9.10: Difference between revisions

From Arizona Citizen Voice
No edit summary
No edit summary
 
(One intermediate revision by the same user not shown)
Line 6: Line 6:


* modifying the organizational structure, responsibilities, and authorities to address identified risks;
* modifying the organizational structure, responsibilities, and authorities to address identified risks;
* determining whether to create a separate process, with separate oversight responsibilities, to manage risks related to the change as part of the entity's overall internal control system;<sup>72</sup>
* determining whether to create a separate process, with separate oversight responsibilities, to manage risks related to the change as part of the entity's overall internal control system;
* identifying any existing control activities, policies and procedures, or other processes in existing or similar programs that could be leveraged or modified;
* identifying any existing control activities, policies and procedures, or other processes in existing or similar programs that could be leveraged or modified;
* identifying preventive control activities that could be implemented prior to the distribution of program benefits, even if time or resources are constrained;
* identifying preventive control activities that could be implemented prior to the distribution of program benefits, even if time or resources are constrained;
Line 17: Line 17:
* '''[[Index of Attributes]]'''
* '''[[Index of Attributes]]'''
* '''Previous Attribute - [[9.09]]'''
* '''Previous Attribute - [[9.09]]'''
* '''Next Attribute - [[9.12]]'''
* '''Next Attribute - [[9.11]]'''
__FORCETOC__
__FORCETOC__



Latest revision as of 16:07, 27 August 2026

Risk Assessment

Principle 9 - Identify, Analyze, and Respond to Change

Attribute 9.10 - Management's change assessment process includes considerations to facilitate its ability to quickly adapt the entity's internal control system and effectively respond to a significant change once it occurs, such as the following:

  • modifying the organizational structure, responsibilities, and authorities to address identified risks;
  • determining whether to create a separate process, with separate oversight responsibilities, to manage risks related to the change as part of the entity's overall internal control system;
  • identifying any existing control activities, policies and procedures, or other processes in existing or similar programs that could be leveraged or modified;
  • identifying preventive control activities that could be implemented prior to the distribution of program benefits, even if time or resources are constrained;
  • identifying monitoring and detective control activities that could be enhanced or performed more frequently if preventive controls to mitigate certain risks are not feasible;
  • considering lessons learned from past programs to inform future practices;
  • identifying and establishing communications with external parties that may contribute to the operational effectiveness of the entity's internal control system when implementing the change; and
  • identifying and establishing data-sharing, data-matching, and data-analytics opportunities, including considering known data access issues.

>>>Navigational Buttons<<<


Jamie's Story

No examples are available to illustrate governance gaps for this attribute.

Election Anomalies

No examples are available to illustrate governance gaps for this attribute.