All terms
Glossary · ERM

Three Lines of Defense Model

Risk governance framework separating operational management, risk oversight, and independent assurance into three distinct organizational layers.

Full definition
The Three Lines of Defense Model structures risk management responsibilities across three layers: first-line business units that own and manage risk, second-line risk and compliance functions that oversee and challenge, and third-line internal audit that provides independent assurance. Each line has distinct roles, accountabilities, and reporting relationships to prevent conflicts of interest. For example, a bank's trading desk (first line) executes transactions, the risk management function (second line) sets limits and monitors exposures, and internal audit (third line) validates the effectiveness of both. This model has evolved into the Three Lines Model by the IIA, emphasizing coordination over rigid separation.
governancerisk-oversightinternal-auditaccountability
Free account required

Unlock the full encyclopedia

Full term breakdowns are free — just sign in to continue.

  • AI Framework Finder — get 4 matched frameworks for your industry.
  • 1000+ glossary terms with detailed definitions + examples.
  • Save assessments, share via public link, export PDF.

Made with Emergent