← All CRM Flashcard Decks

Mixed Deck — All CRM Topics Flashcards

98 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CRM Topics flashcards as text
  1. Which approach best describes 'records management by design' in new information systems?

    Answer: Building records management requirements directly into new systems during their development

    Records management by design integrates records management requirements—such as capture, classification, and retention—directly into new systems during their development phase rather than as an afterthought.

  2. What is the primary goal of regulatory compliance in CRM practice?

    Answer: Ensuring adherence to laws and standards governing professional practice

    Regulatory compliance ensures professionals follow applicable laws and standards to protect public safety and maintain quality.

  3. During the planning phase of a records retention schedule overhaul, the project manager develops a document that describes how changes will be identified, evaluated, and approved. This is called the:

    Answer: Change management plan

    The change management plan defines the process for submitting, reviewing, approving, and implementing changes to the project baseline.

  4. Under ARMA International filing rules, how should the business name 'The Johnson Group' be indexed?

    Answer: Johnson Group The

    ARMA rules treat articles like 'The' as non-essential and transpose them to the end of the filing unit.

  5. The Dodd-Frank Wall Street Reform Act requires certain financial records to be retained for how many years?

    Answer: 5 years

    Dodd-Frank generally imposes 5-year retention requirements for various financial records, including swap transaction data under CFTC rules.

  6. Under OSHA regulations, how long must employers retain records of employee exposure to toxic substances or harmful physical agents?

    Answer: 30 years

    OSHA's Access to Employee Exposure and Medical Records standard (29 CFR 1910.1020) requires retaining exposure records for 30 years.

  7. ERISA requires that employee benefit plan records be retained for a minimum of how many years?

    Answer: 6 years

    ERISA Section 107 requires that records supporting reports filed under ERISA be retained for not less than 6 years after the filing date.

  8. Which regulation requires financial institutions to implement customer information security programs and report breaches to regulators?

    Answer: Gramm-Leach-Bliley Act (GLBA)

    GLBA's Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security program.

  9. Which control is specifically designed to limit the number of employees who can access highly sensitive personnel records?

    Answer: Need-to-know access

    Need-to-know access restricts record access to only those individuals whose job functions require it, reducing unauthorized disclosure risk.

  10. Under HIPAA, how long must a covered entity retain its written privacy policies and procedures?

    Answer: 6 years from creation or last effective date

    HIPAA requires covered entities to retain privacy policies, procedures, and related documentation for 6 years from the date of creation or the date it was last in effect.

  11. Which strategic planning concept refers to the set of high-level decisions that define how a records program will achieve its long-term vision?

    Answer: Strategic objectives

    Strategic objectives are the high-level goals that translate vision into direction, guiding decisions about priorities and resource allocation.

  12. What is the hierarchy of controls in CRM risk management?

    Answer: Elimination, substitution, engineering, administrative, then PPE

    The hierarchy prioritizes the most effective controls first, from eliminating the hazard to using PPE as last resort.

  13. Which process group in project management is concerned with defining, planning, executing, monitoring, and closing project phases?

    Answer: Process groups

    The five PMBOK process groups — Initiating, Planning, Executing, Monitoring & Controlling, and Closing — guide project management activities.

  14. A 'box-level inventory' at a records center captures:

    Answer: Container information, date ranges, and disposition dates

    Box-level inventories record container ID, contents description, date range, and scheduled destruction date without itemizing each document.

  15. A records management program update requires buy-in from multiple departments. Which approach best ensures broad stakeholder support?

    Answer: Involve key stakeholders in the planning process from the beginning

    Early stakeholder involvement creates ownership and reduces resistance to program changes.

  16. In project risk management, a risk response strategy where the records department transfers responsibility for a risk to a third party is called:

    Answer: Transfer

    Risk transfer shifts the negative impact of a risk to a third party, such as through insurance or outsourcing contracts.

  17. What should be considered when assessing the risk of data breaches in electronic records management?

    Answer: The security measures, including encryption, access control, and regular audits to prevent unauthorized access and breaches.

    When assessing the risk of data breaches in electronic records management, key considerations include the strength of security measures in place. This encompasses encryption protocols, robust access controls, and regular security audits to identify vulnerabilities and prevent unauthorized access. Proactive assessment and continuous improvement of these measures are critical for data protection.

  18. A new records management policy affects multiple business units differently. How should the communications be structured?

    Answer: Customize communications to highlight the specific impact and required actions for each business unit

    Tailored communications ensure each unit understands its specific obligations and reduces confusion about policy application.

  19. A records program seeks to integrate with the organization's enterprise risk management (ERM) process. Which records-related risk category is most commonly included in ERM frameworks?

    Answer: Information governance and compliance risk

    Information governance and compliance risk—encompassing data breaches, regulatory violations, and e-discovery failures—is the records-related risk most prominent in ERM frameworks.

  20. In a terminal-digit filing system with the number 24-36-15, which digits serve as the primary guide?

    Answer: 15

    In terminal-digit filing, the last group of digits (15) serves as the primary filing guide.