8.05
Risk Assessment
Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk
Attribute 8.05 - Management considers information that internal and external parties provide to identify risks related to fraud, improper payments, and information security. This may include information reported by the office of inspector general, internal auditors, personnel, service organizations, and other external parties that interact with the entity. Information may include emerging information security threats, identified instances of improper payments, or adjudicated cases of fraud as well as suspected or alleged fraud.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 8.04
- Next Attribute - 8.06
Additional details regarding this aspect of my story are available in a subsection titled Contract with the Motor Vehicle Department (MVD).
In 2024, the Arizona Secretary of State, Adrian Fontes, issued a press release on September 30, 2024, which described how over 218,000 voter registration records were adversely impacted during the collection of data by the MVD and subsequent transfer to the MC Recorders Office. The press release states, "Staff and experts from the Secretary of State’s Office are continuing to work with MVD to investigate if additional voters are impacted, or if other similar errors stemming from improperly coded Proposition 200 rules exist. We will continue to keep the public informed of developments if and when we have accurate, confirmed information to share." The Information Security Risk was real based on the number of corrupted records identified. Yet, MC managers and legal team had no written agreements between them and the MVD.
Potential Green Book Deviation:
Contrary to the Green Book, MC had failed to sufficiently identify risk to information during the process of collection and subsequent transfer of voter registration data from the MVD to MC prior to the September 2024 press release. The lack of a written agreement between MC and MVD suggest no action was taken to address a known risk after single error was found.
