Skip to content

FRM Part II · FRM Exam Part II · Governance

A bank's head of internal audit proposes that the audit function also take over day-to-day monitoring of credit limit breaches, since it already has the data and skilled staff. Which is the best assessment of this proposal?

The proposal should be rejected. Day-to-day limit monitoring belongs to the second line. If internal audit performed it, audit would later be assessing its own activity, which compromises the independent assurance that defines the third line of defense.

  1. AAcceptable, because audit has the strongest independence and can therefore monitor limits most effectively
  2. BAcceptable, provided the audit committee is informed of every breach
  3. CNot acceptable, because performing ongoing risk monitoring is a second-line activity and would impair audit's independent assurance roleCorrect
  4. DNot acceptable, because limit monitoring must be performed by the front-office business units alone

Explanation

Ongoing limit monitoring is a management and second-line responsibility. If audit performs it, audit would later have to assess its own work, losing objectivity as the third line. Limit monitoring is not first line only, so the last option is wrong.

Did you get it right without looking?

One question tells you little. A timed set on Governance shows your real accuracy, how long you take and where you lose marks.

More Governance questions