HomeBusiness AnalysisIIBA-CCAPractice questionsCompliance and Governance
IIBA-CCA · IIBA · Compliance and Governance · Bank updated 2026-07-02

IIBA-CCA practice questions: Compliance and Governance

5 free questions from 75 on this area · answer and explanation for each · no sign-up

These 5 questions come from the Compliance and Governance section of our IIBA-CCA bank (75 questions on this area). Every question is original, with the correct answer explained and linked to the source it is drawn from.

Start 6 free in study mode → All IIBA-CCA sample questions
1/5 · Compliance and Governance
While documenting an organization's security control library, a business analyst encounters four document types: policies, standards, procedures, and guidelines. Which description correctly characterizes a 'standard' within this hierarchy?
AA recommended but optional best practice that teams may adapt to their context.
BA mandatory, specific rule that defines a uniform technical or operational requirement supporting a policy, such as a required minimum password length.
CA high-level statement of management intent and direction that rarely changes.
DA step-by-step set of instructions describing how to perform a specific task.
Show answer & explanation
B is correct. In the governance document hierarchy: policies state management intent (mandatory, high-level), standards specify mandatory uniform requirements that support policies, procedures give step-by-step task instructions, and guidelines are optional recommended practices. Distinguishing these helps the BA classify and trace security requirements correctly.
↗ IIBA-CCA body of knowledge — Compliance and Governance
2/5 · Compliance and Governance
While analyzing a change-management process for a regulated financial application, a BA notices that the same engineer who writes a production code change can also approve it and deploy it to production unsupervised. From a compliance and governance standpoint, what concern should the BA raise first?
AA capacity concern, because one engineer cannot handle the full workload
BA licensing concern, because the deployment tool may require separate seats
CA documentation concern, because the deployment steps may not be written down
DA segregation-of-duties violation, because no single individual should be able to author, approve, and deploy a change without independent oversight
Show answer & explanation
D is correct. Segregation of duties prevents any one person from controlling all phases of a sensitive transaction. Letting one engineer author, approve, and deploy unsupervised removes the independent check that detects errors or malicious changes, a key compliance control in regulated environments.
↗ IIBA-CCA body of knowledge — Compliance and Governance
3/5 · Compliance and Governance
A government client mandates that all of its citizens' personal data must be stored and processed only on infrastructure physically located within the client's own country. The business analyst is translating this mandate into a non-functional requirement for the cloud architecture team. Which concept does this mandate most directly express?
AA data minimization requirement limiting how many attributes are collected
BA data classification requirement assigning sensitivity labels
CA records retention requirement defining how long data is kept
DA data residency / sovereignty requirement constraining the geographic location of storage and processing
Show answer & explanation
D is correct. A mandate that fixes the physical or jurisdictional location of storage and processing is a data residency and sovereignty requirement. The BA must capture it as a geographic constraint that shapes region selection, replication, and vendor architecture, distinct from minimization, classification, or retention, which address other dimensions of data governance.
↗ IIBA-CCA body of knowledge — Compliance and Governance
4/5 · Compliance and Governance · hard
After a confirmed data breach affecting personal data, a business analyst is mapping the incident-response process against regulatory obligations. The regulation requires notifying the supervisory authority within a strict deadline and, where the breach poses high risk, also informing the affected individuals. Several teams dispute who must act. What should the BA build into the process to satisfy the obligation reliably?
AA standing instruction to wait until the next scheduled audit to disclose any breaches in a consolidated report.
BA policy delegating all breach decisions to the external cloud provider, since the data was hosted on its infrastructure.
CA rule that notification is only required if the organization concludes the breach caused actual financial loss to individuals.
DDefined notification triggers, deadlines, and assigned accountable roles for notifying the supervisory authority and, when high risk, the affected individuals, with an escalation path to meet the regulatory clock.
Show answer & explanation
D is correct. Reliable breach-notification compliance requires the process to define what triggers a notification, the regulatory deadlines, the accountable roles for notifying the supervisory authority and (for high-risk breaches) affected individuals, and an escalation path to beat the clock. Conditioning notice on proven financial loss, deferring to an audit cycle, or delegating to a host all fail the obligation.
↗ IIBA-CCA body of knowledge — Compliance and Governance
5/5 · Compliance and Governance
A compliance steering committee states that the organization is willing to accept 'low' overall cybersecurity risk, but for a specific new payment feature it will tolerate deviation only within a narrowly defined range before requiring escalation. Which term best describes this narrowly defined acceptable range of deviation for the specific initiative?
ARisk appetite
BRisk tolerance
CInherent risk
DResidual risk
Show answer & explanation
B is correct. Risk appetite sets the overall, strategic amount of risk an organization is willing to pursue, while risk tolerance defines the specific, measurable acceptable variation around that appetite for a particular objective or initiative. A BA capturing compliance requirements must elicit both concepts precisely, since they drive different escalation thresholds.
↗ IIBA-CCA body of knowledge — Compliance and Governance
Practise all 75 Compliance and Governance questions - start free → See the whole IIBA-CCA bank

Other IIBA-CCA areas

The same kind of free sample for every other section of the IIBA-CCA bank:

Cybersecurity Foundations77 qCybersecurity Risk Management75 qBusiness Analysis Practices in Cybersecurity76 q

Study Compliance and Governance with instant feedback

6 free questions · filter study mode by area and difficulty · error log with spaced repetition · no card, no dumps, no ads.

Create your free account →
Read next
ECBA vs CCBA vs CBAP: Which IIBA Certification Fits Your Experience Level? (2026) ECBA, CCBA or CBAP? The eligibility gate that picks for you, what the 2026 ECBA rewrite changed, and each credential's three-year cost, verified against IIBA. PMI-PBA vs CBAP: The Business Analysis Certification Decision, Settled with Data PMI-PBA ($405-555, 36 months of experience) vs CBAP ($495-650 all-in, 7,500 hours plus references): eligibility, exam mechanics, three-year cost, salary data.
ExamDeck is an independent study tool, not affiliated with IIBA®. IIBA-CCA and BABOK® are trademarks of the International Institute of Business Analysis. Exam facts checked against official IIBA materials (as of August 2026); confirm current details on iiba.org.