7.04

From Corrective Action Plan AZ
Revision as of 04:09, 15 August 2026 by Neil thibodaux (talk | contribs)

Risk Assessment

Principle 7 - Identify, Analyze, and Respond to Risks

Attribute 7.04 - Management considers all significant interactions within the entity and with external parties,43 changes within the entity's internal and external environments,44 and other internal and external factors to identify risks throughout the entity. Management considers these factors at both the entity and transaction levels to comprehensively identify risks that affect defined objectives.45 Entity-level risk factors have a pervasive effect on an entity's internal control system and are generally considered at a relatively high level. Transaction-level risk factors affect specific business processes within all levels of the organizational structure and are generally considered at a more detailed level.

Internal risk factors may include

  • he complex nature of an entity's programs;
  • the level and experience of, and quality of training for, personnel;
  • the entity's organizational structure;
  • limitations of the entity's information system;
  • availability and quality of data;
  • use of new technology in business processes; and
  • use of emerging technologies, such as artificial intelligence.

External risk factors may include

  • new or amended laws, regulations, or standards;
  • economic instability and crises;
  • developments in information technology and related security threats;
  • outsourcing of business processes to external parties;
  • threats to national security; and
  • public health emergencies, natural and human-caused disasters, and other catastrophic events.

The discussion of Attribute 1.03 is from this March 12, 2026 event, under the subheading of

Motor Vehicle Department Contract