Skip to content

FRM Part II · FRM Exam Part II · Risk Governance

A bank's operational risk framework uses the three lines of defense model. Which activity is most appropriately the responsibility of the second line of defense?

The second line of defense independently challenges the business units' risk and control self-assessments and monitors adherence to risk appetite. Owning risks is the first line, independent assurance is internal audit, and approving risk appetite belongs to the board.

  1. AOwning and managing operational risks arising in day-to-day business processes
  2. BIndependently challenging the business units' risk and control self-assessments and monitoring risk appetite adherenceCorrect
  3. CProviding independent assurance to the board on the effectiveness of governance and controls
  4. DApproving the bank's overall risk appetite statement as the final authority

Explanation

The second line (independent operational risk management function) designs the framework, challenges first-line assessments and monitors risk against appetite. Option A is the first line, option C is internal audit (third line), and option D is a board responsibility.

Did you get it right without looking?

One question tells you little. A timed set on Risk Governance shows your real accuracy, how long you take and where you lose marks.

More Risk Governance questions