In the three lines model (formerly three lines of defense), thesecond lineprovides risk management, compliance oversight, and specialized support to the first line (operational management). One of its key responsibilities is monitoring the risk environment andalerting operational management to emerging issues—such as new regulatory requirements, changes in risk levels, and control weaknesses—while advising on appropriate responses. Implementing corrective actions is primarily the responsibility of the first line, which owns the processes. Owning risk scenarios and bearing loss consequences are first-line management responsibilities. Performing duties independently to provide assurance is the role of the third line (internal audit), which maintains organizational independence. Thus, the function of monitoring and advising, including escalation of emerging issues, aligns directly with the mandate of the second line.
[Reference:CRISC Review Manual – Governance (three lines model roles and responsibilities)., ===========, ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit