Skip to content

FRM Part II · FRM Exam Part II · Introduction to Operational Risk and Resilience

A bank's internal audit department is asked by the CEO to design and operate the key risk indicator (KRI) monitoring process for the payments business because audit staff understand the controls best. Which is the most significant governance concern with this proposal?

The main concern is loss of independence. Internal audit is the third line and must provide objective assurance; if it designs and runs the KRI process it would later have to assess its own work, a self-review conflict that undermines the integrity of the assurance.

  1. AInternal audit would lack access to the payments data needed for KRIs
  2. BKRI monitoring is a regulatory requirement that only the board may perform
  3. CInternal audit would compromise its independence by taking on a management function and then having to assess itCorrect
  4. DKRIs are only relevant to the first line and cannot be monitored by any other function

Explanation

Internal audit as third line must remain independent of management activities. If it designs and operates the KRI process it would end up auditing its own work, creating a self-review threat. The data access and board-only claims are not accurate principles.

Did you get it right without looking?

One question tells you little. A timed set on Introduction to Operational Risk and Resilience shows your real accuracy, how long you take and where you lose marks.

More Introduction to Operational Risk and Resilience questions