CAMS · Question #917
How should risk-related issues be addressed to ensure the effectiveness of the three lines of defense model?
The correct answer is A. Ensure that the second line reviews, monitors, and escalates risk-related issues as needed to. The three lines of defense model assigns distinct roles to each line, with the second line responsible for monitoring, oversight, and escalating risk issues to preserve structural integrity.
Question
How should risk-related issues be addressed to ensure the effectiveness of the three lines of defense model?
Options
- AEnsure that the second line reviews, monitors, and escalates risk-related issues as needed to
- BHave senior management handle risk-related issues directly when possible because they are
- CDelegate some risk-related issues to the first line to avoid overwhelming the second line and to
- DAssign risk-related oversight duties to the third line to provide an independent review and address
How the community answered
(42 responses)- A81% (34)
- B12% (5)
- C5% (2)
- D2% (1)
Why each option
The three lines of defense model assigns distinct roles to each line, with the second line responsible for monitoring, oversight, and escalating risk issues to preserve structural integrity.
The second line of defense - typically risk management and compliance functions - is specifically responsible for reviewing and monitoring risk-related issues identified by the first line and escalating them as needed to senior management or the board. This preserves the structural separation between risk-taking and risk oversight that is central to the model. Proper escalation by the second line ensures material risks reach decision-makers in a timely and structured manner.
Having senior management handle risk issues directly bypasses the tiered accountability structure and collapses the separation the three lines model is designed to maintain.
Delegating second-line oversight duties back to the first line eliminates the separation between risk-taking operations and risk oversight, which is the core purpose of the model.
The third line - internal audit - provides independent assurance over the overall framework, not ongoing operational risk oversight or real-time escalation.
Concept tested: Three lines of defense roles and responsibilities
Source: https://www.theiia.org/en/standards/three-lines-model/
Topics
Community Discussion
No community discussion yet for this question.