Template:Principles: Difference between revisions

From Corrective Action Plan AZ
 
(36 intermediate revisions by the same user not shown)
Line 1: Line 1:
=== US GAO Green Book Principles ===
=== Assessment Observations Compared to Green Book Components, Principles, & Attributes ===
# [[Principle 1 - Demonstrate Commitment to Integrity and Ethical Values]]
# [[Principle 2 - Exercise Oversight Responsibility]]
# [[Principle 3 - Establish Structure, Responsibility, and Authority]]
# [[Principle 4 - Demonstrate Commitment to Competence]]
# [[Principle 5 - Enforce Accountability]]
# [[Principle 6 - Define Objectives and Risk Tolerances]]
# [[Principle 7 - Identify, Analyze, and Respond to Risks]]
# [[Principle 8 - Assess Fraud, Improper Payment, and Information]]
# [[Principle 9 - Identify, Analyze, and Respond to Change]]
# [[Principle 10 - Design Control Activities]]
# [[Principle 11 - Design General Control Activities over Information]]
# [[Principle 12 - Implement Control Activities]]
# [[Principle 13 - Use Quality Information]]
# [[Principle 14 - Communicate Internally]]
# [[Principle 15 - Communicate Externally]]
# [[Principle 16 - Perform Monitoring Activities]]
# [[Principle 17 - Evaluate Issues and Remediate Deficiencies]]


=== Index of Green Book Attributes Relating to Maricopa County Performance ===
===== Control Environment =====
<u>Component:</u> '''Control Environment''' ''-'' The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.
* [[1.01|Principle 1]] - Demonstrate Commitment to Integrity and Ethical Values
** Attributes ([[1.01]], [[1.02]], [[1.03]], [[1.04]], [[1.05]], [[1.06]], [[1.07]], [[1.08]], [[1.09]], [[1.10]])


==== '''Principle 1 - Demonstrate Commitment to Integrity and Ethical Values''' ====
* [[2.01|Principle 2]] - Exercise Oversight Responsibility
** Attributes ([[2.01]], [[2.02]], [[2.03]], [[2.04]], [[2.05]], [[2.06]], [[2.07]], [[2.08]], [[2.09]], [[2.10]], [[2.11]], [[2.12]], [[2.13]])


* '''[[1.01|Attribute 1.01]]'''
* [[3.01|Principle 3]] - Establish Structure, Responsibility, and Authority
'''''<big>Tone at the Top</big>'''''
** Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
* '''[[1.02|Attribute 1.02]]'''
* '''[[1.03|Attribute 1.03]]'''
* '''[[1.04|Attribute 1.04]]'''
* '''[[1.05|Attribute 1.05]]'''
'''<big>Standards of Conduct</big>'''
*'''Attribute [[1.06]]'''
* '''Attribute [[1.07]]'''
'''<big>Adherence to Standards of Conduct</big>'''
* '''Attribute [[1.08]]'''
* '''Attribute [[1.10]]              '''
* '''Attribute [[1.11]]'''


==== '''Principle 2 - Exercise Oversight Responsibility''' ====
* [[4.01|Principle 4]] - Demonstrate Commitment to Competence
** Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
* [[5.01|Principle 5]] - Enforce Accountability
**Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)


* '''Attribute 2.01'''
===== Risk Assessment =====
'''<big>Oversight Structure</big>'''
<u>Component:</u> '''Risk Assessment''' - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.
* '''Attribute 2.02'''
* [[6.01|Principle 6]] - Define Objectives and Risk Tolerances
* '''Attribute 2.03'''
**Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
* '''Attribute 2.04'''
* [[7.01|Principle 7]] - Identify, Analyze, and Respond to Risks
* '''Attribute 2.05'''
**Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
* '''Attribute 2.06'''
* [[8.01|Principle 8]] - Assess Fraud, Improper Payment, and Information
* '''Attribute 2.07'''
**Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
* '''Attribute 2.08'''
* [[9.01|Principle 9]] - Identify, Analyze, and Respond to Change
'''<big>Oversight for the Internal Control System</big>'''
**Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
* '''Attribute 2.09'''
* '''Attribute 2.10'''
'''<big>Input for Remediation of Deficiencies</big>'''
* '''Attribute 2.11'''
* '''Attribute 2.12'''
* '''Attribute 2.13'''


==== '''Principle 3 - Establish Structure, Responsibility, and Authority''' ====
===== Control Activities =====
<u>Component:</u> '''Control Activities''' - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.
* [[10.01|Principle 10]] - Design Control Activities
**Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
* [[11.01|Principle 11]] - Design General Control Activities over Information
**Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
* [[12.01|Principle 12]] - Implement Control Activities
**Attributes (12.01, 12.02, 12.03, 12.04, 12.05)


* '''Attribute 3.01'''
===== Information and Communication =====
<u>Component:</u> '''Information and Communication''' - The quality information management and other personnel communicate and use to support the internal control system.
* [[13.01|Principle 13]] - Use Quality Information
**Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
* [[14.01|Principle 14]] - Communicate Internally
**Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
* [[15.01|Principle 15]] - Communicate Externally
**Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)


'''<big>Organizational Structure</big>'''
===== Monitoring =====
<u>Component:</u> '''Monitoring''' - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.
* [[16.01|Principle 16]] - Perform Monitoring Activities
**Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
* [[17.01|Principle 17]] - Evaluate Issues and Remediate Deficiencies
**Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)


* '''Attribute 3.02'''
=== [[Index of Attributes]] ===
* '''Attribute 3.03'''
* '''Attribute 3.04'''
* '''Attribute 3.05'''
 
'''<big>Assignment of Responsibility and Delegation of Authority</big>'''
 
* '''Attribute 3.06'''
* '''Attribute 3.07'''
* '''Attribute 3.08'''
 
'''<big>Documentation of the Internal Control System</big>'''
 
* '''Attribute 3.09'''
* '''Attribute 3.10'''
* '''Attribute 3.11'''
* '''Attribute 3.12'''
 
==== '''Principle 4 - Demonstrate Commitment to Competence''' ====
 
* '''Attribute 4.01'''
 
'''<big>Expectations of Competence</big>'''
 
* '''Attribute 4.02'''
* '''Attribute 4.03'''
* '''Attribute 4.04'''
 
'''<big>Recruitment, Development, and Retention of Individuals</big>'''
 
* '''Attribute 4.05'''
 
'''<big>Succession and Contingency Plans and Preparation</big>'''
 
* '''Attribute 4.06'''
* '''Attribute 4.07'''
* '''Attribute 4.08'''
 
==== '''Principle 5 - Enforce Accountability''' ====
 
* '''Attribute 5.01'''
 
'''<big>Enforcement of Accountability</big>'''
 
* '''Attribute 5.02'''
* '''Attribute 5.03'''
* '''Attribute 5.04'''
* '''Attribute 5.05'''
* '''Attribute 5.06'''
 
'''<big>Consideration of Excessive Pressures</big>'''
 
* '''Attribute 5.07'''
* '''Attribute 5.08'''
 
==== '''Principle 6 - Define Objectives and Risk Tolerances''' ====
 
* '''Attribute 6.01'''
 
'''Definitions of Objectives'''
 
* '''Attribute 6.02'''
* '''Attribute 6.03'''
* '''Attribute 6.04'''
* '''Attribute 6.05'''
* '''Attribute 6.06'''
* '''Attribute 6.07'''
 
'''Definitions of Risk Tolerances'''
 
* '''Attribute 6.08'''
* '''Attribute 6.09'''
* '''Attribute 6.10'''
 
==== '''Principle 7 - Identify, Analyze, and Respond to Risks''' ====
 
* '''Attribute 7.01'''
 
'''<big>Identify Risks</big>'''
 
* '''Attribute 7.02'''
* '''Attribute 7.03'''
 
* '''Attribute 7.04'''
* '''Attribute 7.05'''
* '''Attribute 7.06'''
 
'''<big>Analyze Risks</big>'''
 
* '''Attribute 7.07'''
* '''Attribute 7.08'''
* '''Attribute 7.09'''
 
'''<big>Respond to Risks</big>'''
 
* '''Attribute 7.10'''
* '''Attribute 7.11'''
* '''Attribute 7.12'''
* '''Attribute 7.13'''
* '''Attribute 7.14'''
* '''Attribute 7.15'''
 
==== '''Principle 8 - Assess Fraud, Improper Payment, and Informati<big>on</big>''' ====
 
* '''<big>Attribute 8.01</big>'''
 
'''<big>Identify Risks Related to Fraud, Improper Payments, and Information Security</big>'''
 
* '''Attribute 8.02'''
* '''Attribute 8.03'''
* '''Attribute 8.04'''
* '''Attribute 8.05'''
 
'''<big>Types of Fraud and Fraud Risk Factors</big>'''
 
* '''Attribute 8.06'''
* '''Attribute 8.07'''
* '''Attribute 8.08'''
* '''Attribute 8.09'''
* '''Attribute 8.10'''
 
'''<big>Types of Improper Payments and Improper Payment Risk Factors</big>'''
 
* '''Attribute 8.11'''
* '''Attribute 8.12'''
 
* '''Attribute 8.13'''
 
'''<big>Types of Information Security Risk and Information Security Risk Factors</big>'''
 
* '''Attribute 8.14'''
* '''Attribute 8.15'''
* '''Attribute 8.16'''
* '''Attribute 8.17'''
 
'''<big>Analyze and Respond to Identified Risks</big>'''
 
* '''Attribute 8.18'''
* '''Attribute 8.19'''
* '''Attribute 8.20'''
 
==== '''Principle 9 - Identify, Analyze, and Respond to Change''' ====
 
* '''Attribute 9.01'''
 
'''<big>Identify Significant Changes</big>'''
 
* '''Attribute 9.02'''
* '''Attribute 9.03'''
* '''Attribute 9.04'''
 
'''<big>Establish a Change Assessment Process</big>'''
 
* '''Attribute 9.05'''
* '''Attribute 9.06'''
* '''Attribute 9.07'''
* '''Attribute 9.08'''
* '''Attribute 9.09'''
* '''Attribute 9.10'''
 
'''<big>Identify, Analyze and Respond to Risks Related to Significant Changes</big>'''
 
* '''Attribute 9.11'''
* '''Attribute 9.12'''
* '''Attribute 9.13'''
 
==== '''Principle 10 - Design Control Activities''' ====
 
* '''Attribute 10.01'''
 
'''<big>Response to Risks</big>'''
 
* '''Attribute 10.02'''
 
'''<big>Design of Appropriate Types of Control Activities</big>'''
 
* '''Attribute 10.03'''
* '''Attribute 10.04'''
 
'''<big>Design of Automated and Manual Control Activities</big>'''
 
* '''Attribute 10.05'''
* '''Attribute 10.06'''
* '''Attribute 10.07'''
* '''Attribute 10.08'''
* '''Attribute 10.09'''
 
'''<big>Design of Preventive and Detective Control Activities</big>'''
 
* '''Attribute 10.10'''
* '''Attribute 10.11'''
* '''Attribute 10.12'''
* '''Attribute 10.13'''
 
'''<big>Design of Control Activities at Various Levels</big>'''
 
* '''Attribute 10.14'''
* '''Attribute 10.15'''
* '''Attribute 10.16'''
* '''Attribute 10.17'''
* '''Attribute 10.18'''
* '''Attribute 10.19'''
* '''Attribute 10.20'''
 
'''<big>Segregation of Duties</big>'''
 
* '''Attribute 10.21'''
* '''Attribute 10.22'''
* '''Attribute 10.23'''
 
==== '''Principle 11 - Design General Control Activities over Information''' ====
 
* '''Attribute 11.01'''
 
'''<big>Response to Risks</big>'''
 
* '''Attribute 11.02'''
 
'''<big>Design of the Entity’s Information Technology</big>'''
 
* '''Attribute 11.03'''
* '''Attribute 11.04'''
* '''Attribute 11.05'''
* '''Attribute 11.06'''
 
'''<big>Design of Appropriate Types of General Control Activities</big>'''
 
* '''Attribute 11.07'''
* '''Attribute 11.08'''
* '''Attribute 11.09'''
* '''Attribute 11.10'''
* '''Attribute 11.11'''
* '''Attribute 11.12'''
* '''Attribute 11.13'''
* '''Attribute 11.14'''
* '''Attribute 11.15'''
* '''Attribute 11.16'''
* '''Attribute 11.17'''
 
==== '''Principle 12 - Implement Control Activities''' ====
 
* '''Attribute 12.01'''
 
'''Documentation of Control Activities Through Policies and Procedures'''
 
* '''Attribute 12.02'''
* '''Attribute 12.03'''
* '''Attribute 12.04'''
 
'''<big>Periodic Review of Control Activities</big>'''
 
* '''Attribute 12.05'''
 
==== '''Principle 13 - Use Quality Information''' ====
 
* '''Attribute 13.01'''
 
'''<big>Identification of Information Requirements</big>'''
 
* '''Attribute 13.02'''
* '''Attribute 13.03'''
 
'''<big>Relevant Data from Reliable Sources</big>'''
 
* '''Attribute 13.04'''
 
'''<big>Data Processed into Quality Information</big>'''
 
* '''Attribute 13.05'''
* '''Attribute 13.06'''
* '''Attribute 13.07'''
 
==== '''Principle 14 - Communicate Internally''' ====
 
* '''Attribute 14.01'''
 
'''<big>Communication Throughout the Entity</big>'''
 
* '''Attribute 14.02'''
* '''Attribute 14.03'''
* '''Attribute 14.04'''
* '''Attribute 14.05'''
* '''Attribute 14.06'''
 
'''<big>Appropriate Methods of Communication</big>'''
 
* '''Attribute 14.07'''
* '''Attribute 14.08'''
 
==== '''Principle 15 - Communicate Externally''' ====
 
==== '''Principle 16 - Perform Monitoring Activities''' ====
 
==== '''Principle 17 - Evaluate Issues and Remediate Deficiencies''' ====

Latest revision as of 05:14, 18 August 2026

Assessment Observations Compared to Green Book Components, Principles, & Attributes

Control Environment

Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.

  • Principle 3 - Establish Structure, Responsibility, and Authority
    • Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
  • Principle 4 - Demonstrate Commitment to Competence
    • Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
  • Principle 5 - Enforce Accountability
    • Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment

Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.

  • Principle 6 - Define Objectives and Risk Tolerances
    • Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
  • Principle 7 - Identify, Analyze, and Respond to Risks
    • Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
  • Principle 8 - Assess Fraud, Improper Payment, and Information
    • Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
  • Principle 9 - Identify, Analyze, and Respond to Change
    • Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities

Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.

  • Principle 10 - Design Control Activities
    • Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
  • Principle 11 - Design General Control Activities over Information
    • Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
  • Principle 12 - Implement Control Activities
    • Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication

Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.

  • Principle 13 - Use Quality Information
    • Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
  • Principle 14 - Communicate Internally
    • Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
  • Principle 15 - Communicate Externally
    • Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring

Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.

  • Principle 16 - Perform Monitoring Activities
    • Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
  • Principle 17 - Evaluate Issues and Remediate Deficiencies
    • Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)