GRC Analyst interview questions
100 real questions with model answers and explanations for Senior candidates.
See a GRC Analyst resume example →Practice with flashcards
Spaced repetition · Hunter Pass
Questions
I would create one canonical control layer and treat the 8 frameworks as versioned requirement views rather than separate control sets.
- Normalize the 1,240 requirements into about 320 outcome-based controls, retaining every source citation in a mapping table.
- Give each control a stable ID, objective, owner, test procedure, evidence specification, frequency, applicability rule, and lifecycle status.
- Pilot the schema on 40 high-reuse controls in 6 weeks, then migrate the remaining domains in 3 monthly waves.
- Require control owners and Internal Audit to approve mappings before retiring any legacy record.
Why interviewers ask this: The interviewer is testing whether the candidate can turn framework overlap into a governed data model and executable migration.
I would make testability and accountability mandatory fields, then remediate controls by assurance exposure rather than alphabetically.
- Define required fields for control intent, risk statement, owner, operator, frequency, population, test steps, evidence, mappings, exceptions, and effective dates.
- Freeze publication when any required field is empty and route the record to a named data steward within 2 business days.
- Fix the 75 controls supporting active audits first, then high-risk controls, then the remaining library in 3 fortnightly batches.
- Exit the 90-day effort only when owner coverage reaches 100 percent and at least 95 percent of controls pass a testability review.
Why interviewers ask this: A strong answer connects schema quality to a risk-based remediation sequence and measurable exit criteria.
I would version framework citations independently from canonical controls and preserve an immutable audit snapshot for each engagement.
- Store source framework, edition, requirement ID, mapping strength, rationale, reviewer, and valid-from and valid-to dates on every mapping edge.
- Create a new mapping version for all 186 changes while leaving the 3 fieldwork snapshots read-only and reproducible.
- Run impact analysis to separate citation-only changes from controls needing revised language, evidence, or tests.
- Release changes through a control-library change board after 2 reviewers approve and affected owners receive 30 days to adopt them.
Why interviewers ask this: The interviewer is evaluating mapping version control, audit reproducibility, and disciplined change governance.
I would keep each shared control once at the enterprise parent and permit local overlays only for applicability, operator, evidence source, or stricter performance.
- Link all 14 units to the 6 parent controls through inheritance records with explicit effective dates.
- Prohibit local edits to the parent objective and test intent, while allowing an overlay to name a local operator or additional evidence.
- Require a deviation record with rationale, approver, expiry, and residual risk when a unit cannot inherit the parent as designed.
- Retire the 84 copies after a 2-cycle comparison proves each unit's evidence and test result remain traceable.
Why interviewers ask this: The interviewer wants a concrete inheritance model that reduces duplication without hiding local accountability.
I would assign one accountable control owner per control and separate that role from operators, evidence providers, and risk acceptors.
- Use a 32-row RACI decision log showing the control objective, process authority, budget authority, and proposed accountable owner.
- Resolve controls with clear process ownership in 5 business days and take the remaining disputes to a 60-minute executive decision forum.
- Record one accountable owner, named operators, evidence providers, and an escalation delegate in the canonical record.
- Measure success by 100 percent ownership, no decision older than 10 business days, and recovery of the lost 4-week readiness schedule.
Why interviewers ask this: A strong answer distinguishes accountability from execution and uses a bounded mechanism to settle ownership disputes.
I would score maturity only when design, operation, evidence, and issue performance all meet explicit thresholds.
- Count a control as mature only if ownership is current, design passed, 2 consecutive operating tests passed, and no overdue high issue exists.
- Weight key controls twice and report both weighted maturity and the raw percentage to prevent low-value controls from inflating the result.
- Exclude not-applicable controls only with documented rationale and independent approval, while showing the exclusion rate separately.
- Publish the formula, denominator, data date, and 12-month trend, then sample 25 mature controls quarterly for quality assurance.
Why interviewers ask this: The interviewer is testing whether the candidate can define a defensible metric with anti-gaming safeguards.
I would map the new obligations to existing outcomes first and create controls only for genuine capability gaps.
- Decompose the framework into atomic obligations and dual-map a 20 percent sample to calibrate mapping criteria.
- Classify each obligation as full, partial, or no coverage, with rationale and a second-review requirement for partial mappings.
- Cap new controls at 28, route any request above that threshold to the library change board, and prefer scoped test variants over duplicates.
- Deliver the crosswalk, gap register, owner assignments, and approved version in 4 three-week increments.
Why interviewers ask this: The interviewer is evaluating disciplined framework onboarding under a quantified duplication constraint.
I would consolidate by common control objective while preserving framework-specific assertions and audit traceability as mappings.
- Cluster the 96 records by objective, population, frequency, and test method rather than matching titles alone.
- Ask the 4 audit teams to approve a canonical statement plus any framework-specific assertion that must remain visible.
- Merge records only after evidence history, open issues, owners, and source citations are transferred to the surviving ID.
- Target at least 60 retirements in the quarter and report reuse ratio, evidence-request reduction, and zero broken audit links.
Why interviewers ask this: A strong answer shows that deduplication is controlled record migration rather than simple text cleanup.
I would model each exception as a time-bound child artifact linked to one control, one scope, and one accountable risk acceptor.
- Require business rationale, affected assets or processes, residual risk, compensating control, approver, start date, and expiry date.
- Keep the canonical control status unchanged so an exception cannot make the underlying requirement appear satisfied.
- Trigger review at 60, 30, and 7 days before expiry and escalate the 18 audit-window expirations to owners immediately.
- Report exception age, renewal count, exposure by framework, and compensating-control test results each month.
Why interviewers ask this: The interviewer is checking whether exceptions remain visible, bounded, and separate from canonical control effectiveness.
I would run the library as a governed product with service levels, release trains, and an auditable decision backlog.
- Intake every request through a Control Change Request containing impact, mappings, owner, urgency, and proposed effective date.
- Let data stewards triage within 3 business days and hold a weekly change board for material wording, ownership, or test changes.
- Publish one monthly library release with notes, affected-control list, migration instructions, and a 30-day adoption window.
- Track backlog age, approval lead time, emergency-change rate, mapping defects, and adoption completion by all 8 owners.
Why interviewers ask this: The interviewer is evaluating whether the candidate can operate a control library with predictable governance rather than ad hoc edits.
I would designate one control system of record and keep the other platforms as purpose-specific execution layers connected by stable IDs.
- Select ServiceNow GRC as the canonical control and risk master, with AuditBoard owning audit engagements and Drata owning automated SOC 2 evidence collection.
- Synchronize control ID, owner, scope, and status outward, while returning test results, findings, and evidence links to the master.
- Prohibit bidirectional edits to canonical fields and reconcile all 3 platforms nightly with an exception queue.
- Approve the design only if it removes 2 duplicate masters, cuts annual spend by at least $180,000, and preserves 7-year audit history.
Why interviewers ask this: A strong answer assigns clear system boundaries and quantifies the economic and record-retention outcomes.
I would use source-specific connectors behind a common evidence contract and make every collection run observable and replayable.
- Define an evidence envelope with source, control ID, query or report version, population window, collected-at time, checksum, and service identity.
- Use read-only service accounts, incremental pulls where supported, and a durable queue that retries transient failures without duplicating evidence.
- Store raw payloads immutably, transform only into linked evidence records, and retain connector logs for 18 months.
- Set a 24-hour freshness SLO, alert at 20 hours, and require at least 98 percent successful daily collections across all 12 types.
Why interviewers ask this: The interviewer is testing evidence automation as governed data movement rather than a collection of opaque connectors.
I would make lineage a first-class chain from source extraction through transformation, approval, control, and audit use.
- Assign each evidence object an immutable ID and capture source system, source record or query, collector version, timestamp, checksum, and reporting period.
- Record every transformation as a new version linked to its parent rather than overwriting the original payload.
- Link reviewer identity, approval time, applicable control version, test procedure, and audit request to the final object.
- Backfill the 65 records within 15 business days and require a quarterly replay test on a sample of 20 objects.
Why interviewers ask this: A strong answer provides enough lineage to reproduce evidence and prove which version supported an audit conclusion.
I would replace the uploaded-file percentage with a quality-adjusted completeness measure at the request level.
- Mark a request complete only when evidence exists, covers the required population and period, is fresh, has lineage, and passed reviewer acceptance.
- Reclassify all 420 invalid records as incomplete and separate missing, stale, wrong-period, and rejected categories.
- Weight key controls and auditor PBC items more heavily, while showing both weighted and unweighted completion.
- Publish a daily burn-down with owner, due date, blocker, and a fieldwork gate of 98 percent accepted evidence plus zero missing key controls.
Why interviewers ask this: The interviewer is evaluating whether completeness reflects usable audit evidence rather than attachment volume.
I would separate authoring, operation, testing, approval, and issue closure into roles that cannot approve their own work.
- Create distinct Control Author, Control Owner, Tester, Evidence Reviewer, Issue Owner, and Issue Approver roles with a deny matrix.
- Remove conflicting access from the 26 users, allowing temporary exceptions only through a ticket approved by accountable management or the designated risk owner under access-control policy and expiring within 7 days.
- Give Internal Audit read-only access to configurations and logs plus test-execution rights that cannot change access or approve exceptions, and enforce identity checks before state transitions.
- Finish with a quarterly access certification and a target of zero toxic combinations in the 45-day recertification report.
Why interviewers ask this: A strong answer translates segregation of duties into enforceable platform roles, workflow checks, and periodic certification.
I would tier evidence tasks by audit criticality and start the SLA only when the request is complete and assigned.
- Set 3 business days for key-control PBC items, 5 for standard audit evidence, and 10 for advisory requests.
- Require request templates to include control, period, population, format, approver, and acceptance criteria before the clock starts.
- Escalate at 60 and 85 percent of SLA to the owner and manager, then at breach to the audit sponsor.
- Review weekly aging, first-pass acceptance, reassignment rate, and breaches, targeting fewer than 55 breaches within 2 quarters.
Why interviewers ask this: The interviewer is checking whether workflow SLAs are fair, enforceable, and linked to audit priority and quality.
I would build an explainable control-level score using leading indicators that owners can remediate before fieldwork.
- Score evidence freshness and completeness at 30 percent, recent test failures at 25, overdue issues at 20, owner responsiveness at 15, and prior findings at 10.
- Train thresholds on the 38 findings, but keep a rules-based model until at least 100 labeled outcomes exist.
- Publish high, medium, and low bands with the contributing factors and assign remediation plans to the top 40 controls.
- Back-test quarterly for precision, missed findings, and framework bias, with Internal Audit approving every weight change.
Why interviewers ask this: A strong answer favors an explainable and governable early-warning model over unjustified predictive complexity.
I would migrate governed records in rehearsed waves and prove referential integrity before each cutover.
- Define a source-to-target mapping for controls, mappings, owners, tests, evidence metadata, issues, approvals, and immutable IDs.
- Clean duplicates and orphaned records first, then run 2 full dry migrations in a masked environment.
- Reconcile record counts, checksums, relationships, and a sample of 100 audit trails after every rehearsal.
- Freeze source changes for 48 hours, perform final delta load, obtain Internal Audit sign-off, and retain read-only access for 12 months.
Why interviewers ask this: The interviewer is evaluating controlled GRC data migration, reconciliation, and preservation of audit history.
I would drive retention from an evidence classification schedule rather than use one platform-wide deletion period.
- Classify by framework, record type, jurisdiction, audit period, contract, and minimum retention, resolving overlaps to the longest applicable term.
- Keep metadata and lineage after payload disposal where permitted, while recording deletion time, policy version, and executor.
- Let Legal place object-level or matter-level holds that suspend deletion without altering the original retention rule.
- Run monthly disposition jobs, quarterly hold reconciliation, and an annual sample of 200 objects to verify correct retention.
Why interviewers ask this: A strong answer balances differing retention duties with defensible deletion and legal-hold controls.
I would classify mismatches, stop unsafe overwrites, and reconcile from the authoritative system for each field.
- Split the 760 cases into missing records, stale values, broken links, duplicate IDs, and timing differences.
- Publish a field-level ownership matrix showing which platform masters control, owner, test result, finding, and audit status.
- Quarantine conflicting updates, replay idempotently from the last good checkpoint, and require steward approval for ambiguous records.
- Exit the 30-day plan at fewer than 0.1 percent mismatches, zero orphaned key controls, and 7 consecutive clean nightly runs.
Why interviewers ask this: The interviewer is testing data reconciliation, system-of-record discipline, and measurable recovery criteria.
Locked questions
- 21
A global company with $4 billion revenue and 11 business units needs a technology-risk program in 6 months; what operating model and artifacts would you establish first?
risk-managementartifacts - 22
The board approved a maximum $25 million annual technology-loss appetite, but business units submit risks using 5 different scales; how would you translate appetite into tolerances?
- 23
The CFO requests a 3-year scenario analysis for a cloud concentration event affecting 40 percent of revenue and 18 critical services; how would you quantify it?
cloud-security - 24
Eleven units report 640 risks, including 170 duplicates and correlated exposures to 3 shared platforms; how would you aggregate them for enterprise reporting?
aggregation - 25
A dashboard has 74 KRIs, 38 percent never trigger and executives read only 6; how would you redesign the KRI set in one quarter?
- 26
There are 93 accepted technology risks, 41 have no expiry, and 16 exceed approved tolerance; what governance would you implement within 60 days?
governance - 27
A regulator requests the top 15 technology risks, loss estimates, control status, and remediation evidence within 10 business days; how would you produce a defensible submission?
estimation - 28
The audit committee has 20 minutes quarterly and currently receives a 48-page technology-risk pack; how would you redesign the artifact for 6 meetings?
risk-managementartifacts - 29
A $12 million transformation program has 27 high technology risks and only $1.5 million remediation budget; how would you prioritize funding over 2 planning cycles?
prioritization - 30
A risk taxonomy change would reclassify 310 of 900 records 2 months before year-end reporting; how would you govern the change and preserve trend comparability?
risk-managementrisk-taxonomy - 31
A company must tier 2,400 active vendors in 90 days, but only 18 analysts are available; what TPRM model would you implement?
procurementthird-party-risk - 32
Among 1,800 vendors, 62 critical services depend on 4 cloud and payment providers; how would you measure and govern concentration risk?
cloud-securityrisk-managementprocurement - 33
A Tier 1 vendor uses 35 subcontractors, but names only 9 in its contract schedule; what fourth-party process would you require before a 3-year renewal?
procurementconcurrency - 34
Procurement plans 600 renewals in 2 quarters, and 140 contracts lack audit rights, 24-hour incident notice, or data-return clauses; how would you remediate contractual controls?
procurementincidents - 35
A continuous-monitoring platform generates 9,000 vendor alerts per month for 1,200 vendors, but only 3 percent lead to action; how would you redesign triage?
monitoringalertingvendor-monitoring - 36
A vendor-risk council reviews 55 open Tier 1 issues monthly but closes only 4; what charter and decision process would you introduce?
procurementconcurrencyrisk-management - 37
A business wants to onboard a critical payroll vendor in 21 days, while the standard Tier 1 review takes 45 days and has found 6 material gaps; how would you handle the exception?
procurementonboardingerror-handling - 38
An acquisition target relies on 780 vendors, has no tiering, and must close in 30 days; what TPRM diligence would you perform with a $200,000 budget?
procurementthird-party-risk - 39
After an acquisition, 320 new vendors must enter a 2,100-vendor TPRM program in 120 days without adding headcount; how would you integrate them?
procurementthird-party-risk - 40
A portfolio of 3,000 vendors has 310 overdue reviews and 85 unknown business owners; what recovery plan would you execute over 2 quarters?
procurementrecovery - 41
You must deliver SOC 2 Type II, ISO 27001 surveillance, and PCI DSS 4.0.1 assessments in the same 8-month window across 430 controls; what audit roadmap would you build?
governancecompliancesoc-operations - 42
A FedRAMP Moderate authorization must reach an Authorizing Official decision in 14 months with a $2.4 million budget and 323 baseline controls; what artifact-driven roadmap would you propose?
authidentity-accessfedramp - 43
An audit firm proposes a $780,000 SOW for 4 audits, 6,200 testing hours, and overlapping samples; how would you negotiate scope and budget without weakening assurance?
testing - 44
Internal Audit tested 180 controls 4 months before the external SOC 2 and ISO 27001 audits; how would you design reliance on that work?
governancecompliancesoc-operations - 45
A PCI DSS 4.0.1 assessor and ISO 27001 auditor disagree on evidence sufficiency for 22 shared controls 5 weeks before fieldwork; how would you resolve it?
governancepci-dssconflict - 46
A regulator requires quarterly reporting on 12 remediation commitments for 18 months; what reporting control would you establish?
- 47
A NIST 800-53 Moderate assessment has 74 open POA&M items, 19 over 180 days, and a system launch in 12 weeks; how would you govern readiness?
poamsystem-designhealth-checks - 48
A 3PAO requests implementation statements for 323 baseline controls, but 96 reuse vague policy language and 48 omit responsibility or frequency; how would you raise SSP quality in 8 weeks?
policy-management - 49
A team of 26 control owners must support SOC 2, ISO 27001, PCI DSS, and FedRAMP over 24 months, but the draft calendar overlaps fieldwork for 14 weeks and demands 1,900 owner hours in one quarter; how would you sequence the work?
governancecompliancesoc-operations - 50
Two audit firms cover the same 260 controls, but one permits reliance on Internal Audit and the other refuses; how would you decide the 3-year firm strategy before $2.1 million of renewals?
- 51
Three weeks before a SOC 2 Type II audit, HR confirms that the employee population used for 12 quarterly access reviews omitted 186 of 2,940 workers; do you defend the tests, retest, or disclose an exception?
compliancesoc-operationssoc-2 - 52
A change-management control has deviated in 7 of the last 8 monthly samples, yet Engineering calls each miss immaterial because only 9 of 320 changes lacked approval; what decision do you make?
- 53
An ISO 27001 auditor selects 25 joiners from a list of 410, but 6 records belong to contractors outside the certified HR process; do you accept a qualified sample, replace the records, or challenge the request?
governanceconcurrency - 54
Sales promised that a new EU analytics product would be covered by the current ISO 27001 certificate, but the scope statement names only 4 US services and the launch is in 45 days; do you expand scope, delay the claim, or accept the conflict?
cryptographygovernancepromises - 55
Two days before audit submission, you learn that 38 of 214 screenshots were recreated after the quarter ended and their original capture dates are unavailable; do you submit, withdraw, or reconstruct the evidence set?
- 56
The external auditor says a quarterly privileged-access review failed because approval occurred 11 days after quarter-end, while your policy allows 15 days and 24 of 24 accounts were reviewed; do you concede the finding or dispute it?
policy-management - 57
Six days before SOC 2 fieldwork closes, the audit firm's portal exposes 240 evidence files, including payroll and customer data, to another client for 11 hours; do you continue, suspend, or replace the firm?
compliancesoc-operationssoc-2 - 58
Management refuses to sign a representation letter because 3 of 67 control owners will not attest to completeness, and the SOC 2 report date is 9 days away; do you escalate, narrow scope, or proceed?
compliancesoc-operationssoc-2 - 59
Four days before a SOC 2 report is due, the audit firm discloses that the manager who approved 38 of 110 workpapers began employment talks with your company during fieldwork and joined as GRC director 6 weeks ago; do you issue, require re-performance, or replace the firm?
compliancesoc-operationssoc-2 - 60
An auditor proposes a major nonconformity after finding 4 overdue corrective actions among 92 ISO 27001 actions, while you believe only 1 affects a systemic process; do you accept the grade or seek reclassification?
governancesystem-designconcurrency - 61
The approved risk appetite permits no more than $2 million residual loss for a single scenario, but a product VP wants to accept an $8.5 million exposure for 6 months to protect $14 million in revenue; what decision do you make?
risk-managementrisk-appetite - 62
Eleven high risks are overdue by an average of 143 days, 4 exceed the board appetite, and owners have moved target dates 3 times; do you extend them again, force treatment, or escalate?
escalation - 63
A board risk dashboard has stayed green for 4 quarters, but internal audit found 17 failed tests across 6 key controls and expected loss rose from $3.2 million to $7.9 million; do you change the board rating now?
risk-managementtesting - 64
Five individually moderate control failures affect the same customer-data process, and the combined scenario could expose 4.8 million records; do you keep 5 moderate issues or aggregate them into a high risk?
aggregationconcurrencyrisk-management - 65
Your risk model labels 62% of 340 technology risks as high, but only 8% produced losses or material control failures in 24 months; do you recalibrate thresholds or preserve comparability?
risk-management - 66
A regulator commitment requires 95% of critical controls to pass by September 30, but the July result is 81% across 74 controls and 9 remediations lack funding; do you revise the commitment or escalate delivery?
escalation - 67
A business unit requests a fourth 90-day exception for encryption at rest covering 1.6 million customer records, while migration is 70% complete; do you renew, shorten, or reject it?
encryptioncryptographyrest - 68
The accountable owner for a $5.4 million residual risk refuses to sign because Security designed the control and says the CISO should own the exposure; with 12 days before launch, who owns the decision?
risk-managementdesign - 69
A remediation program reports that residual risk fell 48%, but 13 of 20 controls have never been tested and the estimate uses owner confidence scores; do you accept the reduction for the quarterly report?
estimationrisk-management - 70
Three business units each accept a $1.8 million vendor outage risk within their $2 million authority, but all depend on the same cloud region and combined exposure is $9.7 million; do the acceptances stand?
cloud-securityrisk-managementprocurement - 71
A critical payroll vendor reports a breach affecting 22,000 employees, cannot confirm deletion of copied tax data, and payroll runs in 4 days; do you suspend service, continue, or invoke the exit plan?
procurement - 72
Seven tier-1 vendors representing 68% of customer transactions rely on the same identity provider, and its last outage lasted 11 hours; do you accept the concentration or mandate diversification?
procurementtransactions - 73
A data processor handling 9 million records has no SOC 2 report covering the latest 5 months because the prior report's coverage period ended, and it offers only a 2-page security letter before renewal in 18 days; do you renew?
compliancesoc-operationssoc-2 - 74
A $4.2 million annual SaaS contract renews in 21 days, but 6 of 14 high-risk findings remain open and the vendor requests a 3-year term for a 12% discount; what do you negotiate?
procurementcloudrisk-management - 75
A tier-1 claims vendor discloses that 3 fourth parties process 74% of your customer records, but only 1 appears in the contract and none has supplied assurance; do you pause onboarding or accept the vendor's attestation?
procurementonboardingconcurrency - 76
An acquisition target worth $180 million has 14 unresolved issues rated high, no ISO certificate, and only 10 business days of exclusivity remaining; do you recommend proceeding, repricing, or delaying?
cryptography - 77
SecurityScorecard rates a key vendor 62 out of 100 while its clean SOC 2 Type II covers 118 controls and reports 0 exceptions; do you escalate, override the score, or accept both?
compliancesoc-operationssoc-2 - 78
A vendor proposes moving 3.6 million EU records from Frankfurt to a US subprocessor in 30 days, reducing fees by 18%; do you approve the change?
procurement - 79
A payment vendor missed its 2-hour recovery objective in 3 of 4 tests, taking 5.5 hours on average, but business owners oppose replacement because it processes $26 million monthly; do you accept the failure?
procurementconcurrencytesting - 80
A critical CRM vendor announces end of service in 9 months, holds 12 terabytes of customer data, and your last export test recovered only 83%; do you renew support or trigger exit now?
procurement - 81
A Drata API token expired 47 days ago, so 29 controls still appear green using cached AWS and Okta evidence; do you preserve the dashboard, mark controls failed, or roll back automation?
tokensapicaching - 82
A NIST 800-53 revision changed 63 mappings, but Hyperproof still maps the old controls to FedRAMP and ISO 27001 for 4 months; do you freeze reporting or correct mappings in place?
governance - 83
A GRC platform release allowed 46 control owners to edit approved test criteria, and 19 changed pass conditions after failed tests, altering the criteria displayed on 73 historical workpapers; with fieldwork in 3 weeks, how do you recover?
testing - 84
A GRC team reports 98% on-time remediation, but analysts closed 44 of 510 actions as 'risk accepted' one day before SLA expiry and 31 lack authorized signatures; do you publish the metric?
risk-managementmonitoring - 85
ServiceNow GRC has 1,280 pending attestations, 420 are over 60 days old, and 3 analysts can clear only 45 per week; do you add staff, cancel records, or redesign the workflow?
- 86
An automated access-review workflow auto-closed 312 of 480 decisions after a faulty manager hierarchy import, and 27 involved privileged access; do you roll back all automation or repair forward?
identity-accessrollback - 87
Twelve days before fieldwork, a GRC evidence connector replay overwrites 1,260 approved records across 84 controls with current snapshots and removes their original as-of lineage; do you restore, recollect, or keep the replayed evidence?
lineagesnapshot - 88
During migration from Archer to AuditBoard, 9,600 of 10,000 records moved, but 240 evidence links and 160 issue histories are missing with an audit in 28 days; do you cut over or revert?
migrations - 89
The control library lists 73 controls owned by 11 employees who left more than 90 days ago, including 8 key controls for the upcoming audit; do you reassign centrally or suspend the controls?
- 90
The board dashboard reports 91% mature controls, 186 of 204 in the legacy scope, while AuditBoard reports 78%, the same 186 mature controls out of all 240 after 36 newly scoped controls were added; which number do you brief in 3 days?
- 91
A $465,000 audit SOW limits the report to management use, denies regulators access to workpapers, and allows evidence destruction after 12 months, while customer contracts require report sharing and 7-year assurance retention; do you sign before the audit slot expires in 4 days?
retention - 92
A proposed audit SOW allows the firm to expand samples by up to 100% without approval and bills all rework hourly, while your budget has only 8% contingency; do you sign it?
- 93
The company has 14 months and $3.6 million for compliance, but Sales wants FedRAMP Moderate, PCI DSS 4.0.1, ISO 27001, and SOC 2 completed together; which roadmap do you approve?
governancecompliancesoc-operations - 94
Your internal PCI DSS gap plan has 31 remediation items due before a March 31 assessment deadline, while an ISO 27001 surveillance audit 6 weeks earlier needs the same 9 engineers for 420 hours; which work do you defer?
estimationgovernance - 95
A customer asks to rely on your SOC 2 report for 85 controls, but 17 are carved out to a cloud provider and the ISO audit tests only 9 of those; do you claim full coverage or commission extra work?
compliancecloud-securitysoc-operations - 96
A regulator gives 15 business days to explain why 23 of 140 required access reviews were late and asks whether the issue is systemic; do you argue immateriality or admit a program failure?
system-design - 97
The audit committee meets in 48 hours after 6 key-control failures raised audit pre-fail risk from 18% to 46%, while management expects 4 fixes within 30 days; what decision do you ask from the committee?
risk-management - 98
A senior analyst has produced 5 audit packages with a 22% QA rejection rate, mainly from weak population evidence, and fieldwork begins in 8 weeks; how do you mentor them while protecting delivery?
mentoring - 99
Legal, Engineering, Procurement, and GRC have left 37 vendor findings unowned for 75 days because each team says another function controls the contract or fix; what ownership decision do you make?
procurementownership - 100
Five days before the audit committee reviews Internal Audit's annual assurance opinion, General Counsel directs 4 control owners to withhold 31 Slack messages as privileged, while the Chief Audit Executive says the omission creates a management-imposed scope limitation; who owns the decision and do you let the opinion proceed?