CRISC Certified in Risk and Information Systems ControlGovernanceHard

A global technology company is establishing a new subsidiary in a country with complex and frequently changing cybersecurity laws. The parent company's existing policies are robust but may not fully address the nuances of the local regulations. Which of the following roles is PRIMARILY responsible for ensuring the subsidiary's operations comply with these local legal and regulatory requirements?

  1. AChief Information Officer (CIO) of the parent company.
  2. BThe newly appointed local Chief Executive Officer (CEO) of the subsidiary.
  3. CThe Legal Department of the parent company.
  4. DChief Risk Officer (CRO) of the parent company.
Show answer & explanation

Correct answer: B. The newly appointed local Chief Executive Officer (CEO) of the subsidiary.

Ultimately, the local CEO of the subsidiary holds primary accountability for the overall operations and compliance within their specific jurisdiction. While other roles provide support or oversight, the CEO is directly responsible for ensuring that the subsidiary adheres to all local legal and regulatory requirements, including cybersecurity laws.

Why the other options are wrong

  • A. The CIO sets IT strategy but the local CEO is responsible for overall compliance of the subsidiary.
  • C. The Legal Department provides advice and guidance, but the operational responsibility for ensuring compliance rests with the business unit's leadership.
  • D. The CRO provides enterprise-wide risk oversight but the operational responsibility for local compliance rests with the local leadership.

Organizational Structure, Roles, and Responsibilities

The formal framework defining authority, duties, and accountability within an organization, critical for effective governance.

  • Clear roles prevent gaps and overlaps.
  • Accountability rests with specific individuals or functions.
  • Supports effective decision-making and risk management.

Memory trick: Local CEO steers the local ship of compliance.

More Governance questions