Skip to content

FRM Part I · FRM Exam Part I · The Governance of Risk Management

In the three lines of defense model commonly used in risk governance, which activity is the responsibility of the second line?

The second line of defense, risk management and compliance, establishes risk policies and independently monitors and reports on exposures. The first line owns and manages risk in the business, while the third line, internal audit, provides independent assurance.

  1. AIndependently assuring the board that the risk framework operates effectively
  2. BOwning and managing risks day to day within the business units
  3. CEstablishing risk policies and independently monitoring and reporting on risk exposuresCorrect
  4. DExecuting trades within approved limits

Explanation

The first line (business units) owns and manages risk. The second line (risk management and compliance) sets policies, monitors and reports independently. The third line (internal audit) provides independent assurance on the framework.

Did you get it right without looking?

One question tells you little. A timed set on The Governance of Risk Management shows your real accuracy, how long you take and where you lose marks.

More The Governance of Risk Management questions