FRM Exam Part II · Governance
Three Lines of Defense Model for Credit Risk Governance
Updated 11 October 2026 · Fact-checked
The three lines of defense model splits risk responsibility in a bank. The first line (business units) owns and manages credit risk. The second line (independent risk management) sets policy, challenges and monitors. The third line (internal audit) gives independent assurance to the board. To answer questions, match each task to the right line.
Understand Three Lines of Defense Model
Banks take credit risk to earn a return. If the same people take the risk, measure it and check it, errors and bias go unchecked. The three lines of defense model fixes this by separating roles.
The first line is the business units, such as corporate lending and relationship managers. They originate loans, price them and manage the borrower day to day. They own the risk. They must apply the bank's credit policy and stay within the limits they are given.
The second line is the independent risk management function, often led by the chief risk officer, with compliance sitting alongside. It designs the risk framework, proposes limits and policies, validates models, monitors exposures and reports to senior management and the board. Its key job is effective challenge: questioning the first line's decisions. To do this it must be independent of revenue targets, with its own reporting line and authority to escalate.
The third line is internal audit. It reviews whether the first and second lines follow policy and whether the framework works. It does not manage risk or set limits. It reports to the board, usually through the audit committee, so its independence is protected. Audit gives assurance, not day-to-day control.
Some frameworks add external parties, such as external auditors and supervisors, as further assurance. For the exam, remember the core test: who owns, who challenges, who assures.
Key formulas to remember
- First line
- Business units = risk ownership and day-to-day management
- Originate, underwrite, monitor borrowers and stay within limits.
- Second line
- Independent risk management = framework, oversight and effective challenge
- Sets policy, proposes limits, validates models, reports. Must be independent of revenue generation.
- Third line
- Internal audit = independent assurance to the board
- Reviews both other lines. Reports to the board or audit committee. Does not own or manage risk.
How to solve Three Lines of Defense Model questions
Use this method for any question on roles in credit risk governance.
- 1Read the scenario and list each activity described (originating, setting limits, validating, testing controls).
- 2Label each activity as owning, challenging or assuring.
- 3Map owning to the first line, challenging and oversight to the second line, and assurance to the third line.
- 4Check independence: who reports to whom, and are incentives tied to revenue?
- 5Look for a breach of the model, such as risk management approving its own loans or audit setting limits.
- 6Eliminate options that give one line two conflicting roles.
- 7Choose the option that keeps ownership with the business and independent oversight with risk and audit.
Quickest way: Own, challenge, assure
When to use it: Use when a question asks which line is responsible for a task or which line is weak.
- Ask: does this task create or manage the exposure? First line.
- Ask: does it set rules or independently question the exposure? Second line.
- Ask: does it test whether the other lines work, reporting to the board? Third line.
- Pick the answer that matches, rejecting any that mix roles.
Common mistakes in Three Lines of Defense Model
Saying risk management owns credit risk.
The name suggests the risk team is responsible for all risk.
Fix: The business unit owns the risk. The second line oversees and challenges it.
Putting internal audit in the second line.
Both audit and risk management are control functions.
Fix: Audit is the third line. It gives independent assurance to the board and does not run daily oversight.
Letting audit approve limits or design controls.
Audit knows the controls well, so it seems natural.
Fix: If audit designs or approves, it audits its own work and loses independence. It only assesses.
Ignoring independence of the second line.
Students focus on tasks, not reporting lines and incentives.
Fix: Check whether risk staff are paid on revenue or report to business heads. That weakens challenge.
Treating compliance and risk management as the same function.
Both sit in the second line.
Fix: Both are second line, but risk management covers risk measurement and limits while compliance covers rules and regulation.
Worked examples
Example 1
A bank's relationship managers approve a large loan above their own limit after the credit risk department raised concerns. Credit risk reports to the head of corporate banking, whose bonus depends on loan growth. Which statement best identifies the governance weakness?
Show the solution
- Relationship managers are the first line, so they own the loan decision.
- Credit risk is the second line, and its role is effective challenge.
- Its concerns were overridden, and it reports to a revenue-driven business head.
- This removes independence, so challenge has no real force.
Answer: The second line lacks independence and authority. It should report outside the business and be able to escalate breaches to senior management and the board.
Example 2
Which line should assess whether the bank's credit limit monitoring process and the risk team's model validation work as designed, and to whom should it report?
Show the solution
- The task is testing whether processes in the other lines work.
- That is independent assurance.
- Assurance is the role of the third line, internal audit.
- To protect independence it reports to the board, usually via the audit committee.
Answer: Internal audit, reporting to the board or its audit committee.
Exam tips
- Expect scenario questions where one line does another's job. Spot the conflict first.
- Watch for words like owns, challenges, oversees and assures. They point to the line.
- Independence is the most tested idea. Check reporting lines and incentives.
- Internal audit never sets limits or manages exposures in a correct answer.
Practice questions from Governance
- A bank's chief risk officer notes that the credit risk team that independently monitors portfolio concentrations and challenges the lending …
- A bank's credit policy sets an underwriting standard that commercial real estate loans have a maximum loan-to-value of 70% and a minimum deb…
- A bank is restructuring its credit governance. The proposal: (1) business units own credit risk and perform first-level controls; (2) the CR…
- At a regional bank, the credit risk function reports to the Chief Risk Officer and sets the credit risk limits and monitors compliance with …
- A bank's model risk policy requires a tiering of credit models. A newly developed loss given default (LGD) model drives loan pricing and reg…
Three Lines of Defense Model in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Three Lines of Defense Model: frequently asked questions
What is the difference between the first and second line of defense in banks?
The first line, the business units, takes and manages the risk. The second line, independent risk management, sets the framework, monitors and challenges. The second line must be independent of revenue targets.
What is the role of internal audit in credit risk governance?
Internal audit is the third line. It gives independent assurance to the board that the first and second lines follow policy and that controls work. It does not own or manage credit risk.
Can you give three lines of defense credit risk examples?
A relationship manager underwriting a loan is first line. A credit risk officer setting concentration limits and validating the rating model is second line. An audit team testing whether limit breaches are escalated is third line.
Who does internal audit report to?
It reports to the board, typically through the audit committee. This protects its independence from management.