Template:Principles: Difference between revisions

From Corrective Action Plan AZ
Line 25: Line 25:
'''''<big>Tone at the Top</big>'''''
'''''<big>Tone at the Top</big>'''''
* '''[[1.02|Attribute 1.02]]'''
* '''[[1.02|Attribute 1.02]]'''
* '''[[1.03|Attribute 1.03]] - with examples of potential governance gaps'''
* '''[[1.03|Attribute 1.03]] - with potential governance gap example(s)'''
* '''[[1.04|Attribute 1.04]]'''
* '''[[1.04|Attribute 1.04]]'''
* '''[[1.05|Attribute 1.05]]'''
* '''[[1.05|Attribute 1.05]]'''

Revision as of 11:24, 14 August 2026

US GAO Green Book Principles

  1. Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
  2. Principle 2 - Exercise Oversight Responsibility
  3. Principle 3 - Establish Structure, Responsibility, and Authority
  4. Principle 4 - Demonstrate Commitment to Competence
  5. Principle 5 - Enforce Accountability
  6. Principle 6 - Define Objectives and Risk Tolerances
  7. Principle 7 - Identify, Analyze, and Respond to Risks
  8. Principle 8 - Assess Fraud, Improper Payment, and Information
  9. Principle 9 - Identify, Analyze, and Respond to Change
  10. Principle 10 - Design Control Activities
  11. Principle 11 - Design General Control Activities over Information
  12. Principle 12 - Implement Control Activities
  13. Principle 13 - Use Quality Information
  14. Principle 14 - Communicate Internally
  15. Principle 15 - Communicate Externally
  16. Principle 16 - Perform Monitoring Activities
  17. Principle 17 - Evaluate Issues and Remediate Deficiencies

Index of Green Book Attributes Relating to Maricopa County Performance

Principle 1 - Demonstrate Commitment to Integrity and Ethical Values

Tone at the Top

Standards of Conduct

Adherence to Standards of Conduct

  • Attribute 1.08
  • Attribute 1.09
  • Attribute 1.10              

Principle 2 - Exercise Oversight Responsibility

Oversight Structure

Oversight for the Internal Control System

Input for Remediation of Deficiencies

Principle 3 - Establish Structure, Responsibility, and Authority

Organizational Structure

Assignment of Responsibility and Delegation of Authority

Documentation of the Internal Control System

Principle 4 - Demonstrate Commitment to Competence

Expectations of Competence

Recruitment, Development, and Retention of Individuals

Succession and Contingency Plans and Preparation

Principle 5 - Enforce Accountability

Enforcement of Accountability

Consideration of Excessive Pressures

Principle 6 - Define Objectives and Risk Tolerances

Definitions of Objectives

Definitions of Risk Tolerances

Principle 7 - Identify, Analyze, and Respond to Risks

Identify Risks

Analyze Risks

Respond to Risks

Principle 8 - Assess Fraud, Improper Payment, and Information

Identify Risks Related to Fraud, Improper Payments, and Information Security

Types of Fraud and Fraud Risk Factors

Types of Improper Payments and Improper Payment Risk Factors

Types of Information Security Risk and Information Security Risk Factors

Analyze and Respond to Identified Risks

Principle 9 - Identify, Analyze, and Respond to Change

Identify Significant Changes

Establish a Change Assessment Process

Identify, Analyze and Respond to Risks Related to Significant Changes

Principle 10 - Design Control Activities

Response to Risks

Design of Appropriate Types of Control Activities

Design of Automated and Manual Control Activities

Design of Preventive and Detective Control Activities

Design of Control Activities at Various Levels

Segregation of Duties

Principle 11 - Design General Control Activities over Information

Response to Risks

Design of the Entity’s Information Technology

Design of Appropriate Types of General Control Activities

Principle 12 - Implement Control Activities

Documentation of Control Activities Through Policies and Procedures

Periodic Review of Control Activities

Principle 13 - Use Quality Information

Identification of Information Requirements

Relevant Data from Reliable Sources

Data Processed into Quality Information

Principle 14 - Communicate Internally

Communication Throughout the Entity

Appropriate Methods of Communication

Principle 15 - Communicate Externally

Communication with External Parties

Appropriate Methods of Communication

Principle 16 - Perform Monitoring Activities

Establishment of a Baseline

Internal Control System Monitoring

Evaluation of Results

Principle 17 - Evaluate Issues and Remediate Deficiencies

Reporting of Issues

Evaluation of Issues

Corrective Actions