Principle 8 - Assess Fraud, Improper Payment, and Information

From Corrective Action Plan AZ

8.0 Assess Fraud, Improper Payment, and Information

External Link to US GAO Green Book Principle 8

Overview

8.01

Management should consider risks related to fraud, improper payments, and information security when identifying, analyzing, and responding to risks.

8.02

Management identifies risks related to fraud, improper payments, and information security through the same risk identification process performed for all analyzed risks. However, these risks are discussed further in this principle because they may be pervasive or have an impact on multiple processes and can often be inadequately addressed in the risk assessment process.

8.03

Management identifies risks related to fraud, improper payments, and information security on a periodic and ongoing basis to provide a basis for analyzing risks. Risk assessment is the identification and analysis of risks related to achieving the defined objectives to form a basis for designing risk responses. To determine the scope and frequency of these assessments, management considers the entity’s objectives, risk tolerances, any legal or regulatory requirements, and other factors. However, management may determine that the risk assessments need to be performed more frequently than required by legal or regulatory requirements due to the significance of risks or other factors, such as changes to programs. For example, to adequately identify risks related to improper payments for new programs, management may perform improper payment risk assessments for a certain program or activity on a more frequent and recurring basis, regardless of the required frequency in legal or regulatory requirements for such risk assessments.

8.04

Management considers the types of fraud, improper payments, and information security breaches that may occur, along with relevant risk factors, when identifying risks related to these areas. While risks may be greater when multiple risk factors are present, the presence of one factor may still indicate a risk. Performing an analysis to identify the root cause of identified internal control deficiencies can assist management in identifying risks.

8.05

Management considers information that internal and external parties provide to identify risks related to fraud, improper payments, and information security. This may include information reported by the office of inspector general, internal auditors, personnel, service organizations, and other external parties that interact with the entity. Information may include emerging information security threats, identified instances of improper payments, or adjudicated cases of fraud as well as suspected or alleged fraud.

8.2 Types of Fraud and Fraud Risk Factors

8.06

Management considers the types of fraud that could impact the entity to provide a basis for identifying and analyzing fraud. Fraud involves obtaining something of value through willful misrepresentation.

Types of fraud may include the following:

  • Fraudulent reporting - Intentional misstatements or omissions of amounts or disclosures in financial or nonfinancial reports through willful misrepresentation to deceive report users. For fraudulent financial reports, this could include intentional alteration of accounting records, misrepresentation of transactions, or intentional misapplication of accounting principles. For fraudulent nonfinancial reports, this could include intentional misrepresentation of information.
  • Misappropriation of assets - The unauthorized acquisition, use, or disposal of an entity’s assets through willful misrepresentation. This could include efforts to conceal theft of property, embezzlement of receipts, bid rigging, fraudulent payments, or misrepresentation of eligibility to obtain benefits.
  • Other illegal acts - Intentional violations of laws or regulations through willful misrepresentation that may be related to financial or nonfinancial activities. This could include certain types of corruption, bribery, extortion, and cybercrimes.

8.07

As part of a risk assessment, management considers the risk of fraud that could impact the entity from both within the entity and from external parties. For example, external fraud risk may arise when an entity relies on service organizations’ internal control systems to perform business processes for the entity. External parties that present fraud risk may also include program beneficiaries who fraudulently obtain benefits.

8.08

In addition to fraud, management considers other forms of misconduct that can occur, such as waste and abuse. Waste is the act of using or expending resources carelessly, extravagantly, or to no purpose. Abuse involves behavior that is deficient or improper when compared with behavior that a prudent person would consider reasonable and necessary operational practice given the facts and circumstances. Abuse may include corruption through the misuse of authority or position for personal gain or for the benefit of another. Waste and abuse do not necessarily involve fraud, though fraudulent misrepresentations may be made to conceal such misconduct. The presence of waste and abuse may indicate potential fraud and an environment that is conducive to fraud. Waste and abuse may also impact the achievement of defined objectives.

8.09

In addition to fraud, management also considers the risk of management override of controls. Management override of controls does not necessarily involve fraud but may indicate potential fraud and increases fraud risk.

August 3, 2026: Submitted Complaint – My original PRR requested contracts and MOUs with corporate and governmental entities, respectively. I sought to understand how the contracts were revised, assuming contract changes would be implemented by a formal process. I had not considered the changes could have been implemented by means of a “management override.”

As yet to be determined (unknown), the contract changes did not have a signature or justification. Therefore, it is unknown if the changes were implemented by a management override, which would expand the risk evaluation.

8.10

Management considers fraud risk factors. Fraud risk factors do not necessarily indicate that fraud exists but are often present when fraud occurs.

Fraud risk factors may include the following:

  • Incentive/pressure - Management, other personnel, or external parties have an incentive or are under pressure, which provides a motive to commit fraud.
  • Opportunity - Circumstances exist, such as the absence of controls, ineffective controls, or the ability of management to override controls, that provide an opportunity to commit fraud.
  • Attitude/rationalization - Individuals involved can rationalize committing fraud. Some individuals possess an attitude, character, or ethical values that allow them to commit dishonest acts knowingly and intentionally.

8.3 Types of Improper Payments and Improper Payment Risk Factors

8.11

Management considers the types of improper payments that could impact the entity to provide a basis for identifying and analyzing improper payment risks. Improper payments are any payments that should not have been made or that were made in an incorrect amount. Payments are also considered improper when there is insufficient or lack of documentation. Improper payments can result from lack of oversight, mismanagement, errors, deficiencies in internal control, abuse, or fraud. While all payments resulting from fraudulent activity are considered improper, not all improper payments are the result of fraud. Types of improper payments may include the following:

  • Overpayments - These payments are those in excess of the amount dueto be paid to recipients. They include payments to ineligible recipients, any payment for an ineligible good or service, payments for goods or services not received, and any duplicate payment. They could be either intentional—such as fraudulent payments or unintentional.
  • Underpayments - These payments are those in which recipients did not receive some or all the funds to which they were entitled.

8.12

Management considers improper payment risk factors, both internal and external, which may include the following:

  • whether the program or activity is new to the entity;
  • the complexity of the program or activity;
  • the volume of payments made through the program or activity;
  • whether the payments or payment eligibility decisions are made through external parties;
  • recent major changes in program funding, legal authorities, practices, or procedures;
  • the level and experience of and quality of training for personnel responsible for making payment eligibility determinations or verifying that payments made are accurate;
  • the extent to which the entity relies on potential recipients self certifying their own eligibility;
  • identified internal control deficiencies that might hinder accurate payment processing;
  • similarities to other programs or activities that have reported improper payment estimates or been deemed susceptible to significant improper payments;
  • improper payment estimates previously reported for the program or activity, or other indicator of potential susceptibility to improper payments;
  • whether the program or activity lacks the information or database to confirm eligibility or verify the accuracy of the payment;
  • and the risk of fraud related to the program or activity.

8.13

Management considers existing improper payment estimates, if available, when determining the significance of risks and the effectiveness of the internal control system in responding to improper payment risks. These estimates may come from management’s annual improper payment estimates as part of its monitoring activities, which may be mandated by law. Management may also develop estimates more frequently than mandated by law, such as for programs that are new, substantially changed, or rapidly implemented to facilitate a timely risk assessment.

8.4 Types of Information Security Risk and Information Security Risk Factors

8.14

Management considers the types of risks that could impact the entity’s information and information technology to provide a basis for identifying and analyzing risks related to information security. Information security risk is the risk to entity operations, assets, and personnel, as well as external parties, due to unauthorized access, use, disclosure, disruption, modification, or destruction of information or information technology. These risks may impact the information security objectives of confidentiality, integrity, and availability. Types of information security risk impacting each of these three objectives may include the following:

  • Unauthorized access - End users, developers, or unrelated attackers may compromise the confidentiality of a platform or software system by overriding controls to gain unauthorized access to the entity’s information technology or use capabilities that exceed their rights in those systems.
  • Exploitation of personnel - Attacks, such as phishing attempts, that trick users into revealing information or giving an attacker access to a platform or software system.
  • Installation of malicious software - Installation of a program or file that intentionally attacks the entity’s information technology by corrupting or stealing data, overwhelming a system with traffic, or locking the entity out. The objective of a malicious software (malware) attack may be to harm the entity, gain information, or obtain a financial gain.
  • Automated attacks - Attacks on information technology may be automated through mechanisms, such as bots, artificial intelligence, and machine learning software.
  • Undetected errors - End users, developers, or unrelated attackers may improperly alter data in the entity’s information technology without visible evidence. Erroneous changes resulting from corrupted systems may not be readily detectable by users.
  • Threats to physical environment - Threats to the physical environment, such as fire, loss of electricity, loss of climate controls, or natural disasters, can result in the loss of information or information technology system damage or disruption. In addition, failure to appropriately limit physical access to information or an information technology system may also allow a malicious attacker to access or modify information.

8.15

Internal risks include unintentional acts by employees, whose vigilance is a key defense against external threats and user error. Internal threats may also come from intentional malicious acts by former or disgruntled employees. They pose unique risks because these individuals may be both motivated to work against the entity and better equipped to succeed in carrying out a malicious act as they have greater access to and knowledge of the entity’s information technology and business processes.

8.16

External risks may come from external parties that connect with or operate the entity’s information technology or from unrelated attackers. External parties that connect with the entity’s operating systems and databases in the normal course of operations may include end users, such as program beneficiaries; federal, state, and local government entities; and service organizations. External parties that operate the entity’s information technology may include developers to which the entity outsources the design of information technology or service organizations or location-independent technology services that operate the systems on behalf of the entity. External information security risks may arise when an entity relies on these external parties’ internal control systems as they perform business processes for the entity.

8.17

Management considers information security risk factors, which may include the following:

  • the complexity of the entity’s information technology;
  • new or emerging technologies;
  • information technology that may be outdated or incompatible with new technologies;
  • decentralized operating systems and communications networks;
  • external-party access to the entity’s operating systems and communications networks;
  • information technology personnel not having the knowledge, skills, or abilities to maintain the entity’s information technology and respond to related risks; and personnel being unfamiliar with technology and related risks.

8.5 Analyze and Respond to Identified Risks

8.18

Management analyzes and responds to identified fraud, improper payment, and information security risks so that they are effectively mitigated. These risks are analyzed through the same risk analysis process performed for all identified risks. Management analyzes the identified risks by estimating their significance to assess their impact on achieving the defined objectives.

8.19

Management responds to fraud, improper payment, and information security risks consistent with the risk response process performed for all analyzed risks. Based on the selected risk response, management determines the specific actions to effectively mitigate each risk. It may be possible to reduce or avoid certain fraud, improper payment, or information security risks by making changes to the entity’s activities and processes. These changes may include stopping or reorganizing certain operations, modifying the entity’s information technology, reallocating roles among personnel to enhance segregation of duties, or designing or modifying control activities. Management may also need to develop further responses to address the risk of management override of controls, particularly when considering fraud risks.

8.20

Management may develop separate processes within the periodic and ongoing risk assessment process with separate oversight responsibilities, to manage risks related to fraud, improper payments, or information security as part of the entity’s overall internal control system.

These separate processes would cover all components of internal control related to these specific risks.

Assessment Observations Compared to Green Book Components, Principles, & Attributes

Control Environment

Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.

  • Principle 3 - Establish Structure, Responsibility, and Authority
    • Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
  • Principle 4 - Demonstrate Commitment to Competence
    • Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
  • Principle 5 - Enforce Accountability
    • Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment

Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.

  • Principle 6 - Define Objectives and Risk Tolerances
    • Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
  • Principle 7 - Identify, Analyze, and Respond to Risks
    • Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
  • Principle 8 - Assess Fraud, Improper Payment, and Information
    • Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
  • Principle 9 - Identify, Analyze, and Respond to Change
    • Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities

Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.

  • Principle 10 - Design Control Activities
    • Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
  • Principle 11 - Design General Control Activities over Information
    • Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
  • Principle 12 - Implement Control Activities
    • Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication

Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.

  • Principle 13 - Use Quality Information
    • Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
  • Principle 14 - Communicate Internally
    • Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
  • Principle 15 - Communicate Externally
    • Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring

Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.

  • Principle 16 - Perform Monitoring Activities
    • Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
  • Principle 17 - Evaluate Issues and Remediate Deficiencies
    • Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)

Related Story Events