Risk Management & Compliance Flashcards
7 cards from real CMP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Compliance flashcards as text
A planner is using a mobile event app that collects attendee personal data for a European audience. Which regulation governs data handling?
Answer: GDPR
The General Data Protection Regulation (GDPR) governs the collection and processing of personal data for individuals in the European Union.
During an outdoor event, a severe weather warning is issued. What should the emergency action plan prioritize FIRST?
Answer: Moving attendees to pre-identified shelter locations
Life safety is always the first priority in any emergency, requiring immediate movement of attendees to safe shelter.
What does a 'force majeure' clause in an event contract primarily protect against?
Answer: Cancellation or disruption caused by unforeseeable, uncontrollable events
Force majeure clauses excuse contract performance when extraordinary events beyond either party's control make performance impossible.
Which risk assessment tool plots the likelihood of a risk event against its potential impact?
Answer: Risk matrix (probability-impact grid)
A risk matrix visually maps probability against impact to help planners prioritize which risks require the most attention.
An event venue requires all external vendors to submit certificates of insurance naming the venue as an additional insured. Why?
Answer: To ensure the venue is covered under the vendor's policy for liability claims arising from vendor actions
Adding the venue as an additional insured on a vendor's policy means the venue has coverage protection if the vendor's actions cause a claim.
A conference organizer collects credit card data through an online registration portal. Which standard governs secure handling of this data?
Answer: PCI-DSS
Payment Card Industry Data Security Standard (PCI-DSS) mandates specific controls for any organization that stores, processes, or transmits cardholder data.
What is the PRIMARY purpose of conducting a post-event incident debrief after a risk event occurs?
Answer: To identify what worked and what failed so future risk plans can be improved
Post-event debriefs are a learning tool to improve future emergency response plans, not to attribute fault.