According to industry best practices, different members assume different responsibilities in risk appetite governance. Which of the following statements is least correct?
A.Controls owners are responsible for the design, implementation, and effectiveness of the controls.
B.Risk owners are the second line of defense.
C.Risk owners are the managers responsible for managing, maintaining, and monitoring the risks with the stated limits of appetite and tolerance.
D.Metrics owners are responsible for the collection, reporting and monitoring of the metrics capturing the performance of the organization with regards to risk appetite.
B is correct.
考点:Risk Appetite Governance
解析:Risk owners属于第一道防线,而不是第二道防线。故选项B不正确,当选。
risk owners是一道防线,那control owners和metric owners分别是什么岗位,属于哪道防线?