MCO 5200.24F governs the Marine Corps’ Risk Management and Internal Control Program, including risk mitigation and oversight.
View MCO 5200.24F on armypubs.army.mil
It establishes requirements for enterprise risk management, internal control design, assessment, validation, documentation, and reporting. It also addresses corrective action plans, the MICRR application, privacy, classified programs, and annual RMIC activities.
Applies to: This Order is applicable to the Marine Corps Total Force.
The Marine Corps must establish and maintain an RMIC Program, in accordance with the requirements set forth in references (a) through (d), along with a framework for its governance and oversight. (paragraph 3)
Stakeholders across the Marine Corps must design, implement, execute, and document key internal controls to mitigate those risks that may prevent the Marine Corps from meeting organizational goals and objectives. (paragraph 3)
All “reporting units” depicted in enclosure (1) are required to complete continuous risk assessments that support the achievement of the Marine Corps’ mission. (paragraph 3)
Annually, RMIC activities (e.g. walkthroughs, risk assessments, validation testing, corrective action plans, etc.) are performed during the first three quarters of the fiscal year on priority areas described within the RMIC Operating Plan. (paragraph 3)
All deficiencies identified require corrective action plans (CAPs) to be developed by the responsible stakeholders and executed in a timely manner. (paragraph 3)