Skip to main content
Category: Roles & Accountability

Three Lines of Defense

Also known as: 3LOD, 3LoD, Three Lines Model, Three Lines of Defense Model
Simply put

The Three Lines of Defense is a way of organizing who is responsible for managing risk within an organization by dividing responsibilities across three groups, or 'lines.' The first line owns and manages risk day to day, the second line oversees and monitors risk, and the third line provides independent assurance, typically through internal audit. It is a framework for structuring accountability rather than a technical control, and different organizations may adapt it in different ways.

Formal definition

The Three Lines of Defense is a risk governance framework that assigns and separates accountability for risk management across three distinct roles: the first line, comprising operational functions that own and directly manage risks; the second line, comprising risk management and compliance functions that provide oversight, set policy, and monitor the first line; and the third line, comprising internal audit or an equivalent function that provides independent assurance over the effectiveness of the first two lines. The framework is intended to clarify responsibilities and reduce gaps or overlaps in risk oversight; it structures accountability but does not by itself measure or eliminate risk. The Institute of Internal Auditors (IIA) issued an updated formulation in July 2020 termed the 'Three Lines Model,' which reframes the original 'three lines of defense' language toward supporting governance and objective achievement rather than a purely defensive posture. Practitioners should note that specific role definitions, the degree of independence expected of each line, and how the model maps to particular AI governance or model risk management structures can vary by organization and sector, and application to AI-specific oversight is an evolving area not fully detailed in the evidence provided.

Why it matters

The Three Lines of Defense addresses a recurring failure mode in organizations: when responsibility for managing risk is diffuse or overlapping, risks can fall between functions unnoticed, or multiple functions may assume someone else is accountable. By separating who owns risk day to day, who oversees and monitors it, and who provides independent assurance, the framework is intended to reduce gaps and overlaps in oversight and to clarify accountability. This clarity matters most in regulated environments and in areas of rapidly evolving risk, where ambiguity about ownership can allow problems to persist until they become material.

For AI governance and model risk management, the framework offers a familiar structure onto which AI-specific oversight roles can be mapped: model developers and business owners in the first line, model risk and compliance functions in the second, and internal audit in the third. However, practitioners should treat this mapping as an adaptation rather than a settled standard. How the model applies to AI-specific oversight is an evolving area not fully detailed in established formulations, and the degree of independence expected of each line can vary by organization and sector.

It is important to recognize what the framework does and does not do. The Three Lines of Defense structures accountability; it does not by itself measure, quantify, or eliminate risk. A well-drawn organizational chart of three lines can coexist with weak controls if the lines lack the resources, independence, or authority to perform their roles effectively. The framework should therefore be understood as one component of a broader risk governance approach, not as a substitute for substantive risk identification, measurement, and control.

Who it's relevant to

Model Risk Managers
Model risk functions typically operate as part of the second line, providing oversight, setting policy, and monitoring the first-line owners of models. The framework helps clarify where model risk oversight sits relative to model developers and business owners, though how it maps to AI-specific model risk structures is an evolving area that organizations adapt individually.
Internal Auditors
Internal audit commonly serves as the third line, providing independent assurance over the effectiveness of the first two lines. The IIA's July 2020 update to the model is directly relevant, as it reframes the framework toward supporting governance and objectives; auditors should be aware of the distinction between the original 'defense' language and the updated 'Three Lines Model' formulation.
Compliance Officers
Compliance functions frequently form part of the second line alongside risk management, monitoring first-line activities and helping ensure policies are applied. The framework helps delineate compliance responsibilities from those of operational owners and independent assurance providers, reducing ambiguity about who is accountable for what.
AI Governance and Policy Specialists
Those designing AI governance structures may use the framework as an organizing principle for assigning accountability across development, oversight, and assurance roles. Because application of the model to AI-specific oversight is not fully settled, specialists should treat any mapping as an adaptation and document how each line's responsibilities and independence are defined in their context.
Business and Operational Owners
First-line functions own and directly manage risk in their daily activities, including risks arising from the models and AI systems they deploy. Understanding their role within the framework clarifies that primary responsibility for managing these risks rests with them, not solely with oversight or assurance functions.

Inside 3LOD

First Line of Defense
The business and operational functions that own and manage risk directly, including those who develop, deploy, and use models or AI systems. As commonly defined, this line is accountable for identifying, assessing, and controlling risks arising from day-to-day activities and for implementing controls within its own processes.
Second Line of Defense
Independent oversight and challenge functions such as risk management and compliance. In many model risk frameworks, this line typically includes model validation and risk policy setting, providing an objective check on the first line without owning the underlying activity. Its role is to establish standards, monitor adherence, and challenge risk-taking rather than to perform the operational work itself.
Third Line of Defense
Internal audit, which provides independent assurance to senior management and the board over the design and operating effectiveness of governance, risk management, and controls across the first and second lines. This line does not typically own or execute controls; it evaluates whether the overall framework is functioning as intended.
Independence and Separation of Duties
A central design principle: each line is intended to operate with sufficient independence from the lines it oversees so that challenge and assurance are not compromised. The degree of independence expected varies by framework and by organizational size and sector.
Governance and Board/Senior Management Oversight
Although sometimes described as sitting above the three lines, governing bodies and senior management set risk appetite and accountability. The model applies within a broader governance structure and does not by itself constitute the full accountability framework.

Common questions

Answers to the questions practitioners most commonly ask about 3LOD.

Does the first line of defense refer only to the compliance or risk teams overseeing models?
No. This is a common misconception. In the three lines model as commonly defined, the first line consists of the business functions and model owners or developers who own and manage risk directly as part of operating the model. Compliance and independent risk oversight functions typically sit in the second line, and internal audit in the third. Placing oversight or challenge functions in the first line blurs the separation that the model is intended to preserve.
Are the three lines a strict organizational hierarchy where each line reports up to the next?
Not in the way the term is often misread. The three lines describe distinct roles and responsibilities for managing and overseeing risk, not a chain of command in which the first line reports to the second and the second to the third. In many frameworks the second and third lines are intended to have a degree of independence from the first, and independent assurance functions may report to senior governance bodies rather than to the functions they review. Treating the lines as a simple reporting hierarchy can undermine the independence that gives the model its value.
How should responsibilities be allocated across the three lines in a model risk context?
As commonly applied, the first line owns model development, use, and the day-to-day management of associated risks and controls. The second line typically provides independent oversight, sets policy and standards, and may perform or oversee independent validation activities. The third line, usually internal audit, provides independent assurance over the design and effectiveness of the overall framework. The precise allocation varies by organization and sector, so it should be documented explicitly rather than assumed.
Where does independent model validation fit within the three lines?
Placement can vary. In many banking-oriented frameworks, independent model validation is positioned in the second line as an oversight and challenge function separate from the model developers in the first line. Some organizations structure validation differently. The key implementation consideration is that validation retains sufficient independence from the developers whose work it reviews, however it is organizationally located.
How can an organization avoid overlap or gaps between the lines?
A practical approach is to document roles, responsibilities, and accountabilities explicitly, often through a responsibility matrix, so that each control activity is clearly assigned. Coordination mechanisms between the lines can help avoid duplicated effort, while periodic review can surface gaps where no line is accountable for a given risk. Clarity on which line owns, which oversees, and which assures is typically central to reducing overlap and gaps.
How does the three lines model relate to broader AI governance structures?
The three lines model is primarily a way of organizing roles for managing and overseeing risk, and it can serve as one component within a wider AI governance structure that also addresses policies, accountability, and senior oversight. It is not a complete governance framework on its own. Organizations typically embed the three lines within governance arrangements rather than treating it as a substitute for them, and its adoption reduces rather than eliminates risk.

Common misconceptions

The Three Lines of Defense is a mandatory regulatory requirement that applies uniformly across all organizations and jurisdictions.
It is widely used as an organizing model for risk governance, but its precise application varies by sector, regulator expectation, and organizational context. It should be treated as a commonly adopted framework rather than a single universally binding standard, and its terminology and structure have evolved and been revised over time.
Model validation, which typically sits in the second line, is the same as the model development and testing done by the first line.
Independent validation is distinct from first-line development, testing, and verification. Validation provides independent effective challenge over whether a model is sound for its intended use, whereas the first line builds and operates the model. Blurring these roles undermines the independence the model is designed to preserve.
Having three lines of defense in place eliminates model and AI-related risk.
The structure is intended to reduce and manage risk through clearer accountability, oversight, and assurance. It does not remove inherent risk, and residual risk remains even when all three lines are functioning effectively.

Best practices

Clearly document the roles, responsibilities, and reporting relationships of each line so that ownership, oversight, and assurance activities are not inadvertently combined.
Preserve the independence of the second and third lines from the activities they review, ensuring that validation, compliance, and internal audit can provide unfiltered challenge and assurance.
Keep the distinction between first-line development and verification and second-line independent validation explicit in policy and in practice.
Adapt the model to your organization's size, sector, and regulatory context rather than applying it as a one-size-fits-all template, and note where sector-specific expectations differ.
Ensure senior management and the governing body remain accountable for setting risk appetite and receiving assurance, recognizing that the three lines operate within, not in place of, broader governance.
Periodically reassess how the lines interact to confirm that oversight and assurance activities remain effective and that gaps or overlaps between lines are identified and addressed.