top of page
GAO Green Book Compliance Academy - In-Person

GAO Green Book Compliance Academy - In-Person

Confirmed Event in Miami on Monday-Wednesday, September 21-23, 2026

 

Implement the 2025 GAO Green Book with Practical, Defensible Internal Controls

 

The GAO Green Book Compliance Academy is an intensive three-day, in-person CPE program focused on implementing the 2025 Standards for Internal Control in the Federal Government.

 

The 2025 Green Book supersedes the 2014 edition and is effective beginning with fiscal year 2026. It strengthens requirements and implementation guidance involving fraud, improper payments, information security, significant organizational and program changes, preventive controls, risk-assessment documentation, and management accountability.

 

The course is designed around the Green Book’s five components, 17 principles, supporting attributes, and the direct linkage between organizational objectives, risks, control activities, documentation, monitoring, and remediation. The accompanying course materials emphasize practical implementation guidance rather than theory alone.

 

Why Attend the GAO Green Book Compliance Academy?

Government organizations do not satisfy the Green Book merely by maintaining policies or completing an annual checklist.

 

An effective internal control system must be:

  • Properly designed.
  • Implemented throughout the organization.
  • Operating as intended.
  • Supported by appropriate evidence.
  • Evaluated against organizational objectives and risks.
  • Monitored and improved when deficiencies are identified.

 

The academy gives attendees a structured approach for performing this work.

 

Participants will examine how management can establish accountability, define objectives, assess risks, design preventive and detective controls, evaluate deficiencies, document conclusions, and support an overall assessment of internal control effectiveness.

 

What Is the GAO Green Book?

The Green Book establishes the standards for an effective internal control system within federal agencies. It may also be adopted by state, local, quasi-governmental, and nonprofit organizations as an internal control framework.

 

Internal control helps an organization:

  • Accomplish its operational and program objectives.
  • Produce reliable financial and nonfinancial information.
  • Comply with applicable laws, regulations, grant requirements, and contractual obligations.
  • Detect and respond to fraud, improper payments, cybersecurity threats, and other significant risks.

 

The Green Book describes internal control as an integrated and continuous process, carried out by people, that provides reasonable—not absolute—assurance that organizational objectives will be achieved.

 

Major Changes in the 2025 GAO Green Book

The five components and 17 principles remain intact. However, the 2025 revision substantially modernizes the implementation guidance and documentation expectations.

 

The academy addresses the most consequential changes, including:

 

Fraud and Improper Payments

Management must more explicitly identify, analyze, and respond to fraud risks and risks of improper payments. Attendees will examine how preventive and detective controls should be incorporated into program operations rather than treated as an after-the-fact audit exercise.

Information Security and Technology Risk

The revised Green Book strengthens the consideration of information security risks within the internal control system. The course addresses cybersecurity governance, access controls, system changes, data integrity, technology dependencies, and coordination among program management, information technology, cybersecurity, compliance, and audit functions.

Significant Changes

Management should establish and document a process for identifying, analyzing, and responding to risks caused by significant organizational, technological, regulatory, staffing, vendor, or program changes.

Expanded Documentation

Management must maintain evidence supporting the design, implementation, operation, and evaluation of the internal control system. Documentation should support risk assessments, control responsibilities, control performance, identified deficiencies, corrective actions, and management’s conclusions.

Preventive Control Activities

The 2025 Green Book places greater emphasis on prioritizing preventive control activities where practical rather than relying primarily on controls that detect problems after they occur.

Management Accountability

Internal control is management’s responsibility at every organizational level. Auditors assess management’s system; they do not own or operate it. The course addresses the responsibilities of oversight bodies, executives, program managers, financial managers, information technology personnel, control owners, and other employees.

 

Practical Tools and Implementation Techniques

The academy incorporates practical concepts that attendees can adapt to their organizations, including:

  • Objective-risk-control-assessment linkage.
  • Green Book control mapping.
  • Risk-and-control matrices.
  • Control inventories.
  • Entity-level control assessments.
  • Control self-assessments.
  • Fraud-risk assessments.
  • Information-technology risk assessments.
  • Third-party risk assessments.
  • Significant-change assessments.
  • Internal control maturity models.
  • Control-deficiency aggregation.
  • Root-cause analysis.
  • Corrective-action tracking.
  • Remediation and retesting.
  • Continuous monitoring and data analytics.
  • Management reporting and oversight dashboards.

 

The course materials specifically recognize the Green Book’s relevance to government program and financial managers, auditors, CPA firms auditing federal expenditures, compliance personnel, government contractors, nonprofit organizations, and other internal-control professionals.

 

Benefits to Your Organization

After attending, participants will be better prepared to help their organizations:

  • Establish clear ownership of internal controls.
  • Align controls with mission and program objectives.
  • Identify significant risks before they become failures.
  • Strengthen fraud and improper-payment prevention.
  • Improve cybersecurity and information-security controls.
  • Respond more effectively to organizational and program changes.
  • Produce reliable evidence that controls are operating.
  • Identify and remediate control deficiencies.
  • Improve accountability for federal awards and public resources.
  • Prepare for internal audits, external audits, Inspector General reviews, and management assurance reporting.
  • Build a sustainable culture of internal control and continuous improvement.

 

Take Control of Green Book Implementation

The 2025 Green Book is not merely an audit reference. It is management’s framework for designing, implementing, operating, and evaluating an effective internal control system.

 

Reserve your spot today and unlock your full potential in federal compliance and operational excellence!

  • Details on Event Presentation

    The sessions will be as follows:

    Monday – 9:00 a.m. to 4:45 p.m.

    Tuesday - 9:00 a.m. to 4:45 p.m.

    Wednesday - 9:00 a.m. to 4:00 p.m.

    Offered in-person in various cites each month on Monday-Wednesdays in sessions.

    We can schedule private events on your timetable for two or more attendees.

    NASBA Program Disclosure

    Program Level of Understanding: Basic

    Prerequisites: None

    Advance Preparation: None

    Delivery Format: Seminar (Group Internet Based)

    NASBA Field(s) of Study: Auditing, Information Technology

    CPE Credits: 24, based on 50 minutes of instruction per hour

  • CPE Event Highlights

    In this academy, we will cover important topics such as the GAO Green Book Context, COSO Framework to the GAO Green Book, risk assessment, inventorying controls, policies vs procedures, root cause analysis, communication challenges, and much more.

    Our aim is to provide a deep understanding of GAO Green Book compliance and equip you with practical strategies to implement within your organization.

    The seminar reviews the following:

    • The Components of Green Book framework
    • Logic behind the Green Book Components
    • The structure used to describe the COSO Framework as used in the GAO Green Book
    • Principles present in the GAO Green Book Framework
    • The "Attributes" in the GAO Green Book vs the "Points of Focus" in COSO Framework
    • The importance of the "Attributes"
    • How to gage the effectiveness of internal controls
  • Learning Objectives

    By completing the academy, participants should be able to:

    • Explain the purpose and structure of the 2025 GAO Green Book.
    • Describe the relationship among organizational objectives, risks, controls, and assessments.
    • Apply the five components and 17 principles of internal control.
    • Use the Green Book attributes as implementation guidance.
    • Define responsibilities for oversight bodies, management, control owners, and auditors.
    • Identify operational, reporting, compliance, fraud, improper-payment, information-security, and change-related risks.
    • Design preventive and detective control activities.
    • Develop a practical inventory of significant internal controls.
    • Evaluate whether controls are properly designed and implemented.
    • Test whether controls are operating as intended.
    • Assess and aggregate internal control deficiencies.
    • Document risk assessments, control activities, testing evidence, and conclusions.
    • Establish corrective-action, remediation, and retesting procedures.
    • Evaluate whether the five components are present, functioning, and operating together.
    • Support management’s overall assessment of internal control effectiveness.
    • Develop a sustainable Green Book compliance and continuous-improvement program.
    •  
  • Key Issues on the Agenda

    Day One — Internal Control Foundations and the Green Book Framework

    The Importance of Internal Control and Auditing

    • Why organizations need internal control.
    • Common misconceptions about internal controls.
    • Internal control as an integrated part of operations.
    • Internal control as organizational quality control.
    • Management’s responsibility for internal control.
    • The auditor’s assurance and advisory responsibilities.
    • Coordination among operations, compliance, risk management, legal, information technology, and audit functions.
    • Linking organizational objectives, inherent risks, control objectives, and control assessments.

    COSO and the Development of the Green Book

    • COSO’s Internal Control—Integrated Framework.
    • The relationship between COSO and the GAO Green Book.
    • Operations, reporting, and compliance objectives.
    • The internal control cube.
    • Entity-level, process-level, transaction-level, and technology controls.
    • The relationship between the Green Book and the Yellow Book.
    • The relationship among the Federal Managers’ Financial Integrity Act, the Green Book, and OMB Circular A-123.
    • Application to federal, state, local, quasi-governmental, nonprofit, grant-funded, and contractor organizations.

    Components, Principles, and Attributes

    • The five components of internal control.
    • The 17 principles supporting the components.
    • The role of attributes in designing and evaluating controls.
    • When a principle may not be relevant.
    • Required management documentation.
    • Applying professional judgment based on mission, size, complexity, risk, technology, and regulatory environment.

    The course materials explain that the components and principles are necessary for an effective internal control system and that management should document its rationale in the rare situation where a principle is considered irrelevant.

    Day Two — The 2025 Green Book and Risk-Based Implementation

    Understanding the 2025 Revision

    • What changed from the 2014 Green Book.
    • What remained unchanged.
    • Effective-date considerations.
    • Expanded risk-assessment expectations.
    • Documentation of risk-assessment results.
    • Significant-change assessments.
    • Preventive and detective controls.
    • New implementation resources and appendixes.
    • Responsibilities of staff at every organizational level.

    Risk Assessment

    • Defining measurable organizational and program objectives.
    • Establishing risk tolerances.
    • Identifying inherent risks.
    • Evaluating likelihood, magnitude, velocity, and duration.
    • Assessing fraud risk.
    • Assessing improper-payment risk.
    • Assessing information-security and cybersecurity risk.
    • Evaluating risks created by new or substantially changed programs.
    • Identifying third-party, contractor, vendor, grant-recipient, and subrecipient risks.
    • Selecting appropriate risk responses.
    • Connecting identified risks to control objectives and control activities.

    Control Environment

    • Integrity and ethical values.
    • Tone at the top and throughout the organization.
    • Oversight-body responsibilities.
    • Organizational structure and delegation of authority.
    • Competence and workforce capability.
    • Accountability for control performance.
    • Standards of conduct.
    • Responding to deviations and misconduct.
    • Establishing business-process owners and control owners.

    Control Activities

    • Preventive versus detective controls.
    • Manual and automated controls.
    • Approvals, authorizations, reconciliations, verifications, and supervisory reviews.
    • Segregation of duties.
    • Physical and logical access controls.
    • General controls over information technology.
    • Policies, procedures, standards, and operating practices.
    • Evidence that controls were performed.
    • Control rationalization and elimination of redundant controls.

    Day Three — Evaluation, Documentation, Testing, and Improvement

    Information and Communication

    • Identifying relevant and reliable information.
    • Information produced by the entity.
    • Data quality, completeness, accuracy, and timeliness.
    • Internal communication.
    • Communication with oversight bodies.
    • External reporting.
    • Whistleblower and escalation channels.
    • Communication with service organizations, contractors, vendors, grant recipients, subrecipients, and other external parties.

    Monitoring Activities

    • Ongoing monitoring.
    • Separate evaluations.
    • Management reviews.
    • Control self-assessments.
    • Internal audit evaluations.
    • External audit findings.
    • Data analytics and exception reporting.
    • Communicating deficiencies.
    • Corrective-action plans.
    • Tracking remediation.
    • Retesting corrected controls.
    • Continuous improvement.

    Management’s Evaluation of Internal Control

    Management must determine whether each component and related principle is effectively designed, implemented, and operating. A control cannot operate effectively when it was not properly designed or implemented.

    The academy addresses:

    • Design effectiveness.
    • Implementation effectiveness.
    • Operating effectiveness.
    • Missing and inadequately designed controls.
    • Controls that were not properly implemented.
    • Controls that did not operate consistently.
    • Evaluating the magnitude, likelihood, and nature of deficiencies.
    • Aggregating related deficiencies.
    • Determining whether components are operating together.
    • Supporting management’s overall conclusion.

    Documentation and Audit Evidence

    • Risk-and-control matrices.
    • Process narratives and flowcharts.
    • Control inventories.
    • Policies and procedures.
    • Evidence of control performance.
    • Walkthrough documentation.
    • Testing plans.
    • Sampling and inquiry.
    • Observation and inspection.
    • Reperformance.
    • Testing automated controls.
    • Documentation of exceptions.
    • Deficiency evaluation.
    • Corrective-action documentation.
    • Management certifications and subcertifications.
    • Workpaper conclusions.
  • Summary of the Subject Matter

    This CPE event titled "GAO Green Book Compliance Academy - In-Person" offers an in-depth exploration of the Government Accountability Office (GAO) Green Book, focusing on compliance requirements and best practices applicable to federal agencies. This event provides crucial insights for professionals involved in ensuring adherence to the GAO Green Book standards within their organizations.

    Key areas covered in this event may include:

    • Overview of GAO Green Book: A comprehensive examination of the principles, standards, and guidelines outlined in the GAO Green Book, providing professionals with a clear understanding of its significance in the federal compliance landscape.

    • Internal Control Framework: Insights into the internal control framework prescribed by the GAO Green Book, emphasizing the components and criteria necessary for achieving effective, efficient, and compliant operations within federal agencies.

    • Risk Assessment and Mitigation: Guidance on conducting risk assessments, identifying vulnerabilities, and implementing mitigation strategies aligned with the GAO Green Book's requirements.

    • Compliance Monitoring and Reporting: Best practices for monitoring compliance with GAO Green Book standards and reporting on internal controls, aiming to ensure transparency and accountability in federal agency operations.

    • Implementation Considerations: Practical considerations for implementing GAO Green Book standards, addressing common challenges, and leveraging opportunities to streamline compliance efforts.

    By addressing these critical aspects, the CPE event aims to equip professionals with the knowledge and tools necessary to navigate the complexities of the GAO Green Book, fostering a culture of compliance excellence and accountability within federal agencies.

  • Authoritative Sources

    After attending the CPE event focused on GAO Green Book Compliance Academy, it's crucial to further expand your knowledge by exploring authoritative sources in this domain. Here are relevant sources along with their web links:

    By leveraging these authoritative sources, attendees can enhance their knowledge and expertise in compliance and internal control standards as delineated in the GAO Green Book, thereby fostering a more comprehensive grasp of the subject matter.

$2,160.00Price
0/20
0/20
Quantity

Subscribe Form

Thanks for submitting!

479-200-4373

  • Facebook
  • Twitter
  • LinkedIn
  • Twitter
  • LinkedIn
  • Facebook

©2026 by The Accountware Group. Proudly created with Wix.com

bottom of page