GRC Cheat Sheet 2026

The 30 highest-yield GRC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

100 questions
120 min time limit
75% to pass
  1. An organization publishes a new data classification policy but employees continue using the old scheme. What is the most likely root cause? → Insufficient communication and training on the new policy
  2. The ultimate goal of implementing an integrated GRC capability, as defined by OCEG, is to achieve: → Principled Performance
  3. Which type of risk arises from inadequate or failed internal processes, people, systems, or external events? → Operational risk
  4. The COSO Internal Control — Integrated Framework identifies five components. Which component addresses the 'tone at the top' concept? → Control Environment
  5. Which quantitative technique uses repeated random sampling to model the probability distribution of risk outcomes? → Monte Carlo simulation
  6. An organization separates the duties of transaction authorization, recording, and custody of assets. This is an example of: → Segregation of duties
  7. The NIST Privacy Framework's 'Communicate-P' function focuses on: → Increasing awareness of how privacy values are implemented in policies and practices
  8. A firm's BIA reveals that its order-processing system must be restored within 4 hours. This figure represents the: → RTO
  9. Under the Payment Card Industry Data Security Standard (PCI DSS), what is the minimum password length required for system access? → 12 characters
  10. Under the NIST Cybersecurity Framework, which function involves identifying assets, risks, and governance requirements? → Identify
  11. In GRC, what does 'inherent risk' refer to? → The risk that exists before any controls or mitigating actions are implemented
  12. Which term describes the risk that remains after all controls and mitigation strategies have been applied? → Residual risk
  13. How can organizations measure the effectiveness of their GRC programs? → Track KPIs and assess outcomes
  14. The concept of 'privacy by design' in regulatory compliance requires that privacy protections be integrated at which stage of system development? → From the earliest design phase onward
  15. What is the role of internal controls in governance? → Ensure effective operations and compliance
  16. Which risk response strategy is most appropriate when a risk has very low likelihood and very low impact? → Accept
  17. An organization sets its RPO at zero for financial transaction data. What technology best supports this requirement? → Synchronous real-time replication
  18. During an audit, the auditor requests evidence that the acceptable use policy was in effect 18 months ago. What is needed? → An archived version of the policy as it existed 18 months ago
  19. During a risk review, the team identifies that a mitigation control has reduced the likelihood of a risk but not its impact. What has changed? → The residual risk profile has changed — lower likelihood, same impact
  20. A company discovers that a firewall misconfiguration has been present for six months. Which risk metric best measures how long the vulnerability was exposed? → Mean Time to Detect (MTTD)
  21. Which governance concept describes the board's responsibility to ensure the organization acts in the long-term interests of shareholders and other stakeholders? → Agency theory
  22. Under the Children's Online Privacy Protection Act (COPPA), parental consent is required before collecting personal information from children under what age? → 13
  23. Which risk identification method involves structured interviews and workshops with business stakeholders to surface risks from those closest to the processes? → Facilitated risk workshops and interviews
  24. A risk register typically contains all of the following EXCEPT: → Employee performance evaluations
  25. What is a best practice in implementing governance frameworks? → Involve key stakeholders
  26. Which ISO standard specifically provides guidance on governance of information security, acting as a companion to ISO/IEC 27001? → ISO/IEC 27014
  27. In the context of internal auditing, what does 'independence' mean? → The internal audit function is free from conditions that threaten objectivity
  28. A governance committee reviews an IT investment proposal. Which framework component ensures IT investments deliver value and align with business strategy? → Value delivery in COBIT
  29. A governance framework requires that policies cascade through an organization. Which document type sits directly below a board-approved policy? → Standard
  30. Which metric is MOST useful for measuring how quickly an organization identifies and responds to vendor-related security incidents? → Mean Time to Detect and Respond (MTTR/MTTD) for vendor incidents
Turn these facts into recall:
Was this helpful?