Main public logs

From Corrective Action Plan AZ

Combined display of all available logs of Corrective Action Plan AZ. You can narrow down the view by selecting a log type, the username (case-sensitive), or the affected page (also case-sensitive).

Logs
(newest | oldest) View ( | ) (20 | 50 | 100 | 250 | 500)
  • 22:23, 15 August 2026 Neil thibodaux talk contribs created page 8.15 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.15''' - Internal risks include unintentional acts by employees, whose vigilance is a key defense against external threats and user error. Internal threats may also come from intentional malicious acts by former or disgruntled employees. They pose unique risks because these individuals may be both motivated to work against the entity and better eq...") Tag: Visual edit
  • 22:22, 15 August 2026 Neil thibodaux talk contribs created page 8.14 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.14''' - Management considers the types of risks that could impact the entity's information and information technology to provide a basis for identifying and analyzing risks related to information security.<sup>62</sup> Information security risk is the risk to entity operations, assets, and personnel, as well as external parties, due to unauthoriz...") Tag: Visual edit
  • 22:20, 15 August 2026 Neil thibodaux talk contribs created page 8.13 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.13''' - Management considers existing improper payment estimates, if available, when determining the significance of risks and the effectiveness of the internal control system in responding to improper payment risks. These estimates may come from management's annual improper payment estimates as part of its monitoring activities, which may be man...") Tag: Visual edit
  • 22:19, 15 August 2026 Neil thibodaux talk contribs created page 8.12 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.12''' - Management considers improper payment risk factors, both internal and external, which may include the following: * whether the program or activity is new to the entity; * the complexity of the program or activity; * the volume of payments made through the program or activity; * whether the payments or payment eligibility decisions are ma...") Tag: Visual edit
  • 22:17, 15 August 2026 Neil thibodaux talk contribs created page 8.11 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.11''' - Management considers the types of improper payments that could impact the entity to provide a basis for identifying and analyzing improper payment risks. Improper payments are any payments that should not have been made or that were made in an incorrect amount. Payments are also considered improper when there is insufficient or lack of do...") Tag: Visual edit
  • 22:16, 15 August 2026 Neil thibodaux talk contribs created page 8.10 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.10''' - Management considers fraud risk factors. Fraud risk factors do not necessarily indicate that fraud exists but are often present when fraud occurs. Fraud risk factors may include the following: * '''Incentive/pressure''' - Management, other personnel, or external parties have an incentive or are under pressure, which provides a motive to...") Tag: Visual edit
  • 22:14, 15 August 2026 Neil thibodaux talk contribs created page 8.09 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.09''' - In addition to fraud, management also considers the risk of management override of controls. Management override of controls does not necessarily involve fraud but may indicate potential fraud and increases fraud risk.") Tag: Visual edit
  • 22:13, 15 August 2026 Neil thibodaux talk contribs created page 8.08 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.08''' - In addition to fraud, management considers other forms of misconduct that can occur, such as waste and abuse. Waste is the act of using or expending resources carelessly, extravagantly, or to no purpose. Abuse involves behavior that is deficient or improper when compared with behavior that a prudent person would consider reasonable and ne...") Tag: Visual edit
  • 22:12, 15 August 2026 Neil thibodaux talk contribs created page 8.07 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.07''' - As part of a risk assessment, management considers the risk of fraud that could impact the entity from both within the entity and from external parties. For example, external fraud risk may arise when an entity relies on service organizations' internal control systems to perform business processes for the entity. External parties that pre...") Tag: Visual edit
  • 22:11, 15 August 2026 Neil thibodaux talk contribs created page 8.06 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.06''' - Management considers the types of fraud that could impact the entity to provide a basis for identifying and analyzing fraud. Fraud involves obtaining something of value through willful misrepresentation. Types of fraud may include the following: * '''Fraudulent reporting''' - Intentional misstatements or omissions of amounts or disclosur...") Tag: Visual edit
  • 22:09, 15 August 2026 Neil thibodaux talk contribs created page 8.05 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.05''' - Management considers information that internal and external parties provide to identify risks related to fraud, improper payments, and information security. This may include information reported by the office of inspector general, internal auditors, personnel, service organizations, and other external parties that interact with the entity...") Tag: Visual edit
  • 22:07, 15 August 2026 Neil thibodaux talk contribs created page 8.03 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8,03''' - Management identifies risks related to fraud, improper payments, and information security on a periodic and ongoing basis to provide a basis for analyzing risks. Risk assessment is the identification and analysis of risks related to achieving the defined objectives to form a basis for designing risk responses. To determine the scope and f...") Tag: Visual edit
  • 21:59, 15 August 2026 Neil thibodaux talk contribs created page 7.14 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.14''' - Performance measures are used to assess whether risk response actions enable the entity to operate within the defined risk tolerances. When risk response actions do not enable the entity to operate within the defined risk tolerances, management may need to revise risk responses or reconsider defined risk tolerances. Management may need to conduct periodic risk...") Tag: Visual edit
  • 21:58, 15 August 2026 Neil thibodaux talk contribs created page 7.13 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.13''' - After designing risk responses, management then considers residual risk. In instances where a risk response results in the residual risk exceeding defined risk tolerances, management revisits and revises the response. Operating within the defined risk tolerance provides greater assurance that the entity will achieve its objectives.") Tag: Visual edit
  • 21:57, 15 August 2026 Neil thibodaux talk contribs created page 7.12 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.12''' - When designing controls to mitigate risk, management may modify controls related to the entity's oversight responsibilities, organizational structure, and responsibilities and authorities throughout the entity. Management may also develop separate processes within the periodic and ongoing risk assessment process<sup>50</sup> with separate oversight responsibil...") Tag: Visual edit
  • 21:56, 15 August 2026 Neil thibodaux talk contribs created page 7.11 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.11''' - Based on the selected risk response, management designs controls to effectively mitigate the analyzed risks on a timely basis. If management has chosen to reduce or share a risk, then management designs controls, which may exist within each component of internal control or constitute a specific control activity. Typically, controls are not needed when an entit...") Tag: Visual edit
  • 21:55, 15 August 2026 Neil thibodaux talk contribs created page 7.10 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.10''' - Management designs responses to the analyzed risks so that risks are within the defined risk tolerance for the defined objective.<sup>47</sup> Management designs overall risk responses for the analyzed risks based on the significance of the risk, defined risk tolerance, and cost-benefit determination.<sup>48</sup> These risk responses may include the following...") Tag: Visual edit
  • 21:53, 15 August 2026 Neil thibodaux talk contribs created page 7.09 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.09''' - Risks may be analyzed individually or grouped into categories with related risks and analyzed collectively. Regardless of whether risks are analyzed individually or collectively, management considers the correlation among different risks or groups of risks when estimating their significance. The specific risk analysis methodology used can vary by entity becaus...") Tag: Visual edit
  • 21:51, 15 August 2026 Neil thibodaux talk contribs created page 7.08 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.08''' - Management estimates the significance of the identified risks to assess their impact on achieving the defined objectives at both the entity and transaction levels. Management estimates the significance of a risk by considering the magnitude of impact, likelihood of occurrence, and nature of the risk. Magnitude of impact refers to the likely magnitude of the e...") Tag: Visual edit
  • 21:49, 15 August 2026 Neil thibodaux talk contribs created page 7.07 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.07''' - Management analyzes the identified risks, on a periodic and ongoing basis, to estimate their significance, which provides a basis for responding to the risks.<sup>46</sup> Significance refers to a risk's impact on achieving a defined objective.") Tag: Visual edit
  • 21:47, 15 August 2026 Neil thibodaux talk contribs created page 7.06 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.06''' - Risk identification methods may include qualitative and quantitative ranking activities, forecasting and strategic planning, data analytics, and consideration of internal control deficiencies identified through monitoring activities or reported by internal or external parties. Performing an analysis to identify the root causes of internal control deficiencies...") Tag: Visual edit
  • 19:53, 15 August 2026 Neil thibodaux talk contribs created page 7.05 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.05''' - Management's consideration of risk factors related to fraud, improper payments, and information security is discussed further in principle 8. Management's consideration of significant internal and external changes that could impact the internal control system is discussed further in principle 9.") Tag: Visual edit
  • 19:48, 15 August 2026 Neil thibodaux talk contribs created page 7.03 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.03''' - To identify risks, management considers the types of risks that impact the entity. This includes both inherent and residual risk. Inherent risk is the risk to an entity in the absence of management's response to the risk. Residual risk is the risk that remains after management's response to inherent risk. Once risk responses have been developed to address inhe...") Tag: Visual edit
  • 19:46, 15 August 2026 Neil thibodaux talk contribs created page 7.02 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.02''' - Management identifies risks throughout the entity on a periodic and ongoing basis to provide a basis for analyzing risks. Risk is the possibility that an event will occur and adversely affect the achievement of objectives. Risk assessment is the identification and analysis of risks related to achieving the defined objectives to form a basis for designing risk...") Tag: Visual edit
  • 19:43, 15 August 2026 Neil thibodaux talk contribs created page 7.01 (Created page with "'''Risk Assessment''' '''Principle 7 - Identify, Analyze, and Respond to Risks''' '''Attribute''' '''7.01''' - Management should identify, analyze, and respond to risks related to achieving the defined objectives. '''Green Book Attribute Categories for Principle 7''' The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Identify Risks * Analyze Risks * Respond to Risks") Tag: Visual edit
  • 19:39, 15 August 2026 Neil thibodaux talk contribs created page 6.10 (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.10''' - Management also evaluates whether risk tolerances enable the appropriate design of internal control by considering whether they are consistent with requirements and expectations for the defined objectives. As in defining objectives, management considers the risk tolerances in the context of the entity's applicable laws, regulations, and standards as well as the entity...") Tag: Visual edit
  • 19:36, 15 August 2026 Neil thibodaux talk contribs created page 6.09 (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.09''' - Management defines risk tolerances in specific and measurable terms so that they are clearly stated and can be measured. For example, for an objective to process all benefit applications within 10 business days of receipt, management may determine that a risk tolerance of a range of 8-12 business days would be an acceptable level of variation. Depending on the categor...") Tag: Visual edit
  • 19:34, 15 August 2026 Neil thibodaux talk contribs created page 6.08 (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.08''' - Management defines risk tolerances for the defined objectives. Risk tolerance is the acceptable level of variation in performance relative to the achievement of objectives. Risk tolerances are initially set as part of the objective-setting process. Management defines the risk tolerances for defined objectives by ensuring that the set levels of variation for performanc...") Tag: Visual edit
  • 19:32, 15 August 2026 Neil thibodaux talk contribs created page 6.07 (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.07''' - Management determines whether performance measures for the defined objectives are appropriate for evaluating the entity's performance in achieving those objectives. For quantitative objectives, performance measures may be a targeted percentage or numerical value. For qualitative objectives, management may need to design performance measures that indicate a level or de...") Tag: Visual edit
  • 19:26, 15 August 2026 Neil thibodaux talk contribs created page 6.06 (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.06''' - Management evaluates and, if necessary, revises defined objectives so that they are consistent with external requirements and internal expectations. This consistency enables management to identify and analyze risks associated with achieving the defined objectives.") Tag: Visual edit
  • 19:23, 15 August 2026 Neil thibodaux talk contribs created page 6.05 (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.05''' -") Tag: Visual edit
  • 19:22, 15 August 2026 Neil thibodaux talk contribs created page 6.04 (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.04''' - Management defines objectives in measurable terms so that performance toward achieving those objectives can be assessed. Measurable objectives are generally free of bias and do not require subjective judgments to dominate their measurement. Measurable objectives are also stated in a quantitative or qualitative form that permits reasonably consistent measurement.") Tag: Visual edit
  • 19:17, 15 August 2026 Neil thibodaux talk contribs created page 6.03 (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.03''' - Management defines objectives in specific terms, so that they are understood at all levels of the entity. This involves clearly defining what is to be achieved, who is to achieve it, how it will be achieved, and the time frames for achievement. All objectives can be broadly classified into one or more of three categories: operations, reporting, or compliance. Reportin...") Tag: Visual edit
  • 19:15, 15 August 2026 Neil thibodaux talk contribs created page 6.02 (Created page with "'''Risk Assessment''' '''Principle 6 - Define Objectives and Risk Tolerances''' '''Attribute 6.02''' - Management defines objectives, and related subobjectives, in specific and measurable terms to enable the design of internal control for related risks.<sup>34</sup> Specific terms are fully and clearly set forth so they can be easily understood. Measurable terms allow for the assessment of performance toward achieving objectives. Objectives are initially set as part of...") Tag: Visual edit
  • 19:09, 15 August 2026 Neil thibodaux talk contribs created page 5.08 (Created page with "'''Control Environment''' '''Principle 5 - Enforce Accountability''' '''Attribute 5.08''' - Management is responsible for evaluating pressure on personnel to help personnel fulfill their assigned responsibilities in accordance with the entity's standards of conduct. Management can adjust excessive pressures using many different tools, such as rebalancing workloads or increasing resource levels.") Tag: Visual edit
  • 19:07, 15 August 2026 Neil thibodaux talk contribs created page 5.07 (Created page with "'''Control Environment''' '''Principle 5 - Enforce Accountability''' '''Attribute 5.07''' - Management adjusts excessive pressures on personnel in the entity. Pressure can appear in an entity because of goals management established to meet objectives or cyclical demands of various processes the entity performs, such as year-end financial statement preparation. Excessive pressure can result in personnel "cutting corners" to meet the established goals.") Tag: Visual edit
  • 19:05, 15 August 2026 Neil thibodaux talk contribs created page 5.06 (Created page with "'''Control Environment''' '''Principle 5 - Enforce Accountability''' '''Attribute 5.06''' - Management, with oversight from the oversight body, takes corrective action as necessary to enforce accountability for internal control in the entity. These actions can range from informal feedback provided by the direct supervisor to disciplinary action taken by the oversight body, depending on the significance of the deficiency to the internal control system.") Tag: Visual edit
  • 19:03, 15 August 2026 Neil thibodaux talk contribs created page 5.05 (Created page with "'''Control Environment''' '''Principle 5 - Enforce Accountability''' '''Attribute 5.05''' - Management holds service organizations accountable for their assigned internal control responsibilities. Management may contract with service organizations to perform roles in the organizational structure. Management communicates to each service organization the objectives of the entity and their related risks, the entity's standards of conduct, the role of the service organiza...") Tag: Visual edit
  • 19:01, 15 August 2026 Neil thibodaux talk contribs created page 5.04 (Created page with "'''Control Environment''' '''Principle 5 - Enforce Accountability''' '''Attribute 5.04''' - If management establishes incentives, management recognizes that such actions can yield unintended consequences and evaluates incentives so that they align with the entity's standards of conduct.") Tag: Visual edit
  • 18:59, 15 August 2026 Neil thibodaux talk contribs created page 5.03 (Created page with "'''Control Environment''' '''Principle 5 - Enforce Accountability''' '''Attribute 5.03''' - Management holds personnel accountable for performing their assigned internal control responsibilities. The oversight body, in turn, holds both management and the entire organization accountable for its internal control responsibilities.") Tag: Visual edit
  • 18:57, 15 August 2026 Neil thibodaux talk contribs created page 5.02 (Created page with "'''Control Environment''' '''Principle 5 - Enforce Accountability''' '''Attribute 5.02''' - Management enforces accountability of individuals performing their internal control responsibilities. Accountability is driven by the tone at the top and supported by commitment to integrity and ethical values, organizational structure, and expectations of competence, which influence the control culture of the entity. Accountability for performance of internal control responsibi...") Tag: Visual edit
  • 18:54, 15 August 2026 Neil thibodaux talk contribs created page 5.01 (Created page with "'''Control Environment''' '''Principle 4 - Demonstrate Commitment to Competence''' '''Attribute 5.01''' - Management should evaluate performance and hold individuals accountable for their internal control responsibilities. '''Green Book Attribute Categories:''' The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Enforcement of Accountability * Consideration of Excessive Pressures") Tag: Visual edit
  • 18:51, 15 August 2026 Neil thibodaux talk contribs created page 4.08 (Created page with "'''Control Environment''' '''Principle 4 - Demonstrate Commitment to Competence''' '''Attribute 4,08''' - Management defines contingency plans for assigning responsibilities if a key role in the entity is vacated without advance notice. The importance of the key role in the internal control system and the impact to the entity of its vacancy dictates the formality and depth of the contingency plan.") Tag: Visual edit
  • 18:49, 15 August 2026 Neil thibodaux talk contribs created page 4.07 (Created page with "'''Control Environment''' '''Principle 4 - Demonstrate Commitment to Competence''' '''Attribute 4.07''' - Management defines succession plans for key roles, chooses succession candidates, and trains succession candidates to assume the key roles. If management relies on a service organization to fulfill the assigned responsibilities of key roles in the entity, management assesses whether the service organization can continue in these key roles, identifies other candidat...") Tag: Visual edit
  • 18:46, 15 August 2026 Neil thibodaux talk contribs created page 4.06 (Created page with "'''Control Environment''' '''Principle 4 - Demonstrate Commitment to Competence''' '''Attribute 4.06''' - Management defines succession and contingency plans for key roles to help the entity continue achieving its objectives. Succession plans address the entity's need to replace competent personnel over the long term, whereas contingency plans address the entity's need to respond to sudden personnel changes that could compromise the internal control system.") Tag: Visual edit
  • 18:44, 15 August 2026 Neil thibodaux talk contribs created page 4.05 (Created page with "'''Control Environment''' '''Principle 4 - Demonstrate Commitment to Competence''' '''Attribute 4.05''' - Management recruits, develops, and retains competent personnel to achieve the entity's objectives. Management considers the following: * '''Recruit''' - Conduct procedures to determine whether a particular candidate fits the organizational needs and has the competence for the proposed role. * '''Train''' - Enable individuals to develop competencies appropriate for...") Tag: Visual edit
  • 18:41, 15 August 2026 Neil thibodaux talk contribs created page 4.04 (Created page with "'''Control Environment''' '''Principle 4 - Demonstrate Commitment to Competence''' '''Attribute 4.04''' - Personnel need to possess and maintain a level of competence that allows them to accomplish their assigned responsibilities, as well as understand the importance of effective internal control. Holding personnel accountable to established policies by evaluating their competence is integral to attracting, developing, and retaining individuals. Management evaluates co...") Tag: Visual edit
  • 18:38, 15 August 2026 Neil thibodaux talk contribs created page 4.03 (Created page with "'''Control Environment''' '''Principle 4 - Demonstrate Commitment to Competence''' '''Attribute 4.03''' - Management considers standards of conduct, assigned responsibility, and delegated authority when establishing expectations. Management establishes expectations of competence for key roles. Management may also establish expectations of competence for all personnel through policies within the entity's internal control system.") Tag: Visual edit
  • 18:37, 15 August 2026 Neil thibodaux talk contribs created page 4.02 (Created page with "'''Control Environment''' '''Principle 4 - Demonstrate Commitment to Competence''' '''Attribute 4.02''' - Management establishes expectations of competence for key roles, and other roles at management's discretion, to help the entity achieve its objectives. Competence is the capability to carry out assigned responsibilities. It requires relevant knowledge, skills, and abilities, which are gained largely from professional experience, training, and certifications. It is...") Tag: Visual edit
  • 18:33, 15 August 2026 Neil thibodaux talk contribs created page 4.01 (Created page with "'''Control Environment''' '''Principle 4 - Demonstrate Commitment to Competence''' '''Attribute 4.01''' - Management should demonstrate a commitment to recruit, develop, and retain competent individuals. '''Green Book Attribute Categories:''' The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Expectations of Competence * Recruitment, Development, and Retention of Individuals * Succession and Contingenc...") Tag: Visual edit
(newest | oldest) View ( | ) (20 | 50 | 100 | 250 | 500)