US · guidance
BOP Program Statement 1211.02 § 2
DEFINITIONS
a. Audit Authority. The management official responsible for ensuring audits are conducted and
verifying the effective functioning of management and control systems for their program areas of
responsibility.
b. Common Finding. A formal finding, observation, or condition of concern that is
noted frequently, in large numbers, or that otherwise creates concerns of a systemic issue,
warranting broad corrective and/or preventative action.
c. Component. Institution, Residential Reentry Management Office, Regional Office, and
Divisions within the Bureau.
d. Corrective Action. The process of identifying and eliminating the root cause of a detected
problem to prevent its recurrence.
e. Finding. A reportable deficiency, noncompliance, or fraud identified during an audit,
developed by comparing the condition (what is) against criteria (e.g. rules, regulations, policy
and/or industry standard).
f. Internal Control. A process affected by an entity’s oversight body, management, and other
personnel that provides reasonable assurance that the objectives of an entity will be achieved.
g. Internal Control Audits. Internal Control Audits (ICA) are an assessment of one or more
aspects of an entity’s system of internal control that are designed to provide reasonable assurance
of achieving effective and efficient operations, and reliability of reporting for internal and
external stakeholders. ICA is an evaluation of an organization’s policies, procedures, and systems
designed to ensure effective risk management, accurate financial reporting, and regulatory
compliance. It assesses if controls are properly designed, implemented, and functioning to
prevent fraud and errors, ultimately improving operational efficiency.
h. Management Response Action Plan (MRAP). Documentation of corrective action for
findings identified during the audit process to reduce the likelihood of recurrence.
1211.02 6/22/2026 PROPERTY OF US GOVERNMENT 2
i. Recommendation. A formally proposed action made by auditors to management, designed
to correct identified deficiencies in internal controls, address findings, or improve efficiency and
effectiveness of government programs.
j. Risk Assessment. A systematic process that involves identifying, analyzing and prioritizing
risks (specifically those threatening the achievement of operational objectives) to determine the
appropriate controls needed to manage them.
k. Substantive Comments. Meaningful concerns regarding methodology, findings,
conclusions, or recommendations as outlined in the working draft report.
l. Technical Comments. Technical comments address points of fact or are editorial in nature
and do not address substantive issues, such as methodology, findings, conclusions or
recommendation as outlined in the working draft report.
History
PS 1211.02 dated 2026-06-22
Provenance
- Source
- bop.gov
- Retrieved
- 2026-09-20
- Edition
- bop-ps-2026-09-20
- Content hash
6e4e8259d24fc5512768d7185064e77f4521b78cd02fc4ed1c1c027d684319ff
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.