8.05
Risk Assessment
Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk
Attribute 8.05 - Management considers information that internal and external parties provide to identify risks related to fraud, improper payments, and information security. This may include information reported by the office of inspector general, internal auditors, personnel, service organizations, and other external parties that interact with the entity. Information may include emerging information security threats, identified instances of improper payments, or adjudicated cases of fraud as well as suspected or alleged fraud.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 8.04
- Next Attribute - 8.06
Jamie's Story
Additional details regarding this aspect of my story are available in a subsection titled Contract with the Motor Vehicle Department (MVD).
In 2024, the Arizona Secretary of State, Adrian Fontes, issued a press release on September 30, 2024, which described how over 218,000 voter registration records were adversely impacted during the collection of data by the MVD and subsequent transfer to the MC Recorders Office. The press release states, "Staff and experts from the Secretary of State’s Office are continuing to work with MVD to investigate if additional voters are impacted, or if other similar errors stemming from improperly coded Proposition 200 rules exist. We will continue to keep the public informed of developments if and when we have accurate, confirmed information to share." The Information Security Risk was real based on the number of corrupted records identified. Yet, MC managers and legal team had no written agreements between them and the MVD.
Potential Green Book Deviation:
Contrary to the Green Book, MC had failed to sufficiently identify risk to information during the process of collection and subsequent transfer of voter registration data from the MVD to MC prior to the September 2024 press release. The lack of a written agreement between MC and MVD suggest no action was taken to address a known risk after single error was found.
Election Anomalies
The Green Book's Principle 8 addresses Assess Fraud, Improper Payment, and Information Security Risk. Obviously, improper payments is not a concern during the Assessment of Election Anomalies. However, improper payments by MC county may exist, but would require a separate assessment.
The Green Book's emphasis on fraud and information security as separate risk assessment activity is intentional. MC may be able to defer to the Arizona Secretary of State's Election Procedure Manual as general steps taken to ensure the integrity of election results. Fraud occurs when loopholes are identified and exploited by the fraudsters. The implementers of election services (i.e., Arizona Counties) are better positioned to detect fraud and assess the risk of fraud because they are handling the data, not the state. Hence, governance gaps may be identified from patterns of poor assessment and response to risk with respect to election fraud and information security.
Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues. The Arizona Senate would not have needed to refer the seven allegations to the Arizona Attorney General had MC cooperated with the Senate. MC leaderships refusal to cooperate is also revealed by the election-related records the U.S. Federal Bureau of Investigation seized in 2026. Record turnover was not voluntary.
