FRM Part II · FRM Exam Part II · Risk Governance
A bank's board wants to clarify responsibilities in its operational risk governance framework under the three lines of defense model. Which activity is most appropriately assigned to the second line of defense?
The second line of defense designs the operational risk framework and challenges the first line's assessments. Business units own and manage risk day to day, internal audit gives independent assurance, and the board approves risk appetite, so those activities belong elsewhere.
- AOwning and managing operational risks arising in daily business activities
- BDesigning the operational risk framework and challenging the first line's risk and control assessmentsCorrect
- CProviding independent assurance to the audit committee on the effectiveness of controls
- DApproving the bank's overall risk appetite statement as the highest governing body
Explanation
The second line (independent operational risk management function) develops the framework, sets policies and provides oversight and challenge to the first line. Owning risks is a first-line role, independent assurance is the third line (internal audit), and approving risk appetite is a board responsibility.
Did you get it right without looking?
One question tells you little. A timed set on Risk Governance shows your real accuracy, how long you take and where you lose marks.
More Risk Governance questions
- Which practice most strongly supports the effective embedding of a board-approved risk appetite in an organization's decision making?
- A trading desk head receives a large annual bonus paid entirely in cash immediately, based on that year's profits. Losses from the positions…
- A bank's board approves an operational risk appetite statement that sets annual operational loss tolerance at USD 40 million. Management set…
- A bank's board has approved an operational risk framework, but the document does not say how much operational risk the bank is willing to ac…
- When a board is setting operational risk appetite, which approach best reflects sound governance practice?
- A bank's operational risk committee reviews key risk indicators (KRIs) with amber threshold 4 and red threshold 7 failed settlements per wee…