Skip to content

FRM Part II · FRM Exam Part II · Introduction to Operational Risk and Resilience

A bank's operational risk management function designs the risk and control self-assessment framework, sets risk appetite metrics, aggregates loss data and challenges business unit risk ratings, but does not own the controls in the business units. Which description of this function is most accurate?

This is the second line of defense. It designs the framework, sets and monitors appetite metrics, aggregates data and challenges the business, yet does not own business controls. The third line is internal audit, which independently assures the effectiveness of both the first and second lines.

  1. AIt is the second line of defense, providing independent oversight and challengeCorrect
  2. BIt is the first line of defense because it designs the framework
  3. CIt is the third line of defense because it is independent of the business
  4. DIt is part of internal audit because it challenges business unit ratings

Explanation

The second line develops the framework, monitors and challenges the first line, and reports on risk, while not owning the business controls. The third line, internal audit, independently assures the effectiveness of both the first and second lines. Independence from the business alone does not make a function the third line.

Did you get it right without looking?

One question tells you little. A timed set on Introduction to Operational Risk and Resilience shows your real accuracy, how long you take and where you lose marks.

More Introduction to Operational Risk and Resilience questions