CRISC · Question #325
Which of the following activities should only be performed by the third line of defense?
The correct answer is C. Providing assurance on risk management processes. The third line of defense, typically internal audit, is solely responsible for providing independent assurance on the effectiveness of an organization's governance, risk management, and control processes.
Question
Which of the following activities should only be performed by the third line of defense?
Options
- AOperating controls for risk mitigation
- BTesting the effectiveness and efficiency of internal controls
- CProviding assurance on risk management processes
- DRecommending risk treatment options
How the community answered
(66 responses)- A2% (1)
- B3% (2)
- C92% (61)
- D3% (2)
Why each option
The third line of defense, typically internal audit, is solely responsible for providing independent assurance on the effectiveness of an organization's governance, risk management, and control processes.
Operating controls is the primary responsibility of the first line of defense (operational management).
Testing the effectiveness and efficiency of internal controls is typically performed by the second line of defense (risk management, compliance functions) or can be part of the third line's assurance activities, but it's not only performed by the third line.
The third line of defense, usually internal audit, provides independent and objective assurance on the effectiveness of the organization's governance, risk management, and internal control processes to the board and senior management. This ensures an unbiased evaluation of the entire risk management framework.
Recommending risk treatment options is a core function of the second line of defense, working with the first line to manage risks.
Concept tested: Three Lines of Defense model
Source: https://www.iia-inc.org/three-lines-of-defense-model
Topics
Community Discussion
No community discussion yet for this question.