In theGRC Capability Model, theREVIEWcomponent is designed to ensure continuous improvement and accountability by monitoring, evaluating, and assuring the effectiveness of actions, controls, and strategies. This component ensures that the organization stays on track to achieve its objectives while addressing risks and obligations.
Key Objectives of the REVIEW Component:
Monitoring Actions and Controls:
Ensures that implemented controls and actions are functioning as intended to manage risks and seize opportunities.
Providing Assurance:
The REVIEW component validates that the organization's actions align with its objectives, policies, and obligations, often through internal audits or performance evaluations.
Continuous Improvement:
By analyzing the effectiveness of controls, the REVIEW component identifies areas for improvement and ensures the organization adapts to changing circumstances.
Holistic Focus:
Unlike a narrow focus on compliance or monitoring, the REVIEW component evaluates total performance, encompassing objectives, risks, and obligations.
Why Option B is Correct:
The REVIEW component focuses oncontinuous improvementbymonitoring actions and controlsand providingassurancethat objectives, opportunities, risks, and obligations are being managed effectively, making it the most comprehensive answer.
Why the Other Options Are Incorrect:
A. Implementing new policies and procedures: Implementation is part of the Perform component, not the REVIEW component.
C. Exclusively focusing on monitoring: While monitoring is part of the REVIEW component, it also includes assurance and continuous improvement, making this option incomplete.
D. Conducting audits and inspections: Audits are a subset of assurance activities, but the REVIEW component goes beyond audits to ensure total performance improvement.
References and Resources:
OCEG GRC Capability Model– Provides guidance on the REVIEW component's role in monitoring and assurance.
COSO ERM Framework– Highlights the importance of monitoring and continuous improvement.
ISO 31000:2018– Discusses evaluating risk management performance as part of an ongoing review process.