SPHR HR Risk Management 4 — Questions and Answers
Question 1: An SPHR is designing a vendor risk management program for HR service providers who handle employee data. Which contractual provision is most critical?
- A most-favored-nation pricing clause
- A data processing agreement specifying security obligations and breach notification timelines (Correct answer)
- An exclusivity clause preventing the vendor from serving competitors
- A force majeure clause covering labor shortages
Correct answer: A data processing agreement specifying security obligations and breach notification timelines
A data processing agreement (DPA) legally binds the vendor to security standards and breach notification requirements, directly managing data privacy risk.
Question 2: An organization's culture survey reveals that 40% of employees fear retaliation if they report ethics violations. What is the primary risk this finding signals?
- Excessive voluntary turnover in the next fiscal year
- Underreporting of misconduct, leading to unchecked legal and reputational exposure (Correct answer)
- Declining employee engagement scores on next year's survey
- Increased demand for EAP counseling services
Correct answer: Underreporting of misconduct, leading to unchecked legal and reputational exposure
Fear of retaliation suppresses reporting, allowing misconduct to continue and grow into larger legal, regulatory, or reputational crises.
Question 3: Which OSHA recordkeeping form is used to summarize the total number of job-related injuries and illnesses that occurred during the year?
- OSHA Form 300 (Log of Work-Related Injuries and Illnesses)
- OSHA Form 300A (Summary of Work-Related Injuries and Illnesses) (Correct answer)
- OSHA Form 301 (Injury and Illness Incident Report)
- OSHA Form 7 (Notice of Alleged Safety or Health Hazards)
Correct answer: OSHA Form 300A (Summary of Work-Related Injuries and Illnesses)
OSHA Form 300A is the annual summary that must be posted in the workplace from February 1 through April 30 each year.
Question 4: A company's key-person risk is best mitigated through which HR strategy?
- Increasing salaries of critical employees to retain them indefinitely
- Robust succession planning combined with knowledge transfer and documentation programs (Correct answer)
- Purchasing key-person life insurance policies on all senior leaders
- Restricting critical employees from external professional development to reduce poaching risk
Correct answer: Robust succession planning combined with knowledge transfer and documentation programs
Succession planning paired with knowledge transfer ensures operational continuity regardless of whether a key person departs voluntarily or involuntarily.
Question 5: Under the Sarbanes-Oxley Act (SOX), which HR-related internal control is most directly required?
- Annual employee satisfaction surveys disclosed to shareholders
- Whistleblower protection mechanisms allowing anonymous reporting of financial fraud (Correct answer)
- Mandatory drug testing for all publicly traded company employees
- HR certification requirements for publicly traded company CHRO roles
Correct answer: Whistleblower protection mechanisms allowing anonymous reporting of financial fraud
SOX Section 806 mandates whistleblower protections for employees of publicly traded companies who report securities fraud or violations.
Question 6: An employer in a right-to-work state is drafting a policy on union activity. The most significant legal risk arises if the policy:
- Allows union organizers to use company break rooms on a limited basis
- Prohibits employees from discussing union organizing on non-work time in non-work areas (Correct answer)
- Requires supervisors to report organizing conversations they observe at work
- Establishes a neutral process for employees to raise workplace concerns
Correct answer: Prohibits employees from discussing union organizing on non-work time in non-work areas
The NLRA protects employees' right to discuss organizing on non-work time in non-work areas; policies restricting this create significant Section 7 violation risk regardless of right-to-work status.
Question 7: What is the primary purpose of an HR audit in the context of risk management?
- To evaluate individual employee performance against departmental KPIs
- To systematically assess HR practices for compliance gaps, legal exposure, and operational inefficiencies (Correct answer)
- To determine appropriate compensation benchmarks relative to the market
- To measure return on investment for training and development programs
Correct answer: To systematically assess HR practices for compliance gaps, legal exposure, and operational inefficiencies
An HR audit identifies compliance weaknesses and operational gaps before they become costly legal, regulatory, or financial problems.
An SPHR is designing a vendor risk management program for HR service providers who handle employee data.
Which contractual provision is most critical?