8.19: Difference between revisions
Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.19''' - Management responds to fraud, improper payment, and information security risks consistent with the risk response process performed for all analyzed risks. Based on the selected risk response, management determines the specific actions to effectively mitigate each risk. It may be possible to reduce or avoid certain fraud, improper payment,..." |
No edit summary |
||
| (3 intermediate revisions by the same user not shown) | |||
| Line 3: | Line 3: | ||
'''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' | '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' | ||
'''Attribute''' '''8.19''' - Management responds to fraud, improper payment, and information security risks consistent with the risk response process performed for all analyzed risks. Based on the selected risk response, management determines the specific actions to effectively mitigate each risk. It may be possible to reduce or avoid certain fraud, improper payment, or information security risks by making changes to the entity's activities and processes. These changes may include stopping or reorganizing certain operations, modifying the entity's information technology, reallocating roles among personnel to enhance segregation of duties, or designing or modifying control activities. Management may also need to develop further responses to address the risk of management override of controls, particularly when considering fraud risks | '''Attribute''' '''8.19''' - Management responds to fraud, improper payment, and information security risks consistent with the risk response process performed for all analyzed risks. Based on the selected risk response, management determines the specific actions to effectively mitigate each risk. It may be possible to reduce or avoid certain fraud, improper payment, or information security risks by making changes to the entity's activities and processes. These changes may include stopping or reorganizing certain operations, modifying the entity's information technology, reallocating roles among personnel to enhance segregation of duties, or designing or modifying control activities. Management may also need to develop further responses to address the risk of management override of controls, particularly when considering fraud risks. | ||
'''>>>Navigational Buttons<<<''' | |||
* '''[[Index of Attributes]]''' | |||
* '''Previous Attribute - [[8.18]]''' | |||
* '''Next Attribute - [[8.20]]''' | |||
__FORCETOC__ | |||
=== Jamie's Story === | |||
No examples are available to illustrate governance gaps for this attribute. | |||
=== Election Anomalies === | |||
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment. | |||
The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security. | |||
===== [[Signature Verification|Maricopa County Signature Verification (2020)]] ===== | |||
Governance issues identified from [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation] of Arizona Senate allegations of Maricopa County - Signature Verification Process issues. Rather than stop and formally reorganize in response to risk induced from change, MC appeared to allow or promote the elimination of process steps intended to prevent or detect fraud. | |||
Latest revision as of 15:54, 25 August 2026
Risk Assessment
Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk
Attribute 8.19 - Management responds to fraud, improper payment, and information security risks consistent with the risk response process performed for all analyzed risks. Based on the selected risk response, management determines the specific actions to effectively mitigate each risk. It may be possible to reduce or avoid certain fraud, improper payment, or information security risks by making changes to the entity's activities and processes. These changes may include stopping or reorganizing certain operations, modifying the entity's information technology, reallocating roles among personnel to enhance segregation of duties, or designing or modifying control activities. Management may also need to develop further responses to address the risk of management override of controls, particularly when considering fraud risks.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 8.18
- Next Attribute - 8.20
Jamie's Story
No examples are available to illustrate governance gaps for this attribute.
Election Anomalies
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.
The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.
Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County - Signature Verification Process issues. Rather than stop and formally reorganize in response to risk induced from change, MC appeared to allow or promote the elimination of process steps intended to prevent or detect fraud.
