GRC Principles and Models 3 — Questions and Answers
Question 1: Which component of the COSO Internal Control framework addresses the organization's values, ethical standards, and the importance management places on integrity?
- Risk Assessment
- Control Environment (Correct answer)
- Monitoring Activities
- Information and Communication
Correct answer: Control Environment
The Control Environment is the foundation of COSO's internal control framework, encompassing tone at the top, values, ethics, and organizational structure.
Question 2: In GRC terminology, what is 'risk tolerance' as distinct from 'risk appetite'?
- The total risk capacity of the organization
- The acceptable variation around a risk appetite objective (Correct answer)
- The minimum risk required to generate returns
- The risk level assigned by external regulators
Correct answer: The acceptable variation around a risk appetite objective
Risk tolerance defines the acceptable boundaries of variation around a specific objective, providing more granular guidance than the broader risk appetite statement.
Question 3: The principle of 'separation of duties' in GRC primarily serves to:
- Speed up authorization workflows
- Prevent any single individual from controlling all aspects of a critical process (Correct answer)
- Centralize decision-making authority
- Reduce the cost of compliance activities
Correct answer: Prevent any single individual from controlling all aspects of a critical process
Separation of duties is a key internal control that distributes tasks across multiple people to reduce the risk of error or fraud.
Question 4: Under the NIST Risk Management Framework (RMF), what is the correct order of the first three steps?
- Categorize, Select, Implement
- Identify, Protect, Detect
- Assess, Authorize, Monitor
- Prepare, Categorize, Select (Correct answer)
Correct answer: Prepare, Categorize, Select
The NIST RMF steps in order are: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.
Question 5: Which governance principle requires that board members and executives avoid situations where personal interests conflict with organizational interests?
- Fiduciary duty
- Conflict of interest management (Correct answer)
- Director independence
- Stewardship
Correct answer: Conflict of interest management
Conflict of interest management requires individuals to disclose and abstain from decisions where personal gain could compromise their objectivity.
Question 6: A 'heat map' in risk management is used to:
- Track employee training completion rates
- Visually represent risks by plotting likelihood against impact (Correct answer)
- Monitor network security threats in real-time
- Display financial performance metrics
Correct answer: Visually represent risks by plotting likelihood against impact
A risk heat map plots risks on a matrix with likelihood on one axis and impact on the other, providing a visual prioritization tool.
Question 7: Which GRC model concept refers to the organization's total exposure to risk before any controls or mitigation are applied?
- Residual risk
- Inherent risk (Correct answer)
- Control risk
- Detection risk
Correct answer: Inherent risk
Inherent risk is the natural level of risk in a process or activity before management applies controls to reduce it.
Which component of the COSO Internal Control framework addresses the organization's values, ethical standards, and the importance management places on integrity?