top of page
Search

The 2025 GAO Green Book and AI: Why Strong Internal Controls Matter More Than Ever

Artificial Intelligence is transforming government operations at every level.


Federal agencies, state governments, municipalities, educational institutions, healthcare organizations, and nonprofit entities are rapidly adopting AI to automate workflows, improve citizen services, detect fraud, analyze spending, and strengthen decision-making. At the same time, these technologies introduce new risks involving cybersecurity, data integrity, privacy, model governance, and accountability.


As government operations become increasingly digital, one thing has not changed:

Strong internal controls remain the foundation of effective governance.


That is precisely why the 2025 revision of the GAO Green Book (Standards for Internal Control in the Federal Government) is so important. The updated standards place greater emphasis on fraud risk, improper payments, information security, preventive controls, and accountability, helping organizations address today's rapidly changing risk environment.


The GAO Green Book Standards CPE program from Corporate Compliance Seminars helps government professionals, auditors, compliance officers, grant administrators, and internal control specialists understand how to implement these updated standards while preparing their organizations for the challenges created by Artificial Intelligence and digital transformation.


What Is the GAO Green Book?

The GAO Green Book, formally titled Standards for Internal Control in the Federal Government, provides the framework federal agencies use to design, implement, operate, and continuously improve effective systems of internal control. This is the GAO improved edition of the COSO framework. The GAO has done an excellent job of improving the documentation of an effective internal control framework compared to the COSO documentation.


Although written for the federal government, the Green Book is widely used by:

  • State governments

  • County governments

  • Municipal governments

  • School districts

  • Universities

  • Tribal governments

  • Healthcare organizations

  • Nonprofits

  • Government contractors

  • Organizations managing federal grants


The framework helps management achieve three fundamental objectives:

  • Effective and efficient operations

  • Reliable reporting

  • Compliance with laws and regulations


These objectives are as relevant to AI-enabled organizations as they were before the rise of intelligent technologies.


Why the 2025 Green Book Matters

Government programs are becoming more complex.


Agencies increasingly manage:

  • Artificial Intelligence initiatives

  • Cloud computing

  • Cybersecurity risks

  • Large grant programs

  • Digital citizen services

  • Data analytics

  • Automated financial systems

  • Third-party service providers


Recognizing these changes, GAO updated the Green Book in 2025 to strengthen guidance in several important areas, including:

  • Fraud risk

  • Improper payments

  • Information security

  • Preventive controls

  • Risk documentation

  • Accountability across all organizational levels

  • Managing new and significantly changed programs


These updates reflect the reality that modern internal control systems must evolve as technology and risks evolve.


AI Is Creating New Internal Control Challenges

Artificial Intelligence improves productivity.


It also creates entirely new categories of risk.


Organizations now need internal controls over:

  • AI-generated decisions

  • Machine learning models

  • Automated workflows

  • Data quality

  • Prompt management

  • AI access controls

  • Human review of AI outputs

  • Model monitoring

  • AI cybersecurity

  • Regulatory compliance


Internal auditors increasingly ask questions such as:

  • Who approved the AI model?

  • What data trained the model?

  • How are AI outputs validated?

  • Can management override AI decisions?

  • Are AI activities logged?

  • How are changes monitored?

  • Who is accountable when AI produces incorrect results?


The Green Book's principles of governance, risk assessment, control activities, information and communication, and monitoring provide an excellent framework for answering these questions—even though AI itself did not exist when earlier versions of the framework were developed.


The Five Components Still Drive Effective Governance

The Green Book organizes internal control into five integrated components:


1. Control Environment: Leadership establishes integrity, ethical values, accountability, and organizational culture.

Organizations implementing AI need executives who clearly define acceptable AI use and establish governance over emerging technologies.


2. Risk Assessment: Management identifies risks that could prevent achievement of organizational objectives.


Today those risks include:

  • AI bias

  • Cybersecurity

  • Privacy

  • Data quality

  • Fraud

  • Third-party vendors

  • Automated decision-making


3. Control Activities: Management designs controls to mitigate identified risks.


Examples include:

  • Approval workflows

  • Access controls

  • Segregation of duties

  • Preventive controls

  • Automated validations

  • AI governance reviews


4. Information and Communication: Reliable information must reach decision makers in a timely manner.


As organizations increasingly depend on AI-generated insights, controls over data accuracy and communication become even more important.


5. Monitoring: Internal control systems require continuous monitoring and improvement.


Organizations should regularly evaluate whether both traditional controls and AI-related controls remain effective as technology changes.


These five components continue to provide one of the strongest governance frameworks available for public-sector organizations.


Fraud Prevention Begins with Strong Internal Controls

Government agencies manage billions of taxpayer dollars every year.


Without effective internal controls, organizations become more vulnerable to:

  • Fraud

  • Improper payments

  • Procurement abuse

  • Grant misuse

  • Payroll fraud

  • Cybercrime

  • Financial reporting errors

  • Asset misappropriation


The updated Green Book places increased emphasis on identifying and preventing these risks through proactive internal control systems rather than relying solely on detective controls after losses occur.


AI Will Improve Internal Auditing—Not Replace Internal Auditors

Internal Audit departments are rapidly adopting AI to improve efficiency.


Today's auditors use AI to:

  • Analyze large transaction populations

  • Review contracts

  • Summarize policies

  • Identify unusual transactions

  • Draft audit programs

  • Prepare workpapers

  • Generate executive summaries

  • Research regulations

  • Assist with risk assessments


These tools save time.


However, AI cannot replace:

  • Professional judgment

  • Ethical decision-making

  • Risk prioritization

  • Governance oversight

  • Board communication

  • Independent assurance


Those responsibilities remain firmly with experienced audit and compliance professionals.


What You'll Learn in the GAO Green Book Standards CPE Program

The GAO Green Book Standards course from Corporate Compliance Seminars is built around the 2025 revision of the Green Book and provides practical guidance for implementing effective internal control systems. Participants learn how to:

  • Understand the five components, 17 principles, and 52 attributes of the Green Book

  • Apply the framework to operational, compliance, fraud, and information security risks

  • Evaluate internal control effectiveness using maturity concepts

  • Align Green Book principles with COSO

  • Strengthen risk assessment and monitoring processes

  • Support compliance with Uniform Guidance and federal grant requirements

  • Build a stronger culture of accountability and continuous improvement

  • Apply Green Book concepts to modern AI-enabled business processes and government operations


The course focuses on translating the Green Book from a compliance document into a practical management framework that improves organizational performance and governance.


Who Should Attend?

This program is ideal for professionals responsible for governance, compliance, and accountability, including:

  • Internal Auditors

  • Government Auditors

  • Compliance Officers

  • Federal Managers

  • State and Local Government Officials

  • Grant Administrators

  • Inspectors General Staff

  • Risk Managers

  • Financial Managers

  • Program Managers

  • School District Administrators

  • Government Contractors


Whether your organization is implementing new AI tools, managing federal grants, or strengthening enterprise risk management, the Green Book provides a proven framework for building resilient internal controls.


The Future of Government Accountability

Artificial Intelligence will continue transforming public-sector operations.


Digital services will expand.


Cyber threats will evolve.


Federal funding programs will become increasingly complex.


The organizations that succeed will not simply adopt new technologies—they will implement strong governance structures that ensure those technologies operate responsibly, transparently, and effectively.


The GAO Green Book provides exactly that foundation.


If you are responsible for internal controls, government auditing, compliance, enterprise risk management, or federal grant oversight, the GAO Green Book Standards CPE program from Corporate Compliance Seminars provides practical, immediately applicable guidance for implementing one of the most respected internal control frameworks in government while preparing your organization for the AI-driven future.

 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page