7.06
Risk Assessment
Principle 7 - Identify, Analyze, and Respond to Risks
Attribute 7.06 - Risk identification methods may include qualitative and quantitative ranking activities, forecasting and strategic planning, data analytics, and consideration of internal control deficiencies identified through monitoring activities or reported by internal or external parties. Performing an analysis to identify the root causes of internal control deficiencies can assist management in identifying risks. Management also collaborates with relevant internal and external parties to identify risks. Internal parties include appropriate management and other personnel from all appropriate units within the entity's organizational structure, including program and financial managers. External parties may include service organizations, suppliers, contractors, regulated entities, federal entities, state and local governments, and grantees.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 7.05
- Next Attribute - 7.07
Election Anomalies
Principle 7 addresses the need to Identify, Analyze, and Respond to Risks. The identification and analysis of risk are presumed to have been performed at the state level, which are addressed in the Arizona Secretary of State's Election Procedure Manual. The MC leadership team's Response to Risk is the primary governance weakness with respect to the Green Book's Principle #7, including this attribute.
Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues. Section 2 of the AZ AG's inspector's report identifies numerous issues, which present risk to potential fraud.
This attribute specifically states, "Ongoing risk assessments are performed as needed, on a real-time basis, such as when significant internal or external change occurs or significant emerging risks are identified." External changes consisted of Public Health mandates associated with the Covid-19 pandemic. Rather than implement risk reduction actions, MC management appeared to ignore procedure requirements, which actually increased the risk of fraud. The following issues identified in the inspector's report are related to management actions or inaction related to increasing the risk of fraud:
Contrary to the Green Book statement, "Performing an analysis to identify the root causes of internal control deficiencies can assist management in identifying risks.", MC did not perform an investigation into any of the following anomalies or noteworthy situations:
- See the heading Deviation: Missing Entries on Election Forms from Maricopa Dropbox Collection (2020) webpage.
- See the heading Deviation: Missing Ballot Counts from Maricopa Dropbox Collection (2020) webpage.
- See the heading Deviation: Used Email instead of EVBTS Forms from Maricopa Dropbox Collection (2020) webpage.
- See the heading Deviation: Unfulfilled Party Representation Requirements for Couriers from Maricopa Dropbox Collection (2020) webpage.
- See the heading Deviation: Fictious Addresses in MC Voter Registration Database from Maricopa Dropbox Collection (2020) webpage.
- See the heading Deviation: Allegations Confirmed from Maricopa Dropbox Collection (2020) webpage.
- See the heading Noteworthy: Consequences Unknown from Maricopa Dropbox Collection (2020) webpage
- See the heading Noteworthy: Transmission of USPS Data to MC and Runbeck from Maricopa Dropbox Collection (2020) webpage
Contrary to the Green Book Statement, "Management also collaborates with relevant internal and external parties to identify risks.", MC management did not collaborate with the USPS to assess the risk of over 56,000 undeliverable early ballots.
- See the heading Deviation: Fictious Addresses in MC Voter Registration Database from Maricopa Dropbox Collection (2020) webpage.
- See the heading Noteworthy: Transmission of USPS Data to MC and Runbeck from Maricopa Dropbox Collection (2020) webpage
