GRC Governance Frameworks & Best Practices 3 — Questions and Answers
Question 1: Which component of the COSO ERM framework 2017 update reflects the integration of strategy-setting with enterprise risk management?
- Risk assessment
- Strategy and objective-setting (Correct answer)
- Control activities
- Information, communication, and reporting
Correct answer: Strategy and objective-setting
The 2017 COSO ERM update emphasized 'Strategy and Objective-Setting' as the component linking ERM directly to organizational strategy.
Question 2: A governance framework requires that policies cascade through an organization. Which document type sits directly below a board-approved policy?
- Standard (Correct answer)
- Procedure
- Guideline
- Baseline
Correct answer: Standard
Standards define mandatory, specific requirements that support policies, while procedures describe how to implement standards.
Question 3: The OECD Principles of Corporate Governance emphasize 'equitable treatment of shareholders,' which specifically addresses:
- Ensuring all shareholders, including minorities, have equal voting rights (Correct answer)
- Maximizing dividends for majority shareholders
- Restricting shareholder access to board meetings
- Eliminating institutional investor influence
Correct answer: Ensuring all shareholders, including minorities, have equal voting rights
Equitable treatment requires that minority and foreign shareholders receive the same protections and voting rights as majority shareholders.
Question 4: In IT governance, a 'tollgate' review is best described as:
- A continuous monitoring process for all IT systems
- A formal checkpoint where a project must meet criteria before proceeding (Correct answer)
- An automated compliance scan run quarterly
- A board-level review of annual IT budget
Correct answer: A formal checkpoint where a project must meet criteria before proceeding
A tollgate review is a structured decision point where stakeholders evaluate whether a project meets predefined criteria before authorizing the next phase.
Question 5: Which ISO standard specifically provides guidance on governance of information security, acting as a companion to ISO/IEC 27001?
- ISO/IEC 27002
- ISO/IEC 27014 (Correct answer)
- ISO/IEC 27005
- ISO/IEC 27701
Correct answer: ISO/IEC 27014
ISO/IEC 27014 provides guidance on governance of information security for board-level and executive evaluation, direction, and monitoring.
Question 6: When a GRC framework refers to 'residual risk,' it means the risk that remains after:
- Initial risk identification is complete
- Control measures have been applied (Correct answer)
- Risk transfer to an insurer occurs
- The board formally accepts the risk
Correct answer: Control measures have been applied
Residual risk is the level of risk remaining after controls and mitigating measures have been implemented.
Question 7: The King IV Report on Corporate Governance is principally applied in which country and is notable for which approach?
- UK; rules-based mandatory compliance
- South Africa; apply-and-explain principles-based approach (Correct answer)
- USA; shareholder-centric mandatory disclosures
- Australia; sector-specific industry codes
Correct answer: South Africa; apply-and-explain principles-based approach
King IV is a South African governance code using an 'apply and explain' approach, where organizations disclose how they apply each principle.
Which component of the COSO ERM framework 2017 update reflects the integration of strategy-setting with enterprise risk management?