Principle 3 - Establish Structure, Responsibility, and Authority

From Corrective Action Plan AZ

3.0 Establish Structure, Responsibility, and Authority

External Link to US GAO Green Book Principle 3

Overview

3.01

Management should establish an organizational structure, assign responsibility, and delegate authority to achieve the entity’s objectives.

3.1 Organizational Structure

3.02

Management establishes the organizational structure necessary to enable the entity to plan, execute, control, and assess the organization in achieving its objectives. Management develops the overall responsibilities from the entity’s objectives that enable the entity to achieve its objectives and address related risks.

3.03

Management develops an organizational structure with an understanding of the overall responsibilities and assigns these responsibilities to enable the organization to operate efficiently and effectively, comply with applicable laws and regulations, and reliably report information. Based on the nature of the assigned overall responsibility and related risks, management chooses the type and number of discrete divisions, operating units, functions, and other structures needed to achieve the entity’s objectives. Management may identify discrete divisions, operating units, or functions, such as program offices and related subunits, to manage the entity’s risk responses within the internal control system.

3.04

As part of establishing an organizational structure, management considers how divisions, operating units, functions, and other structures interact to fulfill their overall responsibilities. Management establishes reporting lines within an organizational structure so that units can communicate the quality information necessary for each unit to fulfill its overall responsibilities to support the internal control system. Reporting lines are defined at all levels of the organization and provide methods of communication that can flow down, across, up, and around the structure. Management also considers the entity’s overall responsibilities to external stakeholders and establishes reporting lines that allow the entity to both communicate with and obtain information from external stakeholders.

3.05

Management periodically evaluates the organizational structure so that it meets the entity’s objectives and has adapted to any new entity objectives, such as to comply with a new law or regulation. Management also adapts the organizational structure as necessary to respond to risks and identified deficiencies in the internal control system.

3.2 Assignment of Responsibility and Delegation of Authority

3.06

To achieve the entity’s objectives and address related risks, management assigns responsibility and delegates authority to key roles throughout the entity. A key role is a position in the organizational structure that is assigned an overall responsibility of the entity. Generally, key roles relate to senior management positions within an entity.

3.07

Management considers the overall responsibilities assigned across the organizational structure, determines what key roles are needed to fulfill the assigned responsibilities, and establishes the key roles. Those in key roles can further assign responsibility for internal control to roles below them in the organizational structure, but they retain ownership for fulfilling the overall responsibilities assigned to them.

3.08

Management determines what level of authority each key role needs to fulfill a responsibility. Management delegates authority only to the extent required to achieve the entity’s objectives. As part of delegating authority, management evaluates each delegation for proper segregation of duties within the organizational structure. Segregation of duties helps prevent fraud, waste, and abuse in the entity by considering the need to separate authority, custody, and accounting in the organizational structure. As with assigning responsibility, those in key roles can

3.3 Documentation of the Internal Control System

3.09

Management develops and maintains documentation of its internal control system [documentation requirement].

3.10

Effective documentation assists in management’s design of internal control by establishing and communicating the who, what, when, where, and why of internal control execution to personnel. Documentation also provides a means to retain organizational knowledge and mitigate the risk of having that knowledge limited to a few personnel, and to communicate that knowledge as needed to external parties, such as external auditors.

Note: The Green Book standard is reflected in Arizona Statutes. A.R.S. § 39-121 provides that public records in the custody of any officer shall be open to inspection.

April 15, 2025: Public Records Request – The Disaster Recovery Plan was stricken through the contract for Runbeck Election Services prior to the November 2020 election. It was subsequently restored after the election. There was a Covid-19 Pandemic occurring during the election, which was disrupting operations nationwide, in both the private and government sectors.

Contrary to the Green Book, MCBOS removed the Disaster Recovery Plan during Covid-19, which disrupted normal services, including elections. No replacement was added. The documentation was insufficient to determine who, what, when, where, and why internal control execution was changed during the Covid-19 Pandemic.

3.11

Management documents internal control to meet operational needs. Documentation of controls, including changes to controls, is evidence that controls are identified, capable of being communicated to those responsible for their performance, and capable of being monitored and evaluated by the entity.

April 15, 2025: Public Records Request – MCBOS Procurement Department delivers two Runbeck Election Services contracts and two Dominion Voting Systems contracts. Some sections of the contracts have been stricken through apparently to indicate no longer applicable. Some content was added as an amendment according to verbal accounts from MC employees. However, new content and content that was stricken through was not explained (justified) or authorized given the absence of an approval signature.

Contrary to the Green Book, the apparent changes to the contract documentation was insufficient to determine who, what, when, where, and why of internal control execution to personnel.

3.12

The extent of documentation needed to support the design, implementation, and operating effectiveness of the five components of internal control is a matter of judgment for management. Management considers the benefits and costs of documentation for the entity as well as the size, nature, and complexity of the entity and its objectives. Some level of documentation, however, is necessary so that the components of internal control can be designed, implemented, and operating effectively.`

Assessment Observations Compared to Green Book Components, Principles, & Attributes

Control Environment

Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.

  • Principle 3 - Establish Structure, Responsibility, and Authority
    • Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
  • Principle 4 - Demonstrate Commitment to Competence
    • Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
  • Principle 5 - Enforce Accountability
    • Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment

Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.

  • Principle 6 - Define Objectives and Risk Tolerances
    • Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
  • Principle 7 - Identify, Analyze, and Respond to Risks
    • Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
  • Principle 8 - Assess Fraud, Improper Payment, and Information
    • Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
  • Principle 9 - Identify, Analyze, and Respond to Change
    • Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities

Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.

  • Principle 10 - Design Control Activities
    • Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
  • Principle 11 - Design General Control Activities over Information
    • Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
  • Principle 12 - Implement Control Activities
    • Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication

Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.

  • Principle 13 - Use Quality Information
    • Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
  • Principle 14 - Communicate Internally
    • Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
  • Principle 15 - Communicate Externally
    • Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring

Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.

  • Principle 16 - Perform Monitoring Activities
    • Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
  • Principle 17 - Evaluate Issues and Remediate Deficiencies
    • Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)

Related Story Events