Skip to content

FRM Part II · FRM Exam Part II · Risk Governance

A bank's board wants to clarify responsibilities in its operational risk governance framework under the three lines of defense model. Which activity is most appropriately assigned to the second line of defense?

The second line of defense designs the operational risk framework and challenges the first line's assessments. Business units own and manage risk day to day, internal audit gives independent assurance, and the board approves risk appetite, so those activities belong elsewhere.

  1. AOwning and managing operational risks arising in daily business activities
  2. BDesigning the operational risk framework and challenging the first line's risk and control assessmentsCorrect
  3. CProviding independent assurance to the audit committee on the effectiveness of controls
  4. DApproving the bank's overall risk appetite statement as the highest governing body

Explanation

The second line (independent operational risk management function) develops the framework, sets policies and provides oversight and challenge to the first line. Owning risks is a first-line role, independent assurance is the third line (internal audit), and approving risk appetite is a board responsibility.

Did you get it right without looking?

One question tells you little. A timed set on Risk Governance shows your real accuracy, how long you take and where you lose marks.

More Risk Governance questions