Volume I - Financial Management
Chapter 05 – Management’s Responsibility for Internal Controls
Questions concerning this policy chapter should be directed to:
0501 Overview
This chapter establishes the Department of Veterans Affairs’ (VA) financial policies regarding management’s responsibility for internal controls.
Key points covered in this chapter:
- VA management is responsible for establishing and maintaining internal controls to achieve the objectives of effective and efficient operations, reliable financial reporting, and compliance with applicable laws and regulations;
- Management will establish the internal control system to align with the Federal internal control standards set forth by the Government Accountability Office (GAO), Standards for Internal Control in the Federal Government (Green Book);
- VA will establish a process for performing an annual assessment of internal controls to meet the statutory requirements of the Federal Managers’ Financial Integrity Act of 1982 (FMFIA); and
- VA will follow the implementation guidance set forth by Office of Management and Budget (OMB) Circular A-123, Management’s Responsibility for Internal Control.
0502 Revisions
Previous revisions can be found in Appendix A.
| Section | Revision | Office | Reason for Change | Effective Date |
|---|---|---|---|---|
| Various | Completed full review | OFP | GAO Green Book update | May 2026 |
| 0503 | Updated definitions and added definitions for CSOC and CUEC. | OFP | GAO Green Book update | May 2026 |
| 050501 | Revised List of Green Book Principles by Component. | OFP | In conjunction with updates GAO Green Book | May 2026 |
| 050504 | Added authority for controls. | OFP | Aligning with OMB Circular No. A-123, Management’s Responsibly for Internal Control | May 2026 |
| 050504 | Included subservice organizations | OFP | To address assessment of supply chain risk | May 2026 |
| 050505 | Change reference to CFO Council as the governing body for internal controls to the Executive Leadership Team (ELT) | OFP | Changes in internal control governance | May 2026 |
| 0506 | Updated, reformatted and added link for OMB Bulletin No. 24-02 | OFP | Consistency among financial policies | May 2026 |
For a complete list of previous policy revisions, see Appendix A: Previous Policy Revisions.
0503 Definitions
Anti-Deficiency Act (ADA) Violation – Pursuant to 31 U.S.C. § 1341, an ADA violation may occur when an obligation of funds exceeds the amount, time or purpose of such spending as approved by Congress in the form of enacted law.
Change Risk – Risk posed to the organization that results from changes in internal or external conditions. Internal conditions may include changes to the entity’s programs or activities, oversight structure, organizational structure, personnel, and technology. Changes in external conditions include changes in the Governmental, economic, technological, legal, regulatory, and physical environments.
Complementary Subservice Organization Controls (CSOCs) – Controls that management of the service organization assumes, in the design of the service organization’s system, will be implemented by the subservice organizations and are necessary to achieve the control objectives stated in management’s description of the service organization’s system.
Complementary User Entity Controls (CUECs) – Controls that management of the service organization assumes, in the design of its system, will be implemented by user entities and are necessary to achieve the control objectives stated within management’s description of the service organization’s system.
Component – Highest level of the hierarchy of Federal internal control standards in the GAO Green Book’s internal control framework. There are five required internal control components: Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring.
Control Activities – The policies, procedures, techniques, and mechanisms that mitigate risks to achieving an entity’s objectives.
Control Objective – The aim or purpose of specified controls. Control objectives address the risks related to achieving an entity’s objectives.
Deficiency or Control Deficiency – When the design, implementation, or operation of a control does not allow management or personnel, in the normal course of performing their assigned functions, to achieve control objectives and address related risks.
Fraud Risk – The potential that a person or organization may obtain something of value through willful misrepresentation, (e.g., fraudulent financial reporting, misappropriation of assets, and corruption).
Inherent Risk – The risk to an entity in the absence of management’s response to the risk.
Internal Controls – The organizational activities, plans, methods, policies, and processes used to reasonably ensure (1) programs achieve their intended results; (2) resources are used consistent with the organization/Department mission; (3) programs and resources are protected from waste, fraud, and mismanagement; (4) laws and regulations are followed; and (5) reliable and timely information is obtained, maintained, reported, and used for decision making.
Internal Controls Assessment – Annual assessment performed to determine the effectiveness of internal controls against Federal internal control standards and to identify reportable Material Weaknesses and Material Non-Compliances with Laws or Regulations at VA’s entity level.
Internal Control System – Consists of integrated and continuous processes, affected by people, that are collectively designed to provide reasonable assurance, not absolute assurance, that an entity’s objectives will be achieved.
Material Weakness or Material Non-Compliance with Laws or Regulations – The most severe level of control deficiency, which is defined by management of the unit being assessed as being of sufficient importance to materially (1) impair fulfillment of the mission; (2) deprive customers and Veterans of services; (3) violate statutory or regulatory requirements; or (4) significantly weaken safeguards against waste, loss, unauthorized use, or misappropriation of assets. A material weakness in internal control over compliance (Material Non-Compliance with Laws or Regulations) is a condition where management lacks a process that reasonably ensures preventing a violation of law or regulation that has a direct and material effect on financial reporting or significant effect on other reporting or in achieving Agency objectives.
Operational Objectives – Objectives related to program operations that help achieve an entity’s mission. It is one of the three categories of objectives and related risks (along with reporting and compliance) for which Federal agencies implement internal controls.
Principle – Fundamental concept that is integral to supporting the effective design, implementation, and operation of the associated components of internal control and represents requirements necessary to establish an effective internal control system. There are 17 required internal control principles within the 5 components.
Reasonable Assurance – A satisfactory level of confidence in achieving program, administrative and financial management objectives effectively and efficiently, and safeguarding Government resources under given considerations of costs, benefits and risks. The emphasis is on the term ‘reasonable’ since ‘absolute’ assurance can never be given for any process.
Reporting Entity – VA offices responsible for annually completing the Internal Controls Assessment and Statement of Assurance (SOA). Reporting Entities consist of the three Administrations and major Staff Offices, and collectively account for all activities in VA.
Residual Risk – The risk that remains after management’s response to the inherent risk.
Risk – The potential for loss, harm, or missed opportunities in achieving the organization’s mission and strategic objectives due to uncertainty.
Risk Assessment – The identification and analysis of risks facing the entity as it seeks to achieve its objectives. This assessment provides the basis for developing appropriate risk responses.
Risk Tolerance – The acceptable level of variation in performance relative to the achievement of objectives.
Segregation of Duties (SOD) – The separation of responsibilities for performing control activities related to the authority, custody, and accounting of operations so that incompatible duties are segregated.
Service Organization – An external party that performs business processes or provides services in support of business processes for an entity. These services may include operational process(es) (e.g., accounting and payroll processing, security services, health care claims processing, or system hosting and administration).
Significant Deficiency – A deficiency, or a combination of deficiencies, in internal control that is less severe than a material weakness, yet important enough to merit attention by those charged with governance. A Significant Deficiency should be shared internally across VA when identified by Reporting Entities because they represent significant weaknesses in the design or operation of internal controls that could adversely affect the Reporting Entity or organization’s ability to meet its internal control objectives. At the Department level, Significant Deficiencies are defined as severe enough to share across VA but not report to the President and Congress in the Secretary’s SOA.
Statement of Assurance (SOA) – The annual statement certifying that management has appropriately assessed operational activities. The statement is also management’s objective decision that a program and/or financial management systems are or are not operating in compliance with FMFIA. The statement is based on the results of internal control assessments, evaluations, and/or reviews.
Subservice Organization (SSO) – A third-party service provider used by the primary service organization to outsource processes and controls.
0504 Roles and Responsibilities
Secretary of Veterans Affairs (SECVA) is responsible for ensuring the maintenance of a sound control environment throughout VA and providing reasonable assurance to the President, Congress, and OMB on the status of VA’s compliance with FMFIA through the signed annual SOA reported in the Agency Financial Report (AFR). SECVA is responsible for reporting Material Weaknesses and instances of Material Non-Compliance with Laws and Regulations in the SOA. SECVA considers information from VA’s internal control assessment process, with input from the Chief Financial Officer (CFO) and has ultimate decision authority for deficiencies deemed Material Weaknesses or Material Non-Compliance with Laws and Regulations and included in the SOA.
Assistant Secretary for Management/Chief Financial Officer (VA CFO) directs and evaluates FMFIA annual reporting and coordinates with subordinate CFOs and Under Secretaries, Assistant Secretaries, and Other Key Officials to make recommendations for the SECVA SOA. The CFO has oversight responsibility for financial audit activities and governance over internal controls.
Chief Executive Officers (e.g., CFO, Chief Information Officer (CIO), Chief Acquisition Officer(CAO)) have VA-wide duties and responsibilities required by Federal law and regulations, OMB guidance, or VA delegation. Chief Executive Officers review and attest to the effectiveness of internal controls, report deficiencies, and provide an overall SOA for all responsibilities within the purview of their assigned Chief Executive Officer function, including activities organizationally aligned outside their chain of command.
Office of Acquisition, Logistics and Construction (OALC) is responsible for establishing acquisition policy and working across the Department to make strategic sourcing decisions that maximize its purchasing authority.
Office of Business Oversight (OBO) is responsible for overseeing the process of assessing risks facing VA as it seeks to achieve its objectives, managing and implementing VA’s program for addressing risk, drafting management’s assessment and reporting on the effectiveness of the internal controls implemented to reduce risk in accordance with OMB Circular A-123 and as required by FMFIA and GAO Green Book.
Office of Information and Technology (OIT) is responsible for the evaluation of VA’s financial management systems’ conformance with FMFIA Section 4 requirements in accordance with OMB Circular A-123, Appendix D, Compliance with the Federal Financial Management Improvement Act of 1996; OMB Bulletin 21-04, Audit Requirements for Federal Financial Statements; and the Treasury Financial Manual (TFM) Volume I, Part 6, Chapter 9500, Revised Federal Financial Management System Requirements for Fiscal Reporting.
VA Managers and Supervisors at all levels are responsible for assigned activities within their purview and for designing, implementing and monitoring internal controls to achieve operational objectives.
VA Employees are responsible for participating in the internal control system designed by management by fulfilling assigned internal control responsibilities as part of day-to- day activities. Employees are responsible for reporting issues to their supervisory chain of command, including potential internal control deficiencies.
0505 Policies
050501 General Policies
- VA will establish internal controls in accordance with GAO’s Green Book standards as required by FMFIA. The GAO Green Book applies to all categories of VA’s internal control objectives: effectiveness and efficiency of operations, reliability of reporting, and compliance with laws and regulations.
- VA will use GAO Green Book’s hierarchical structure of 5 components and 17 principles to effectively design, implement, maintain and document internal control systems that operate in an integrated manner to address identified control objectives.
| Components of Internal Control | Principles |
|---|---|
| 1. Control Environment | 1. The oversight body and management should demonstrate a commitment to integrity and ethical values. 2. The oversight body should oversee the entity’s internal control system. 3. Management should establish an organizational structure, assign responsibility, and delegate authority to achieve the entity’s objectives. 4. Management should demonstrate a commitment to recruit, develop, and retain competent individuals. 5. Management should evaluate performance and hold individuals accountable for their internal control responsibilities. |
| 2. Risk Assessment | 6. Management should define objectives clearly to enable the identification of risks and define tolerances. 7. Management should identify, analyze, and respond to risks related to achieving the defined objectives. 8. Management should consider risks related to fraud, improper payments, and information security when identifying, analyzing and responding to risks. 9. Management should identify, analyze, and respond to significant changes that could impact the internal control system. |
| 3. Control Activities | 10. Management should design control activities to mitigate risks to achieve the entity’s objectives to acceptable levels. 11. Management should design general control activities over information technology to mitigate risks to achieving the entity’s objectives to acceptable levels. 12. Management should implement control activities through policies and procedures. |
| 4. Information and Communication | 13. Management should obtain or generate relevant, quality information and use it to support the functioning of the internal control system. 14. Management should internally communicate relevant and quality information, including objectives and responsibilities for internal control, necessary to support the functioning of the internal control system. 15. Management should communicate relevant and quality information with appropriate external parties regarding matters impacting the functioning of the internal control system. |
| 5. Monitoring | 16. Management should establish and operate monitoring activities to monitor the internal control system and evaluate the results. 17. Management should remediate identified internal control deficiencies on a timely basis. |
- In accordance with FMFIA and the GAO Green Book, all levels of VA management are responsible for internal controls. VA managers at all organizational levels will continuously monitor, assess, and improve the effectiveness of internal controls associated with mitigating risks to achieve objectives. In addition, due to the decentralized structure of VA, managers will also be aware that their responsibility for internal control may extend beyond traditional organizational reporting lines.
- The establishment of appropriate internal controls will be supported by higher levels of management.
- Management will view the internal control system as an integral part of the operational processes used to guide operations rather than as a separate system within VA. In this sense, internal control is built into VA as a part of the organizational structure to help managers achieve their objectives on an ongoing basis.
- VA management will comply with GAO Green Book documentation requirements and maintain documentation to demonstrate the internal control system. Specifically, management will:
- Develop and maintain documentation of its internal control system. The level and nature of documentation will vary based on the size of the entity and the complexity of the operational processes the entity performs;
- Determine if a principle is not relevant and support that determination with documentation that includes the rationale of how, in the absence of that principle, the associated component could be designed, implemented, and operated effectively;
- Document the results of risk assessments, including the identification, analysis and response to risks, that are completed on both a periodic and ongoing basis. This includes documentation of the consideration of risks related to fraud, improper payments, information security, and significant internal and external changes that could impact the internal control system;
- Establish and document a change assessment process for identifying, analyzing, and responding to risks related to significant changes, so that internal controls can be quickly modified as significant changes occur;
- Evaluate and document the results of ongoing monitoring and separate evaluations to identify internal control issues;
- Evaluate and document internal control issues and determine appropriate corrective actions for internal control deficiencies, including those reported from internal and external audits and evaluations, on a timely basis; and
- Create, document and complete corrective actions to remediate internal control deficiencies, including those reported from internal and external audits and evaluations, on a timely basis.
- Management will exercise judgment in determining what documentation may be necessary for an effective internal control system. If management identifies deficiencies in achieving these documentation requirements, the effect of the identified deficiencies is considered as part of management’s summary determination as to whether the related principle is designed, implemented, and operating effectively.
050502 Internal Controls Integration and Risk
- VA’s internal control system will be a continuous, built-in component of operations, that provides reasonable assurance VA’s objectives will be achieved. Internal control is not a single event or action, but a series of events and actions that occur throughout VA’s operations.
- Management at all levels of VA will define the specific goals and priorities of the organization or controlled unit in measurable, understandable terms to enable the identification of risks and define risk tolerances (GAO Green Book, Component 2, Principle 6).
- VA management will identify risks that could prevent the organization or unit under their influence from achieving its objectives, analyze those risks, and determine the appropriate risk response (GAO Green Book, Component 2, Principles 7-9).
- VA management will identify risks, formulate control objectives, then design and implement internal controls for those risks/objectives (typically high and medium) for which mitigation is the desired risk response (GAO Green Book, Component 3, Principles 10-12).
- VA management will assess the inherent and residual risks across the following risk types (GAO Green Book, Component 2, Principles 8-9):
- Fraud;
- Improper Payment;
- Information Security; and
- Significant Internal and External Changes
- VA management will have access to relevant and reliable communication related to internal as well as external events, in order to support and design effective internal controls. Communication of quality information is at the center of the cycle and is integral to effective system operation (GAO Green Book, Component 4, Principles 13-15).
Figure 1: Continuous Cycle of Internal Control

- VA management will continuously monitor controls to ensure they are designed effectively and operating as intended (GAO Green Book, Component 5, Principle 16).
- When internal control deficiencies are identified, such as when testing controls, VA management will implement necessary corrective actions to remediate the deficiencies (GAO Green Book, Component 5, Principle 17).
050503 Internal Control Responsibilities
- VA management’s responsibility for implementing and monitoring internal controls will not be diminished by the decentralization of operational processes.
- VA’s Executive Director for Office of Acquisitions, Logistics and Construction (OALC), in collaboration with VA CFO, will ensure controls over acquisitions are in place and integrated into the agency’s internal control review processes. Executive Director OALC will lead VA acquisition assessments, applying guidance in OMB Circular No. A-123, Management’s Responsibility for Internal Control
- All levels of the organization will communicate information not only within their chain of command but also across and around the organizational structure, to include the Chief Executive Officers with delegated agency-level responsibilities such as human capital, finance, acquisition, and information technology.
- In similar fashion, VA’s Chief Executive Officers will design, implement, and monitor internal controls for their areas of functional responsibility, regardless of the reporting lines conducting the activities. All levels of the organization will communicate information not only within their chain of command but also across and around the organizational structure, to include the Chief Executive Officers with delegated agency-level responsibilities such as human capital, finance, acquisition, and information technology.
- Management will consider how units interact to fulfill their overall responsibilities and establish reporting lines within an organizational structure that enables units to efficiently and effectively communicate the quality information necessary to comply with applicable laws and regulations while fulfilling its overall responsibilities.
050504 Service Organizations
- VA management retains responsibility for the performance of, and risks associated with, processes outsourced to service organizations, including subservice organizations (e.g., DFAS).
- VA will use System and Organization Control (SOC) or similar type reports to monitor service organization and subservice organization activities and internal controls.
- The extent of VA’s reliance on a SOC or similar type report will be dependent upon the nature of the contract or agreement and its significance to VA’s operation and financial statements.
- Management will provide increased oversight or implement compensating controls if deficiencies are noted in a SOC or similar type report and the related activity is significant to VA’s achievement of mission objectives and/or material to VA’s financial statements.
- In accordance with the American Institute of Certified Public Accountants (AICPA) Statement on Standards for Attestation Engagements (SSAE) No. 18, Attestation Standards: Clarification and Recodification (AT-C), management will work with assigned VA contracting officers to establish contractual requirements to obtain independent audit reports attesting to the controls of service organizations and applicable subservice organizations when services are either material to VA’s financial statements or mission objectives. SOC reports most relevant to VA contracts include:
- SOC 1, Type 2 reports on the fairness of the presentation of management’s description of the service organization’s system, and the suitability of the design and operating effectiveness of controls for a service organization relevant to VA’s internal controls over financial reporting throughout a specified period. SOC 1 Type 2 reports typically, cover a period of time (e.g. the first 10 months of the user entities’ fiscal year) versus a Type 1 report that assesses controls at a single point in time. These reports are intended to support user entities and their auditors in evaluating the impact of service organization controls on financial statements and must be prepared in accordance with SSAE 18, AT-C Section 320 – Reporting on an Examination of Controls at a Service Organization Relevant to User Entities’ Internal Control Over Financial Reporting.
- SOC 2, Type 2. Reports on the fairness of the presentation of management’s description of the service organization’s system, and the suitability of the design and operating effectiveness of a service organization relevant to security, availability, processing integrity, confidentiality, and privacy throughout a specified period. These reports are intended to meet the needs of a broad range of users that need detailed information and assurance about the controls at a service organization relevant to security, availability, and processing integrity of the systems the service organization uses to process users’ data and the confidentiality and privacy of the information processed by these systems. These reports must be prepared in accordance with SSAE 18, AT-C Section 205, Examination Engagements, and the AICPA’s trust service criteria set forth in TSP Section 100, 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy, and DC Section 200, 2018 Description Criteria for a Description of a Service Organization’s System in a SOC 2 Report.
- VA will review SOC and/or similar type reports to understand the service and subservice provider’s controls and identify control deficiencies or gaps that may significantly impact the integrity of VA data, or control objectives and implement necessary corrective actions to remediate the deficiencies on a timely basis.
- VA will determine whether control failures pose a risk to VA financial statements, operations, laws and regulations, and/or compliance. Where relevant risks are noted, VA will identify compensating controls implemented by the service organization or VA that may help mitigate the risk and determine the effectiveness of such controls.
- VA will identify VA-specific controls that address and are mapped to relevant CUECs and confirm the controls are designed and operating effectively.
- VA will evaluate the use of subservice organizations for subservice organizations relevant to VA financial reporting, review the subservice organization SOC and similar type reports to determine the effectiveness of relevant CSOCs. Additionally, VA will confirm the implementation of subservice organization CUECs within the service organization SOC and similar reports.
- When SOC or similar type report is unavailable, insufficient, or not the most appropriate method, VA may use other monitoring or assessment methods consistent with OMB Bulletin No. 24-02 (July 2024). These include but are not limited to:
- Assessing service organization internal controls; or
- Monitoring and regularly reporting on processes, products, or services provided by the service organization.
- VA will maintain documentation evidencing its review of SOC or similar type reports for service and subservice organizations, including the report period, scope relevance, deficiencies identified, related CUECs and CSOCs, compensating controls considered, and managements conclusion regarding the extent of reliance placed on the report.
- When the service provider discloses in a SOC or similar type report uses a subservice organization, VA must determine the relevance of the subservice organization as it relates to the service organization’s performance of processes and controls for VA. Where relevant, VA must review and assess the subservice organization SOC or similar type report. Documentation of the assessment as well as, documentation of the subservice provider’s SOC or similar type report must be maintained for audit and management review purposes.
050505 Governance
- The Executive Leadership Team (ELT) will provide and support open communication among financial and senior management working to support VA’s mission and the Federal Government.
- The CFO and subordinate CFOs will review financial and operational internal controls and financial audit matters and encourage continuous improvement of VA’s policies, procedures, and practices at all levels. Improving internal controls reduces audit findings, helps VA maintain clean audit opinions, and helps meet operational objectives.
- The CFO will review deficiencies, consider the impact to VA, and recommend the content of the VA Secretary’s SOA.
- The CFO and subordinate CFOs will follow financial management regulations and implement guidance including but not limited to the FMFIA, Federal Financial Management Improvement Act of 1996 (FFMIA), OMB Circular A-123, and the CFO Act of 1990.
050506 Reporting Entities’ Internal Controls Assessments
- OBO will coordinate the annual Internal Controls Assessment and SOA official announcement from OM, typically made in a memorandum to heads of the Reporting Entities. The annual notice will include information regarding instructions, required templates, and due dates for conducting the assessment and submitting the SOA. When VA uses a combination of interim and final Statements of Assurance to cover the entire year, OBO will coordinate all related announcements from OM.
- OBO’s intranet site maintains the most current Internal Controls Assessment process template, guidebooks, reference documents, policies, training materials, editable SOA templates, and service organization review documents.
- OBO will ensure VA’s annual Internal Controls Assessment process conforms to the most recent Federal internal control framework issued by GAO Green Book, including any changes that are published and effective for the current fiscal year.
- OBO will ensure the Internal Controls Assessment, SOA templates, tools, and training are compliant with OMB Circular A-123.
- OBO will determine VA’s designated Reporting Entities required to complete annual assessments of the effectiveness of the entity’s internal controls.
- Each of VA’s designated Reporting Entities will complete an annual assessment of the effectiveness of internal controls and submit the assessment to OBO. The assessment, referred to as the Internal Controls Assessment, requires Reporting Entities to:
- Evaluate the internal control system against the 5 Components and 17 Principles of internal control specified in GAO’s Green Book:
- Describe how the Reporting Entity meets the principle;
- Identify deficiencies and their severity;
- Report internal control deficiencies;
- Describe corrective action plans for Material Weaknesses and Material Non-Compliance with Laws and Regulations; and
- Conclude on the effectiveness of each principle.
- Evaluate the internal control system against the 5 Components and 17 Principles of internal control specified in GAO’s Green Book:
- Reporting Entities will provide supporting documentation to substantiate the statements contained in their Internal Controls Assessment and demonstrate the internal control system is documented as required by GAO Green Book.
- Deficiencies will be described with enough detail for people outside the Reporting Entity to understand the nature of the deficiency. The Reporting Entity will consider the magnitude of impact and the likelihood of the deficiency to conclude on the appropriate severity level.
- Magnitude of impact considers the effect the deficiency had or could have on the Reporting Entity’s ability to achieve its objectives. In other words, could the deficiency have a severe impact on meeting objectives;
- Likelihood considers how likely it is the deficiency will impact the objectives. In other words, what is the chance the deficiency will impact effectiveness and efficiency of operations, reliability of reporting, or compliance with laws and regulations.
- After assessing each Principle within the Component, the Reporting Entity will conclude on the effectiveness of the Component. The effectiveness of the Component is directly related to the effectiveness of each Principle. If any Principle within a control Component is deemed ineffective, the entire control Component is ineffective. The Internal Controls Assessment provides space for the Reporting Entity management to document its conclusion for each Principle, followed by the relevant component. Reporting Entities complete an assessment for each of the first 5 principles and then conclude on the effectiveness of Component 1 as well as the rest of the Components.
- Reporting Entity management will identify and select the appropriate severity rating for each deficiency. The Internal Controls Assessment categorizes deficiencies in four severity levels:
- Material Weaknesses (the most severe);
- Significant Deficiencies;
- Control Deficiencies; and
- Material Non-Compliance with Laws and Regulations.
- The severity rating should not conflict with the identified magnitude of impact and likelihood. For example, if a deficiency has a low impact and is considered unlikely, it should typically not be considered a Material Weakness. By assigning the highest severity level, management is recommending the Material Weakness be reported external to the Reporting Entity and considered by the oversight body for reporting outside VA.
- The Internal Controls Assessment requires information about planned corrective actions for deficiencies identified as Material Weaknesses and Material Non-Compliance with Laws and Regulations. The Reporting Entity will provide a copy of the corrective action plan to OBO unless the Material Weakness is part of the financial statement audit as OBO has access to the Office of Financial Audit and Policy developed CAPs for material weaknesses identified by the external financial statement auditors. The corrective action plan can be the most recent version of a corrective action plan already being tracked by another organization (e.g., OIG, GAO, OM, or established by the Reporting Entity). Once identified, Material Weaknesses will be reported in subsequent fiscal years until the Reporting Entity can demonstrate the deficiency was resolved or lessened.
- When requested, Reporting Entities will each complete a comprehensive Internal Controls Assessment at the Reporting Entity level, including providing documentation to support all assertions and narratives in the Internal Controls Assessment and signing an SOA. To the greatest extent possible, documentation provided will consist of the detailed results of transactional level testing of internal controls.
- Reporting Entities will identify and obtain appropriate input from sub-offices and programs covering every level of their organization when completing their Internal Controls Assessment and SOA.
- Entities with Chief Officers (VA officials with Department-wide duties and responsibilities) will encompass all Chief Officer responsibilities in Internal Controls Assessment responses.
- Information on how the Reporting Entity monitors service organization controls for outsourced processes is required for a complete Internal Controls Assessment.
- Internal Controls Assessment responses must include self-identified deficiencies from throughout the organization and address deficiencies identified by all other sources, including auditor findings.
- Entities will provide corrective action plans for deficiencies in accordance with instructions. All internal control deficiencies rising to the severity of a material weakness or significant deficiency must be accompanied by a detailed, fully developed corrective action plan that clearly addresses the root causes of the deficiency and provides a path to correct them.
- In addition to the assessments for GAO Green Book’s 17 Principles and 5 Components of internal control, the Internal Controls Assessment may contain additional sections addressing or adding emphasis to requirements that intersect with FMFIA, OMB Circular A-123, and GAO Green Book. For example, Public Law 112-194, The Government Charge Card Abuse Prevention Act of 2012, mandates that each executive agency that issues and uses charge cards (purchase cards, convenience checks, fleet cards, and travel cards) will establish and maintain safeguards and internal controls. To help management reach a conclusion regarding internal controls over charge cards, the Internal Controls Assessment contains a Charge Card Assessment section. Reporting Entities will complete the Charge Card Assessment section and ensure any internal control deficiencies related to charge cards are included in the appropriate principle within the Internal Controls Assessment.
- Depending on management’s conclusions in the Internal Controls Assessment and the existence of Material Weaknesses and Material Non-Compliance with Laws and Regulations, Reporting Entities will submit one of the following types of SOAs:
- Unmodified SOA. The Reporting Entity will prepare an Unmodified SOA when management concluded in the Internal Controls Assessment that the overall system of internal controls was effective and there were no Material Weaknesses or Material Non-Compliance to report;
- Modified SOA. The Reporting Entity will prepare a Modified SOA when management concluded in the Internal Controls Assessment that the overall system of internal controls was effective and identified one or more Material Weaknesses or Material Non-Compliances; or
- Statement of No Assurance. The Reporting Entity will prepare a Statement of No Assurance when management cannot attest to the effectiveness of internal controls because an assessment was not performed, the extent of Material Weaknesses or Material Non-Compliance are pervasive, or the activities being assessed have been established less than 6 months.
- Reporting Entities will provide supporting documentation to substantiate the statements contained in their Internal Controls Assessment and demonstrate the internal control system is documented as required by GAO Green Book.
- Entity Internal Controls Assessments and SOAs will be submitted to OBO who will analyze each report and review them for completeness, (e.g., ensure proper supporting documentation is provided). OBO will perform a reasonableness review and inform Reporting Entities of any apparent conflicts between deficiencies reported and conclusions reached by management within the Internal Controls Assessment. OBO will require Reporting Entities to make corrections for missing or conflicting information.
050507 Statement of Assurance (SOA)
- The SOA provides an informed judgement of the overall adequacy and effectiveness of the Reporting Entity’s internal controls. It should be prepared after completion of the Internal Controls Assessment by Reporting Entities and viewed as the means of applying management’s signature to the assertions in the Internal Controls Assessment about the effectiveness of the internal controls system and the existence of Material Weakness and Material Non-Compliance with Laws and Regulations.
- Per the timelines set annually by OBO, VA may use a phased approach to obtain management’s assurance over the full fiscal year by using interim and final Statements of Assurance.
- Each Reporting Entity will prepare a SOA using templates provided by OBO. The SOA will list all Material Weaknesses and Material Non-Compliance with Laws and Regulations identified in the Internal Controls Assessment, provide corrective action plans, and report on any ADA violations. The head of the Reporting Entity will sign the Entity SOA.
- The Reporting Entity will ensure the Internal Controls Assessment and SOA are updated to reflect changes in deficiencies (adding newly identified deficiencies or removing remediated deficiencies) that impact the fiscal year being assessed.
- The results of continuous monitoring and reviews should be reported to leadership as part of the SOA. The SOA should include a:
- Report of Internal Control Deficiencies: VA managers and staff will identify and report deficiencies, and all levels of leadership will support a culture of openness. Managers can inform the chain of command of the perceived significance of deficiencies by designating the severity level using the definitions in this policy (e.g., material weakness, significant deficiency, control deficiency). Sharing deficiencies with the next level of supervision allows the VA chain of command to determine the relative importance of each deficiency.
- Corrective Action Plan (CAP) for noted deficiencies: Correcting control deficiencies is an integral part of management accountability and is a priority in VA. VA’s ability to correct control deficiencies is an indicator of the strength of its internal control environment. Effective remediation of control deficiencies is essential to achieving the objectives of FMFIA, and uncorrected or longstanding control deficiencies will be considered in determining the overall effectiveness of internal control.
050508 VA’s Consolidated Internal Controls Assessment and SOA
- The Internal Controls Assessment and resulting SOA completed by the Reporting Entities are vital in providing the basis for the overall VA Internal Controls Assessment. When OBO deems all assessments and statements for Reporting Entities are complete, OBO will consolidate all identified control deficiencies submitted into VA’s annual Internal Controls Assessment.
- OBO will present deficiencies from the Reporting Entity Internal Controls Assessments to the CFO Council and prepare the VA Secretary’s SOA based on recommendations from the CFO Council or as directed by OM. OBO will include Material Weaknesses and Material Non-Compliance with Laws and Regulations recommended by the CFO Council, with deviations only as directed by OM. The Secretary will ultimately decide the final contents of the Departmental SOA and will submit the Statement to Congress by November 15 in the Agency Financial Report (AFR).
0506 Authorities and References
- 31 U.S.C. § 1341, Limitations on expending and obligating amounts
- Chief Financial Officers (CFO) Act of 1990, P.L. 101-576
- Federal Financial Management Improvement Act of 1996 (FFMIA), P.L. 104-208, Title VIII
- Federal Managers’ Financial Integrity Act of 1982 (FMFIA), P.L. 97-255
- Government Charge Card Abuse Prevention Act of 2012, P.L. 112-194
- OMB Bulletin 21-04, Audit Requirements for Federal Financial Statements
- OMB Bulletin No. 24-02, July 2024
- OMB Circular No. A-123, Management’s Responsibility for Internal Control, March 10, 2026
- OMB Memorandum M-13-21, Implementation of P.L. 112-194
- TFM Volume I, Part 6, Chapter 9500, Revised Federal Financial Management System Requirements for Fiscal Reporting
- GAO Standards for Internal Control in the Federal Government (GAO Green Book)
- American Institute of Certified Public Accountants (AICPA) Statement on Standards for Attestation Engagements (SSAE) No. 18, Attestation Standards: Clarification and Recodification
- AT-C Section 205 – Assertion Based Examination Engagements
- AT-C Section 320 – Reporting on an Examination of Controls at a Service Organization Relevant to User Entities’ Internal Control Over Financial Reporting
- TSP Section 100 – 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
- DC Section 200 – 2018 Description Criteria for a Description of a Service Organization’s System in a SOC 2 Report (With Revised Implementation Guidance – 2022)
0507 Rescissions
Volume I, Chapter 5 – Management’s Responsibility for Internal Controls, December 2022.
Appendix A: Previous Policy Revisions
| Section | Revision | Office | Reason for Change | Effective Date |
|---|---|---|---|---|
| 0503 Definitions | Added definition for CFO SOA, four types of risk, and Separation of Duties Updated definition of Statement of Assurance to include material non-compliances with laws or regulations | OBO (047B) | Update definitions to align with OMB and GAO standards and policy | December 2022 |
| 0504 Roles and Responsibilities | Added GAO Green Book as guiding document for OBO | OBO (047B) | Align with OBO mission | December 2022 |
| 0505 Policies | Added 050501 General Policies Added discussion from prior Appendix A Enhanced discussion on components and principles | OFP (047G) | Reorganized chapter layout Clarify types of risk and VA’s responsibility to identify, analyze and respond | December 2022 |
| 0506 Authorities and References | Added reference to OMB Bulletin 21-04 and removed reference to 17-03 Added reference to PIIA and removed reference to IPIA, IPERA and IPERIA Added refence to OMB Memorandum, May 21, 2008 | OFP (047G) | OMB Bulletin 17-03 rescinded by 21-04 Rescission of IPIA, IPERA and IPERIA by PIIA Missing reference for OALC guidance | December 2022 |
| Appendix A | Updated language to ensure transactional level testing of internal controls to the greatest extent possible Added requirement for corrective action plans in the event of a material weakness or significant deficiency | OBO (047B) | Clarification on requirements for transaction level testing and corrective action plans | February 2019 |
| Various | Reformatted to new policy format and completed five-year update | OFP (047G) | Reorganized chapter layout | November 2018 |
| Overall | Clarified policy to match GAO and OMB’s revision to internal control requirements Update the roles and responsibilities for the implementation and management of internal control in VA | OBO (047B) | Align VA internal control policy with the GAO Green Book and OMB Circular A-123 | November 2018 |
| Overall | Change reference to SAT as the governing body for internal controls to the CFO Council | OBO (047B) | Changes internal control governance from the SAT to the CFO Council | November 2018 |
| 0503 Definitions | Added definitions for clarity of understanding of the Internal Control Assessment Process | OBO (047B) | Update definitions to align with OMB and GAO standards and policy | November 2018 |
| 0504 Responsibilities | Clarifies responsibilities for internal controls | OBO (047B) | Defines specific responsibilities for various positions and organizations responsible for internal controls | November 2018 |
| 0505 Policy | Entire section establishes revised procedures for designing, implementing, and assessing internal controls Adds responsibility for assessing service organization controls | OBO (047B) | Implements changes to internal control assessments per the Green Book and OMB Circular A-123 | November 2018 |
| 0506 Authorities and References | Updated Green Book and OMB Circular A-123 references to align with revisions | OBO (047B) | Reflects changes to managements’ responsibilities for internal controls | November 2018 |
| Appendix A | Added to provide description of the Internal Control Assessment Process | OBO (047B) | Implements VA process for compliance with GAO Green Book and OMB Circular A-123 | November 2018 |
| Appendices B – F | Deleted | OBO (047B) | Processes and procedures described in these appendices are no longer applicable to new GAO standards | November 2018 |



