Principle 5 - Enforce Accountability

From Corrective Action Plan AZ

5.0 Enforce Accountability

External Link to US GAO Green Book Principle 5

Overview

5.01

Management should evaluate performance and hold individuals accountable for their internal control responsibilities.

5.1 Enforcement of Accountability

5.02

Management enforces accountability of individuals performing their internal control responsibilities. Accountability is driven by the tone at the top and supported by commitment to integrity and ethical values, organizational structure, and expectations of competence, which influence the control culture of the entity. Accountability for performance of internal control responsibility supports day-to-day decision-making, attitudes, and behaviors. Management holds personnel accountable through mechanisms such as performance appraisals and disciplinary actions.

August 3, 2026: Submitted Complaint – My original PRR requested contracts and MOUs with corporate and governmental entities, respectively. I believed the delivery of those contracts would provide objective evidence of the Maricopa County personnel that were accountable for acquiring election related materials and services. Who authorized and what was in those contracts and MOUs?

As expected (no deviation), the original contracts with Runbeck and Dominion were approved by the Director of the MCBOS Procurement Department.

As yet unresolved (unknown), accountability for the contracts and MOUs could not be determined for the documents not delivered in response to my PRR. Hence, it is not known who was responsible and what was the content of the following documents:

• Amendments, addenda, renewals, exhibits, or revisions for 2018–2024
• Post-election contract administration records
• MVD election-related contracts
• USPS-related agreements
• Temporary staffing contracts for signature verification

Contrary to the Green Book (deviation), no change history documentation was included with sections of the Runbeck and Dominion contracts that were stricken through or had new content added, apparently by an amendment process. However, there was no justification for the changes. Nor was there an approval signature for the “amendment.” Therefore, the Green Book’s requirements for accountability were not fulfilled based on the documentation provided.

5.03

Management holds personnel accountable for performing their assigned internal control responsibilities. The oversight body, in turn, holds both management and the entire organization accountable for its internal control responsibilities.

5.04

If management establishes incentives, management recognizes that such actions can yield unintended consequences and evaluates incentives so that they align with the entity’s standards of conduct.

5.05

Management holds service organizations accountable for their assigned internal control responsibilities. Management may contract with service organizations to perform roles in the organizational structure. Management communicates to each service organization the objectives of the entity and their related risks, the entity’s standards of conduct, the role of the service organization in the organizational structure, the assigned responsibilities and authorities of the role, and the expectations of competence for its role that will enable a service organization to perform its internal control responsibilities. Management, however, retains responsibility for the effectiveness of controls over the business processes assigned to service organizations.

See item 5.02 (above) for an explanation of this Green Book attribute, 5.05, to my PRR request. The prior response applies to this attribute.

5.06

Management, with oversight from the oversight body, takes corrective action as necessary to enforce accountability for internal control in the entity. These actions can range from informal feedback provided by the direct supervisor to disciplinary action taken by the oversight body, depending on the significance of the deficiency to the internal control system.Consideration of Excessive Pressures

5.2 Consideration of Excessive Pressures

5.07

Management adjusts excessive pressures on personnel in the entity. Pressure can appear in an entity because of goals management established to meet objectives or cyclical demands of various processes the entity performs, such as year-end financial statement preparation. Excessive pressure can result in personnel “cutting corners” to meet the established goals.

5.08

Management is responsible for evaluating pressure on personnel to help personnel fulfill their assigned responsibilities in accordance with the entity’s standards of conduct. Management can adjust excessive pressures using many different tools, such as rebalancing workloads or increasing resource levels.

5.3 Risk Assessment

Management assesses internal and external risks and performs risk assessments on a periodic and ongoing basis to achieve its objectives.

These assessments provide the basis for identifying risks and developing appropriate risk responses.

Risk Assessment Principles

  • Management should define objectives clearly to enable the identification of risks and define risk tolerances.
  • Management should identify, analyze, and respond to risks related to achieving the defined objectives.
  • Management should consider risks related to fraud, improper payments, and information security when identifying, analyzing, and responding to risks.
  • Management should identify, analyze, and respond to significant changes that could impact the internal control system.

Assessment Observations Compared to Green Book Components, Principles, & Attributes

Control Environment

Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.

  • Principle 3 - Establish Structure, Responsibility, and Authority
    • Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
  • Principle 4 - Demonstrate Commitment to Competence
    • Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
  • Principle 5 - Enforce Accountability
    • Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment

Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.

  • Principle 6 - Define Objectives and Risk Tolerances
    • Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
  • Principle 7 - Identify, Analyze, and Respond to Risks
    • Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
  • Principle 8 - Assess Fraud, Improper Payment, and Information
    • Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
  • Principle 9 - Identify, Analyze, and Respond to Change
    • Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities

Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.

  • Principle 10 - Design Control Activities
    • Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
  • Principle 11 - Design General Control Activities over Information
    • Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
  • Principle 12 - Implement Control Activities
    • Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication

Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.

  • Principle 13 - Use Quality Information
    • Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
  • Principle 14 - Communicate Internally
    • Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
  • Principle 15 - Communicate Externally
    • Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring

Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.

  • Principle 16 - Perform Monitoring Activities
    • Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
  • Principle 17 - Evaluate Issues and Remediate Deficiencies
    • Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)

Related Story Events