8.02: Difference between revisions

From Arizona Citizen Voice
 
(5 intermediate revisions by the same user not shown)
Line 12: Line 12:
=== Jamie's Story ===
=== Jamie's Story ===


==== [[March 12, 2026: This is How Maricopa County Wants to be Represented in Court]] ====
==== [[March 12, 2026: Maricopa County Defense Briefing]] ====
The discussion of Attribute 8.02 is from this March 12, 2026 event, under the subheading of Motor Vehicle Department Contract.
The discussion of Attribute 8.02 is from this March 12, 2026 event, under the subheading of Motor Vehicle Department Contract.


Line 27: Line 27:
For Attribute 8.02, fraud and information security are the primary concerns. That said, improper payments may also be an area of interest given that the contract between MC and Dominion included an annual inflation price increase in the double digits when inflation rate was less than 3% when the contract was approved. However, this type of improper payment would not be associated with fraud since MC management knowingly approved of the higher than actual inflation rate. Contrary to the Green Book, MC was unable to provide any objective evidence to explain how they investigated numerous election-related anomalies as potential fraud.   
For Attribute 8.02, fraud and information security are the primary concerns. That said, improper payments may also be an area of interest given that the contract between MC and Dominion included an annual inflation price increase in the double digits when inflation rate was less than 3% when the contract was approved. However, this type of improper payment would not be associated with fraud since MC management knowingly approved of the higher than actual inflation rate. Contrary to the Green Book, MC was unable to provide any objective evidence to explain how they investigated numerous election-related anomalies as potential fraud.   


=== The Anomalies ===
=== Election Anomalies ===
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.
 
The Green Book's <u>emphasis on fraud and information security</u> as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.
 
===== Arizona Senate Allegations =====
Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation]. In their oversight role, the Arizona Senate sought to understand the risk to accurate tabulation of election results given the abundance of election-related anomalies. The Arizona Senate's allegations were focused on the potential for fraud. Yet, MC elected officials and MC leadership did not investigate any of the election anomalies for fraud, which necessitated the turnover of their allegations to the Arizona Attorney General. This potential deviation from the Green Book standard applies to the following Arizona Senate Allegations:
 
* [[The Anomalies#Maricopa Election Management Server (2020)|Maricopa Election Management Server (2020)]]
** [[The Anomalies#MC EMS 2020 - Election Management System Database Purged|MC EMS 2020 - Election Management System Database Purged]]
** [[The Anomalies#MC EMS 2020 - Election Files Deleted|MC EMS 2020 - Election Files Deleted]]
** [[The Anomalies#MC EMS 2020 - Corrupt Ballot Images|MC EMS 2020 - Corrupt Ballot Images]]
** [[The Anomalies#MC EMS 2020 - Missing Ballot Images|MC EMS 2020 - Missing Ballot Images]]
** [[The Anomalies#MC EMS 2020 - Failure to Follow Basic Cyber Security Practices|MC EMS 2020 - Failure to Follow Basic Cyber Security Practices]]
** [[The Anomalies#MC EMS 2020 - Subpoenaed Equipment Not Yet Provided|MC EMS 2020 - Subpoenaed Equipment Not Yet Provided]]
** [[The Anomalies#MC EMS 2020 - Anonymous Logins|MC EMS 2020 - Anonymous Logins]]
** [[The Anomalies#MC EMS 2020 - Dual Boot System Discovered|MC EMS 2020 - Dual Boot System Discovered]]
** [[The Anomalies#MC EMS 2020 - Operating System Logs Not Preserved|MC EMS 2020 - Operating System Logs Not Preserved]]
** [[The Anomalies#MC EMS 2020 - Internet Connections to the EMS|MC EMS 2020 - Internet Connections to the EMS]]
 
===== [[Dropbox Collection (2020)|Maricopa Dropbox Collection (2020)]] =====
Governance issues identified from [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation] of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues. Section 2 of the AZ AG's inspector's report identifies numerous issues, which present risk to potential fraud.
 
This attribute specifically states, "Ongoing risk assessments are performed as needed, on a real-time basis, such as when significant internal or external change occurs or significant emerging risks are identified." External changes consisted of Public Health mandates associated with the Covid-19 pandemic. Rather than implement risk reduction actions, MC management appeared to ignore procedure requirements, which actually increased the risk of fraud. The following issues identified in the inspector's report are related to management actions or inaction related to increasing the risk of fraud:
 
* See the heading [[Dropbox Collection (2020)#Deviation: Missing Entries on Election Forms|Deviation: Missing Entries on Election Forms]] from Maricopa Dropbox Collection (2020) webpage.
* See the heading [[Dropbox Collection (2020)#Deviation: Missing Ballot Counts|Deviation: Missing Ballot Counts]] from Maricopa Dropbox Collection (2020) webpage.
* See the heading [[Dropbox Collection (2020)#Deviation: Used Email instead of EVBTS Forms|Deviation: Used Email instead of EVBTS Forms]] from Maricopa Dropbox Collection (2020) webpage.
* See the heading [[Dropbox Collection (2020)#Deviation: Unfulfilled Party Representation Requirement for Couriers.|Deviation: Unfulfilled Party Representation Requirements for Couriers]] from Maricopa Dropbox Collection (2020) webpage.
* See the heading [[Dropbox Collection (2020)#Deviation: Fictious Addresses in the MC Voter Registration Database|Deviation: Fictious Addresses in MC Voter Registration Database]] from Maricopa Dropbox Collection (2020) webpage.
* See the heading [[Dropbox Collection (2020)#Deviation: Allegations Confirmed|Deviation: Allegations Confirmed]] from Maricopa Dropbox Collection (2020) webpage.
* See the heading [[Dropbox Collection (2020)#Noteworthy: Consequences Unknown|Noteworthy: Consequences Unknown]] from Maricopa Dropbox Collection (2020) webpage
* See the heading [[Dropbox Collection (2020)#Noteworthy: Transmission of USPS Data to MC and Runbeck|Noteworthy: Transmission of USPS Data to MC and Runbeck]] from Maricopa Dropbox Collection (2020) webpage


===== [[Signature Verification|Maricopa County Signature Verification (2020)]] =====
===== [[Signature Verification|Maricopa County Signature Verification (2020)]] =====
Governance issues identified from [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation] of Arizona Senate allegations of Maricopa County - Signature Verification Process issues.ds This attribute applies because of the relevance to fraud and security risk. It's a balancing act between detecting voter fraud and preserving the confidentiality of the vote. As applied by Maricopa County, there appears the maximum effort to preserve the confidentiality of the vote is being outweighed over the need to detect fraudulent votes.  
Governance issues identified from [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation] of Arizona Senate allegations of Maricopa County - Signature Verification Process issues. This attribute applies because of the relevance to fraud and security risk. It's a balancing act between detecting voter fraud and preserving the confidentiality of the vote. As applied by Maricopa County, there appears the maximum effort to preserve the confidentiality of the vote is being outweighed over the need to detect fraudulent votes.  
 
A single person, the Signature Verifier, is expected to make a fraud decision every seven-seconds. The is an apparent lack of analysis to assess the risk of fraud not being detected by the signature verifier. 
   
   
__FORCETOC__
__FORCETOC__

Latest revision as of 10:35, 14 September 2026

Risk Assessment

Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk

Attribute 8.02 - Management identifies risks related to fraud, improper payments, and information security through the same risk identification process performed for all analyzed risks. However, these risks are discussed further in this principle because they may be pervasive or have an impact on multiple processes and can often be inadequately addressed in the risk assessment process.

Navigational Buttons:

Jamie's Story

The discussion of Attribute 8.02 is from this March 12, 2026 event, under the subheading of Motor Vehicle Department Contract.

Attribute 8.02 is unique, it seems redundant to the prior Green Book presentation "Risk Assessment" as addressed in "Components of Internal Controls." The Green Book discussion of Risk Assessment identified four risk-related Principles (i.e., 6, 7, 8, and 9), which consisted of 58 specific attributes. Despite all the prior emphasis of addressing risk, the Green Book intentionally placed the topic of risk within a broader topic of fraud, improper payments and information security. Why?

The prior discussion of risk addressed how things can go wrong on a good day; sometimes the unexpected happens and it's in the manager's best interest to understand how day-to-day operations can be disrupted from the unexpected. Here, in Principle 8 addresses risk from the perspective of malicious intent; there are "bad" people or entities that will try to deceive the governing entity for personal benefit. Thus, the Green Book addresses the risk of malicious intent separately from day-to-day risk.

Would there be any motivation to infiltrate and deceive the MC to sway the election results?

The obvious answer is "Yes." So what is MC doing to address the risk of malicious intent?

Apparently, the answer is "Nothing." Perhaps, some MC employees may be purposefully ignoring the risk, which may have legal implications, which are far beyond the scope of this governance assessment.

For Attribute 8.02, fraud and information security are the primary concerns. That said, improper payments may also be an area of interest given that the contract between MC and Dominion included an annual inflation price increase in the double digits when inflation rate was less than 3% when the contract was approved. However, this type of improper payment would not be associated with fraud since MC management knowingly approved of the higher than actual inflation rate. Contrary to the Green Book, MC was unable to provide any objective evidence to explain how they investigated numerous election-related anomalies as potential fraud.

Election Anomalies

The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.

The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.

Arizona Senate Allegations

Arizona Senate allegations arose from MC's failure to recognize the Arizona Senates Oversight Role. These allegations were investigated and reported on by the Arizona Attorney General's Office 2020 General Election Investigation. In their oversight role, the Arizona Senate sought to understand the risk to accurate tabulation of election results given the abundance of election-related anomalies. The Arizona Senate's allegations were focused on the potential for fraud. Yet, MC elected officials and MC leadership did not investigate any of the election anomalies for fraud, which necessitated the turnover of their allegations to the Arizona Attorney General. This potential deviation from the Green Book standard applies to the following Arizona Senate Allegations:

Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues. Section 2 of the AZ AG's inspector's report identifies numerous issues, which present risk to potential fraud.

This attribute specifically states, "Ongoing risk assessments are performed as needed, on a real-time basis, such as when significant internal or external change occurs or significant emerging risks are identified." External changes consisted of Public Health mandates associated with the Covid-19 pandemic. Rather than implement risk reduction actions, MC management appeared to ignore procedure requirements, which actually increased the risk of fraud. The following issues identified in the inspector's report are related to management actions or inaction related to increasing the risk of fraud:

Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County - Signature Verification Process issues. This attribute applies because of the relevance to fraud and security risk. It's a balancing act between detecting voter fraud and preserving the confidentiality of the vote. As applied by Maricopa County, there appears the maximum effort to preserve the confidentiality of the vote is being outweighed over the need to detect fraudulent votes.

A single person, the Signature Verifier, is expected to make a fraud decision every seven-seconds. The is an apparent lack of analysis to assess the risk of fraud not being detected by the signature verifier.