HR Risk Management Flashcards
7 cards from real SPHR practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 HR Risk Management flashcards as text
An organization experiences a ransomware attack that encrypts all HR records. From a risk management perspective, this event most directly represents which type of risk materializing?
Answer: Operational risk from a cybersecurity control failure
A ransomware attack exploiting inadequate cybersecurity controls is a textbook operational risk event, where an internal process or system failure causes disruption.
The FMLA's 'key employee' exception allows an employer to deny restoration to which category of employee?
Answer: A salaried employee among the highest-paid 10% whose restoration would cause substantial and grievous economic injury
FMLA permits employers to deny reinstatement to 'key employees' — salaried employees in the top 10% of earners — if restoration would cause substantial and grievous economic injury to the employer.
A company is assessing the risk of a hostile work environment claim. Which factor most significantly increases legal exposure?
Answer: Management was aware of the harassing conduct and failed to take prompt corrective action
Employer liability for hostile work environment is greatly increased when management knew or should have known about the conduct and failed to act promptly.
Which scenario best illustrates the risk management concept of 'risk transfer' in HR?
Answer: Purchasing employment practices liability (EPL) insurance to shift the financial burden of claims to an insurer
Purchasing EPL insurance transfers the financial consequences of employment-related claims from the organization to the insurer.
When evaluating third-party background check vendors, an employer must ensure the vendor complies with which federal law to minimize legal risk?
Answer: The Fair Credit Reporting Act (FCRA)
The FCRA governs consumer reports used for employment purposes, requiring specific disclosures, candidate consent, and adverse action procedures from both the employer and the vendor.
An HR leader is presenting to the board about talent risk. Which data point most effectively communicates flight risk among high performers?
Answer: Regrettable attrition rate segmented by performance tier and tenure
Regrettable attrition segmented by performance and tenure isolates the loss of critical talent and provides a focused, actionable view of flight risk for the board.
A pharmaceutical company's HR team is developing controls for the risk of employees in sensitive roles leaking proprietary research. Which layered control set is most comprehensive?
Answer: NDAs, role-based access controls on data systems, security awareness training, and post-employment garden leave provisions
A layered approach combining legal agreements, technical access controls, behavioral training, and garden leave addresses the risk from multiple dimensions throughout the employment lifecycle.