8.07: Difference between revisions

From Arizona Citizen Voice
 
(One intermediate revision by the same user not shown)
Line 17: Line 17:


=== Election Anomalies ===
=== Election Anomalies ===
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.


==== [[Fraud Potential (2020, 2022, 2024, 2025)]] ====
The Green Book's <u>emphasis on fraud and information security</u> as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.  
Additional details regarding this aspect of my story are available in a subsection titled Contract with the Motor Vehicle Department (MVD).
 
In 2024, the Arizona Secretary of State, Adrian Fontes, issued a '''press release on September 30, 2024''', which described how over 218,000 voter registration records were adversely impacted during the collection of data by the MVD and subsequent transfer to the MC Recorders Office. The press release states, "Staff and experts from the Secretary of State’s Office are continuing to work with MVD to investigate if additional voters are impacted, or if other similar errors stemming from improperly coded Proposition 200 rules exist. We will continue to keep the public informed of developments if and when we have accurate, confirmed information to share." The Information Security Risk was real based on the number of corrupted records identified. Yet, MC managers and legal team had no written agreements between them and the MVD. Contrary to the Green Book, there is no evidence to suggest MC recognized the significance of elevated risk associated with receiving data from an external entity, which was the MVD.


===== [[Dropbox Collection (2020)|Maricopa Dropbox Collection (2020)]] =====
==== [[Dropbox Collection (2020)|Maricopa Dropbox Collection (2020)]] ====
Governance issues identified from [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation] of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues. The inspector notes a USPS Inspector reported 56,226 early ballots were undeliverable.
Governance issues identified from [https://www.azag.gov/sites/default/files/2025-06/2020_General_Election_Investigation_Summary.pdf Arizona Attorney General's Office 2020 General Election Investigation] of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues. The inspector notes a USPS Inspector reported 56,226 early ballots were undeliverable.


Line 35: Line 33:


The AZ AG's inspector's notes is silent on the storage of 56,226 undelivered early ballots. Were they stored in a secure location? Was the storage of undelivered early ballots addressed in a written agreement between MC Elections and USPS?
The AZ AG's inspector's notes is silent on the storage of 56,226 undelivered early ballots. Were they stored in a secure location? Was the storage of undelivered early ballots addressed in a written agreement between MC Elections and USPS?
==== [[Fraud Potential (2020, 2022, 2024, 2025)]] ====
Additional details regarding this aspect of my story are available in a subsection titled Contract with the Motor Vehicle Department (MVD).
In 2024, the Arizona Secretary of State, Adrian Fontes, issued a '''press release on September 30, 2024''', which described how over 218,000 voter registration records were adversely impacted during the collection of data by the MVD and subsequent transfer to the MC Recorders Office. The press release states, "Staff and experts from the Secretary of State’s Office are continuing to work with MVD to investigate if additional voters are impacted, or if other similar errors stemming from improperly coded Proposition 200 rules exist. We will continue to keep the public informed of developments if and when we have accurate, confirmed information to share." The Information Security Risk was real based on the number of corrupted records identified. Yet, MC managers and legal team had no written agreements between them and the MVD. Contrary to the Green Book, there is no evidence to suggest MC recognized the significance of elevated risk associated with receiving data from an external entity, which was the MVD.

Latest revision as of 12:14, 25 August 2026

Risk Assessment

Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk

Attribute 8.07 - As part of a risk assessment, management considers the risk of fraud that could impact the entity from both within the entity and from external parties. For example, external fraud risk may arise when an entity relies on service organizations' internal control systems to perform business processes for the entity. External parties that present fraud risk may also include program beneficiaries who fraudulently obtain benefits.

>>>Navigational Buttons<<<


Jamie's Story

No examples are available

Election Anomalies

The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.

The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.

Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues. The inspector notes a USPS Inspector reported 56,226 early ballots were undeliverable.

It is important to note undeliverable ballots in the wrong hand could be fraudulently completed and then submitted in a drop box. Undelivered mail does not change the contents of the envelope; a good ballot was being mailed by MC but intercepted by USPS as being undeliverable.

The USPS Inspector describes how the 56,226 ballots were scanned into an "Address Change Service File" for later use. If this was performed during the election, was chain of custody documented to ensure the same number of ballots to be scanned left the scanning facility. Was this USPS scanning function addressed in any written agreement between MC and the USPS?

The USPS Inspector did not provide any documentation to prove that chain of custody was documented when theses ballots were turned over to BlueEarth Secure Destruction Process to confirm all 56,226 ballots were destroyed. If these ballots were destroyed during the election, any ballots siphoned off by wrongdoers at BlueEarth could be used for fraudulent voting. The services of this third party, without any contract with MC County, could impact fraud. Was this USPS scanning function addressed in any written agreement between MC and the USPS?

The USPS describes how a data file of 56,226 addresses for the undelivered mail were provided to MC Elections and Runbeck Election Services. Again, the inspector's notes were generic in terms of the describing the USPS intent but did not provide any documentation to describe the chain of custody transfer of their data file to any specific person at MC Elections or Runbeck Election Services. Was this USPS transfer of a data file containing addresses for undelivered early ballots contained within any written agreement between MC and the USPS? Especially, the transfer of sensitive data between two third parties (USPS to Runbeck) without any MC involvement. How could MC determine if their data and Runbecks data files were the same, when considering that data corruption may somehow be exploited by fraudsters.

The AZ AG's inspector's notes is silent on the storage of 56,226 undelivered early ballots. Were they stored in a secure location? Was the storage of undelivered early ballots addressed in a written agreement between MC Elections and USPS?

Additional details regarding this aspect of my story are available in a subsection titled Contract with the Motor Vehicle Department (MVD).

In 2024, the Arizona Secretary of State, Adrian Fontes, issued a press release on September 30, 2024, which described how over 218,000 voter registration records were adversely impacted during the collection of data by the MVD and subsequent transfer to the MC Recorders Office. The press release states, "Staff and experts from the Secretary of State’s Office are continuing to work with MVD to investigate if additional voters are impacted, or if other similar errors stemming from improperly coded Proposition 200 rules exist. We will continue to keep the public informed of developments if and when we have accurate, confirmed information to share." The Information Security Risk was real based on the number of corrupted records identified. Yet, MC managers and legal team had no written agreements between them and the MVD. Contrary to the Green Book, there is no evidence to suggest MC recognized the significance of elevated risk associated with receiving data from an external entity, which was the MVD.