CRISC - Governance - Section 1.8

Establish lines of defence that separate risk ownership, oversight and independent assurance.

Describe the three lines of defence model, distinguishing risk ownership in the first line, risk oversight in the second, and independent assurance provided by internal audit in the third. Apply this structure to evaluate whether an organisation's governance design adequately separates these responsibilities.

Lines of defenceRisk ownershipOversightInternal audit

Practice question for this objective

Free sampleGovernancemedium

An organisation is documenting how the three lines model allocates risk duties. Which statement correctly describes the role of each line?

  • AThe first line gives independent assurance, the second owns the risk, and the third sets policy and monitors the framework
  • BThe first line oversees and challenges, the second owns the risk daily, and the third defines the appetite for the business
  • CThe first line owns and manages the risk, the second provides oversight and challenge, and the third gives independent assurance Correct
  • DThe first line audits the controls, the second owns the risk, and the third reports findings straight to the audit committee
The three lines model places risk ownership in the first line, oversight in the second, and assurance in the third. The three lines model separates duties: operational management owns and manages risk, risk and compliance functions provide oversight and challenge, and internal audit delivers independent assurance. Keeping these distinct preserves objective assurance.

Why A is wrong: Tempting because each phrase is a real duty, but the lines are scrambled: assurance is the third line's role, not the first line's responsibility.

Why B is wrong: Plausible wording, yet ownership sits with the first line and appetite is set through governance, so the duties here are misassigned across lines.

Why C is correct: Correct because operational management owns the risk, the risk and compliance functions oversee and challenge, and internal audit provides independent assurance over both.

Why D is wrong: Auditing is the third line's job, not the first line's, so attaching the audit task to operational management misstates the model's structure.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Governance objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.