nerdexam
Isaca

CGEIT · Question #447

An enterprise has entered into a new market which brings additional regulatory compliance requirements. What should be done FIRST to address these requirements?

The correct answer is C. Update the organization's risk profile.. When new regulatory compliance requirements arise from entering a new market, the organization should first update its risk profile to understand the impact and severity of these new obligations. This initial step informs all subsequent compliance actions.

Submitted by miguelv· Apr 18, 2026Risk Optimization

Question

An enterprise has entered into a new market which brings additional regulatory compliance requirements. What should be done FIRST to address these requirements?

Options

  • AOutsource the compliance process.
  • BAppoint a compliance officer.
  • CUpdate the organization's risk profile.
  • DHave executive management monitor compliance.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    86% (24)
  • D
    7% (2)

Why each option

When new regulatory compliance requirements arise from entering a new market, the organization should first update its risk profile to understand the impact and severity of these new obligations. This initial step informs all subsequent compliance actions.

AOutsource the compliance process.

Outsourcing the compliance process might be a solution, but it cannot be done effectively until the specific requirements and associated risks are understood.

BAppoint a compliance officer.

Appointing a compliance officer is important, but this role needs to be informed by a clear understanding of the compliance landscape and the risks involved, which comes from updating the risk profile.

CUpdate the organization's risk profile.Correct

Updating the organization's risk profile is the essential first step because it allows the enterprise to identify, assess, and prioritize the new compliance risks introduced by the market entry. Understanding the nature and potential impact of these risks is crucial before deciding on specific actions or resource allocations to address them.

DHave executive management monitor compliance.

Executive management monitoring compliance is an ongoing governance activity, but it must be based on an initial assessment of what needs to be monitored and why, derived from the risk profile.

Concept tested: Prioritizing new regulatory compliance requirements through risk assessment

Source: https://www.isaca.org/resources/cobit/cobit-2019-framework

Topics

#Regulatory compliance#Risk management#Risk assessment#New market entry

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice