← All GRC Flashcard Decks

Governance Frameworks & Best Practices Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Governance Frameworks & Best Practices flashcards as text
  1. In a GRC program, 'integrated GRC' refers to an approach where:

    Answer: Governance, risk, and compliance activities share common data, processes, and technology

    Integrated GRC breaks down silos by using a unified platform, common taxonomy, and shared processes across governance, risk, and compliance activities.

  2. Which principle in the UN Global Compact specifically requires companies to support and respect internationally proclaimed human rights?

    Answer: Principle 1

    UN Global Compact Principle 1 states that businesses should support and respect the protection of internationally proclaimed human rights.

  3. A chief compliance officer (CCO) receives a request from the CEO to waive a policy requirement for a key client deal. The best governance response is to:

    Answer: Evaluate the request against the formal waiver process and escalate to the board if material

    Waivers should follow a documented approval process, and material waivers that affect regulatory compliance should be escalated to the audit committee or board.

  4. The COSO Internal Control — Integrated Framework identifies five components. Which component addresses the 'tone at the top' concept?

    Answer: Control Environment

    The Control Environment component encompasses the organization's commitment to integrity, ethical values, and management's oversight — often called 'tone at the top.'

  5. Under the GDPR governance requirements, what role must certain organizations appoint to oversee data protection compliance?

    Answer: Data Protection Officer (DPO)

    GDPR Article 37 mandates that certain public authorities, and organizations processing sensitive data at scale, appoint a Data Protection Officer.

  6. When building a governance dashboard, which metric type most directly helps the board understand whether controls are preventing failures before they occur?

    Answer: Leading indicators (e.g., control testing completion rates)

    Leading indicators signal future risk by measuring the health of preventive activities, unlike lagging indicators that measure outcomes after failures occur.

  7. Which of the following scenarios represents a failure of the 'separation of duties' control in a governance framework?

    Answer: The same employee both approves purchase orders and processes vendor payments

    Separation of duties requires that no single individual control an entire transaction process; combining approval and payment functions creates fraud risk.