Enterprise Risk Management in Practice
A Practitioner's Course
Session Three
The Three Lines Model
How risk responsibility is distributed across an institution, what genuine independence looks like in oversight and assurance, and how the model most often breaks down in practice
|
Disclaimer This course is provided for general information and education only. It is not legal advice. Legislation, regulatory rules, and supervisory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation. |
Session Three: The Three Lines Model
The Institute of Internal Auditors released the Three Lines Model in 2020 as an update to the earlier Three Lines of Defence framing. The model places more emphasis on governance, value creation, and clear accountability. The IIA has since updated the position paper to align terminology with its current internal audit standards, but the central distinction remains: management owns and manages risk, while internal audit provides independent assurance.
This session uses the Three Lines Model as a governance reference point rather than as a statutory framework. It does not depend on a specific legal provision. Where a jurisdiction has its own prudential or conduct rules, those rules prevail over the model.
First line: business management
The first line comprises the business units and functions that create risk. They are responsible for identifying, assessing, and managing risks within their area of activity, and for implementing the controls that keep those risks within agreed limits.
First-line ownership of risk is a foundational principle, not a formality. The people closest to the activity that creates a risk are usually best placed to manage it. A lending decision, trading position, or technology change is a first-line risk decision. Second-line oversight can challenge, guide, and escalate, but it cannot substitute for the first line owning the outcome.
Second line: risk and compliance oversight
The second line provides the frameworks, policies, tools, and oversight that support first-line risk management. This includes the risk management function, the compliance function, and specialist functions such as financial crime, model risk, and information security. The second line sets standards and monitors whether the first line is operating within them.
The second line does not own the risks it oversees. Once that distinction blurs, accountability becomes unclear: the second line starts making first-line decisions, or the first line treats second-line approval as risk management. Ownership stays with the first line. Oversight sits with the second.
Third line: internal audit
The third line provides independent assurance that the first and second lines are functioning as intended. Internal audit should have a direct reporting line to the board or audit committee, giving the board confidence that the risk management framework is effective, not just documented.
The independence of internal audit from management is essential to its value. An audit function that reports into the business it audits will struggle to provide genuine assurance, whatever its findings say. Independence requires access to organisational resources, personnel, and data, and protection from interference in how audits are planned and executed.
External assurance
Beyond the three internal lines, external auditors and regulators provide additional assurance. External audit gives assurance on financial reporting. Regulators assess whether the institution is meeting its prudential and conduct obligations. These external checks complement the internal framework, but they are not a substitute for it. A regulator's supervisory review happens periodically and from outside, while the three lines operate continuously and from inside the institution.
Where the model breaks down
A common failure of the Three Lines Model is the second line being absorbed into the first. The risk function exists on paper to provide independent oversight. In practice, it may report to people with commercial incentives, sit too close to the business units it is meant to oversee, or be resourced in ways that make effective challenge difficult.
Independence in that situation exists as a job title, not as a working reality. The fix is structural, not aspirational: reporting lines that preserve escalation to the CRO and ultimately the board, remuneration that does not depend on the commercial performance of the unit being overseen, and a culture that treats second-line challenge as useful rather than obstructive.
A parallel failure affects the third line. Internal audit that is under-resourced, staffed mainly by short-term rotations, or restricted from reviewing the areas it needs to see, produces assurance that looks complete on paper and tells the board very little in practice.
|
Key takeaways from Session Three
|
Coming up in Session Four
Session Four covers the regulatory capital framework: the Basel standards from their origins through to the finalised Basel III reforms, and what jurisdictional divergence means for internationally active institutions.
Further reading and resources
Institute of Internal Auditors, The Three Lines Model. The IIA position paper explains the roles of the governing body, management, and internal audit, and how those roles support governance, risk management, assurance, and value creation. Available at theiia.org.
Enterprise Risk Management in Banking. The published Ārai Tika guide this session draws on, with a fuller treatment of the model's principles and roles. Available at araitika.com.