Skip to main content
Framework library
Framework module · gao-green-book-2025

GAO Green Book

The federal internal-control standard for designing, implementing, operating, and evaluating controls over operations, reporting, and compliance. It supplies auditable criteria for federal entities; it is not an organizational certification.

2025 Revision · US Government Accountability Office · published 2025-05-15

Standing today
Directory entry

00Answer

from the registry record
What is GAO Green Book?
The federal internal-control standard for designing, implementing, operating, and evaluating controls over operations, reporting, and compliance. It supplies auditable criteria for federal entities; it is not an organizational certification.
Who does GAO Green Book apply to?
GAO Green Book applies to federal, government audit, public sector, US, per US Government Accountability Office.
What is the current version of GAO Green Book?
The current edition is 2025 Revision, issued by US Government Accountability Office and published 2025-05-15. Source: https://www.gao.gov/greenbook.
What does an assessment under GAO Green Book require?
No control catalog has been ingested for GAO Green Book yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

GAO Green Book is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

GAO publishes the complete current standard; pin the 2025 Revision and its fiscal-year-2026 effective guidance before normalization.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Control environment · Risk assessment · Control activities · Information and communication · Monitoring
Applies to
federal · government audit · public sector · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28

03Version ledger

2 editions
2014 RevisionSuperseded2014-09-10
2025 RevisionCurrent edition · supersedes 2014 Revision2025-05-15

05Change history

06Related frameworks

scored from registry facts
  1. GAO FISCAMJune 2026 (GAO-26-108633)

    Also applies to federal · The federal audit methodology for assessing the design, implementation, and operating effectiveness of information-system controls under generally accepted government auditing standards. It is audit guidance, not an agency authorization or certification.

  2. Commonly assessed together · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.

  3. Also applies to government audit · Generally accepted government auditing standards for financial audits, attestation engagements, reviews, and performance audits. They govern auditor and audit-organization quality; they do not certify the entity being audited.

  4. FISMAFederal Information Security Modernization Act of 2014

    Also applies to federal · The Federal Information Security Modernization Act of 2014 — the statutory authority a federal RFP names, implemented operationally through NIST SP 800-53 and the NIST Cybersecurity Framework, both already tracked as their own registry entries.

GAO Green Book | ControlFrame