Three Lines of Defense Model - 30 Questions

CRISC Practice: 30 Three Lines of Defense Questions

CRISC Practice Questions

Three Lines of Defense Model - 30 Questions
Interactive Quiz
Question 1 of 30 0%
Score: 0
Correct: 0
Wrong: 0
1 Under the Three Lines of Defense model, who owns and manages risk on a day-to-day basis?
Answer: B - Operational Management (First Line) The First Line of Defense consists of operational management who own and manage risks as part of their daily activities. They are the primary risk takers and risk owners.
2 Which line of defense provides independent assurance over the effectiveness of risk management and internal controls?
Answer: C - Third Line The Third Line of Defense (Internal Audit) provides independent and objective assurance to the board and senior management on the effectiveness of governance, risk management, and internal controls.
3 The Second Line of Defense is BEST described as:
Answer: B - The function that provides oversight, guidance, and monitoring of risk The Second Line (e.g., risk management, compliance, security) provides expertise, oversight, guidance, and monitoring of risk. It supports but does not replace the First Line's risk ownership.
4 Which line of defense is responsible for implementing corrective actions when control weaknesses are identified?
Answer: A - First Line The First Line (operational management) owns the risk and is responsible for implementing corrective actions to address control weaknesses. The Second Line monitors and the Third Line verifies.
5 Independence is a KEY characteristic of which line of defense?
Answer: C - Third Line Independence is a critical characteristic of the Third Line (Internal Audit). Internal Audit must be independent of management to provide objective assurance. The Second Line can have some independence but still reports to management.
6 Which of the following is the PRIMARY role of the Second Line of Defense?
Answer: D - Monitoring, guidance, and oversight of risk The Second Line provides risk monitoring, guidance, policy development, and oversight. It complements but does not replace the First Line's risk ownership.
7 In the Three Lines of Defense model, who typically reports to the Board or Audit Committee?
Answer: A - The Third Line (Internal Audit) The Third Line (Internal Audit) reports functionally to the Board or Audit Committee to maintain independence. The First Line reports to operational management, and the Second Line typically reports to senior management or the CRO.
8 Which of the following BEST describes the relationship between the First and Second Lines of Defense?
Answer: B - The Second Line supports and monitors the First Line's risk management activities The Second Line supports the First Line by providing risk frameworks, guidance, and monitoring, but does NOT take over the First Line's risk ownership responsibilities.
9 A Chief Risk Officer (CRO) typically operates in which line of defense?
Answer: C - Second Line The Chief Risk Officer (CRO) and the risk management function typically operate as the Second Line of Defense, providing oversight and guidance on risk management.
10 Which line of defense is responsible for establishing risk appetite and tolerance levels?
Answer: D - Board of Directors / Senior Management The Board and senior management are responsible for setting risk appetite and tolerance. The Second Line often helps facilitate and communicate this, but the Board owns the decision.
11 Which of the following is a TYPICAL Second Line of Defense function?
Answer: B - Compliance monitoring and reporting Compliance monitoring and reporting are classic Second Line functions. Processing transactions and managing IT are First Line, while internal audit is Third Line.
12 What is the MAIN risk of having a weak First Line of Defense?
Answer: A - Risks may not be identified or managed at the source A weak First Line means risks are not managed where they originate. This pushes the burden to the Second and Third Lines, which is inefficient and increases overall risk exposure.
13 Which of the following BEST describes the Three Lines of Defense model?
Answer: C - A model that clarifies roles and responsibilities for risk management and control The Three Lines of Defense model clarifies roles and responsibilities for risk management and control across the organization. It does NOT replace external audit and applies across industries.
14 Which of the following is a KEY benefit of implementing the Three Lines of Defense model?
Answer: B - It provides clear accountability and reduces gaps/overlaps in risk management The primary benefit of the Three Lines model is clear accountability, reduced gaps and overlaps, and improved coordination of risk management activities across the organization.
15 In which line of defense would you typically find the information security function?
Answer: D - Usually Second Line, sometimes First Line depending on structure Information security is typically a Second Line function (providing oversight and guidance), but in some organizations it may be part of the First Line if it directly manages operational security controls.
16 Which line of defense is responsible for the design and implementation of internal controls?
Answer: A - First Line The First Line (operational management) is responsible for designing, implementing, and maintaining internal controls. The Second Line provides guidance and the Third Line evaluates effectiveness.
17 What is the MAIN purpose of the Third Line of Defense?
Answer: C - To provide independent assurance over the effectiveness of risk management and controls The Third Line (Internal Audit) provides independent, objective assurance to the Board and senior management on the effectiveness of governance, risk management, and internal controls.
18 A company's IT department implements security patches on servers. This activity belongs to which line of defense?
Answer: B - First Line Implementing security patches is an operational activity performed by the First Line (IT operations). The Second Line may set patch management policies, and the Third Line may audit compliance.
19 Which of the following is a CRITICAL success factor for the Three Lines of Defense model?
Answer: D - Clear coordination and communication among the three lines Clear coordination, communication, and defined roles among the three lines are critical to the model's success. This prevents gaps, overlaps, and confusion about risk ownership.
20 Which line of defense is MOST likely to identify a new regulatory requirement and communicate it to the organization?
Answer: B - Second Line The Second Line (compliance function) typically monitors regulatory changes and communicates requirements to the organization. The First Line implements them, and the Third Line audits compliance.
21 What is the PRIMARY risk of the Second Line taking over risk ownership from the First Line?
Answer: C - Accountability for risk becomes blurred and risk management becomes less effective If the Second Line takes over risk ownership, accountability becomes blurred. The First Line may disengage from risk management, leading to less effective risk management overall.
22 Which of the following BEST describes the role of the First Line in the Three Lines of Defense model?
Answer: A - Risk owner and risk taker The First Line owns and takes risks as part of executing business activities. They are responsible for managing risk on a day-to-day basis.
23 Which of the following is a TYPICAL Third Line of Defense activity?
Answer: D - Conducting independent audits and assessments Conducting independent audits and assessments is the primary activity of the Third Line (Internal Audit). Other options are First or Second Line activities.
24 In the Three Lines of Defense model, who is responsible for reporting significant risk issues to the Board?
Answer: B - Third Line, and senior management through governance channels The Third Line reports significant risk issues directly to the Board/Audit Committee. Senior management also reports through governance channels. The First Line reports to management, and the Second Line reports to senior management.
25 Which line of defense is MOST likely to conduct a risk assessment of a new business initiative?
Answer: C - First Line with support from Second Line The First Line conducts the risk assessment as the risk owner, often with support and guidance from the Second Line (risk management function). The Third Line may audit the process later.
26 Which of the following is a WEAKNESS of the Three Lines of Defense model?
Answer: A - It can create silos and confusion if roles are not clearly defined A common weakness of the Three Lines model is that it can create silos and confusion if roles and responsibilities are not clearly defined and communicated across the organization.
27 The Three Lines of Defense model was originally developed by which organization?
Answer: D - IIA (Institute of Internal Auditors) The Three Lines of Defense model was originally developed by the Institute of Internal Auditors (IIA) and has been widely adopted across industries and regulators globally.
28 A company's risk management function develops a risk register and monitors key risk indicators. This is an example of which line of defense?
Answer: B - Second Line Developing risk registers and monitoring key risk indicators are typical Second Line (risk management function) activities. The First Line owns the risks, and the Third Line audits the process.
29 Which of the following statements about the Three Lines of Defense model is CORRECT?
Answer: C - The First Line owns and manages risk, the Second Line provides oversight, and the Third Line provides independent assurance This is the core principle of the Three Lines of Defense model: First Line owns risk, Second Line provides oversight and guidance, and Third Line provides independent assurance.
30 In a small organization where separate lines may not be feasible, what is the BEST approach?
Answer: A - Apply the principles of the model with combined roles, ensuring independence of assurance is maintained In smaller organizations, roles may be combined, but the principles should still be applied. Independence of the assurance function (Third Line) must be maintained, even if it is outsourced or handled by the Board.
🏆

Quiz Complete!

0 / 30
0
Correct
0
Wrong
30
Total
Quick Reference Summary
Line of Defense Role Typical Functions
First Line Own and manage risk Operational management, business units, IT operations
Second Line Oversight, guidance, monitoring Risk management, compliance, security, quality
Third Line Independent assurance Internal audit

Exam Tips

  1. First Line = Owns risk. Operational management, day-to-day risk takers.
  2. Second Line = Monitors risk. Risk, compliance, and security functions providing oversight.
  3. Third Line = Assures risk. Internal Audit providing independent assurance to the Board.
  4. Independence is the key characteristic of the Third Line, not the Second Line.
  5. Clear coordination among the three lines is critical for the model to work effectively.

Post a Comment

0 Comments