CGRC Governance Principles 4 — Questions and Answers
Question 1: Which of the following is an example of a leading key risk indicator (KRI)?
- Number of data breaches in the past year
- Employee turnover rate in the compliance department (Correct answer)
- Regulatory fines already paid
- Audit findings from the prior quarter
Correct answer: Employee turnover rate in the compliance department
Employee turnover in compliance is a leading KRI because elevated turnover may signal future compliance failures before they occur.
Question 2: A governance structure where business units have significant autonomy in making risk and compliance decisions is characterized as:
- Centralized governance
- Federated governance (Correct answer)
- Hierarchical governance
- Directive governance
Correct answer: Federated governance
Federated governance balances central oversight with business unit autonomy, allowing decentralized decision-making within defined boundaries.
Question 3: Under the Sarbanes-Oxley Act (SOX), which section requires management to assess and report on internal controls over financial reporting?
- Section 302
- Section 404 (Correct answer)
- Section 906
- Section 201
Correct answer: Section 404
SOX Section 404 requires management to assess the effectiveness of internal controls over financial reporting and have auditors attest to that assessment.
Question 4: Which principle requires governance processes to be proportional to the size, complexity, and risk profile of the organization?
- Scalability
- Materiality
- Proportionality (Correct answer)
- Relevance
Correct answer: Proportionality
Proportionality means governance controls and processes should be scaled appropriately to the organization's size, complexity, and risk level.
Question 5: Which governance role is primarily responsible for championing the GRC program and ensuring it receives adequate resources?
- Chief Compliance Officer
- Executive Sponsor (Correct answer)
- Risk Owner
- Internal Auditor
Correct answer: Executive Sponsor
An Executive Sponsor advocates for the GRC program at the senior leadership level and ensures it has the authority and resources needed to succeed.
Question 6: The concept of 'duty of care' in board governance requires directors to:
- Personally guarantee the company's financial obligations
- Act in an informed and diligent manner when making decisions (Correct answer)
- Approve all contracts above a set threshold
- Attend every operational meeting
Correct answer: Act in an informed and diligent manner when making decisions
Duty of care requires directors to make decisions on an informed basis, exercising the diligence and prudence of a reasonable person.
Question 7: Which approach to policy management ensures all policies are reviewed for consistency, gaps, and conflicts across the organization?
- Decentralized policy ownership
- Policy lifecycle management (Correct answer)
- Ad hoc policy review
- Shadow policy development
Correct answer: Policy lifecycle management
Policy lifecycle management provides a structured approach to creating, reviewing, updating, and retiring policies to maintain consistency and completeness.
Which of the following is an example of a leading key risk indicator (KRI)?