CRMA Risk Management Governance 2 — Questions and Answers
Question 1: In the Three Lines of Defense model, which group is primarily responsible for owning and managing risks on a day-to-day basis?
- Internal audit
- Risk and compliance functions
- Business unit management (Correct answer)
- The board of directors
Correct answer: Business unit management
Business unit management (the first line) owns and manages risks as part of their operational responsibilities.
Question 2: Which governance body holds ultimate accountability for ensuring an effective enterprise risk management framework exists?
- Chief Risk Officer
- Risk Management Committee
- Board of Directors (Correct answer)
- Internal Audit Committee
Correct answer: Board of Directors
The board of directors bears ultimate accountability for the organization's risk governance framework.
Question 3: When a company separates the Risk Committee from the Audit Committee, what is the primary governance benefit?
- It reduces the total number of board meetings required
- It allows deeper focus on risk strategy versus financial reporting oversight (Correct answer)
- It transfers risk ownership from management to the board
- It ensures the CFO chairs both committees independently
Correct answer: It allows deeper focus on risk strategy versus financial reporting oversight
Separating the committees allows each to specialize — the Risk Committee focuses on strategic and operational risk while the Audit Committee focuses on financial reporting and controls.
Question 4: What is the most appropriate reporting line for a Chief Risk Officer (CRO) to maintain risk governance independence?
- Chief Financial Officer
- Chief Operating Officer
- Chief Executive Officer or Board Risk Committee (Correct answer)
- Chief Compliance Officer
Correct answer: Chief Executive Officer or Board Risk Committee
The CRO should report to the CEO or directly to the Board Risk Committee to maintain sufficient independence and authority.
Question 5: Under the Three Lines of Defense model, the second line's primary governance role is to:
- Execute transactions and control day-to-day operations
- Provide independent assurance to the board on risk management effectiveness
- Oversee, challenge, and support first-line risk management activities (Correct answer)
- Approve the annual risk appetite statement
Correct answer: Oversee, challenge, and support first-line risk management activities
The second line (risk and compliance functions) oversees, challenges, and supports the first line rather than owning operational risk directly.
Question 6: Which document formally establishes the authority, responsibilities, and composition of a board-level Risk Committee?
- Risk Register
- Risk Appetite Statement
- Committee Charter (Correct answer)
- Enterprise Risk Policy
Correct answer: Committee Charter
A committee charter defines the mandate, membership, authority, and reporting obligations of a board-level committee.
Question 7: A risk governance failure most commonly occurs when:
- The board requires quarterly risk reports instead of annual ones
- Risk ownership is unclear and accountability is not assigned to specific roles (Correct answer)
- Internal audit conducts risk assessments alongside management
- The CRO has a smaller team than the CFO
Correct answer: Risk ownership is unclear and accountability is not assigned to specific roles
Unclear risk ownership and absent accountability structures are the most common root causes of risk governance failures.
In the Three Lines of Defense model, which group is primarily responsible for owning and managing risks on a day-to-day basis?