The second line of defense is the compliance and risk-management function that sets financial-crime policy, defines standards, and independently challenges the risk-taking of the business. It is the check on the people chasing revenue, and it only works when it has the authority to actually say no.
What is the second line, in plain English?
The second line of defense is the compliance and risk-management layer that oversees and challenges how the business handles financial-crime risk. It writes the policies, sets the standards, owns the monitoring frameworks, gives guidance to the front line, and escalates issues when the business steps outside the rules. In the three lines model it sits between the business, which takes the risk, and internal audit, which independently assures the whole thing.
The crucial distinction is that the second line should not own the day-to-day business risk itself. The first line owns that. The second line's job is to set the guardrails and check that the first line stays inside them, not to make the commercial decisions. When compliance starts doing first-line work, the independence that gives its challenge weight begins to erode.
The structural weakness that shows up again and again is a second line without real authority or resources. It exists on the org chart, it produces policies, but it cannot genuinely stop the business when the business wants to press on. If compliance can only suggest and never veto, its oversight is advisory in name and powerless in fact. Real challenge needs teeth, not just a seat at the table.
First line versus second line
What changes | First line (business) | Second line (compliance/risk) |
Owns | The day-to-day risk and the revenue. | The policy, standards, and oversight framework. |
Decides | Whether to onboard, transact, proceed. | Whether those decisions meet the firm's standards. |
Incentive | Growth and speed. | Control and defensibility. |
Power needed | Authority to run the business. | Authority to challenge and, when needed, say no. |
Who sits in the second line?
Who | Their role |
Chief Compliance Officer | Leads the function, owns the AML program, and reports to senior management and the board. |
AML and compliance teams | Set policy, run monitoring frameworks, review escalations, and file regulatory reports. |
Risk management | Frames and measures the firm's risk, feeding the appetite and the controls. |
Financial crime advisory | Guides the first line on how to apply the rules to real cases. |
What it looks like in practice
In practice
A relationship manager wants to onboard a lucrative corporate client with a complex offshore ownership structure. The business is keen; the fees are large. Compliance reviews the structure, cannot get comfortable with who ultimately controls it, and recommends declining.
In a firm with a real second line, that recommendation holds, and the client is turned away or onboarded only with strict conditions and senior sign-off. In a firm with a weak one, the deal goes through over compliance's objection, the objection is quietly filed, and the second line learns that its challenge does not actually count.
Why it matters to operators
The second line is the reason a firm's controls are more than a set of documents. Someone has to own the standards, watch whether the business follows them, and push back when it does not. Strip that layer of its authority and the whole three lines model collapses into a business that polices itself, which is no policing at all.
For anyone working in compliance, the health of the second line is measured by what happens when it disagrees with revenue. If challenge is heard, resourced, and occasionally decisive, the line is real. If it is routinely overridden, under-staffed, and treated as a box to tick, the oversight is fiction, and that is the kind of gap examiners and, eventually, launderers find.
What to watch
- Advisory only. A compliance function that can recommend but never block is powerless in practice.
- Blurred lines. Second line staff doing first-line onboarding or approvals lose the independence that gives challenge weight.
- Chronic under-resourcing. Alert backlogs and unfilled roles are a sign the second line is not equipped to do its job.
- Overrides without record. Business decisions that overrule compliance with no documented rationale or escalation.
- No direct board line. A compliance head who cannot reach the board independently can be filtered by the very business it oversees.
Quick questions
How is the second line different from the first?
The first line, the business, owns and takes the risk. The second line sets the standards and independently oversees and challenges how the first line manages it. One does; the other checks.
How is it different from internal audit?
The second line provides ongoing oversight and owns the control framework. Internal audit, the third line, independently assures that both the first and second lines are working, including whether the second line's own oversight is effective.
Why should the second line not own business risk?
Because if compliance owns the decisions it is also supposed to challenge, it cannot challenge them objectively. The separation is what keeps the oversight independent and credible.
What makes a second line weak?
Lack of authority, resources, or independence. If it can only advise, is chronically under-staffed, or reports through the business it oversees, its challenge becomes advisory in name and powerless in fact.
Who leads the second line?
Typically the Chief Compliance Officer, supported by AML, compliance, and risk-management teams. The CCO usually needs a reporting line to the board that the business cannot filter.
How do you tell if it has real teeth?
Watch what happens when it disagrees with revenue. If challenge is heard and sometimes decisive, and if the firm will walk away from profitable business on compliance's call, the second line is genuinely functioning.
Go deeper
- FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
- FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

