GRC Regulatory and Legal Compliance 5 — Questions and Answers
Question 1: Which legal doctrine holds that a parent company may be liable for the compliance violations of its subsidiary?
- Respondeat superior
- Piercing the corporate veil
- Vicarious liability
- Alter ego doctrine (Correct answer)
Correct answer: Alter ego doctrine
The alter ego doctrine allows courts to hold a parent company liable for a subsidiary's actions when the subsidiary lacks separate identity and is merely an extension of the parent.
Question 2: Under the Payment Card Industry Data Security Standard (PCI DSS), what is the minimum password length required for system access?
- 6 characters
- 7 characters
- 8 characters
- 12 characters (Correct answer)
Correct answer: 12 characters
PCI DSS v4.0 requires passwords/passphrases to be a minimum of 12 characters (or if the system does not support 12 characters, a minimum length of eight characters).
Question 3: A compliance officer identifies a legal requirement that conflicts with a business objective. What is the appropriate escalation path?
- Quietly defer the legal requirement until business objectives are met
- Immediately shut down the conflicting business activity
- Escalate to senior leadership and legal counsel to document the risk and determine a resolution (Correct answer)
- Report the conflict directly to the regulator
Correct answer: Escalate to senior leadership and legal counsel to document the risk and determine a resolution
Compliance officers should escalate conflicts between legal requirements and business objectives to senior leadership and legal counsel to ensure informed decision-making and documented risk acceptance.
Question 4: Which U.S. law requires federal agencies to protect sensitive unclassified information and mandates specific safeguarding requirements for contractors handling such data?
- Federal Information Security Modernization Act (FISMA)
- NIST SP 800-171
- Defense Federal Acquisition Regulation Supplement (DFARS)
- Controlled Unclassified Information (CUI) Program under 32 CFR Part 2002 (Correct answer)
Correct answer: Controlled Unclassified Information (CUI) Program under 32 CFR Part 2002
The CUI Program established under 32 CFR Part 2002 standardizes how federal agencies and contractors must identify, handle, and protect Controlled Unclassified Information.
Question 5: An organization's compliance program includes 'reasonable care' as a defense strategy. Under the U.S. Federal Sentencing Guidelines, which factor most significantly reduces the culpability score when an offense occurs?
- Self-reporting the violation to authorities
- Having a high-level person responsible for the compliance program
- Implementing an effective compliance and ethics program prior to the offense (Correct answer)
- Cooperating with government investigation
Correct answer: Implementing an effective compliance and ethics program prior to the offense
Having an effective compliance and ethics program in place before the offense is the most significant mitigating factor under the Federal Sentencing Guidelines, potentially reducing the culpability score by three points.
Question 6: The concept of 'adequate procedures' as a defense in the UK Bribery Act 2010 requires which of the following?
- Proof that no bribery occurred anywhere in the organization
- Demonstration that the organization had proportionate anti-bribery procedures in place (Correct answer)
- Evidence that all employees received annual bribery training
- Confirmation that the organization passed an external audit
Correct answer: Demonstration that the organization had proportionate anti-bribery procedures in place
Under the UK Bribery Act, an organization can use 'adequate procedures' as a defense if it can show it had proportionate anti-bribery procedures in place, even if bribery still occurred.
Question 7: In the context of regulatory compliance, what is 'regulatory capture'?
- When a regulator issues a formal enforcement action against a company
- When regulators begin to advance the interests of the industry they regulate rather than the public interest (Correct answer)
- When a company acquires a regulated entity
- When a government agency captures and centralizes data from regulated firms
Correct answer: When regulators begin to advance the interests of the industry they regulate rather than the public interest
Regulatory capture occurs when regulatory agencies prioritize the commercial or political interests of the industries they oversee rather than the broader public interest.
Which legal doctrine holds that a parent company may be liable for the compliance violations of its subsidiary?