CGRC Compliance and Policy 4 — Questions and Answers
Question 1: A compliance officer identifies a control that mitigates risk but is not explicitly required by any regulation. The cost to maintain the control is high. What should the officer recommend?
- Remove the control immediately to reduce costs
- Conduct a cost-benefit analysis and present findings to leadership for a risk-based decision (Correct answer)
- Add the control to the regulatory requirement list
- Transfer the risk to a third party without further analysis
Correct answer: Conduct a cost-benefit analysis and present findings to leadership for a risk-based decision
A cost-benefit analysis provides the data leadership needs to make an informed, risk-based decision about maintaining or removing the control.
Question 2: What distinguishes a 'standard' from a 'policy' in a governance documentation hierarchy?
- Standards are optional; policies are mandatory
- Standards provide specific, measurable requirements that support policy statements (Correct answer)
- Policies are technical documents; standards are management-level documents
- There is no meaningful distinction between the two
Correct answer: Standards provide specific, measurable requirements that support policy statements
Policies state high-level intent and requirements, while standards define the specific, measurable criteria for meeting those policy requirements.
Question 3: Which of the following BEST describes a 'compliance gap analysis'?
- An assessment comparing current practices against required compliance obligations to identify deficiencies (Correct answer)
- A financial audit of compliance program costs
- A review of employee satisfaction with compliance training
- A list of all regulations that do not apply to the organization
Correct answer: An assessment comparing current practices against required compliance obligations to identify deficiencies
A gap analysis compares where the organization is against where it needs to be under applicable requirements, surfacing areas needing remediation.
Question 4: An employee reports a potential compliance violation through the organization's hotline. Under best practices, what should happen FIRST?
- Terminate the subject of the report pending investigation
- Acknowledge receipt, protect reporter confidentiality, and initiate a preliminary review (Correct answer)
- Share the report details with all managers for awareness
- Forward the report directly to law enforcement
Correct answer: Acknowledge receipt, protect reporter confidentiality, and initiate a preliminary review
Best practice requires confirming receipt, protecting the reporter from retaliation, and conducting a preliminary review before any other action.
Question 5: The Children's Online Privacy Protection Act (COPPA) applies to websites and online services directed at children under what age?
- 13 (Correct answer)
- 16
- 18
- 21
Correct answer: 13
COPPA applies to operators of websites and online services directed to children under 13 and requires verifiable parental consent for data collection.
Question 6: Which of the following BEST describes the concept of 'privacy by design' as it applies to compliance?
- Retrofitting privacy controls after a product is launched
- Embedding privacy protections into systems and processes from the outset of development (Correct answer)
- Designing privacy policies after a regulatory audit
- Outsourcing all privacy responsibilities to a third party
Correct answer: Embedding privacy protections into systems and processes from the outset of development
Privacy by design requires integrating privacy protections proactively into product and process design rather than as an afterthought.
Question 7: A company operating in the EU must appoint a Data Protection Officer (DPO) under GDPR. Which scenario does NOT trigger this requirement?
- A public authority processing personal data
- A company whose core activities involve large-scale systematic monitoring of individuals
- A small retailer processing employee payroll data only (Correct answer)
- An organization processing special category data on a large scale
Correct answer: A small retailer processing employee payroll data only
GDPR's DPO requirement is triggered by public authorities, large-scale systematic monitoring, or large-scale special category data processing — not routine HR payroll processing.
A compliance officer identifies a control that mitigates risk but is not explicitly required by any regulation.
The cost to maintain the control is high.
What should the officer recommend?