Principle 12 - Implement Control Activities

From Corrective Action Plan AZ
Revision as of 23:49, 3 August 2026 by Kelly (talk | contribs) (Auto-created by CAP AZ bot)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

12.01 Management should implement control activities through policies and procedures.

Documentation of Control Activities Through Policies and Procedures

12.02 Management establishes control activities by documenting in policies what is expected and in procedures specified actions that implement policies, to mitigate risks to achieving the entity’s objectives to acceptable levels [documentation requirement].

12.03 Management documents in policies and procedures for each unit within the entity’s organizational structure its responsibility for a business process’s objectives and related risks and control activity design, implementation, and operating effectiveness.102 Each unit, with guidance from management, determines the policies necessary to operate the business process based on the objectives and related risks. Each unit also documents policies and procedures in the appropriate level of detail to allow management to effectively monitor the control activity. The documentation may appear in various forms, such as management directives, administrative policies, or operating manuals.

12.04 Those in key roles for the unit may further define policies through day-to-day procedures, depending on the rate of change in the operating environment and complexity of the business process. Procedures may include the timing of when a control activity occurs and any follow-up corrective actions to be performed by competent personnel if deficiencies are identified.103 Management communicates the policies and procedures entity-wide so that personnel can implement the control activities for their assigned responsibilities.

Periodic Review of Control Activities

12.05 Management reviews policies, procedures, and related control activities on a periodic and ongoing basis for continued relevance and effectiveness in achieving the entity’s objectives or mitigating related risks. If there is a significant change in an entity’s process, management reviews this process in a timely manner after the change to determine that the control activities are designed and implemented appropriately. Changes may occur in personnel, business processes, or information technology. A new law or regulation may change an entity’s objectives or how an entity is to achieve an objective. Further, in the federal environment, this may occur through government-wide policy or guidance issued by entities like the Office of Management and Budget, Office of Personnel Management, and the Department of the Treasury. Management considers these changes in its periodic and ongoing reviews. Management also considers the results of its monitoring activities to determine whether control activities are designed and implemented effectively.