The third line of defense is internal audit, giving the board independent assurance on how well the first and second lines manage financial-crime risk. Its whole value rests on independence and on whether its findings actually get fixed rather than just noted.
What is the third line, in plain English?
The third line of defense is internal audit. Its job is to give the board an independent, trustworthy view of whether the firm's financial-crime controls actually work. It sits above both the business, which owns the risk, and compliance, which oversees it day to day. In the simplest terms, audit checks the checkers.
That separation is the point. The board needs a picture of the AML program that is not colored by the people running the controls. Compliance will naturally tend to report that its own frameworks are sound. Internal audit exists to test that claim independently, sampling files, re-performing checks, and probing whether the controls hold up under real scrutiny rather than just existing on paper.
Its value depends on two things. First, genuine independence from both other lines, which means audit cannot review controls it helped design. Second, the technical skill to actually test AML controls, not merely confirm that a process document exists. And the real measure of whether the third line is working is what happens to its findings: recurring or aging issues signal that assurance is being noted but never acted on, which quietly defeats the purpose of having a third line at all.
Second line versus third line
What changes | Second line (compliance) | Third line (audit) |
Function | Ongoing oversight and challenge. | Periodic independent assurance. |
Owns | The control framework itself. | Nothing it audits, by design. |
Reports to | Senior management and the board. | The board or audit committee directly. |
Question it asks | Is the business inside the rules? | Do the rules and their oversight actually work? |
What it looks like in practice
In practice
Internal audit runs a review of the transaction monitoring system. Rather than accepting compliance's assurance that alerts are handled, it pulls a sample of closed alerts and re-reads them. It finds a pattern of alerts closed with thin, templated rationale, and a backlog older than the firm admitted.
Audit reports this to the board with a finding and a remediation timeline. The test of the third line comes next: if the backlog is cleared and the rationale improves by the follow-up review, the assurance did its job. If the same finding reappears a year later, aging and unresolved, the third line is producing paper, not protection.
Why it matters to operators
Without an independent third line, the board only ever hears about the AML program from the people who run it. That is a structural blind spot: no function is well placed to grade its own homework. Internal audit is the mechanism that gives the board a view it can actually trust, which is why regulators expect it to be genuinely separate and technically capable.
For operators, the most useful signal from the third line is the trend in its findings. New findings are healthy; that is audit doing its job. Recurring and aging findings are the warning, because they show a program that can identify problems but cannot, or will not, fix them. When issues linger across review cycles, the assurance has become a formality, and the risk it flagged is still live.
What to watch
- Auditing its own work. Audit reviewing controls it helped design has lost the independence the line depends on.
- Aging findings. Issues that stay open across cycles show assurance without remediation.
- Recurring findings. The same problem flagged year after year means fixes are cosmetic, not real.
- Process-only testing. Confirming a document exists is not the same as testing whether the control works.
- Weak board line. Audit that reports through management it audits cannot deliver truly independent assurance.
Quick questions
How is the third line different from the second?
The second line, compliance, provides ongoing oversight and owns the control framework. The third line, internal audit, provides periodic independent assurance and owns none of the controls it reviews. Audit checks whether the second line's oversight actually works.
Why does it have to be independent?
Because assurance is only worth anything if it is not shaped by the people running the controls. If audit reviews work it helped build or reports through management it audits, its independence, and therefore its value, disappears.
Who does internal audit report to?
The board, usually through an audit committee, rather than through the management it reviews. That direct line is what lets it deliver findings the business cannot filter or soften.
What does good AML audit actually test?
It re-performs and samples real work: reopening closed alerts, retesting risk ratings, checking whether EDD was genuinely done. It tests whether controls work in practice, not just whether a policy document exists.
Why do aging findings matter so much?
Because they show the program can spot problems but does not fix them. A finding noted and left open across cycles means the underlying risk is still live and the assurance function is being ignored.
Can a firm outsource internal audit?
Yes, many smaller firms use external specialists for the third line. What matters is not who performs it but that it is independent of the controls and technically capable of testing them.
Go deeper
- FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
- FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

