nerdexam
Isaca

CRISC · Question #506

Within the three lines of defense model, the PRIMARY responsibility for ensuring risk mitigation controls are properly configured belongs with:

The correct answer is A. line management. In the three lines of defense model, the primary responsibility for ensuring risk mitigation controls are properly configured lies with line management. This represents the first line of defense, which directly owns and manages risks.

Submitted by emma.c· Apr 18, 2026Governance

Question

Within the three lines of defense model, the PRIMARY responsibility for ensuring risk mitigation controls are properly configured belongs with:

Options

  • Aline management.
  • Bthe IT risk function.
  • Centerprise compliance.
  • Dinternal audit.

How the community answered

(19 responses)
  • A
    84% (16)
  • C
    5% (1)
  • D
    11% (2)

Why each option

In the three lines of defense model, the primary responsibility for ensuring risk mitigation controls are properly configured lies with line management. This represents the first line of defense, which directly owns and manages risks.

Aline management.Correct

Line management, representing the "first line of defense," is primarily responsible for identifying, assessing, managing, and mitigating risks inherent in their day-to-day operations and processes. This includes the direct ownership and proper configuration of risk mitigation controls because they are closest to the operational activities and resources that generate and manage risk.

Bthe IT risk function.

The IT risk function (often part of the second line of defense) provides oversight, guidance, and challenges to the first line, but does not have primary responsibility for the *direct configuration* of operational controls.

Centerprise compliance.

Enterprise compliance (also part of the second line of defense) focuses on ensuring adherence to laws, regulations, and internal policies, providing oversight rather than direct control configuration.

Dinternal audit.

Internal audit (the third line of defense) provides independent assurance on the effectiveness of governance, risk management, and internal controls, but does not perform the direct configuration or management of controls.

Concept tested: Three lines of defense model responsibilities

Source: https://www.iia.org.uk/about-us/advocacy/position-papers/the-three-lines-of-defence-in-effective-risk-management-and-control/

Topics

#Three Lines of Defense#Risk Mitigation Controls#Control Ownership#Line Management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice