New pages

From Corrective Action Plan AZ
New pages
Hide registered users | Show bots | Show redirects
(newest | oldest) View ( | ) (20 | 50 | 100 | 250 | 500)

16 August 2026

  • 00:2800:28, 16 August 2026 9.09 (hist | edit) [789 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.09''' - Management's change assessment process includes considerations for management to effectively analyze risk related to significant change, which may include the following: * how to determine the appropriate scope and extent of initial risk assessment related to a significant change—management considers entity objectives, risk tolerances, and other factors wh...") Tag: Visual edit
  • 00:2700:27, 16 August 2026 9.08 (hist | edit) [1,407 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.08''' - Management's change assessment process includes steps for timely identifying risks related to significant change, which may include the following: * the need to provide complex or different services quickly, which may result in increased risks overall, including those related to fraud, improper payments, information security, and noncompliance with applicabl...") Tag: Visual edit
  • 00:2600:26, 16 August 2026 9.07 (hist | edit) [518 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.07''' - Management develops and documents a change assessment process based on the risk assessment process described in principle 7. The process includes procedures for identifying, analyzing, and responding to risks related to significant changes.") Tag: Visual edit
  • 00:2400:24, 16 August 2026 9.06 (hist | edit) [876 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.06''' - As significant changes that an entity may need to respond to can occur quickly and unexpectedly, establishing a change assessment process in advance of significant changes occurring is essential to maintaining an effective internal control system as change occurs. This is especially important in situations where management may need to rapidly implement a new...") Tag: Visual edit
  • 00:2300:23, 16 August 2026 9.05 (hist | edit) [629 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9,05''' - Management documents a change assessment process for identifying, analyzing, and responding to risks related to significant changes so that the internal control system can be quickly adapted as needed to respond to significant changes as they occur ['''documentation requirement''']. Emphasis was placed on '''Documentation Requirement''' by the GAO.") Tag: Visual edit
  • 00:2100:21, 16 August 2026 9.04 (hist | edit) [759 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.04''' - Changes in internal conditions may include changes to the entity's programs or activities, oversight structure, organizational structure, personnel, and technology. Changes in external conditions may include changes in the governmental, economic, technological, legal, regulatory, and physical environments. Changes in external conditions may also include econo...") Tag: Visual edit
  • 00:2000:20, 16 August 2026 9.03 (hist | edit) [733 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.03''' - Conditions affecting the entity and its environment continually change. Management identifies, on a timely basis, significant changes to internal and external conditions that have already occurred or are expected to occur. Management anticipates and plans for significant changes that are expected to occur by using a forward-looking process to identify expecte...") Tag: Visual edit
  • 00:1900:19, 16 August 2026 9.02 (hist | edit) [826 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.02''' - As part of periodic and ongoing risk assessments, management identifies, on a timely basis, significant internal and external changes that could impact the entity's internal control system. Identifying, analyzing, and responding to significant changes is similar to, if not part of, the entity's periodic and ongoing risk assessment process. However, change is...") Tag: Visual edit
  • 00:1700:17, 16 August 2026 9.01 (hist | edit) [711 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.01''' - Management should identify, analyze, and respond to significant changes that could impact the internal control system. '''Green Book Attribute Categories for Principle 9''' The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Identify Significant Changes * Establish a Change Assessment Process...") Tag: Visual edit

15 August 2026

  • 22:2922:29, 15 August 2026 8.20 (hist | edit) [677 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.20''' - Management may develop separate processes within the periodic and ongoing risk assessment process with separate oversight responsibilities, to manage risks related to fraud, improper payments, or information security as part of the entity's overall internal control system. These separate processes would cover all components of internal co...") Tag: Visual edit
  • 22:2822:28, 15 August 2026 8.19 (hist | edit) [1,114 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.19''' - Management responds to fraud, improper payment, and information security risks consistent with the risk response process performed for all analyzed risks. Based on the selected risk response, management determines the specific actions to effectively mitigate each risk. It may be possible to reduce or avoid certain fraud, improper payment,...") Tag: Visual edit
  • 22:2722:27, 15 August 2026 8.18 (hist | edit) [675 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.18''' - Management analyzes and responds to identified fraud, improper payment, and information security risks so that they are effectively mitigated. These risks are analyzed through the same risk analysis process performed for all identified risks. Management analyzes the identified risks by estimating their significance to assess their impact...") Tag: Visual edit
  • 22:2622:26, 15 August 2026 8.17 (hist | edit) [940 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.17''' - Management considers information security risk factors, which may include the following: * the complexity of the entity's information technology; * new or emerging technologies; * information technology that may be outdated or incompatible with new technologies; * decentralized operating systems and communications networks; * external-pa...") Tag: Visual edit
  • 22:2522:25, 15 August 2026 8.16 (hist | edit) [1,128 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.16''' - External risks may come from external parties that connect with or operate the entity's information technology or from unrelated attackers. External parties that connect with the entity's operating systems and databases in the normal course of operations may include end users, such as program beneficiaries; federal, state, and local gover...") Tag: Visual edit
  • 22:2322:23, 15 August 2026 8.15 (hist | edit) [796 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.15''' - Internal risks include unintentional acts by employees, whose vigilance is a key defense against external threats and user error. Internal threats may also come from intentional malicious acts by former or disgruntled employees. They pose unique risks because these individuals may be both motivated to work against the entity and better eq...") Tag: Visual edit
  • 22:2222:22, 15 August 2026 8.14 (hist | edit) [2,675 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.14''' - Management considers the types of risks that could impact the entity's information and information technology to provide a basis for identifying and analyzing risks related to information security.<sup>62</sup> Information security risk is the risk to entity operations, assets, and personnel, as well as external parties, due to unauthoriz...") Tag: Visual edit
  • 22:2022:20, 15 August 2026 8.13 (hist | edit) [849 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.13''' - Management considers existing improper payment estimates, if available, when determining the significance of risks and the effectiveness of the internal control system in responding to improper payment risks. These estimates may come from management's annual improper payment estimates as part of its monitoring activities, which may be man...") Tag: Visual edit
  • 22:1922:19, 15 August 2026 8.12 (hist | edit) [1,611 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.12''' - Management considers improper payment risk factors, both internal and external, which may include the following: * whether the program or activity is new to the entity; * the complexity of the program or activity; * the volume of payments made through the program or activity; * whether the payments or payment eligibility decisions are ma...") Tag: Visual edit
  • 22:1722:17, 15 August 2026 8.11 (hist | edit) [1,451 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.11''' - Management considers the types of improper payments that could impact the entity to provide a basis for identifying and analyzing improper payment risks. Improper payments are any payments that should not have been made or that were made in an incorrect amount. Payments are also considered improper when there is insufficient or lack of do...") Tag: Visual edit
  • 22:1622:16, 15 August 2026 8.10 (hist | edit) [1,466 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.10''' - Management considers fraud risk factors. Fraud risk factors do not necessarily indicate that fraud exists but are often present when fraud occurs. Fraud risk factors may include the following: * '''Incentive/pressure''' - Management, other personnel, or external parties have an incentive or are under pressure, which provides a motive to...") Tag: Visual edit
  • 22:1422:14, 15 August 2026 8.09 (hist | edit) [2,110 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.09''' - In addition to fraud, management also considers the risk of management override of controls. Management override of controls does not necessarily involve fraud but may indicate potential fraud and increases fraud risk.") Tag: Visual edit
  • 22:1322:13, 15 August 2026 8.08 (hist | edit) [2,705 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.08''' - In addition to fraud, management considers other forms of misconduct that can occur, such as waste and abuse. Waste is the act of using or expending resources carelessly, extravagantly, or to no purpose. Abuse involves behavior that is deficient or improper when compared with behavior that a prudent person would consider reasonable and ne...") Tag: Visual edit
  • 22:1222:12, 15 August 2026 8.07 (hist | edit) [2,119 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.07''' - As part of a risk assessment, management considers the risk of fraud that could impact the entity from both within the entity and from external parties. For example, external fraud risk may arise when an entity relies on service organizations' internal control systems to perform business processes for the entity. External parties that pre...") Tag: Visual edit
  • 22:1122:11, 15 August 2026 8.06 (hist | edit) [1,598 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.06''' - Management considers the types of fraud that could impact the entity to provide a basis for identifying and analyzing fraud. Fraud involves obtaining something of value through willful misrepresentation. Types of fraud may include the following: * '''Fraudulent reporting''' - Intentional misstatements or omissions of amounts or disclosur...") Tag: Visual edit
  • 22:0922:09, 15 August 2026 8.05 (hist | edit) [2,347 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.05''' - Management considers information that internal and external parties provide to identify risks related to fraud, improper payments, and information security. This may include information reported by the office of inspector general, internal auditors, personnel, service organizations, and other external parties that interact with the entity...") Tag: Visual edit
  • 22:0722:07, 15 August 2026 8.03 (hist | edit) [1,336 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8,03''' - Management identifies risks related to fraud, improper payments, and information security on a periodic and ongoing basis to provide a basis for analyzing risks. Risk assessment is the identification and analysis of risks related to achieving the defined objectives to form a basis for designing risk responses. To determine the scope and f...") Tag: Visual edit
  • 21:5921:59, 15 August 2026 7.14 (hist | edit) [711 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.14''' - Performance measures are used to assess whether risk response actions enable the entity to operate within the defined risk tolerances. When risk response actions do not enable the entity to operate within the defined risk tolerances, management may need to revise risk responses or reconsider defined risk tolerances. Management may need to conduct periodic risk...") Tag: Visual edit
  • 21:5821:58, 15 August 2026 7.13 (hist | edit) [610 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.13''' - After designing risk responses, management then considers residual risk. In instances where a risk response results in the residual risk exceeding defined risk tolerances, management revisits and revises the response. Operating within the defined risk tolerance provides greater assurance that the entity will achieve its objectives.") Tag: Visual edit
  • 21:5721:57, 15 August 2026 7.12 (hist | edit) [1,055 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.12''' - When designing controls to mitigate risk, management may modify controls related to the entity's oversight responsibilities, organizational structure, and responsibilities and authorities throughout the entity. Management may also develop separate processes within the periodic and ongoing risk assessment process<sup>50</sup> with separate oversight responsibil...") Tag: Visual edit
  • 21:5621:56, 15 August 2026 7.11 (hist | edit) [828 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.11''' - Based on the selected risk response, management designs controls to effectively mitigate the analyzed risks on a timely basis. If management has chosen to reduce or share a risk, then management designs controls, which may exist within each component of internal control or constitute a specific control activity. Typically, controls are not needed when an entit...") Tag: Visual edit
  • 21:5521:55, 15 August 2026 7.10 (hist | edit) [1,049 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.10''' - Management designs responses to the analyzed risks so that risks are within the defined risk tolerance for the defined objective.<sup>47</sup> Management designs overall risk responses for the analyzed risks based on the significance of the risk, defined risk tolerance, and cost-benefit determination.<sup>48</sup> These risk responses may include the following...") Tag: Visual edit
  • 21:5321:53, 15 August 2026 7.09 (hist | edit) [758 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.09''' - Risks may be analyzed individually or grouped into categories with related risks and analyzed collectively. Regardless of whether risks are analyzed individually or collectively, management considers the correlation among different risks or groups of risks when estimating their significance. The specific risk analysis methodology used can vary by entity becaus...") Tag: Visual edit
  • 21:5121:51, 15 August 2026 7.08 (hist | edit) [1,077 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.08''' - Management estimates the significance of the identified risks to assess their impact on achieving the defined objectives at both the entity and transaction levels. Management estimates the significance of a risk by considering the magnitude of impact, likelihood of occurrence, and nature of the risk. Magnitude of impact refers to the likely magnitude of the e...") Tag: Visual edit
  • 21:4921:49, 15 August 2026 7.07 (hist | edit) [508 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.07''' - Management analyzes the identified risks, on a periodic and ongoing basis, to estimate their significance, which provides a basis for responding to the risks.<sup>46</sup> Significance refers to a risk's impact on achieving a defined objective.") Tag: Visual edit
  • 21:4721:47, 15 August 2026 7.06 (hist | edit) [1,120 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.06''' - Risk identification methods may include qualitative and quantitative ranking activities, forecasting and strategic planning, data analytics, and consideration of internal control deficiencies identified through monitoring activities or reported by internal or external parties. Performing an analysis to identify the root causes of internal control deficiencies...") Tag: Visual edit
  • 19:5319:53, 15 August 2026 7.05 (hist | edit) [579 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.05''' - Management's consideration of risk factors related to fraud, improper payments, and information security is discussed further in principle 8. Management's consideration of significant internal and external changes that could impact the internal control system is discussed further in principle 9.") Tag: Visual edit
  • 19:4819:48, 15 August 2026 7.03 (hist | edit) [1,042 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.03''' - To identify risks, management considers the types of risks that impact the entity. This includes both inherent and residual risk. Inherent risk is the risk to an entity in the absence of management's response to the risk. Residual risk is the risk that remains after management's response to inherent risk. Once risk responses have been developed to address inhe...") Tag: Visual edit
  • 19:4619:46, 15 August 2026 7.02 (hist | edit) [1,254 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.02''' - Management identifies risks throughout the entity on a periodic and ongoing basis to provide a basis for analyzing risks. Risk is the possibility that an event will occur and adversely affect the achievement of objectives. Risk assessment is the identification and analysis of risks related to achieving the defined objectives to form a basis for designing risk...") Tag: Visual edit
  • 19:4319:43, 15 August 2026 7.01 (hist | edit) [608 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.01''' - Management should identify, analyze, and respond to risks related to achieving the defined objectives. '''Green Book Attribute Categories for Principle 7''' The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Identify Risks * Analyze Risks * Respond to Risks") Tag: Visual edit
  • 19:3919:39, 15 August 2026 6.10 (hist | edit) [914 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.10''' - Management also evaluates whether risk tolerances enable the appropriate design of internal control by considering whether they are consistent with requirements and expectations for the defined objectives. As in defining objectives, management considers the risk tolerances in the context of the entity's applicable laws, regulations, and standards as well as the entity...") Tag: Visual edit
  • 19:3619:36, 15 August 2026 6.09 (hist | edit) [1,520 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.09''' - Management defines risk tolerances in specific and measurable terms so that they are clearly stated and can be measured. For example, for an objective to process all benefit applications within 10 business days of receipt, management may determine that a risk tolerance of a range of 8-12 business days would be an acceptable level of variation. Depending on the categor...") Tag: Visual edit
  • 19:3419:34, 15 August 2026 6.08 (hist | edit) [717 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.08''' - Management defines risk tolerances for the defined objectives. Risk tolerance is the acceptable level of variation in performance relative to the achievement of objectives. Risk tolerances are initially set as part of the objective-setting process. Management defines the risk tolerances for defined objectives by ensuring that the set levels of variation for performanc...") Tag: Visual edit
  • 19:3219:32, 15 August 2026 6.07 (hist | edit) [685 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.07''' - Management determines whether performance measures for the defined objectives are appropriate for evaluating the entity's performance in achieving those objectives. For quantitative objectives, performance measures may be a targeted percentage or numerical value. For qualitative objectives, management may need to design performance measures that indicate a level or de...") Tag: Visual edit
  • 19:2619:26, 15 August 2026 6.06 (hist | edit) [539 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.06''' - Management evaluates and, if necessary, revises defined objectives so that they are consistent with external requirements and internal expectations. This consistency enables management to identify and analyze risks associated with achieving the defined objectives.") Tag: Visual edit
  • 19:2319:23, 15 August 2026 6.05 (hist | edit) [904 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.05''' -") Tag: Visual edit
  • 19:2219:22, 15 August 2026 6.04 (hist | edit) [639 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.04''' - Management defines objectives in measurable terms so that performance toward achieving those objectives can be assessed. Measurable objectives are generally free of bias and do not require subjective judgments to dominate their measurement. Measurable objectives are also stated in a quantitative or qualitative form that permits reasonably consistent measurement.") Tag: Visual edit
  • 19:1719:17, 15 August 2026 6.03 (hist | edit) [864 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.03''' - Management defines objectives in specific terms, so that they are understood at all levels of the entity. This involves clearly defining what is to be achieved, who is to achieve it, how it will be achieved, and the time frames for achievement. All objectives can be broadly classified into one or more of three categories: operations, reporting, or compliance. Reportin...") Tag: Visual edit
  • 19:1519:15, 15 August 2026 6.02 (hist | edit) [814 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.02''' - Management defines objectives, and related subobjectives, in specific and measurable terms to enable the design of internal control for related risks.<sup>34</sup> Specific terms are fully and clearly set forth so they can be easily understood. Measurable terms allow for the assessment of performance toward achieving objectives. Objectives are initially set as part of...") Tag: Visual edit
  • 19:0919:09, 15 August 2026 5.08 (hist | edit) [1,389 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Control Environment''' '''Principle 5 - Enforce Accountability''' '''Attribute 5.08''' - Management is responsible for evaluating pressure on personnel to help personnel fulfill their assigned responsibilities in accordance with the entity's standards of conduct. Management can adjust excessive pressures using many different tools, such as rebalancing workloads or increasing resource levels.") Tag: Visual edit
  • 19:0719:07, 15 August 2026 5.07 (hist | edit) [626 bytes] Neil thibodaux (talk | contribs) (Created page with "'''Control Environment''' '''Principle 5 - Enforce Accountability''' '''Attribute 5.07''' - Management adjusts excessive pressures on personnel in the entity. Pressure can appear in an entity because of goals management established to meet objectives or cyclical demands of various processes the entity performs, such as year-end financial statement preparation. Excessive pressure can result in personnel "cutting corners" to meet the established goals.") Tag: Visual edit
(newest | oldest) View ( | ) (20 | 50 | 100 | 250 | 500)