Skip to content

FRM Part II · FRM Exam Part II · Introduction to Operational Risk and Resilience

A bank's internal audit department is asked by the chief operating officer to design and implement a new set of reconciliation controls in the payments unit, and then to audit those same controls the following year. Which governance concern is most directly raised?

The main concern is that internal audit's independence would be compromised. As the third line it must give objective assurance, but designing and implementing controls and then auditing them creates a self-review conflict, since it would be assessing its own work.

  1. AInternal audit's independence as the third line would be compromised by self-reviewCorrect
  2. BSecond line risk appetite metrics would become too conservative
  3. CThe first line would lose accountability for risk identification entirely
  4. DOperational loss data would be double counted in the capital model

Explanation

Internal audit must stay independent to give objective assurance. Designing and implementing controls makes it effectively a first-line owner, and auditing them later creates a self-review threat. The other options do not follow directly from this arrangement.

Did you get it right without looking?

One question tells you little. A timed set on Introduction to Operational Risk and Resilience shows your real accuracy, how long you take and where you lose marks.

More Introduction to Operational Risk and Resilience questions