A county IRM architect wants internal audit to reuse risk register data for engagement planning without making audit a second risk owner. Which architecture best preserves third-line independence?
Select an answer to reveal the explanation.
Short Explanation
Think of the risk register like a shared weather map: auditors can read the forecast without grabbing the steering wheel. Third-line work should reuse IRM data for planning, but engagements and workpapers stay on their own track so independence does not collapse into day-to-day risk ownership.
Full Explanation
Integrated Risk Management is designed so multiple lines of defense can share entities, risks, and controls. Architecture that lets audit consume risk posture while maintaining a distinct audit engagement and workpaper lifecycle preserves independence. Folding auditors into risk response ownership or forcing them to rebuild everything offline either blurs the third line or throws away the integration benefit.