Larsson, Q43 2017 Risk governance

I don’t understand the explanation or rationale for this question.

Can someone elaborate on this and the explanation?