A municipal utility cites the three lines of defense in its charter and asks where day-to-day risk ownership sits versus independent assurance. Which placement is correct at overview depth?
Select an answer to reveal the explanation.
Short Explanation
Picture three fences around the same plant: the operators run the valves, the risk/compliance team watches the gauges, and audit walks the yard independently. Day-to-day ownership stays with the first line.
Full Explanation
The three lines of defense model places operational management as the first line owning risks and controls in the business. Risk and compliance functions form the second line for oversight, frameworks, and challenge. Internal audit provides the third line of independent assurance. Overview-level CIS-RC items expect that placement—not ITSM, VR, or TPRM as substitutes for the model.