GRC GRC Ethics, Culture, and Stakeholder Accountability 2 — Questions and Answers
Question 1: In GRC, 'accountability' at the board level primarily means that directors are responsible for:
- Personally executing all compliance tasks within the organization
- Providing oversight and ensuring management establishes and maintains an effective governance and risk framework (Correct answer)
- Filing compliance reports directly with regulators on behalf of management
- Approving every individual risk mitigation action plan
Correct answer: Providing oversight and ensuring management establishes and maintains an effective governance and risk framework
Board-level accountability in GRC means directors oversee and challenge management's approach to governance and risk rather than performing operational compliance tasks themselves.
Question 2: Which of the following is a characteristic of a strong organizational compliance culture?
- Employees routinely bypass approval workflows for efficiency
- Compliance concerns are discussed openly and leadership consistently models expected behavior (Correct answer)
- Audit findings are kept confidential from business unit leaders
- Risk appetite is determined solely by the legal department
Correct answer: Compliance concerns are discussed openly and leadership consistently models expected behavior
A strong compliance culture is characterized by open communication about compliance risks, leadership modeling ethical behavior, and psychological safety for raising concerns.
Question 3: The U.S. Federal Sentencing Guidelines incentivize companies to have effective compliance programs by:
- Eliminating all penalties for companies with certified compliance officers
- Reducing potential fines and penalties for organizations that can demonstrate a robust compliance program was in place at the time of an offense (Correct answer)
- Granting tax credits for compliance training expenditures
- Requiring courts to defer all compliance judgments to the SEC
Correct answer: Reducing potential fines and penalties for organizations that can demonstrate a robust compliance program was in place at the time of an offense
The Federal Sentencing Guidelines allow judges to mitigate criminal fines for organizations that had effective compliance programs, creating a strong incentive for robust compliance infrastructure.
Question 4: An organization's 'risk appetite' statement in a GRC framework should be:
- Drafted by external auditors and filed with the board annually
- Approved by the board and reflect the amount of risk the organization is willing to accept in pursuit of its objectives (Correct answer)
- Limited to financial risks and reviewed only during mergers
- Set by the CISO and focused exclusively on cybersecurity risk thresholds
Correct answer: Approved by the board and reflect the amount of risk the organization is willing to accept in pursuit of its objectives
A risk appetite statement reflects board-approved guidance on the types and levels of risk the organization is willing to accept to achieve its strategic goals.
Question 5: Which term describes the process of embedding GRC responsibilities into the everyday roles of business unit managers rather than relegating them solely to a compliance department?
- Risk centralization
- Compliance outsourcing
- Three lines of defense model (Correct answer)
- Regulatory arbitrage
Correct answer: Three lines of defense model
The three lines of defense model distributes GRC responsibilities across business operations (first line), risk and compliance functions (second line), and internal audit (third line).
Question 6: In GRC stakeholder management, which group is typically considered the 'second line of defense'?
- External auditors and regulators
- Risk management and compliance functions that monitor and oversee the first line (Correct answer)
- Business unit managers executing day-to-day operations
- Board audit committee members
Correct answer: Risk management and compliance functions that monitor and oversee the first line
The second line of defense consists of risk management and compliance functions that set policies, provide oversight, and monitor whether the first line is managing risks appropriately.
In GRC, 'accountability' at the board level primarily means that directors are responsible for: