The Three Lines of Defense model provides a clear structure for assigning risk management responsibilities across an organization, preventing gaps and duplication of effort.
The Three Lines Responsibility Matrix
The framework splits risk ownership into three clear operational layers, ensuring independent oversight:
  Defense Layer   |   Operational Governance Function |   Core Risk Management Responsibility
------------------+-----------------------------------+-----------------------------------------
  1st Line        |   Front-Line Business Operations  |   Owns and executes daily risk controls
  2nd Line        |   Risk Management & Compliance    |   Sets policy boundaries and monitors risk
  3rd Line        |   Independent Internal Audit      |   Provides objective, third-party validation

  • First Line of Defense: Front-line business units and operational managers. They interact with risks directly and are responsible for executing daily controls and maintaining compliance check-lists.
  • Second Line of Defense: The specialized risk management and compliance functions. They design the risk frameworks, set policy boundaries, monitor metrics, and provide risk management expertise to the business units.
  • Third Line of Defense: Internal audit. Operating completely independently, this team reports directly to the board, providing an objective assessment of how effectively the first two lines of defense are performing. [1, 2, 3]

Â