Principle 7 - Identify, Analyze, and Respond to Risks

From Corrective Action Plan AZ

7.0 Identify, Analyze, and Respond to Risks

External Link to US GAO Green Book Principle 7

Overview

7.01

Management should identify, analyze, and respond to risks related to achieving the defined objectives.

7.1 Identify Risks

7.02

Management identifies risks throughout the entity on a periodic and ongoing basis to provide a basis for analyzing risks. Risk is the possibility that an event will occur and adversely affect the achievement of objectives. Risk assessment is the identification and analysis of risks related to achieving the defined objectives to form a basis for designing risk responses. Periodic risk assessments are performed at specific times and at regular intervals, such as annually. Management considers entity objectives, risk tolerances, and other factors when determining the scope and frequency of these assessments. Ongoing risk assessments are performed as needed, on a real-time basis, such as when significant internal or external change occurs or significant emerging risks are identified. Management also considers performing ongoing risk assessments when internal control deficiencies, improper payments, potential fraud, or information security breaches are detected.

7.03

To identify risks, management considers the types of risks that impact the entity. This includes both inherent and residual risk. Inherent risk is the risk to an entity in the absence of management’s response to the risk. Residual risk is the risk that remains after management’s response to inherent risk. Once risk responses have been developed to address inherent risk, management then considers the impact or significance of the residual risk that remains and whether it is at an acceptable level within the defined risk tolerances. Assessing inherent and residual risk can assist management in understanding the extent of risk responses needed. Management’s lack of response to either type of risk could cause deficiencies in the internal control system.

7.04

Management considers all significant interactions within the entity and with external parties, changes within the entity’s internal and external environments, and other internal and external factors to identify risks throughout the entity. Management considers these factors at both the entity and transaction levels to comprehensively identify risks that affect defined objectives. Entity-level risk factors have a pervasive effect on an entity’s internal control system and are generally considered at a relatively high level. Transaction-level risk factors affect specific business processes within all levels of the organizational structure and are generally considered at a more detailed level.

August 3, 2026: Submitted Complaint – My original PRR sought contracts and MOUs associated with MC’s acquisition of election-related materials and services for the purpose determining how change was implemented. More specifically, I wanted to know if the contract changes adversely effected election integrity by increasing the probability or consequences mismanagement of election data.

As expected (no deviation), the Dominion and Runbeck contracts prior to 2020 had disaster recovery agreements stated in the contract.

Contrary to the Green Book (deviation), the disaster recovery agreements were stricken from the contracts without justification and with no signature of the person performing the change just prior to the 2020 election. The stricken disaster recover agreements were not replaced. Therefore, risk significantly increased because a disaster was in progress; the Covid-19 was adversely impacting their normal business practices. There was no disaster recovery plan, original or alternate, in place during the disaster, which increased the election integrity risk beyond the impacts of the disaster. Insufficient documentation was delivered to determine how MC and their third-parties responded to the disaster.

7.05

Management’s consideration of risk factors related to fraud, improper payments, and information security is discussed further in principle 8. Management’s consideration of significant internal and external changes that could impact the internal control system is discussed further in principle 9.

August 3, 2026: Submitted Complaint – My original PRR sought contracts and MOUs associated with MC’s acquisition of election-related materials and services from third-parties. This Green Book attribute is noted because it specifically identifies information security as a risk factor, which directly relates to election integrity. See discussion of Green Book attribute 7.04 (above) for additional information.

7.06

Risk identification methods may include qualitative and quantitative ranking activities, forecasting and strategic planning, data analytics, and consideration of internal control deficiencies identified through monitoring activities or reported by internal or external parties. Performing an analysis to identify the root causes of internal control deficiencies can assist management in identifying risks. Management also collaborates with relevant internal and external parties to identify risks. Internal parties include appropriate management and other personnel from all appropriate units within the entity’s organizational structure, including program and financial managers. External parties may include service organizations, suppliers, contractors, regulated entities, federal entities, state and local governments, and grantees.

August 3, 2026: Submitted Complaint – My original PRR sought contracts and MOUs associated with MC’s acquisition of election-related materials and services for an extended period, well past the 2020 election. The purpose was to determine if the 2020 anomalies had been investigated and corrective actions initiated in accordance to risk, likelihood and consequences of recurrence.

Generally speaking, it would have been impossible to assess the risk to election integrity from changes in the operating environment originating from Washington D.C.. There was too much uncertainty occurring at a rapid pace. However, much more certainty in assessing risk after the 2020 election because the consequences were known and the lock-downs had been extended by the MCBOS.

Contrary to the Green Book (deviation), there was no evidence to suggest any root cause investigations were implemented following the 2020, which would have allowed the MC management team to assess risk to future elections. Hence, the recurrence of similar election anomalies occurred in subsequent elections.

7.2 Analyze Risks

7.07

Management analyzes the identified risks, on a periodic and ongoing basis, to estimate their significance, which provides a basis for responding to the risks. Significance refers to a risk’s impact on achieving a defined objective.

7.08

Management estimates the significance of the identified risks to assess their impact on achieving the defined objectives at both the entity and transaction levels. Management estimates the significance of a risk by considering the magnitude of impact, likelihood of occurrence, and nature of the risk. Magnitude of impact refers to the likely magnitude of the effect of the risk on the entity’s ability to achieve its objectives. It is affected by factors such as the size, pace, and duration of the risk’s impact. Likelihood of occurrence refers to the level of possibility that an unintended event or result will occur. The nature of the risk involves factors such as the degree of subjectivity involved with the risk and whether the risk arises from fraud or from complex or unusual transactions.

7.09

Risks may be analyzed individually or grouped into categories with related risks and analyzed collectively. Regardless of whether risks are analyzed individually or collectively, management considers the correlation among different risks or groups of risks when estimating their significance. The specific risk analysis methodology used can vary by entity because of differences in entities’ missions and the difficulty in qualitatively and quantitatively defining risk tolerances.

7.3 Respond to Risks

7.10

Management designs responses to the analyzed risks so that risks are within the defined risk tolerance for the defined objective. Management designs overall risk responses for the analyzed risks based on the significance of the risk, defined risk tolerance, and cost-benefit determination.

These risk responses may include the following:

  • Acceptance - No action is taken to respond to the risk.
  • Avoidance - Action is taken to stop the business process or the part of the business process causing the risk.
  • Reduction - Action is taken to reduce the likelihood or magnitude of the risk.
  • Sharing - Action is taken to transfer or share risks across the entity or with external parties, such as insuring against losses.

7.11

Based on the selected risk response, management designs controls to effectively mitigate the analyzed risks on a timely basis. If management has chosen to reduce or share a risk, then management designs controls, which may exist within each component of internal control or constitute a specific control activity.49 Typically, controls are not needed when an entity chooses to either accept or avoid a risk. The nature and extent of risk response actions and any associated controls will depend, at least in part, on the defined level of risk tolerance.

7.12

When designing controls to mitigate risk, management may modify controls related to the entity’s oversight responsibilities, organizational structure, and responsibilities and authorities throughout the entity. Management may also develop separate processes within the periodic and ongoing risk assessment process with separate oversight responsibilities, to manage certain risks as part of the entity’s overall internal control system. This may be necessary to achieve objectives due to the nature of certain types of risks, such as for risks related to fraud, improper payments, or information security, or when a risk is pervasive or has an impact on multiple processes. These separate processes would cover all components of internal control related to these specific risks.

7.13

After designing risk responses, management then considers residual risk. In instances where a risk response results in the residual risk exceeding defined risk tolerances, management revisits and revises the response. Operating within the defined risk tolerance provides greater assurance that the entity will achieve its objectives.

7.14

Performance measures are used to assess whether risk response actions enable the entity to operate within the defined risk tolerances. When risk response actions do not enable the entity to operate within the defined risk tolerances, management may need to revise risk responses or reconsider defined risk tolerances. Management may need to conduct periodic risk assessments to evaluate the effectiveness of the risk response actions.

7.15

Management documents the results of the risk assessments, including the identification, analysis, and response to risks, that are completed on both a periodic and ongoing basis. This includes documentation of the consideration of risks related to fraud, improper payments, information security, and significant internal and external changes that could impact the internal control system [documentation requirement.]

Assessment Observations Compared to Green Book Components, Principles, & Attributes

Control Environment

Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.

  • Principle 3 - Establish Structure, Responsibility, and Authority
    • Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
  • Principle 4 - Demonstrate Commitment to Competence
    • Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
  • Principle 5 - Enforce Accountability
    • Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment

Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.

  • Principle 6 - Define Objectives and Risk Tolerances
    • Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
  • Principle 7 - Identify, Analyze, and Respond to Risks
    • Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
  • Principle 8 - Assess Fraud, Improper Payment, and Information
    • Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
  • Principle 9 - Identify, Analyze, and Respond to Change
    • Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities

Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.

  • Principle 10 - Design Control Activities
    • Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
  • Principle 11 - Design General Control Activities over Information
    • Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
  • Principle 12 - Implement Control Activities
    • Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication

Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.

  • Principle 13 - Use Quality Information
    • Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
  • Principle 14 - Communicate Internally
    • Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
  • Principle 15 - Communicate Externally
    • Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring

Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.

  • Principle 16 - Perform Monitoring Activities
    • Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
  • Principle 17 - Evaluate Issues and Remediate Deficiencies
    • Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)