nerdexam
Isaca

CRISC · Question #325

Which of the following activities should only be performed by the third line of defense?

The correct answer is C. Providing assurance on risk management processes. The third line of defense, typically internal audit, is solely responsible for providing independent assurance on the effectiveness of an organization's governance, risk management, and control processes.

Submitted by naveen.iyer· Apr 18, 2026Governance

Question

Which of the following activities should only be performed by the third line of defense?

Options

  • AOperating controls for risk mitigation
  • BTesting the effectiveness and efficiency of internal controls
  • CProviding assurance on risk management processes
  • DRecommending risk treatment options

How the community answered

(66 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    92% (61)
  • D
    3% (2)

Why each option

The third line of defense, typically internal audit, is solely responsible for providing independent assurance on the effectiveness of an organization's governance, risk management, and control processes.

AOperating controls for risk mitigation

Operating controls is the primary responsibility of the first line of defense (operational management).

BTesting the effectiveness and efficiency of internal controls

Testing the effectiveness and efficiency of internal controls is typically performed by the second line of defense (risk management, compliance functions) or can be part of the third line's assurance activities, but it's not only performed by the third line.

CProviding assurance on risk management processesCorrect

The third line of defense, usually internal audit, provides independent and objective assurance on the effectiveness of the organization's governance, risk management, and internal control processes to the board and senior management. This ensures an unbiased evaluation of the entire risk management framework.

DRecommending risk treatment options

Recommending risk treatment options is a core function of the second line of defense, working with the first line to manage risks.

Concept tested: Three Lines of Defense model

Source: https://www.iia-inc.org/three-lines-of-defense-model

Topics

#Three Lines of Defense#Internal Audit#Risk Assurance#Governance Frameworks

Community Discussion

No community discussion yet for this question.

Full CRISC Practice