nerdexam
Isaca

CGEIT · Question #564

Within a governance structure for risk management, which of the following activities should be performed by the second line of defense?

The correct answer is C. Monitoring risk and controls. Within a three lines of defense governance structure for risk management, the second line of defense is primarily responsible for monitoring risk and controls.

Submitted by salim_om· Apr 18, 2026Governance of Enterprise IT

Question

Within a governance structure for risk management, which of the following activities should be performed by the second line of defense?

Options

  • AConducting internal and external audits
  • BImplementing controls to manage risk
  • CMonitoring risk and controls
  • DIdentifying and assessing risk

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    10% (2)
  • C
    85% (17)

Why each option

Within a three lines of defense governance structure for risk management, the second line of defense is primarily responsible for monitoring risk and controls.

AConducting internal and external audits

Conducting internal and external audits is the primary role of the third line of defense, which provides independent assurance.

BImplementing controls to manage risk

Implementing controls to manage risk is the responsibility of the first line of defense (operational management) as part of their day-to-day activities.

CMonitoring risk and controlsCorrect

The second line of defense typically consists of functions like risk management, compliance, and quality assurance. Their role is to oversee the effectiveness of the first line's risk management activities, develop risk management frameworks, and perform ongoing monitoring of risks and the design and operating effectiveness of controls to ensure they are functioning as intended and align with the organization's risk appetite.

DIdentifying and assessing risk

Identifying and assessing risk is a shared responsibility across all three lines, but the operational identification and initial assessment reside with the first line, with the second line providing frameworks and oversight.

Concept tested: Three Lines of Defense model in risk management

Source: https://na.theiia.org/periodicals/Internal%20Auditor/Documents/IIA-Position-Paper-Three-Lines-of-Defense-Update.pdf

Topics

#Three Lines of Defense Model#Risk Management Governance#Organizational Roles#Risk Monitoring

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice