WGU D486 GOVERNANCE RISK AND
COMPLIANCE CERTIFICATION SCRIPT 2026
QUESTIONS WITH SOLUTIONS GRADED A+
◍ 3.3 ISO 26000 standards provide guidance on how businesses and other
organizations can be socially responsible..
Answer: True
◍ 3.3 Only the board of directors and management are responsible for the
success of corporate social responsibility (CSR) initiatives..
Answer: False - all employees are responsible
◍ Risk.
Answer: A measure of the extent to which an entity is threatened by a
potential circumstance or event. It is typically a function of: (i) the adverse
impacts that would arise if the circumstance or event occurs; and (ii) the
likelihood of occurrence. Source: FIPS PUB 200; NIST SP 800-37, Rev. 1
◍ 3.2 The design and implementation of governance processes are the
responsibility of internal audit..
Answer: False - The design and implementation of governance processes are
the responsibility of the board. Internal audit's responsibility is to assess
these processes and help the board improve them.
◍ 3.2 When control issues are known or the governance process is not mature,
the CAE may consider different methods for improving control or
governance through consulting services..
Answer: True
◍ Senior management establishes.
Answer: reporting requirements for risk owners related to their risk
management activities.
,◍ The following are four alternative CSR strategies:.
Answer: 1. Reaction. The organization denies responsibility and tries to
maintain the status quo.2. Defense. The organization uses legal action or
public relations efforts to avoid additional responsibilities.3.
Accommodation. The organization assumes additional responsibilities only
when pressured.4. Proaction. The organization takes the initiative in
implementing a CSR program that serves as an example for the industry.
◍ 3.1 Governance practices ensure that the organization complies with
society's legal and regulatory rules and satisfies the generally accepted
business norms..
Answer: True
◍ Regulations.
Answer: Rules enforced by a regulatory body or authority.
◍ Stakeholders are.
Answer: persons or entities who are affected by the activities of the entity.
Among others, these include shareholders, employees, suppliers, customers,
neighbors of the entity's facilities, and government regulators.
◍ 3.1 Ensuring effective organizational performance management and
accountability is more directly the proper function of A. ControlB.
Governance C. Risk ManagementD. A quality assurance program.
Answer: B. Governance The process responsible for ensuring effective org
performance management and accountability
◍ 3.1 Governance has three major components: the business model, the
strategic direction, and oversight..
Answer: False - strategic direction and oversight.
◍ Governance is defined as.
Answer: "[t]he combination of processes and structures implemented by the
board to inform, direct, manage, and monitor the activities of the
organization toward the achievement of its objectives."
, ◍ Which of the following actions could be construed as a violation of The
IIA's Code of Ethics?A. Expressing an opinion on internal financial
statements.B. Turning a case over to the security department when an
internal auditor suspects fraud but has no proof.C. Failing to report to
management information that would be material to management's
judgment.D. Including an internal control problem in a final engagement
communication when it has been corrected prior to completion of the
engagement..
Answer: C. Failing to report to management information that would be
material to management's judgment.
◍ Risk Treatment.
Answer: The determination of the best way to address an identified risk.
◍ Legacy IT Systems.
Answer: IT systems that have been in use for an extended time period. A
computer system, hardware, or related business process that is outdated and
not supported by a vendor but is still in use.
https://blog.morphisec.com/cyber-security-glossary
◍ Implementation Standard 2110.A2.
Answer: The internal audit activity must assess whether the information
technology governance of the organization supports the organization's
strategies and objectives.
◍ Adequate Controls.
Answer: Safeguards and countermeasures commensurate with the level of
risk.
◍ Management performs.
Answer: day-to-day governance functions. Senior management carries out
board directives (within specified tolerances for unacceptable outcomes) to
achieve objectives.
◍ Performance Standard 2110GovernanceThe internal audit activity must
assess and make appropriate recommendations to improve the organization's
COMPLIANCE CERTIFICATION SCRIPT 2026
QUESTIONS WITH SOLUTIONS GRADED A+
◍ 3.3 ISO 26000 standards provide guidance on how businesses and other
organizations can be socially responsible..
Answer: True
◍ 3.3 Only the board of directors and management are responsible for the
success of corporate social responsibility (CSR) initiatives..
Answer: False - all employees are responsible
◍ Risk.
Answer: A measure of the extent to which an entity is threatened by a
potential circumstance or event. It is typically a function of: (i) the adverse
impacts that would arise if the circumstance or event occurs; and (ii) the
likelihood of occurrence. Source: FIPS PUB 200; NIST SP 800-37, Rev. 1
◍ 3.2 The design and implementation of governance processes are the
responsibility of internal audit..
Answer: False - The design and implementation of governance processes are
the responsibility of the board. Internal audit's responsibility is to assess
these processes and help the board improve them.
◍ 3.2 When control issues are known or the governance process is not mature,
the CAE may consider different methods for improving control or
governance through consulting services..
Answer: True
◍ Senior management establishes.
Answer: reporting requirements for risk owners related to their risk
management activities.
,◍ The following are four alternative CSR strategies:.
Answer: 1. Reaction. The organization denies responsibility and tries to
maintain the status quo.2. Defense. The organization uses legal action or
public relations efforts to avoid additional responsibilities.3.
Accommodation. The organization assumes additional responsibilities only
when pressured.4. Proaction. The organization takes the initiative in
implementing a CSR program that serves as an example for the industry.
◍ 3.1 Governance practices ensure that the organization complies with
society's legal and regulatory rules and satisfies the generally accepted
business norms..
Answer: True
◍ Regulations.
Answer: Rules enforced by a regulatory body or authority.
◍ Stakeholders are.
Answer: persons or entities who are affected by the activities of the entity.
Among others, these include shareholders, employees, suppliers, customers,
neighbors of the entity's facilities, and government regulators.
◍ 3.1 Ensuring effective organizational performance management and
accountability is more directly the proper function of A. ControlB.
Governance C. Risk ManagementD. A quality assurance program.
Answer: B. Governance The process responsible for ensuring effective org
performance management and accountability
◍ 3.1 Governance has three major components: the business model, the
strategic direction, and oversight..
Answer: False - strategic direction and oversight.
◍ Governance is defined as.
Answer: "[t]he combination of processes and structures implemented by the
board to inform, direct, manage, and monitor the activities of the
organization toward the achievement of its objectives."
, ◍ Which of the following actions could be construed as a violation of The
IIA's Code of Ethics?A. Expressing an opinion on internal financial
statements.B. Turning a case over to the security department when an
internal auditor suspects fraud but has no proof.C. Failing to report to
management information that would be material to management's
judgment.D. Including an internal control problem in a final engagement
communication when it has been corrected prior to completion of the
engagement..
Answer: C. Failing to report to management information that would be
material to management's judgment.
◍ Risk Treatment.
Answer: The determination of the best way to address an identified risk.
◍ Legacy IT Systems.
Answer: IT systems that have been in use for an extended time period. A
computer system, hardware, or related business process that is outdated and
not supported by a vendor but is still in use.
https://blog.morphisec.com/cyber-security-glossary
◍ Implementation Standard 2110.A2.
Answer: The internal audit activity must assess whether the information
technology governance of the organization supports the organization's
strategies and objectives.
◍ Adequate Controls.
Answer: Safeguards and countermeasures commensurate with the level of
risk.
◍ Management performs.
Answer: day-to-day governance functions. Senior management carries out
board directives (within specified tolerances for unacceptable outcomes) to
achieve objectives.
◍ Performance Standard 2110GovernanceThe internal audit activity must
assess and make appropriate recommendations to improve the organization's