Principle 5 - Enforce Accountability: Difference between revisions

From Corrective Action Plan AZ
No edit summary
No edit summary
Line 1: Line 1:
== 5.0 Enforce Accountability ==
'''5.01 Management should evaluate performance and hold individuals
accountable for their internal control responsibilities.'''


5.01 Management should evaluate performance and hold individuals
=== 5.1 Enforcement of Accountability ===
accountable for their internal control responsibilities.
'''5.02 Management enforces accountability of individuals performing their internal control responsibilities.''' Accountability is driven by the tone at the top and supported by commitment to integrity and ethical values, organizational structure, and expectations of competence, which influence the control culture of the entity. Accountability for performance of internal control responsibility supports day-to-day decision-making, attitudes, and behaviors. Management holds personnel accountable through mechanisms such as performance appraisals and disciplinary actions.
August 3, 2026: Submitted Complaint – My original PRR requested contracts and MOUs with corporate and governmental entities, respectively. I believed the delivery of those contracts would provide objective evidence of the Maricopa County personnel that were accountable for acquiring election related materials and services. Who authorized and what was in those contracts and MOUs?
As expected (no deviation), the original contracts with Runbeck and Dominion were approved by the Director of the MCBOS Procurement Department.
As yet unresolved (unknown), accountability for the contracts and MOUs could not be determined for the documents not delivered in response to my PRR. Hence, it is not known who was responsible and what was the content of the following documents:
• Amendments, addenda, renewals, exhibits, or revisions for 2018–2024
• Post-election contract administration records
• MVD election-related contracts
• USPS-related agreements
• Temporary staffing contracts for signature verification
Contrary to the Green Book (deviation), no change history documentation was included with sections of the Runbeck and Dominion contracts that were stricken through or had new content added, apparently by an amendment process. However, there was no justification for the changes. Nor was there an approval signature for the “amendment.” Therefore, the Green Book’s requirements for accountability were not fulfilled based on the documentation provided.
'''5.03 Management holds personnel accountable for performing their assigned internal control responsibilities.''' The oversight body, in turn, holds both management and the entire organization accountable for its internal control responsibilities.


Enforcement of Accountability
'''5.04 If management establishes incentives, management recognizes that such actions can yield unintended consequences and evaluates incentives so that they align with the entity’s standards of conduct.'''


5.02 Management enforces accountability of individuals performing their
'''5.05 Management holds service organizations accountable for their assigned internal control responsibilities.''' Management may contract with service organizations to perform roles in the organizational structure. Management communicates to each service organization the objectives of the entity and their related risks, the entity’s standards of conduct, the role of the service organization in the organizational structure, the assigned responsibilities and authorities of the role, and the expectations of competence for its role that will enable a service organization to perform its internal control responsibilities. Management, however, retains responsibility for the effectiveness of controls over the business processes assigned to service organizations.
internal control responsibilities. Accountability is driven by the tone
See item 5.02 (above) for an explanation of this Green Book attribute, 5.05, to my PRR request. The prior response applies to this attribute.
at the top and supported by commitment to integrity and ethical values,
'''5.06 Management, with oversight from the oversight body, takes corrective action as necessary to enforce accountability for internal control in the entity.''' These actions can range from informal feedback provided by the direct supervisor to disciplinary action taken by the oversight body, depending on the significance of the deficiency to the internal control system.Consideration of Excessive Pressures
organizational structure, and expectations of competence, which
influence the control culture of the entity. Accountability for
performance of internal control responsibility supports day-to-day
decision-making, attitudes, and behaviors. Management holds personnel
accountable through mechanisms such as performance appraisals and
disciplinary actions.


August 3, 2026: Submitted Complaint – My original PRR requested
=== 5.2 Consideration of Excessive Pressures ===
contracts and MOUs with corporate and governmental entities,
'''5.07 Management adjusts excessive pressures on personnel in the entity.''' Pressure can appear in an entity because of goals management established to meet objectives or cyclical demands of various processes the entity performs, such as year-end financial statement preparation. Excessive pressure can result in personnel “cutting corners” to meet the established goals.
respectively. I believed the delivery of those contracts would provide
objective evidence of the Maricopa County personnel that were
accountable for acquiring election related materials and services. Who
authorized and what was in those contracts and MOUs?


As expected (no deviation), the original contracts with Runbeck and
'''5.08 Management is responsible for evaluating pressure on personnel to help personnel fulfill their assigned responsibilities in accordance with the entity’s standards of conduct.''' Management can adjust excessive pressures using many different tools, such as rebalancing workloads or increasing resource levels.
Dominion were approved by the Director of the MCBOS Procurement
Department.


As yet unresolved (unknown), accountability for the contracts and MOUs
=== 5.3 Risk Assessment ===
could not be determined for the documents not delivered in response to
'''Management assesses internal and external risks and performs risk assessments on a periodic and ongoing basis to achieve its objectives.'''
my PRR. Hence, it is not known who was responsible and what was the
content of the following documents:


*  Amendments, addenda, renewals, exhibits, or revisions for 2018–2024
These assessments provide the basis for identifying risks and developing appropriate risk responses.


*  Post-election contract administration records
==== Principles ====
 
*  MVD election-related contracts
 
*  USPS-related agreements
 
*  Temporary staffing contracts for signature verification
 
Contrary to the Green Book (deviation), no change history documentation
was included with sections of the Runbeck and Dominion contracts that
were stricken through or had new content added, apparently by an
amendment process. However, there was no justification for the changes.
Nor was there an approval signature for the “amendment.” Therefore, the
Green Book’s requirements for accountability were not fulfilled based on
the documentation provided.
 
5.03 Management holds personnel accountable for performing their
assigned internal control responsibilities. The oversight body, in turn,
holds both management and the entire organization accountable for its
internal control responsibilities.
 
5.04 If management establishes incentives, management recognizes that
such actions can yield unintended consequences and evaluates incentives
so that they align with the entity’s standards of conduct.
 
5.05 Management holds service organizations accountable for their
assigned internal control responsibilities. Management may contract with
service organizations to perform roles in the organizational structure.
Management communicates to each service organization the objectives of
the entity and their related risks, the entity’s standards of conduct,
the role of the service organization in the organizational structure,
the assigned responsibilities and authorities of the role, and the
expectations of competence for its role that will enable a service
organization to perform its internal control responsibilities.
Management, however, retains responsibility for the effectiveness of
controls over the business processes assigned to service organizations.
 
See item 5.02 (above) for an explanation of this Green Book attribute,
5.05, to my PRR request. The prior response applies to this attribute.
 
5.06 Management, with oversight from the oversight body, takes
corrective action as necessary to enforce accountability for internal
control in the entity. These actions can range from informal feedback
provided by the direct supervisor to disciplinary action taken by the
oversight body, depending on the significance of the deficiency to the
internal control system.
 
Consideration of Excessive Pressures
 
5.07 Management adjusts excessive pressures on personnel in the entity.
Pressure can appear in an entity because of goals management established
to meet objectives or cyclical demands of various processes the entity
performs, such as year-end financial statement preparation. Excessive
pressure can result in personnel “cutting corners” to meet the
established goals.
 
5.08 Management is responsible for evaluating pressure on personnel to
help personnel fulfill their assigned responsibilities in accordance
with the entity’s standards of conduct. Management can adjust excessive
pressures using many different tools, such as rebalancing workloads or
increasing resource levels.
 
Risk Assessment
 
Management assesses internal and external risks and performs risk
assessments on a periodic and ongoing basis to achieve its objectives.
These assessments provide the basis for identifying risks and developing
appropriate risk responses.
 
Principles
 
Management should define objectives clearly to enable the identification of risks and define risk tolerances.
 
Management should identify, analyze, and respond to risks related to achieving the defined objectives.
 
Management should consider risks related to fraud, improper payments, and information security when identifying, analyzing, and responding to risks.
 
Management should identify, analyze, and respond to significant changes that could impact the internal control system.


* Management should define objectives clearly to enable the identification of risks and define risk tolerances.
* Management should identify, analyze, and respond to risks related to achieving the defined objectives.
* Management should consider risks related to fraud, improper payments, and information security when identifying, analyzing, and responding to risks.
* Management should identify, analyze, and respond to significant changes that could impact the internal control system.
# [[Principle 1 - Demonstrate Commitment to Integrity and Ethical Values]]
# [[Principle 1 - Demonstrate Commitment to Integrity and Ethical Values]]
# [[Principle 2 - Exercise Oversight Responsibility]]
# [[Principle 2 - Exercise Oversight Responsibility]]

Revision as of 03:05, 6 August 2026

5.0 Enforce Accountability

5.01 Management should evaluate performance and hold individuals accountable for their internal control responsibilities.

5.1 Enforcement of Accountability

5.02 Management enforces accountability of individuals performing their internal control responsibilities. Accountability is driven by the tone at the top and supported by commitment to integrity and ethical values, organizational structure, and expectations of competence, which influence the control culture of the entity. Accountability for performance of internal control responsibility supports day-to-day decision-making, attitudes, and behaviors. Management holds personnel accountable through mechanisms such as performance appraisals and disciplinary actions.

August 3, 2026: Submitted Complaint – My original PRR requested contracts and MOUs with corporate and governmental entities, respectively. I believed the delivery of those contracts would provide objective evidence of the Maricopa County personnel that were accountable for acquiring election related materials and services. Who authorized and what was in those contracts and MOUs?

As expected (no deviation), the original contracts with Runbeck and Dominion were approved by the Director of the MCBOS Procurement Department.

As yet unresolved (unknown), accountability for the contracts and MOUs could not be determined for the documents not delivered in response to my PRR. Hence, it is not known who was responsible and what was the content of the following documents:

• Amendments, addenda, renewals, exhibits, or revisions for 2018–2024
• Post-election contract administration records
• MVD election-related contracts
• USPS-related agreements
• Temporary staffing contracts for signature verification

Contrary to the Green Book (deviation), no change history documentation was included with sections of the Runbeck and Dominion contracts that were stricken through or had new content added, apparently by an amendment process. However, there was no justification for the changes. Nor was there an approval signature for the “amendment.” Therefore, the Green Book’s requirements for accountability were not fulfilled based on the documentation provided.

5.03 Management holds personnel accountable for performing their assigned internal control responsibilities. The oversight body, in turn, holds both management and the entire organization accountable for its internal control responsibilities.

5.04 If management establishes incentives, management recognizes that such actions can yield unintended consequences and evaluates incentives so that they align with the entity’s standards of conduct.

5.05 Management holds service organizations accountable for their assigned internal control responsibilities. Management may contract with service organizations to perform roles in the organizational structure. Management communicates to each service organization the objectives of the entity and their related risks, the entity’s standards of conduct, the role of the service organization in the organizational structure, the assigned responsibilities and authorities of the role, and the expectations of competence for its role that will enable a service organization to perform its internal control responsibilities. Management, however, retains responsibility for the effectiveness of controls over the business processes assigned to service organizations.

See item 5.02 (above) for an explanation of this Green Book attribute, 5.05, to my PRR request. The prior response applies to this attribute.

5.06 Management, with oversight from the oversight body, takes corrective action as necessary to enforce accountability for internal control in the entity. These actions can range from informal feedback provided by the direct supervisor to disciplinary action taken by the oversight body, depending on the significance of the deficiency to the internal control system.Consideration of Excessive Pressures

5.2 Consideration of Excessive Pressures

5.07 Management adjusts excessive pressures on personnel in the entity. Pressure can appear in an entity because of goals management established to meet objectives or cyclical demands of various processes the entity performs, such as year-end financial statement preparation. Excessive pressure can result in personnel “cutting corners” to meet the established goals.

5.08 Management is responsible for evaluating pressure on personnel to help personnel fulfill their assigned responsibilities in accordance with the entity’s standards of conduct. Management can adjust excessive pressures using many different tools, such as rebalancing workloads or increasing resource levels.

5.3 Risk Assessment

Management assesses internal and external risks and performs risk assessments on a periodic and ongoing basis to achieve its objectives.

These assessments provide the basis for identifying risks and developing appropriate risk responses.

Principles

  • Management should define objectives clearly to enable the identification of risks and define risk tolerances.
  • Management should identify, analyze, and respond to risks related to achieving the defined objectives.
  • Management should consider risks related to fraud, improper payments, and information security when identifying, analyzing, and responding to risks.
  • Management should identify, analyze, and respond to significant changes that could impact the internal control system.
  1. Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
  2. Principle 2 - Exercise Oversight Responsibility
  3. Principle 3 - Establish Structure, Responsibility, and Authority
  4. Principle 5 - Enforce Accountability
  5. Principle 8 - Assess Fraud, Improper Payment, and Information
  6. Principle 10 - Design Control Activities
  7. Principle 11 - Design General Control Activities over Information
  8. Principle 12 - Implement Control Activities
  9. Principle 13 - Use Quality Information
  10. Principle 14 - Communicate Internally
  11. Principle 15 - Communicate Externally
  12. Principle 16 - Perform Monitoring Activities
  13. Principle 17 - Evaluate Issues and Remediate Deficiencies

Related Story Events