Index of Attributes: Difference between revisions

From Corrective Action Plan AZ
No edit summary
Line 5: Line 5:


=== '''<u>Control Environment</u>''' ===
=== '''<u>Control Environment</u>''' ===
[[File:Control Environment.jpg|center|thumb]]


==== Principle 1 - Demonstrate Commitment to Integrity and Ethical Values ====
==== Principle 1 - Demonstrate Commitment to Integrity and Ethical Values ====

Revision as of 21:59, 17 August 2026

Overview

This page is an index, referencing Green Book Attributes (potential deviations) to parts of my story.

Control Environment

Principle 1 - Demonstrate Commitment to Integrity and Ethical Values

Tone at the Top

  • Attribute 1.02
  • Attribute 1.03 - with example(s) of potential governance gaps
  • Attribute 1.04
  • Attribute 1.05

Standards of Conduct

Adherence to Standards of Conduct

  • Attribute 1.08
  • Attribute 1.09
  • Attribute 1.10              

Principle 2 - Exercise Oversight Responsibility

Oversight Structure

Oversight for the Internal Control System

Input for Remediation of Deficiencies

Principle 3 - Establish Structure, Responsibility, and Authority

Organizational Structure

Assignment of Responsibility and Delegation of Authority

Documentation of the Internal Control System

Principle 4 - Demonstrate Commitment to Competence

Expectations of Competence

Recruitment, Development, and Retention of Individuals

Succession and Contingency Plans and Preparation

Principle 5 - Enforce Accountability

Enforcement of Accountability

Consideration of Excessive Pressures

Risk Assessment

Principle 6 - Define Objectives and Risk Tolerances

Definitions of Objectives

Definitions of Risk Tolerances

Principle 7 - Identify, Analyze, and Respond to Risks

Identify Risks

Analyze Risks

Respond to Risks

Principle 8 - Assess Fraud, Improper Payment, and Information

Identify Risks Related to Fraud, Improper Payments, and Information Security

Types of Fraud and Fraud Risk Factors

Types of Improper Payments and Improper Payment Risk Factors

Types of Information Security Risk and Information Security Risk Factors

Analyze and Respond to Identified Risks

Principle 9 - Identify, Analyze, and Respond to Change

Identify Significant Changes

Establish a Change Assessment Process

Identify, Analyze and Respond to Risks Related to Significant Changes

Control Activities

Principle 10 - Design Control Activities

Response to Risks

Design of Appropriate Types of Control Activities

Design of Automated and Manual Control Activities

Design of Preventive and Detective Control Activities

Design of Control Activities at Various Levels

Segregation of Duties

Principle 11 - Design General Control Activities over Information

Response to Risks

Design of the Entity’s Information Technology

Design of Appropriate Types of General Control Activities

Principle 12 - Implement Control Activities

Documentation of Control Activities Through Policies and Procedures

Periodic Review of Control Activities

Information and Communication

Principle 13 - Use Quality Information

Identification of Information Requirements

Relevant Data from Reliable Sources

Data Processed into Quality Information

Principle 14 - Communicate Internally

Communication Throughout the Entity

Appropriate Methods of Communication

Principle 15 - Communicate Externally

Communication with External Parties

Appropriate Methods of Communication

Monitoring

Principle 16 - Perform Monitoring Activities

Establishment of a Baseline

Internal Control System Monitoring

Evaluation of Results

Principle 17 - Evaluate Issues and Remediate Deficiencies

Reporting of Issues

Evaluation of Issues

Corrective Actions