GRC Governance Frameworks & Best Practices 4 — Questions and Answers
Question 1: A company adopts COBIT 2019 and focuses on the management objective 'APO12 Managed Risk.' This objective belongs to which COBIT domain?
- Build, Acquire and Implement (BAI)
- Align, Plan and Organize (APO) (Correct answer)
- Monitor, Evaluate and Assess (MEA)
- Deliver, Service and Support (DSS)
Correct answer: Align, Plan and Organize (APO)
APO (Align, Plan and Organize) is the domain containing APO12 Managed Risk, reflecting its strategic and planning nature.
Question 2: Which of the following best describes 'governance washing' in a corporate context?
- Implementing excessive governance controls beyond regulatory requirements
- Publicly claiming strong governance practices without substantive implementation (Correct answer)
- Automating governance activities to reduce human oversight
- Transferring governance responsibilities to a third-party provider
Correct answer: Publicly claiming strong governance practices without substantive implementation
Governance washing refers to organizations projecting an image of strong governance through marketing or disclosures while failing to implement meaningful controls.
Question 3: Under Sarbanes-Oxley Section 302, who must personally certify the accuracy of financial reports?
- External auditors only
- The CFO and CEO (Correct answer)
- The audit committee chair
- All members of the board of directors
Correct answer: The CFO and CEO
SOX Section 302 requires the CEO and CFO to personally certify the accuracy and completeness of financial reports filed with the SEC.
Question 4: In governance frameworks, a 'maturity model' is primarily used to:
- Enforce mandatory compliance with regulatory standards
- Benchmark and roadmap the improvement of governance capabilities (Correct answer)
- Assign liability for governance failures to specific individuals
- Replace key performance indicators in governance reporting
Correct answer: Benchmark and roadmap the improvement of governance capabilities
Maturity models provide a structured scale for assessing current capability levels and planning incremental improvements toward a target state.
Question 5: Which governance best practice addresses conflicts of interest by requiring board members to disclose personal financial interests related to company decisions?
- Director independence requirements
- Related-party transaction disclosure (Correct answer)
- Say-on-pay voting
- Proxy access provisions
Correct answer: Related-party transaction disclosure
Related-party transaction disclosure requires directors to reveal personal financial interests that could influence their objectivity on board decisions.
Question 6: The NIST Privacy Framework's 'Communicate-P' function focuses on:
- Encrypting personal data at rest and in transit
- Increasing awareness of how privacy values are implemented in policies and practices (Correct answer)
- Filing breach notifications with regulators
- Transferring privacy risk to third-party processors
Correct answer: Increasing awareness of how privacy values are implemented in policies and practices
The Communicate-P function involves developing and implementing activities to inform individuals and increase awareness of privacy policies and practices.
Question 7: An organization implements a 'comply-or-explain' governance regime. This means companies must:
- Always comply with every provision of the governance code without exception
- Either follow the code's provisions or explain publicly why they have not (Correct answer)
- Explain their compliance posture only when regulators request it
- Comply with mandatory rules and explain voluntary guidelines
Correct answer: Either follow the code's provisions or explain publicly why they have not
Under comply-or-explain, companies must either follow each code provision or provide a public explanation of why they have departed from it.
A company adopts COBIT 2019 and focuses on the management objective 'APO12 Managed Risk.' This objective belongs to which COBIT domain?