FRM Exam Part II · Risk Governance
Three Lines of Defense Model in Risk Governance
Updated 11 October 2026 · Fact-checked
The three lines of defense model splits risk responsibility into three groups. The first line, business units, owns and manages risk. The second line, independent risk management and compliance, sets standards and challenges the first line. The third line, internal audit, gives independent assurance to the board on both.
Understand Three Lines of Defense Model
Start with a simple idea: the people who take a risk should not be the only ones checking it. A trader who earns a bonus from profit has a reason to understate risk. So banks build layers of control, each with a different job and a different level of independence.
The first line is the business units: trading desks, lending teams, operations and technology. They create risk, so they own it. They identify it, measure it, control it and stay within the risk appetite and limits the board has approved. Line managers run day-to-day controls.
The second line is independent risk management, often led by the chief risk officer, plus compliance. It does not take business risk. It designs the risk framework, sets policies and limits, monitors risk against appetite, aggregates and reports risk, and challenges the first line's decisions. Independence matters: the second line must not report to the people it oversees and must not be paid on their profit.
The third line is internal audit. It is independent of both lines and reports to the board, usually through the audit committee. It does not own risk or design controls. It tests whether the first and second lines are working and whether the governance framework itself is effective. It gives assurance, not management.
The lines work together but stay separate. The board sets risk appetite. Management and the first line operate within it. The second line monitors and escalates breaches. Audit reviews everything and reports gaps. External auditors and supervisors sit outside the model and are sometimes described as additional layers of oversight. Failures usually come from a weak line: a first line that treats risk as someone else's job, a second line without authority or stature, or an audit function that is not independent.
Key formulas to remember
- First line role
- Business units = risk ownership + day-to-day control
- They identify, assess, manage and report risk within limits and appetite.
- Second line role
- Risk management and compliance = framework + oversight + challenge
- Independent of the business. Sets policy, monitors limits, aggregates and reports risk.
- Third line role
- Internal audit = independent assurance to the board
- Reviews the first and second lines and the framework. Does not own risk or design business controls.
- Independence rule
- Independence rises from line 1 to line 3
- Audit has the highest independence and reports to the board or its audit committee.
How to solve Three Lines of Defense Model questions
Most questions give a scenario and ask which line is responsible or which line failed. Use this routine.
- 1Identify the activity in the scenario: taking or managing risk, setting or monitoring policy, or testing and assuring.
- 2Ask who owns the risk. If the activity is running a desk, a process or a control day to day, it is the first line.
- 3Ask whether the activity is independent oversight, such as limit setting, monitoring, risk reporting or challenge. That is the second line.
- 4Ask whether the activity is an independent review of controls and governance, reporting to the board. That is the third line.
- 5Check independence. A group that reports to or is paid by the business cannot be the second or third line.
- 6Look for role confusion, such as audit designing controls or risk management approving trades, and mark it as a weakness.
- 7Pick the option that matches the role and keeps independence intact.
Quickest way: Own, Oversee, Assure
When to use it: Use when you have under a minute and the question asks which line is responsible.
- Own and run the risk: first line.
- Oversee, set limits, monitor and challenge: second line.
- Assure independently to the board: third line.
- Cross out any option that breaks independence or gives audit a management role.
Common mistakes in Three Lines of Defense Model
Saying risk management owns the risk.
The name suggests it manages all risk.
Fix: The business owns risk. Risk management oversees and challenges.
Placing compliance in the first line.
Compliance staff sometimes sit inside business areas.
Fix: Compliance is a second line function. Its role is oversight, even if staff are located near the business.
Letting internal audit design or run controls.
Audit knows controls well and seems helpful.
Fix: Audit gives assurance only. Designing or operating controls would compromise its independence.
Thinking the second line approves every business decision.
Confusing challenge with ownership.
Fix: The second line challenges and sets limits. The first line still makes and answers for its decisions.
Treating audit as part of management reporting.
Audit works inside the firm.
Fix: Audit reports to the board or audit committee, not to business management.
Worked examples
Example 1
A bank's equity derivatives desk breaches its approved VaR limit for three days. The desk head tells no one. Risk management detects the breach in its daily monitoring and escalates it to the chief risk officer. Which statement is most accurate?
Show the solution
- The desk is part of the business, so it is the first line and owns the risk and the duty to stay within limits.
- The desk head's silence is a first line failure to manage and report risk.
- Risk management detecting and escalating the breach is second line monitoring working as designed.
- Internal audit is not involved in day-to-day monitoring. It would later review whether the process worked.
Answer: The first line failed to own and escalate the breach, and the second line performed its monitoring and escalation role correctly.
Example 2
A bank's internal audit head is asked to join the team that designs a new limit framework for credit exposures and to sign off on the limits afterwards. What is the main governance concern?
Show the solution
- Designing limits is a second line task, since the second line sets the framework.
- Audit's value is independent assurance over that framework.
- If audit helps design the limits and then signs them off, it reviews its own work.
- This weakens independence and its ability to report objectively to the board.
Answer: Audit independence would be compromised because it would be assuring a framework it helped design. Audit should review the framework, not build it.
Exam tips
- Match the verb to the line: own and manage is line 1, oversee and challenge is line 2, assure is line 3.
- Look for independence clues such as reporting lines and compensation. They often decide the answer.
- In failure cases, ask which line should have caught the issue first. Usually it starts with the first line.
- Expect distractors that give audit a management role or give risk management ownership of business risk.
Practice questions from Risk Governance
- A bank's board sets a risk appetite statement that annual operational losses should not exceed 5% of annual pre-provision net revenue. The b…
- A trading desk head also approves the reconciliation of the desk's own profit and loss and reports operational incidents only when he judges…
- A bank is preparing to launch a new payments product. The head of operational risk reviews the plan against the Basel operational risk princ…
- A bank sets a risk appetite of operational losses not exceeding 5% of annual gross income. Gross income is USD 2.0 billion. Tolerance is set…
- A bank's board receives a monthly operational risk report containing forty pages of raw loss event listings with no commentary. Which change…
Three Lines of Defense Model in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Three Lines of Defense Model: frequently asked questions
What is the difference between the first and second line of defense?
The first line, the business units, takes and owns risk and runs daily controls. The second line, risk management and compliance, is independent of the business and sets policy, monitors limits and challenges the first line.
Where does compliance sit in the three lines model?
Compliance is normally a second line function. It oversees adherence to laws, regulation and internal policy, independent of the business units it monitors.
Who does internal audit report to?
Internal audit reports independently to the board, typically through the audit committee. This keeps it free from influence by the management and business units it reviews.
How does the model apply to operational risk?
Business units manage their own operational risks and controls. The second line runs the operational risk framework, tools and reporting and challenges the business. Internal audit tests whether the framework and controls work.