Certified in Risk and Information Systems Control (CRISC) — Question 1153
Which of the following is a PRIMARY benefit to an organization adopting a three lines of defense model?
Answer options
- A. It establishes clear communication among stakeholders.
- B. It outlines a control layering approach.
- C. It provides a risk governance structure.
- D. It enforces a strong risk culture.
Correct answer: C
Explanation
The correct answer is C, as a three lines of defense model is specifically designed to establish a structured approach to risk governance. While options A, B, and D may be benefits of the model, they do not encapsulate its primary purpose as clearly as option C does.