top of page
Search

The GAO Green Book Changed for FY2026: Government Auditors and Managers Need to Understand What Changed

GAO Green Book Standards — Wednesday, October 28, 2026

The GAO Green Book is not simply another government compliance manual.

It provides the framework federal agencies use to design, implement, operate, and evaluate an effective system of internal control. The framework is also highly relevant to state and local governments, grant recipients, public authorities, government contractors, auditors, and other organizations responsible for public funds.


And in 2026, there is an especially important reason to revisit it:

GAO issued a substantially revised Green Book in 2025, and that revision became effective beginning with fiscal year 2026.

The new edition supersedes the 2014 Green Book and adds stronger requirements and guidance concerning fraud, improper payments, information security, significant organizational change, documentation, and preventive controls.


Corporate Compliance Seminars is presenting its GAO Green Book Standards webinar on:

Wednesday, October 28, 2026


The live program provides 4 CPE credits in Auditing and runs from 10:00 a.m. to 2:30 p.m. Central Time.



What Is the GAO Green Book?


The formal title is: Standards for Internal Control in the Federal Government


The Government Accountability Office describes internal control as a process management uses to help an agency achieve its objectives. The Green Book provides standards for an effective internal-control system supporting three categories of objectives:

  • Operations

  • Reporting

  • Compliance.


The logic is straightforward:


Objectives

Risks

Controls

Information

Monitoring

Achievement of Mission


That is why the Green Book should matter to far more people than auditors.

Internal control is fundamentally a management responsibility.


The 2025 Green Book Is Now the Standard

Anyone relying primarily on the 2014 Green Book needs to update their knowledge.


GAO issued the revised Green Book in May 2025. It became effective beginning with fiscal year 2026 and for Federal Managers' Financial Integrity Act reports covering that year.

Early implementation was permitted.


GAO says the revision was designed in part to help management address risks involving:

  • Fraud

  • Improper payments

  • Information security

  • New or substantially changed programs

  • Emergency assistance programs.


Those changes reflect what government organizations have experienced over the last decade.


The risk environment has changed.


The internal-control system needs to change with it.


The Green Book Retains the COSO Architecture

The Green Book continues to align closely with the COSO Internal Control—Integrated Framework.


CCS's program examines the framework through its:

  • 5 Components

  • 17 Principles

  • and related Attributes.


The five components are:


Control Environment

The foundation of the organization—integrity, ethics, accountability, competence, organizational structure, and governance.


Risk Assessment

Determining objectives and identifying the risks that could prevent their achievement.


Control Activities

The policies, procedures, approvals, reconciliations, segregation of duties, technology controls, and other activities used to respond to risk.


Information and Communication

Getting reliable information to the people who need it when they need it.


Monitoring

Determining whether the internal-control system continues to operate effectively.


These components should not operate independently.


They form a system of internal control.


Start With the Objective

One of the most useful ways to understand the Green Book is to begin with a deceptively simple question:

What are we trying to accomplish?

Without a clearly defined objective, meaningful risk assessment becomes difficult.


Suppose a government program's objective is:

Provide eligible recipients with accurate benefit payments on a timely basis and in accordance with applicable laws and regulations.

Now management can ask:


What could prevent that objective from being achieved?


Perhaps:

  • Payments to ineligible recipients

  • Duplicate payments

  • Incorrect benefit calculations

  • Fraudulent applications

  • Unauthorized changes to recipient information

  • Cyberattacks

  • System failures

  • Inaccurate source data


Now the organization can design controls.


The logic becomes:


Objective

Risk

Control


That relationship is at the heart of effective internal control.


The New Green Book Puts More Attention on Risk Assessment Documentation

One of the important 2025 changes involves documentation.


GAO now specifically emphasizes documentation of the results of risk assessments, including the identification, analysis, and response to risks.


This is important.


It is not enough for management to say:

“We understand our risks.”

The organization should be able to demonstrate:

  • What are the objectives?

  • What risks were identified?

  • How were those risks analyzed?

  • Which risks require responses?

  • What responses were selected?

  • Which controls implement those responses?


That creates an auditable trail:


Objective

Risk

Risk Assessment

Risk Response

Control

Evidence


Fraud Risk Receives Greater Attention

Government programs can be attractive fraud targets because they frequently involve large volumes of transactions, public funds, benefits, grants, procurement, contractors, and third parties.


GAO specifically identifies fraud as one of the risk areas receiving additional attention in the revised Green Book.


Management should therefore think beyond:

“Could something accidentally go wrong?”

and ask:

“How could someone intentionally defeat this process?”

That means considering:

  • Asset misappropriation

  • Procurement fraud

  • Grant fraud

  • Payroll fraud

  • False claims

  • Conflicts of interest

  • Corruption

  • Management override

  • Collusion

  • Cyber-enabled fraud


The distinction matters because controls designed for accidental error may not be sufficient to address deliberate circumvention.


Improper Payments Are Now Explicitly Important

The revised Green Book also strengthens attention to improper payments.


That is especially important for government programs administering benefits, grants, reimbursements, contracts, loans, and other public expenditures.


An improper payment may involve:

  • Wrong recipient

  • Wrong amount

  • Duplicate payment

  • Ineligible recipient

  • Unsupported payment

  • Payment made without adequate documentation


The internal-control question becomes:

Which preventive control should stop the improper payment before public money leaves the organization?

That leads directly to another major theme in the new Green Book.

Preventive Controls Deserve Priority

GAO's 2025 revision emphasizes prioritizing preventive control activities.


That is a significant management concept.


Consider two approaches.


Detective Model

Payment occurs.

Exception report identifies the problem.

Management investigates.

Organization attempts recovery.


Preventive Model

System identifies the problem.

Transaction is stopped.

Exception requires resolution.

Only authorized transaction proceeds.


Both preventive and detective controls matter.


But when practical, preventing fraud, error, or improper payment before it occurs can be substantially better than trying to recover public money afterward.


Information Security Is an Internal-Control Issue

Cybersecurity should not be viewed solely as an IT department responsibility.


GAO specifically expanded attention to information-security risks in the revised Green Book.


Consider how dependent government operations have become on technology:

  • Eligibility systems

  • Financial systems

  • Procurement systems

  • Payroll

  • Grant systems

  • Databases

  • Cloud services

  • Contractor systems

  • Electronic payments


If those systems cannot be trusted, many of the controls dependent upon them cannot be trusted either.


Management therefore needs to connect:


Information Security Risk

Business Objective

Internal Control


That makes cybersecurity part of the organization's broader system of internal control.


Significant Change Now Requires More Attention

Another particularly important revision concerns change.


GAO added documentation requirements around a change-assessment process for identifying, analyzing, and responding to risks arising from significant changes.


Consider what can change:

  • Leadership

  • Employees

  • Technology

  • Funding

  • Legislation

  • Regulations

  • Programs

  • Contractors

  • Organizational structure

  • Cyber threats

  • Artificial intelligence


A control system designed around yesterday's organization may not adequately manage today's risks.


A strong change process asks:

What changed?
Which objectives are affected?
Which risks changed?
Are existing controls still appropriate?
Do we need new controls?

That is much stronger than discovering the control gap during next year's audit.


Management Owns the Controls

One of the most important concepts reinforced in the revised Green Book is management's responsibility for internal control throughout the organization.


GAO emphasizes responsibility at all levels within the entity's organizational structure, including program and financial managers.


That distinction is fundamental.

  • Internal Audit does not own internal control.

  • The external auditor does not own internal control.

  • The Inspector General does not own internal control.

  • Management owns internal control.


Auditors provide assurance.


Management operates the organization.


How Mature Is Your Green Book Control System?

The CCS program goes beyond simply identifying components and principles. It includes management evaluation, design, implementation, operation, and maturity-model evaluation.


That raises a better question than:

“Do we comply with the Green Book?”

Ask:

“How mature is our Green Book internal-control system?”

A practical five-level maturity model might be:

  • Level 1 — Initial

    • Controls are informal and heavily dependent upon individuals.

  • Level 2 — Developing

    • Policies and controls exist but are inconsistently documented or applied.

  • Level 3 — Defined

    • Objectives, risks, controls, ownership, and responsibilities are formally established.

  • Level 4 — Managed

    • Control effectiveness is measured. Risk indicators, exceptions, deficiencies, and corrective actions are actively monitored.

  • Level 5 — Optimized

    • Internal control is integrated into day-to-day management and continuously improved as objectives and risks change.


Interestingly, GAO itself noted during development of the revised standards that in a mature and highly effective internal-control system, internal control may become essentially indistinguishable from employees' normal day-to-day activities.


That is an excellent description of maturity.


Design, Implementation and Operation

CCS's October program specifically examines three important stages:

  • Design

  • Implementation

  • Operation.


These should not be confused.


Design

Is the control capable of addressing the identified risk?


Implementation

Has the organization actually put the control into place?


Operation

Did the control operate as designed?


This distinction prevents one of the most common internal-control mistakes:

Assuming a control is effective simply because a policy says it exists.

A beautifully written procedure manual proves very little about whether controls actually operate.


Auditors Need to Follow the Evidence

For each significant risk, auditors should be able to trace:


Objective

Risk

Control

Control Owner

Procedure

Evidence

Testing

Exception

Corrective Action

Monitoring


That is considerably more valuable than a Green Book compliance checklist.


The objective isn't simply to determine whether the organization can point to all 17 principles.


t is to determine whether the internal-control system actually supports the achievement of the organization's mission.


Who Should Attend?

CCS designed the program for government professionals, auditors, compliance officers, advisors, and others responsible for internal control implementation and evaluation.


It is particularly relevant for professionals working with:

  • Federal agencies

  • State and local governments

  • Public authorities

  • Federal grants

  • Uniform Guidance

  • Government contractors

  • Internal Audit

  • Compliance

  • Program management

  • Financial management


The program also addresses the relationship between Green Book compliance and Uniform Administrative Requirements Section 200.303.


October 28 Is a Good Time to Revisit the Green Book

The Wednesday, October 28, 2026 program comes during the first fiscal year in which the 2025 Green Book revision is effective for federal agencies.


That makes this more than a refresher on a familiar internal-control framework.


Government professionals need to understand the increased emphasis on:

  • Fraud risk

  • Improper payments

  • Information security

  • Preventive controls

  • Documented risk assessments

  • Significant change

  • Management responsibility

and the continuing expectation that organizations design, implement, operate, and evaluate an effective internal-control system.


The Bottom Line: The Green Book Is About Achieving Objectives

The Green Book should not become another binder sitting on a shelf.


Its logic is much more useful:


What are our objectives?

What could prevent us from achieving them?

What controls address those risks?

Are those controls properly designed?

Have they been implemented?

Are they operating effectively?

How do we know?

What needs to improve?


That is internal control.


And the 2025 Green Book makes that conversation particularly relevant in 2026.


Corporate Compliance Seminars' GAO Green Book Standards webinar on Wednesday, October 28, 2026 provides 4 CPE credits in Auditing and focuses on turning the Green Book from a set of government standards into a practical framework for improving internal control, risk management, compliance, and accountability.


 
 
 

Recent Posts

See All

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page