A Free Tool for Assessing GAO Green Book Compliance: Using Virginia's ARMICS Assessment Guides
- John C. Blackshire, Jr.

- 11 hours ago
- 9 min read
Governmental Organizations Don't Have to Start Their Green Book Assessment From Scratch
How does a governmental organization determine whether its system of internal control complies with the GAO Green Book?
That can be a surprisingly difficult question.
The U.S. Government Accountability Office's Standards for Internal Control in the Federal Government—better known as the Green Book—provides an excellent framework for internal control.
But reading the Green Book is one thing.
Turning its requirements into a practical organizational assessment is something else entirely.
Management needs a methodology for asking questions such as:
Do our controls address all five Green Book components?
Are the 17 principles adequately addressed?
Do our controls actually exist?
Are they properly designed?
Are they operating effectively?
What documentation supports our conclusions?
Where are our internal-control deficiencies?
How mature and reliable are our controls?
What corrective actions should management take?
Fortunately, governmental organizations don't necessarily need to create all of those assessment tools from scratch.
The Commonwealth of Virginia Department of Accounts has made its Agency Risk Management and Internal Control Standards—or ARMICS—Assessment Guides publicly available.
These tools provide governmental organizations with a practical starting point for developing their own Green Book internal-control assessment program.
What Is ARMICS?
ARMICS stands for:
Virginia's Department of Accounts developed ARMICS to strengthen how state agencies manage risk, safeguard public resources, improve operations, and maintain reliable financial reporting.
Virginia agencies perform annual self-assessments and certifications regarding their systems of internal control.
But what makes ARMICS particularly interesting to auditors and governmental managers outside Virginia is the assessment methodology and supporting tools.
The Virginia Department of Accounts provides downloadable assessment guides covering:
Control Environment
Risk Assessment
Control Activities
Information and Communication
Monitoring
Information-system general controls
Process-level controls
Transaction-level controls
Does that list look familiar?
It should.
It closely parallels the structure governmental auditors encounter when working with the GAO Green Book which is based on COSO.
Start With the GAO Green Book
Before using ARMICS, management needs to understand what it is assessing.
The 2025 GAO Green Book establishes standards for an effective internal-control system and became effective beginning with fiscal year 2026.
The Green Book organizes internal control around five components and 17 principles.
The five components are:
1. Control Environment
The foundation for the organization's system of internal control.
2. Risk Assessment
The process for identifying, analyzing, and responding to risks that could prevent achievement of objectives.
3. Control Activities
The actions management establishes through policies and procedures to respond to risks and achieve objectives.
4. Information and Communication
The processes used to obtain, generate, use, and communicate quality information.
5. Monitoring
The activities used to determine whether the internal-control system continues to operate effectively.
The Green Book then establishes principles underlying those five components.
The challenge is converting those principles into something management can actually assess.
That is where ARMICS can help.
Step 1 — Download the ARMICS Assessment Tools
The Virginia Department of Accounts provides its ARMICS assessment materials online.
Management can download individual Microsoft Word assessment guides or download the complete collection.
This is important because the files can serve as templates.
A governmental organization outside Virginia should not simply adopt the questionnaires and declare itself Green Book compliant.
Instead:
Use ARMICS as the starting point for developing an organization's own Green Book assessment methodology.
The tools should be customized for the organization's:
Mission
Organizational structure
Programs
Risks
Information systems
Funding sources
Laws and regulations
Grant requirements
Financial processes
Fraud exposures
Step 2 — Assess the Control Environment
ARMICS begins at the entity level.
Its Control Environment Assessment Guide includes separate assessment exhibits addressing:
Ethics
Management's commitment to professional and technical competence
Organizational structure
Assignment of authority and responsibility
Human-resource standards
These areas provide an excellent starting point for assessing the Green Book's Control Environment.
Management should examine more than whether policies exist.
For example:
Does the organization have a Code of Ethics?
That is a starting question.
But the better assessment asks:
Does management actually demonstrate a commitment to integrity and ethical values?
That requires evidence.
Consider:
Ethics policies
Employee training
Hotline activity
Disciplinary actions
Conflict-of-interest disclosures
Management communications
Board or governing-body oversight
Employee surveys
Investigation results
Management responses to misconduct
The distinction is critical.
Policy existence is not the same thing as control effectiveness.
Step 3 — Assess Risk Assessment
ARMICS provides separate tools for:
Risk Assessment
and
Risk Response
These can help management evaluate whether the organization has developed a systematic approach to identifying and responding to risks.
Under the 2025 Green Book, this area deserves particular attention.
GAO's updated standards emphasize risk areas including:
Fraud
Improper payments
Information security
Significant organizational or program changes
Management should therefore use the ARMICS questionnaires as a starting point and expand them to address the current Green Book requirements.
For each significant objective, ask:
What could prevent us from achieving the objective?
Then:
How likely is it?
What would be the impact?
What controls address the risk?
Is the remaining risk acceptable?
That begins transforming risk assessment from an annual compliance exercise into a management process.
Step 4 — Assess Control Activities
ARMICS becomes particularly useful when examining Control Activities.
The Virginia tools include assessment guides covering controls applicable to:
Fiscal processes
Accounting administration
General ledger activities
But ARMICS goes further.
It also provides questionnaires addressing important information-system general controls, including:
System risk assessment
Agency-wide security management
Access control
Application software development and change control
System software controls
Segregation of duties
Service continuity
That is extremely useful for a modern Green Book assessment.
Why?
Because governmental operations increasingly depend upon technology.
A control cannot necessarily be considered reliable simply because the employee operating it performs the control correctly.
Auditors also need to understand the technology supporting that control.
Step 5 — Assess Information and Communication
ARMICS provides separate questionnaires for:
Information
and
Communication
These can be used as the foundation for evaluating the Green Book's Information and Communication component.
Management should ask:
Does management receive the information it needs?
Is the information accurate?
Is it complete?
Is it timely?
Do employees understand their internal-control responsibilities?
Can employees communicate concerns upward?
Does information move across organizational boundaries?
Does the governing body receive information necessary for effective oversight?
This component is frequently underestimated.
An organization can have excellent control procedures and still experience significant control failures because important information never reaches the people who need it.
Step 6 — Assess Monitoring
ARMICS also provides a dedicated Monitoring Questionnaire.
Monitoring answers a critical question:
How does management know that its controls continue to work?
That is different from asking Internal Audit to find out.
Management owns internal control.
Management therefore needs processes for identifying when controls deteriorate.
Those processes might include:
Supervisory reviews
Control self-assessments
Exception reports
Performance indicators
Data analytics
Complaint analysis
Internal Audit findings
External audit findings
Regulatory findings
Corrective-action tracking
A mature organization does not wait for the annual audit to discover that a significant control stopped working nine months ago.
Step 7 — Go Below the Entity Level
One of the strongest aspects of the ARMICS approach is that it doesn't stop with an entity-level questionnaire.
ARMICS includes a second stage addressing process and transaction-level controls.
The available tools address areas such as:
Appropriations
Cash receipts
Cash disbursements
Expenditures
Prompt payment
Petty cash
Capital outlays
Purchase cards
Accounts receivable
Federal grants
Indirect costs
Reconciliations
Fixed assets
Information-system security
This is where a Green Book assessment becomes operational.
Management can move from:
“We believe our Control Activities component is effective.”
to determining whether significant processes actually contain properly designed and functioning controls.
Step 8 — Use ARMICS to Measure Control Reliability
Here is another reason auditors should examine the ARMICS methodology.
It doesn't simply ask yes-or-no questions.
ARMICS provides a five-level Internal Control Reliability Model.
The levels are:
Level 1 — Initial
Documentation is very limited, procedures are largely ad hoc, and monitoring is absent.
Level 2 — Informal
Controls may be repeatable but remain inconsistently documented and are not fully integrated into operations.
Level 3 — Systematic
Documentation becomes comprehensive, controls are formally standardized, and employees receive more structured communication and training.
Level 4 — Integrated
Control processes become integrated with organizational strategy and periodic monitoring occurs.
Level 5 — Optimized
Controls are supported by comprehensive documentation and training, continuous improvement is emphasized, and monitoring can become real-time.
This gives management something extremely valuable:
A way to think about internal-control maturity—not merely the existence of controls.
Effective Is Not the Same as Mature
Suppose a government finance department performs a monthly bank reconciliation.
The reconciliation is performed correctly every month.
The control might therefore be operating effectively.
But suppose:
Only one employee knows how to perform it.
Procedures haven't been documented.
The process relies on a complex spreadsheet.
Management doesn't monitor completion.
Exceptions aren't formally tracked.
Nobody has evaluated whether the process could be automated.
That may be an effective but relatively immature control.
Now consider another agency where:
Procedures are documented.
Responsibilities are assigned.
Employees are cross-trained.
Completion is monitored.
Exceptions are measured.
Supervisory review is documented.
Analytics identify unusual reconciling items.
Management periodically evaluates opportunities for automation.
The control objective may be identical.
The control capability is not.
ARMICS provides governmental organizations with a methodology for recognizing that difference.
Step 9 — Build a Green Book Crosswalk
A governmental organization using ARMICS should create a formal crosswalk.
For each Green Book principle, identify:
Green Book Component
Green Book Principle
Applicable ARMICS Questions
Organization-Specific Controls
Control Owner
Supporting Evidence
Design Effectiveness
Operating Effectiveness
Control Reliability/Maturity
Deficiencies
Corrective Action
Responsible Party
Target Completion Date
The result might look like this:
Green Book Area | ARMICS Assessment | Current Reliability | Target |
Control Environment | Ethics, competence, authority, HR | 3 | 4 |
Risk Assessment | Risk assessment and response | 2 | 4 |
Control Activities | Fiscal, accounting and IT controls | 3 | 4 |
Information & Communication | Information and communication questionnaires | 3 | 4 |
Monitoring | Monitoring questionnaire | 2 | 4 |
Now management has something far more useful than a statement saying:
“We comply with the Green Book.”
Management has a roadmap for improving internal control.
Step 10 — Validate the Answers
This is probably the most important warning.
Do not turn ARMICS into a checklist exercise.
The Virginia Department of Accounts itself warns that its tools are not all-inclusive and cannot replace analysis and professional judgment.
More importantly, completing a questionnaire does not prove that a control exists or operates effectively.
If management answers:
“Yes, supervisors review monthly reconciliations.”
someone should verify it.
Select reconciliations.
Inspect the evidence.
Determine:
Was the review actually performed?
Was it timely?
Was the reviewer qualified?
Were exceptions investigated?
Was corrective action taken?
Is there evidence demonstrating the review?
That is the difference between self-assessment and assurance.
Management and Internal Audit Have Different Roles
Management owns the system of internal control.
Management should therefore perform or oversee the Green Book self-assessment.
Internal Audit can then independently evaluate:
The assessment methodology
Management's conclusions
Supporting evidence
Design effectiveness
Operating effectiveness
Identified deficiencies
Reliability ratings
Corrective-action plans
Internal Audit should not become the owner of management's internal-control system simply because auditors understand internal controls.
That distinction is fundamental to maintaining Internal Audit's independence.
ARMICS Is a Starting Point—Not a Substitute for the Green Book
Governmental organizations outside Virginia should recognize an important limitation.
ARMICS is a Commonwealth of Virginia internal-control program.
It is not the GAO Green Book.
And an ARMICS questionnaire by itself does not establish Green Book compliance.
The organization should use the current 2025 GAO Green Book as its criteria and use ARMICS as an assessment methodology and source of practical tools.
That means management should:
Start with the Green Book.
Crosswalk the 17 principles.
Adapt the ARMICS questionnaires.
Add organization-specific risks and controls.
Document supporting evidence.
Test significant controls.
Identify deficiencies.
Measure reliability and maturity.
Develop corrective-action plans.
Monitor improvement.
That is a much stronger methodology than simply completing a checklist.
A Valuable Free Resource for Governmental Organizations
Governmental organizations spend significant amounts of money developing internal-control assessment methodologies.
Before building another one from scratch, take a look at what the Commonwealth of Virginia has already made publicly available.
The ARMICS Assessment Guides provide a practical collection of tools addressing:
Entity-level controls
Risk assessment
Fiscal controls
IT general controls
Information and communication
Monitoring
Process-level controls
Transaction-level controls
Control reliability
Combined with the 2025 GAO Green Book, these tools can provide the foundation for a comprehensive governmental internal-control assessment.
The ultimate objective should not be:
“Can we check the Green Book compliance box?”
The better objective is:
“Can we demonstrate that our system of internal control is properly designed, operating effectively, appropriately documented, and capable of improving as our risks change?”
That is what governmental accountability should look like.
Strengthen Your Green Book Knowledge With CCS
Corporate Compliance Seminars provides CPE training for governmental auditors, internal auditors, financial managers, compliance professionals, and other professionals responsible for internal control.
CCS's GAO Green Book Compliance Academy provides intensive training on applying the Green Book to governmental organizations and evaluating internal-control systems.
Governmental organizations can use training of this type together with practical resources such as ARMICS to move beyond simply understanding the Green Book toward actually assessing, documenting, testing, and improving their system of internal control.
The Green Book provides the standards.
ARMICS provides useful assessment tools.
Management provides ownership.
Internal Audit provides independent assurance.
Together, those elements can turn Green Book compliance from an annual exercise into a meaningful system for protecting public resources.
Comments