A compliance manager asks to score residual risk inside the same engagement where they designed the controls under review. Why is that a problem in IRM audit architecture?
Select an answer to reveal the explanation.
Short Explanation
The third line is the independent referee—not the coach grading their own plays. Audit has to assess risk and compliance work with independence, so the same person shouldn’t both design the controls and declare them assured. That’s three-lines architecture.
Full Explanation
In the three lines of defense model reflected in GRC/IRM positioning, internal audit is the third line and must remain objective when assessing first- and second-line risk and compliance activities. Collapsing compliance operator duties into audit judgment undermines independence. External-only staffing is not a hard rule, Entity Framework does not ban auditor read access, and continuous monitoring does not replace independent audit.