01. A company has outsourced enrollment support and claims appeals for its health plan to an external administrator. The administrator, without telling the company, subcontracted its overflow call handling to a smaller firm. That firm has now suffered a data breach exposing enrollment records for a number of the company's employees, and the administrator's position is that its own systems were never compromised.
What should the CHRO have established in the contracting model?
a) Require the administrator to put the same safeguards and breach duties on any firm it hands the work to, and to notify the plan at the point it brings one in
b) Require the administrator to carry insurance covering a breach at any subcontractor, and to indemnify the plan for the full cost of notifying the employees affected
c) Require the administrator to certify each year that its security program meets a recognized industry standard, and to send the plan a copy of the certification it obtains
d) Require the administrator to keep all plan information on its own systems, and to obtain the plan's approval before any employee record moves outside the company's network
02. A company is launching a voluntary wellness program delivered by an external vendor, combining a biometric screening with a health questionnaire. The vendor describes its platform as HIPAA-compliant. Its proposal includes a manager dashboard showing individual results, and suggests that human resources follow up personally with employees whose screening results look concerning. A modest premium reduction is offered to employees who complete the screening.
What data flow should the CHRO require before the program opens?
a) Aggregate results to the employer with no names on them, and individual results held by the vendor so that it can reach out to the employee itself
b) Individual results delivered to the human resources team, and a confidentiality undertaking signed by every person who is given access to the dashboard
c) Individual results delivered to the employer's occupational health provider, and a summary sent to human resources so that the premium reduction can be applied accurately
d) Aggregate results to the employer with no identifiers, and individual results released to the employee's manager wherever the vendor judges that follow-up is needed
03. A manufacturer with plants in several states is replacing a patchwork of site safety rules with one enterprise standard. Some of its plants sit in states that operate their own occupational safety plans, and a few of those states require more of certain operations than the federal requirement does. The general counsel proposes writing the enterprise standard to the federal requirement alone. Adopting the strictest requirement found anywhere in the footprint would mean re-engineering equipment at every plant, at a cost the business has said it cannot absorb this cycle.
What should the CHRO advise the executive team to adopt?
a) A single enterprise standard set at the most protective requirement found anywhere in the footprint, so that every plant operates to one rule and one curriculum no matter what its own regulator asks of it
b) A single enterprise standard set at the federal requirement, with anything a state plan asks beyond it left to each plant's management and its own regulator to settle between them
c) A single enterprise standard set at the federal requirement, with a stated mechanism applying the more protective requirement wherever a state plan covers that plant for a given operation
d) A separate standard written for each plant, so that every set of requirements appears exactly where it applies and no plant carries an obligation that a different plant's regulator imposed
04. A people analytics team has proposed a model to predict which employees are most likely to resign. It wants to join four sources: the annual engagement survey, which employees answered under a promise that responses would be reported only in groups; performance ratings; pay history; and the categories of claim recorded against each member of the health plan. The chief financial officer supports the proposal because retention costs are rising sharply.
What should the CHRO rule on the design?
a) Include the claims data as a de-identified extract, and use the survey only at a grouping large enough to keep individual responses unrecoverable
b) Exclude the claims data entirely, and use the survey only at a grouping large enough that every individual response stays unrecoverable from the model
c) Include both sources in full, and publish the model's input list to the workforce, so that employees can see what the company has used about them
d) Exclude the claims data from the model, and use the survey at individual level under a written undertaking signed by each analyst who works on it
05. A regional utility runs a continuity exercise every year. The exercise has passed each time: the call tree reaches everyone, the standby site comes up, and the technology function meets its stated recovery times. When a real regional event struck, the plan nonetheless stalled for most of a day because no one below the chief operating officer believed they could commit the company to emergency contractor spending, and the chief operating officer was unreachable.
What should the CHRO ask the risk committee to change about how the next exercise is designed?
a) Extend it to a full working day with the executive team present throughout, and judge it on whether the documented recovery times were achieved
b) Commission an independent assessor to observe the exercise, and judge it against the continuity standards that assessor's methodology applies
c) Run it across every operating site at the same time, and judge it on how quickly each site reports that it is ready to operate and to take on work
d) Run it against a scenario that takes away something the plan assumes will be there, and judge it on which decisions could not be made
06. A software company has moved permanently to a majority-remote model. An employee has been injured at home during working hours while moving equipment the company shipped to them, and the general counsel has asked what the company's safety policy should say about remote work before the question arises again.
What should the CHRO have the policy establish?
a) Require every employee to certify their home workspace annually, and limit the reporting duty to injuries that occur at a company site or facility
b) Treat every home workspace as a company worksite for all purposes, and inspect each one before an employee is approved to work remotely
c) Define the workspace conditions the company requires and supports, and keep the same duty to notify the company of an injury wherever the work is performed
d) Treat the home as falling outside the company's safety program, and rely on each employee's own household insurance unless the company shipped the equipment involved
07. A US insurance company recognizes outstanding work through manager nominations, with the awards presented at a quarterly all-hands meeting. Since the company moved to hybrid working, roughly three quarters of the awards have gone to employees based at headquarters, who are a minority of the workforce.
Claims and field employees working remotely have started to comment on the pattern, and the engagement survey shows recognition falling among exactly that group.
What should the head of total rewards change in the program's design?
a) Publish the criteria an award has to meet, and report the distribution of awards by location and job type each quarter
b) Set a share of the awards for each site, so that each location receives a proportion matching its own headcount
c) Replace manager nomination with a peer nomination process, opened to the whole company, and give the awards to the nominees who receive the most votes
d) Move the presentation online and add a recorded message from the chief executive, so that every employee sees the awards being made wherever they happen to work
08. A US professional services firm is configuring manager self-service in a new human resource information system. The implementation partner has proposed a single manager role: full read access to the complete employee record for anyone in the manager's reporting line, on the argument that managers make better decisions with more context.
The record holds compensation history, leave notes that identify a health condition, and the outcomes of closed workplace investigations.
What principle should govern how the access is configured?
a) Each manager sees a view set by their own grade, with directors and above holding the complete record while frontline managers get a reduced one
b) Each manager sees only the data their own decisions require, with compensation, health and investigation records held under separate permissions
c) Each manager sees the full record for everyone in their reporting line, with an audit log capturing every record opened and a policy stating what may be discussed
d) Each manager sees only what human resources releases to them on request, with every release recorded and afterward reviewed by the human resources business partner
09. A US retailer's people analytics team wants to model why health benefit costs differ so sharply between its distribution centers. The analytics director has asked the group health plan's third-party administrator to send the team a claims extract at participant level, so that claims patterns can be joined to job, shift and tenure data already held in the HR system.
The chief human resources officer sponsors the analytics program and also sits on the benefits committee.
What should the chief human resources officer require before any of that data moves?
a) That the analytics team hold the claims extract under the access controls it applies to compensation and investigation files, with a confidentiality agreement signed by each analyst who opens it
b) That every employee whose claims are included sign an authorization at open enrollment, after which the administrator sends the analytics team whatever detail the model requires
c) That the administrator strip the obvious identifiers from the extract before sending it, so that the file reaches the analytics team carrying only the location and cost fields the model needs
d) That the analysis run on de-identified or summary health information, with any wider flow conditioned on amended plan documents and a certified separation of who may see it
10. Litigation brought by a former employee has exposed how a company keeps employment records. Managers hold interview notes and coaching files on their own drives, the human resources system holds the formal record, investigation material sits in a shared folder, and several sites still keep paper. During the case one manager deleted their notes as part of a routine clear-out, while recruitment files from a decade ago were produced intact.
What should the CHRO have the records policy establish?
a) A retention period chosen for each system by the function that owns it, so that storage cost is matched to the value that function still gets from the records
b) A single retention period applied across the company, with destruction carried out automatically once that period has run for a given record
c) A retention schedule set by record class and owned by a named function, with routine destruction suspended across all systems for every record a legal hold reaches
d) A storage plan that consolidates employment records into one repository, so that managers no longer keep local copies which cannot be found when a claim arrives