Skip to content

FRM Exam Part II · Risk Mitigation

Internal Controls and Control Frameworks for Operational Risk

Updated 11 October 2026 · Fact-checked

Internal controls are policies, procedures and checks that reduce the chance or impact of operational loss. They are preventive, detective or corrective. The three lines of defense assign ownership, and frameworks such as COSO structure design and testing. To solve questions, classify the control, identify who owns it, then judge design and operating effectiveness.

Understand Internal Controls and Control Frameworks

An internal control is any process, rule or check that gives reasonable assurance an organisation will meet its objectives: reliable reporting, effective operations and compliance with rules. It lowers the likelihood of a loss event or limits its size. No control gives absolute assurance.

Controls are grouped by timing. Preventive controls stop an error or fraud before it happens, such as access rights, dual authorisation and trading limits. Detective controls find a problem after it has happened, such as reconciliations, exception reports and surveillance. Corrective controls fix the problem and restore the position, such as reversing a wrong trade, restoring from backup or invoking a recovery plan. Strong frameworks use all three in layers.

The three lines of defense model sets ownership. The first line is business management, which owns risks and runs day-to-day controls. The second line is independent risk management and compliance, which sets policy, challenges and monitors. The third line is internal audit, which gives independent assurance to the board on whether the first two lines work. Independence grows with each line.

COSO is a widely used internal control framework. Its Internal Control Integrated Framework has five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. The control environment (tone at the top, integrity, accountability) underpins the rest. COSO also has a separate enterprise risk management framework.

Testing asks two questions. Design effectiveness: if the control works as written, would it address the risk? Operating effectiveness: did it actually work consistently over the period? A well-designed control that people bypass fails the second test. Residual risk is inherent risk after controls, and it should sit within risk appetite.

Key formulas to remember

Residual risk
Residual risk = Inherent risk − effect of controls
Conceptual, not a precise calculation. Used in RCSA to rate risk after controls.
COSO components
Control environment, Risk assessment, Control activities, Information and communication, Monitoring activities
Five components of the Internal Control Integrated Framework. Control environment is the foundation.
Control timing
Preventive (before) → Detective (during or after) → Corrective (after detection)
Classify by when the control acts relative to the event.
Three lines of defense
1st: business owns risk and controls; 2nd: risk and compliance oversee; 3rd: internal audit gives independent assurance
Ownership and independence are the tested points.
Control effectiveness test
Effective control = adequate design AND consistent operation
Both must hold. Failing either means the control is ineffective.

How to solve Internal Controls and Control Frameworks questions

Use this sequence for any scenario question on controls, frameworks or the three lines.

  1. 1Identify the risk event and the failure in the scenario: what went wrong and where.
  2. 2Decide the timing of each control mentioned: before the event (preventive), finding it (detective) or fixing it (corrective).
  3. 3Assign ownership: who runs it (first line), who sets policy and challenges (second line), who gives independent assurance (third line).
  4. 4Map any framework words to COSO components, such as tone at the top to control environment.
  5. 5Judge effectiveness: is the failure one of design (control missing or inadequate) or operation (control exists but not followed)?
  6. 6Check independence: a line cannot assess its own work, and audit should not own controls.
  7. 7Pick the option that fixes the root cause at the right line and timing, and drop options that overstate assurance.

Quickest way: Timing and ownership shortcut

When to use it: Use for short MCQs asking you to classify a control or name the responsible line.

  1. Ask: did it act before, after finding, or after fixing? Before is preventive, finding is detective, fixing is corrective.
  2. Ask: who does it? Business is first line, risk or compliance second, audit third.
  3. Ask: was it missing or ignored? Missing is a design gap; ignored is an operating failure.
  4. Eliminate options with absolute words like guarantee or eliminate all risk.

Common mistakes in Internal Controls and Control Frameworks

  • Calling a reconciliation a preventive control.

    Reconciliations feel like a safeguard, so students link them to prevention.

    Fix: A reconciliation finds breaks after transactions occur, so it is detective. Prevention stops the error before it is posted.

  • Treating internal audit as part of the second line.

    Audit and risk both look like oversight functions.

    Fix: Audit is the third line and reports independently to the board or audit committee. The second line is risk management and compliance.

  • Saying risk management owns the risk.

    The name suggests ownership.

    Fix: The first line owns and manages risk. The second line oversees and challenges but does not take ownership.

  • Confusing design and operating effectiveness.

    Both are called effectiveness, so they blur.

    Fix: Design asks if the control could work on paper. Operating asks if it did work in practice. A control can pass one and fail the other.

  • Believing controls eliminate risk.

    Students assume strong controls mean zero loss.

    Fix: Controls give reasonable, not absolute, assurance. Residual risk always remains, and management can override controls.

  • Listing COSO components in the wrong order of importance.

    Students memorise the list without its logic.

    Fix: Control environment is the foundation. Control activities are only one of five components, not the whole framework.

Worked examples

Example 1

A bank's payment system requires a second employee to approve any transfer above USD 1 million. Each night, an independent team compares payments sent with approved requests and flags differences. When a wrong payment is found, operations recalls the funds and the amount is returned. Classify the three controls.

Show the solution
  1. Dual approval acts before the payment is released, so it is preventive.
  2. The nightly comparison finds mismatches after payments are sent, so it is detective.
  3. Recalling the funds fixes the loss after detection, so it is corrective.
  4. Together they form layered defenses: stop, find, fix.

Answer: Dual approval is preventive, the nightly comparison is detective, and the fund recall is corrective.

Example 2

A trading desk head overrides a position limit and the desk's risk analyst, who reports to the desk head, does not escalate the breach. Internal audit later reports the breach. Identify the control failure by line of defense and the best remedy.

Show the solution
  1. The desk is the first line and owns the limit. The override is a first-line control failure and a weak control environment.
  2. The analyst reports to the desk head, so the second-line function lacks independence and cannot challenge effectively.
  3. Internal audit, the third line, detected it after the fact. That is useful assurance but does not prevent the breach.
  4. The root cause is independence: challenge must come from a function outside the business reporting line.
  5. The remedy is to have the risk function report independently to the chief risk officer, with mandatory escalation of limit breaches.

Answer: The failure is a lack of second-line independence plus a weak tone at the top. The best remedy is independent reporting for risk staff with mandatory breach escalation.

Exam tips

  • Always classify by timing first. Many options differ only in preventive, detective or corrective wording.
  • In three-lines questions, look for independence. The correct answer usually keeps risk oversight separate from the business.
  • Match scenario wording to COSO components: tone at the top points to control environment, dashboards and reporting to information and communication.
  • Distinguish design from operating failure. A missing control is a design gap; an ignored control is an operating failure.
  • Be careful with options claiming controls guarantee or eliminate loss. They are usually wrong.

Practice questions from Risk Mitigation

Internal Controls and Control Frameworks in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Internal Controls and Control Frameworks: frequently asked questions

What is the difference between preventive, detective and corrective controls?

Preventive controls stop an event before it occurs, detective controls find it after it occurs, and corrective controls fix the damage and restore normal operations. Banks layer all three so that one failure does not cause a loss.

Who is in each line of defense?

The first line is business management that owns risk and runs controls. The second line is independent risk management and compliance that sets policy and challenges the business. The third line is internal audit, which gives independent assurance to the board.

What are the five COSO components?

They are control environment, risk assessment, control activities, information and communication, and monitoring activities. The control environment is the foundation that supports the others.

How do you assess control effectiveness in operational risk?

Test design effectiveness, meaning whether the control would address the risk if followed, and operating effectiveness, meaning whether it worked consistently in practice. Evidence comes from testing, KRIs, loss events and audit findings. The result feeds residual risk ratings in RCSA.