Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
The two kinds of PROACTIVE controls are
Proactive controls are those measures implemented to prevent undesirable events before they occur. Promoting controls are designed to encourage desired behaviors and outcomes, such as compliance with policies and procedures. Preventive controls are aimed at stopping undesirable events or actions before they happen, such as implementing security measures to prevent unauthorized access. Both types of controls are essential for effective risk management and ensuring the security and integrity of an organization's processes and systems. Reference:
COSO Internal Control -- Integrated Framework
ISO/IEC 27002:2013 - Information technology - Security techniques - Code of practice for information security controls
If follow-up discovers that actions and controls haven't been implemented, immediately escalate to the board
If follow-up discovers that actions and controls haven't been implemented, it is important to use professional judgment and work with the action owner to understand why the plans have not been implemented. Immediate escalation to the board without understanding the context may not be the most effective approach. Engaging with the action owner can help identify obstacles and facilitate a constructive resolution. Escalation should be considered if there is a significant risk or if there is consistent non-compliance despite reasonable efforts to address the issue. Reference:
ISO 19011:2018 - Guidelines for auditing management systems
IIA Standards for the Professional Practice of Internal Auditing
The key steps in the Assessment Process are
The key steps in the Assessment Process are Plan, Perform, Report, and Follow-Up. These steps provide a structured approach to conducting assessments, ensuring thorough evaluation and continuous improvement:
Plan: Define the scope, objectives, and methodology.
Perform: Execute the assessment according to the plan.
Report: Document findings and provide recommendations.
Follow-Up: Monitor the implementation of recommendations and improvements.
These steps help ensure assessments are systematic, objective, and effective in identifying areas for improvement. Reference:
ISO 19011:2018 - Guidelines for auditing management systems
COSO Internal Control -- Integrated Framework
Which of the following is defined as "a measure of the degree to which obligations and requirements are addressed"
Compliance is defined as a measure of the degree to which obligations and requirements are addressed. It involves adhering to laws, regulations, policies, and standards that are relevant to the organization. Compliance ensures that the organization meets its legal and ethical obligations, thereby avoiding legal penalties, reputational damage, and operational disruptions. Effective compliance programs involve continuous monitoring, training, and auditing to ensure all requirements are met and maintained. Reference:
ISO 19600:2014 - Compliance management systems - Guidelines
NIST SP 800-37 Rev. 2 - Risk Management Framework for Information Systems and Organizations
The key steps in the Assurance Process are
The key steps in the Assurance Process are Plan, Perform, Report, and Follow-Up. This structured approach ensures that assurance activities are conducted methodically and effectively:
Plan: Define the objectives, scope, and methodology of the assurance activity.
Perform: Carry out the assurance activity based on the defined plan.
Report: Document and communicate findings, conclusions, and recommendations.
Follow-Up: Verify that recommendations are implemented and assess their effectiveness.
These steps help ensure that assurance activities provide valuable insights and drive improvements within the organization. Reference:
IIA Standards for the Professional Practice of Internal Auditing
COSO Internal Control -- Integrated Framework
45 questions covering all exam domains, starting from $20
Exam domains verified against: Official OCEG GRCA exam guide, last checked September 2026.
Start with definitions and key GRC terminology so you can recognize concepts across real audits. Then learn why organizations adopt integrated GRC approaches and how they connect to governance, strategy, risk, compliance, ethics, and audit disciplines.
This is the core of the GRCA exam. Study the models and methodologies used in audit and assurance work. Focus on how to plan assessments, what steps you take when performing them, and how to design meaningful reports with follow-up actions.
Understand the content and structure of the GRC Assessment Framework (the Burgundy Book). Learn to apply it in different assessment contexts and know how the framework components guide your audit scope and approach.
Common questions about the exam itself