29. As emphasized in the Basel Committee guidance for 'Sound management of risks related to money laundering and financing of terrorism', the third line of defense, or audit function, should:

Answer: C

Explanation:

The third line of defense, or audit function, should report to the audit committee of the board of directors to maintain independence.

Reporting to the audit committee of the board of directors ensures that the audit function operates independently and can effectively oversee the adequacy of the AML program without any conflicts of interest.

A) be involved in the day-to-day operations of the AML program to immediately prevent control failures.

While involvement in daily operations might offer immediate oversight, it compromises the independence of the audit function. The third line of defense should maintain a level of detachment to provide unbiased evaluations of the AML program rather than direct involvement in its execution.

B) remain independent from expressing opinions on the sufficiency of remediation or action plans to address findings and recommendations.

This option incorrectly suggests that the audit function should not provide opinions on remediation efforts. In fact, expressing opinions on the sufficiency of such plans is an essential part of the audit role to ensure that issues identified are adequately addressed.

D) conduct AML audits no less often than every 12 months for consistency in annual reporting.

While conducting audits regularly is important, this option does not directly address the independence of the audit function. The primary focus should be on reporting structures rather than the frequency of audits, which can vary based on organizational needs and risks.

Conclusion

The correct answer emphasizes the importance of independence in the audit function, which is crucial for effective oversight of the AML program. Options A, B, and D either compromise this independence or do not align with the core principles set forth by the Basel Committee regarding the third line of defense. Thus, C stands out as the definitive choice for maintaining the integrity of the audit process.