← All BPA Flashcard Decks

BPA Compliance, Auditing & Risk Management Flashcards

6 cards from real BPA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 BPA Compliance, Auditing & Risk Management flashcards as text
  1. What is a 'control gap' in a BPA compliance review?

    Answer: A missing or insufficient control that leaves a compliance requirement unaddressed

    A control gap exists when a required compliance control is absent or inadequate, exposing the organization to regulatory or operational risk.

  2. Which risk assessment methodology assigns a numerical score to risks by multiplying likelihood by impact?

    Answer: Quantitative risk analysis

    Quantitative risk analysis uses numerical values for probability and impact to calculate a risk score, enabling objective prioritization.

  3. A BPA process is found to be non-compliant during an internal audit. What is the appropriate immediate next step?

    Answer: Issue a corrective action plan (CAP) to address the non-compliance within a defined timeline

    A corrective action plan documents the steps and timeline required to remediate the identified non-compliance, demonstrating accountability to auditors.

  4. In BPA compliance, 'data lineage' refers to:

    Answer: The documented journey of data from its origin through all transformations to its final destination

    Data lineage tracks the full lifecycle of data—where it came from, how it was transformed, and where it ended up—supporting transparency and compliance.

  5. Which approach best helps a BPA team proactively identify compliance risks before a new process goes live?

    Answer: Conducting a pre-implementation compliance review or Privacy/Security Impact Assessment

    A pre-implementation compliance review identifies regulatory risks early, when they are far less costly and disruptive to address.

  6. Under GDPR, which BPA process design principle requires that only the minimum necessary personal data be collected and processed?

    Answer: Data minimization

    GDPR's data minimization principle mandates that automated processes collect and use only the personal data strictly necessary for their stated purpose.