
Ultimate access to all questions.
A community bank uses the three lines of defense approach to manage its operational risk exposures. The bank is in the process of implementing an enterprise risk management (ERM) framework, and the CRO decides to extend the three lines of defense approach to its implementation of ERM. The CRO also wants to ensure that the ERM framework appropriately reflects the bank's risk appetite and risk culture. Which of the following actions should the CRO recommend for the bank to take?
A
The third line of defense should continuously monitor the bank's implementation of its ERM framework to ensure its effectiveness.
B
Business line managers, as part of the first line of defense, should have the authority to take on risk exposures within the bank's risk appetite limits.
C
The bank should implement a set of risk culture indicators as part of its ERM framework in order to accurately quantify the losses that could occur due to failures of risk culture.
D
As part of the second line of defense, the executive committee should perform an independent review of the bank's risk management framework.