Template:Principles: Difference between revisions

From Corrective Action Plan AZ
 
(24 intermediate revisions by the same user not shown)
Line 1: Line 1:
=== US GAO Green Book Principles ===
=== Assessment Observations Compared to Green Book Components, Principles, & Attributes ===
# [[Principle 1 - Demonstrate Commitment to Integrity and Ethical Values]]
# [[Principle 2 - Exercise Oversight Responsibility]]
# [[Principle 3 - Establish Structure, Responsibility, and Authority]]
# [[Principle 4 - Demonstrate Commitment to Competence]]
# [[Principle 5 - Enforce Accountability]]
# [[Principle 6 - Define Objectives and Risk Tolerances]]
# [[Principle 7 - Identify, Analyze, and Respond to Risks]]
# [[Principle 8 - Assess Fraud, Improper Payment, and Information]]
# [[Principle 9 - Identify, Analyze, and Respond to Change]]
# [[Principle 10 - Design Control Activities]]
# [[Principle 11 - Design General Control Activities over Information]]
# [[Principle 12 - Implement Control Activities]]
# [[Principle 13 - Use Quality Information]]
# [[Principle 14 - Communicate Internally]]
# [[Principle 15 - Communicate Externally]]
# [[Principle 16 - Perform Monitoring Activities]]
# [[Principle 17 - Evaluate Issues and Remediate Deficiencies]]


=== Index of Green Book Attributes Relating to Maricopa County Performance ===
===== Control Environment =====
<u>Component:</u> '''Control Environment''' ''-'' The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.
* [[1.01|Principle 1]] - Demonstrate Commitment to Integrity and Ethical Values
** Attributes ([[1.01]], [[1.02]], [[1.03]], [[1.04]], [[1.05]], [[1.06]], [[1.07]], [[1.08]], [[1.09]], [[1.10]])


==== '''Principle 1 - Demonstrate Commitment to Integrity and Ethical Values''' ====
* [[2.01|Principle 2]] - Exercise Oversight Responsibility
** Attributes ([[2.01]], [[2.02]], [[2.03]], [[2.04]], [[2.05]], [[2.06]], [[2.07]], [[2.08]], [[2.09]], [[2.10]], [[2.11]], [[2.12]], [[2.13]])


* '''[[1.01|Attribute 1.01]]'''
* [[3.01|Principle 3]] - Establish Structure, Responsibility, and Authority
'''''<big>Tone at the Top</big>'''''
** Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
* '''[[1.02|Attribute 1.02]]'''
* '''[[1.03|Attribute 1.03]]'''
* '''[[1.04|Attribute 1.04]]'''
* '''[[1.05|Attribute 1.05]]'''
'''<big>Standards of Conduct</big>'''
*'''Attribute [[1.06]]'''
* '''Attribute [[1.07]]'''
'''<big>Adherence to Standards of Conduct</big>'''
* '''Attribute [[1.08]]'''
* '''Attribute [[1.09]]'''
* '''Attribute [[1.10]]              '''


==== '''Principle 2 - Exercise Oversight Responsibility''' ====
* [[4.01|Principle 4]] - Demonstrate Commitment to Competence
** Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
* [[5.01|Principle 5]] - Enforce Accountability
**Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)


* '''Attribute [[2.01]]'''
===== Risk Assessment =====
'''<big>Oversight Structure</big>'''
<u>Component:</u> '''Risk Assessment''' - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.
* '''Attribute [[2.02]]'''
* [[6.01|Principle 6]] - Define Objectives and Risk Tolerances
* '''Attribute [[2.03]]'''
**Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
* '''Attribute [[2.04]]'''
* [[7.01|Principle 7]] - Identify, Analyze, and Respond to Risks
* '''Attribute [[2.05]]'''
**Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
* '''Attribute [[2.06]]'''
* [[8.01|Principle 8]] - Assess Fraud, Improper Payment, and Information
* '''Attribute [[2.07]]'''
**Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
* '''Attribute [[2.08]]'''
* [[9.01|Principle 9]] - Identify, Analyze, and Respond to Change
'''<big>Oversight for the Internal Control System</big>'''
**Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
* '''Attribute [[2.09]]'''
* '''Attribute [[2.10]]'''
'''<big>Input for Remediation of Deficiencies</big>'''
* '''Attribute [[2.11]]'''
* '''Attribute [[2.12]]'''
* '''Attribute [[2.13]]'''


==== '''Principle 3 - Establish Structure, Responsibility, and Authority''' ====
===== Control Activities =====
<u>Component:</u> '''Control Activities''' - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.
* [[10.01|Principle 10]] - Design Control Activities
**Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
* [[11.01|Principle 11]] - Design General Control Activities over Information
**Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
* [[12.01|Principle 12]] - Implement Control Activities
**Attributes (12.01, 12.02, 12.03, 12.04, 12.05)


* '''Attribute [[3.01]]'''
===== Information and Communication =====
<u>Component:</u> '''Information and Communication''' - The quality information management and other personnel communicate and use to support the internal control system.
* [[13.01|Principle 13]] - Use Quality Information
**Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
* [[14.01|Principle 14]] - Communicate Internally
**Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
* [[15.01|Principle 15]] - Communicate Externally
**Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)


'''<big>Organizational Structure</big>'''
===== Monitoring =====
<u>Component:</u> '''Monitoring''' - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.
* [[16.01|Principle 16]] - Perform Monitoring Activities
**Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
* [[17.01|Principle 17]] - Evaluate Issues and Remediate Deficiencies
**Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)


* '''Attribute [[3.02]]'''
=== [[Index of Attributes]] ===
* '''Attribute [[3.03]]'''
* '''Attribute [[3.04]]'''
* '''Attribute [[3.05]]'''
 
'''<big>Assignment of Responsibility and Delegation of Authority</big>'''
 
* '''Attribute [[3.06]]'''
* '''Attribute [[3.07]]'''
* '''Attribute [[3.08]]'''
 
'''<big>Documentation of the Internal Control System</big>'''
 
* '''Attribute [[3.09]]'''
* '''Attribute [[3.10]]'''
* '''Attribute [[3.11]]'''
* '''Attribute [[3.12]]'''
 
==== '''Principle 4 - Demonstrate Commitment to Competence''' ====
 
* '''Attribute [[4.01]]'''
 
'''<big>Expectations of Competence</big>'''
 
* '''Attribute [[4.02]]'''
* '''Attribute [[4.03]]'''
* '''Attribute [[4.04]]'''
 
'''<big>Recruitment, Development, and Retention of Individuals</big>'''
 
* '''Attribute [[4.05]]'''
 
'''<big>Succession and Contingency Plans and Preparation</big>'''
 
* '''Attribute [[4.06]]'''
* '''Attribute [[4.07]]'''
* '''Attribute [[4.08]]'''
 
==== '''Principle 5 - Enforce Accountability''' ====
 
* '''Attribute [[5.01]]'''
 
'''<big>Enforcement of Accountability</big>'''
 
* '''Attribute [[5.02]]'''
* '''Attribute [[5.03]]'''
* '''Attribute [[5.04]]'''
* '''Attribute [[5.05]]'''
* '''Attribute [[5.06]]'''
 
'''<big>Consideration of Excessive Pressures</big>'''
 
* '''Attribute [[5.07]]'''
* '''Attribute [[5.08]]'''
 
==== '''Principle 6 - Define Objectives and Risk Tolerances''' ====
 
* '''Attribute [[6.01]]'''
 
'''Definitions of Objectives'''
 
* '''Attribute [[6.02]]'''
* '''Attribute [[6.03]]'''
* '''Attribute [[6.04]]'''
* '''Attribute [[6.05]]'''
* '''Attribute [[6.06]]'''
* '''Attribute [[6.07]]'''
 
'''Definitions of Risk Tolerances'''
 
* '''Attribute [[6.08]]'''
* '''Attribute [[6.09]]'''
* '''Attribute [[6.10]]'''
 
==== '''Principle 7 - Identify, Analyze, and Respond to Risks''' ====
 
* '''Attribute [[7.01]]'''
 
'''<big>Identify Risks</big>'''
 
* '''Attribute [[7.02]]'''
* '''Attribute [[7.03]]'''
 
* '''Attribute [[7.04]]'''
* '''Attribute [[7.05]]'''
* '''Attribute [[7.06]]'''
 
'''<big>Analyze Risks</big>'''
 
* '''Attribute [[7.07]]'''
* '''Attribute [[7.08]]'''
* '''Attribute [[7.09]]'''
 
'''<big>Respond to Risks</big>'''
 
* '''Attribute [[7.10]]'''
* '''Attribute [[7.11]]'''
* '''Attribute [[7.12]]'''
* '''Attribute [[7.13]]'''
* '''Attribute [[7.14]]'''
* '''Attribute [[7.15]]'''
 
==== '''Principle 8 - Assess Fraud, Improper Payment, and Informati<big>on</big>''' ====
 
* '''Attribute [[8.01]]'''
 
'''<big>Identify Risks Related to Fraud, Improper Payments, and Information Security</big>'''
 
* '''Attribute [[8.02]]'''
* '''Attribute [[8.03]]'''
* '''Attribute [[8.04]]'''
* '''Attribute [[8.05]]'''
 
'''<big>Types of Fraud and Fraud Risk Factors</big>'''
 
* '''Attribute [[8.06]]'''
* '''Attribute [[8.07]]'''
* '''Attribute [[8.08]]'''
* '''Attribute [[8.09]]'''
* '''Attribute [[8.10]]'''
 
'''<big>Types of Improper Payments and Improper Payment Risk Factors</big>'''
 
* '''Attribute [[8.11]]'''
* '''Attribute [[8.12]]'''
 
* '''Attribute [[8.13]]'''
 
'''<big>Types of Information Security Risk and Information Security Risk Factors</big>'''
 
* '''Attribute [[8.14]]'''
* '''Attribute [[8.15]]'''
* '''Attribute [[8.16]]'''
* '''Attribute [[8.17]]'''
 
'''<big>Analyze and Respond to Identified Risks</big>'''
 
* '''Attribute [[8.18]]'''
* '''Attribute [[8.19]]'''
* '''Attribute [[8.20]]'''
 
==== '''Principle 9 - Identify, Analyze, and Respond to Change''' ====
 
* '''Attribute [[9.01]]'''
 
'''<big>Identify Significant Changes</big>'''
 
* '''Attribute [[9.02]]'''
* '''Attribute [[9.03]]'''
* '''Attribute [[9.04]]'''
 
'''<big>Establish a Change Assessment Process</big>'''
 
* '''Attribute [[9.05]]'''
* '''Attribute [[9.06]]'''
* '''Attribute [[9.07]]'''
* '''Attribute [[9.08]]'''
* '''Attribute [[9.09]]'''
* '''Attribute [[9.10]]'''
 
'''<big>Identify, Analyze and Respond to Risks Related to Significant Changes</big>'''
 
* '''Attribute [[9.11]]'''
* '''Attribute [[9.12]]'''
* '''Attribute [[9.13]]'''
 
==== '''Principle 10 - Design Control Activities''' ====
 
* '''Attribute [[10.01]]'''
 
'''<big>Response to Risks</big>'''
 
* '''Attribute [[10.02]]'''
 
'''<big>Design of Appropriate Types of Control Activities</big>'''
 
* '''Attribute [[10.03]]'''
* '''Attribute [[10.04]]'''
 
'''<big>Design of Automated and Manual Control Activities</big>'''
 
* '''Attribute [[10.05]]'''
* '''Attribute [[10.06]]'''
* '''Attribute [[10.07]]'''
* '''Attribute [[10.08]]'''
* '''Attribute [[10.09]]'''
 
'''<big>Design of Preventive and Detective Control Activities</big>'''
 
* '''Attribute [[10.10]]'''
* '''Attribute [[10.11]]'''
* '''Attribute [[10.12]]'''
* '''Attribute [[10.13]]'''
 
'''<big>Design of Control Activities at Various Levels</big>'''
 
* '''Attribute [[10.14]]'''
* '''Attribute [[10.15]]'''
* '''Attribute [[10.16]]'''
* '''Attribute [[10.17]]'''
* '''Attribute [[10.18]]'''
* '''Attribute [[10.19]]'''
* '''Attribute [[10.20]]'''
 
'''<big>Segregation of Duties</big>'''
 
* '''Attribute [[10.21]]'''
* '''Attribute [[10.22]]'''
* '''Attribute [[10.23]]'''
 
==== '''Principle 11 - Design General Control Activities over Information''' ====
 
* '''Attribute [[11.01]]'''
 
'''<big>Response to Risks</big>'''
 
* '''Attribute [[11.02]]'''
 
'''<big>Design of the Entity’s Information Technology</big>'''
 
* '''Attribute [[11.03]]'''
* '''Attribute [[11.04]]'''
* '''Attribute [[11.05]]'''
* '''Attribute [[11.06]]'''
 
'''<big>Design of Appropriate Types of General Control Activities</big>'''
 
* '''Attribute [[11.07]]'''
* '''Attribute [[11.08]]'''
* '''Attribute [[11.09]]'''
* '''Attribute [[11.10]]'''
* '''Attribute [[11.11]]'''
* '''Attribute [[11.12]]'''
* '''Attribute [[11.13]]'''
* '''Attribute [[11.14]]'''
* '''Attribute [[11.15]]'''
* '''Attribute [[11.16]]'''
* '''Attribute [[11.17]]'''
 
==== '''Principle 12 - Implement Control Activities''' ====
 
* '''Attribute 12.01'''
 
'''Documentation of Control Activities Through Policies and Procedures'''
 
* '''Attribute 12.02'''
* '''Attribute 12.03'''
* '''Attribute 12.04'''
 
'''<big>Periodic Review of Control Activities</big>'''
 
* '''Attribute 12.05'''
 
==== '''Principle 13 - Use Quality Information''' ====
 
* '''Attribute 13.01'''
 
'''<big>Identification of Information Requirements</big>'''
 
* '''Attribute 13.02'''
* '''Attribute 13.03'''
 
'''<big>Relevant Data from Reliable Sources</big>'''
 
* '''Attribute 13.04'''
 
'''<big>Data Processed into Quality Information</big>'''
 
* '''Attribute 13.05'''
* '''Attribute 13.06'''
* '''Attribute 13.07'''
 
==== '''Principle 14 - Communicate Internally''' ====
 
* '''Attribute 14.01'''
 
'''<big>Communication Throughout the Entity</big>'''
 
* '''Attribute 14.02'''
* '''Attribute 14.03'''
* '''Attribute 14.04'''
* '''Attribute 14.05'''
* '''Attribute 14.06'''
 
'''<big>Appropriate Methods of Communication</big>'''
 
* '''Attribute 14.07'''
* '''Attribute 14.08'''
 
==== '''Principle 15 - Communicate Externally''' ====
 
* '''Attribute 15.01'''
 
'''<big>Communication with External Parties</big>'''
 
* '''Attribute 15.02'''
* '''Attribute 15.03'''
* '''Attribute 15.04'''
* '''Attribute 15.05'''
* '''Attribute 15.06'''
 
'''<big>Appropriate Methods of Communication</big>'''
 
* '''Attribute 15.07'''
* '''Attribute 15.08'''
* '''Attribute 15.09'''
 
==== '''Principle 16 - Perform Monitoring Activities''' ====
 
* '''Attribute 16.01'''
 
'''<big>Establishment of a Baseline</big>'''
 
* '''Attribute 16.02'''
* '''Attribute 16.03'''
 
'''<big>Internal Control System Monitoring</big>'''
 
* '''Attribute 16.04'''
* '''Attribute 16.05'''
* '''Attribute 16.06'''
* '''Attribute 16.07'''
* '''Attribute 16.08'''
 
'''<big>Evaluation of Results</big>'''
 
* '''Attribute 16.09'''
* '''Attribute 16.10'''
 
==== '''Principle 17 - Evaluate Issues and Remediate Deficiencies''' ====
 
* '''Attribute 17.01'''
 
'''<big>Reporting of Issues</big>'''
 
* '''Attribute 17.02'''
* '''Attribute 17.03'''
* '''Attribute 17.04'''
 
'''<big>Evaluation of Issues</big>'''
 
* '''Attribute 17.05'''
 
'''<big>Corrective Actions</big>'''
 
* '''Attribute 17.06'''
* '''Attribute 17.07'''
* '''Attribute 17.08'''

Latest revision as of 05:14, 18 August 2026

Assessment Observations Compared to Green Book Components, Principles, & Attributes

Control Environment

Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.

  • Principle 3 - Establish Structure, Responsibility, and Authority
    • Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
  • Principle 4 - Demonstrate Commitment to Competence
    • Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
  • Principle 5 - Enforce Accountability
    • Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment

Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.

  • Principle 6 - Define Objectives and Risk Tolerances
    • Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
  • Principle 7 - Identify, Analyze, and Respond to Risks
    • Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
  • Principle 8 - Assess Fraud, Improper Payment, and Information
    • Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
  • Principle 9 - Identify, Analyze, and Respond to Change
    • Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities

Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.

  • Principle 10 - Design Control Activities
    • Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
  • Principle 11 - Design General Control Activities over Information
    • Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
  • Principle 12 - Implement Control Activities
    • Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication

Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.

  • Principle 13 - Use Quality Information
    • Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
  • Principle 14 - Communicate Internally
    • Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
  • Principle 15 - Communicate Externally
    • Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring

Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.

  • Principle 16 - Perform Monitoring Activities
    • Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
  • Principle 17 - Evaluate Issues and Remediate Deficiencies
    • Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)