Principle 15 - Communicate Externally
15.0 Communicate Externally
External Link to US GAO Green Book Principle 15
Overview
15.01
Management should communicate relevant and quality information with appropriate external parties regarding matters impacting the functioning of the internal control system.
15.1 Communication with External Parties
15.02
Management communicates with, and obtains relevant and quality information from, appropriate external parties using established reporting lines. Open two-way external reporting lines allow for this communication. External parties may include service organizations, suppliers, contractors, regulators, regulated entities, external auditors, federal entities, state and local governments, grantees, and the public.
15.03
Management communicates relevant and quality information externally through reporting lines so that appropriate external parties can help the entity achieve its objectives, address related risks, and support its internal control system. Information communicated by management includes significant matters relating to the entity’s events and activities that impact its internal control system. For instance, information communicated to service organizations may include information on the entity’s objectives and ethical values, identified risks, internal control practices to consider, and performance metrics. Information communicated for the entity to achieve program-related objectives may include information on eligibility, reporting, and audit requirements for recipients of federal financial assistance and legal and regulatory requirements to regulated entities.
15.04
Management obtains information through reporting lines from external parties. Information communicated to management includes significant matters relating to risks, changes, or issues that impact the entity’s internal control system. Communication may also include information for the entity to achieve program-related objectives. These communications are necessary for the effective operation of internal control. Management evaluates external information obtained against the characteristics of quality information and information processing objectives and takes any necessary actions so that the information is quality information.
15.05
The oversight body obtains information through reporting lines from external parties. Information communicated to the oversight body includes significant matters relating to risks, changes, and issues that impact the entity’s internal control system. This communication is necessary for the effective oversight of internal control.
15.06
External parties use separate reporting lines when external reporting lines are compromised. Laws and regulations may require entities to establish separate lines of communication, such as whistleblower and ethics hotlines, for communicating confidential information. Management informs external parties of these separate reporting lines, how they operate, how they are to be used, and how the information will remain confidential.
15.2 Appropriate Methods of Communication
15.07
Management selects appropriate methods for communicating externally. Management considers a variety of factors in selecting an appropriate method of communication.
Some factors to consider follow:
- Audience - The intended recipients of the communication.
- Nature of information - The purpose and type of information being communicated.
- Availability - Information readily available to the audience when needed.
- Cost - The resources used to communicate the information.
- Legal or regulatory requirements - Requirements in laws and regulations that may impact communication.
15.08
Based on consideration of the factors, management selects appropriate methods of communication. Management evaluates the entity’s methods of communication on a periodic and ongoing basis so that the organization has the appropriate tools to communicate quality information throughout and outside of the entity on a timely basis.
15.09
Government entities not only report to the head of the government, legislators, and regulators but to the public as well. In the federal government, entities not only report to the President and Congress but also to the public. Entities consider appropriate methods for communicating with such a broad audience.
Assessment Observations Compared to Green Book Components, Principles, & Attributes
Control Environment
Component: Control Environment - The foundation for an internal control system. It provides the discipline and structure to help an entity achieve its objectives.
- Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
- Principle 2 - Exercise Oversight Responsibility
- Principle 3 - Establish Structure, Responsibility, and Authority
- Attributes (3.01, 3.02, 3.03, 3.04, 3.05, 3.06, 3.07, 3.08, 3.09, 3.10, 3.11, 3.12)
- Principle 4 - Demonstrate Commitment to Competence
- Attributes (4.01, 4.02, 4.03, 4.04, 4.05, 4.06, 4.07, 4.08)
- Principle 5 - Enforce Accountability
- Attributes (5.01, 5.02, 5.03, 5.04, 5.05, 5.06, 5.07, 5.08)
Risk Assessment
Component: Risk Assessment - The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.
- Principle 6 - Define Objectives and Risk Tolerances
- Attributes (6.01, 6.02, 6.03, 6.04, 6.05, 6.06, 6.07, 6.08, 6.09, 6.10)
- Principle 7 - Identify, Analyze, and Respond to Risks
- Attributes (7.01, 7.02, 7.03, 7.04, 7.05, 7.06, 7.07, 7.08, 7.09, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15)
- Principle 8 - Assess Fraud, Improper Payment, and Information
- Attributes (8.01, 8.02, 8.03, 8.04, 8.05, 8.06, 8.07, 8.08, 8.09, 8.10, 8.11, 8.12, 8.13, 8.14, 8.15, 8.16, 8.17, 8.18, 8.19, 8.20)
- Principle 9 - Identify, Analyze, and Respond to Change
- Attributes (9.01, 9.02, 9.03, 9.04, 9.05, 9.06, 9.07, 9.08, 9.09, 9.10, 9.11, 9.12, 9.13)
Control Activities
Component: Control Activities - The actions management establishes through policies and procedures to mitigate risks to achieving the entity's objectives to acceptable levels.
- Principle 10 - Design Control Activities
- Attributes (10.01, 10.02, 10.03, 10.04, 10.05, 10.06, 10.07, 10.08, 10.09, 10.10, 10.11, 10.12, 10.13, 10.14, 10.15, 10.16, 10.17, 10.18, 10.19, 10.20, 10.21, 10.22, 10.23)
- Principle 11 - Design General Control Activities over Information
- Attributes (11.01, 11.02, 11.03, 11.04, 11.05, 11.06, 11.07, 11.08, 11.09, 11.10, 11.11, 11.12, 11.13, 11.14, 11.15, 11.16, 11.17)
- Principle 12 - Implement Control Activities
- Attributes (12.01, 12.02, 12.03, 12.04, 12.05)
Information and Communication
Component: Information and Communication - The quality information management and other personnel communicate and use to support the internal control system.
- Principle 13 - Use Quality Information
- Attributes (13.01, 13.02, 13.03, 13.04, 13.05, 13.06, 13.07)
- Principle 14 - Communicate Internally
- Attributes (14.01, 14.02, 14.03, 14.04, 14.05, 14.06, 14.07, 14.08)
- Principle 15 - Communicate Externally
- Attributes (15.01, 15.02, 15.03, 15.04, 15.05, 15.06, 15.07, 15.08, 15.09)
Monitoring
Component: Monitoring - Activities management establishes and operates to assess the quality of performance over time and promptly resolve the findings of audits and other reviews.
- Principle 16 - Perform Monitoring Activities
- Attributes (16.01, 16.02, 16.03, 16.04, 16.05, 16.06, 16.07, 16.08, 16.09, 16.10)
- Principle 17 - Evaluate Issues and Remediate Deficiencies
- Attributes (17.01, 17.02, 17.03, 17.04, 17.05, 17.06, 17.07, 17.08)
