The Three Lines of Defence (3LoD) model serves as the foundational structural framework for modern corporate governance. It establishes clear boundaries, responsibilities, and accountability measures across all operational layers of an enterprise. This framework prevents conflicts of interest and ensures that risk management activities are subject to objective validation.
[THE ORGANIZATION BASE: STRATEGIC OPERATION LAYER]
  │
  ├─► LINE 1: Front-Line Business Units (Owns, executes, and mitigates risks daily)
  │
  ├─► LINE 2: Risk Management & Compliance (Oversight, provides tools, challenges, tracks metrics)
  │
  └─► LINE 3: Internal & External Audit (Independent verification, reports directly to Board)

Line 1: Front-Line Business Operations
  • Functional Scope: Includes revenue-generating units, transactional operations teams, and customer-facing staff.
  • Core Responsibilities: Line 1 has direct ownership of risk. They are responsible for identifying, assessing, and mitigating operational risks within their daily workflows. They execute controls and maintain the baseline risk registers.
Line 2: Risk Management and Compliance
  • Functional Scope: Central Risk Management Department, Financial Crime Units, and Data Privacy Offices.
  • Core Responsibilities: Operates as an independent oversight function. Line 2 establishes the corporate risk policy frameworks, provides risk management tools (such as RCSA methodologies and KRI metrics), and tracks risk thresholds. They actively review and challenge Line 1’s self-assessments.
Line 3: Internal Audit
  • Functional Scope: Completely independent Internal Audit Department.
  • Core Responsibilities: Provides independent, objective assurance to the Board of Directors and Audit Committee. Line 3 evaluates the design and operating effectiveness of both Line 1’s control execution and Line 2’s oversight activities. Line 3 must remain free from operational management duties to preserve its auditing independence.

Â