CRISC · Question #552
In the three lines of defense model, a PRIMARY objective of the second line is to:
The correct answer is B. Ensure risk and controls are effectively managed. The second line of defense in risk management focuses on developing policies, monitoring compliance, and ensuring that the first line effectively manages risks and controls.
Question
In the three lines of defense model, a PRIMARY objective of the second line is to:
Options
- AReview and evaluate the risk management program.
- BEnsure risk and controls are effectively managed.
- CImplement risk management policies regarding roles and responsibilities.
- DAct as the owner for any operational risk identified as part of the risk program.
How the community answered
(23 responses)- A4% (1)
- B91% (21)
- D4% (1)
Why each option
The second line of defense in risk management focuses on developing policies, monitoring compliance, and ensuring that the first line effectively manages risks and controls.
Reviewing and evaluating the overall risk management program is typically a primary objective of the third line of defense (internal audit), which provides independent assurance.
The second line of defense is responsible for developing risk management policies, providing oversight, and ensuring that the first line's risk and control management activities are effectively implemented and operating as intended.
While implementing risk management policies is a function of the second line, its primary objective extends to ensuring the effective *management* of risks and controls across the organization, not just policy implementation.
Acting as the owner for operational risk is a responsibility of the first line of defense, which directly owns and manages operational risks within their business processes.
Concept tested: Three lines of defense model (second line)
Source: https://learn.microsoft.com/en-us/compliance/regulatory/audits-risk-compliance-3-lines-of-defense
Topics
Community Discussion
No community discussion yet for this question.