Change Management Regulatory Frameworks & Compliance 3 — Questions and Answers
Question 1: What is the primary purpose of a regulatory impact assessment (RIA) in the change management process?
- To estimate the financial cost of implementing a change
- To identify which regulations are affected by a proposed change and assess compliance risks (Correct answer)
- To determine whether a change requires CAB approval
- To measure employee resistance to the proposed change
Correct answer: To identify which regulations are affected by a proposed change and assess compliance risks
A regulatory impact assessment evaluates which laws, standards, or regulations a change may affect and identifies compliance risks before the change is approved.
Question 2: A healthcare organization is migrating its EHR system to the cloud. Under HIPAA, which change management artifact is most important to update before go-live?
- Marketing plan
- Business Associate Agreement (BAA) with the cloud provider (Correct answer)
- Annual budget forecast
- Organizational chart
Correct answer: Business Associate Agreement (BAA) with the cloud provider
HIPAA requires a signed BAA with any business associate that will handle ePHI, making it a mandatory pre-deployment compliance artifact for cloud migrations.
Question 3: Which change management framework principle most directly supports regulatory audit readiness?
- Speed of deployment
- Comprehensive documentation and traceability of all changes (Correct answer)
- Minimizing the number of stakeholders involved
- Automating all change approvals
Correct answer: Comprehensive documentation and traceability of all changes
Audit readiness depends on maintaining complete, traceable records that demonstrate changes were authorized, tested, and implemented in a controlled manner.
Question 4: Under the FDA 21 CFR Part 11 regulation, what is required when software used in pharmaceutical manufacturing undergoes a change?
- Revalidation of the system to ensure it still meets regulatory requirements (Correct answer)
- Submission of a new drug application
- Replacement of all electronic signatures
- An independent third-party security audit
Correct answer: Revalidation of the system to ensure it still meets regulatory requirements
FDA 21 CFR Part 11 requires that validated computerized systems undergo revalidation after significant changes to ensure continued compliance and data integrity.
Question 5: In a SOX-compliant change management process, which role is typically prohibited from having both development and production deployment access?
- Change Manager
- Developer (Correct answer)
- CAB Chair
- Risk Officer
Correct answer: Developer
Developers must not have production deployment access under SOX controls, as this would violate segregation of duties requirements for financially significant systems.
Question 6: A bank subject to OCC guidelines experiences an unauthorized change to a core banking system. What is the MOST important immediate compliance obligation?
- Submit a currency transaction report
- Document and investigate the incident per the bank's change control incident response policy (Correct answer)
- Immediately restore the previous system version
- Notify all customers of the unauthorized change
Correct answer: Document and investigate the incident per the bank's change control incident response policy
OCC guidelines require that unauthorized changes trigger a documented incident investigation to determine scope, impact, and root cause as part of the bank's control environment.
Question 7: Which ITIL practice most directly supports regulatory compliance by ensuring that all changes are formally recorded and traceable?
- Service Desk
- Change Enablement (Correct answer)
- Continual Improvement
- Service Level Management
Correct answer: Change Enablement
ITIL's Change Enablement practice governs the authorization and documentation of all changes, creating the audit trail that regulators require.
What is the primary purpose of a regulatory impact assessment (RIA) in the change management process?