Principle 17 - Evaluate Issues and Remediate Deficiencies
17.0 Evaluate Issues and Remediate Deficiencies
17.01 Management should remediate identified internal control deficiencies on a timely basis.
17.1 Reporting of Issues
17.02 Personnel report internal control issues through established reporting lines to the appropriate internal and external parties on a timely basis to enable the entity to promptly evaluate those issues and complete corrective action to remediate issues that rise to the level of internal control deficiencies.
I don’t think we can support a deviation for this because we didn’t ask for CAP documents in the original PRR. Did you ask for CAP documents? If so, who, what, when, where, how?
17.03 Personnel may identify internal control issues while performing their assigned internal control responsibilities. Personnel communicate these issues internally to the person in the key role responsible for the internal control or associated process and, when appropriate, to at least one level of management above that individual. Depending on the nature of the issues, personnel may consider reporting certain issues to the oversight body or an established hotline. Such issues may include
- issues that cut across the organizational structure or extend outside the entity to service organizations, contractors, or suppliers and issues that may not be remediated because of the interests of management, such as sensitive information regarding fraud or other illegal acts.
We have no documentation of this, but the Covid-19 Pandemic likely caused issues that cut across organizational boundaries
17.04 Depending on the entity’s regulatory or compliance requirements, the entity may also be required to report issues externally to appropriate external parties, such as the legislators, regulators, and standard-setting.
I don’t think we have a deviation here.
17.2 Evaluation of Issues
17.05 Management evaluates and documents internal control issues and determines appropriate corrective actions for internal control deficiencies, including those reported from internal and external audits and evaluations, on a timely basis [documentation requirement]. Management evaluates issues identified through monitoring activities or reported by personnel to determine whether any of the issues rise to the level of an internal control deficiency. Internal control deficiencies require further evaluation and remediation by management. An internal control deficiency can be in the design, implementation, or operating effectiveness of the internal control and its related process. Management determines from the type of internal control deficiency the appropriate corrective actions to remediate it on a timely basis.
April 15, 2025: Public Records Request – There was no objective evidence was found to confirm an Maricopa evaluated any of the election anomalies that necessitated portions of the contracts to be stricken through and amendments added. Contrary to the Green Book, there was no documentation of the evaluation of the unexpected Covid-19 pandemic conditions that necessitate contract revisions.
17.3 Corrective Actions
17.06 Management completes and documents corrective actions to remediate internal control deficiencies, including those reported from internal and external audits and evaluations, on a timely basis [documentation requirement]. Depending on the nature of the deficiency, either the oversight body or management oversees the prompt remediation of deficiencies by communicating the corrective actions to the appropriate level of the organizational structure and delegating authority for completing corrective actions to appropriate personnel. Documentation of corrective actions may include
- root cause analysis,
- planned actions,
- interim milestones,
- completion dates,
- measurable indicators of compliance and remediation to assess and validate progress throughout the remediation process, and the entity official responsible for monitoring the status of the corrective actions.
April 15, 2025: Public Records Request – It could be debated as to whether the election-related contracts were revised as Corrective Action. However, no documentation was found to suggest these changes were implemented as corrective action to a formal evaluation. Contrary to the Green Book, no documentation was found to attribute the contract changes as corrective action to a formal evaluation.
17.07 Corrective actions may include changes to controls within each of the five components of internal control, such as providing training on identified risks or modifying or adding control activities. Management also updates the entity’s periodic risk assessment based on the results of monitoring activities and may consider performing ongoing risk assessments when internal control deficiencies are identified.
[This will not make the list of Green Book deviations; it’s a permissive statement, “corrective actions may…”]
17.08 Corrective actions also include remediating audit and evaluation findings. The remediation process begins when audit or other review results are reported to management. It is completed only after action has been taken that (1) corrects identified deficiencies, (2) produces improvements, or (3) demonstrates that the findings and recommendations do not warrant management action. Management, with oversight from the oversight body, monitors the status of remediation efforts so that they are completed on a timely basis.
[I can’t see this being a deviation]
OLD STUFF
Concern: Lack of Public Access to a Citizen Complaint Process
In my search of the Maricopa County Website, I could not identify a County process to submit my questions about lessons learned from the County’s investigation of election anomalies. I think it’s odd that the County places a research burden on the citizen (me) to find the appropriate process to submit a concern.
Concern: Less than Adequate Responsiveness
Finding no process, I began to make calls, submit emails, [and make presentations to the Maricopa County Board of supervisors]. Once again the
[Note the exception, Jen]
Concern: Hot Potato Mentality
One PRR was submitted to the County, which was
Concern: Misleading Assertion of No Statutory Obligation
The June 27, 2025, the closeout comments of PRR 2025-64 appeared to disregard the A.R.S. The Maricopa County Recorder’s Office closed this PRR by stating “records had been released and asserting no statutory obligation to respond.”
Contrary to the MCRO’s claim, the following statutes appeared applicable to my original PRR.
A.R.S. § 39-121 provides that public records in the custody of any
officer shall be open to inspection.
A.R.S. § 39-121.01(D) requires a prompt, good-faith search
reasonably calculated to locate responsive records.
A.R.S. § 39-121.01(E) requires citation of legal authority if access
is denied in whole or in part.
Governance: Unresolved Issues
As a benchmark for governance concerns, we utilized the Standards for Internal Control in the Federal Government (a.k.a., the Green Book), which was published by the United States Government Accountability Office in May 2025 in accordance with the Federal Managers’ Financial Integrity Act of 1982 (FMFIA). We assume Arizona Counties are under no obligation to follow federal governance guidance. That said, the Green book states,
“The Green Book may also be adopted by federal entities outside the executive branch and by nonfederal entities, such as state, local, and quasi-governmental entities and nonprofit organizations, as a framework for an internal control system. Management of an entity determines, based on applicable laws and regulations, how to appropriately adapt the standards presented in the Green Book as a framework for the entity.”
Use of the Green Book serves as benchmark for good governance, even if there is presumed to be no County obligation to follow its guidance
Governance Concerns were identified by observation of Maricopa responses to my inquiries as well as the review of documents provided to me in response to PRR [???].
Documentation provided to Jamie Weinhauer Martin by Maricopa County consisted of the following:
Runbeck
Runbeck
Dominion
Dominion
The content of these documents was too lengthy to include in this letter. However, the documents are available as court records for Arizona Superior Court in Maricopa County, regarding Case CV 2035-063720, if additional review is desired.
Concern: Inadequate Documentation
The Green Book, Overview, Section 2 -Establishing an Effective Internal Control System explains Documentation Requirements. For some Green Book Attributes, documentation is a requirement; its not optional.
While the Green Book is a performance benchmark, Arizona Statutes are obligations that must be fulfilled. The following statutes specify documentation requirements:
A.R.S. § 39-121 provides that public records in the custody of any
officer shall be open to inspection.
A.R.S. § 39-121.01(D) requires a prompt, good-faith search
reasonably calculated to locate responsive records.
A.R.S. § 39-121.01(E) requires citation of legal authority if access
is denied in whole or in part.
Contrary to >>>>>>>>
Concern: Inconsistent Adherence to Standards of Conduct
Green Book, Principle 1 -Demonstrate Commitment to Integrity and Ethical Values, Adherence to Standards of Conduct how leaders and employees should adhere to standards of conduct. Item 1.08 states, “Management establishes processes to evaluate performance against the entity’s expected standards of conduct and address any deviations in a timely manner.”
Concern: Lack of Corrective Action Plans
The Green Book, Principle 17 - Evaluate Issues and Remediate Deficiencies, requires controls for 1) reporting of issues, 2) evaluation of issues and 3) corrective actions.
Contrary to Green Book expectations, there is no evidence to suggest Maricopa County took action to report, evaluate and correct any of the election anomalies that was reported in national news following the 2020, 2022, and 2024 elections.
Concern: Potential Financial Improprieties1
No CAP as required by contract
No documentation justifying Amendment changes
No change approval documentation
List specific issues
Issue: Missing Disaster Recovery Policy
No clear enforceable Disaster Recovery Policy in the Runbeck contract used during a 2020 pandemic election. Although we can not change that, we can ensure its properly documented and monitored going forward so that type of contract documentation failure does not happen again. Implementing formal Corrective Action Plans with ongoing monitoring would mitigate risk proactively vs. reactively.
Compliance Review and Corrective Action Framework
Purpose
The purpose of this framework is to describe the key elements of an effective citizen complaint, compliance review, and corrective action process for Arizona counties which may include state entities. It presents a practical governance framework that promotes transparency, accountability, consistency, and continuous improvement while strengthening public confidence in local/county/state government.
Rather than creating new compliance standards, this framework applies well-established compliance review principles already used throughout government and private industry to citizen-identified governance concerns. It describes the essential components of an objective compliance review process, outlines the lifecycle of an effective complaint and corrective action program, and establishes the governance principles necessary to ensure significant citizen concerns are evaluated consistently, documented objectively, and resolved through a structured process.
Our Vision
We believe Arizona has a timely opportunity to strengthen public confidence in county government by establishing a consistent, objective process for reviewing citizen-identified governance concerns. The goal is not to create more government—it is to create better government through a standardized process that ensures legitimate concerns receive a fair, documented, and objective compliance review.
Every citizen should have confidence that when a concern involving government operations, contracts, procurement, public records, elections, financial stewardship, or other governance matters is submitted in good faith, it will be evaluated using consistent standards. The outcome should not depend on which department receives the complaint, but on whether applicable laws, contracts, policies, procedures, or compliant governance standards were followed.
An effective complaint process should do more than acknowledge receipt of a concern or provide a response within a prescribed timeframe. It should determine whether a potential deviation from an established requirement exists and, when appropriate, initiate a structured compliance evaluation process to investigate the concern, identify root causes, implement corrective actions, verify their effectiveness, monitor long-term results, and formally close the matter. Regardless of whether deficiency is identified or not, the citizen should receive a clear explanation describing how that conclusion was reached.
A compliance review is not intended to prove that government is right or wrong. Its purpose is to objectively and independently determine whether government complied with its own governing requirements. When compliance is confirmed, public confidence is strengthened. When deficiencies are identified, government has an opportunity to improve before issues become litigation, audit findings, operational failures, financial loss, or recurring problems.
This Quality Management framework is not intended to replace existing complaint processes or diminish the authority of elected officials, county leadership, or individual departments. Rather, it provides a standardized compliant governance framework that promotes consistency across county government by establishing a uniform method for evaluating significant governance concerns, assigning ownership, documenting findings, implementing corrective actions when warranted, verifying results, and ensuring formal closure.
The framework presented in this document describes the essential elements of an effective Citizen Compliance Review and Corrective Action Process. It outlines the complaint lifecycle, establishes the standards against which complaints should be evaluated, defines the characteristics of an effective Corrective Action Program, and identifies the governance elements necessary to strengthen accountability, improve transparency, and build lasting public confidence in Arizona's county governments.
Definition of Standards with respect to Compliance:
A standard is a documented requirement established by law, regulation, contract, policy, procedure, specification, or recognized governance framework that defines what is expected and serves as the benchmark for determining compliance.
The purpose of a compliance review is to determine whether the applicable standard was met.
Every compliance review begins by identifying the applicable standard. Every compliance review ends by answering one question: Was that standard met?
Established Compliance Review Standards
Across government and private industry, organizations responsible for public safety, financial stewardship, regulatory compliance, and operational excellence rely on structured compliance review processes to determine whether established requirements have been met. Although terminology varies by industry, the underlying principles are remarkably consistent.
Examples include:
Industry Common Standard
--------------------------------------------------
Nuclear Power Corrective Action Program (CAP), Root Cause
Analysis, 10 CFR Part 50 Appendix B, NQA-1
Aviation FAA Safety Management System (SMS), FAA
regulations, ICAO Standards
Healthcare Joint Commission accreditation, CMS Conditions of
Participation, CAPA, Patient Safety Programs
Pharmaceuticals FDA Quality System Regulation, CAPA (21 CFR Part
820)
Medical Devices ISO 13485 Corrective and Preventive Action
Manufacturing ISO 9001 Quality Management Systems
Aerospace AS9100 Quality Management Systems
Financial Services SOX Internal Controls, OCC, CFPB, FDIC compliance
programs
Government Auditing GAO Green Book, Government Auditing Standards
Information Security NIST Risk Management Framework, ISO 27001
Although each industry operates under different regulations, they all follow the same fundamental methodology:
Note: Each of these industries has an established compliance function responsible for evaluating potential deviations from governing requirements.
Identify the applicable requirement.
Gather objective evidence.
Determine whether the requirement was met.
Document the findings.
Correct identified deficiencies.
Verify the effectiveness of corrective actions.
Monitor for sustained compliance.
Formally close the issue.
This methodology has become the accepted standard for evaluating compliance because it provides a consistent, objective, and repeatable process for determining whether organizations are meeting their governing requirements.
The Opportunity for Arizona
Arizona counties already operate under numerous laws, contracts, policies, procurement requirements, financial controls, and governance standards. These establish what government is expected to do.
What is largely absent is a standardized methodology for determining whether those standards were actually met when a citizen raises a significant governance concern.
This framework does not propose creating new compliance standards. Rather, it proposes applying a well-established compliance review methodology—one that has been successfully used for decades across government and industry—to citizen-identified governance concerns within Arizona county government.
Workflow 1: County Complaint Intake and Compliance Review
Purpose: Determine whether a citizen's concern warrants a formal compliance review.
Step Action Responsible Outcome
Party
-------------------- ---------------- ------------------------
1 Citizen submits Citizen Complaint received
complaint
2 Complaint County Case opened
acknowledged and
tracking number
assigned
3 Administrative County Complaint Ready for evaluation
review for Coordinator
jurisdiction and
completeness
4 Applicable standards Compliance Review criteria
identified (laws, Reviewer established
contracts, policies,
procedures)
5 Preliminary risk Compliance Risk classification
assessment (Red Rule Reviewer assigned
/ Blue Rule)
6 Determine whether a Compliance Decision documented
formal compliance Reviewer
review is required
7 Blue Rule → Department Normal resolution
Department-level
review
8 Red Rule → Escalate State Independent review
to State Compliance initiated
Review
Workflow 2 – State-Level Compliance Review
When a county determines that a citizen complaint involves a significant governance concern—or when the matter spans multiple departments, involves substantial legal, contractual, financial, election, or public accountability issues—the complaint should be referred for an independent compliance review.
The purpose of the state-level review is to objectively determine whether the applicable laws, contracts, policies, procedures, or other governing standards were followed. The review is evidence-based and is not intended to advocate for either the citizen or the government. Its role is simply to answer one question:
Were the applicable standards met?
If the review determines that compliance was achieved, the matter is documented and formally closed. If deficiencies are identified, the responsible agency develops a Corrective Action Plan that identifies the root cause, establishes corrective measures, assigns responsibility, and defines how the effectiveness of those actions will be verified before the case is formally closed.
Governance Gaps Identified Through Research and Experience
1. Public Accessibility
No clearly identifiable public citizen complaint process.
Citizens often do not know where to submit governance concerns.
Complaint pathways differ among departments.
2. Complaint Intake
No standardized intake process.
No consistent screening criteria.
No standardized tracking number.
No documented complaint lifecycle.
3. Compliance Review
No objective methodology for determining whether laws, contracts,
policies, or procedures were followed.
No standardized compliance review criteria.
No requirement to identify the governing standard before evaluating
the complaint.
4. Governance and Accountability
Ownership becomes fragmented when concerns span multiple
departments.
No clearly designated authority responsible for coordinating
cross-department governance reviews.
Responsibilities can become disputed or unclear.
5. Corrective Action
No standardized requirement for a documented Corrective Action Plan
when deficiencies are identified.
No documented root cause analysis.
No standardized verification that corrective actions were effective.
6. Verification and Monitoring
No standardized follow-up to determine whether corrective actions
resolved the issue.
No monitoring process to prevent recurrence.
No formal closure methodology documenting that compliance has been
restored.
7. Transparency
Citizens receive responses but may not receive documentation
explaining how compliance determinations were reached.
Review methodologies are not consistently documented or
communicated.
Outcomes may differ depending on which department receives the
complaint.
8. Continuous Improvement
No formal process for capturing lessons learned.
No mechanism for identifying recurring governance issues across
departments.
Limited opportunity to improve county-wide governance through trend
analysis.
Citizen Complaint Lifecycle
The Arizona Citizen Compliance Review and Corrective Action Framework is founded upon a standardized complaint lifecycle that provides a consistent methodology for evaluating significant citizen-identified governance concerns. While complaints may vary in complexity, every significant concern should progress through the same structured lifecycle from initial submission through formal closure.
Citizen Complaint
↓
1. Complaint Intake
↓
2. Acknowledgment & Tracking Number
↓
3. Administrative Review
↓
4. Standards Identification
↓
5. Risk Classification
(Red Rule / Blue Rule)
↓
6. Compliance Review
↓
7. Findings & Decision
↓ ↓
Standards Met Deficiency Identified
↓ ↓
Formal Closure 8. Root Cause Analysis
↓
9. Corrective Action Plan
↓
10. Verification
↓
11. Monitoring
↓
12. Formal Closure
↓
Continuous Improvement
(Lessons Learned • Trend Analysis • Governance Improvements)
Purpose of the Lifecycle
This lifecycle provides a standardized governance methodology for evaluating citizen complaints regardless of which county department receives the concern. It establishes clear ownership, identifies the governing standards that apply, ensures objective compliance reviews, requires corrective action when deficiencies are identified, verifies that corrective actions are effective, monitors for sustained compliance, and formally closes each matter with documented results.
Rather than replacing existing complaint processes, the lifecycle provides a common governance framework that promotes transparency, accountability, consistency, and continuous improvement while preserving the authority of existing elected officials, county leadership, and individual departments. It offers citizens and government alike a predictable, objective, and repeatable process for resolving significant governance concerns and strengthening public confidence in county government.
Case Study Observations
The concepts presented in this framework were informed by a real-world citizen governance case study involving multiple Maricopa County departments. What began as a Public Records Request seeking election-related contract documentation evolved into a broader examination of how significant citizen governance concerns are received, evaluated, coordinated, and resolved when they span multiple areas of county government.
Throughout this process, requests and questions involved multiple departments, including Procurement, Elections, the Recorder's Office, Information Governance, County Management, and ultimately the Board of Supervisors. While individual departments responded within their respective areas of responsibility, the experience highlighted the absence of a standardized methodology for conducting an objective, cross-department compliance review when a citizen raises concerns involving multiple governing requirements.
Rather than focusing on the merits of any individual issue, the experience revealed broader governance observations that informed this framework. These observations include the difficulty citizens may encounter identifying the appropriate complaint pathway, the lack of a clearly defined governance review process, fragmented ownership when concerns cross departmental boundaries, and the absence of a standardized methodology for determining whether applicable laws, contracts, policies, procedures, or other governing standards were followed.
The framework presented in this document is intended to address those governance observations by applying well-established compliance review principles already used throughout government and private industry. Its purpose is to provide a consistent, objective, and transparent methodology for evaluating significant citizen-identified governance concerns while strengthening accountability, improving transparency, and increasing public confidence in Arizona county government.
Background: Complaint Process
Explain attributes of an effective Complaint Process
List statutory requirements (don’t forget show the AZ state complaint process as a potential model
Explain implementation
Reemphasis the “complaint by invitation”
Explain your interface with the State Ombudsman, contrasting that interface the Maricopa county Ombudsman
Existing Statutes
1608
However, there is another complaint link (1155) that the citizen could discover, and that complaint goes to the registrar’s office. Those complaints involve contractors too and do have a formal compliance review process.
The fact we have two different experiences for citizen complaints prompted us to bring this to your attention.
Since both citizen complaints could have two entirely different experiences depending on which link is used to submit the complaint, then this explains why some issues get resolution; while others seem to go into a bit black hole or resemble a hot potato being passed from one department to another, with no one actually owning the complaint that spans multiple departments.
Both complaints are listed below for reference:
Under A.R.S. § 32-1155, State statute the complaint receives an objective compliance review to determine whether laws, rules, contracts, or standards were followed. If deficiencies are found, corrective action follow.
Under A.R.S. § 11-1608, the county is required to respond in a timely manner and provide an appeals process, but there is no corresponding requirement that anyone objectively determine whether government actually complied with its own laws, contracts, or policies.
Issue: Inconsistent Statutory Expectations
Explain various complaint statutes
Issue
Background: Corrective Action Plans
Explain the attributes of an effective CAP program
Identify the AZ GAO CAP as a model.
Issue: Lack of a Compliance Officer
When a citizen identifies a true concern, violation of law, statue, or 3^(rd) party vendor contractor/contract anomalies, and submits in good faith, a formal complaint, there currently is not a step for that concern to be reviewed by a compliance officer to determine if the complaint is a blue or red rule violation. Blue rules are subjective and do not require formal action; however, red rules are deviations of law, statute or contract and do require formal oversight such as Corrective Action Plans. This document is to address the later.
Why the compliance review matters. When a citizen files a complaint, they are expecting someone with authority is reviewing that complaint in a manner that utilizes a consistent method of operation. If the process the reviewer is following is inconsistently enforced, then the outcome is, public and leadership dissatisfaction in the fact that the potential violation is never addressed or fixed.
The Goal: The goal isn't to create more government—it's to create better government. A structured citizen compliance review and corrective action process helps identify governance and contract compliance issues before they turn into litigation, audit findings, operational failures, or the same problems happening over and over again. By assigning ownership, documenting corrective actions, verifying the results, and formally closing the issue, the County can reduce duplicate work, strengthen contract oversight, improve operational efficiency, and better protect taxpayer dollars. Every major industry that depends on quality management uses corrective action because it's far less expensive to prevent repeat failures than it is to keep paying to fix the same problems after the fact.
Proposal
Merge Complaint and CAP processes
Managed by the state, implemented by the county. Point to existing arrangements wit GAO Audit findings.
The ask for our current legislators: We believe these findings, fit into a code of conduct quality management style leadership umbrella that would help build trust in our community again. Without the public knowing what we’ve found, transparency isn’t possible. We believe that expanding this knowledge would benefit all Arizonians.
We would like to ask for your partnership and your guidance on how to expand our dialog and education because we believe if we do, the benefits would be bipartisan and would address the question of “How do we make sure these issues never ever happen again”.
Please see the case study below, in hopes it will help guide us all on the best way to approach bringing it to the public, and to leadership.
Existing Support
The MCRC ECG Approval of our Resolution: The Maricopa County Republican Committee has approved the below resolution twice. The first time it was approved was in December 2024 when Tristan Manos submitted it to the committee and then again during the Prescott Valley MCRC Republican Committee Mandatory Meeting on January 10^(th) 2026.
[]
Our Present Action: We’re continuing a dialog with our Republican peers via Legislative District monthly meetings where we are presenting our findings and proposed solution. The objective for attending these events is to educate Precinct Committeemen, of the identified gap.
Gaps Identified: There are three gaps identified:
1.
2. Regardless of how a citizen files a complaint, that complaint
warrants a compliance review to determine the severity of the
concern. If no compliance review takes place, there is no confidence
that the issue being brought forward will ever be heard by
leadership or actioned.
3. Contract Compliance requires formal review and enforcement as does
Complaints and Corrective Action Plans going forward. The goal is
that if we implement formal corrective action plans into the
complaint process and we treat contract compliance with quality
management oversight, we would mitigate our risk to meet levels that
industries that utilize corrective action and total quality
management achieve. Consistent monitoring after quality management
implementation would provide the missing safety net.
What's in It for Legislators
Provides a practical governance tool to help constituents when concerns don't fit existing complaint channels.
Strengthens transparency and accountability without changing the authority of elected officials.
Helps identify governance and compliance issues before they become litigation, audit findings, or public controversies.
Demonstrates responsible stewardship of taxpayer resources through documented oversight and continuous improvement.
Gives legislators a proven, repeatable framework they can champion as good government rather than partisan reform.
What's in It for the Board of Supervisors
Establishes a consistent framework for evaluating citizen-identified governance concerns.
Improves cross-department coordination when issues involve multiple County offices.
Provides documented ownership, accountability, and closure for significant concerns.
Identifies systemic issues early, reducing recurring operational problems.
Demonstrates transparency and public accountability.
What's in It for the Recorder
Provides an objective review process when election administration concerns are raised.
Strengthens election operations through documented governance and continuous improvement.
Improves contract administration and document control.
Creates a documented record showing concerns were evaluated and addressed.
Builds public confidence by demonstrating that legitimate concerns receive objective review.
What's in It for Procurement
Strengthens contract compliance and third-party vendor oversight.
Improves documentation of contract administration and performance.
Helps identify missing documentation, amendment history, and governance records.
Encourages corrective action before issues become larger operational or legal problems.
Provides better traceability throughout the life of a contract.
What's in It for Citizens
Provides an objective evaluation of significant governance concerns.
Ensures concerns are acknowledged, reviewed, assigned, and documented.
Creates a process for corrective action when appropriate.
Provides verification, monitoring, and formal closure rather than concerns disappearing into a "black hole."
Increases transparency, accountability, and public trust.
What's in It for Everyone
Instead of government and citizens working against one another, everyone works from the same documented process. Legitimate concerns are acknowledged, objectively evaluated, assigned to the appropriate owner, corrected when warranted, verified, monitored, and formally closed. The result is stronger governance, better accountability, more consistent decision-making, improved stewardship of taxpayer resources, and greater public confidence in county government.
Visuals of the Disaster Recovery Experience: The below screenshots show Exhibit C (Disaster Recovery Policy) used in the 2020 Runbeck Contract in Maricopa County Arizona. See the document signed June 4, 2020 where the terms say all other terms and conditions remain unchanged, signed by Procurement 90 days into the pandemic with no Corrective Action Plans or Lessons Learned post the election. This raises a concern because the exhibits below show one version of the first page with strikethroughs and no explanation and then see the one-page document of exhibit C, same contract serial number, but it’s dated 1-1-2016 so the question becomes, which disaster recovery policy was in effect during the Arizona election in 2020? Was the one with no date corresponding with the June 4 2020 date or with the 1-1-2016 date? This was in the 116-page Runbeck doc. The update to Exhibit C is mentioned in the 58-page Runbeck document; however, it’s dated October 2021. This highlights that there was no clear disaster recovery policy in effect during the pandemic election.
[1] See app. II for examples of sources of data that may be helpful to management.=== Assessment Observations Compared to Green Book Components, Principles, & Attributes ===
Control Environment
Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.
- Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
- Principle 2 - Exercise Oversight Responsibility
- Principle 3 - Establish Structure, Responsibility, and Authority
- Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
- Principle 4 - Demonstrate Commitment to Competence
- Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
- Principle 5 - Enforce Accountability
- Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment
Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.
- Principle 6 - Define Objectives and Risk Tolerances
- Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
- Principle 7 - Identify, Analyze, and Respond to Risks
- Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
- Principle 8 - Assess Fraud, Improper Payment, and Information
- Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
- Principle 9 - Identify, Analyze, and Respond to Change
- Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities
Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.
- Principle 10 - Design Control Activities
- Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
- Principle 11 - Design General Control Activities over Information
- Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
- Principle 12 - Implement Control Activities
- Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication
Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.
- Principle 13 - Use Quality Information
- Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
- Principle 14 - Communicate Internally
- Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
- Principle 15 - Communicate Externally
- Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring
Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.
- Principle 16 - Perform Monitoring Activities
- Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
- Principle 17 - Evaluate Issues and Remediate Deficiencies
- Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)
