Three Lines of Defense
The Three Lines of Defense is a way of organizing who is responsible for managing risk within an organization by dividing responsibilities across three groups, or 'lines.' The first line owns and manages risk day to day, the second line oversees and monitors risk, and the third line provides independent assurance, typically through internal audit. It is a framework for structuring accountability rather than a technical control, and different organizations may adapt it in different ways.
The Three Lines of Defense is a risk governance framework that assigns and separates accountability for risk management across three distinct roles: the first line, comprising operational functions that own and directly manage risks; the second line, comprising risk management and compliance functions that provide oversight, set policy, and monitor the first line; and the third line, comprising internal audit or an equivalent function that provides independent assurance over the effectiveness of the first two lines. The framework is intended to clarify responsibilities and reduce gaps or overlaps in risk oversight; it structures accountability but does not by itself measure or eliminate risk. The Institute of Internal Auditors (IIA) issued an updated formulation in July 2020 termed the 'Three Lines Model,' which reframes the original 'three lines of defense' language toward supporting governance and objective achievement rather than a purely defensive posture. Practitioners should note that specific role definitions, the degree of independence expected of each line, and how the model maps to particular AI governance or model risk management structures can vary by organization and sector, and application to AI-specific oversight is an evolving area not fully detailed in the evidence provided.
Why it matters
The Three Lines of Defense addresses a recurring failure mode in organizations: when responsibility for managing risk is diffuse or overlapping, risks can fall between functions unnoticed, or multiple functions may assume someone else is accountable. By separating who owns risk day to day, who oversees and monitors it, and who provides independent assurance, the framework is intended to reduce gaps and overlaps in oversight and to clarify accountability. This clarity matters most in regulated environments and in areas of rapidly evolving risk, where ambiguity about ownership can allow problems to persist until they become material.
For AI governance and model risk management, the framework offers a familiar structure onto which AI-specific oversight roles can be mapped: model developers and business owners in the first line, model risk and compliance functions in the second, and internal audit in the third. However, practitioners should treat this mapping as an adaptation rather than a settled standard. How the model applies to AI-specific oversight is an evolving area not fully detailed in established formulations, and the degree of independence expected of each line can vary by organization and sector.
It is important to recognize what the framework does and does not do. The Three Lines of Defense structures accountability; it does not by itself measure, quantify, or eliminate risk. A well-drawn organizational chart of three lines can coexist with weak controls if the lines lack the resources, independence, or authority to perform their roles effectively. The framework should therefore be understood as one component of a broader risk governance approach, not as a substitute for substantive risk identification, measurement, and control.
Who it's relevant to
Inside 3LOD
Common questions
Answers to the questions practitioners most commonly ask about 3LOD.