Main public logs
From Corrective Action Plan AZ
Combined display of all available logs of Corrective Action Plan AZ. You can narrow down the view by selecting a log type, the username (case-sensitive), or the affected page (also case-sensitive).
- 12:33, 16 August 2026 Neil thibodaux talk contribs created page 17.04 (Created page with "'''Monitoring''' '''Principle 17 - Evaluate Issues and Remediate Deficiencies''' '''Attribute 17.04''' - Depending on the entity's regulatory or compliance requirements, the entity may also be required to report issues externally to appropriate external parties, such as the legislators, regulators, and standard-setting bodies that establish laws, rules, regulations, or standards to which the entity is subject.") Tag: Visual edit
- 12:32, 16 August 2026 Neil thibodaux talk contribs created page 17.03 (Created page with "'''Monitoring''' '''Principle 17 - Evaluate Issues and Remediate Deficiencies''' '''Attribute 17.03''' - Personnel may identify internal control issues while performing their assigned internal control responsibilities. Personnel communicate these issues internally to the person in the key role responsible for the internal control or associated process and, when appropriate, to at least one level of management above that individual. Depending on the nature of the issues...") Tag: Visual edit
- 12:30, 16 August 2026 Neil thibodaux talk contribs created page 17.02 (Created page with "'''Monitoring''' '''Principle 17 - Evaluate Issues and Remediate Deficiencies''' '''Attribute 17.02''' - Personnel report internal control issues through established reporting lines to the appropriate internal and external parties on a timely basis to enable the entity to promptly evaluate those issues and complete corrective action to remediate issues that rise to the level of internal control deficiencies.") Tag: Visual edit
- 12:30, 16 August 2026 Neil thibodaux talk contribs created page 17.01 (Created page with "'''Monitoring''' '''Principle 17 - Evaluate Issues and Remediate Deficiencies''' '''Attribute 17.01''' - Management should remediate identified internal control deficiencies on a timely basis. Attributes The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Reporting of Issues * Evaluation of Issues * Corrective Actions") Tag: Visual edit
- 12:24, 16 August 2026 Neil thibodaux talk contribs created page 16.10 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.10''' - Management identifies changes in the internal control system that either have occurred or are needed because of changes in the entity and its environment. External parties can also help management identify issues in the internal control system. For example, complaints from the public, regulator comments, and findings from investigations may indicate areas in the internal control...") Tag: Visual edit
- 12:22, 16 August 2026 Neil thibodaux talk contribs created page 16.09 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.09''' - Management evaluates and documents the results of ongoing monitoring and separate evaluations to identify internal control issues ['''documentation requirement'''].<sup>114</sup> Management uses this evaluation to determine the effectiveness of the internal control system. Differences between the results of monitoring activities and the previously established baseline may indica...") Tag: Visual edit
- 12:20, 16 August 2026 Neil thibodaux talk contribs created page 16.08 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.08''' - Management retains responsibility for monitoring the effectiveness of controls performed by service organizations that are necessary for the entity to achieve its control objectives. Management uses ongoing monitoring, separate evaluations, or a combination of the two to obtain reasonable assurance of the operating effectiveness of a service organization's internal controls over...") Tag: Visual edit
- 12:19, 16 August 2026 Neil thibodaux talk contribs created page 16.07 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.07''' - Management also uses the results of separate evaluations performed in connection with internal and external audits, investigations, and other evaluations that may involve the review of internal control design and testing of internal controls to help identify issues in the internal control system. These audits and other evaluations may be mandated by law and are performed by inte...") Tag: Visual edit
- 12:18, 16 August 2026 Neil thibodaux talk contribs created page 16.06 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.06''' - Management uses separate evaluations to monitor the design and operating effectiveness of the overall internal control system at a specific time or of a specific function or process. The scope and frequency of separate evaluations depend primarily on the assessment of risks, risk responses, evolving technology, identification of new risks or deficiencies, results of ongoing moni...") Tag: Visual edit
- 12:17, 16 August 2026 Neil thibodaux talk contribs created page 16.05 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.05''' - Management performs ongoing monitoring of the design and operating effectiveness of the internal control system as part of the normal course of operations. Ongoing monitoring includes regular management and supervisory activities, comparisons, reconciliations, trend analysis, data analytics, activities to identify improper payments or potential fraud, testing, and other routine...") Tag: Visual edit
- 12:16, 16 August 2026 Neil thibodaux talk contribs created page 16.04 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.04''' - Management monitors the internal control system through ongoing monitoring and separate evaluations. Ongoing monitoring is built into the entity's operations, performed continually, and responsive to change. Separate evaluations are performed periodically and may provide feedback on the effectiveness of ongoing monitoring. Many of the methods and tools described below may be use...") Tag: Visual edit
- 12:14, 16 August 2026 Neil thibodaux talk contribs created page 16.03 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.03''' - Once established, management can use the baseline as criteria in evaluating the internal control system and make changes to reduce the difference between the criteria and condition. Management reduces this difference in one of two ways. Management either changes the design of the internal control system to better address the objectives and risks of the entity or improves the ope...") Tag: Visual edit
- 12:14, 16 August 2026 Neil thibodaux talk contribs created page 16.02 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.02''' - Monitoring activities evaluate whether each of the five components of internal control, including controls to effect the principles within each component, is present and functioning or if change is needed. Management establishes a baseline to monitor the internal control system. The baseline is the current state of the internal control system compared against management's design...") Tag: Visual edit
- 12:13, 16 August 2026 Neil thibodaux talk contribs created page 16.01 (Created page with "'''Monitoring''' '''Principle 16 - Perform Monitoring Activities''' '''Attribute 16.01''' - Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. <u>Attribute Categories</u> The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Establishment of a Baseline * Internal Control System Monitoring * Evaluation of Results") Tag: Visual edit
- 12:03, 16 August 2026 Neil thibodaux talk contribs created page 15.09 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.09''' - Government entities not only report to the head of the government, legislators, and regulators but to the public as well. In the federal government, entities not only report to the President and Congress but also to the public. Entities consider appropriate methods for communicating with such a broad audience.") Tag: Visual edit
- 12:00, 16 August 2026 Neil thibodaux talk contribs created page 15.08 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.08''' - Based on consideration of the factors, management selects appropriate methods of communication. Management evaluates the entity's methods of communication on a periodic and ongoing basis so that the organization has the appropriate tools to communicate quality information throughout and outside of the entity on a timely basis.") Tag: Visual edit
- 11:59, 16 August 2026 Neil thibodaux talk contribs created page 15.07 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.07''' - Management selects appropriate methods for communicating externally. Management considers a variety of factors in selecting an appropriate method of communication. Some factors to consider follow: * '''Audience''' - The intended recipients of the communication. * '''Nature of information''' - The purpose and type of information being communicated. * '''Availability'...") Tag: Visual edit
- 11:58, 16 August 2026 Neil thibodaux talk contribs created page 15.06 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.06''' - External parties use separate reporting lines when external reporting lines are compromised. Laws and regulations may require entities to establish separate lines of communication, such as whistleblower and ethics hotlines, for communicating confidential information. Management informs external parties of these separate reporting lines, how they operate, how they are...") Tag: Visual edit
- 11:57, 16 August 2026 Neil thibodaux talk contribs created page 15.05 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.05''' - The oversight body obtains information through reporting lines from external parties. Information communicated to the oversight body includes significant matters relating to risks, changes, and issues that impact the entity's internal control system. This communication is necessary for the effective oversight of internal control.") Tag: Visual edit
- 11:55, 16 August 2026 Neil thibodaux talk contribs created page 15.04 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.04''' - Management obtains information through reporting lines from external parties. Information communicated to management includes significant matters relating to risks, changes, or issues that impact the entity's internal control system. Communication may also include information for the entity to achieve program-related objectives. These communications are necessary for...") Tag: Visual edit
- 11:54, 16 August 2026 Neil thibodaux talk contribs created page 15.03 (Created page with "'''Information and Communication''' '''Principle 15 - Communicate Externally''' '''Attribute 15.03''' - Management communicates relevant and quality information externally through reporting lines so that appropriate external parties can help the entity achieve its objectives, address related risks, and support its internal control system. Information communicated by management includes significant matters relating to the entity's events and activities that impact its i...") Tag: Visual edit
- 11:51, 16 August 2026 Neil thibodaux talk contribs created page 15.02 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.02''' - Management communicates with, and obtains relevant and quality information from, appropriate external parties using established reporting lines. Open two-way external reporting lines allow for this communication. External parties may include service organizations, suppliers, contractors, regulators, regulated entities, external auditors, federal entities, state and l...") Tag: Visual edit
- 11:41, 16 August 2026 Neil thibodaux talk contribs created page 14.08 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.08''' - Based on consideration of the factors, management selects appropriate methods of communication. Management evaluates the entity's methods of communication on a periodic and ongoing basis so that the organization has the appropriate tools to communicate quality information throughout the entity on a timely basis.") Tag: Visual edit
- 11:40, 16 August 2026 Neil thibodaux talk contribs created page 14.07 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.07''' - Management selects appropriate methods for communicating internally. Management considers a variety of factors in selecting an appropriate method of communication. Some factors to consider follow: * '''Audience''' - The intended recipients of the communication. * '''Nature of information''' - The purpose and type of information being communicated. * '''Availability'...") Tag: Visual edit
- 11:38, 16 August 2026 Neil thibodaux talk contribs created page 14.06 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.06''' - Personnel use separate reporting lines to go around upward reporting lines when these lines are compromised. Laws and regulations may require entities to establish separate lines of communication, such as whistleblower and ethics hotlines, for communicating confidential information. Management informs employees of these separate reporting lines, how they operate, how...") Tag: Visual edit
- 11:37, 16 August 2026 Neil thibodaux talk contribs created page 14.05 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.05''' - The oversight body obtains relevant and quality information that flows up the reporting lines from management and other personnel. Information relating to internal control communicated to the oversight body includes significant matters about adherence to, changes in, or issues arising from the internal control system. This upward communication is necessary for the ef...") Tag: Visual edit
- 11:37, 16 August 2026 Neil thibodaux talk contribs created page 14.04 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.04''' - Management obtains relevant and quality information about the entity's business processes that flows up the reporting lines from personnel to help management achieve the entity's objectives. Information communicated by personnel may include internal control issues; this communication helps management identify internal control deficiencies and take corrective action.") Tag: Visual edit
- 11:36, 16 August 2026 Neil thibodaux talk contribs created page 14.03 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.03''' - Management communicates relevant and quality information down and across reporting lines to enable personnel to understand and perform key roles in achieving objectives, addressing risks, and supporting the internal control system. In these communications, management assigns the internal control responsibilities for key roles. Communications support the functioning o...") Tag: Visual edit
- 11:34, 16 August 2026 Neil thibodaux talk contribs created page 14.02 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.02''' - Management communicates relevant and quality information throughout the entity using established reporting lines. Communication is the continual, iterative process of providing, sharing, and obtaining necessary information. Quality information is communicated down, across, up, and around reporting lines to all levels of the entity.") Tag: Visual edit
- 11:33, 16 August 2026 Neil thibodaux talk contribs created page 14.01 (Created page with "'''Information and Communication''' '''Principle 14 - Communicate Internally''' '''Attribute 14.01''' - Management should internally communicate relevant and quality information, including objectives and responsibilities for internal control, necessary to support the functioning of the internal control system. <u>Attribute Categories</u> The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Communication...") Tag: Visual edit
- 11:26, 16 August 2026 Neil thibodaux talk contribs created page 13.07 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.07''' - Management evaluates the processed information to determine whether it is quality information. Quality information meets the identified information requirements when relevant data from reliable sources are used. Quality information is appropriate, current, complete, accurate, accessible, verifiable, retained as appropriate, and provided on a timely basis. Management...") Tag: Visual edit
- 11:25, 16 August 2026 Neil thibodaux talk contribs created page 13.06 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.06''' - Management develops the entity's information system to obtain, generate, and process relevant data into quality information to meet the identified information requirements needed to support the internal control system. Information processing can be manual, automated through the use of information technology, or a combination of both.") Tag: Visual edit
- 11:24, 16 August 2026 Neil thibodaux talk contribs created page 13.05 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.05''' - Management processes relevant data obtained or generated from reliable sources into quality information through the entity's information system. The entity's information system comprises the people, processes, data, and information technology that management uses to obtain, generate, communicate, or dispose of information to support the entity's business processes.") Tag: Visual edit
- 11:22, 16 August 2026 Neil thibodaux talk contribs created page 13.04 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.04''' - Management obtains or generates relevant data from reliable internal and external sources in a timely manner based on the identified information requirements. Relevant data have a logical connection with, or bearing upon, the identified information requirements. Reliable internal and external sources provide data that are reasonably free from error and bias and fait...") Tag: Visual edit
- 11:20, 16 August 2026 Neil thibodaux talk contribs created page 13.03 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.03''' - Management identifies information requirements in an iterative and ongoing process that occurs throughout the design, implementation, and operation of an effective internal control system. An entity's controls within the five components of internal control establish information requirements. As change in the entity and its objectives and risks occurs, management cha...") Tag: Visual edit
- 11:19, 16 August 2026 Neil thibodaux talk contribs created page 13.02 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.02''' - Management designs a process that uses the entity's objectives and related risks to identify the information requirements needed to support the internal control system. Information requirements consider the needs of both internal and external users. Management defines the identified information requirements at the relevant level and requisite specificity for appropr...") Tag: Visual edit
- 11:17, 16 August 2026 Neil thibodaux talk contribs created page 13.01 (Created page with "'''Information and Communication''' '''Principle 13 - Use Quality Information''' '''Attribute 13.01''' - Management should obtain or generate relevant, quality information and use it to support the functioning of the internal control system. <u>Attributes</u> The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Identification of Information Requirements * Relevant Data from Reliable Sources * Data Proces...") Tag: Visual edit
- 11:12, 16 August 2026 Neil thibodaux talk contribs created page 12.05 (Created page with "'''Control Activities''' '''Principle 12 - Implement Control Activities''' '''Attribute 12.05''' - Management reviews policies, procedures, and related control activities on a periodic and ongoing basis for continued relevance and effectiveness in achieving the entity's objectives or mitigating related risks. If there is a significant change in an entity's process, management reviews this process in a timely manner after the change to determine that the control activit...") Tag: Visual edit
- 11:10, 16 August 2026 Neil thibodaux talk contribs created page 12.04 (Created page with "'''Control Activities''' '''Principle 12 - Implement Control Activities''' '''Attribute 12.04''' - Those in key roles for the unit may further define policies through day-to-day procedures, depending on the rate of change in the operating environment and complexity of the business process. Procedures may include the timing of when a control activity occurs and any follow-up corrective actions to be performed by competent personnel if deficiencies are identified. Manage...") Tag: Visual edit
- 11:09, 16 August 2026 Neil thibodaux talk contribs created page 12.03 (Created page with "'''Control Activities''' '''Principle 12 - Implement Control Activities''' '''Attribute 12.03''' - Management documents in policies and procedures for each unit within the entity's organizational structure its responsibility for a business process's objectives and related risks and control activity design, implementation, and operating effectiveness. Each unit, with guidance from management, determines the policies necessary to operate the business process based on the...") Tag: Visual edit
- 11:07, 16 August 2026 Neil thibodaux talk contribs created page 12.02 (Created page with "'''Control Activities''' '''Principle 12 - Implement Control Activities''' '''Attribute 12.02''' - Management establishes control activities by documenting in policies what is expected and in procedures specified actions that implement policies, to mitigate risks to achieving the entity's objectives to acceptable levels ['''documentation requirement''']. Note: The GAO emphasized "'''documentation requirements."'''") Tag: Visual edit
- 11:04, 16 August 2026 Neil thibodaux talk contribs created page 12.01 (Created page with "'''Control Activities''' '''Principle 12 - Implement Control Activities''' '''Attribute 12.01''' - Management should implement control activities through policies and procedures. <u>Attributes</u> The following attributes contribute to the design, implementation, and operating effectiveness of this principle: * Documentation of Control Activities Through Policies and Procedures * Periodic Review of Control Activities") Tag: Visual edit
- 01:50, 16 August 2026 Neil thibodaux talk contribs created page 11.17 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.17''' - Contingency planning protects critical and sensitive data against loss and allows for critical operations to continue without disruption or be promptly resumed when unexpected events occur. Maintaining technology through contingency planning often includes backup and recovery procedures, as well as continuity of operations plans, depending...") Tag: Visual edit
- 01:49, 16 August 2026 Neil thibodaux talk contribs created page 11.16 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.16''' - Segregation of duties control activities help prevent fraud, waste, and abuse from being executed using information technology in the internal control system and mitigate the risk of management override of automated processes. Management considers the need to separate responsibilities for control activities related to the entity's informat...") Tag: Visual edit
- 01:48, 16 August 2026 Neil thibodaux talk contribs created page 11.15 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.15''' - Control activities for changing information technology prevent unauthorized or untested modifications to existing systems. To reasonably assure that changes to the configuration of information technology are necessary, work as intended, and do not cause loss of data or program integrity, changes go through a formal change management proces...") Tag: Visual edit
- 01:46, 16 August 2026 Neil thibodaux talk contribs created page 11.14 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.14''' - Control activities for maintaining information technology include identifying vulnerabilities to patch and other functional updates to be made. Management continuously monitors the entity's information technology to establish a baseline for evaluating performance, detecting underlying deficiencies before they negatively impact users, colle...") Tag: Visual edit
- 01:45, 16 August 2026 Neil thibodaux talk contribs created page 11.13 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.13''' - Control activities for developing information technology, commonly referred to as systems development controls, prevent the use of unauthorized or untested systems. Management may internally develop information technology, acquire it from suppliers, or outsource its development to service organizations. Management incorporates methodologie...") Tag: Visual edit
- 01:44, 16 August 2026 Neil thibodaux talk contribs created page 11.12 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.12''' - Configuration management control activities involve the identification and management of operating and security features for information technology (i.e., infrastructure, platforms, and software) throughout the technology development process. Management may use a technology development methodology to provide a structure for a new informati...") Tag: Visual edit
- 01:44, 16 August 2026 Neil thibodaux talk contribs created page 11.11 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.11''' - Logical and physical access control activities include restricting access or detecting inappropriate access to information and information technology. They protect information technology resources against unauthorized access, use, disclosure, disruption, modification, or destruction, whether from malicious intent or error. Logical access c...") Tag: Visual edit
- 01:42, 16 August 2026 Neil thibodaux talk contribs created page 11.10 (Created page with "'''Control Activities''' '''Principle 11 - Design General Control Activities over Information Technology''' '''Attribute 11.10''' - Security management is the ongoing process for mitigating information security risks as part of the entity's overall internal control system (sometimes referred to as a security management program). This ongoing process covers all components of internal control related to information security risks.") Tag: Visual edit
