nerdexam
Isaca

CRISC · Question #552

In the three lines of defense model, a PRIMARY objective of the second line is to:

The correct answer is B. Ensure risk and controls are effectively managed. The second line of defense in risk management focuses on developing policies, monitoring compliance, and ensuring that the first line effectively manages risks and controls.

Submitted by weili_xi· Apr 18, 2026Governance

Question

In the three lines of defense model, a PRIMARY objective of the second line is to:

Options

  • AReview and evaluate the risk management program.
  • BEnsure risk and controls are effectively managed.
  • CImplement risk management policies regarding roles and responsibilities.
  • DAct as the owner for any operational risk identified as part of the risk program.

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    91% (21)
  • D
    4% (1)

Why each option

The second line of defense in risk management focuses on developing policies, monitoring compliance, and ensuring that the first line effectively manages risks and controls.

AReview and evaluate the risk management program.

Reviewing and evaluating the overall risk management program is typically a primary objective of the third line of defense (internal audit), which provides independent assurance.

BEnsure risk and controls are effectively managed.Correct

The second line of defense is responsible for developing risk management policies, providing oversight, and ensuring that the first line's risk and control management activities are effectively implemented and operating as intended.

CImplement risk management policies regarding roles and responsibilities.

While implementing risk management policies is a function of the second line, its primary objective extends to ensuring the effective *management* of risks and controls across the organization, not just policy implementation.

DAct as the owner for any operational risk identified as part of the risk program.

Acting as the owner for operational risk is a responsibility of the first line of defense, which directly owns and manages operational risks within their business processes.

Concept tested: Three lines of defense model (second line)

Source: https://learn.microsoft.com/en-us/compliance/regulatory/audits-risk-compliance-3-lines-of-defense

Topics

#Three Lines of Defense#Second Line of Defense#Risk Management Roles#Risk Governance

Community Discussion

No community discussion yet for this question.

Full CRISC Practice