nerdexam
Isaca

CGEIT · Question #669

A regulator has expressed concerns about the timeliness of information reported from an enterprise. Which of the following should be done FIRST to address this issue?

The correct answer is A. Assess the reporting delivery process. The first action to address regulator concerns about reporting timeliness is to assess the existing reporting delivery process to identify root causes and areas for improvement.

Submitted by manish99· Apr 18, 2026Governance of Enterprise IT

Question

A regulator has expressed concerns about the timeliness of information reported from an enterprise. Which of the following should be done FIRST to address this issue?

Options

  • AAssess the reporting delivery process.
  • BNegotiate an exception process with the regulator.
  • CAutomate the reporting process.
  • DEvaluate the implications of risk acceptance.

How the community answered

(27 responses)
  • A
    81% (22)
  • B
    11% (3)
  • C
    4% (1)
  • D
    4% (1)

Why each option

The first action to address regulator concerns about reporting timeliness is to assess the existing reporting delivery process to identify root causes and areas for improvement.

AAssess the reporting delivery process.Correct

When a regulator expresses concerns about timeliness, the initial step is to understand the current state of the reporting delivery process, including data collection, processing, and submission, to pinpoint bottlenecks or inefficiencies. This assessment helps identify the root causes of the delay before implementing solutions.

BNegotiate an exception process with the regulator.

Negotiating an exception process is a reactive measure and should only be considered after understanding why the current process is failing and exploring solutions.

CAutomate the reporting process.

Automating the reporting process might be a solution, but it's premature to jump to a solution without first assessing the current process to understand what needs to be automated and why.

DEvaluate the implications of risk acceptance.

Evaluating risk acceptance implies deciding not to address the issue directly, which is generally not an appropriate first response to a regulator's stated concern about non-compliance.

Concept tested: Root cause analysis for reporting issues

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/govern/policy-compliance/discipline-audit-process

Topics

#Regulatory compliance#Information reporting#Process assessment

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice