GRC Ethics, Culture, and Stakeholder Accountability Flashcards
6 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 GRC Ethics, Culture, and Stakeholder Accountability flashcards as text
Anti-bribery and anti-corruption (ABAC) programs in U.S. companies are primarily governed by which federal law?
Answer: The Foreign Corrupt Practices Act (FCPA)
The FCPA prohibits U.S. companies and individuals from bribing foreign government officials and requires maintenance of accurate books and records and adequate internal controls.
Which of the following best describes 'ethical leadership' in a GRC context?
Answer: Leaders who model integrity, make decisions aligned with organizational values, and hold themselves accountable to the same standards they set for others
Ethical leadership in GRC involves consistently demonstrating values-aligned behavior, transparent decision-making, and personal accountability at all levels of leadership.
Which component is considered essential for a 'seven elements' effective compliance program as described by the U.S. Department of Justice?
Answer: Written policies and procedures, compliance training, reporting mechanisms, and consistent enforcement
The DOJ's seven elements framework for effective compliance programs includes written standards, oversight, training, reporting mechanisms, enforcement, monitoring, and response to violations.
In GRC, 'non-retaliation' policies are critical because they:
Answer: Encourage employees to report compliance concerns by protecting them from adverse employment actions
Non-retaliation policies protect employees who report suspected violations from adverse consequences, which is foundational to a speak-up culture and effective compliance reporting.
Which governance principle requires that decision-makers can be held responsible and must answer for their actions to stakeholders?
Answer: Accountability
Accountability in governance means that individuals and organizations must answer for their decisions and actions to appropriate stakeholders and accept the consequences of those decisions.
An organization's GRC program includes an annual compliance risk assessment. The primary purpose of this assessment is to:
Answer: Identify, prioritize, and address the most significant compliance risks the organization faces
A compliance risk assessment systematically identifies where the greatest compliance exposures lie so that resources and controls can be focused on the highest-priority risks.