Template:Principles: Difference between revisions
| Line 315: | Line 315: | ||
==== '''Principle 13 - Use Quality Information''' ==== | ==== '''Principle 13 - Use Quality Information''' ==== | ||
* '''Attribute 13.01''' | |||
'''<big>Identification of Information Requirements</big>''' | |||
* '''Attribute 13.02''' | |||
* '''Attribute 13.03''' | |||
'''<big>Relevant Data from Reliable Sources</big>''' | |||
* '''Attribute 13.04''' | |||
'''<big>Data Processed into Quality Information</big>''' | |||
* '''Attribute 13.05''' | |||
* '''Attribute 13.06''' | |||
* '''Attribute 13.07''' | |||
==== '''Principle 14 - Communicate Internally''' ==== | ==== '''Principle 14 - Communicate Internally''' ==== | ||
Revision as of 10:23, 14 August 2026
US GAO Green Book Principles
- Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
- Principle 2 - Exercise Oversight Responsibility
- Principle 3 - Establish Structure, Responsibility, and Authority
- Principle 4 - Demonstrate Commitment to Competence
- Principle 5 - Enforce Accountability
- Principle 6 - Define Objectives and Risk Tolerances
- Principle 7 - Identify, Analyze, and Respond to Risks
- Principle 8 - Assess Fraud, Improper Payment, and Information
- Principle 9 - Identify, Analyze, and Respond to Change
- Principle 10 - Design Control Activities
- Principle 11 - Design General Control Activities over Information
- Principle 12 - Implement Control Activities
- Principle 13 - Use Quality Information
- Principle 14 - Communicate Internally
- Principle 15 - Communicate Externally
- Principle 16 - Perform Monitoring Activities
- Principle 17 - Evaluate Issues and Remediate Deficiencies
Index of Green Book Attributes Relating to Maricopa County Performance
Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
Tone at the Top
Standards of Conduct
Adherence to Standards of Conduct
Principle 2 - Exercise Oversight Responsibility
- Attribute 2.01
Oversight Structure
- Attribute 2.02
- Attribute 2.03
- Attribute 2.04
- Attribute 2.05
- Attribute 2.06
- Attribute 2.07
- Attribute 2.08
Oversight for the Internal Control System
- Attribute 2.09
- Attribute 2.10
Input for Remediation of Deficiencies
- Attribute 2.11
- Attribute 2.12
- Attribute 2.13
Principle 3 - Establish Structure, Responsibility, and Authority
- Attribute 3.01
Organizational Structure
- Attribute 3.02
- Attribute 3.03
- Attribute 3.04
- Attribute 3.05
Assignment of Responsibility and Delegation of Authority
- Attribute 3.06
- Attribute 3.07
- Attribute 3.08
Documentation of the Internal Control System
- Attribute 3.09
- Attribute 3.10
- Attribute 3.11
- Attribute 3.12
Principle 4 - Demonstrate Commitment to Competence
- Attribute 4.01
Expectations of Competence
- Attribute 4.02
- Attribute 4.03
- Attribute 4.04
Recruitment, Development, and Retention of Individuals
- Attribute 4.05
Succession and Contingency Plans and Preparation
- Attribute 4.06
- Attribute 4.07
- Attribute 4.08
Principle 5 - Enforce Accountability
- Attribute 5.01
Enforcement of Accountability
- Attribute 5.02
- Attribute 5.03
- Attribute 5.04
- Attribute 5.05
- Attribute 5.06
Consideration of Excessive Pressures
- Attribute 5.07
- Attribute 5.08
Principle 6 - Define Objectives and Risk Tolerances
- Attribute 6.01
Definitions of Objectives
- Attribute 6.02
- Attribute 6.03
- Attribute 6.04
- Attribute 6.05
- Attribute 6.06
- Attribute 6.07
Definitions of Risk Tolerances
- Attribute 6.08
- Attribute 6.09
- Attribute 6.10
Principle 7 - Identify, Analyze, and Respond to Risks
- Attribute 7.01
Identify Risks
- Attribute 7.02
- Attribute 7.03
- Attribute 7.04
- Attribute 7.05
- Attribute 7.06
Analyze Risks
- Attribute 7.07
- Attribute 7.08
- Attribute 7.09
Respond to Risks
- Attribute 7.10
- Attribute 7.11
- Attribute 7.12
- Attribute 7.13
- Attribute 7.14
- Attribute 7.15
Principle 8 - Assess Fraud, Improper Payment, and Information
- Attribute 8.01
Identify Risks Related to Fraud, Improper Payments, and Information Security
- Attribute 8.02
- Attribute 8.03
- Attribute 8.04
- Attribute 8.05
Types of Fraud and Fraud Risk Factors
- Attribute 8.06
- Attribute 8.07
- Attribute 8.08
- Attribute 8.09
- Attribute 8.10
Types of Improper Payments and Improper Payment Risk Factors
- Attribute 8.11
- Attribute 8.12
- Attribute 8.13
Types of Information Security Risk and Information Security Risk Factors
- Attribute 8.14
- Attribute 8.15
- Attribute 8.16
- Attribute 8.17
Analyze and Respond to Identified Risks
- Attribute 8.18
- Attribute 8.19
- Attribute 8.20
Principle 9 - Identify, Analyze, and Respond to Change
- Attribute 9.01
Identify Significant Changes
- Attribute 9.02
- Attribute 9.03
- Attribute 9.04
Establish a Change Assessment Process
- Attribute 9.05
- Attribute 9.06
- Attribute 9.07
- Attribute 9.08
- Attribute 9.09
- Attribute 9.10
Identify, Analyze and Respond to Risks Related to Significant Changes
- Attribute 9.11
- Attribute 9.12
- Attribute 9.13
Principle 10 - Design Control Activities
- Attribute 10.01
Response to Risks
- Attribute 10.02
Design of Appropriate Types of Control Activities
- Attribute 10.03
- Attribute 10.04
Design of Automated and Manual Control Activities
- Attribute 10.05
- Attribute 10.06
- Attribute 10.07
- Attribute 10.08
- Attribute 10.09
Design of Preventive and Detective Control Activities
- Attribute 10.10
- Attribute 10.11
- Attribute 10.12
- Attribute 10.13
Design of Control Activities at Various Levels
- Attribute 10.14
- Attribute 10.15
- Attribute 10.16
- Attribute 10.17
- Attribute 10.18
- Attribute 10.19
- Attribute 10.20
Segregation of Duties
- Attribute 10.21
- Attribute 10.22
- Attribute 10.23
Principle 11 - Design General Control Activities over Information
- Attribute 11.01
Response to Risks
- Attribute 11.02
Design of the Entity’s Information Technology
- Attribute 11.03
- Attribute 11.04
- Attribute 11.05
- Attribute 11.06
Design of Appropriate Types of General Control Activities
- Attribute 11.07
- Attribute 11.08
- Attribute 11.09
- Attribute 11.10
- Attribute 11.11
- Attribute 11.12
- Attribute 11.13
- Attribute 11.14
- Attribute 11.15
- Attribute 11.16
- Attribute 11.17
Principle 12 - Implement Control Activities
- Attribute 12.01
Documentation of Control Activities Through Policies and Procedures
- Attribute 12.02
- Attribute 12.03
- Attribute 12.04
Periodic Review of Control Activities
- Attribute 12.05
Principle 13 - Use Quality Information
- Attribute 13.01
Identification of Information Requirements
- Attribute 13.02
- Attribute 13.03
Relevant Data from Reliable Sources
- Attribute 13.04
Data Processed into Quality Information
- Attribute 13.05
- Attribute 13.06
- Attribute 13.07
