HR Risk Assessment & Management 2 — Questions and Answers
Question 1: A software company is onboarding a new HR platform vendor. Which control helps mitigate third-party data-breach risk MOST directly?
- Requiring the vendor to sign an NDA
- Conducting a vendor security assessment and reviewing SOC 2 reports (Correct answer)
- Limiting the vendor to daytime-only system access
- Assigning the vendor a dedicated account manager
Correct answer: Conducting a vendor security assessment and reviewing SOC 2 reports
SOC 2 reports and security assessments verify that a vendor has operational controls in place to protect data.
Question 2: In a risk matrix, a hazard rated 'High Likelihood / Low Impact' should typically be:
- Accepted without action because impact is low
- Monitored and mitigated with low-cost controls (Correct answer)
- Escalated immediately as a critical risk
- Transferred to an insurance provider
Correct answer: Monitored and mitigated with low-cost controls
High-likelihood/low-impact risks are good candidates for inexpensive controls or monitoring rather than full escalation.
Question 3: Which HR software configuration practice BEST reduces the risk of unauthorized payroll modifications?
- Allowing managers to self-approve their own pay changes
- Implementing dual-control approval workflows for payroll edits (Correct answer)
- Storing payroll data in an unencrypted local spreadsheet
- Granting all HR staff administrator-level access
Correct answer: Implementing dual-control approval workflows for payroll edits
Dual-control (four-eyes) approval ensures no single person can unilaterally change payroll records.
Question 4: A risk register entry shows Residual Risk remaining after controls. What does 'residual risk' mean?
- Risk that has been fully eliminated
- Risk that remains after all planned controls are applied (Correct answer)
- Risk that is transferred to a third party
- Risk documented but not yet assessed
Correct answer: Risk that remains after all planned controls are applied
Residual risk is the level of risk that persists even after mitigation controls have been implemented.
Question 5: An HR director wants to quantify the financial exposure of a potential data-loss event. Which metric should they calculate?
- Key Risk Indicator (KRI)
- Annual Loss Expectancy (ALE) (Correct answer)
- Return on Security Investment (ROSI)
- Risk Appetite Statement
Correct answer: Annual Loss Expectancy (ALE)
ALE = Single Loss Expectancy × Annual Rate of Occurrence, giving a dollar figure for expected yearly loss.
Question 6: Which scenario represents a strategic HR risk for a software firm?
- A printer running out of toner in the HR office
- Key engineering talent leaving for competitors due to below-market compensation (Correct answer)
- An employee submitting a vacation request late
- A minor payroll tax rounding error
Correct answer: Key engineering talent leaving for competitors due to below-market compensation
Talent attrition in a competitive market directly threatens a software firm's ability to deliver products and revenue.
Question 7: When updating HR software, what risk does insufficient regression testing primarily introduce?
- Increased software licensing costs
- Previously working features breaking after the update (Correct answer)
- Slower new-hire onboarding workflows
- Compliance penalties from regulators
Correct answer: Previously working features breaking after the update
Regression testing catches defects introduced by changes; skipping it risks breaking existing functionality.
A software company is onboarding a new HR platform vendor.
Which control helps mitigate third-party data-breach risk MOST directly?