GRC Analyst interview questions
100 real questions with model answers and explanations for Middle candidates.
See a GRC Analyst resume example →Practice with flashcards
Spaced repetition · Hunter Pass
Questions
I map each requirement to the objective and activity it actually covers, not merely to similar wording.
- Each row identifies the source citation and version, common-control ID, covered assertion, and any uncovered condition.
- For quarterly privileged-access reviews, I record the population, reviewer, decision criteria, cadence, and retained approvals as implementation facts.
- I label each relationship full, partial, or supporting and require framework-owner approval before claiming full coverage.
Why interviewers ask this: The interviewer is testing whether the candidate treats a crosswalk as traceable analysis rather than keyword matching.
I build the library around operating activities, with one stable record for each distinct control.
- Each record contains an objective, owner, frequency, scoped systems, procedure, evidence specification, test method, and version history.
- Framework requirements link many-to-many to that record, while framework-specific conditions remain explicit extensions.
- I split a control when activities have different owners, frequencies, populations, or failure modes because one test cannot support them all.
Why interviewers ask this: A strong answer shows that reuse comes from precise control design rather than broad statements.
An obligation states what must be achieved, a control is how the organization addresses it, and evidence shows that the control operated.
- A PCI requirement or contract clause enters an obligations register with source, applicability, owner, and effective date.
- One or more controls implement it through named activities, such as disabling terminated accounts within 24 hours.
- An Okta log and approved termination ticket support operation for a period, but neither artifact is the control itself or proof of every related obligation.
Why interviewers ask this: The interviewer wants a data model that prevents requirements, controls, and screenshots from becoming synonyms.
I turn the objective into a falsifiable statement that names the population, expected condition, period, and criteria.
- For production access, the assertion may be that every privileged account in the complete quarter-end population was authorized by the system owner and unnecessary access was removed on time.
- The procedure obtains a complete system-generated population, validates its completeness, and inspects selected approvals, removals, and timing against the defined criteria.
- The evidence specification identifies export parameters and timestamp, approval records, removal tickets, and exceptions so another tester can reproduce the conclusion.
Why interviewers ask this: The interviewer is testing whether the candidate can turn a broad objective into an assertion with a defined population, procedure, and reproducible evidence.
One artifact can be reused only when its provenance, scope, period, and attributes satisfy each linked control specification.
- A monthly IAM export may support inventory and review controls if it is system-generated, complete, dated, and tied to an approved review.
- The evidence catalog stores the source system, report parameters, extraction time, covered population, custodian, and immutable location.
- I keep separate conclusions per control because the export may prove population completeness but not timely approval or removal.
Why interviewers ask this: The interviewer is looking for disciplined reuse rather than attaching one convenient report everywhere.
I document which responsibility is inherited, which remains with the consuming team, and what validates the boundary.
- The record names the provider, service scope, control statement, assurance source, validity period, and consuming systems.
- For AWS physical security I may rely on a relevant SOC report, while our team still owns region selection, IAM, logging, and customer responsibilities.
- A service change, report qualification, uncovered region, or expired assurance triggers reassessment instead of silent continued reliance.
Why interviewers ask this: A strong answer distinguishes inherited assurance from shared and retained responsibilities.
I establish scope from business services and regulated data flows before selecting systems or controls.
- The scope pack includes legal entities, products, locations, data-flow diagrams, system and asset inventories, interfaces, vendors, and explicit exclusions.
- Every exclusion has a factual rationale, such as no connectivity or relevant data handling, plus an accountable approver.
- I reconcile diagrams to CMDB, cloud accounts, repositories, identity tenants, and vendor records so an outdated inventory does not create a false boundary.
Why interviewers ask this: The interviewer is testing whether scope is evidence-based rather than negotiated around inconvenient systems.
I reuse a test only when the control, scope, period, population, attributes, and assurance standard support the second purpose.
- The reuse memo links the original workpaper, tester competence and independence, sample, exceptions, test date, and exact requirements covered.
- A SOC 2 access review test may support ISO for the same systems and period, but not a PCI population containing additional CDE systems.
- If timing or criteria differ, I perform a roll-forward or incremental test and record the remaining gap rather than copying the conclusion.
Why interviewers ask this: The interviewer is checking whether efficiency is balanced with sufficient and appropriate evidence.
I mark the common awareness control as partial and model role-based training as an additional requirement or activity.
- The mapping records which clauses the annual course satisfies and leaves the role-specific audience, content, and completion evidence visibly open.
- I add targeted training for administrators or payment staff with an owner, trigger, due date, roster, and completion record.
- Coverage changes to full only after design review and operating evidence show both activities work for the scoped population.
Why interviewers ask this: A strong candidate preserves requirement-level gaps instead of letting a broad control hide them.
I version the source requirement, mapping decision, and control together so historical assurance conclusions remain reproducible.
- The change record captures old and new citations, effective date, impact assessment, mapping owner, approver, and affected tests and evidence requests.
- A diff review classifies the change as editorial, clarified, expanded, new, or retired and opens gaps for any new obligation.
- Approved mappings are baselined per audit period, while later changes use change control rather than silently rewriting prior workpapers.
Why interviewers ask this: The interviewer is evaluating whether the library can explain what was true during an earlier audit period.
I run it as a staged assurance project: define scope and criteria, remediate readiness gaps, operate controls for the period, support testing, and close the report.
- Readiness produces the system boundary, service commitments, selected Trust Services Criteria, control matrix, owners, evidence plan, and gap register.
- Before the period starts, key controls are implemented and owners can produce complete populations and repeatable evidence on schedule.
- During fieldwork I manage walkthroughs, PBC requests, samples, deviations, management responses, representation materials, and final report review with the CPA firm.
Why interviewers ask this: The interviewer wants end-to-end ownership and correct separation between readiness, management operation, and auditor examination.
I treat a Type II report as assurance bounded by its scope and period, not as a general badge for the vendor.
- I first compare the system description, covered services and locations, selected Trust Services Criteria, and report period with our use of the service.
- I then read control test procedures and results, deviations, and management responses, assessing their pervasiveness and relevance to the controls we depend on.
- Finally, I map CUECs to our responsibilities and review the subservice-organization method, complementary controls, and any coverage gaps.
Why interviewers ask this: The interviewer is checking whether the candidate can read the core Type II sections and connect scope, period, test results, and allocated responsibilities to the use case.
The scoped controls must be designed, assigned, implemented, and capable of producing evidence from the first day of the period.
- I baseline the system description, selected criteria, control matrix, subservice treatment, CUECs, owners, frequencies, and evidence sources.
- For recurring controls I dry-run population generation, timestamps, approvals, and retention instead of waiting for fieldwork to reveal gaps.
- Open readiness items are remediated before day one, excluded through a defensible scope change, or accepted with the likely report impact.
Why interviewers ask this: A strong answer recognizes that evidence cannot normally be recreated after a control failed to operate during the period.
A walkthrough confirms how a control is designed and implemented by tracing a real instance with the people who perform it.
- I capture the owner, trigger, systems, steps, frequency, population source, retained evidence, exceptions, and handoffs.
- The owner demonstrates one recent item from initiation through approval and completion, and I reconcile it to the written control.
- The workpaper records attendees, date, artifact references, design gaps, and follow-ups without treating the walkthrough as full operating-effectiveness testing.
Why interviewers ask this: The interviewer is looking for the distinction between understanding implementation and concluding on operation across the period.
I validate how the population was generated before relying on any sample selected from it.
- The PBC package includes system of record, report name or query, parameters, covered dates, filters, row count, extraction timestamp, and preparer.
- I reconcile counts to an independent source, inspect first and last dates, test excluded statuses, and preserve the generated file and parameters.
- If a Jira export omits emergency changes or an API paginates incompletely, I regenerate it before the auditor selects samples.
Why interviewers ask this: A strong answer shows that testing selected items is meaningless when the source population is not demonstrably complete and accurate.
I make populations and item-level evidence audit-ready while leaving sample selection and sufficiency judgments to the service auditor.
- The control matrix states frequency and expected attributes such as requester, approver, timestamp, test result, and closure evidence for each change.
- I provide a complete population in a reproducible format and maintain an index so any selected item can be retrieved without alteration.
- I track selections, replacements, missing evidence, deviations, and due dates but never substitute convenient items without the auditor’s documented reason.
Why interviewers ask this: The interviewer is testing whether management prepares evidence while the auditor owns the test sample.
CUECs are controls the service organization assumes user entities operate for its controls to achieve the stated criteria.
- A payroll provider may require the customer to authorize users, review payroll inputs, and remove access for terminated staff.
- The customer maps each applicable CUEC to an internal owner, procedure, evidence, and test or records why it is not applicable.
- A clean provider opinion does not cover the customer’s failure to operate a required CUEC, so the CUEC section belongs in the review workpaper.
Why interviewers ask this: The interviewer is checking whether the candidate reads customer responsibilities rather than only the opinion page.
A subservice organization performs functions relevant to service commitments, so its role and control dependencies must be explicit.
- I identify the service, data and processes involved, relevant controls, assurance reports, period coverage, exceptions, and management monitoring.
- Complementary subservice organization controls describe what the provider must operate, while our controls cover selection, configuration, monitoring, and incidents.
- Cloud hosts and payment processors are assessed for relevance rather than automatically listed merely because they are vendors.
Why interviewers ask this: A strong answer distinguishes a relevant subservice dependency from the general vendor inventory.
The carve-out method excludes the subservice organization’s controls from examination, while the inclusive method includes them in the described system and testing.
- Under carve-out, the description identifies omitted functions and complementary subservice organization controls, and management monitors the provider separately.
- Under inclusive, relevant provider controls, management assertion, and auditor testing are included, requiring cooperation and suitable evidence from that organization.
- Neither method removes our responsibility to understand dependencies, CUECs, report periods, exceptions, and customer commitments.
Why interviewers ask this: The interviewer is testing a precise reporting distinction rather than simple awareness that a cloud provider is involved.
I establish the condition and extent, remediate transparently, and leave the assurance conclusion to the service auditor.
- The issue record captures the expected control, observed item and dates, cause, population size, duration, and any compensating activity, followed by a search for similar cases.
- The response states the facts, risk, immediate correction, corrective action, owner, due date, and effectiveness evidence without arguing the exception away.
- The auditor independently considers frequency, pervasiveness, other evidence, and report impact, and remediation cannot erase the original test result.
Why interviewers ask this: A strong answer separates management investigation and remediation from the auditor’s opinion judgment.
Locked questions
- 21
How do you determine organizational context and ISMS scope under ISO 27001:2022?
governanceiso-27001 - 22
What should an ISO 27001 risk assessment method define before risks are scored?
governancerisk-management - 23
How do the risk assessment, risk treatment plan, and risk acceptance decision fit together in an ISO 27001 ISMS?
governancerisk-managementiso-27001 - 24
What must a defensible ISO 27001:2022 Statement of Applicability contain?
statement-of-applicabilitygovernance - 25
How should a team use the 93 controls in ISO 27001:2022 Annex A during risk treatment?
governancerisk-management - 26
How would you design an ISO 27001 internal audit program for a growing organization?
audit-planningdesigngovernance - 27
What inputs and outputs should be visible in an ISO 27001 management review record?
management-reviewgovernance - 28
An internal audit finds that two quarterly access reviews were late. How do you record the ISO 27001 nonconformity?
governance - 29
What is the difference between correction, root-cause analysis, corrective action, and effectiveness review in ISO 27001?
corrective-actiongovernance - 30
How do you demonstrate continual improvement of an ISO 27001 ISMS without relying on slogans?
governanceiso-27001 - 31
How do you determine PCI DSS 4.0.1 scope for an e-commerce environment?
pci-dss - 32
What evidence demonstrates that PCI DSS network segmentation actually reduces scope?
network-securitynetwork-segmentation - 33
How do you validate PCI DSS scope annually and after a significant change?
validation - 34
How do SAQ, ROC, and assessor roles differ in a PCI DSS validation?
evaluationvalidation - 35
What does an Attestation of Compliance prove, and what does it not replace?
compliance - 36
How does the PCI DSS customized approach differ from a compensating control?
- 37
What is a targeted risk analysis in PCI DSS 4.0.1, and when is it used?
risk-managementpci-dss - 38
How would you build Current and Target Profiles using NIST CSF 2.0?
governancenist-csf - 39
How would you map NIST SP 800-53 controls to GDPR Article 32 without claiming legal equivalence?
gdprgovernancecompliance - 40
How would you connect a PCI DSS assessment, a NIST CSF 2.0 Profile, and NIST 800-53 controls in one GRC system?
governancenist-csfsystem-design - 41
How do inherent and residual risk differ in a third-party risk assessment?
risk-managementdependencies - 42
How would you design third-party risk tiers that drive actual workflow?
risk-managementdesigndependencies - 43
How should due diligence depth differ for a critical SaaS provider and a low-risk office-supply vendor?
vendor-due-diligencecloudprocurement - 44
How do you validate a vendor’s ISO 27001 certificate before relying on it in a third-party risk assessment?
validationcryptographygovernance - 45
A vendor’s SOC 2 period ended four months ago. What value does a bridge letter add, and what are its limits?
compliancesoc-operationssoc-2 - 46
Which security and resilience terms would you prioritize in a contract for a critical data-processing vendor?
concurrencyprocurement - 47
How do you assess concentration risk when several critical services depend on the same provider?
risk-management - 48
How do you evaluate fourth-party risk when a SaaS vendor relies on subprocessors?
procurementdecision-makingcloud - 49
What should continuous monitoring for a critical third party include beyond a security-rating feed?
monitoring - 50
How do you offboard a critical vendor in a way that closes security, compliance, and operational risk?
compliancerisk-managementprocurement - 51
You own a 12-month SOC 2 Type II audit covering 146 controls, with fieldwork starting in 10 weeks. How would you launch the cycle?
compliancesoc-operationssoc-2 - 52
Three weeks before SOC 2 fieldwork, 28 of 180 evidence requests are still open across Engineering, HR, and Finance. What would you do?
compliancesoc-operationssoc-2 - 53
An access-review control requires quarterly evidence, but the Q2 package contains an undated spreadsheet and approval only in Slack. How would you handle the gap?
spreadsheetsspread - 54
A SOC 2 change-management control says every production deployment is approved, but the CI/CD platform also permits service-account and emergency deployments. How would you test the control design?
compliancesoc-operationssoc-2 - 55
In a sample of 25 terminated users, two accounts were disabled 3 and 6 days after the 24-hour control target. How would you manage the exceptions?
error-handling - 56
Your SaaS system depends on customers to configure SSO and remove departed users, but the draft SOC 2 report lists no complementary user entity controls. What would you do?
compliancesoc-operationssoc-2 - 57
A cloud hosting provider and payroll processor both support the in-scope service; how would you decide and document SOC 2 subservice organization scope?
compliancecloud-securitysoc-operations - 58
A key subservice provider's SOC 2 report ends September 30, while your audit period ends December 31. How would you cover the three-month gap?
compliancesoc-operationssoc-2 - 59
The SOC 2 auditor proposes an exception because monthly vulnerability-review evidence is missing for 2 of 12 months, and management says the reviews happened verbally. How would you draft the response?
vulnerabilitiescompliancesoc-operations - 60
A company wants to extend its SOC 2 Type II period from 6 to 12 months, but a redesigned access-review control went live in month 4. How would you plan testing?
compliancesoc-operationssoc-2 - 61
You must run an ISO 27001 internal audit of 42 controls, but you helped design 11 of them. How would you preserve audit independence?
governancedesign - 62
The Statement of Applicability marks Annex A supplier controls not applicable, yet the vendor register lists 137 cloud and professional-service providers. What would you do?
statement-of-applicabilityprocurementcloud-security - 63
During an ISO internal audit, 7 of 30 sampled access reviews lack reviewer approval, while the process owner calls them minor paperwork issues. How would you classify the finding?
concurrency - 64
An ISO 27001 nonconformity for overdue risk reviews has recurred in two consecutive audits. What CAPA would you expect?
governancerisk-management - 65
A CAPA was marked complete after a policy update, but the affected control still failed 4 of 18 samples. What would you do?
policy-management - 66
Six weeks before an ISO 27001 surveillance audit, the ISMS objectives dashboard has not been updated for one quarter. How would you recover readiness?
governanceiso-27001health-checks - 67
A PCI DSS 4.0 scoping workshop finds card data in 3 applications and 27 infrastructure components, while the existing scope lists only 14 components. What would you do?
components - 68
A PCI review finds PAN in application logs and backups 14 months after the approved 90-day retention period. How would you respond?
retentionbackups - 69
An e-commerce site added 6 payment-page scripts, but the PCI evidence folder contains only an annual screenshot. What evidence would you require?
- 70
A legacy payment application cannot meet 1 PCI DSS requirement before an assessment in 4 months, and the owner proposes a compensating control. How would you evaluate it?
decision-making - 71
You are asked to assess risks for a new customer-data platform across 8 business processes and 34 systems. How would you structure the assessment?
system-designconcurrency - 72
Five business units each rate reliance on the same identity provider as medium risk, but a provider outage would stop 78% of company operations. How would you aggregate the risk?
aggregationrisk-management - 73
A risk owner lowers a risk from high inherent to low residual because a policy maps to 6 controls, but none has been tested. What would you do?
policy-managementriskrisk-management - 74
A $180,000 control would reduce an estimated $90,000 annualized risk, while a $25,000 insurance rider covers part of the loss. How would you recommend treatment?
estimationrisk-management - 75
A high data-exfiltration risk lists 12 controls, but every control is preventive and none detects, contains, or recovers from an event. How would you assess the treatment?
data-exfiltrationrisk-management - 76
A third-party KRI shows overdue critical remediations rising from 4 to 11 in one month. Its amber threshold is 10 and red threshold is 15. How would you respond?
dependencies - 77
A director wants to accept a $2.4 million residual risk, but the authority matrix limits directors to $500,000. What would you do?
risk-management - 78
Which materials would you prepare for an audit committee when 3 high risks exceed appetite and one could delay a $12 million product launch?
- 79
A risk rated medium six months ago now affects 240,000 additional customer records after an acquisition. How would you reassess it?
risk-management - 80
A risk dashboard shows 64 open risks, but leaders cannot tell whether exposure is improving because teams use four different scoring scales. What would you change?
risk-management - 81
You inherit a TPRM inventory of 386 vendors with no tiering, and 74 process confidential data. How would you prioritize the first 60 days?
prioritizationownershipconcurrency - 82
A critical payroll vendor provides a SOC 2 report that is 14 months old and covers security but not availability. Renewal is in 21 days. What would you do?
compliancesoc-operationssoc-2 - 83
A top-tier vendor's SOC 2 report has a qualified opinion tied to change management, with 9 of 40 samples missing approval. How would you assess it?
compliancesoc-operationssoc-2 - 84
A vendor handling 600,000 customer records proposes breach notice within 10 business days, while company policy requires 48 hours. How would you handle the contract review?
policy-managementprocurement - 85
A critical analytics vendor uses 23 fourth parties, but its assurance package names only 8. What would you do?
procurement - 86
A medium-tier vendor was reviewed 11 months ago, but it has now gained production access and doubled its data volume. When and how would you reassess it?
procurement - 87
A strategic vendor rejects your 220-question security questionnaire and offers only a SOC 2 report and ISO 27001 certificate. How would you proceed?
cryptographygovernancecompliance - 88
Procurement wants to onboard a revenue-critical vendor in 5 days, but the normal high-risk review takes 20 days. What would you do?
procurementonboardingrisk-management - 89
Across 500 vendors, 37 high-risk findings are overdue and business owners dispute 12 of them. How would you recover the remediation program?
procurementrisk-management - 90
A critical sole-source vendor receives a going-concern warning and reports only nine months of cash runway. How would you assess and govern the risk?
procurementrisk-management - 91
SOC 2, ISO 27001, and PCI teams maintain 318 overlapping controls in separate spreadsheets. How would you build a shared control library?
governancecompliancesoc-operations - 92
A NIST 800-53 to ISO 27001 crosswalk marks 96% coverage, but 41 mappings have no control owner or evidence. How would you correct the metric?
governancecoveragemonitoring - 93
Drata shows 82% automated evidence coverage, but an AWS connector was disconnected for 19 days without an alert. How would you assess automation reliability?
coveragealerting - 94
Hyperproof contains 240 controls, but 63 evidence links point to editable documents with no retained version. How would you remediate this?
- 95
AuditBoard sends the same quarterly evidence request to 54 owners, causing duplicates and 31% late submissions. How would you redesign the workflow?
- 96
ServiceNow GRC creates Jira remediation tickets, but 18 of 76 tickets closed in Jira remain open in the risk register. How would you fix the integration?
risk-managementrisk-registerrisk - 97
The CISO dashboard reports 94% control health, yet 22 overdue evidence tasks and 6 accepted exceptions are excluded. How would you rebuild it?
error-handling - 98
Evidence owners meet the 5-day SLA only 58% of the time across 210 monthly requests. How would you improve performance?
performance - 99
You are mentoring 2 analysts who inconsistently review SOC reports and vendor findings. What 90-day plan would you use?
procurementmentoringsoc-operations - 100
You have 48 hours to prepare the CISO for an audit committee briefing on a SOC 2 exception, 9 overdue high risks, and a delayed PCI remediation. What would you deliver?
compliancesoc-operationssoc-2