7.12: Difference between revisions

From Arizona Citizen Voice
Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.12''' - When designing controls to mitigate risk, management may modify controls related to the entity's oversight responsibilities, organizational structure, and responsibilities and authorities throughout the entity. Management may also develop separate processes within the periodic and ongoing risk assessment process<sup>50</sup> with separate oversight responsibil..."
 
 
(5 intermediate revisions by the same user not shown)
Line 3: Line 3:
'''Principle 7 - Identify, Analyze, and Respond to Risks'''
'''Principle 7 - Identify, Analyze, and Respond to Risks'''


'''Attribute''' '''7.12''' - When designing controls to mitigate risk, management may modify controls related to the entity's oversight responsibilities, organizational structure, and responsibilities and authorities throughout the entity. Management may also develop separate processes within the periodic and ongoing risk assessment process<sup>50</sup> with separate oversight responsibilities, to manage certain risks as part of the entity's overall internal control system. This may be necessary to achieve objectives due to the nature of certain types of risks, such as for risks related to fraud, improper payments, or information security, or when a risk is pervasive or has an impact on multiple processes. These separate processes would cover all components of internal control related to these specific risks.
'''Attribute''' '''7.12''' - When designing controls to mitigate risk, management may modify controls related to the entity's oversight responsibilities, organizational structure, and responsibilities and authorities throughout the entity. Management may also develop separate processes within the periodic and ongoing risk assessment process with separate oversight responsibilities, to manage certain risks as part of the entity's overall internal control system. This may be necessary to achieve objectives due to the nature of certain types of risks, such as for risks related to fraud, improper payments, or information security, or when a risk is pervasive or has an impact on multiple processes. These separate processes would cover all components of internal control related to these specific risks.
 
'''>>>Navigational Buttons<<<'''
* '''[[Index of Attributes]]'''
* '''Previous Attribute - [[7.11]]'''
* '''Next Attribute - [[7.13]]'''
__FORCETOC__
 
=== Jamie's Story ===
No examples are available to illustrate governance gaps for this attribute.
 
=== Election Anomalies ===
Principle 7 addresses the need to Identify, Analyze, and Respond to Risks. The identification and analysis of risk are presumed to have been performed at the state level, which are addressed in the [https://apps.azsos.gov/election/files/epm/2025/Election-Procedures-Manual-2025--FINAL-12-22-25.pdf Arizona Secretary of State's Election Procedure Manual.] The MC leadership team's <u>Response to Risk</u> is the primary governance weakness with respect to the Green Book's Principle #7, including this attribute.
 
===== >>>>>Allegation #5 - two person rule versus two people from opposite part for drop box pickups =====

Latest revision as of 14:40, 27 August 2026

Risk Assessment

Principle 7 - Identify, Analyze, and Respond to Risks

Attribute 7.12 - When designing controls to mitigate risk, management may modify controls related to the entity's oversight responsibilities, organizational structure, and responsibilities and authorities throughout the entity. Management may also develop separate processes within the periodic and ongoing risk assessment process with separate oversight responsibilities, to manage certain risks as part of the entity's overall internal control system. This may be necessary to achieve objectives due to the nature of certain types of risks, such as for risks related to fraud, improper payments, or information security, or when a risk is pervasive or has an impact on multiple processes. These separate processes would cover all components of internal control related to these specific risks.

>>>Navigational Buttons<<<


Jamie's Story

No examples are available to illustrate governance gaps for this attribute.

Election Anomalies

Principle 7 addresses the need to Identify, Analyze, and Respond to Risks. The identification and analysis of risk are presumed to have been performed at the state level, which are addressed in the Arizona Secretary of State's Election Procedure Manual. The MC leadership team's Response to Risk is the primary governance weakness with respect to the Green Book's Principle #7, including this attribute.

>>>>>Allegation #5 - two person rule versus two people from opposite part for drop box pickups