GRC Governance Frameworks & Best Practices 5 — Questions and Answers
Question 1: In a GRC program, 'integrated GRC' refers to an approach where:
- Governance, risk, and compliance are managed in completely separate silos
- Governance, risk, and compliance activities share common data, processes, and technology (Correct answer)
- All GRC functions report directly to the CEO rather than the board
- GRC tools are integrated with external regulatory databases only
Correct answer: Governance, risk, and compliance activities share common data, processes, and technology
Integrated GRC breaks down silos by using a unified platform, common taxonomy, and shared processes across governance, risk, and compliance activities.
Question 2: Which principle in the UN Global Compact specifically requires companies to support and respect internationally proclaimed human rights?
- Principle 1 (Correct answer)
- Principle 4
- Principle 7
- Principle 10
Correct answer: Principle 1
UN Global Compact Principle 1 states that businesses should support and respect the protection of internationally proclaimed human rights.
Question 3: A chief compliance officer (CCO) receives a request from the CEO to waive a policy requirement for a key client deal. The best governance response is to:
- Grant the waiver immediately to support business objectives
- Deny the waiver without escalation to avoid setting precedent
- Evaluate the request against the formal waiver process and escalate to the board if material (Correct answer)
- Refer the decision entirely to external legal counsel
Correct answer: Evaluate the request against the formal waiver process and escalate to the board if material
Waivers should follow a documented approval process, and material waivers that affect regulatory compliance should be escalated to the audit committee or board.
Question 4: The COSO Internal Control — Integrated Framework identifies five components. Which component addresses the 'tone at the top' concept?
- Risk Assessment
- Control Environment (Correct answer)
- Control Activities
- Monitoring Activities
Correct answer: Control Environment
The Control Environment component encompasses the organization's commitment to integrity, ethical values, and management's oversight — often called 'tone at the top.'
Question 5: Under the GDPR governance requirements, what role must certain organizations appoint to oversee data protection compliance?
- Chief Privacy Officer (CPO)
- Data Protection Officer (DPO) (Correct answer)
- Chief Information Security Officer (CISO)
- Records Management Officer (RMO)
Correct answer: Data Protection Officer (DPO)
GDPR Article 37 mandates that certain public authorities, and organizations processing sensitive data at scale, appoint a Data Protection Officer.
Question 6: When building a governance dashboard, which metric type most directly helps the board understand whether controls are preventing failures before they occur?
- Lagging indicators (e.g., number of incidents last quarter)
- Leading indicators (e.g., control testing completion rates) (Correct answer)
- Financial performance ratios
- Regulatory penalty amounts
Correct answer: Leading indicators (e.g., control testing completion rates)
Leading indicators signal future risk by measuring the health of preventive activities, unlike lagging indicators that measure outcomes after failures occur.
Question 7: Which of the following scenarios represents a failure of the 'separation of duties' control in a governance framework?
- The CFO reviews financial reports prepared by the accounting team
- The same employee both approves purchase orders and processes vendor payments (Correct answer)
- The internal audit team reports to the audit committee rather than management
- The risk committee and audit committee hold separate quarterly meetings
Correct answer: The same employee both approves purchase orders and processes vendor payments
Separation of duties requires that no single individual control an entire transaction process; combining approval and payment functions creates fraud risk.
In a GRC program, 'integrated GRC' refers to an approach where: