Â
This lesson explores the industry-standard model for organising risk management and internal control functions within a bank, defining distinct roles and responsibilities.
2.1 The Architecture of the ICS
The modern ICS is structured as a pyramid or “Three Lines of Defense” model with distinct yet complementary responsibilities and functions. The model ensures compliance with regulations and internal policies, with each line having a specific role.
2.2 The First Line of Defense: Operational Management
The first line comprises the operational units and business lines that own and manage risk on a day-to-day basis. These are the front-line staff, such as the loan origination team or trading desk. Their responsibilities include:
-
First-level Controls:Â Integrating controls into daily operational procedures, such as the back office, to ensure the correct application of procedures and compliance of transactions.
-
Initial Risk Identification:Â Identifying and monitoring risks inherent in their activities.
-
Operational Monitoring:Â Continuous observation of portfolio quality, borrower behaviour, and early warning signals.
They are ultimately responsible for performing first-line operational risk management activities, including regular self-assessments of key controls.
2.3 The Second Line of Defense: Risk and Compliance Functions
The second line provides oversight and support to the first line. It comprises specialist control functions, including:
-
Risk Management:Â Oversees the identification, measurement, monitoring, and reporting of risks. This function has evolved towards proactive and integrated risk management, which today includes climate and environmental factors. It is responsible for defining the Risk Appetite Framework (RAF).
-
Compliance:Â Responsible for ensuring compliance with applicable regulations and preventing non-compliance risks. It ensures the implementation of regulatory provisions and prepares reports for corporate bodies.
-
AML/CFT:Â Oversees anti-money laundering and countering the financing of terrorism activities, with the aim of preventing the introduction of illicit funds into the financial system.
-
ICT Risk:Â Monitors and mitigates technological and cybersecurity risks.
2.4 The Third Line of Defense: Internal Audit
The third line is the Internal Audit function, which provides independent assurance. It is responsible for verifying the completeness, functionality, and overall adequacy of the ICS and may analyse agreements, processes, and internal governance mechanisms to ensure they are robust, effective, and applied consistently. Internal audit conducts fully independent reviews of the overall effectiveness of the ICS, checking that the second-line functions are operating as intended.
2.5 Integrated Approach and Responsibility
Ultimately, responsibility for the supervision and monitoring of internal controls and the governance framework lies with the management body, exercising its strategic oversight function, while the corporate body with control functions oversees the overall functioning of the ICS. Effective collaboration between control functions is essential for effective management.