FRM Part II · FRM Exam Part II · Risk Governance
A bank's internal audit department is asked by the COO to design the key risk indicator thresholds for the payments business and then, six months later, to provide independent assurance that the risk framework is working effectively. What is the principal concern with this arrangement under the three lines of defense model?
The main concern is loss of independence. Internal audit is the third line and must provide objective assurance. If it designs the key risk indicator thresholds, it later audits its own work, which creates a self-review conflict and undermines the credibility of its assurance.
- AInternal audit would be reviewing a design it helped create, impairing its independence as the third lineCorrect
- BInternal audit lacks the technical skill to evaluate key risk indicators
- CThe second line would be unable to report to the board risk committee
- DThe first line would lose ownership of operational risk data
Explanation
The third line must remain independent of both the first and second lines. Designing risk indicator thresholds is a management responsibility, so auditing that same design later creates a self-review threat. Skill and reporting lines are not the core issue.
Did you get it right without looking?
One question tells you little. A timed set on Risk Governance shows your real accuracy, how long you take and where you lose marks.
More Risk Governance questions
- Which activity is most clearly a second-line responsibility in an operational risk governance framework?
- A bank's key risk indicator (KRI) for failed reconciliations has an amber threshold at 40 breaks per month and a red threshold at 70. Over s…
- In a bank using the three lines of defence model as described in the Basel operational risk principles, which statement best describes the r…
- A bank assigns its operational risk function the following: it designs the framework, challenges business line risk and control self-assessm…
- A bank's operational risk function receives loss event data from business units. The Chief Risk Officer notices that several units report lo…
- Which practice most strongly supports the effective embedding of a board-approved risk appetite in an organization's decision making?