Template:Principles: Difference between revisions
| Line 229: | Line 229: | ||
==== '''Principle 10 - Design Control Activities''' ==== | ==== '''Principle 10 - Design Control Activities''' ==== | ||
* '''Attribute 10.01''' | * '''Attribute [[10.01]]''' | ||
'''<big>Response to Risks</big>''' | '''<big>Response to Risks</big>''' | ||
* '''Attribute 10.02''' | * '''Attribute [[10.02]]''' | ||
'''<big>Design of Appropriate Types of Control Activities</big>''' | '''<big>Design of Appropriate Types of Control Activities</big>''' | ||
* '''Attribute 10.03''' | * '''Attribute [[10.03]]''' | ||
* '''Attribute 10.04''' | * '''Attribute [[10.04]]''' | ||
'''<big>Design of Automated and Manual Control Activities</big>''' | '''<big>Design of Automated and Manual Control Activities</big>''' | ||
* '''Attribute 10.05''' | * '''Attribute [[10.05]]''' | ||
* '''Attribute 10.06''' | * '''Attribute [[10.06]]''' | ||
* '''Attribute 10.07''' | * '''Attribute [[10.07]]''' | ||
* '''Attribute 10.08''' | * '''Attribute [[10.08]]''' | ||
* '''Attribute 10.09''' | * '''Attribute [[10.09]]''' | ||
'''<big>Design of Preventive and Detective Control Activities</big>''' | '''<big>Design of Preventive and Detective Control Activities</big>''' | ||
* '''Attribute 10.10''' | * '''Attribute [[10.10]]''' | ||
* '''Attribute 10.11''' | * '''Attribute [[10.11]]''' | ||
* '''Attribute 10.12''' | * '''Attribute [[10.12]]''' | ||
* '''Attribute 10.13''' | * '''Attribute [[10.13]]''' | ||
'''<big>Design of Control Activities at Various Levels</big>''' | '''<big>Design of Control Activities at Various Levels</big>''' | ||
* '''Attribute 10.14''' | * '''Attribute [[10.14]]''' | ||
* '''Attribute 10.15''' | * '''Attribute [[10.15]]''' | ||
* '''Attribute 10.16''' | * '''Attribute [[10.16]]''' | ||
* '''Attribute 10.17''' | * '''Attribute [[10.17]]''' | ||
* '''Attribute 10.18''' | * '''Attribute [[10.18]]''' | ||
* '''Attribute 10.19''' | * '''Attribute [[10.19]]''' | ||
* '''Attribute 10.20''' | * '''Attribute [[10.20]]''' | ||
'''<big>Segregation of Duties</big>''' | '''<big>Segregation of Duties</big>''' | ||
* '''Attribute 10.21''' | * '''Attribute [[10.21]]''' | ||
* '''Attribute 10.22''' | * '''Attribute [[10.22]]''' | ||
* '''Attribute 10.23''' | * '''Attribute [[10.23]]''' | ||
==== '''Principle 11 - Design General Control Activities over Information''' ==== | ==== '''Principle 11 - Design General Control Activities over Information''' ==== | ||
* '''Attribute 11.01''' | * '''Attribute [[11.01]]''' | ||
'''<big>Response to Risks</big>''' | '''<big>Response to Risks</big>''' | ||
* '''Attribute 11.02''' | * '''Attribute [[11.02]]''' | ||
'''<big>Design of the Entity’s Information Technology</big>''' | '''<big>Design of the Entity’s Information Technology</big>''' | ||
* '''Attribute 11.03''' | * '''Attribute [[11.03]]''' | ||
* '''Attribute 11.04''' | * '''Attribute [[11.04]]''' | ||
* '''Attribute 11.05''' | * '''Attribute [[11.05]]''' | ||
* '''Attribute 11.06''' | * '''Attribute [[11.06]]''' | ||
'''<big>Design of Appropriate Types of General Control Activities</big>''' | '''<big>Design of Appropriate Types of General Control Activities</big>''' | ||
* '''Attribute 11.07''' | * '''Attribute [[11.07]]''' | ||
* '''Attribute 11.08''' | * '''Attribute [[11.08]]''' | ||
* '''Attribute 11.09''' | * '''Attribute [[11.09]]''' | ||
* '''Attribute 11.10''' | * '''Attribute [[11.10]]''' | ||
* '''Attribute 11.11''' | * '''Attribute [[11.11]]''' | ||
* '''Attribute 11.12''' | * '''Attribute [[11.12]]''' | ||
* '''Attribute 11.13''' | * '''Attribute [[11.13]]''' | ||
* '''Attribute 11.14''' | * '''Attribute [[11.14]]''' | ||
* '''Attribute 11.15''' | * '''Attribute [[11.15]]''' | ||
* '''Attribute 11.16''' | * '''Attribute [[11.16]]''' | ||
* '''Attribute 11.17''' | * '''Attribute [[11.17]]''' | ||
==== '''Principle 12 - Implement Control Activities''' ==== | ==== '''Principle 12 - Implement Control Activities''' ==== | ||
Revision as of 11:15, 14 August 2026
US GAO Green Book Principles
- Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
- Principle 2 - Exercise Oversight Responsibility
- Principle 3 - Establish Structure, Responsibility, and Authority
- Principle 4 - Demonstrate Commitment to Competence
- Principle 5 - Enforce Accountability
- Principle 6 - Define Objectives and Risk Tolerances
- Principle 7 - Identify, Analyze, and Respond to Risks
- Principle 8 - Assess Fraud, Improper Payment, and Information
- Principle 9 - Identify, Analyze, and Respond to Change
- Principle 10 - Design Control Activities
- Principle 11 - Design General Control Activities over Information
- Principle 12 - Implement Control Activities
- Principle 13 - Use Quality Information
- Principle 14 - Communicate Internally
- Principle 15 - Communicate Externally
- Principle 16 - Perform Monitoring Activities
- Principle 17 - Evaluate Issues and Remediate Deficiencies
Index of Green Book Attributes Relating to Maricopa County Performance
Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
Tone at the Top
Standards of Conduct
Adherence to Standards of Conduct
Principle 2 - Exercise Oversight Responsibility
- Attribute 2.01
Oversight Structure
- Attribute 2.02
- Attribute 2.03
- Attribute 2.04
- Attribute 2.05
- Attribute 2.06
- Attribute 2.07
- Attribute 2.08
Oversight for the Internal Control System
Input for Remediation of Deficiencies
Principle 3 - Establish Structure, Responsibility, and Authority
- Attribute 3.01
Organizational Structure
Assignment of Responsibility and Delegation of Authority
Documentation of the Internal Control System
Principle 4 - Demonstrate Commitment to Competence
- Attribute 4.01
Expectations of Competence
Recruitment, Development, and Retention of Individuals
- Attribute 4.05
Succession and Contingency Plans and Preparation
Principle 5 - Enforce Accountability
- Attribute 5.01
Enforcement of Accountability
Consideration of Excessive Pressures
Principle 6 - Define Objectives and Risk Tolerances
- Attribute 6.01
Definitions of Objectives
Definitions of Risk Tolerances
Principle 7 - Identify, Analyze, and Respond to Risks
- Attribute 7.01
Identify Risks
Analyze Risks
Respond to Risks
Principle 8 - Assess Fraud, Improper Payment, and Information
- Attribute 8.01
Identify Risks Related to Fraud, Improper Payments, and Information Security
Types of Fraud and Fraud Risk Factors
Types of Improper Payments and Improper Payment Risk Factors
- Attribute 8.13
Types of Information Security Risk and Information Security Risk Factors
Analyze and Respond to Identified Risks
Principle 9 - Identify, Analyze, and Respond to Change
- Attribute 9.01
Identify Significant Changes
Establish a Change Assessment Process
Identify, Analyze and Respond to Risks Related to Significant Changes
Principle 10 - Design Control Activities
- Attribute 10.01
Response to Risks
- Attribute 10.02
Design of Appropriate Types of Control Activities
Design of Automated and Manual Control Activities
Design of Preventive and Detective Control Activities
Design of Control Activities at Various Levels
- Attribute 10.14
- Attribute 10.15
- Attribute 10.16
- Attribute 10.17
- Attribute 10.18
- Attribute 10.19
- Attribute 10.20
Segregation of Duties
Principle 11 - Design General Control Activities over Information
- Attribute 11.01
Response to Risks
- Attribute 11.02
Design of the Entity’s Information Technology
Design of Appropriate Types of General Control Activities
- Attribute 11.07
- Attribute 11.08
- Attribute 11.09
- Attribute 11.10
- Attribute 11.11
- Attribute 11.12
- Attribute 11.13
- Attribute 11.14
- Attribute 11.15
- Attribute 11.16
- Attribute 11.17
Principle 12 - Implement Control Activities
- Attribute 12.01
Documentation of Control Activities Through Policies and Procedures
- Attribute 12.02
- Attribute 12.03
- Attribute 12.04
Periodic Review of Control Activities
- Attribute 12.05
Principle 13 - Use Quality Information
- Attribute 13.01
Identification of Information Requirements
- Attribute 13.02
- Attribute 13.03
Relevant Data from Reliable Sources
- Attribute 13.04
Data Processed into Quality Information
- Attribute 13.05
- Attribute 13.06
- Attribute 13.07
Principle 14 - Communicate Internally
- Attribute 14.01
Communication Throughout the Entity
- Attribute 14.02
- Attribute 14.03
- Attribute 14.04
- Attribute 14.05
- Attribute 14.06
Appropriate Methods of Communication
- Attribute 14.07
- Attribute 14.08
Principle 15 - Communicate Externally
- Attribute 15.01
Communication with External Parties
- Attribute 15.02
- Attribute 15.03
- Attribute 15.04
- Attribute 15.05
- Attribute 15.06
Appropriate Methods of Communication
- Attribute 15.07
- Attribute 15.08
- Attribute 15.09
Principle 16 - Perform Monitoring Activities
- Attribute 16.01
Establishment of a Baseline
- Attribute 16.02
- Attribute 16.03
Internal Control System Monitoring
- Attribute 16.04
- Attribute 16.05
- Attribute 16.06
- Attribute 16.07
- Attribute 16.08
Evaluation of Results
- Attribute 16.09
- Attribute 16.10
Principle 17 - Evaluate Issues and Remediate Deficiencies
- Attribute 17.01
Reporting of Issues
- Attribute 17.02
- Attribute 17.03
- Attribute 17.04
Evaluation of Issues
- Attribute 17.05
Corrective Actions
- Attribute 17.06
- Attribute 17.07
- Attribute 17.08
