CGRC Governance Principles 3 — Questions and Answers
Question 1: Which of the following best describes the concept of 'tone at the top' in governance?
- The volume of compliance training delivered to staff
- Leadership's demonstrated commitment to ethical culture and compliance (Correct answer)
- The strictness of disciplinary procedures
- The number of board-level policies in place
Correct answer: Leadership's demonstrated commitment to ethical culture and compliance
'Tone at the top' refers to leadership's visible commitment to ethical conduct, which shapes organizational culture.
Question 2: Which COSO component addresses the policies and procedures that help ensure management directives are carried out?
- Risk Assessment
- Control Activities (Correct answer)
- Monitoring Activities
- Information and Communication
Correct answer: Control Activities
Control Activities are the policies and procedures that help ensure management's risk responses are properly executed.
Question 3: A company's audit committee is composed entirely of executive directors. This arrangement violates which governance principle?
- Proportionality
- Independence (Correct answer)
- Accountability
- Stewardship
Correct answer: Independence
Audit committee members should be independent (non-executive) directors to provide objective oversight without conflicts of interest.
Question 4: Which governance mechanism is designed to prevent any single individual from having unchecked authority over critical processes?
- Risk appetite statement
- Segregation of duties (Correct answer)
- Control self-assessment
- Key risk indicators
Correct answer: Segregation of duties
Segregation of duties divides critical tasks among multiple individuals to prevent errors, fraud, and abuse of authority.
Question 5: In the CGRC context, 'governance' is best defined as:
- The process of identifying and quantifying risks
- The system of rules, practices, and processes by which an organization is directed and controlled (Correct answer)
- The set of technical controls protecting information assets
- The legal requirements imposed by regulators
Correct answer: The system of rules, practices, and processes by which an organization is directed and controlled
Governance is the system of rules, practices, and processes by which an organization is directed, controlled, and held accountable.
Question 6: Which document communicates an organization's high-level expectations and requirements for a specific area of governance?
- Procedure
- Standard
- Policy (Correct answer)
- Guideline
Correct answer: Policy
A policy establishes high-level expectations and mandatory requirements, while procedures and standards provide more detailed implementation guidance.
Question 7: What is the primary purpose of a governance risk and compliance (GRC) framework?
- To replace internal audit functions
- To integrate governance, risk management, and compliance into a cohesive approach (Correct answer)
- To automate regulatory reporting
- To eliminate all organizational risk
Correct answer: To integrate governance, risk management, and compliance into a cohesive approach
A GRC framework integrates governance, risk management, and compliance activities to create a unified and efficient approach to organizational oversight.
Which of the following best describes the concept of 'tone at the top' in governance?