GRC Principles and Models 5 — Questions and Answers
Question 1: Which governance concept describes the board's responsibility to ensure the organization acts in the long-term interests of shareholders and other stakeholders?
- Agency theory (Correct answer)
- Stakeholder theory
- Stewardship theory
- Resource dependency theory
Correct answer: Agency theory
Agency theory addresses the relationship between principals (shareholders) and agents (management), and the board's role in aligning these interests.
Question 2: Under ISO 31000:2018, what is the correct sequence of the risk management process?
- Identify, Analyze, Evaluate, Treat (Correct answer)
- Assess, Mitigate, Monitor, Report
- Plan, Do, Check, Act
- Categorize, Select, Implement, Authorize
Correct answer: Identify, Analyze, Evaluate, Treat
ISO 31000 defines the risk management process as: communication and consultation, scope/context/criteria, risk assessment (identify, analyze, evaluate), risk treatment, and monitoring/review.
Question 3: Which term describes the scenario where an organization decides to accept a risk because the cost of mitigation exceeds the potential loss?
- Risk avoidance
- Risk transfer
- Risk acceptance (Correct answer)
- Risk reduction
Correct answer: Risk acceptance
Risk acceptance (or retention) is a deliberate decision to tolerate a risk when the cost-benefit analysis shows mitigation is not economically justified.
Question 4: The principle of 'tone at the top' in GRC governance refers to:
- Regulatory requirements imposed on the C-suite
- Leadership's visible commitment to ethics, compliance, and risk culture (Correct answer)
- Senior management's responsibility to approve all risk assessments
- Board-level mandates for technology investment
Correct answer: Leadership's visible commitment to ethics, compliance, and risk culture
Tone at the top reflects how senior leaders' attitudes and behaviors toward ethics and compliance set the cultural standard for the entire organization.
Question 5: In GRC, a 'control objective' is best defined as:
- A specific test procedure used by internal auditors
- A statement of the desired result or purpose to be achieved by implementing controls (Correct answer)
- A regulatory requirement imposed by law
- A metric used to measure control performance
Correct answer: A statement of the desired result or purpose to be achieved by implementing controls
A control objective states the goal that a control is designed to achieve, providing the basis for designing and evaluating the control.
Question 6: Which risk response strategy involves shifting the financial consequence of a risk to a third party, such as through insurance?
- Risk avoidance
- Risk reduction
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer moves the financial burden of a risk to another party (e.g., insurer or vendor) while the organization may still retain some residual risk.
Question 7: Which of the following best describes the relationship between governance, risk management, and compliance in an integrated GRC model?
- They are independent silos that operate separately to avoid conflicts of interest
- They are interdependent disciplines that share data, processes, and objectives to create organizational value (Correct answer)
- Governance sets rules, risk ignores them, and compliance enforces penalties
- Compliance subsumes both governance and risk management in regulated industries
Correct answer: They are interdependent disciplines that share data, processes, and objectives to create organizational value
An integrated GRC model recognizes that governance, risk, and compliance are mutually reinforcing and share common information, enabling better decision-making and efficiency.
Which governance concept describes the board's responsibility to ensure the organization acts in the long-term interests of shareholders and other stakeholders?