Skip to content

GRC Analyst interview questions

100 real questions with model answers and explanations for Middle candidates.

See a GRC Analyst resume example

Practice with flashcards

Spaced repetition · Hunter Pass

Questions

governancecompliancesoc-operations

I map each requirement to the objective and activity it actually covers, not merely to similar wording.

  • Each row identifies the source citation and version, common-control ID, covered assertion, and any uncovered condition.
  • For quarterly privileged-access reviews, I record the population, reviewer, decision criteria, cadence, and retained approvals as implementation facts.
  • I label each relationship full, partial, or supporting and require framework-owner approval before claiming full coverage.

Why interviewers ask this: The interviewer is testing whether the candidate treats a crosswalk as traceable analysis rather than keyword matching.

control-library

I build the library around operating activities, with one stable record for each distinct control.

  • Each record contains an objective, owner, frequency, scoped systems, procedure, evidence specification, test method, and version history.
  • Framework requirements link many-to-many to that record, while framework-specific conditions remain explicit extensions.
  • I split a control when activities have different owners, frequencies, populations, or failure modes because one test cannot support them all.

Why interviewers ask this: A strong answer shows that reuse comes from precise control design rather than broad statements.

An obligation states what must be achieved, a control is how the organization addresses it, and evidence shows that the control operated.

  • A PCI requirement or contract clause enters an obligations register with source, applicability, owner, and effective date.
  • One or more controls implement it through named activities, such as disabling terminated accounts within 24 hours.
  • An Okta log and approved termination ticket support operation for a period, but neither artifact is the control itself or proof of every related obligation.

Why interviewers ask this: The interviewer wants a data model that prevents requirements, controls, and screenshots from becoming synonyms.

control-objectives

I turn the objective into a falsifiable statement that names the population, expected condition, period, and criteria.

  • For production access, the assertion may be that every privileged account in the complete quarter-end population was authorized by the system owner and unnecessary access was removed on time.
  • The procedure obtains a complete system-generated population, validates its completeness, and inspects selected approvals, removals, and timing against the defined criteria.
  • The evidence specification identifies export parameters and timestamp, approval records, removal tickets, and exceptions so another tester can reproduce the conclusion.

Why interviewers ask this: The interviewer is testing whether the candidate can turn a broad objective into an assertion with a defined population, procedure, and reproducible evidence.

artifacts

One artifact can be reused only when its provenance, scope, period, and attributes satisfy each linked control specification.

  • A monthly IAM export may support inventory and review controls if it is system-generated, complete, dated, and tied to an approved review.
  • The evidence catalog stores the source system, report parameters, extraction time, covered population, custodian, and immutable location.
  • I keep separate conclusions per control because the export may prove population completeness but not timely approval or removal.

Why interviewers ask this: The interviewer is looking for disciplined reuse rather than attaching one convenient report everywhere.

ownershipoopcloud-security

I document which responsibility is inherited, which remains with the consuming team, and what validates the boundary.

  • The record names the provider, service scope, control statement, assurance source, validity period, and consuming systems.
  • For AWS physical security I may rely on a relevant SOC report, while our team still owns region selection, IAM, logging, and customer responsibilities.
  • A service change, report qualification, uncovered region, or expired assurance triggers reassessment instead of silent continued reliance.

Why interviewers ask this: A strong answer distinguishes inherited assurance from shared and retained responsibilities.

compliancecompliance-scopeartifacts

I establish scope from business services and regulated data flows before selecting systems or controls.

  • The scope pack includes legal entities, products, locations, data-flow diagrams, system and asset inventories, interfaces, vendors, and explicit exclusions.
  • Every exclusion has a factual rationale, such as no connectivity or relevant data handling, plus an accountable approver.
  • I reconcile diagrams to CMDB, cloud accounts, repositories, identity tenants, and vendor records so an outdated inventory does not create a false boundary.

Why interviewers ask this: The interviewer is testing whether scope is evidence-based rather than negotiated around inconvenient systems.

engagement

I reuse a test only when the control, scope, period, population, attributes, and assurance standard support the second purpose.

  • The reuse memo links the original workpaper, tester competence and independence, sample, exceptions, test date, and exact requirements covered.
  • A SOC 2 access review test may support ISO for the same systems and period, but not a PCI population containing additional CDE systems.
  • If timing or criteria differ, I perform a roll-forward or incremental test and record the remaining gap rather than copying the conclusion.

Why interviewers ask this: The interviewer is checking whether efficiency is balanced with sufficient and appropriate evidence.

I mark the common awareness control as partial and model role-based training as an additional requirement or activity.

  • The mapping records which clauses the annual course satisfies and leaves the role-specific audience, content, and completion evidence visibly open.
  • I add targeted training for administrators or payment staff with an owner, trigger, due date, roster, and completion record.
  • Coverage changes to full only after design review and operating evidence show both activities work for the scoped population.

Why interviewers ask this: A strong candidate preserves requirement-level gaps instead of letting a broad control hide them.

control-mapping

I version the source requirement, mapping decision, and control together so historical assurance conclusions remain reproducible.

  • The change record captures old and new citations, effective date, impact assessment, mapping owner, approver, and affected tests and evidence requests.
  • A diff review classifies the change as editorial, clarified, expanded, new, or retired and opens gaps for any new obligation.
  • Approved mappings are baselined per audit period, while later changes use change control rather than silently rewriting prior workpapers.

Why interviewers ask this: The interviewer is evaluating whether the library can explain what was true during an earlier audit period.

compliancesoc-operationssoc-2

I run it as a staged assurance project: define scope and criteria, remediate readiness gaps, operate controls for the period, support testing, and close the report.

  • Readiness produces the system boundary, service commitments, selected Trust Services Criteria, control matrix, owners, evidence plan, and gap register.
  • Before the period starts, key controls are implemented and owners can produce complete populations and repeatable evidence on schedule.
  • During fieldwork I manage walkthroughs, PBC requests, samples, deviations, management responses, representation materials, and final report review with the CPA firm.

Why interviewers ask this: The interviewer wants end-to-end ownership and correct separation between readiness, management operation, and auditor examination.

compliancesoc-operationssoc-2

I treat a Type II report as assurance bounded by its scope and period, not as a general badge for the vendor.

  • I first compare the system description, covered services and locations, selected Trust Services Criteria, and report period with our use of the service.
  • I then read control test procedures and results, deviations, and management responses, assessing their pervasiveness and relevance to the controls we depend on.
  • Finally, I map CUECs to our responsibilities and review the subservice-organization method, complementary controls, and any coverage gaps.

Why interviewers ask this: The interviewer is checking whether the candidate can read the core Type II sections and connect scope, period, test results, and allocated responsibilities to the use case.

compliancesoc-operationssoc-2

The scoped controls must be designed, assigned, implemented, and capable of producing evidence from the first day of the period.

  • I baseline the system description, selected criteria, control matrix, subservice treatment, CUECs, owners, frequencies, and evidence sources.
  • For recurring controls I dry-run population generation, timestamps, approvals, and retention instead of waiting for fieldwork to reveal gaps.
  • Open readiness items are remediated before day one, excluded through a defensible scope change, or accepted with the likely report impact.

Why interviewers ask this: A strong answer recognizes that evidence cannot normally be recreated after a control failed to operate during the period.

compliancesoc-operationssoc-2

A walkthrough confirms how a control is designed and implemented by tracing a real instance with the people who perform it.

  • I capture the owner, trigger, systems, steps, frequency, population source, retained evidence, exceptions, and handoffs.
  • The owner demonstrates one recent item from initiation through approval and completion, and I reconcile it to the written control.
  • The workpaper records attendees, date, artifact references, design gaps, and follow-ups without treating the walkthrough as full operating-effectiveness testing.

Why interviewers ask this: The interviewer is looking for the distinction between understanding implementation and concluding on operation across the period.

compliancesoc-operationssoc-2

I validate how the population was generated before relying on any sample selected from it.

  • The PBC package includes system of record, report name or query, parameters, covered dates, filters, row count, extraction timestamp, and preparer.
  • I reconcile counts to an independent source, inspect first and last dates, test excluded statuses, and preserve the generated file and parameters.
  • If a Jira export omits emergency changes or an API paginates incompletely, I regenerate it before the auditor selects samples.

Why interviewers ask this: A strong answer shows that testing selected items is meaningless when the source population is not demonstrably complete and accurate.

compliancesoc-operationssoc-2

I make populations and item-level evidence audit-ready while leaving sample selection and sufficiency judgments to the service auditor.

  • The control matrix states frequency and expected attributes such as requester, approver, timestamp, test result, and closure evidence for each change.
  • I provide a complete population in a reproducible format and maintain an index so any selected item can be retrieved without alteration.
  • I track selections, replacements, missing evidence, deviations, and due dates but never substitute convenient items without the auditor’s documented reason.

Why interviewers ask this: The interviewer is testing whether management prepares evidence while the auditor owns the test sample.

compliancesoc-operationssoc-2

CUECs are controls the service organization assumes user entities operate for its controls to achieve the stated criteria.

  • A payroll provider may require the customer to authorize users, review payroll inputs, and remove access for terminated staff.
  • The customer maps each applicable CUEC to an internal owner, procedure, evidence, and test or records why it is not applicable.
  • A clean provider opinion does not cover the customer’s failure to operate a required CUEC, so the CUEC section belongs in the review workpaper.

Why interviewers ask this: The interviewer is checking whether the candidate reads customer responsibilities rather than only the opinion page.

compliancesoc-operationssoc-2

A subservice organization performs functions relevant to service commitments, so its role and control dependencies must be explicit.

  • I identify the service, data and processes involved, relevant controls, assurance reports, period coverage, exceptions, and management monitoring.
  • Complementary subservice organization controls describe what the provider must operate, while our controls cover selection, configuration, monitoring, and incidents.
  • Cloud hosts and payment processors are assessed for relevance rather than automatically listed merely because they are vendors.

Why interviewers ask this: A strong answer distinguishes a relevant subservice dependency from the general vendor inventory.

compliancesoc-operationssoc-2

The carve-out method excludes the subservice organization’s controls from examination, while the inclusive method includes them in the described system and testing.

  • Under carve-out, the description identifies omitted functions and complementary subservice organization controls, and management monitors the provider separately.
  • Under inclusive, relevant provider controls, management assertion, and auditor testing are included, requiring cooperation and suitable evidence from that organization.
  • Neither method removes our responsibility to understand dependencies, CUECs, report periods, exceptions, and customer commitments.

Why interviewers ask this: The interviewer is testing a precise reporting distinction rather than simple awareness that a cloud provider is involved.

complianceincident-responsesoc-operations

I establish the condition and extent, remediate transparently, and leave the assurance conclusion to the service auditor.

  • The issue record captures the expected control, observed item and dates, cause, population size, duration, and any compensating activity, followed by a search for similar cases.
  • The response states the facts, risk, immediate correction, corrective action, owner, due date, and effectiveness evidence without arguing the exception away.
  • The auditor independently considers frequency, pervasiveness, other evidence, and report impact, and remediation cannot erase the original test result.

Why interviewers ask this: A strong answer separates management investigation and remediation from the auditor’s opinion judgment.

Locked questions

  • 21

    How do you determine organizational context and ISMS scope under ISO 27001:2022?

    governanceiso-27001
  • 22

    What should an ISO 27001 risk assessment method define before risks are scored?

    governancerisk-management
  • 23

    How do the risk assessment, risk treatment plan, and risk acceptance decision fit together in an ISO 27001 ISMS?

    governancerisk-managementiso-27001
  • 24

    What must a defensible ISO 27001:2022 Statement of Applicability contain?

    statement-of-applicabilitygovernance
  • 25

    How should a team use the 93 controls in ISO 27001:2022 Annex A during risk treatment?

    governancerisk-management
  • 26

    How would you design an ISO 27001 internal audit program for a growing organization?

    audit-planningdesigngovernance
  • 27

    What inputs and outputs should be visible in an ISO 27001 management review record?

    management-reviewgovernance
  • 28

    An internal audit finds that two quarterly access reviews were late. How do you record the ISO 27001 nonconformity?

    governance
  • 29

    What is the difference between correction, root-cause analysis, corrective action, and effectiveness review in ISO 27001?

    corrective-actiongovernance
  • 30

    How do you demonstrate continual improvement of an ISO 27001 ISMS without relying on slogans?

    governanceiso-27001
  • 31

    How do you determine PCI DSS 4.0.1 scope for an e-commerce environment?

    pci-dss
  • 32

    What evidence demonstrates that PCI DSS network segmentation actually reduces scope?

    network-securitynetwork-segmentation
  • 33

    How do you validate PCI DSS scope annually and after a significant change?

    validation
  • 34

    How do SAQ, ROC, and assessor roles differ in a PCI DSS validation?

    evaluationvalidation
  • 35

    What does an Attestation of Compliance prove, and what does it not replace?

    compliance
  • 36

    How does the PCI DSS customized approach differ from a compensating control?

  • 37

    What is a targeted risk analysis in PCI DSS 4.0.1, and when is it used?

    risk-managementpci-dss
  • 38

    How would you build Current and Target Profiles using NIST CSF 2.0?

    governancenist-csf
  • 39

    How would you map NIST SP 800-53 controls to GDPR Article 32 without claiming legal equivalence?

    gdprgovernancecompliance
  • 40

    How would you connect a PCI DSS assessment, a NIST CSF 2.0 Profile, and NIST 800-53 controls in one GRC system?

    governancenist-csfsystem-design
  • 41

    How do inherent and residual risk differ in a third-party risk assessment?

    risk-managementdependencies
  • 42

    How would you design third-party risk tiers that drive actual workflow?

    risk-managementdesigndependencies
  • 43

    How should due diligence depth differ for a critical SaaS provider and a low-risk office-supply vendor?

    vendor-due-diligencecloudprocurement
  • 44

    How do you validate a vendor’s ISO 27001 certificate before relying on it in a third-party risk assessment?

    validationcryptographygovernance
  • 45

    A vendor’s SOC 2 period ended four months ago. What value does a bridge letter add, and what are its limits?

    compliancesoc-operationssoc-2
  • 46

    Which security and resilience terms would you prioritize in a contract for a critical data-processing vendor?

    concurrencyprocurement
  • 47

    How do you assess concentration risk when several critical services depend on the same provider?

    risk-management
  • 48

    How do you evaluate fourth-party risk when a SaaS vendor relies on subprocessors?

    procurementdecision-makingcloud
  • 49

    What should continuous monitoring for a critical third party include beyond a security-rating feed?

    monitoring
  • 50

    How do you offboard a critical vendor in a way that closes security, compliance, and operational risk?

    compliancerisk-managementprocurement
  • 51

    You own a 12-month SOC 2 Type II audit covering 146 controls, with fieldwork starting in 10 weeks. How would you launch the cycle?

    compliancesoc-operationssoc-2
  • 52

    Three weeks before SOC 2 fieldwork, 28 of 180 evidence requests are still open across Engineering, HR, and Finance. What would you do?

    compliancesoc-operationssoc-2
  • 53

    An access-review control requires quarterly evidence, but the Q2 package contains an undated spreadsheet and approval only in Slack. How would you handle the gap?

    spreadsheetsspread
  • 54

    A SOC 2 change-management control says every production deployment is approved, but the CI/CD platform also permits service-account and emergency deployments. How would you test the control design?

    compliancesoc-operationssoc-2
  • 55

    In a sample of 25 terminated users, two accounts were disabled 3 and 6 days after the 24-hour control target. How would you manage the exceptions?

    error-handling
  • 56

    Your SaaS system depends on customers to configure SSO and remove departed users, but the draft SOC 2 report lists no complementary user entity controls. What would you do?

    compliancesoc-operationssoc-2
  • 57

    A cloud hosting provider and payroll processor both support the in-scope service; how would you decide and document SOC 2 subservice organization scope?

    compliancecloud-securitysoc-operations
  • 58

    A key subservice provider's SOC 2 report ends September 30, while your audit period ends December 31. How would you cover the three-month gap?

    compliancesoc-operationssoc-2
  • 59

    The SOC 2 auditor proposes an exception because monthly vulnerability-review evidence is missing for 2 of 12 months, and management says the reviews happened verbally. How would you draft the response?

    vulnerabilitiescompliancesoc-operations
  • 60

    A company wants to extend its SOC 2 Type II period from 6 to 12 months, but a redesigned access-review control went live in month 4. How would you plan testing?

    compliancesoc-operationssoc-2
  • 61

    You must run an ISO 27001 internal audit of 42 controls, but you helped design 11 of them. How would you preserve audit independence?

    governancedesign
  • 62

    The Statement of Applicability marks Annex A supplier controls not applicable, yet the vendor register lists 137 cloud and professional-service providers. What would you do?

    statement-of-applicabilityprocurementcloud-security
  • 63

    During an ISO internal audit, 7 of 30 sampled access reviews lack reviewer approval, while the process owner calls them minor paperwork issues. How would you classify the finding?

    concurrency
  • 64

    An ISO 27001 nonconformity for overdue risk reviews has recurred in two consecutive audits. What CAPA would you expect?

    governancerisk-management
  • 65

    A CAPA was marked complete after a policy update, but the affected control still failed 4 of 18 samples. What would you do?

    policy-management
  • 66

    Six weeks before an ISO 27001 surveillance audit, the ISMS objectives dashboard has not been updated for one quarter. How would you recover readiness?

    governanceiso-27001health-checks
  • 67

    A PCI DSS 4.0 scoping workshop finds card data in 3 applications and 27 infrastructure components, while the existing scope lists only 14 components. What would you do?

    components
  • 68

    A PCI review finds PAN in application logs and backups 14 months after the approved 90-day retention period. How would you respond?

    retentionbackups
  • 69

    An e-commerce site added 6 payment-page scripts, but the PCI evidence folder contains only an annual screenshot. What evidence would you require?

  • 70

    A legacy payment application cannot meet 1 PCI DSS requirement before an assessment in 4 months, and the owner proposes a compensating control. How would you evaluate it?

    decision-making
  • 71

    You are asked to assess risks for a new customer-data platform across 8 business processes and 34 systems. How would you structure the assessment?

    system-designconcurrency
  • 72

    Five business units each rate reliance on the same identity provider as medium risk, but a provider outage would stop 78% of company operations. How would you aggregate the risk?

    aggregationrisk-management
  • 73

    A risk owner lowers a risk from high inherent to low residual because a policy maps to 6 controls, but none has been tested. What would you do?

    policy-managementriskrisk-management
  • 74

    A $180,000 control would reduce an estimated $90,000 annualized risk, while a $25,000 insurance rider covers part of the loss. How would you recommend treatment?

    estimationrisk-management
  • 75

    A high data-exfiltration risk lists 12 controls, but every control is preventive and none detects, contains, or recovers from an event. How would you assess the treatment?

    data-exfiltrationrisk-management
  • 76

    A third-party KRI shows overdue critical remediations rising from 4 to 11 in one month. Its amber threshold is 10 and red threshold is 15. How would you respond?

    dependencies
  • 77

    A director wants to accept a $2.4 million residual risk, but the authority matrix limits directors to $500,000. What would you do?

    risk-management
  • 78

    Which materials would you prepare for an audit committee when 3 high risks exceed appetite and one could delay a $12 million product launch?

  • 79

    A risk rated medium six months ago now affects 240,000 additional customer records after an acquisition. How would you reassess it?

    risk-management
  • 80

    A risk dashboard shows 64 open risks, but leaders cannot tell whether exposure is improving because teams use four different scoring scales. What would you change?

    risk-management
  • 81

    You inherit a TPRM inventory of 386 vendors with no tiering, and 74 process confidential data. How would you prioritize the first 60 days?

    prioritizationownershipconcurrency
  • 82

    A critical payroll vendor provides a SOC 2 report that is 14 months old and covers security but not availability. Renewal is in 21 days. What would you do?

    compliancesoc-operationssoc-2
  • 83

    A top-tier vendor's SOC 2 report has a qualified opinion tied to change management, with 9 of 40 samples missing approval. How would you assess it?

    compliancesoc-operationssoc-2
  • 84

    A vendor handling 600,000 customer records proposes breach notice within 10 business days, while company policy requires 48 hours. How would you handle the contract review?

    policy-managementprocurement
  • 85

    A critical analytics vendor uses 23 fourth parties, but its assurance package names only 8. What would you do?

    procurement
  • 86

    A medium-tier vendor was reviewed 11 months ago, but it has now gained production access and doubled its data volume. When and how would you reassess it?

    procurement
  • 87

    A strategic vendor rejects your 220-question security questionnaire and offers only a SOC 2 report and ISO 27001 certificate. How would you proceed?

    cryptographygovernancecompliance
  • 88

    Procurement wants to onboard a revenue-critical vendor in 5 days, but the normal high-risk review takes 20 days. What would you do?

    procurementonboardingrisk-management
  • 89

    Across 500 vendors, 37 high-risk findings are overdue and business owners dispute 12 of them. How would you recover the remediation program?

    procurementrisk-management
  • 90

    A critical sole-source vendor receives a going-concern warning and reports only nine months of cash runway. How would you assess and govern the risk?

    procurementrisk-management
  • 91

    SOC 2, ISO 27001, and PCI teams maintain 318 overlapping controls in separate spreadsheets. How would you build a shared control library?

    governancecompliancesoc-operations
  • 92

    A NIST 800-53 to ISO 27001 crosswalk marks 96% coverage, but 41 mappings have no control owner or evidence. How would you correct the metric?

    governancecoveragemonitoring
  • 93

    Drata shows 82% automated evidence coverage, but an AWS connector was disconnected for 19 days without an alert. How would you assess automation reliability?

    coveragealerting
  • 94

    Hyperproof contains 240 controls, but 63 evidence links point to editable documents with no retained version. How would you remediate this?

  • 95

    AuditBoard sends the same quarterly evidence request to 54 owners, causing duplicates and 31% late submissions. How would you redesign the workflow?

  • 96

    ServiceNow GRC creates Jira remediation tickets, but 18 of 76 tickets closed in Jira remain open in the risk register. How would you fix the integration?

    risk-managementrisk-registerrisk
  • 97

    The CISO dashboard reports 94% control health, yet 22 overdue evidence tasks and 6 accepted exceptions are excluded. How would you rebuild it?

    error-handling
  • 98

    Evidence owners meet the 5-day SLA only 58% of the time across 210 monthly requests. How would you improve performance?

    performance
  • 99

    You are mentoring 2 analysts who inconsistently review SOC reports and vendor findings. What 90-day plan would you use?

    procurementmentoringsoc-operations
  • 100

    You have 48 hours to prepare the CISO for an audit committee briefing on a SOC 2 exception, 9 overdue high risks, and a delayed PCI remediation. What would you deliver?

    compliancesoc-operationssoc-2