GRC Cheat Sheet 2026

The 30 highest-yield GRC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

100 questions
120 min time limit
75% to pass
  1. An organization publishes a new data classification policy but employees continue using the old scheme. What is the most likely root cause? Insufficient communication and training on the new policy
  2. The ultimate goal of implementing an integrated GRC capability, as defined by OCEG, is to achieve: Principled Performance
  3. Which type of risk arises from inadequate or failed internal processes, people, systems, or external events? Operational risk
  4. The COSO Internal Control — Integrated Framework identifies five components. Which component addresses the 'tone at the top' concept? Control Environment
  5. Which quantitative technique uses repeated random sampling to model the probability distribution of risk outcomes? Monte Carlo simulation
  6. An organization separates the duties of transaction authorization, recording, and custody of assets. This is an example of: Segregation of duties
  7. The NIST Privacy Framework's 'Communicate-P' function focuses on: Increasing awareness of how privacy values are implemented in policies and practices
  8. A firm's BIA reveals that its order-processing system must be restored within 4 hours. This figure represents the: RTO
  9. Under the Payment Card Industry Data Security Standard (PCI DSS), what is the minimum password length required for system access? 12 characters
  10. Under the NIST Cybersecurity Framework, which function involves identifying assets, risks, and governance requirements? Identify
  11. In GRC, what does 'inherent risk' refer to? The risk that exists before any controls or mitigating actions are implemented
  12. Which term describes the risk that remains after all controls and mitigation strategies have been applied? Residual risk
  13. How can organizations measure the effectiveness of their GRC programs? Track KPIs and assess outcomes
  14. The concept of 'privacy by design' in regulatory compliance requires that privacy protections be integrated at which stage of system development? From the earliest design phase onward
  15. What is the role of internal controls in governance? Ensure effective operations and compliance
  16. Which risk response strategy is most appropriate when a risk has very low likelihood and very low impact? Accept
  17. An organization sets its RPO at zero for financial transaction data. What technology best supports this requirement? Synchronous real-time replication
  18. During an audit, the auditor requests evidence that the acceptable use policy was in effect 18 months ago. What is needed? An archived version of the policy as it existed 18 months ago
  19. During a risk review, the team identifies that a mitigation control has reduced the likelihood of a risk but not its impact. What has changed? The residual risk profile has changed — lower likelihood, same impact
  20. A company discovers that a firewall misconfiguration has been present for six months. Which risk metric best measures how long the vulnerability was exposed? Mean Time to Detect (MTTD)
  21. Which governance concept describes the board's responsibility to ensure the organization acts in the long-term interests of shareholders and other stakeholders? Agency theory
  22. Under the Children's Online Privacy Protection Act (COPPA), parental consent is required before collecting personal information from children under what age? 13
  23. Which risk identification method involves structured interviews and workshops with business stakeholders to surface risks from those closest to the processes? Facilitated risk workshops and interviews
  24. A risk register typically contains all of the following EXCEPT: Employee performance evaluations
  25. What is a best practice in implementing governance frameworks? Involve key stakeholders
  26. Which ISO standard specifically provides guidance on governance of information security, acting as a companion to ISO/IEC 27001? ISO/IEC 27014
  27. In the context of internal auditing, what does 'independence' mean? The internal audit function is free from conditions that threaten objectivity
  28. A governance committee reviews an IT investment proposal. Which framework component ensures IT investments deliver value and align with business strategy? Value delivery in COBIT
  29. A governance framework requires that policies cascade through an organization. Which document type sits directly below a board-approved policy? Standard
  30. Which metric is MOST useful for measuring how quickly an organization identifies and responds to vendor-related security incidents? Mean Time to Detect and Respond (MTTR/MTTD) for vendor incidents
Turn these facts into recall:
Was this helpful?
GRC Cheat Sheet 2026 — Free Printable Quick-Reference