The Principles for Risk Governance, as established by PRMIA (Professional Risk Managers'
International Association), emphasize the Three Lines of Defense (3LoD) Model, which is widely used
in risk management and governance frameworks.
Business Line Ownership of Risk (First Line of Defense)
The business units are responsible for identifying, assessing, managing, and monitoring risks within
their operations.
Since they generate the risks through their activities, they must own the risk assessment process.
This aligns with PRMIA Governance Principles, which state that risk management should be
embedded within business operations to ensure proactive risk identification and control.
Risk Management’s Role (Second Line of Defense)
The risk management function is not directly responsible for conducting risk assessments but plays a
key role in designing and maintaining the risk assessment framework.
This includes setting standards, methodologies, and tools for assessing risks across business
functions.
Risk management provides supervision and oversight, ensuring that risk assessments align with
organizational policies and regulatory expectations.
Oversight from Senior Management & the Board (Third Line of Defense)
Internal audit (third line of defense) independently reviews and provides assurance that the risk
management framework is effective and that risk assessments are conducted properly.
PRMIA’s Risk Governance Standards emphasize that internal audit should evaluate the effectiveness
of the risk assessment framework without being involved in its direct execution.
Why Other Answers Are Incorrect
Option
Explanation
A . Risk management, in its role as second line of
defense, performs the risk assessment process from
beginning to end. There is no business line
involvement.
Incorrect – Risk management facilitates and
oversees the risk assessment process, but the
business must take ownership of the risks it
generates.
Incorrect – While the business owns the process,
risk management plays a crucial role in developing
the framework, setting policies, and providing
oversight.
C . Business owns the risk assessment process so
risk management does not play a role in the
process.
Incorrect – Business management is actively
responsible for executing risk assessments, not just
overseeing them.
D . Business management's role in the risk
assessment process should be confined to oversight.
PRMIA Reference for Verification
PRMIA Standards for Risk Governance – Establishes the Three Lines of Defense and the separation of
responsibilities.
PRMIA Risk Management Framework (RMF) Guidelines – Defines the roles of business and risk
management in risk assessment.
PRMIA Enterprise Risk Management Best Practices – Outlines how risk management facilitates risk
assessments while the business retains ownership.
This answer is verified according to PRMIA’s official risk governance documents and best practices.
Would you like additional clarification or supporting documentation