Principle 6 - Define Objectives and Risk Tolerances

From Corrective Action Plan AZ
Revision as of 23:49, 3 August 2026 by Kelly (talk | contribs) (Auto-created by CAP AZ bot)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

6.01 Management should define objectives clearly to enable the identification of risks and define risk tolerances.

Definitions of Objectives

6.02 Management defines objectives, and related subobjectives, in specific and measurable terms to enable the design of internal control for related risks. Specific terms are fully and clearly set forth so they can be easily understood. Measurable terms allow for the assessment of performance toward achieving objectives. Objectives are initially set as part of the objective-setting process and then refined as they are incorporated into the internal control system when management uses them to establish the control environment.

6.03 Management defines objectives in specific terms, so that they are understood at all levels of the entity. This involves clearly defining what is to be achieved, who is to achieve it, how it will be achieved, and the time frames for achievement. All objectives can be broadly classified into one or more of three categories: operations, reporting, or compliance. Reporting objectives are further categorized as being either internal or external and financial or nonfinancial. Management defines objectives in alignment with the organization’s mission, strategic plan, and performance goals.

August 3, 2026: Submitted Complaint -My original PRR sought the complete sequence of contracts and amendments for the purpose of determining exactly what governed the during the 2020 and subsequent elections. The election objectives never changed. However, I sought to understand the specific way those objectives were achieved during the Covid-19 pandemic and thereafter.

As yet unresolved (unknown), the complete scope of changes implemented during the Covid-19 pandemic. Therefore, the coordination of specific objectives cannot be assessed for impact to the operations (election process) and compliance. Reporting objectives were adversely impacted given the chaotic status reported by MCBOS and MCRO.

6.04 Management defines objectives in measurable terms so that performance toward achieving those objectives can be assessed. Measurable objectives are generally free of bias and do not require subjective judgments to dominate their measurement. Measurable objectives are also stated in a quantitative or qualitative form that permits reasonably consistent measurement.

6.05 Management considers external requirements and internal expectations when defining objectives to enable the design of internal control. Legislators, regulators, and standard-setting bodies set external requirements by establishing the laws, regulations, and standards with which the entity is required to comply. Management identifies, understands, and incorporates these requirements into the entity’s objectives. Management sets internal expectations and requirements through the established standards of conduct, oversight structure, organizational structure, and expectations of competence as part of the control environment.

6.06 Management evaluates and, if necessary, revises defined objectives so that they are consistent with external requirements and internal expectations. This consistency enables management to identify and analyze risks associated with achieving the defined objectives.

6.07 Management determines whether performance measures for the defined objectives are appropriate for evaluating the entity’s performance in achieving those objectives. For quantitative objectives, performance measures may be a targeted percentage or numerical value. For qualitative objectives, management may need to design performance measures that indicate a level or degree of performance, such as milestones.

Definitions of Risk Tolerances

6.08 Management defines risk tolerances for the defined objectives. Risk objectives by ensuring that the set levels of variation for performance measures are appropriate for the design of an internal control system.

6.09 Management defines risk tolerances in specific and measurable terms so that they are clearly stated and can be measured. For example, for an objective to process all benefit applications within 10 business days of receipt, management may determine that a risk tolerance of a range of 8–12 business days would be an acceptable level of variation. Depending on the category of objectives, risk tolerances may be expressed as follows:

Operations objectives - Acceptable levels of variation in performance relative to the achievement of operations objectives.

Nonfinancial reporting objectives - Level of precision and accuracy suitable for user needs, involving both qualitative and quantitative considerations to meet the needs of the nonfinancial report user.

Financial reporting objectives - Judgments about materiality that consider surrounding circumstances, involve both qualitative and quantitative considerations, and are affected by the needs of financial report users and size or nature of a misstatement.

Compliance objectives - Acceptable levels of variation in performance relative to the achievement of compliance objectives, within the context of applicable laws, regulations, and external standards.

6.10 Management also evaluates whether risk tolerances enable the appropriate design of internal control by considering whether they are consistent with requirements and expectations for the defined objectives. As in defining objectives, management considers the risk tolerances in the context of the entity’s applicable laws, regulations, and standards as well as the entity’s standards of conduct, oversight structure, organizational structure, and expectations of competence. If risk tolerances for defined objectives are not consistent with these requirements and expectations, management revises the risk tolerances to achieve consistency.