Template:Principles: Difference between revisions

From Corrective Action Plan AZ
Line 229: Line 229:
==== '''Principle 10 - Design Control Activities''' ====
==== '''Principle 10 - Design Control Activities''' ====


* '''Attribute 10.01'''
* '''Attribute [[10.01]]'''


'''<big>Response to Risks</big>'''
'''<big>Response to Risks</big>'''


* '''Attribute 10.02'''
* '''Attribute [[10.02]]'''


'''<big>Design of Appropriate Types of Control Activities</big>'''
'''<big>Design of Appropriate Types of Control Activities</big>'''


* '''Attribute 10.03'''
* '''Attribute [[10.03]]'''
* '''Attribute 10.04'''
* '''Attribute [[10.04]]'''


'''<big>Design of Automated and Manual Control Activities</big>'''
'''<big>Design of Automated and Manual Control Activities</big>'''


* '''Attribute 10.05'''
* '''Attribute [[10.05]]'''
* '''Attribute 10.06'''
* '''Attribute [[10.06]]'''
* '''Attribute 10.07'''
* '''Attribute [[10.07]]'''
* '''Attribute 10.08'''
* '''Attribute [[10.08]]'''
* '''Attribute 10.09'''
* '''Attribute [[10.09]]'''


'''<big>Design of Preventive and Detective Control Activities</big>'''
'''<big>Design of Preventive and Detective Control Activities</big>'''


* '''Attribute 10.10'''
* '''Attribute [[10.10]]'''
* '''Attribute 10.11'''
* '''Attribute [[10.11]]'''
* '''Attribute 10.12'''
* '''Attribute [[10.12]]'''
* '''Attribute 10.13'''
* '''Attribute [[10.13]]'''


'''<big>Design of Control Activities at Various Levels</big>'''
'''<big>Design of Control Activities at Various Levels</big>'''


* '''Attribute 10.14'''
* '''Attribute [[10.14]]'''
* '''Attribute 10.15'''
* '''Attribute [[10.15]]'''
* '''Attribute 10.16'''
* '''Attribute [[10.16]]'''
* '''Attribute 10.17'''
* '''Attribute [[10.17]]'''
* '''Attribute 10.18'''
* '''Attribute [[10.18]]'''
* '''Attribute 10.19'''
* '''Attribute [[10.19]]'''
* '''Attribute 10.20'''
* '''Attribute [[10.20]]'''


'''<big>Segregation of Duties</big>'''
'''<big>Segregation of Duties</big>'''


* '''Attribute 10.21'''
* '''Attribute [[10.21]]'''
* '''Attribute 10.22'''
* '''Attribute [[10.22]]'''
* '''Attribute 10.23'''
* '''Attribute [[10.23]]'''


==== '''Principle 11 - Design General Control Activities over Information''' ====
==== '''Principle 11 - Design General Control Activities over Information''' ====


* '''Attribute 11.01'''
* '''Attribute [[11.01]]'''


'''<big>Response to Risks</big>'''
'''<big>Response to Risks</big>'''


* '''Attribute 11.02'''
* '''Attribute [[11.02]]'''


'''<big>Design of the Entity’s Information Technology</big>'''
'''<big>Design of the Entity’s Information Technology</big>'''


* '''Attribute 11.03'''
* '''Attribute [[11.03]]'''
* '''Attribute 11.04'''
* '''Attribute [[11.04]]'''
* '''Attribute 11.05'''
* '''Attribute [[11.05]]'''
* '''Attribute 11.06'''
* '''Attribute [[11.06]]'''


'''<big>Design of Appropriate Types of General Control Activities</big>'''
'''<big>Design of Appropriate Types of General Control Activities</big>'''


* '''Attribute 11.07'''
* '''Attribute [[11.07]]'''
* '''Attribute 11.08'''
* '''Attribute [[11.08]]'''
* '''Attribute 11.09'''
* '''Attribute [[11.09]]'''
* '''Attribute 11.10'''
* '''Attribute [[11.10]]'''
* '''Attribute 11.11'''
* '''Attribute [[11.11]]'''
* '''Attribute 11.12'''
* '''Attribute [[11.12]]'''
* '''Attribute 11.13'''
* '''Attribute [[11.13]]'''
* '''Attribute 11.14'''
* '''Attribute [[11.14]]'''
* '''Attribute 11.15'''
* '''Attribute [[11.15]]'''
* '''Attribute 11.16'''
* '''Attribute [[11.16]]'''
* '''Attribute 11.17'''
* '''Attribute [[11.17]]'''


==== '''Principle 12 - Implement Control Activities''' ====
==== '''Principle 12 - Implement Control Activities''' ====

Revision as of 11:15, 14 August 2026

US GAO Green Book Principles

  1. Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
  2. Principle 2 - Exercise Oversight Responsibility
  3. Principle 3 - Establish Structure, Responsibility, and Authority
  4. Principle 4 - Demonstrate Commitment to Competence
  5. Principle 5 - Enforce Accountability
  6. Principle 6 - Define Objectives and Risk Tolerances
  7. Principle 7 - Identify, Analyze, and Respond to Risks
  8. Principle 8 - Assess Fraud, Improper Payment, and Information
  9. Principle 9 - Identify, Analyze, and Respond to Change
  10. Principle 10 - Design Control Activities
  11. Principle 11 - Design General Control Activities over Information
  12. Principle 12 - Implement Control Activities
  13. Principle 13 - Use Quality Information
  14. Principle 14 - Communicate Internally
  15. Principle 15 - Communicate Externally
  16. Principle 16 - Perform Monitoring Activities
  17. Principle 17 - Evaluate Issues and Remediate Deficiencies

Index of Green Book Attributes Relating to Maricopa County Performance

Principle 1 - Demonstrate Commitment to Integrity and Ethical Values

Tone at the Top

Standards of Conduct

Adherence to Standards of Conduct

  • Attribute 1.08
  • Attribute 1.09
  • Attribute 1.10              

Principle 2 - Exercise Oversight Responsibility

Oversight Structure

Oversight for the Internal Control System

Input for Remediation of Deficiencies

Principle 3 - Establish Structure, Responsibility, and Authority

Organizational Structure

Assignment of Responsibility and Delegation of Authority

Documentation of the Internal Control System

Principle 4 - Demonstrate Commitment to Competence

Expectations of Competence

Recruitment, Development, and Retention of Individuals

Succession and Contingency Plans and Preparation

Principle 5 - Enforce Accountability

Enforcement of Accountability

Consideration of Excessive Pressures

Principle 6 - Define Objectives and Risk Tolerances

Definitions of Objectives

Definitions of Risk Tolerances

Principle 7 - Identify, Analyze, and Respond to Risks

Identify Risks

Analyze Risks

Respond to Risks

Principle 8 - Assess Fraud, Improper Payment, and Information

Identify Risks Related to Fraud, Improper Payments, and Information Security

Types of Fraud and Fraud Risk Factors

Types of Improper Payments and Improper Payment Risk Factors

Types of Information Security Risk and Information Security Risk Factors

Analyze and Respond to Identified Risks

Principle 9 - Identify, Analyze, and Respond to Change

Identify Significant Changes

Establish a Change Assessment Process

Identify, Analyze and Respond to Risks Related to Significant Changes

Principle 10 - Design Control Activities

Response to Risks

Design of Appropriate Types of Control Activities

Design of Automated and Manual Control Activities

Design of Preventive and Detective Control Activities

Design of Control Activities at Various Levels

Segregation of Duties

Principle 11 - Design General Control Activities over Information

Response to Risks

Design of the Entity’s Information Technology

Design of Appropriate Types of General Control Activities

Principle 12 - Implement Control Activities

  • Attribute 12.01

Documentation of Control Activities Through Policies and Procedures

  • Attribute 12.02
  • Attribute 12.03
  • Attribute 12.04

Periodic Review of Control Activities

  • Attribute 12.05

Principle 13 - Use Quality Information

  • Attribute 13.01

Identification of Information Requirements

  • Attribute 13.02
  • Attribute 13.03

Relevant Data from Reliable Sources

  • Attribute 13.04

Data Processed into Quality Information

  • Attribute 13.05
  • Attribute 13.06
  • Attribute 13.07

Principle 14 - Communicate Internally

  • Attribute 14.01

Communication Throughout the Entity

  • Attribute 14.02
  • Attribute 14.03
  • Attribute 14.04
  • Attribute 14.05
  • Attribute 14.06

Appropriate Methods of Communication

  • Attribute 14.07
  • Attribute 14.08

Principle 15 - Communicate Externally

  • Attribute 15.01

Communication with External Parties

  • Attribute 15.02
  • Attribute 15.03
  • Attribute 15.04
  • Attribute 15.05
  • Attribute 15.06

Appropriate Methods of Communication

  • Attribute 15.07
  • Attribute 15.08
  • Attribute 15.09

Principle 16 - Perform Monitoring Activities

  • Attribute 16.01

Establishment of a Baseline

  • Attribute 16.02
  • Attribute 16.03

Internal Control System Monitoring

  • Attribute 16.04
  • Attribute 16.05
  • Attribute 16.06
  • Attribute 16.07
  • Attribute 16.08

Evaluation of Results

  • Attribute 16.09
  • Attribute 16.10

Principle 17 - Evaluate Issues and Remediate Deficiencies

  • Attribute 17.01

Reporting of Issues

  • Attribute 17.02
  • Attribute 17.03
  • Attribute 17.04

Evaluation of Issues

  • Attribute 17.05

Corrective Actions

  • Attribute 17.06
  • Attribute 17.07
  • Attribute 17.08