or improves the operating effectiveness of the internal control system. As part of monitoring, management determines when to revise the baseline to reflect changes in the internal control system.
16.2 Internal Control System Monitoring
16.04
Management monitors the internal control system through ongoing monitoring and separate evaluations. Ongoing monitoring is built into the entity’s operations, performed continually, and responsive to change. Separate evaluations are performed periodically and may provide feedback on the effectiveness of ongoing monitoring. Many of the methods and tools described below may be used for both ongoing monitoring and separate evaluations, depending on when and how they are implemented.
16.05
Management performs ongoing monitoring of the design and operating effectiveness of the internal control system as part of the normal course of operations. Ongoing monitoring includes regular management and supervisory activities, comparisons, reconciliations, trend analysis, data analytics, activities to identify improper payments or potential fraud, testing, and other routine actions. Ongoing monitoring may include automated tools, which can increase objectivity and efficiency by electronically compiling evaluations of controls and transactions or by automating data analytics.
16.06
Management uses separate evaluations to monitor the design and operating effectiveness of the overall internal control system at a specific time or of a specific function or process. The scope and frequency of separate evaluations depend primarily on the assessment of risks, risk responses, evolving technology, identification of new risks or deficiencies, results of ongoing monitoring, and rate of change within the entity and its environment. Management may also increase the frequency of separate evaluations when management rapidly implements a new program or substantially changes an existing one, such as emergency assistance programs. Separate evaluations include observations, inquiries, reviews, improper payment estimates, and other examinations, as appropriate. These evaluate whether controls to effect principles across the entity are designed, implemented, and operating effectively. Separate evaluations may also take the form of self-assessments, which include crossoperating unit or cross-functional evaluations.
16.07
Management also uses the results of separate evaluations performed in connection with internal and external audits, investigations, and other evaluations that may involve the review of internal control design and testing of internal controls to help identify issues in the internal control system. These audits and other evaluations may be mandated by law and are performed by internal auditors, external auditors, inspectors general, and other reviewers. Separate evaluations provide greater objectivity when performed by reviewers who do not have responsibility for the activities being evaluated.
16.08
Management retains responsibility for monitoring the effectiveness of controls performed by service organizations that are necessary for the entity to achieve its control objectives. Management uses ongoing monitoring, separate evaluations, or a combination of the two to obtain reasonable assurance of the operating effectiveness of a service organization’s internal controls over the assigned process. Monitoring activities related to service organizations may include the use of work performed by external parties, such as service auditors, and reviewed by management.
16.3 Evaluation of Results
16.09
Management evaluates and documents the results of ongoing monitoring and separate evaluations to identify internal control issues [documentation requirement]. Management uses this evaluation to determine the effectiveness of the internal control system. Differences between the results of monitoring activities and the previously established baseline may indicate internal control issues, including undocumented changes in the internal control system or potential internal control deficiencies.
16.10
Management identifies changes in the internal control system that either have occurred or are needed because of changes in the entity and its environment. External parties can also help management identify issues in the internal control system. For example, complaints from the public, regulator comments, and findings from investigations may indicate areas in the internal control system that need improvement. Other external parties that interact with the entity, including relevant suppliers, contractors, and service organizations, may collaborate with management to identify and respond to issues in the entity’s business processes and related internal controls. Management considers whether current controls address the identified issues and modifies controls if necessary.
Assessment Observations Compared to Green Book Components, Principles, & Attributes
Control Environment
Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.
- Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
- Principle 2 - Exercise Oversight Responsibility
- Principle 3 - Establish Structure, Responsibility, and Authority
- Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
- Principle 4 - Demonstrate Commitment to Competence
- Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
- Principle 5 - Enforce Accountability
- Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment
Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.
- Principle 6 - Define Objectives and Risk Tolerances
- Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
- Principle 7 - Identify, Analyze, and Respond to Risks
- Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
- Principle 8 - Assess Fraud, Improper Payment, and Information
- Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
- Principle 9 - Identify, Analyze, and Respond to Change
- Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities
Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.
- Principle 10 - Design Control Activities
- Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
- Principle 11 - Design General Control Activities over Information
- Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
- Principle 12 - Implement Control Activities
- Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication
Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.
- Principle 13 - Use Quality Information
- Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
- Principle 14 - Communicate Internally
- Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
- Principle 15 - Communicate Externally
- Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring
Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.
- Principle 16 - Perform Monitoring Activities
- Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
- Principle 17 - Evaluate Issues and Remediate Deficiencies
- Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)
