CRISC Practice Questions
Three Lines of Defense Model - 30 Questions
Interactive Quiz
Question 1 of 30
0%
Score: 0
Correct: 0
Wrong: 0
1 Under the Three Lines of Defense model, who owns and manages risk on a day-to-day basis?
Answer: B - Operational Management (First Line)
The First Line of Defense consists of operational management who own and manage risks as part of their daily activities. They are the primary risk takers and risk owners.
2 Which line of defense provides independent assurance over the effectiveness of risk management and internal controls?
Answer: C - Third Line
The Third Line of Defense (Internal Audit) provides independent and objective assurance to the board and senior management on the effectiveness of governance, risk management, and internal controls.
3 The Second Line of Defense is BEST described as:
Answer: B - The function that provides oversight, guidance, and monitoring of risk
The Second Line (e.g., risk management, compliance, security) provides expertise, oversight, guidance, and monitoring of risk. It supports but does not replace the First Line's risk ownership.
4 Which line of defense is responsible for implementing corrective actions when control weaknesses are identified?
Answer: A - First Line
The First Line (operational management) owns the risk and is responsible for implementing corrective actions to address control weaknesses. The Second Line monitors and the Third Line verifies.
5 Independence is a KEY characteristic of which line of defense?
Answer: C - Third Line
Independence is a critical characteristic of the Third Line (Internal Audit). Internal Audit must be independent of management to provide objective assurance. The Second Line can have some independence but still reports to management.
6 Which of the following is the PRIMARY role of the Second Line of Defense?
Answer: D - Monitoring, guidance, and oversight of risk
The Second Line provides risk monitoring, guidance, policy development, and oversight. It complements but does not replace the First Line's risk ownership.
7 In the Three Lines of Defense model, who typically reports to the Board or Audit Committee?
Answer: A - The Third Line (Internal Audit)
The Third Line (Internal Audit) reports functionally to the Board or Audit Committee to maintain independence. The First Line reports to operational management, and the Second Line typically reports to senior management or the CRO.
8 Which of the following BEST describes the relationship between the First and Second Lines of Defense?
Answer: B - The Second Line supports and monitors the First Line's risk management activities
The Second Line supports the First Line by providing risk frameworks, guidance, and monitoring, but does NOT take over the First Line's risk ownership responsibilities.
9 A Chief Risk Officer (CRO) typically operates in which line of defense?
Answer: C - Second Line
The Chief Risk Officer (CRO) and the risk management function typically operate as the Second Line of Defense, providing oversight and guidance on risk management.
10 Which line of defense is responsible for establishing risk appetite and tolerance levels?
Answer: D - Board of Directors / Senior Management
The Board and senior management are responsible for setting risk appetite and tolerance. The Second Line often helps facilitate and communicate this, but the Board owns the decision.
11 Which of the following is a TYPICAL Second Line of Defense function?
Answer: B - Compliance monitoring and reporting
Compliance monitoring and reporting are classic Second Line functions. Processing transactions and managing IT are First Line, while internal audit is Third Line.
12 What is the MAIN risk of having a weak First Line of Defense?
Answer: A - Risks may not be identified or managed at the source
A weak First Line means risks are not managed where they originate. This pushes the burden to the Second and Third Lines, which is inefficient and increases overall risk exposure.
13 Which of the following BEST describes the Three Lines of Defense model?
Answer: C - A model that clarifies roles and responsibilities for risk management and control
The Three Lines of Defense model clarifies roles and responsibilities for risk management and control across the organization. It does NOT replace external audit and applies across industries.
14 Which of the following is a KEY benefit of implementing the Three Lines of Defense model?
Answer: B - It provides clear accountability and reduces gaps/overlaps in risk management
The primary benefit of the Three Lines model is clear accountability, reduced gaps and overlaps, and improved coordination of risk management activities across the organization.
15 In which line of defense would you typically find the information security function?
Answer: D - Usually Second Line, sometimes First Line depending on structure
Information security is typically a Second Line function (providing oversight and guidance), but in some organizations it may be part of the First Line if it directly manages operational security controls.
16 Which line of defense is responsible for the design and implementation of internal controls?
Answer: A - First Line
The First Line (operational management) is responsible for designing, implementing, and maintaining internal controls. The Second Line provides guidance and the Third Line evaluates effectiveness.
17 What is the MAIN purpose of the Third Line of Defense?
Answer: C - To provide independent assurance over the effectiveness of risk management and controls
The Third Line (Internal Audit) provides independent, objective assurance to the Board and senior management on the effectiveness of governance, risk management, and internal controls.
18 A company's IT department implements security patches on servers. This activity belongs to which line of defense?
Answer: B - First Line
Implementing security patches is an operational activity performed by the First Line (IT operations). The Second Line may set patch management policies, and the Third Line may audit compliance.
19 Which of the following is a CRITICAL success factor for the Three Lines of Defense model?
Answer: D - Clear coordination and communication among the three lines
Clear coordination, communication, and defined roles among the three lines are critical to the model's success. This prevents gaps, overlaps, and confusion about risk ownership.
20 Which line of defense is MOST likely to identify a new regulatory requirement and communicate it to the organization?
Answer: B - Second Line
The Second Line (compliance function) typically monitors regulatory changes and communicates requirements to the organization. The First Line implements them, and the Third Line audits compliance.
21 What is the PRIMARY risk of the Second Line taking over risk ownership from the First Line?
Answer: C - Accountability for risk becomes blurred and risk management becomes less effective
If the Second Line takes over risk ownership, accountability becomes blurred. The First Line may disengage from risk management, leading to less effective risk management overall.
22 Which of the following BEST describes the role of the First Line in the Three Lines of Defense model?
Answer: A - Risk owner and risk taker
The First Line owns and takes risks as part of executing business activities. They are responsible for managing risk on a day-to-day basis.
23 Which of the following is a TYPICAL Third Line of Defense activity?
Answer: D - Conducting independent audits and assessments
Conducting independent audits and assessments is the primary activity of the Third Line (Internal Audit). Other options are First or Second Line activities.
24 In the Three Lines of Defense model, who is responsible for reporting significant risk issues to the Board?
Answer: B - Third Line, and senior management through governance channels
The Third Line reports significant risk issues directly to the Board/Audit Committee. Senior management also reports through governance channels. The First Line reports to management, and the Second Line reports to senior management.
25 Which line of defense is MOST likely to conduct a risk assessment of a new business initiative?
Answer: C - First Line with support from Second Line
The First Line conducts the risk assessment as the risk owner, often with support and guidance from the Second Line (risk management function). The Third Line may audit the process later.
26 Which of the following is a WEAKNESS of the Three Lines of Defense model?
Answer: A - It can create silos and confusion if roles are not clearly defined
A common weakness of the Three Lines model is that it can create silos and confusion if roles and responsibilities are not clearly defined and communicated across the organization.
27 The Three Lines of Defense model was originally developed by which organization?
Answer: D - IIA (Institute of Internal Auditors)
The Three Lines of Defense model was originally developed by the Institute of Internal Auditors (IIA) and has been widely adopted across industries and regulators globally.
28 A company's risk management function develops a risk register and monitors key risk indicators. This is an example of which line of defense?
Answer: B - Second Line
Developing risk registers and monitoring key risk indicators are typical Second Line (risk management function) activities. The First Line owns the risks, and the Third Line audits the process.
29 Which of the following statements about the Three Lines of Defense model is CORRECT?
Answer: C - The First Line owns and manages risk, the Second Line provides oversight, and the Third Line provides independent assurance
This is the core principle of the Three Lines of Defense model: First Line owns risk, Second Line provides oversight and guidance, and Third Line provides independent assurance.
30 In a small organization where separate lines may not be feasible, what is the BEST approach?
Answer: A - Apply the principles of the model with combined roles, ensuring independence of assurance is maintained
In smaller organizations, roles may be combined, but the principles should still be applied. Independence of the assurance function (Third Line) must be maintained, even if it is outsourced or handled by the Board.
🏆
Quiz Complete!
0 / 30
0
Correct
0
Wrong
30
Total
Quick Reference Summary
| Line of Defense | Role | Typical Functions |
|---|---|---|
| First Line | Own and manage risk | Operational management, business units, IT operations |
| Second Line | Oversight, guidance, monitoring | Risk management, compliance, security, quality |
| Third Line | Independent assurance | Internal audit |
Exam Tips
- First Line = Owns risk. Operational management, day-to-day risk takers.
- Second Line = Monitors risk. Risk, compliance, and security functions providing oversight.
- Third Line = Assures risk. Internal Audit providing independent assurance to the Board.
- Independence is the key characteristic of the Third Line, not the Second Line.
- Clear coordination among the three lines is critical for the model to work effectively.
0 Comments