9.08: Difference between revisions
From Arizona Citizen Voice
No edit summary |
No edit summary |
||
| Line 6: | Line 6: | ||
* the need to provide complex or different services quickly, which may result in increased risks overall, including those related to fraud, improper payments, information security, and noncompliance with applicable laws and regulations; | * the need to provide complex or different services quickly, which may result in increased risks overall, including those related to fraud, improper payments, information security, and noncompliance with applicable laws and regulations; | ||
=== ability to design and implement preventive control activities timely due to legal requirements or urgency to deliver a service quickly; === | |||
* ability to timely communicate relevant and quality information both internally and externally to support the internal control system, such as changes to identified risks, internal control responsibilities, and training on how to administer new internal controls; | * ability to timely communicate relevant and quality information both internally and externally to support the internal control system, such as changes to identified risks, internal control responsibilities, and training on how to administer new internal controls; | ||
* availability of existing resources, such as workforce capacity or availability of data (i.e., data-sharing agreements for external data), to adequately and timely adapt the entity's internal control system to address new or increased risks; and | * availability of existing resources, such as workforce capacity or availability of data (i.e., data-sharing agreements for external data), to adequately and timely adapt the entity's internal control system to address new or increased risks; and | ||
| Line 13: | Line 14: | ||
'''>>>Navigational Buttons<<<''' | '''>>>Navigational Buttons<<<''' | ||
* '''[[Index of Attributes]]''' | * '''[[Index of Attributes]]''' | ||
* '''Previous Attribute - | * '''Previous Attribute - [[9.07]]''' | ||
* '''Next Attribute - | * '''Next Attribute - [[9.09]]''' | ||
__FORCETOC__ | __FORCETOC__ | ||
=== ' | |||
=== Jamie's Story === | |||
No examples are available to illustrate governance gaps for this attribute. | |||
Election Anomalies | |||
No examples are available to illustrate governance gaps for this attribute. | |||
Revision as of 08:59, 22 August 2026
Risk Assessment
Principle 9 - Identify, Analyze, and Respond to Change
Attribute 9.08 - Management's change assessment process includes steps for timely identifying risks related to significant change, which may include the following:
- the need to provide complex or different services quickly, which may result in increased risks overall, including those related to fraud, improper payments, information security, and noncompliance with applicable laws and regulations;
ability to design and implement preventive control activities timely due to legal requirements or urgency to deliver a service quickly;
- ability to timely communicate relevant and quality information both internally and externally to support the internal control system, such as changes to identified risks, internal control responsibilities, and training on how to administer new internal controls;
- availability of existing resources, such as workforce capacity or availability of data (i.e., data-sharing agreements for external data), to adequately and timely adapt the entity's internal control system to address new or increased risks; and
- known internal control deficiencies that could increase risks related to significant change.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 9.07
- Next Attribute - 9.09
Jamie's Story
No examples are available to illustrate governance gaps for this attribute.
Election Anomalies
No examples are available to illustrate governance gaps for this attribute.
