
Answer-first summary for fast verification
Answer: The bank considers independent review and audit of the risk processes and systems as the third line of defense.
## Explanation According to Basel II and Basel III operational risk governance frameworks: - **Option A is incorrect**: Identification and management of risk is the **first line of defense** (business units), not the second line. - **Option B is correct**: Independent review and audit of risk processes and systems is indeed the **third line of defense** under Basel frameworks. The three lines of defense are: 1. First line: Business units that own and manage risks 2. Second line: Risk management and compliance functions 3. Third line: Internal audit - **Option C is incorrect**: Damaged reputation due to a failed merger is typically considered a **strategic risk**, not operational risk. Operational risk is defined as the risk of loss resulting from inadequate or failed internal processes, people, and systems or from external events. - **Option D is incorrect**: Destruction by fire or other external catastrophes is explicitly included in the definition of operational risk under Basel frameworks as "external events." The correct answer is B because it accurately reflects the Basel operational risk governance framework where independent audit functions serve as the third line of defense.
Author: LeetQuiz .
Ultimate access to all questions.
The CEO of a large bank has reported that the bank's framework for managing operational risk are consistent with Basel II and Basel III model for operation risk governance. Which of the following actions and principles of the bank is correct?
A
The bank considers identification and management of risk as the second line of defense.
B
The bank considers independent review and audit of the risk processes and systems as the third line of defense.
C
The bank includes damaged reputation due to a failed merger in its measurement of operational risk.
D
The bank excludes destruction by fire or other external catastrophes from its measurement of operational risk.
No comments yet.