Template:Principles: Difference between revisions

From Corrective Action Plan AZ
Line 118: Line 118:
==== '''Principle 6 - Define Objectives and Risk Tolerances''' ====
==== '''Principle 6 - Define Objectives and Risk Tolerances''' ====


* '''Attribute 6.01'''
* '''Attribute [[6.01]]'''


'''Definitions of Objectives'''
'''Definitions of Objectives'''


* '''Attribute 6.02'''
* '''Attribute [[6.02]]'''
* '''Attribute 6.03'''
* '''Attribute [[6.03]]'''
* '''Attribute 6.04'''
* '''Attribute [[6.04]]'''
* '''Attribute 6.05'''
* '''Attribute [[6.05]]'''
* '''Attribute 6.06'''
* '''Attribute [[6.06]]'''
* '''Attribute 6.07'''
* '''Attribute [[6.07]]'''


'''Definitions of Risk Tolerances'''
'''Definitions of Risk Tolerances'''


* '''Attribute 6.08'''
* '''Attribute [[6.08]]'''
* '''Attribute 6.09'''
* '''Attribute [[6.09]]'''
* '''Attribute 6.10'''
* '''Attribute [[6.10]]'''


==== '''Principle 7 - Identify, Analyze, and Respond to Risks''' ====
==== '''Principle 7 - Identify, Analyze, and Respond to Risks''' ====


* '''Attribute 7.01'''
* '''Attribute [[7.01]]'''


'''<big>Identify Risks</big>'''
'''<big>Identify Risks</big>'''


* '''Attribute 7.02'''
* '''Attribute [[7.02]]'''
* '''Attribute 7.03'''
* '''Attribute [[7.03]]'''


* '''Attribute 7.04'''
* '''Attribute [[7.04]]'''
* '''Attribute 7.05'''
* '''Attribute [[7.05]]'''
* '''Attribute 7.06'''
* '''Attribute [[7.06]]'''


'''<big>Analyze Risks</big>'''
'''<big>Analyze Risks</big>'''


* '''Attribute 7.07'''
* '''Attribute [[7.07]]'''
* '''Attribute 7.08'''
* '''Attribute [[7.08]]'''
* '''Attribute 7.09'''
* '''Attribute [[7.09]]'''


'''<big>Respond to Risks</big>'''
'''<big>Respond to Risks</big>'''


* '''Attribute 7.10'''
* '''Attribute [[7.10]]'''
* '''Attribute 7.11'''
* '''Attribute [[7.11]]'''
* '''Attribute 7.12'''
* '''Attribute [[7.12]]'''
* '''Attribute 7.13'''
* '''Attribute [[7.13]]'''
* '''Attribute 7.14'''
* '''Attribute [[7.14]]'''
* '''Attribute 7.15'''
* '''Attribute [[7.15]]'''


==== '''Principle 8 - Assess Fraud, Improper Payment, and Informati<big>on</big>''' ====
==== '''Principle 8 - Assess Fraud, Improper Payment, and Informati<big>on</big>''' ====


* '''<big>Attribute 8.01</big>'''
* '''Attribute 8.01'''


'''<big>Identify Risks Related to Fraud, Improper Payments, and Information Security</big>'''
'''<big>Identify Risks Related to Fraud, Improper Payments, and Information Security</big>'''

Revision as of 11:03, 14 August 2026

US GAO Green Book Principles

  1. Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
  2. Principle 2 - Exercise Oversight Responsibility
  3. Principle 3 - Establish Structure, Responsibility, and Authority
  4. Principle 4 - Demonstrate Commitment to Competence
  5. Principle 5 - Enforce Accountability
  6. Principle 6 - Define Objectives and Risk Tolerances
  7. Principle 7 - Identify, Analyze, and Respond to Risks
  8. Principle 8 - Assess Fraud, Improper Payment, and Information
  9. Principle 9 - Identify, Analyze, and Respond to Change
  10. Principle 10 - Design Control Activities
  11. Principle 11 - Design General Control Activities over Information
  12. Principle 12 - Implement Control Activities
  13. Principle 13 - Use Quality Information
  14. Principle 14 - Communicate Internally
  15. Principle 15 - Communicate Externally
  16. Principle 16 - Perform Monitoring Activities
  17. Principle 17 - Evaluate Issues and Remediate Deficiencies

Index of Green Book Attributes Relating to Maricopa County Performance

Principle 1 - Demonstrate Commitment to Integrity and Ethical Values

Tone at the Top

Standards of Conduct

Adherence to Standards of Conduct

  • Attribute 1.08
  • Attribute 1.09
  • Attribute 1.10              

Principle 2 - Exercise Oversight Responsibility

Oversight Structure

Oversight for the Internal Control System

Input for Remediation of Deficiencies

Principle 3 - Establish Structure, Responsibility, and Authority

Organizational Structure

Assignment of Responsibility and Delegation of Authority

Documentation of the Internal Control System

Principle 4 - Demonstrate Commitment to Competence

Expectations of Competence

Recruitment, Development, and Retention of Individuals

Succession and Contingency Plans and Preparation

Principle 5 - Enforce Accountability

Enforcement of Accountability

Consideration of Excessive Pressures

Principle 6 - Define Objectives and Risk Tolerances

Definitions of Objectives

Definitions of Risk Tolerances

Principle 7 - Identify, Analyze, and Respond to Risks

Identify Risks

Analyze Risks

Respond to Risks

Principle 8 - Assess Fraud, Improper Payment, and Information

  • Attribute 8.01

Identify Risks Related to Fraud, Improper Payments, and Information Security

  • Attribute 8.02
  • Attribute 8.03
  • Attribute 8.04
  • Attribute 8.05

Types of Fraud and Fraud Risk Factors

  • Attribute 8.06
  • Attribute 8.07
  • Attribute 8.08
  • Attribute 8.09
  • Attribute 8.10

Types of Improper Payments and Improper Payment Risk Factors

  • Attribute 8.11
  • Attribute 8.12
  • Attribute 8.13

Types of Information Security Risk and Information Security Risk Factors

  • Attribute 8.14
  • Attribute 8.15
  • Attribute 8.16
  • Attribute 8.17

Analyze and Respond to Identified Risks

  • Attribute 8.18
  • Attribute 8.19
  • Attribute 8.20

Principle 9 - Identify, Analyze, and Respond to Change

  • Attribute 9.01

Identify Significant Changes

  • Attribute 9.02
  • Attribute 9.03
  • Attribute 9.04

Establish a Change Assessment Process

  • Attribute 9.05
  • Attribute 9.06
  • Attribute 9.07
  • Attribute 9.08
  • Attribute 9.09
  • Attribute 9.10

Identify, Analyze and Respond to Risks Related to Significant Changes

  • Attribute 9.11
  • Attribute 9.12
  • Attribute 9.13

Principle 10 - Design Control Activities

  • Attribute 10.01

Response to Risks

  • Attribute 10.02

Design of Appropriate Types of Control Activities

  • Attribute 10.03
  • Attribute 10.04

Design of Automated and Manual Control Activities

  • Attribute 10.05
  • Attribute 10.06
  • Attribute 10.07
  • Attribute 10.08
  • Attribute 10.09

Design of Preventive and Detective Control Activities

  • Attribute 10.10
  • Attribute 10.11
  • Attribute 10.12
  • Attribute 10.13

Design of Control Activities at Various Levels

  • Attribute 10.14
  • Attribute 10.15
  • Attribute 10.16
  • Attribute 10.17
  • Attribute 10.18
  • Attribute 10.19
  • Attribute 10.20

Segregation of Duties

  • Attribute 10.21
  • Attribute 10.22
  • Attribute 10.23

Principle 11 - Design General Control Activities over Information

  • Attribute 11.01

Response to Risks

  • Attribute 11.02

Design of the Entity’s Information Technology

  • Attribute 11.03
  • Attribute 11.04
  • Attribute 11.05
  • Attribute 11.06

Design of Appropriate Types of General Control Activities

  • Attribute 11.07
  • Attribute 11.08
  • Attribute 11.09
  • Attribute 11.10
  • Attribute 11.11
  • Attribute 11.12
  • Attribute 11.13
  • Attribute 11.14
  • Attribute 11.15
  • Attribute 11.16
  • Attribute 11.17

Principle 12 - Implement Control Activities

  • Attribute 12.01

Documentation of Control Activities Through Policies and Procedures

  • Attribute 12.02
  • Attribute 12.03
  • Attribute 12.04

Periodic Review of Control Activities

  • Attribute 12.05

Principle 13 - Use Quality Information

  • Attribute 13.01

Identification of Information Requirements

  • Attribute 13.02
  • Attribute 13.03

Relevant Data from Reliable Sources

  • Attribute 13.04

Data Processed into Quality Information

  • Attribute 13.05
  • Attribute 13.06
  • Attribute 13.07

Principle 14 - Communicate Internally

  • Attribute 14.01

Communication Throughout the Entity

  • Attribute 14.02
  • Attribute 14.03
  • Attribute 14.04
  • Attribute 14.05
  • Attribute 14.06

Appropriate Methods of Communication

  • Attribute 14.07
  • Attribute 14.08

Principle 15 - Communicate Externally

  • Attribute 15.01

Communication with External Parties

  • Attribute 15.02
  • Attribute 15.03
  • Attribute 15.04
  • Attribute 15.05
  • Attribute 15.06

Appropriate Methods of Communication

  • Attribute 15.07
  • Attribute 15.08
  • Attribute 15.09

Principle 16 - Perform Monitoring Activities

  • Attribute 16.01

Establishment of a Baseline

  • Attribute 16.02
  • Attribute 16.03

Internal Control System Monitoring

  • Attribute 16.04
  • Attribute 16.05
  • Attribute 16.06
  • Attribute 16.07
  • Attribute 16.08

Evaluation of Results

  • Attribute 16.09
  • Attribute 16.10

Principle 17 - Evaluate Issues and Remediate Deficiencies

  • Attribute 17.01

Reporting of Issues

  • Attribute 17.02
  • Attribute 17.03
  • Attribute 17.04

Evaluation of Issues

  • Attribute 17.05

Corrective Actions

  • Attribute 17.06
  • Attribute 17.07
  • Attribute 17.08