HR Risk Assessment & Management 5 — Questions and Answers
Question 1: An organization accepts a low-level risk because the cost of controls exceeds the potential loss. This decision should be:
- Implemented without documentation since it is low-level
- Formally documented and approved by an authorized risk owner (Correct answer)
- Referred immediately to legal counsel
- Escalated to the board as a critical finding
Correct answer: Formally documented and approved by an authorized risk owner
Even accepted risks require documented authorization so accountability is clear and decisions can be revisited.
Question 2: Which HR-specific risk is MOST associated with poorly designed performance management software?
- Server downtime during payroll runs
- Biased or inconsistent evaluations leading to discrimination claims (Correct answer)
- Increased vendor licensing fees
- Loss of source code through a cyberattack
Correct answer: Biased or inconsistent evaluations leading to discrimination claims
Algorithmic bias in performance tools can produce inequitable outcomes that expose the company to employment discrimination liability.
Question 3: A disaster recovery plan (DRP) for an HRIS should be tested using which method to confirm full recoverability WITHOUT impacting production?
- Parallel (simulation) test using a restored copy in an isolated environment (Correct answer)
- Cutting over production to the backup system and monitoring for errors
- Reviewing the DRP document without executing any recovery steps
- Deleting the primary database to force a real recovery scenario
Correct answer: Parallel (simulation) test using a restored copy in an isolated environment
A parallel test restores systems in an isolated environment, validating recoverability without any risk to live operations.
Question 4: Under HIPAA, an HR department that self-administers a company health plan must treat employee health records as:
- General HR records accessible to all managers
- Protected Health Information (PHI) with strict access limitations (Correct answer)
- Public information that can be shared with insurers freely
- Financial records subject only to SOX controls
Correct answer: Protected Health Information (PHI) with strict access limitations
Self-insured employer health plans are covered entities under HIPAA, making employee health data PHI subject to its full privacy rules.
Question 5: A software firm wants to assess supply-chain HR risks. Which scenario represents this risk type?
- A key contractor's company goes bankrupt, halting critical project delivery (Correct answer)
- An internal employee submits a late expense report
- The HR director takes a two-week vacation
- A payroll system produces a rounding error of $0.01
Correct answer: A key contractor's company goes bankrupt, halting critical project delivery
Supply-chain HR risk includes dependency on external contractors or vendors whose disruption directly impacts the organization's operations.
Question 6: Which action BEST reduces the risk of insider threat in an HR software environment?
- Allowing all employees to view the full HR database for transparency
- Implementing user behavior analytics (UBA) and least-privilege access (Correct answer)
- Requiring employees to change passwords only once per year
- Storing sensitive data on USB drives for offline access
Correct answer: Implementing user behavior analytics (UBA) and least-privilege access
UBA detects anomalous activity patterns while least-privilege limits what insiders can access, together reducing insider threat risk.
Question 7: A risk treatment plan differs from a risk register because the treatment plan primarily:
- Lists all identified risks and their likelihood scores
- Describes specific actions, owners, and deadlines for addressing each risk (Correct answer)
- Records historical incidents that have already occurred
- Calculates the Annual Loss Expectancy for each asset
Correct answer: Describes specific actions, owners, and deadlines for addressing each risk
A treatment plan is an action document that specifies who will do what by when to reduce each risk.
An organization accepts a low-level risk because the cost of controls exceeds the potential loss.
This decision should be: