Template:Principles

From Corrective Action Plan AZ

US GAO Green Book Principles

  1. Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
  2. Principle 2 - Exercise Oversight Responsibility
  3. Principle 3 - Establish Structure, Responsibility, and Authority
  4. Principle 4 - Demonstrate Commitment to Competence
  5. Principle 5 - Enforce Accountability
  6. Principle 6 - Define Objectives and Risk Tolerances
  7. Principle 7 - Identify, Analyze, and Respond to Risks
  8. Principle 8 - Assess Fraud, Improper Payment, and Information
  9. Principle 9 - Identify, Analyze, and Respond to Change
  10. Principle 10 - Design Control Activities
  11. Principle 11 - Design General Control Activities over Information
  12. Principle 12 - Implement Control Activities
  13. Principle 13 - Use Quality Information
  14. Principle 14 - Communicate Internally
  15. Principle 15 - Communicate Externally
  16. Principle 16 - Perform Monitoring Activities
  17. Principle 17 - Evaluate Issues and Remediate Deficiencies

Index of Green Book Attributes Relating to Maricopa County Performance

Principle 1 - Demonstrate Commitment to Integrity and Ethical Values

Tone at the Top

Standards of Conduct

Adherence to Standards of Conduct

  • Attribute 1.08
  • Attribute 1.09
  • Attribute 1.10              

Principle 2 - Exercise Oversight Responsibility

Oversight Structure

Oversight for the Internal Control System

Input for Remediation of Deficiencies

Principle 3 - Establish Structure, Responsibility, and Authority

Organizational Structure

Assignment of Responsibility and Delegation of Authority

Documentation of the Internal Control System

Principle 4 - Demonstrate Commitment to Competence

Expectations of Competence

Recruitment, Development, and Retention of Individuals

Succession and Contingency Plans and Preparation

Principle 5 - Enforce Accountability

Enforcement of Accountability

Consideration of Excessive Pressures

Principle 6 - Define Objectives and Risk Tolerances

Definitions of Objectives

Definitions of Risk Tolerances

Principle 7 - Identify, Analyze, and Respond to Risks

Identify Risks

Analyze Risks

Respond to Risks

Principle 8 - Assess Fraud, Improper Payment, and Information

Identify Risks Related to Fraud, Improper Payments, and Information Security

Types of Fraud and Fraud Risk Factors

Types of Improper Payments and Improper Payment Risk Factors

Types of Information Security Risk and Information Security Risk Factors

Analyze and Respond to Identified Risks

Principle 9 - Identify, Analyze, and Respond to Change

Identify Significant Changes

Establish a Change Assessment Process

Identify, Analyze and Respond to Risks Related to Significant Changes

Principle 10 - Design Control Activities

Response to Risks

Design of Appropriate Types of Control Activities

Design of Automated and Manual Control Activities

Design of Preventive and Detective Control Activities

Design of Control Activities at Various Levels

Segregation of Duties

Principle 11 - Design General Control Activities over Information

Response to Risks

Design of the Entity’s Information Technology

Design of Appropriate Types of General Control Activities

Principle 12 - Implement Control Activities

  • Attribute 12.01

Documentation of Control Activities Through Policies and Procedures

  • Attribute 12.02
  • Attribute 12.03
  • Attribute 12.04

Periodic Review of Control Activities

  • Attribute 12.05

Principle 13 - Use Quality Information

  • Attribute 13.01

Identification of Information Requirements

  • Attribute 13.02
  • Attribute 13.03

Relevant Data from Reliable Sources

  • Attribute 13.04

Data Processed into Quality Information

  • Attribute 13.05
  • Attribute 13.06
  • Attribute 13.07

Principle 14 - Communicate Internally

  • Attribute 14.01

Communication Throughout the Entity

  • Attribute 14.02
  • Attribute 14.03
  • Attribute 14.04
  • Attribute 14.05
  • Attribute 14.06

Appropriate Methods of Communication

  • Attribute 14.07
  • Attribute 14.08

Principle 15 - Communicate Externally

  • Attribute 15.01

Communication with External Parties

  • Attribute 15.02
  • Attribute 15.03
  • Attribute 15.04
  • Attribute 15.05
  • Attribute 15.06

Appropriate Methods of Communication

  • Attribute 15.07
  • Attribute 15.08
  • Attribute 15.09

Principle 16 - Perform Monitoring Activities

  • Attribute 16.01

Establishment of a Baseline

  • Attribute 16.02
  • Attribute 16.03

Internal Control System Monitoring

  • Attribute 16.04
  • Attribute 16.05
  • Attribute 16.06
  • Attribute 16.07
  • Attribute 16.08

Evaluation of Results

  • Attribute 16.09
  • Attribute 16.10

Principle 17 - Evaluate Issues and Remediate Deficiencies

  • Attribute 17.01

Reporting of Issues

  • Attribute 17.02
  • Attribute 17.03
  • Attribute 17.04

Evaluation of Issues

  • Attribute 17.05

Corrective Actions

  • Attribute 17.06
  • Attribute 17.07
  • Attribute 17.08