Internal audit is the third line of defense, providing independent assurance regarding risk management, controls, and governance effectiveness.
According to CRISC and the Three Lines Model:
“Internal audit independently reviews risk management processes and provides feedback on the achievement of objectives.”
Risk management (second line) monitors, not audits. Senior leadership (first line) executes strategy. Thus, B is correct.
CRISC Reference: Domain 1 – IT Risk Governance, Topic: Three Lines Model Roles.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit