nerdexam
Isaca

CRISC · Question #623

Which of the following is the PRIMARY risk management responsibility of the third line of defense?

The correct answer is A. Providing assurance of the effectiveness of risk management activities. The third line of defense, typically internal audit, is primarily responsible for providing independent assurance regarding the effectiveness of risk management and internal controls.

Submitted by olafpl· Apr 18, 2026Governance

Question

Which of the following is the PRIMARY risk management responsibility of the third line of defense?

Options

  • AProviding assurance of the effectiveness of risk management activities
  • BProviding guidance on the design of effective controls
  • CProviding advisory services on enterprise risk management (ERM)
  • DProviding benchmarking on other organizations' risk management programs

How the community answered

(52 responses)
  • A
    90% (47)
  • B
    2% (1)
  • C
    6% (3)
  • D
    2% (1)

Why each option

The third line of defense, typically internal audit, is primarily responsible for providing independent assurance regarding the effectiveness of risk management and internal controls.

AProviding assurance of the effectiveness of risk management activitiesCorrect

The third line of defense, generally internal audit, is responsible for providing objective and independent assurance to the board and senior management on the effectiveness of governance, risk management, and internal control processes. This involves evaluating whether risk management activities are operating as intended and achieving their objectives.

BProviding guidance on the design of effective controls

Providing guidance on the design of effective controls is typically a responsibility of the second line of defense (e.g., risk management function).

CProviding advisory services on enterprise risk management (ERM)

Providing advisory services on ERM is primarily a role of the second line of defense or external consultants, not the independent assurance function of the third line.

DProviding benchmarking on other organizations' risk management programs

Benchmarking other organizations' risk management programs, while potentially informative, is not the primary, core responsibility of the third line of defense.

Concept tested: Three Lines of Defense model (third line)

Source: https://www.theiia.org/en/content/knowledge/standards/global-guidance/position-papers/2020/iias-three-lines-model/

Topics

#Three Lines Model#Risk Management Roles#Assurance#Internal Audit

Community Discussion

No community discussion yet for this question.

Full CRISC Practice