7.02

From Arizona Citizen Voice

Risk Assessment

Principle 7 - Identify, Analyze, and Respond to Risks

Attribute 7.02 - Management identifies risks throughout the entity on a periodic and ongoing basis to provide a basis for analyzing risks. Risk is the possibility that an event will occur and adversely affect the achievement of objectives. Risk assessment is the identification and analysis of risks related to achieving the defined objectives to form a basis for designing risk responses. Periodic risk assessments are performed at specific times and at regular intervals, such as annually. Management considers entity objectives, risk tolerances, and other factors when determining the scope and frequency of these assessments. Ongoing risk assessments are performed as needed, on a real-time basis, such as when significant internal or external change occurs or significant emerging risks are identified. Management also considers performing ongoing risk assessments when internal control deficiencies, improper payments, potential fraud, or information security breaches are detected.

>>>Navigational Buttons<<<


Jamie's Story

No examples available to illustrate governance gaps for this attribute.

Election Anomalies

Principle 7 addresses the need to Identify, Analyze, and Respond to Risks. The identification and analysis of risk are presumed to have been performed at the state level, which are addressed in the Arizona Secretary of State's Election Procedure Manual. The MC leadership team's Response to Risk is the primary governance weakness with respect to the Green Book's Principle #7, including this attribute.

Governance issues identified from Arizona Attorney General's Office 2020 General Election Investigation of Arizona Senate allegations of Maricopa County Election Department - Drop Box Collections issues. Section 2 of the AZ AG's inspector's report identifies numerous issues, which present risk to potential fraud.

This attribute specifically states, "Ongoing risk assessments are performed as needed, on a real-time basis, such as when significant internal or external change occurs or significant emerging risks are identified." External changes consisted of Public Health mandates associated with the Covid-19 pandemic. Rather than implement risk reduction actions, MC management appeared to ignore procedure requirements, which actually increased the risk of fraud. The following issues identified in the inspector's report are related to management actions or inaction related to increasing the risk of fraud: