6.1 The Philosophy of Structural Defense Segregation
To prevent control gaps, conflicting duties, and internal blind spots, mature corporate governance requires the implementation of the Three Lines Model (originally formalized by the Institute of Internal Auditors – IIA). This structural model clearly assigns and separates risk management responsibilities across the entire organization.
It establishes a clear segregation of duties between day-to-day business operations, risk oversight teams, and independent audit functions, ensuring that no single executive can initiate transactions, override controls, and cover up process failures without detection.
6.2 Detailed Breakdown of the Three Defensive Lines
  • The First Line of Defense (Business Operations): Consists of front-line managers, operational teams, and sales divisions who directly execute core corporate processes. The first line owns and manages the risk. They are directly responsible for identifying vulnerabilities within their workflows and maintaining daily internal controls to operate within corporate appetite limits.
  • The Second Line of Defense (Risk and Compliance): Consists of specialized oversight functions that operate outside direct frontline operations, such as the ERM department, compliance offices, information security (CISO) groups, and quality control teams. The second line provides the frameworks, tools, and oversight. They do not own the risks; instead, they set the corporate risk methodologies, monitor the first line, challenge risk scores, and track compliance trends.
  • The Third Line of Defense (Internal Audit): Comprised of the Internal Audit Function, which maintains absolute structural independence from both first-line operations and second-line oversight teams. Internal audit provides independent, objective assurance directly to the Board Audit Committee, bypassing standard executive lines to evaluate how effectively the entire first and second lines are functioning.
6.3 Managing Governing Body Oversight and Senior Management Realities
The entire Three Lines architecture is overseen by the Governing Body (Board of Directors), which sets the strategy, defines the risk appetite, and receives unfiltered reports directly from the third line to monitor corporate health. Senior Management receives operational updates from the first and second lines to guide capital deployment and project execution.
By maintaining clear reporting and communication paths across these layers, the organization ensures that risk data flows smoothly to corporate leaders, supporting informed governance and rapid response deployment.