GRC Ethics, Culture, and Stakeholder Accountability Flashcards
6 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 GRC Ethics, Culture, and Stakeholder Accountability flashcards as text
In GRC, 'accountability' at the board level primarily means that directors are responsible for:
Answer: Providing oversight and ensuring management establishes and maintains an effective governance and risk framework
Board-level accountability in GRC means directors oversee and challenge management's approach to governance and risk rather than performing operational compliance tasks themselves.
Which of the following is a characteristic of a strong organizational compliance culture?
Answer: Compliance concerns are discussed openly and leadership consistently models expected behavior
A strong compliance culture is characterized by open communication about compliance risks, leadership modeling ethical behavior, and psychological safety for raising concerns.
The U.S. Federal Sentencing Guidelines incentivize companies to have effective compliance programs by:
Answer: Reducing potential fines and penalties for organizations that can demonstrate a robust compliance program was in place at the time of an offense
The Federal Sentencing Guidelines allow judges to mitigate criminal fines for organizations that had effective compliance programs, creating a strong incentive for robust compliance infrastructure.
An organization's 'risk appetite' statement in a GRC framework should be:
Answer: Approved by the board and reflect the amount of risk the organization is willing to accept in pursuit of its objectives
A risk appetite statement reflects board-approved guidance on the types and levels of risk the organization is willing to accept to achieve its strategic goals.
Which term describes the process of embedding GRC responsibilities into the everyday roles of business unit managers rather than relegating them solely to a compliance department?
Answer: Three lines of defense model
The three lines of defense model distributes GRC responsibilities across business operations (first line), risk and compliance functions (second line), and internal audit (third line).
In GRC stakeholder management, which group is typically considered the 'second line of defense'?
Answer: Risk management and compliance functions that monitor and oversee the first line
The second line of defense consists of risk management and compliance functions that set policies, provide oversight, and monitor whether the first line is managing risks appropriately.