Skip to content

FRM Part II · FRM Exam Part II · Risk Governance

A bank's internal audit department reports to the head of the retail banking division, which also owns many of the processes audit reviews. The audit plan for operational risk controls is also approved by that division head. Which conclusion is most consistent with the Basel principles on the third line of defence?

Independence is compromised. Internal audit must be independent of the units it reviews and should report to the board's audit committee. Staff competence, CORF review of the plan or first-line process knowledge cannot substitute for that structural independence required for third-line assurance.

  1. AIndependence is compromised; audit should report to the audit committee of the board and be free of influence from the units it reviewsCorrect
  2. BThe arrangement is acceptable if audit staff are well qualified
  3. CThe arrangement is acceptable provided the CORF reviews the audit plan
  4. DThe arrangement is acceptable because the first line understands its own processes best

Explanation

Audit coverage of the operational risk framework must be independent, with staff competent and not involved in developing the framework or the processes reviewed. Reporting to a business division head undermines that independence, and competence or CORF review does not cure it. Familiarity with processes is not a substitute for independence.

Did you get it right without looking?

One question tells you little. A timed set on Risk Governance shows your real accuracy, how long you take and where you lose marks.

More Risk Governance questions