Template:Principles

From Corrective Action Plan AZ

US GAO Green Book Principles

  1. Principle 1 - Demonstrate Commitment to Integrity and Ethical Values
  2. Principle 2 - Exercise Oversight Responsibility
  3. Principle 3 - Establish Structure, Responsibility, and Authority
  4. Principle 4 - Demonstrate Commitment to Competence
  5. Principle 5 - Enforce Accountability
  6. Principle 6 - Define Objectives and Risk Tolerances
  7. Principle 7 - Identify, Analyze, and Respond to Risks
  8. Principle 8 - Assess Fraud, Improper Payment, and Information
  9. Principle 9 - Identify, Analyze, and Respond to Change
  10. Principle 10 - Design Control Activities
  11. Principle 11 - Design General Control Activities over Information
  12. Principle 12 - Implement Control Activities
  13. Principle 13 - Use Quality Information
  14. Principle 14 - Communicate Internally
  15. Principle 15 - Communicate Externally
  16. Principle 16 - Perform Monitoring Activities
  17. Principle 17 - Evaluate Issues and Remediate Deficiencies

Index of Green Book Attributes Relating to Maricopa County Performance

Principle 1 - Demonstrate Commitment to Integrity and Ethical Values

Tone at the Top

Standards of Conduct

Adherence to Standards of Conduct

  • Attribute 1.08
  • Attribute 1.10              
  • Attribute 1.11

Principle 2 - Exercise Oversight Responsibility

  • Attribute 2.01

Oversight Structure

  • Attribute 2.02
  • Attribute 2.03
  • Attribute 2.04
  • Attribute 2.05
  • Attribute 2.06
  • Attribute 2.07
  • Attribute 2.08

Oversight for the Internal Control System

  • Attribute 2.09
  • Attribute 2.10

Input for Remediation of Deficiencies

  • Attribute 2.11
  • Attribute 2.12
  • Attribute 2.13

Principle 3 - Establish Structure, Responsibility, and Authority

  • Attribute 3.01

Organizational Structure

  • Attribute 3.02
  • Attribute 3.03
  • Attribute 3.04
  • Attribute 3.05

Assignment of Responsibility and Delegation of Authority

  • Attribute 3.06
  • Attribute 3.07
  • Attribute 3.08

Documentation of the Internal Control System

  • Attribute 3.09
  • Attribute 3.10
  • Attribute 3.11
  • Attribute 3.12

Principle 4 - Demonstrate Commitment to Competence

  • Attribute 4.01

Expectations of Competence

  • Attribute 4.02
  • Attribute 4.03
  • Attribute 4.04

Recruitment, Development, and Retention of Individuals

  • Attribute 4.05

Succession and Contingency Plans and Preparation

  • Attribute 4.06
  • Attribute 4.07
  • Attribute 4.08

Principle 5 - Enforce Accountability

  • Attribute 5.01

Enforcement of Accountability

  • Attribute 5.02
  • Attribute 5.03
  • Attribute 5.04
  • Attribute 5.05
  • Attribute 5.06

Consideration of Excessive Pressures

  • Attribute 5.07
  • Attribute 5.08

Principle 6 - Define Objectives and Risk Tolerances

  • Attribute 6.01

Definitions of Objectives

  • Attribute 6.02
  • Attribute 6.03
  • Attribute 6.04
  • Attribute 6.05
  • Attribute 6.06
  • Attribute 6.07

Definitions of Risk Tolerances

  • Attribute 6.08
  • Attribute 6.09
  • Attribute 6.10

Principle 7 - Identify, Analyze, and Respond to Risks

  • Attribute 7.01

Identify Risks

  • Attribute 7.02
  • Attribute 7.03
  • Attribute 7.04
  • Attribute 7.05
  • Attribute 7.06

Analyze Risks

  • Attribute 7.07
  • Attribute 7.08
  • Attribute 7.09

Respond to Risks

  • Attribute 7.10
  • Attribute 7.11
  • Attribute 7.12
  • Attribute 7.13
  • Attribute 7.14
  • Attribute 7.15

Principle 8 - Assess Fraud, Improper Payment, and Information

  • Attribute 8.01

Identify Risks Related to Fraud, Improper Payments, and Information Security

  • Attribute 8.02
  • Attribute 8.03
  • Attribute 8.04
  • Attribute 8.05

Types of Fraud and Fraud Risk Factors

  • Attribute 8.06
  • Attribute 8.07
  • Attribute 8.08
  • Attribute 8.09
  • Attribute 8.10

Types of Improper Payments and Improper Payment Risk Factors

  • Attribute 8.11
  • Attribute 8.12
  • Attribute 8.13

Types of Information Security Risk and Information Security Risk Factors

  • Attribute 8.14
  • Attribute 8.15
  • Attribute 8.16
  • Attribute 8.17

Analyze and Respond to Identified Risks

  • Attribute 8.18
  • Attribute 8.19
  • Attribute 8.20

Principle 9 - Identify, Analyze, and Respond to Change

  • Attribute 9.01

Identify Significant Changes

  • Attribute 9.02
  • Attribute 9.03
  • Attribute 9.04

Establish a Change Assessment Process

  • Attribute 9.05
  • Attribute 9.06
  • Attribute 9.07
  • Attribute 9.08
  • Attribute 9.09
  • Attribute 9.10

Identify, Analyze and Respond to Risks Related to Significant Changes

  • Attribute 9.11
  • Attribute 9.12
  • Attribute 9.13

Principle 10 - Design Control Activities

  • Attribute 10.01

Response to Risks

  • Attribute 10.02

Design of Appropriate Types of Control Activities

  • Attribute 10.03
  • Attribute 10.04

Design of Automated and Manual Control Activities

  • Attribute 10.05
  • Attribute 10.06
  • Attribute 10.07
  • Attribute 10.08
  • Attribute 10.09

Design of Preventive and Detective Control Activities

  • Attribute 10.10
  • Attribute 10.11
  • Attribute 10.12
  • Attribute 10.13

Design of Control Activities at Various Levels

  • Attribute 10.14
  • Attribute 10.15
  • Attribute 10.16
  • Attribute 10.17
  • Attribute 10.18
  • Attribute 10.19
  • Attribute 10.20

Segregation of Duties

  • Attribute 10.21
  • Attribute 10.22
  • Attribute 10.23

Principle 11 - Design General Control Activities over Information

  • Attribute 11.01

Response to Risks

  • Attribute 11.02

Design of the Entity’s Information Technology

  • Attribute 11.03
  • Attribute 11.04
  • Attribute 11.05
  • Attribute 11.06

Design of Appropriate Types of General Control Activities

  • Attribute 11.07
  • Attribute 11.08
  • Attribute 11.09
  • Attribute 11.10
  • Attribute 11.11
  • Attribute 11.12
  • Attribute 11.13
  • Attribute 11.14
  • Attribute 11.15
  • Attribute 11.16
  • Attribute 11.17

Principle 12 - Implement Control Activities

Principle 13 - Use Quality Information

Principle 14 - Communicate Internally

Principle 15 - Communicate Externally

Principle 16 - Perform Monitoring Activities

Principle 17 - Evaluate Issues and Remediate Deficiencies