This model governs how an organization distributes financial crime prevention duties across separate banking departments to ensure overlapping layers of protection:
[BOARD OF DIRECTORS / AUDIT COMMITTEE]
                 |
  +--------------+--------------+

  |                             |
  v                             v
[1st LINE OF DEFENCE]     [2nd LINE OF DEFENCE]     [3rd LINE OF DEFENCE]
Front-Line Operations     Financial Crime Comp.     Internal Audit Team
  - Relationship Managers   - Models & Algorithms     - Independent Testing
  - Intake Clerks           - Enhanced Due Diligence  - System Validation
  - Basic Screening         - SAR/STR Filing          - Board-Direct Reports

  • 1st Line of Defence (Front-Line Operations): Consists of trade finance originators, relationship managers, and letter-of-credit intake clerks. They own the risk at the point of origin, executing basic Know Your Customer (KYC) identity verification, checking document completeness, and flagging obvious client or behavioral anomalies during initial transaction capture.
  • 2nd Line of Defence (Financial Crime Compliance): Consists of the Financial Crime Compliance (FCC) Unit and Corporate Risk Management. This department is structurally independent of commercial targets. They design active transaction monitoring models, tune price anomaly thresholds (e.g., IQR limits), run enhanced due diligence (EDD) on escalated clients, and file Suspicious Activity Reports (SARs).
  • 3rd Line of Defence (Internal Audit): Consists of the Internal Audit team, reporting directly to the Board of Directors. This unit provides completely independent, periodic testing of both the 1st and 2nd lines’ operational effectiveness. They verify that screening algorithms are properly calibrated, audit look-back files, and ensure that compliance policy exceptions are not systematically abused by the business lines