Principles and Models Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Principles and Models flashcards as text
Which GRC model principle emphasizes that risk management activities should be proportional to the size and complexity of the organization?
Answer: Scalability
Scalability ensures that GRC frameworks are appropriately sized and tailored to the organization's complexity, not applied in a one-size-fits-all manner.
In the Three Lines of Defense model, who is responsible for the SECOND line of defense?
Answer: Risk management and compliance functions
The second line consists of risk management, compliance, and control functions that oversee and provide guidance to the first line.
Which principle of GRC holds that all significant decisions and their rationale should be documented and available for review?
Answer: Auditability
Auditability requires that decisions, processes, and outcomes are documented so they can be independently reviewed and verified.
The COSO ERM framework was updated in 2017 to emphasize which key integration?
Answer: Integration of strategy and performance with risk management
The 2017 COSO ERM update explicitly linked enterprise risk management to strategy-setting and performance management.
Which GRC principle ensures that the same risk assessment methodology is applied across all business units and departments?
Answer: Consistency
Consistency in GRC means applying uniform criteria, methods, and standards so results are comparable across the organization.
In a mature GRC model, 'risk appetite' is best described as:
Answer: The amount of risk an organization is willing to accept to achieve its objectives
Risk appetite is the level of risk an organization is prepared to accept in pursuit of its strategic goals, set by senior leadership.
Which ISO standard provides a framework specifically for risk management principles and guidelines applicable to any organization?
Answer: ISO 31000
ISO 31000 provides universal principles, a framework, and a process for managing risk applicable to any organization regardless of sector.