Principle 9 - Identify, Analyze, and Respond to Change
9.0 Identify, Analyze, and Respond to Change
External Link to US GAO Green Book Principle 9
Overview
9.01
Management should identify, analyze, and respond to significant changes that could impact the internal control system.
9.1 Identify Significant Changes
9.02
As part of periodic and ongoing risk assessments, management identifies, on a timely basis, significant internal and external changes that could impact the entity’s internal control system. Identifying, analyzing, and responding to significant changes is similar to, if not part of, the entity’s periodic and ongoing risk assessment process. However, change is discussed separately because it is critical to an effective internal control system and can often be overlooked or inadequately or not timely addressed in the normal course of operations.
9.03
Conditions affecting the entity and its environment continually change. Management identifies, on a timely basis, significant changes to internal and external conditions that have already occurred or are expected to occur. Management anticipates and plans for significant changes that are expected to occur by using a forward-looking process to identify expected changes. This enables management to timely identify and analyze the impact of related risks.
9.04
Changes in internal conditions may include changes to the entity’s programs or activities, oversight structure, organizational structure, personnel, and technology. Changes in external conditions may include changes in the governmental, economic, technological, legal, regulatory, and physical environments. Changes in external conditions may also include economic instability or crises, public health emergencies, natural and human-caused disasters, and other catastrophic events.
9.2 Establish a Change Assessment Process
9.05
Management documents a change assessment process for identifying, analyzing, and responding to risks related to significant changes so that the internal control system can be quickly adapted as needed to respond to significant changes as they occur [documentation requirement].
9.06
As significant changes that an entity may need to respond to can occur quickly and unexpectedly, establishing a change assessment process in advance of significant changes occurring is essential to maintaining an effective internal control system as change occurs. This is especially important in situations where management may need to rapidly implement a new program or substantially change an existing program. For example, management may need to implement an emergency assistance program in response to public health emergencies, natural or human-caused disasters, or other catastrophic events.
9.07
Management develops and documents a change assessment process based on the risk assessment process described in principle 7. The process includes procedures for identifying, analyzing, and responding to risks related to significant changes.
9.08
Management’s change assessment process includes steps for timely identifying risks related to significant change, which may include the following:
- the need to provide complex or different services quickly, which may result in increased risks overall, including those related to fraud, improper payments, information security, and noncompliance with applicable laws and regulations;
- ability to design and implement preventive control activities timely due to legal requirements or urgency to deliver a service quickly
- ability to timely communicate relevant and quality information both internally and externally to support the internal control system, such as changes to identified risks, internal control responsibilities, and training on how to administer new internal controls;
- availability of existing resources, such as workforce capacity or availability of data (i.e., data-sharing agreements for external data), to adequately and timely adapt the entity’s internal control system to address new or increased risks; and
- known internal control deficiencies that could increase risks related to significant change.
9.09
Management’s change assessment process includes considerations for management to effectively analyze risk related to significant change, which may include the following:
- how to determine the appropriate scope and extent of initial risk assessment related to a significant change—management considers entity objectives, risk tolerances, and other factors when making this determination—and
- how to determine the timing of subsequent ongoing risk assessments as the entity responds to significant changes.
9.10
Management’s change assessment process includes considerations to facilitate its ability to quickly adapt the entity’s internal control system and effectively respond to a significant change once it occurs, such as the following:
- modifying the organizational structure, responsibilities, and authorities to address identified risks;
- determining whether to create a separate process, with separate oversight responsibilities, to manage risks related to the change as part of the entity’s overall internal control system;
- identifying any existing control activities, policies and procedures, or other processes in existing or similar programs that could be leveraged or modified;
- identifying preventive control activities that could be implemented prior to the distribution of program benefits, even if time or resources are constrained;
- identifying monitoring and detective control activities that could be enhanced or performed more frequently if preventive controls tomitigate certain risks are not feasible;
- considering lessons learned from past programs to inform future practices;
- identifying and establishing communications with external parties that may contribute to the operational effectiveness of the entity’s internal control system when implementing the change; and
- identifying and establishing data-sharing, data-matching, and data-analytics opportunities, including considering known data access issues.
9.3 Identify, Analyze and Respond to Risks Related to Significant Changes
9.11
Changes in conditions affecting the entity and its environment often require changes to the entity’s internal control system, as existing controls may not be effective for meeting objectives or addressing risks under changed conditions. Once significant changes are identified, management uses its change assessment process to identify and analyze the impact of risks related to the identified significant changes on the internal control system and responds by revising the system on a timely basis, when necessary, to maintain its effectiveness. This risk assessment, and revision to the internal control system when necessary, is completed before the entity responds to changing conditions, for example, before it implements a new program or makes significant changes to existing programs or activities.
9.12
Management also performs ongoing risk assessments as the entity responds to changing conditions to analyze and respond to risks on a real-time basis.
9.13
Further, changing conditions often prompt new risks or changes to existing risks that need to be assessed. As part of analyzing and responding to significant change, management performs a risk assessment to identify, analyze, and respond to any new risks prompted by the changes. Additionally, existing risk assessments may need to be updated to determine whether the defined risk tolerances and risk responses need to be revised.
Assessment Observations Compared to Green Book Components, Principles, & Attributes
Control Environment
Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.
- Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
- Principle 2 - Exercise Oversight Responsibility
- Principle 3 - Establish Structure, Responsibility, and Authority
- Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
- Principle 4 - Demonstrate Commitment to Competence
- Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
- Principle 5 - Enforce Accountability
- Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment
Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.
- Principle 6 - Define Objectives and Risk Tolerances
- Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
- Principle 7 - Identify, Analyze, and Respond to Risks
- Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
- Principle 8 - Assess Fraud, Improper Payment, and Information
- Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
- Principle 9 - Identify, Analyze, and Respond to Change
- Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities
Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.
- Principle 10 - Design Control Activities
- Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
- Principle 11 - Design General Control Activities over Information
- Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
- Principle 12 - Implement Control Activities
- Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication
Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.
- Principle 13 - Use Quality Information
- Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
- Principle 14 - Communicate Internally
- Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
- Principle 15 - Communicate Externally
- Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring
Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.
- Principle 16 - Perform Monitoring Activities
- Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
- Principle 17 - Evaluate Issues and Remediate Deficiencies
- Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)
