Skip to content

FRM Part II · FRM Exam Part II · Risk Governance

A bank's internal audit department is asked by the COO to design the key risk indicator thresholds for the payments business and then, six months later, to provide independent assurance that the risk framework is working effectively. What is the principal concern with this arrangement under the three lines of defense model?

The main concern is loss of independence. Internal audit is the third line and must provide objective assurance. If it designs the key risk indicator thresholds, it later audits its own work, which creates a self-review conflict and undermines the credibility of its assurance.

  1. AInternal audit would be reviewing a design it helped create, impairing its independence as the third lineCorrect
  2. BInternal audit lacks the technical skill to evaluate key risk indicators
  3. CThe second line would be unable to report to the board risk committee
  4. DThe first line would lose ownership of operational risk data

Explanation

The third line must remain independent of both the first and second lines. Designing risk indicator thresholds is a management responsibility, so auditing that same design later creates a self-review threat. Skill and reporting lines are not the core issue.

Did you get it right without looking?

One question tells you little. A timed set on Risk Governance shows your real accuracy, how long you take and where you lose marks.

More Risk Governance questions