Do you think the second line of defense should also do testing?
Sigiloso
Yes, I think every level has a responsibility to determine whether relevant risks are addressed and control objectives met. It may not be in the form similar to each level but there should be accountability.