8.04

From Arizona Citizen Voice

Risk Assessment

Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk

Attribute 8,04 - Management considers the types of fraud, improper payments, and information security breaches that may occur, along with relevant risk factors, when identifying risks related to these areas. While risks may be greater when multiple risk factors are present, the presence of one factor may still indicate a risk. Performing an analysis to identify the root cause of identified internal control deficiencies can assist management in identifying risks.

Navigational Buttons:

Jamie's Story

The discussion of Attribute 8.04 is from this March 12, 2026 event, under the subheading of Motor Vehicle Department Contract.

This Green Book attribute is fundamentally saying that a single risk factor can be more significant that a list of other risk. The likelihood and consequences from a single risk factor can be significant. This attribute describes how root cause analysis to address internal control deficiencies is good governance. Root cause analysis identifies the organizational risk and Corrective Action Plans mitigate that risk. Contrary to the Green Book, MC did not provide me with any objective evidence that demonstrated their interest in investigating election-related anomalies for the purpose of understanding the risk to election outcomes and developing corrective actions where necessary.

Election Anomalies

The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.

The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.

Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County - Signature Verification Process issues. As this attribute, one factor may, and in this case, does present risk. The one factor is the one person that makes fraud decisions every seven-seconds. No root cause has been performed as this attribute suggests.