Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A bank's cyber risk team uses a three-lines model. An internal audit function reports that the IT security team both designs access controls and independently tests whether those controls work, with no separate review. Which finding is most appropriate?

The key finding is that independent assurance is lacking. The same team designs and tests the access controls, so no separate line challenges or validates their effectiveness. A three-lines model requires independent oversight and testing, regardless of how expert the security team is.

  1. AThe framework is sound because the team with most expertise performs testing
  2. BThe first line should be replaced by external consultants for all controls
  3. CIndependent assurance is lacking because control ownership and testing sit within the same lineCorrect
  4. DTesting should be removed since controls are already designed by experts

Explanation

Under a three-lines model, control owners (first line) should be challenged by independent oversight (second line) and assurance (third line). When the designers also test their own controls, independence is missing, so effectiveness assurance is weak. Expertise does not substitute for independence.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions