SardineCon SF/2026

Learn More
AML programs4 min de leitura

O que é Three lines of defense?

SUBSCRIBE

The three lines of defense is a governance model that separates who owns risk, who oversees and challenges it, and who gives independent assurance. It makes accountability clear, but it is a framework, not a guarantee, and it fails the moment the lines quietly blur.

What is the three lines model, in plain English?

The three lines of defense is the standard way firms organize responsibility for managing risk, including financial-crime risk. It splits the job into three: the first line is the business, which owns and takes the risk; the second line is compliance and risk, which oversees and challenges it; and the third line is internal audit, which independently assures that the first two are working. The point is to make clear who does what, so accountability does not fall through the cracks.

Each line has a different job and a different vantage point. The business makes the daily decisions. Compliance sets the standards and checks the business stays inside them. Audit stands back and tests whether the whole arrangement actually holds. Together they are meant to create layered accountability, where a failure in one line has a decent chance of being caught by the next.

The important caution is that the model is a framework, not a promise. Drawing three boxes does not create three genuinely separate functions. The frequent failure mode is blurred lines: compliance drifting into first-line tasks, or audit reviewing controls it helped build. Either erodes the independence the whole model rests on. When the lines quietly merge, you lose exactly the separation that made the model useful. Guard the boundaries, not just the boxes.

The three lines at a glance

Line

Who

What they do

First line

The business.

Owns and takes the risk; makes daily onboarding and transaction calls.

Second line

Compliance and risk.

Sets policy and standards; oversees and challenges the first line.

Third line

Internal audit.

Independently assures the board that the first two lines work.

Who plays each line?

Who

Their role

Front-line staff and management

Own the risk in their business: onboarding, transactions, customer decisions.

Compliance and risk functions

Set standards, run oversight, and challenge the business's risk-taking.

Internal audit

Independently tests both other lines and reports to the board.

The board

Owns overall accountability and relies on the model to see the true risk picture.

What it looks like in practice

In practice

A fast-growing fintech is short on compliance headcount, so the same small team both writes the AML policies and helps the business clear its onboarding backlog by approving cases directly. On paper it still has three lines. In reality the second line is now doing first-line work.

When internal audit reviews onboarding, it finds compliance approving the very cases it is meant to independently challenge. The separation has collapsed, and the firm has lost a layer of protection it believed it still had. The fix is not more boxes on the chart; it is pulling compliance back out of the approval seat.

Why it matters to operators

The model is the backbone of how regulators expect firms to govern financial-crime risk. When something goes wrong, one of the first questions is whether the lines were clear and independent, because layered accountability is supposed to catch failures before they become losses. A firm that can show three genuinely separate lines has a defensible governance story; one where the lines are muddled does not.

For operators, the practical warning is that the danger is rarely a missing line. It is a line that has quietly stopped being independent. Compliance helping the business hit targets, or audit signing off on systems it advised on, feels efficient in the moment and hollows out the model over time. The value is in the separation, so the job is to protect the boundaries, not just to keep the labels on the org chart.

What to watch

  • Compliance doing first-line work. Approving onboarding or transactions blurs the second line into the business it oversees.
  • Audit reviewing its own advice. Assurance over controls audit helped design is not independent.
  • Shared staff. The same people wearing two line hats defeats the separation entirely.
  • Reporting lines that filter. Second or third line that reports through the business it checks can be muffled.
  • Boxes without substance. An org chart with three lines that behave as one is a governance risk hiding in plain sight.

Quick questions

What are the three lines, briefly?

First line: the business that owns the risk. Second line: compliance and risk that oversee and challenge it. Third line: internal audit that independently assures both. Each has a distinct role and vantage point.

Why separate them at all?

Separation creates layered accountability, so a failure in one line has a chance of being caught by the next. If the same people take the risk, oversee it, and assure it, there is no independent check anywhere.

What is the most common failure?

Blurred lines. Compliance drifting into first-line approvals, or audit reviewing controls it helped build. Either quietly removes the independence the whole model depends on.

Is the model a regulatory requirement?

It is the widely expected governance standard rather than a single rule, embedded in regulatory and supervisory guidance. Firms are expected to show clear, independent lines even if the exact structure varies.

Does a small firm need all three lines?

The functions still need to exist and stay independent, but they can be sized to the firm. Smaller firms often outsource internal audit to keep the third line genuinely separate from the people running the controls.

How do you keep the lines from blurring?

Keep roles, reporting lines, and staff distinct, resist the temptation to have compliance clear operational backlogs, and make sure audit never reviews work it advised on. Guard the boundaries, not just the labels.

Go deeper

  • FFIEC BSA/AML Examination Manual ↗ — The manual US examiners use to assess BSA and AML programs.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

O que saber junto com Three lines of defense