โ† All SPHR Flashcard Decks

HR Risk Management Flashcards

7 cards from real SPHR practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 HR Risk Management flashcards as text
  1. An SPHR is designing a vendor risk management program for HR service providers who handle employee data. Which contractual provision is most critical?

    Answer: A data processing agreement specifying security obligations and breach notification timelines

    A data processing agreement (DPA) legally binds the vendor to security standards and breach notification requirements, directly managing data privacy risk.

  2. An organization's culture survey reveals that 40% of employees fear retaliation if they report ethics violations. What is the primary risk this finding signals?

    Answer: Underreporting of misconduct, leading to unchecked legal and reputational exposure

    Fear of retaliation suppresses reporting, allowing misconduct to continue and grow into larger legal, regulatory, or reputational crises.

  3. Which OSHA recordkeeping form is used to summarize the total number of job-related injuries and illnesses that occurred during the year?

    Answer: OSHA Form 300A (Summary of Work-Related Injuries and Illnesses)

    OSHA Form 300A is the annual summary that must be posted in the workplace from February 1 through April 30 each year.

  4. A company's key-person risk is best mitigated through which HR strategy?

    Answer: Robust succession planning combined with knowledge transfer and documentation programs

    Succession planning paired with knowledge transfer ensures operational continuity regardless of whether a key person departs voluntarily or involuntarily.

  5. Under the Sarbanes-Oxley Act (SOX), which HR-related internal control is most directly required?

    Answer: Whistleblower protection mechanisms allowing anonymous reporting of financial fraud

    SOX Section 806 mandates whistleblower protections for employees of publicly traded companies who report securities fraud or violations.

  6. An employer in a right-to-work state is drafting a policy on union activity. The most significant legal risk arises if the policy:

    Answer: Prohibits employees from discussing union organizing on non-work time in non-work areas

    The NLRA protects employees' right to discuss organizing on non-work time in non-work areas; policies restricting this create significant Section 7 violation risk regardless of right-to-work status.

  7. What is the primary purpose of an HR audit in the context of risk management?

    Answer: To systematically assess HR practices for compliance gaps, legal exposure, and operational inefficiencies

    An HR audit identifies compliance weaknesses and operational gaps before they become costly legal, regulatory, or financial problems.