Template:Principles: Difference between revisions

From Corrective Action Plan AZ
 
(10 intermediate revisions by the same user not shown)
Line 1: Line 1:
=== US GAO Green Book Components, Principles, & Attributes ===
=== Assessment Observations Compared to Green Book Components, Principles, & Attributes ===


===== Control Environment =====
===== Control Environment =====
 
<u>Component:</u> '''Control Environment''' ''-'' The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.
* [[1.01|Principle 1]] - Demonstrate Commitment to Integrity and Ethical Values
* [[1.01|Principle 1]] - Demonstrate Commitment to Integrity and Ethical Values
** Attributes ([[1.01]], [[1.02]], [[1.03]], [[1.04]], [[1.05]], [[1.06]], [[1.07]], [[1.08]], [[1.09]], [[1.10]])
** Attributes ([[1.01]], [[1.02]], [[1.03]], [[1.04]], [[1.05]], [[1.06]], [[1.07]], [[1.08]], [[1.09]], [[1.10]])
Line 9: Line 9:
** Attributes ([[2.01]], [[2.02]], [[2.03]], [[2.04]], [[2.05]], [[2.06]], [[2.07]], [[2.08]], [[2.09]], [[2.10]], [[2.11]], [[2.12]], [[2.13]])
** Attributes ([[2.01]], [[2.02]], [[2.03]], [[2.04]], [[2.05]], [[2.06]], [[2.07]], [[2.08]], [[2.09]], [[2.10]], [[2.11]], [[2.12]], [[2.13]])


* Principle 3 - Establish Structure, Responsibility, and Authority
* [[3.01|Principle 3]] - Establish Structure, Responsibility, and Authority
** Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
** Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)


* Principle 4 - Demonstrate Commitment to Competence
* [[4.01|Principle 4]] - Demonstrate Commitment to Competence
** Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
** Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
* Principle 5 - Enforce Accountability
* [[5.01|Principle 5]] - Enforce Accountability
**Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
**Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)


===== Risk Assessment =====
===== Risk Assessment =====
 
<u>Component:</u> '''Risk Assessment''' - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.
* Principle 6 - Define Objectives and Risk Tolerances
* [[6.01|Principle 6]] - Define Objectives and Risk Tolerances
**Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
**Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
* Principle 7 - Identify, Analyze, and Respond to Risks
* [[7.01|Principle 7]] - Identify, Analyze, and Respond to Risks
**Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
**Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
* Principle 8 - Assess Fraud, Improper Payment, and Information
* [[8.01|Principle 8]] - Assess Fraud, Improper Payment, and Information
**Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
**Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
* Principle 9 - Identify, Analyze, and Respond to Change
* [[9.01|Principle 9]] - Identify, Analyze, and Respond to Change
**Attributes (
**Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)


===== Control Activities =====
===== Control Activities =====
 
<u>Component:</u> '''Control Activities''' - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.
* Principle 10 - Design Control Activities
* [[10.01|Principle 10]] - Design Control Activities
**Attributes (
**Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
* Principle 11 - Design General Control Activities over Information
* [[11.01|Principle 11]] - Design General Control Activities over Information
**Attributes (
**Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
* Principle 12 - Implement Control Activities
* [[12.01|Principle 12]] - Implement Control Activities
**Attributes (
**Attributes (12.01, 12.02, 12.03, 12.04, 12.05)


===== Information and Communication =====
===== Information and Communication =====
 
<u>Component:</u> '''Information and Communication''' - The quality information management and other personnel communicate and use to support the internal control system.
* Principle 13 - Use Quality Information
* [[13.01|Principle 13]] - Use Quality Information
**Attributes (
**Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
* Principle 14 - Communicate Internally
* [[14.01|Principle 14]] - Communicate Internally
**Attributes (
**Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
* Principle 15 - Communicate Externally
* [[15.01|Principle 15]] - Communicate Externally
**Attributes (
**Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)


===== Monitoring =====
===== Monitoring =====
 
<u>Component:</u> '''Monitoring''' - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.
* Principle 16 - Perform Monitoring Activities
* [[16.01|Principle 16]] - Perform Monitoring Activities
**Attributes (
**Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
* Principle 17 - Evaluate Issues and Remediate Deficiencies
* [[17.01|Principle 17]] - Evaluate Issues and Remediate Deficiencies
**Attributes (
**Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)


=== [[Index of Attributes]] ===
=== [[Index of Attributes]] ===

Latest revision as of 05:14, 18 August 2026

Assessment Observations Compared to Green Book Components, Principles, & Attributes

Control Environment

Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.

  • Principle 3 - Establish Structure, Responsibility, and Authority
    • Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
  • Principle 4 - Demonstrate Commitment to Competence
    • Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
  • Principle 5 - Enforce Accountability
    • Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment

Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.

  • Principle 6 - Define Objectives and Risk Tolerances
    • Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
  • Principle 7 - Identify, Analyze, and Respond to Risks
    • Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
  • Principle 8 - Assess Fraud, Improper Payment, and Information
    • Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
  • Principle 9 - Identify, Analyze, and Respond to Change
    • Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities

Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.

  • Principle 10 - Design Control Activities
    • Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
  • Principle 11 - Design General Control Activities over Information
    • Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
  • Principle 12 - Implement Control Activities
    • Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication

Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.

  • Principle 13 - Use Quality Information
    • Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
  • Principle 14 - Communicate Internally
    • Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
  • Principle 15 - Communicate Externally
    • Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring

Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.

  • Principle 16 - Perform Monitoring Activities
    • Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
  • Principle 17 - Evaluate Issues and Remediate Deficiencies
    • Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)