GRC Policy and Procedure Management 4 — Questions and Answers
Question 1: What is the purpose of mapping policies to regulatory requirements in a compliance matrix?
- To reduce the number of policies needed
- To demonstrate coverage and identify compliance gaps (Correct answer)
- To replace the need for internal audits
- To automatically satisfy regulatory obligations
Correct answer: To demonstrate coverage and identify compliance gaps
A compliance matrix shows which policies address which requirements, making gap identification and audit evidence gathering more efficient.
Question 2: A policy owner role is BEST described as:
- The person who writes the policy document
- The executive accountable for the policy's content, accuracy, and enforcement (Correct answer)
- An external auditor who reviews the policy annually
- Any employee who has read and signed the policy
Correct answer: The executive accountable for the policy's content, accuracy, and enforcement
The policy owner is accountable for ensuring the policy remains accurate, current, and effectively implemented.
Question 3: Which of the following is a risk of having too many overlapping policies?
- Employees will have too much clarity on expectations
- Conflicting requirements may confuse employees and create compliance gaps (Correct answer)
- Auditors will have difficulty finding policy violations
- Regulatory bodies will require fewer controls
Correct answer: Conflicting requirements may confuse employees and create compliance gaps
Overlapping or conflicting policies create ambiguity about which requirement to follow, increasing the risk of non-compliance.
Question 4: What is the primary function of a policy governance committee?
- To write all organizational policies from scratch
- To oversee policy development, approval, and lifecycle management across the enterprise (Correct answer)
- To replace the role of individual policy owners
- To conduct employee policy training sessions
Correct answer: To oversee policy development, approval, and lifecycle management across the enterprise
A policy governance committee provides cross-functional oversight to ensure policies are consistent, current, and aligned with organizational goals.
Question 5: When communicating a new password policy, which approach is most effective for ensuring compliance?
- Email the policy to all staff with no follow-up
- Publish the policy on an intranet page employees rarely visit
- Combine mandatory training, manager briefings, and technical controls that enforce requirements (Correct answer)
- Post a printed copy on the office bulletin board
Correct answer: Combine mandatory training, manager briefings, and technical controls that enforce requirements
A multi-channel approach combining awareness, management reinforcement, and technical enforcement maximizes policy adoption.
Question 6: A procedure contains outdated system screenshots after a software upgrade. What is the correct action?
- Archive the procedure and create a new one from scratch
- Update the procedure and route it through the change management and approval process (Correct answer)
- Allow employees to use the outdated procedure until the next annual review
- Remove the screenshots and leave the text unchanged
Correct answer: Update the procedure and route it through the change management and approval process
Procedure changes require controlled updates through an approval process to ensure accuracy and maintain version integrity.
Question 7: What does 'policy scope' define?
- The technical details of how to implement the policy
- Which systems, people, and processes the policy applies to (Correct answer)
- The penalties for policy violations
- The frequency of policy reviews
Correct answer: Which systems, people, and processes the policy applies to
Scope defines the boundaries of policy applicability, clarifying who and what is covered to prevent ambiguity.
What is the purpose of mapping policies to regulatory requirements in a compliance matrix?