Principle 12 - Implement Control Activities: Difference between revisions

From Arizona Citizen Voice
No edit summary
 
(5 intermediate revisions by 2 users not shown)
Line 1: Line 1:
__NOTOC__
== 12.0 Implement Control Activities ==
[https://guides.gaoinnovations.gov/greenbook/2025/principle-12-implement-control-activities/ External Link to US GAO Green Book Principle 12]


12.01 Management should implement control activities through policies
=== Overview ===
and procedures.


Documentation of Control Activities Through Policies and Procedures
==== '''[[12.01]]''' ====
Management should implement control activities through policies and procedures.


12.02 Management establishes control activities by documenting in
=== 12.1 Documentation of Control Activities Through Policies and Procedures ===
policies what is expected and in procedures specified actions that
implement policies, to mitigate risks to achieving the entity’s
objectives to acceptable levels [documentation requirement].


12.03 Management documents in policies and procedures for each unit
==== '''[[12.02]]''' ====
within the entity’s organizational structure its responsibility for a
Management establishes control activities by documenting in policies what is expected and in procedures specified actions that implement policies, to mitigate risks to achieving the entity’s objectives to acceptable levels '''[documentation requirement].'''
business process’s objectives and related risks and control activity
design, implementation, and operating effectiveness.102 Each unit, with
guidance from management, determines the policies necessary to operate
the business process based on the objectives and related risks. Each
unit also documents policies and procedures in the appropriate level of
detail to allow management to effectively monitor the control activity.
The documentation may appear in various forms, such as management
directives, administrative policies, or operating manuals.


12.04 Those in key roles for the unit may further define policies
==== '''[[12.03]]''' ====
through day-to-day procedures, depending on the rate of change in the
Management documents in policies and procedures for each unit within the entity’s organizational structure its responsibility for a business process’s objectives and related risks and control activity design, implementation, and operating effectiveness. Each unit, with guidance from management, determines the policies necessary to operate the business process based on the objectives and related risks. Each unit also documents policies and procedures in the appropriate level of detail to allow management to effectively monitor the control activity. The documentation may appear in various forms, such as management directives, administrative policies, or operating manuals.
operating environment and complexity of the business process. Procedures
may include the timing of when a control activity occurs and any
follow-up corrective actions to be performed by competent personnel if
deficiencies are identified.103 Management communicates the policies and
procedures entity-wide so that personnel can implement the control
activities for their assigned responsibilities.


Periodic Review of Control Activities
==== '''[[12.04]]''' ====
Those in key roles for the unit may further define policies through day-to-day procedures, depending on the rate of change in the operating environment and complexity of the business process. Procedures may include the timing of when a control activity occurs and any follow-up corrective actions to be performed by competent personnel if deficiencies are identified. Management communicates the policies and procedures entity-wide so that personnel can implement the control activities for their assigned responsibilities.


12.05 Management reviews policies, procedures, and related control
=== 12.2 Periodic Review of Control Activities ===
activities on a periodic and ongoing basis for continued relevance and
effectiveness in achieving the entity’s objectives or mitigating related
risks. If there is a significant change in an entity’s process,
management reviews this process in a timely manner after the change to
determine that the control activities are designed and implemented
appropriately. Changes may occur in personnel, business processes, or
information technology. A new law or regulation may change an entity’s
objectives or how an entity is to achieve an objective. Further, in the
federal environment, this may occur through government-wide policy or
guidance issued by entities like the Office of Management and Budget,
Office of Personnel Management, and the Department of the Treasury.
Management considers these changes in its periodic and ongoing reviews.
Management also considers the results of its monitoring activities to
determine whether control activities are designed and implemented
effectively.


{{Principles}}
==== '''[[12.05]]''' ====
Management reviews policies, procedures, and related control activities on a periodic and ongoing basis for continued relevance and effectiveness in achieving the entity’s objectives or mitigating related risks. If there is a significant change in an entity’s process, management reviews this process in a timely manner after the change to determine that the control activities are designed and implemented appropriately. Changes may occur in personnel, business processes, or information technology. A new law or regulation may change an entity’s objectives or how an entity is to achieve an objective. Further, in the federal environment, this may occur through government-wide policy or guidance issued by entities like the Office of Management and Budget, Office of Personnel Management, and the Department of the Treasury. Management considers these changes in its periodic and ongoing reviews. Management also considers the results of its monitoring activities to determine whether control activities are designed and implemented effectively.


== Related Story Events ==
'''<big>[[Index of Attributes|Back to Index of Principles and Attributes]]</big>'''
 
* [[2020: The Event|🗳️ 2020: The Event]]
* [[December 2024: Gaining Support|📋 December 2024: Gaining Support]]

Latest revision as of 12:11, 16 September 2026

12.0 Implement Control Activities

External Link to US GAO Green Book Principle 12

Overview

Management should implement control activities through policies and procedures.

12.1 Documentation of Control Activities Through Policies and Procedures

Management establishes control activities by documenting in policies what is expected and in procedures specified actions that implement policies, to mitigate risks to achieving the entity’s objectives to acceptable levels [documentation requirement].

Management documents in policies and procedures for each unit within the entity’s organizational structure its responsibility for a business process’s objectives and related risks and control activity design, implementation, and operating effectiveness. Each unit, with guidance from management, determines the policies necessary to operate the business process based on the objectives and related risks. Each unit also documents policies and procedures in the appropriate level of detail to allow management to effectively monitor the control activity. The documentation may appear in various forms, such as management directives, administrative policies, or operating manuals.

Those in key roles for the unit may further define policies through day-to-day procedures, depending on the rate of change in the operating environment and complexity of the business process. Procedures may include the timing of when a control activity occurs and any follow-up corrective actions to be performed by competent personnel if deficiencies are identified. Management communicates the policies and procedures entity-wide so that personnel can implement the control activities for their assigned responsibilities.

12.2 Periodic Review of Control Activities

Management reviews policies, procedures, and related control activities on a periodic and ongoing basis for continued relevance and effectiveness in achieving the entity’s objectives or mitigating related risks. If there is a significant change in an entity’s process, management reviews this process in a timely manner after the change to determine that the control activities are designed and implemented appropriately. Changes may occur in personnel, business processes, or information technology. A new law or regulation may change an entity’s objectives or how an entity is to achieve an objective. Further, in the federal environment, this may occur through government-wide policy or guidance issued by entities like the Office of Management and Budget, Office of Personnel Management, and the Department of the Treasury. Management considers these changes in its periodic and ongoing reviews. Management also considers the results of its monitoring activities to determine whether control activities are designed and implemented effectively.

Back to Index of Principles and Attributes