CRISC Certified in Risk and Information Systems ControlGovernanceEasy

A global manufacturing company is implementing a new enterprise resource planning (ERP) system across all its subsidiaries worldwide. The corporate IT department has developed a comprehensive set of security standards for the new system. However, a subsidiary in a particular country has local regulations that mandate specific data encryption algorithms and key management practices that differ from the corporate standard. Which of the following is the MOST appropriate action for the risk manager to recommend?

  1. ADevelop a new, hybrid security standard that incorporates both the corporate and local requirements for all global implementations.
  2. BImplement the local regulatory requirements in the subsidiary, even if it deviates from the corporate standard, and document the exception.
  3. CRequire the subsidiary to adhere strictly to the corporate security standards, as they represent the global benchmark for the company.
  4. DIsolate the subsidiary's ERP system from the rest of the global network to prevent non-compliance from affecting the corporate standard.
Show answer & explanation

Correct answer: B. Implement the local regulatory requirements in the subsidiary, even if it deviates from the corporate standard, and document the exception.

When corporate standards conflict with local legal or regulatory requirements, adherence to local law takes precedence. The most appropriate action is to implement the local requirements and document the deviation, ensuring compliance while maintaining visibility of the exception within the global framework.

Why the other options are wrong

  • A. Developing a new hybrid standard for all implementations might be overly complex and unnecessary if the local requirement is an isolated case.
  • C. Ignoring local regulations is a compliance failure and can lead to legal penalties.
  • D. Isolating the system might be technically feasible but could hinder business operations and data flow, and doesn't address the core compliance conflict.

Legal and Regulatory Supremacy

In cases of conflict, local legal and regulatory requirements always take precedence over internal corporate policies or global standards.

  • Compliance with law is non-negotiable.
  • Exceptions to corporate standards must be documented.
  • Legal obligations supersede internal guidelines.

Memory trick: When the law and the company clash, the law always wins the race.

More Governance questions