9.10: Difference between revisions
From Arizona Citizen Voice
No edit summary |
No edit summary |
||
| (One intermediate revision by the same user not shown) | |||
| Line 6: | Line 6: | ||
* modifying the organizational structure, responsibilities, and authorities to address identified risks; | * modifying the organizational structure, responsibilities, and authorities to address identified risks; | ||
* determining whether to create a separate process, with separate oversight responsibilities, to manage risks related to the change as part of the entity's overall internal control system; | * determining whether to create a separate process, with separate oversight responsibilities, to manage risks related to the change as part of the entity's overall internal control system; | ||
* identifying any existing control activities, policies and procedures, or other processes in existing or similar programs that could be leveraged or modified; | * identifying any existing control activities, policies and procedures, or other processes in existing or similar programs that could be leveraged or modified; | ||
* identifying preventive control activities that could be implemented prior to the distribution of program benefits, even if time or resources are constrained; | * identifying preventive control activities that could be implemented prior to the distribution of program benefits, even if time or resources are constrained; | ||
| Line 17: | Line 17: | ||
* '''[[Index of Attributes]]''' | * '''[[Index of Attributes]]''' | ||
* '''Previous Attribute - [[9.09]]''' | * '''Previous Attribute - [[9.09]]''' | ||
* '''Next Attribute - [[9. | * '''Next Attribute - [[9.11]]''' | ||
__FORCETOC__ | __FORCETOC__ | ||
Latest revision as of 16:07, 27 August 2026
Risk Assessment
Principle 9 - Identify, Analyze, and Respond to Change
Attribute 9.10 - Management's change assessment process includes considerations to facilitate its ability to quickly adapt the entity's internal control system and effectively respond to a significant change once it occurs, such as the following:
- modifying the organizational structure, responsibilities, and authorities to address identified risks;
- determining whether to create a separate process, with separate oversight responsibilities, to manage risks related to the change as part of the entity's overall internal control system;
- identifying any existing control activities, policies and procedures, or other processes in existing or similar programs that could be leveraged or modified;
- identifying preventive control activities that could be implemented prior to the distribution of program benefits, even if time or resources are constrained;
- identifying monitoring and detective control activities that could be enhanced or performed more frequently if preventive controls to mitigate certain risks are not feasible;
- considering lessons learned from past programs to inform future practices;
- identifying and establishing communications with external parties that may contribute to the operational effectiveness of the entity's internal control system when implementing the change; and
- identifying and establishing data-sharing, data-matching, and data-analytics opportunities, including considering known data access issues.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 9.09
- Next Attribute - 9.11
Jamie's Story
No examples are available to illustrate governance gaps for this attribute.
Election Anomalies
No examples are available to illustrate governance gaps for this attribute.
