Certified in Risk and Information Systems Control (CRISC) — Question 752
To reduce costs, an organization is combining the second and third lines of defense in a new department that reports to a recently appointed C-level executive.
Which of the following is the GREATEST concern with this situation?
Answer options
- A. The risk governance approach of the second and third lines of defense may differ.
- B. The independence of the internal third line of defense may be compromised.
- C. The new structure is not aligned to the organization's internal control framework.
- D. Cost reductions may negatively impact the productivity of other departments.
Correct answer: B
Explanation
The greatest concern is that the independence of the internal third line of defense may be compromised, as merging these lines can lead to conflicts of interest and reduced objectivity in assessments. While differing governance approaches (A) and misalignment with the control framework (C) are valid issues, they are secondary to the impact on independence. Although cost reductions affecting productivity (D) is a concern, it does not directly relate to the integrity of the defense lines.