HR Risk Assessment & Management 4 — Questions and Answers
Question 1: Which technique is used to assign probability and impact scores to risks in a qualitative risk assessment?
- Monte Carlo simulation
- Probability-Impact matrix (Correct answer)
- Fault tree analysis
- Annual Loss Expectancy formula
Correct answer: Probability-Impact matrix
A Probability-Impact (PI) matrix ranks risks by plotting likelihood against severity using descriptive scales.
Question 2: An HR manager notices that employee turnover in the engineering department has tripled over six months. In risk terms, this is BEST described as:
- A threat that has already materialized into an incident
- A Key Risk Indicator signaling elevated talent-retention risk (Correct answer)
- An acceptable residual risk requiring no action
- A compliance violation under FLSA
Correct answer: A Key Risk Indicator signaling elevated talent-retention risk
KRIs are metrics that provide early warning signals of increasing risk exposure before a major loss occurs.
Question 3: A software company's HR team must comply with CCPA. Which risk does non-compliance MOST directly create?
- Increased employee absenteeism
- Regulatory fines and civil litigation from California residents (Correct answer)
- Loss of ISO 27001 certification
- Reduced employee performance review accuracy
Correct answer: Regulatory fines and civil litigation from California residents
CCPA violations expose organizations to statutory damages and enforcement actions by the California Attorney General.
Question 4: When conducting a risk assessment for an HR cloud migration, which asset should be inventoried FIRST?
- Office furniture and physical equipment
- All data types and their sensitivity classifications (Correct answer)
- Employee satisfaction survey results
- Vendor contract renewal dates
Correct answer: All data types and their sensitivity classifications
Knowing what data exists and its sensitivity level is prerequisite to assessing what risks a migration poses.
Question 5: Which scenario best illustrates an inherent risk in an HRIS before any controls are applied?
- An access review completed last quarter found no violations
- Sensitive employee data is accessible to anyone with network access by default (Correct answer)
- Multi-factor authentication has been enabled for all HR users
- An audit log captures every change to employee records
Correct answer: Sensitive employee data is accessible to anyone with network access by default
Inherent risk is the raw risk level that exists without any mitigating controls in place.
Question 6: A company's HR risk committee meets quarterly. Between meetings, who is responsible for escalating newly identified risks?
- Only the Chief Risk Officer
- Risk owners and department managers as risks emerge (Correct answer)
- External auditors during their annual review
- The board of directors at its next scheduled meeting
Correct answer: Risk owners and department managers as risks emerge
Risk owners and line managers must escalate emerging risks in real time rather than waiting for a periodic committee cycle.
Question 7: In HR software security, 'patch management' primarily reduces which type of risk?
- Reputational risk from poor employer branding
- Exploitation of known software vulnerabilities by attackers (Correct answer)
- Workforce planning inaccuracies
- Turnover caused by poor management
Correct answer: Exploitation of known software vulnerabilities by attackers
Applying patches closes known security flaws that threat actors actively search for and exploit.
Which technique is used to assign probability and impact scores to risks in a qualitative risk assessment?