top of page
Search

A Free Tool for Assessing GAO Green Book Compliance: Using Virginia's ARMICS Assessment Guides

Governmental Organizations Don't Have to Start Their Green Book Assessment From Scratch

How does a governmental organization determine whether its system of internal control complies with the GAO Green Book?


That can be a surprisingly difficult question.


The U.S. Government Accountability Office's Standards for Internal Control in the Federal Government—better known as the Green Book—provides an excellent framework for internal control.


But reading the Green Book is one thing.


Turning its requirements into a practical organizational assessment is something else entirely.


Management needs a methodology for asking questions such as:

  • Do our controls address all five Green Book components?

  • Are the 17 principles adequately addressed?

  • Do our controls actually exist?

  • Are they properly designed?

  • Are they operating effectively?

  • What documentation supports our conclusions?

  • Where are our internal-control deficiencies?

  • How mature and reliable are our controls?

  • What corrective actions should management take?


Fortunately, governmental organizations don't necessarily need to create all of those assessment tools from scratch.


The Commonwealth of Virginia Department of Accounts has made its Agency Risk Management and Internal Control Standards—or ARMICS—Assessment Guides publicly available.


These tools provide governmental organizations with a practical starting point for developing their own Green Book internal-control assessment program.


What Is ARMICS?

ARMICS stands for:


Virginia's Department of Accounts developed ARMICS to strengthen how state agencies manage risk, safeguard public resources, improve operations, and maintain reliable financial reporting.


Virginia agencies perform annual self-assessments and certifications regarding their systems of internal control.


But what makes ARMICS particularly interesting to auditors and governmental managers outside Virginia is the assessment methodology and supporting tools.


The Virginia Department of Accounts provides downloadable assessment guides covering:

  • Control Environment

  • Risk Assessment

  • Control Activities

  • Information and Communication

  • Monitoring

  • Information-system general controls

  • Process-level controls

  • Transaction-level controls


Does that list look familiar?


It should.


It closely parallels the structure governmental auditors encounter when working with the GAO Green Book which is based on COSO.


Start With the GAO Green Book

Before using ARMICS, management needs to understand what it is assessing.


The 2025 GAO Green Book establishes standards for an effective internal-control system and became effective beginning with fiscal year 2026.


The Green Book organizes internal control around five components and 17 principles.


The five components are:

1. Control Environment

The foundation for the organization's system of internal control.


2. Risk Assessment

The process for identifying, analyzing, and responding to risks that could prevent achievement of objectives.


3. Control Activities

The actions management establishes through policies and procedures to respond to risks and achieve objectives.


4. Information and Communication

The processes used to obtain, generate, use, and communicate quality information.


5. Monitoring

The activities used to determine whether the internal-control system continues to operate effectively.


The Green Book then establishes principles underlying those five components.


The challenge is converting those principles into something management can actually assess.


That is where ARMICS can help.


Step 1 — Download the ARMICS Assessment Tools

The Virginia Department of Accounts provides its ARMICS assessment materials online.

Management can download individual Microsoft Word assessment guides or download the complete collection.


This is important because the files can serve as templates.


A governmental organization outside Virginia should not simply adopt the questionnaires and declare itself Green Book compliant.


Instead:

Use ARMICS as the starting point for developing an organization's own Green Book assessment methodology.

The tools should be customized for the organization's:

  • Mission

  • Organizational structure

  • Programs

  • Risks

  • Information systems

  • Funding sources

  • Laws and regulations

  • Grant requirements

  • Financial processes

  • Fraud exposures


Step 2 — Assess the Control Environment

ARMICS begins at the entity level.


Its Control Environment Assessment Guide includes separate assessment exhibits addressing:

  • Ethics

  • Management's commitment to professional and technical competence

  • Organizational structure

  • Assignment of authority and responsibility

  • Human-resource standards


These areas provide an excellent starting point for assessing the Green Book's Control Environment.


Management should examine more than whether policies exist.

For example:

Does the organization have a Code of Ethics?

That is a starting question.


But the better assessment asks:

Does management actually demonstrate a commitment to integrity and ethical values?

That requires evidence.


Consider:

  • Ethics policies

  • Employee training

  • Hotline activity

  • Disciplinary actions

  • Conflict-of-interest disclosures

  • Management communications

  • Board or governing-body oversight

  • Employee surveys

  • Investigation results

  • Management responses to misconduct


The distinction is critical.


Policy existence is not the same thing as control effectiveness.


Step 3 — Assess Risk Assessment

ARMICS provides separate tools for:

Risk Assessment

and

Risk Response


These can help management evaluate whether the organization has developed a systematic approach to identifying and responding to risks.


Under the 2025 Green Book, this area deserves particular attention.


GAO's updated standards emphasize risk areas including:

  • Fraud

  • Improper payments

  • Information security

  • Significant organizational or program changes


Management should therefore use the ARMICS questionnaires as a starting point and expand them to address the current Green Book requirements.


For each significant objective, ask:


  • What could prevent us from achieving the objective?


Then:

  • How likely is it?

  • What would be the impact?

  • What controls address the risk?

  • Is the remaining risk acceptable?


That begins transforming risk assessment from an annual compliance exercise into a management process.


Step 4 — Assess Control Activities

ARMICS becomes particularly useful when examining Control Activities.


The Virginia tools include assessment guides covering controls applicable to:

  • Fiscal processes

  • Accounting administration

  • General ledger activities


But ARMICS goes further.


It also provides questionnaires addressing important information-system general controls, including:

  • System risk assessment

  • Agency-wide security management

  • Access control

  • Application software development and change control

  • System software controls

  • Segregation of duties

  • Service continuity


That is extremely useful for a modern Green Book assessment.


Why?


Because governmental operations increasingly depend upon technology.


A control cannot necessarily be considered reliable simply because the employee operating it performs the control correctly.


Auditors also need to understand the technology supporting that control.


Step 5 — Assess Information and Communication

ARMICS provides separate questionnaires for:

Information

and

Communication


These can be used as the foundation for evaluating the Green Book's Information and Communication component.


Management should ask:

  • Does management receive the information it needs?

  • Is the information accurate?

  • Is it complete?

  • Is it timely?

  • Do employees understand their internal-control responsibilities?

  • Can employees communicate concerns upward?

  • Does information move across organizational boundaries?

  • Does the governing body receive information necessary for effective oversight?


This component is frequently underestimated.


An organization can have excellent control procedures and still experience significant control failures because important information never reaches the people who need it.


Step 6 — Assess Monitoring

ARMICS also provides a dedicated Monitoring Questionnaire.


Monitoring answers a critical question:

How does management know that its controls continue to work?

That is different from asking Internal Audit to find out.


Management owns internal control.


Management therefore needs processes for identifying when controls deteriorate.


Those processes might include:

  • Supervisory reviews

  • Control self-assessments

  • Exception reports

  • Performance indicators

  • Data analytics

  • Complaint analysis

  • Internal Audit findings

  • External audit findings

  • Regulatory findings

  • Corrective-action tracking


A mature organization does not wait for the annual audit to discover that a significant control stopped working nine months ago.


Step 7 — Go Below the Entity Level

One of the strongest aspects of the ARMICS approach is that it doesn't stop with an entity-level questionnaire.


ARMICS includes a second stage addressing process and transaction-level controls.


The available tools address areas such as:

  • Appropriations

  • Cash receipts

  • Cash disbursements

  • Expenditures

  • Prompt payment

  • Petty cash

  • Capital outlays

  • Purchase cards

  • Accounts receivable

  • Federal grants

  • Indirect costs

  • Reconciliations

  • Fixed assets

  • Information-system security


This is where a Green Book assessment becomes operational.


Management can move from:

“We believe our Control Activities component is effective.”

to determining whether significant processes actually contain properly designed and functioning controls.


Step 8 — Use ARMICS to Measure Control Reliability

Here is another reason auditors should examine the ARMICS methodology.


It doesn't simply ask yes-or-no questions.


ARMICS provides a five-level Internal Control Reliability Model.


The levels are:


Level 1 — Initial

Documentation is very limited, procedures are largely ad hoc, and monitoring is absent.


Level 2 — Informal

Controls may be repeatable but remain inconsistently documented and are not fully integrated into operations.


Level 3 — Systematic

Documentation becomes comprehensive, controls are formally standardized, and employees receive more structured communication and training.


Level 4 — Integrated

Control processes become integrated with organizational strategy and periodic monitoring occurs.


Level 5 — Optimized

Controls are supported by comprehensive documentation and training, continuous improvement is emphasized, and monitoring can become real-time.


This gives management something extremely valuable:

A way to think about internal-control maturity—not merely the existence of controls.

Effective Is Not the Same as Mature

Suppose a government finance department performs a monthly bank reconciliation.


The reconciliation is performed correctly every month.


The control might therefore be operating effectively.


But suppose:

  • Only one employee knows how to perform it.

  • Procedures haven't been documented.

  • The process relies on a complex spreadsheet.

  • Management doesn't monitor completion.

  • Exceptions aren't formally tracked.

  • Nobody has evaluated whether the process could be automated.


That may be an effective but relatively immature control.


Now consider another agency where:

  • Procedures are documented.

  • Responsibilities are assigned.

  • Employees are cross-trained.

  • Completion is monitored.

  • Exceptions are measured.

  • Supervisory review is documented.

  • Analytics identify unusual reconciling items.

  • Management periodically evaluates opportunities for automation.


The control objective may be identical.


The control capability is not.


ARMICS provides governmental organizations with a methodology for recognizing that difference.


Step 9 — Build a Green Book Crosswalk

A governmental organization using ARMICS should create a formal crosswalk.


For each Green Book principle, identify:

  • Green Book Component

  • Green Book Principle

  • Applicable ARMICS Questions

  • Organization-Specific Controls

  • Control Owner

  • Supporting Evidence

  • Design Effectiveness

  • Operating Effectiveness

  • Control Reliability/Maturity

  • Deficiencies

  • Corrective Action

  • Responsible Party

  • Target Completion Date


The result might look like this:

Green Book Area

ARMICS Assessment

Current Reliability

Target

Control Environment

Ethics, competence, authority, HR

3

4

Risk Assessment

Risk assessment and response

2

4

Control Activities

Fiscal, accounting and IT controls

3

4

Information & Communication

Information and communication questionnaires

3

4

Monitoring

Monitoring questionnaire

2

4


Now management has something far more useful than a statement saying:

“We comply with the Green Book.”

Management has a roadmap for improving internal control.


Step 10 — Validate the Answers

This is probably the most important warning.


Do not turn ARMICS into a checklist exercise.


The Virginia Department of Accounts itself warns that its tools are not all-inclusive and cannot replace analysis and professional judgment.


More importantly, completing a questionnaire does not prove that a control exists or operates effectively.


If management answers:

“Yes, supervisors review monthly reconciliations.”

someone should verify it.


Select reconciliations.


Inspect the evidence.


Determine:

  • Was the review actually performed?

  • Was it timely?

  • Was the reviewer qualified?

  • Were exceptions investigated?

  • Was corrective action taken?

  • Is there evidence demonstrating the review?


That is the difference between self-assessment and assurance.


Management and Internal Audit Have Different Roles

Management owns the system of internal control.


Management should therefore perform or oversee the Green Book self-assessment.


Internal Audit can then independently evaluate:

  • The assessment methodology

  • Management's conclusions

  • Supporting evidence

  • Design effectiveness

  • Operating effectiveness

  • Identified deficiencies

  • Reliability ratings

  • Corrective-action plans


Internal Audit should not become the owner of management's internal-control system simply because auditors understand internal controls.


That distinction is fundamental to maintaining Internal Audit's independence.


ARMICS Is a Starting Point—Not a Substitute for the Green Book

Governmental organizations outside Virginia should recognize an important limitation.


ARMICS is a Commonwealth of Virginia internal-control program.


It is not the GAO Green Book.


And an ARMICS questionnaire by itself does not establish Green Book compliance.


The organization should use the current 2025 GAO Green Book as its criteria and use ARMICS as an assessment methodology and source of practical tools.


That means management should:

  • Start with the Green Book.

  • Crosswalk the 17 principles.

  • Adapt the ARMICS questionnaires.

  • Add organization-specific risks and controls.

  • Document supporting evidence.

  • Test significant controls.

  • Identify deficiencies.

  • Measure reliability and maturity.

  • Develop corrective-action plans.

  • Monitor improvement.


That is a much stronger methodology than simply completing a checklist.


A Valuable Free Resource for Governmental Organizations

Governmental organizations spend significant amounts of money developing internal-control assessment methodologies.


Before building another one from scratch, take a look at what the Commonwealth of Virginia has already made publicly available.


The ARMICS Assessment Guides provide a practical collection of tools addressing:

  • Entity-level controls

  • Risk assessment

  • Fiscal controls

  • IT general controls

  • Information and communication

  • Monitoring

  • Process-level controls

  • Transaction-level controls

  • Control reliability


Combined with the 2025 GAO Green Book, these tools can provide the foundation for a comprehensive governmental internal-control assessment.


The ultimate objective should not be:

“Can we check the Green Book compliance box?”

The better objective is:

“Can we demonstrate that our system of internal control is properly designed, operating effectively, appropriately documented, and capable of improving as our risks change?”

That is what governmental accountability should look like.


Strengthen Your Green Book Knowledge With CCS

Corporate Compliance Seminars provides CPE training for governmental auditors, internal auditors, financial managers, compliance professionals, and other professionals responsible for internal control.


CCS's GAO Green Book Compliance Academy provides intensive training on applying the Green Book to governmental organizations and evaluating internal-control systems.


Governmental organizations can use training of this type together with practical resources such as ARMICS to move beyond simply understanding the Green Book toward actually assessing, documenting, testing, and improving their system of internal control.


The Green Book provides the standards.


ARMICS provides useful assessment tools.


Management provides ownership.


Internal Audit provides independent assurance.


Together, those elements can turn Green Book compliance from an annual exercise into a meaningful system for protecting public resources.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page