Main public logs
From Corrective Action Plan AZ
Combined display of all available logs of Corrective Action Plan AZ. You can narrow down the view by selecting a log type, the username (case-sensitive), or the affected page (also case-sensitive).
- 01:18, 16 August 2026 Neil thibodaux talk contribs created page 10.22 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.22''' - Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity's business processes. Segregation of duties can mitigate the risk of management override. Management ove...") Tag: Visual edit
- 01:16, 16 August 2026 Neil thibodaux talk contribs created page 10.21 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.21''' - Management considers segregation of duties in designing control activities so that incompatible duties are segregated. Where such segregation is not practical, management designs alternative control activities to mitigate the risk.") Tag: Visual edit
- 01:15, 16 August 2026 Neil thibodaux talk contribs created page 10.20 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.20''' - When designing entity-level and transaction control activities, management evaluates the level of precision needed for the business processes to meet the entity's objectives and mitigate related risks. The precision of a control activity refers to how exact the control activity will be in preventing or detecting an unintended event or result. Control activity precision is cl...") Tag: Visual edit
- 01:14, 16 August 2026 Neil thibodaux talk contribs created page 10.19 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.19''' - While the information processing objectives are most often associated with financial processes and transactions, information processing objectives can be applied to any activity in an organization. For example, information processing objectives and related control activities can be applied to management's decision-making processes that use nonfinancial data.") Tag: Visual edit
- 01:13, 16 August 2026 Neil thibodaux talk contribs created page 10.18 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.18''' - When designing transaction control activities, management evaluates information processing objectives to meet the entity's objectives and mitigate related risks.<sup>89</sup> Information processing objectives may include the following: * '''Completeness''' - All transactions and events that occur have been properly recorded. * '''Accuracy''' - Data relating to transactions...") Tag: Visual edit
- 01:11, 16 August 2026 Neil thibodaux talk contribs created page 10.17 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.17''' - Transaction control activities are controls that directly mitigate information processing risks in the entity's business processes. The term transaction tends to be associated with business processes addressing reporting objectives (e.g., financial transactions), while the term activity is more often associated with business processes addressing operations or compliance obje...") Tag: Visual edit
- 01:09, 16 August 2026 Neil thibodaux talk contribs created page 10.16 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.16''' - Entity-level control activities are controls designed to mitigate risks that have a pervasive effect on an entity's internal control system and may pertain to multiple components. Entity-level control activities may include controls related to the entity's risk assessment process, control environment, service organizations, management override, and performance or analytical...") Tag: Visual edit
- 01:06, 16 August 2026 Neil thibodaux talk contribs created page 10.15 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.15''' -") Tag: Visual edit
- 01:06, 16 August 2026 Neil thibodaux talk contribs created page 10.14 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.14''' - Management designs control activities at the appropriate levels in the organizational structure.") Tag: Visual edit
- 01:05, 16 August 2026 Neil thibodaux talk contribs created page 10.13 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.13''' - There may be rare situations where management determines through its evaluation that a preventive control activity would better mitigate a particular risk but is unable to implement it. In these situations, management strengthens and expedites detective control activities and may also expedite monitoring activities to enable the entity to effectively mitigate the risk to acc...") Tag: Visual edit
- 01:04, 16 August 2026 Neil thibodaux talk contribs created page 10.12 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.12''' - Management designs an appropriate mix of preventive and detective control activities to mitigate risks to an acceptable level, prioritizing preventive control activities where appropriate. When designing control activities, management first considers preventive control activities, as they generally offer the most cost-efficient use of resources and are generally effective at...") Tag: Visual edit
- 01:03, 16 August 2026 Neil thibodaux talk contribs created page 10.11 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute 10.11''' - Management evaluates the purpose of the control activity as well as the likelihood of an unintended event or result occurring and the magnitude of impact it would have on the entity in achieving its objectives. Management may design both preventive and detective control activities to effectively mitigate the risks to achieving the objectives, particularly in circumstances wh...") Tag: Visual edit
- 01:01, 16 August 2026 Neil thibodaux talk contribs created page 10.10 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute''' '''10.10''' - Control activities can be either preventive or detective. The main difference between preventive and detective control activities is timing, that is, when the control activity occurs within an entity's operations. A preventive control activity is designed to avoid an unintended event or result before it occurs. A detective control activity is designed to discover and t...") Tag: Visual edit
- 00:59, 16 August 2026 Neil thibodaux talk contribs created page 10.09 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute''' '''10.09''' - Common categories of information technology control activities and how they align with information processing and information security objectives are illustrated in figure 7.<sup>84</sup> The common categories of information technology control activities listed in figure 7 are meant only to illustrate the range and variety of control activities that may be useful to ma...") Tag: Visual edit
- 00:58, 16 August 2026 Neil thibodaux talk contribs created page 10.08 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute''' '''10.08''' - General control activities are designed to mitigate information security risks and are the actions established through policies and procedures that apply to all or a large segment of an entity's information technology. General control activities support the proper operation of the entity's information technology by creating a suitable environment for effective operatio...") Tag: Visual edit
- 00:57, 16 August 2026 Neil thibodaux talk contribs created page 10.07 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute''' '''10.07''' - Application and user control activities rely on the entity's information technology. Application control activities are automated control activities that are incorporated directly into application software to achieve the completeness, accuracy, and validity of transactions and data. Application control activities include control activities over the input, processing, a...") Tag: Visual edit
- 00:55, 16 August 2026 Neil thibodaux talk contribs created page 10.06 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute''' '''10.06''' - Management designs information technology control activities to support the operation and security of the entity's information technology and automated business processes. Information technology control activities consist of general, application, and user control activities.") Tag: Visual edit
- 00:54, 16 August 2026 Neil thibodaux talk contribs created page 10.05 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute''' '''10.05''' - Control activities can be designed and implemented in an automated, partially automated, or a manual manner. Automated control activities may be wholly or partially performed using the entity's information technology. Manual control activities are performed by individuals without relying on the entity's information technology. Automated control activities tend to be mo...") Tag: Visual edit
- 00:53, 16 August 2026 Neil thibodaux talk contribs created page 10.04 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute''' '''10.04''' - The common categories of control activities listed in table 1 illustrate the range and variety of control activities that may be useful to management. The list is not all inclusive and may not include all categories of control activities that an entity may need. <u>Common Categories of Control Activities</u> * Top-level reviews of actual performance * Reviews by mana...") Tag: Visual edit
- 00:50, 16 August 2026 Neil thibodaux talk contribs created page 10.03 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute''' '''10.03''' - Management designs appropriate types of control activities for the entity's internal control system, including the entity's information technology, by considering all aspects of its internal control components, relevant business processes, and operating environment. An entity's internal control is flexible to allow management to tailor control activities to meet the en...") Tag: Visual edit
- 00:49, 16 August 2026 Neil thibodaux talk contribs created page 10.02 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute''' '''10.02''' - Management designs control activities in response to risks to achieve an effective internal control system. Control activities are the actions management establishes through policies and procedures to specifically mitigate risks to achieving the entity's objectives to acceptable levels. Control activities support all the components of internal control but are particula...") Tag: Visual edit
- 00:48, 16 August 2026 Neil thibodaux talk contribs created page 10.01 (Created page with "'''Control Activities''' '''Principle 10 - Design Control Activities''' '''Attribute''' '''10.01''' - Management should design control activities to mitigate risks to achieving the entity's objectives to acceptable levels. <u>Attributes</u> The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Response to Risks * Design of Appropriate Types of Control Activities * Design of Automated and Manual Control...") Tag: Visual edit
- 00:32, 16 August 2026 Neil thibodaux talk contribs created page 9.13 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.13''' - Further, changing conditions often prompt new risks or changes to existing risks that need to be assessed. As part of analyzing and responding to significant change, management performs a risk assessment to identify, analyze, and respond to any new risks prompted by the changes. Additionally, existing risk assessments may need to be updated to determine whet...") Tag: Visual edit
- 00:31, 16 August 2026 Neil thibodaux talk contribs created page 9.12 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.12''' - Management also performs ongoing risk assessments as the entity responds to changing conditions to analyze and respond to risks on a real-time basis.") Tag: Visual edit
- 00:30, 16 August 2026 Neil thibodaux talk contribs created page 9.11 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.11''' - Changes in conditions affecting the entity and its environment often require changes to the entity's internal control system, as existing controls may not be effective for meeting objectives or addressing risks under changed conditions. Once significant changes are identified, management uses its change assessment process to identify and analyze the impact of...") Tag: Visual edit
- 00:29, 16 August 2026 Neil thibodaux talk contribs created page 9.10 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.10''' - Management's change assessment process includes considerations to facilitate its ability to quickly adapt the entity's internal control system and effectively respond to a significant change once it occurs, such as the following: * modifying the organizational structure, responsibilities, and authorities to address identified risks; * determining whether to...") Tag: Visual edit
- 00:28, 16 August 2026 Neil thibodaux talk contribs created page 9.09 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.09''' - Management's change assessment process includes considerations for management to effectively analyze risk related to significant change, which may include the following: * how to determine the appropriate scope and extent of initial risk assessment related to a significant change—management considers entity objectives, risk tolerances, and other factors wh...") Tag: Visual edit
- 00:27, 16 August 2026 Neil thibodaux talk contribs created page 9.08 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.08''' - Management's change assessment process includes steps for timely identifying risks related to significant change, which may include the following: * the need to provide complex or different services quickly, which may result in increased risks overall, including those related to fraud, improper payments, information security, and noncompliance with applicabl...") Tag: Visual edit
- 00:26, 16 August 2026 Neil thibodaux talk contribs created page 9.07 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.07''' - Management develops and documents a change assessment process based on the risk assessment process described in principle 7. The process includes procedures for identifying, analyzing, and responding to risks related to significant changes.") Tag: Visual edit
- 00:24, 16 August 2026 Neil thibodaux talk contribs created page 9.06 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.06''' - As significant changes that an entity may need to respond to can occur quickly and unexpectedly, establishing a change assessment process in advance of significant changes occurring is essential to maintaining an effective internal control system as change occurs. This is especially important in situations where management may need to rapidly implement a new...") Tag: Visual edit
- 00:23, 16 August 2026 Neil thibodaux talk contribs created page 9.05 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9,05''' - Management documents a change assessment process for identifying, analyzing, and responding to risks related to significant changes so that the internal control system can be quickly adapted as needed to respond to significant changes as they occur ['''documentation requirement''']. Emphasis was placed on '''Documentation Requirement''' by the GAO.") Tag: Visual edit
- 00:21, 16 August 2026 Neil thibodaux talk contribs created page 9.04 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.04''' - Changes in internal conditions may include changes to the entity's programs or activities, oversight structure, organizational structure, personnel, and technology. Changes in external conditions may include changes in the governmental, economic, technological, legal, regulatory, and physical environments. Changes in external conditions may also include econo...") Tag: Visual edit
- 00:20, 16 August 2026 Neil thibodaux talk contribs created page 9.03 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.03''' - Conditions affecting the entity and its environment continually change. Management identifies, on a timely basis, significant changes to internal and external conditions that have already occurred or are expected to occur. Management anticipates and plans for significant changes that are expected to occur by using a forward-looking process to identify expecte...") Tag: Visual edit
- 00:19, 16 August 2026 Neil thibodaux talk contribs created page 9.02 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.02''' - As part of periodic and ongoing risk assessments, management identifies, on a timely basis, significant internal and external changes that could impact the entity's internal control system. Identifying, analyzing, and responding to significant changes is similar to, if not part of, the entity's periodic and ongoing risk assessment process. However, change is...") Tag: Visual edit
- 00:17, 16 August 2026 Neil thibodaux talk contribs created page 9.01 (Created page with "'''Risk Assessment''' '''Principle 9 - Identify, Analyze, and Respond to Change''' '''Attribute''' '''9.01''' - Management should identify, analyze, and respond to significant changes that could impact the internal control system. '''Green Book Attribute Categories for Principle 9''' The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Identify Significant Changes * Establish a Change Assessment Process...") Tag: Visual edit
- 22:29, 15 August 2026 Neil thibodaux talk contribs created page 8.20 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.20''' - Management may develop separate processes within the periodic and ongoing risk assessment process with separate oversight responsibilities, to manage risks related to fraud, improper payments, or information security as part of the entity's overall internal control system. These separate processes would cover all components of internal co...") Tag: Visual edit
- 22:28, 15 August 2026 Neil thibodaux talk contribs created page 8.19 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.19''' - Management responds to fraud, improper payment, and information security risks consistent with the risk response process performed for all analyzed risks. Based on the selected risk response, management determines the specific actions to effectively mitigate each risk. It may be possible to reduce or avoid certain fraud, improper payment,...") Tag: Visual edit
- 22:27, 15 August 2026 Neil thibodaux talk contribs created page 8.18 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.18''' - Management analyzes and responds to identified fraud, improper payment, and information security risks so that they are effectively mitigated. These risks are analyzed through the same risk analysis process performed for all identified risks. Management analyzes the identified risks by estimating their significance to assess their impact...") Tag: Visual edit
- 22:26, 15 August 2026 Neil thibodaux talk contribs created page 8.17 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.17''' - Management considers information security risk factors, which may include the following: * the complexity of the entity's information technology; * new or emerging technologies; * information technology that may be outdated or incompatible with new technologies; * decentralized operating systems and communications networks; * external-pa...") Tag: Visual edit
- 22:25, 15 August 2026 Neil thibodaux talk contribs created page 8.16 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.16''' - External risks may come from external parties that connect with or operate the entity's information technology or from unrelated attackers. External parties that connect with the entity's operating systems and databases in the normal course of operations may include end users, such as program beneficiaries; federal, state, and local gover...") Tag: Visual edit
- 22:23, 15 August 2026 Neil thibodaux talk contribs created page 8.15 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.15''' - Internal risks include unintentional acts by employees, whose vigilance is a key defense against external threats and user error. Internal threats may also come from intentional malicious acts by former or disgruntled employees. They pose unique risks because these individuals may be both motivated to work against the entity and better eq...") Tag: Visual edit
- 22:22, 15 August 2026 Neil thibodaux talk contribs created page 8.14 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.14''' - Management considers the types of risks that could impact the entity's information and information technology to provide a basis for identifying and analyzing risks related to information security.<sup>62</sup> Information security risk is the risk to entity operations, assets, and personnel, as well as external parties, due to unauthoriz...") Tag: Visual edit
- 22:20, 15 August 2026 Neil thibodaux talk contribs created page 8.13 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.13''' - Management considers existing improper payment estimates, if available, when determining the significance of risks and the effectiveness of the internal control system in responding to improper payment risks. These estimates may come from management's annual improper payment estimates as part of its monitoring activities, which may be man...") Tag: Visual edit
- 22:19, 15 August 2026 Neil thibodaux talk contribs created page 8.12 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.12''' - Management considers improper payment risk factors, both internal and external, which may include the following: * whether the program or activity is new to the entity; * the complexity of the program or activity; * the volume of payments made through the program or activity; * whether the payments or payment eligibility decisions are ma...") Tag: Visual edit
- 22:17, 15 August 2026 Neil thibodaux talk contribs created page 8.11 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.11''' - Management considers the types of improper payments that could impact the entity to provide a basis for identifying and analyzing improper payment risks. Improper payments are any payments that should not have been made or that were made in an incorrect amount. Payments are also considered improper when there is insufficient or lack of do...") Tag: Visual edit
- 22:16, 15 August 2026 Neil thibodaux talk contribs created page 8.10 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.10''' - Management considers fraud risk factors. Fraud risk factors do not necessarily indicate that fraud exists but are often present when fraud occurs. Fraud risk factors may include the following: * '''Incentive/pressure''' - Management, other personnel, or external parties have an incentive or are under pressure, which provides a motive to...") Tag: Visual edit
- 22:14, 15 August 2026 Neil thibodaux talk contribs created page 8.09 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.09''' - In addition to fraud, management also considers the risk of management override of controls. Management override of controls does not necessarily involve fraud but may indicate potential fraud and increases fraud risk.") Tag: Visual edit
- 22:13, 15 August 2026 Neil thibodaux talk contribs created page 8.08 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.08''' - In addition to fraud, management considers other forms of misconduct that can occur, such as waste and abuse. Waste is the act of using or expending resources carelessly, extravagantly, or to no purpose. Abuse involves behavior that is deficient or improper when compared with behavior that a prudent person would consider reasonable and ne...") Tag: Visual edit
- 22:12, 15 August 2026 Neil thibodaux talk contribs created page 8.07 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.07''' - As part of a risk assessment, management considers the risk of fraud that could impact the entity from both within the entity and from external parties. For example, external fraud risk may arise when an entity relies on service organizations' internal control systems to perform business processes for the entity. External parties that pre...") Tag: Visual edit
- 22:11, 15 August 2026 Neil thibodaux talk contribs created page 8.06 (Created page with "'''Risk Assessment''' '''Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk''' '''Attribute''' '''8.06''' - Management considers the types of fraud that could impact the entity to provide a basis for identifying and analyzing fraud. Fraud involves obtaining something of value through willful misrepresentation. Types of fraud may include the following: * '''Fraudulent reporting''' - Intentional misstatements or omissions of amounts or disclosur...") Tag: Visual edit
