CORES Internal Audit & Three Lines of Defense 1 — Questions and Answers
Question 1: In the Three Lines of Defense model, which line is primarily responsible for owning and managing operational risks on a day-to-day basis?
- Internal Audit
- Risk Management and Compliance functions
- Business units and operational management (Correct answer)
- Board of Directors
Correct answer: Business units and operational management
The first line of defense consists of business units and operational management who own the risks inherent in their activities and are responsible for implementing controls.
Question 2: Which of the following BEST describes the role of the second line of defense in the Three Lines of Defense model?
- Executing business processes and transactions
- Providing independent assurance to the board
- Overseeing and challenging the first line's risk management activities (Correct answer)
- Setting strategic direction for the organization
Correct answer: Overseeing and challenging the first line's risk management activities
The second line (risk management, compliance, legal) provides oversight, frameworks, and challenge to the first line without taking ownership of the risks themselves.
Question 3: What is the defining characteristic that distinguishes the third line of defense from the second line?
- Greater technical expertise in risk management
- Organizational independence from management and risk-taking activities (Correct answer)
- Direct authority to remediate control deficiencies
- Responsibility for setting the risk appetite
Correct answer: Organizational independence from management and risk-taking activities
Internal audit (third line) derives its value from organizational independence, reporting to the audit committee and board rather than to management functions it reviews.
Question 4: Under the IIA's Three Lines Model (2020 update), which body is positioned OUTSIDE the three lines and provides governing oversight?
- Chief Risk Officer
- Compliance function
- Governing body (Board) (Correct answer)
- External auditors
Correct answer: Governing body (Board)
The 2020 IIA model places the governing body (board) outside and above the three lines, accountable to stakeholders and responsible for overseeing the entire governance structure.
Question 5: A bank's operational risk manager in the second line discovers a significant control weakness identified by a first-line business unit. What is the MOST appropriate immediate action?
- Remediate the control weakness directly without notifying business management
- Log the finding, require a remediation plan from the first line, and track progress (Correct answer)
- Escalate immediately to external auditors
- Transfer the risk to a third-party insurer
Correct answer: Log the finding, require a remediation plan from the first line, and track progress
The second line's role is to challenge and oversee, requiring the first line to own remediation while the second line monitors and escalates if progress stalls.
Question 6: Which concept describes the risk that internal controls fail to prevent or detect material errors or fraud, often assessed during operational risk reviews?
- Residual risk
- Control risk (Correct answer)
- Inherent risk
- Systemic risk
Correct answer: Control risk
Control risk is the probability that a material misstatement or failure will not be prevented or detected by the entity's internal control system.
Question 7: In a well-functioning Three Lines of Defense model, coordination between lines is BEST achieved through:
- Allowing each line to operate in isolation to preserve independence
- Structured communication protocols and shared risk reporting platforms (Correct answer)
- Having internal audit perform second-line oversight functions
- Delegating all risk decisions to the first line without challenge
Correct answer: Structured communication protocols and shared risk reporting platforms
Effective coordination requires formal communication, shared reporting tools, and periodic joint reviews while preserving each line's distinct role and independence.
In the Three Lines of Defense model, which line is primarily responsible for owning and managing operational risks on a day-to-day basis?