Jul 8

FMFIA, OMB A-123, and the GAO Green Book: The Legal Foundation of Federal Internal Controls

Federal internal controls over financial reporting rest on three documents that work together. The Federal Managers' Financial Integrity Act of 1982 (FMFIA) is the statute that creates the requirement. OMB Circular A-123, Management's Responsibility for Enterprise Risk Management and Internal Control (revised July 15, 2016), is the policy that implements the statute. The GAO Standards for Internal Control in the Federal Government (the Green Book), 2025 revision GAO-25-107721, is the standard that defines what "effective" internal control looks like. Together they establish who is accountable, how the assessment gets done, and how effectiveness is measured. Understanding each one, and how they connect, is foundational for any federal accountant, auditor, or internal control assessor.

Key takeaways

FMFIA is the statute (the why). Enacted in 1982 and codified at 31 U.S.C. § 3512, it requires agency heads to establish internal controls and report annually to the President and Congress on their effectiveness.
OMB A-123 is the policy (the how). The current base circular was issued July 15, 2016 and expanded internal control from financial reporting alone to include operations and compliance objectives, integrated with enterprise risk management.
The Green Book is the standard (the what). The current version is the 2025 revision (GAO-25-107721), effective for fiscal year 2026, superseding the 2014 version.
A-123 has four appendices. Each covers a distinct area: reporting and data integrity risk, government charge card programs, payment integrity, and financial management systems.
Agencies must evaluate against all 17 Green Book principles. A-123 requires agencies to determine whether each of the 17 principles is designed, implemented, and operating effectively, and to identify specific principles that are not met.
The accountability is personal. The agency head cannot delegate the assurance statement. That signature is required by law.

Why the distinction matters

It is common to hear people use FMFIA, A-123, and the Green Book interchangeably. They are not interchangeable. Each answers a different question. Confusing them makes it hard to have a productive conversation about what is required, what is recommended, and what is a matter of judgment. Our federal ICFR pillar post covers the framework at a high level. This post drills into each document.
When a CFO asks why the agency is required to have ICFR at all, the answer is FMFIA. When someone asks how the assessment should be conducted, the answer is OMB A-123 and its appendices. When someone asks what an "effective" control looks like, the answer is the Green Book. Knowing which document answers which question is a small thing that saves a lot of confusion.

FMFIA: the statute that created the requirement

The Federal Managers' Financial Integrity Act of 1982 amended the Accounting and Auditing Act of 1950 to require agency heads to establish internal accounting and administrative controls. It is codified at 31 U.S.C. § 3512. The statute is short by federal law standards, which is part of why the implementing policy (A-123) has to do so much operational work.

What FMFIA actually requires

Establish internal controls. Every executive agency must maintain systems of internal accounting and administrative control designed to provide reasonable assurance that obligations and costs comply with applicable law, that funds, property, and other assets are safeguarded against waste, loss, unauthorized use, or misappropriation, and that revenues and expenditures are properly recorded and accounted for.
Assess effectiveness annually. The agency head must annually evaluate whether the systems of internal accounting and administrative control fully comply with the statute.
Report to the President and Congress. The agency head must submit an annual report on the results of the evaluation, along with any material weaknesses identified and the plans for correcting them.
The Comptroller General role. The statute directs the Comptroller General to prescribe the standards for internal controls, which is why the Green Book exists.

Personal accountability

The agency head cannot delegate the annual assurance statement. This is a design feature, not an oversight. Congress wanted personal accountability at the top of the agency because that is where the political and organizational leverage sits. When a Secretary or Administrator signs the assurance statement, they are certifying, based on their own judgment informed by the assessment, that ICFR is or is not operating effectively at their agency. The signature is legally required and personally attributed.

OMB Circular A-123: the implementation policy

OMB Circular A-123, Management's Responsibility for Enterprise Risk Management and Internal Control, is how the executive branch implements FMFIA. FMFIA tells agencies what to do. A-123 tells them how to do it. The base circular was most recently revised on July 15, 2016. That revision was substantial: it expanded the circular's scope from financial reporting to all three internal control objectives (operations, reporting, and compliance) and integrated enterprise risk management (ERM) with internal control. The four appendices have been revised separately at various points since.

What A-123 covers

Scope of internal control. Three objectives: operations, reporting, and compliance. Reporting includes both financial and non-financial reporting.
Enterprise Risk Management integration. Agencies must maintain a risk profile that identifies significant risks across the portfolio of agency objectives and prioritizes risk response.
Methodology. The risk-based approach to assessment, including planning, scoping, walk-throughs, and design and operating effectiveness testing.
Evaluation against Green Book principles. Agencies must evaluate whether each of the 17 Green Book principles is designed, implemented, and operating effectively.
Documentation requirements. Work papers, materiality determinations, scoping decisions, testing procedures and results, findings, and conclusions.
Governance. The role of senior accountable officials, the Chief Financial Officer, and the Senior Assessment Team in the ICFR program.
Fraud risk. Specific requirements to address fraud risks in areas including payroll, beneficiary payments, grants, large contracts, IT and information security, asset safeguards, and purchase/travel/fleet cards.
Reporting. The form and content of the annual assurance statement and how findings should be classified.
The 17-principle evaluation requirement. A-123 requires each agency to evaluate its system of internal control against every one of the 17 Green Book principles. For each principle, agencies must determine whether it is designed, implemented, and operating effectively. Where a principle is not met, the agency must document the deficiency and identify the specific principle. This is a substantive obligation, not a checkbox. It shapes how walk-throughs, testing, and findings documentation are scoped throughout the year.

The four appendices to A-123

A-123 has four appendices. Each one addresses a specific area of internal control and reporting risk. If you are working on a federal internal control assessment, you will encounter at least one of these. If you are the CFO or senior accountable official, you will encounter all four.
Appendix Title Current version
A Management of Reporting and Data Integrity Risk Revised 6/6/2018 (M-18-16)
B Risk Management Framework for Government Charge Card Programs Revised 8/27/2019
C Requirements for Payment Integrity Improvement Revised 3/5/2021
D Management of Financial Management Systems - Risk and Compliance Revised 12/23/2022

Appendix A: Management of Reporting and Data Integrity Risk

Appendix A was revised on June 6, 2018 (issued as OMB Memorandum M-18-16) and retitled from "Internal Control Over Financial Reporting" to "Management of Reporting and Data Integrity Risk." The retitling matters. The previous version, issued in 2004, focused narrowly on ICFR. The 2018 revision expanded the scope to all reporting objectives, including non-financial reporting, and integrated the DATA Act's data quality requirements. Appendix A now covers financial reporting risk as one component of a broader reporting and data integrity picture.
For agencies conducting their ICFR assessment, Appendix A is still the primary reference. But treating it as an "ICFR-only" document misses the broader reporting risk analysis it now requires. Agencies are expected to consider the reliability of all reporting flowing from their financial and data systems, not just the balances that show up on the financial statements.

Appendix B: Government Charge Card Programs

Appendix B, most recently revised August 27, 2019, provides the risk management framework for federal government charge card programs. Purchase cards, travel cards, and fleet cards are all covered. Agencies must maintain policies, procedures, and controls to prevent card misuse and detect it when it happens. Charge card compliance is one of the specific fraud risk areas A-123 requires agencies to address.

Appendix C: Payment Integrity Improvement

Appendix C, most recently revised March 5, 2021, sets requirements for identifying, measuring, and reducing improper payments across federal programs. It operationalizes the Payment Integrity Information Act of 2019 (PIIA) and its predecessors. Agencies with programs identified as susceptible to significant improper payments must conduct payment integrity risk assessments, report annually on improper payment rates, and implement corrective action plans. The 2025 Green Book aligns with Appendix C by explicitly naming improper payments as a required risk consideration.

Appendix D: Financial Management Systems

Appendix D, most recently revised December 23, 2022, replaced the former OMB Circular A-127 and addresses financial management systems risk and compliance. It sets requirements for the design, implementation, operation, and oversight of federal financial management systems, including compliance with the Federal Financial Management Improvement Act (FFMIA). Appendix D matters increasingly as agencies modernize their financial systems and as ICFR assessments have to evaluate the reliability of the systems that produce the financial reports.
Not just financial reporting. Since the 2016 revision, A-123 covers all three internal control objectives (operations, reporting, and compliance). "ICFR" is a subset of reporting controls. When people say "A-123 assessment" they usually mean the ICFR assessment specifically, but the broader circular addresses much more.

The GAO Green Book: the standard for "effective"

The GAO Standards for Internal Control in the Federal Government, commonly called the Green Book, defines what an effective internal control system looks like. The current version is the 2025 revision, GAO-25-107721, issued May 15, 2025. It is effective for fiscal year 2026 and the FMFIA reports covering that year, with early implementation permitted. The 2025 revision supersedes the 2014 version (GAO-14-704G) and represents the first substantial update in over a decade. The Green Book is adapted from the COSO Internal Control - Integrated Framework and remains the standard federal agencies use to evaluate whether their controls are effective.

The five components

The Green Book defines five components of an effective internal control system. All five must be present and operating for the system to be considered effective. Each component contains principles (17 principles total across the five components), and each principle has application guidance called attributes. The five components are the backbone of any Green Book evaluation.

1. Control Environment

The tone at the top. The organizational structure, ethics, competence, and commitment to internal control that shape how everything else operates. This includes the agency's approach to hiring, training, evaluating, and holding people accountable. When the control environment is weak, no amount of specific control activities will fix it. When it is strong, it makes every other component work better.

2. Risk Assessment

Identifying and analyzing risks to achieving objectives. This includes the agency's ability to identify what could go wrong, assess how likely and how impactful each risk is, and consider the potential for fraud. The 2025 revision adds explicit requirements to consider risks related to improper payments and information security alongside fraud, and to document the results of the risk assessment. Without a real risk assessment, scoping decisions become arbitrary.

3. Control Activities

The specific policies, procedures, and mechanisms that address risks. This is where preventative and detective controls, manual and automated controls, live. Control activities are the most visible component because they are the actual controls being tested. Most of an ICFR assessment focuses on control activities, though effectiveness in this component depends on the other four. The 2025 revision emphasizes preventive control activities where practical.

4. Information and Communication

Capturing quality information and sharing it with the people who need it. This includes both internal communication (management getting the information they need to make decisions) and external communication (reporting to Congress, OMB, and the public). If control activities produce information nobody uses, or if operators do not receive the information they need to operate controls correctly, this component is weak.

5. Monitoring

Ongoing evaluation of whether internal controls are still working. This includes both ongoing monitoring (built into normal operations) and separate evaluations (internal audit, management reviews, external assessments). Monitoring is what catches deterioration in the other components. Without it, controls can degrade for months or years before anyone notices.

The 17 principles and their attributes

Each of the five components has associated principles that give more specific criteria. There are 17 principles in total across the five components. Each principle in turn has application guidance called attributes, which may contain minimum documentation requirements. For example, the Control Environment component includes principles about demonstrating a commitment to integrity and ethical values, and about establishing structure, responsibility, and authority. Under A-123, agencies must evaluate each of the 17 principles for design, implementation, and operating effectiveness. This is where the Green Book meets the operational assessment.

What changed in the 2025 revision

The 2025 Green Book keeps the five components and 17 principles but adds requirements that reflect how federal risk has evolved since the 2014 version.
Fraud, improper payments, and information security. These three risk areas are now explicitly required considerations under the Risk Assessment component.
Documented risk assessment results. The revision adds requirements to document the identification, analysis, and response to risks.
Change assessment process. A new requirement to document a process for identifying, analyzing, and responding to risks from significant changes so the internal control system can adapt quickly.
Emphasis on preventive control activities. The revision leans harder into prevention over detection where practical, though both remain essential.
Two new appendices. The 2025 Green Book adds Appendix I and Appendix II. Appendix II specifically catalogs examples of preventive and detective control activities and sources of data.

How the three documents fit together

FMFIA is the legal source of authority. It creates the requirement for internal controls, requires the annual assessment and report, and directs the Comptroller General to prescribe standards. OMB A-123 is the executive branch's response to that statutory requirement, laying out the methodology every executive branch agency uses. The Green Book is the standard the Comptroller General was directed to prescribe under FMFIA.
Document Type Answers Issued by
FMFIA Statute Why we do this Congress (1982)
OMB Circular A-123 Policy How we do this OMB (2016 base circular)
GAO Green Book Standard  What "effective" means GAO (2025 revision)
When you look at any specific ICFR requirement or practice, ask which document is the source. If the source is FMFIA, the requirement is statutory and non-negotiable. If the source is A-123, it is executive branch policy that agencies must follow but can be updated. If the source is the Green Book, it is the standard against which effectiveness is measured. All three matter, and they matter in different ways.

Where COSO fits

COSO stands for the Committee of Sponsoring Organizations of the Treadway Commission. Its Internal Control - Integrated Framework is the internationally recognized standard for internal control. The Green Book is adapted from COSO for the federal government context. The five components and 17 principles map directly. Someone with a strong COSO background will find the Green Book familiar, though the federal-specific context and terminology require some adjustment. The 2025 Green Book explicitly notes continued harmonization with COSO.

Common misconceptions about the legal foundation

• "A-123 is the law." A-123 is a policy, not a law. FMFIA is the law. A-123 implements it. This distinction matters when you are talking about what is legally required versus what is executive branch policy.
• "Appendix A is only about ICFR." Not since 2018. Appendix A was retitled "Management of Reporting and Data Integrity Risk" and expanded to cover all reporting objectives, including non-financial reporting. It is still the primary reference for ICFR, but it is broader now.
• "The Green Book is optional." The Green Book is the standard the Comptroller General was directed to prescribe under FMFIA. Federal executive branch agencies are required to establish internal control in accordance with these standards. Ignoring the Green Book is not really an option.
• "The 2014 Green Book is still current." Not for reports covering FY 2026 and beyond. The 2025 revision supersedes the 2014 version. Early implementation is permitted.
• "SOX and A-123 are the same thing." Sarbanes-Oxley applies to publicly traded companies. FMFIA and A-123 apply to federal agencies. The concepts overlap because both address ICFR, but the legal basis and specific requirements differ.
• "The agency head can delegate the assurance statement." No. The statute requires the agency head to submit the annual report. Others prepare the analysis, but the agency head signs.

Frequently asked questions

What does FMFIA stand for?

FMFIA stands for the Federal Managers' Financial Integrity Act. Enacted in 1982, it requires the head of each executive agency to establish internal accounting and administrative controls and to report annually to the President and Congress on the effectiveness of those controls. FMFIA is codified at 31 U.S.C. § 3512.

What is OMB Circular A-123?

OMB Circular A-123, Management's Responsibility for Enterprise Risk Management and Internal Control, is the executive branch's operational framework for implementing FMFIA. The base circular was most recently revised on July 15, 2016 to integrate enterprise risk management with internal control and to expand scope from financial reporting alone to all three internal control objectives (operations, reporting, compliance). It has four appendices: Appendix A (reporting and data integrity risk), Appendix B (charge card programs), Appendix C (payment integrity), and Appendix D (financial management systems).

What does A-123 Appendix A cover?

Appendix A to OMB Circular A-123 is titled "Management of Reporting and Data Integrity Risk." It was revised on June 6, 2018 through OMB Memorandum M-18-16. The 2018 revision expanded the scope from internal control over financial reporting alone (the original 2004 focus) to include all reporting objectives, financial and non-financial. Appendix A remains the primary reference for federal ICFR assessments, but it now covers the broader reporting risk landscape, including data quality requirements under the DATA Act.

What is the GAO Green Book?

The GAO Green Book is the informal name for the GAO Standards for Internal Control in the Federal Government. The current version is the 2025 revision, GAO-25-107721, effective for fiscal year 2026. It defines the five components of an effective internal control system: Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring. Each component has principles (17 total) and each principle has application guidance called attributes. The Green Book is adapted from the COSO Internal Control - Integrated Framework.

Does A-123 require evaluation of every Green Book principle?

Yes. A-123 requires each agency to evaluate its system of internal control against every one of the 17 Green Book principles. For each principle, the agency must determine whether it is designed, implemented, and operating effectively. Where a principle is not met, the agency must document the deficiency and identify the specific principle. This is a substantive obligation, not a checkbox exercise. It shapes how walk-throughs, testing, and findings documentation are scoped throughout the year.

How are FMFIA, OMB A-123, and the Green Book related?

FMFIA is the statute (the why), OMB A-123 is the policy that implements the statute (the how), and the Green Book is the standard that defines what effective internal control looks like (the what). FMFIA directs the Comptroller General to prescribe internal control standards, which is why the Green Book exists. A-123 gives agencies the operational methodology to satisfy FMFIA using the Green Book criteria. All three documents work together to produce the annual assurance statement.

Is the Green Book the same as COSO?

The Green Book is adapted from the COSO Internal Control - Integrated Framework for use in the federal government. The five components and 17 principles map directly. The Green Book uses federal-specific terminology and examples but is conceptually aligned with COSO. The 2025 revision explicitly notes continued harmonization with COSO. Someone with strong COSO experience from private sector work will find the Green Book familiar, with mostly terminology and context adjustments required.

Who is responsible for signing the FMFIA assurance statement?

The agency head personally. FMFIA requires the head of each executive agency to submit the annual report on internal control effectiveness. This responsibility cannot be delegated. The CFO and internal control office prepare the analysis and supporting work papers, but the agency head signs and takes personal accountability.

Where can I find OMB Circular A-123?

OMB Circular A-123 and its four appendices are published on the OMB website at whitehouse.gov/omb. The base circular was last revised July 15, 2016. The appendices have been revised on different dates: Appendix A (6/6/2018), Appendix B (8/27/2019), Appendix C (3/5/2021), and Appendix D (12/23/2022). Always work from the current version of each.

Where can I find the GAO Green Book?

The GAO Green Book is available at gao.gov/greenbook. The current version is the 2025 revision, GAO-25-107721. GAO also publishes an implementation guide and other supporting resources at that location.

What to learn next

Sources

• Federal Managers' Financial Integrity Act of 1982, 31 U.S.C. § 3512
• OMB Circular A-123, Management's Responsibility for Enterprise Risk Management and Internal Control (Revised 7/15/2016)
• Appendix A to OMB Circular A-123, Management of Reporting and Data Integrity Risk (Revised 6/6/2018, M-18-16)
• Appendix B to OMB Circular A-123, Risk Management Framework for Government Charge Card Programs (Revised 8/27/2019)
• Appendix C to OMB Circular A-123, Requirements for Payment Integrity Improvement (Revised 3/5/2021)
• Appendix D to OMB Circular A-123, Management of Financial Management Systems - Risk and Compliance (Revised 12/23/2022)
• GAO Standards for Internal Control in the Federal Government (Green Book), 2025 Revision, GAO-25-107721 (effective FY 2026; supersedes GAO-14-704G)
• COSO Internal Control - Integrated Framework