nerdexam
IIA

IIA-CIA-PART3 · Question #11

An organization is considering integration of governance, risk., and compliance (GRC) activities into a centralized technology-based resource. In implementing this GRC resource, which of the…

The correct answer is A. The board should be fully satisfied that there is an effective system of governance in place through. Option A is correct because enterprise governance is fundamentally about accountability to the board - a centralized GRC system must give board-level assurance that governance structures are effective, not just operational. This is the primary purpose of governance: ensuring…

Question

An organization is considering integration of governance, risk., and compliance (GRC) activities into a centralized technology-based resource. In implementing this GRC resource, which of the following is a key enterprise governance concern that should be fulfilled by the final product?

Options

  • AThe board should be fully satisfied that there is an effective system of governance in place through
  • BCompliance, audit, and risk management can find and seek efficiencies between their functions
  • CKey compliance and risk metrics can be tracked and compared throughout the enterprise, aiding in
  • DData analytics can be utilized for trending of the data to ensure that patterns and ongoing

How the community answered

(38 responses)
  • A
    82% (31)
  • B
    5% (2)
  • C
    3% (1)
  • D
    11% (4)

Explanation

Option A is correct because enterprise governance is fundamentally about accountability to the board - a centralized GRC system must give board-level assurance that governance structures are effective, not just operational. This is the primary purpose of governance: ensuring leadership can verify the organization is controlled and accountable.

Options B, C, and D are incorrect because they describe operational or tactical benefits of a GRC system - efficiency gains between departments (B), enterprise-wide metric tracking (C), and data analytics for trend analysis (D) - rather than addressing the governance concern. These are valuable outcomes, but they serve management and operational teams, not the board's fiduciary oversight responsibility.

Memory tip: Think "G comes first in GRC." Governance is the top layer - it flows down to risk and compliance, not the other way around. When a question asks about a governance concern specifically, look for the answer that satisfies the board or executive leadership, since governance is always about top-level accountability and oversight.

Community Discussion

No community discussion yet for this question.

Full IIA-CIA-PART3 Practice