Three Lines of Defence in Banks: CAIIB Risk Governance Guide 2026

CAIIB By Ashish Jain · IIBF STORE Editorial · 20 July 2026 · Updated 20 Jul 2026 · 11 min read · 3 views
Three Lines of Defence in Banks: CAIIB Risk Governance Guide 2026

Every CAIIB Risk Management candidate meets a question that looks deceptively simple: who actually owns risk in a bank? The answer sits inside the three lines of defence in banks, the governance model that separates the people who take risk, the people who challenge it, and the people who independently assure the board that both are doing their jobs. Examiners love this topic because it is conceptual, RBI-mandated and easy to test through short scenario questions. This guide walks through the model, the roles of the CRO, the Chief Compliance Officer and internal audit, the board-level committees involved, and the mistakes that cost marks.

📌 Remember: The three lines model is about independence, not about hierarchy. All three lines report upward to the same board — they simply must not report through each other.

🏛️ What Risk Governance Means in a Bank

Risk governance is the structure through which a bank's board of directors sets risk appetite, delegates authority, and receives assurance that the appetite is being respected. Unlike a manufacturing firm, a bank's core business is the assumption of risk, so governance cannot mean risk avoidance. It means deliberate, priced and monitored risk-taking within limits the board has approved.

The architecture begins with the board, which approves the risk appetite statement and the overall risk management framework. Below the board sit specialised committees — the Risk Management Committee of the Board (RMCB), the Audit Committee of the Board (ACB), and in most banks a Credit Approval Committee. Executive-level committees such as the Asset Liability Committee (ALCO), the Credit Risk Management Committee and the Operational Risk Management Committee translate board policy into day-to-day limits.

The Basel Committee on Banking Supervision's corporate governance principles for banks make the board ultimately accountable for the bank's risk culture. The RBI has operationalised this in India through binding requirements: a mandatory Chief Risk Officer for scheduled commercial banks, a mandatory Chief Compliance Officer, and Risk Based Internal Audit. Together these create the independent, professionally staffed second and third lines that the model requires.

The practical consequence is that risk ownership is never outsourced to the risk department. A branch manager who sanctions a loan owns that credit risk. The risk function owns the framework, the models and the challenge — not the exposure itself. Confusing these two ownerships is the single most common conceptual error in this chapter.

🛡️ The Three Lines Explained, Line by Line

First line — business and operations. These are the risk owners: branches, corporate credit teams, the treasury dealing room, the digital channels team. They originate exposures and therefore own the identification, control and reporting of risk in their own processes. First-line controls include maker-checker discipline, sanction authority matrices, dealer position limits, KYC checks at onboarding and daily reconciliations. Crucially, the first line also runs its own embedded control units — a credit administration department or a treasury back office is still first line, because it sits inside the business chain.

Second line — risk management and compliance. This line sets the policies and challenges the first. It houses the Chief Risk Officer, the integrated risk management department, model validation, and the compliance function under the Chief Compliance Officer. Its job is to define measurement standards, aggregate exposures across the bank, monitor limit breaches, run stress tests and escalate to the RMCB. It advises but does not take the business decision, which is precisely what preserves its independence.

Third line — internal audit. Internal audit provides independent assurance to the Audit Committee of the Board on whether the first two lines are designed well and operating effectively. Under RBI's Risk Based Internal Audit approach, audit resources are allocated according to the assessed risk of each auditable unit rather than on a mechanical cyclical basis. Internal audit does not design controls or own risk — doing so would destroy the independence that gives its assurance value.

External auditors and the RBI's own supervisory inspection are sometimes described as a fourth line, but strictly they sit outside the bank's internal governance.

Key Concepts — Risk Management (Elective)
Key Concepts — Risk Management (Elective)

📊 Comparing the Three Lines at a Glance

The table below is the fastest way to revise this chapter. Notice how the answer to "owns the risk" and "reports to the board" varies — that contrast is exactly what multiple-choice questions probe.

AttributeFirst LineSecond LineThird Line
Typical functionsBranches, corporate credit, treasury front office, operationsRisk management under CRO, compliance under CCO, model validationInternal audit / RBIA function
Owns the risk exposure✅ Yes❌ No❌ No
Sets policy and limits❌ No✅ Yes❌ No
Provides independent assurance❌ No❌ No✅ Yes
Can be given business targets✅ Yes❌ No❌ No
Primary board reporting lineMD & CEORisk Management Committee of the BoardAudit Committee of the Board
Audits the other lines❌ No❌ No✅ Yes

Read the "can be given business targets" row twice. It captures the entire logic of independence: the moment a risk or audit officer earns a bonus linked to loan growth, the line collapses into the first line and the model stops working.

💡 Exam Tip: If a question describes a treasury back office, a credit administration cell or an operations reconciliation team, the answer is first line — embedded controls inside the business are not the second line.

👤 The CRO, the CCO and Why Their Tenure Is Protected

India's version of the model has teeth because the RBI has hard-wired protections for the officers who must say no. Scheduled commercial banks must appoint a Chief Risk Officer of sufficient seniority with a clearly specified role. The CRO is appointed for a fixed minimum tenure and cannot be transferred or removed before that tenure ends without board approval, with the change reported to the supervisor. The logic is straightforward: an officer who can be moved out for raising uncomfortable findings will eventually stop raising them.

Equally important is the prohibition on dual hatting. The CRO must not have any reporting relationship with business verticals and must not be given any business targets. Where the CRO participates in the credit sanction process, that participation is restricted to an advisory or vetting role rather than a decision-making one, so that the risk function never has to audit its own sanction. The CRO reports directly to the MD & CEO or to the Risk Management Committee of the Board, and has an unimpeded right of access to the RMCB.

The Chief Compliance Officer carries a parallel design. RBI's framework for the compliance function specifies a senior-level CCO with a minimum fixed tenure, a transparent selection process, independence from business lines and direct access to the Audit Committee or MD & CEO. The compliance function is second line: it identifies regulatory obligations, tests adherence and reports breaches, but it does not carry business volumes.

For revision, pair this with your reading on liquidity risk management, because ALCO decisions are a textbook case of the first line acting within limits the second line has independently framed. The same interaction underpins asset liability management reporting to the board.

⚠️ Common Mistake: Candidates write that the CRO "approves" loans. The CRO's role in credit sanction is advisory or vetting — the sanctioning authority remains with the business or the credit committee.
Process & Framework — Risk Management (Elective)
Process & Framework — Risk Management (Elective)

🔍 How the Model Shows Up in Practice — and in the Exam

Governance failures are rarely failures of the framework document; they are failures of the boundary between lines. A rogue-trading loss occurs when the dealing room and the back office are not genuinely separated. A misselling penalty follows when compliance testing is staffed by the same product team that designed the incentive. A large NPA slippage often traces back to a credit monitoring unit whose escalations went to the very relationship manager whose loan was slipping.

The second line is also the home of quantitative discipline. Independent model validation, back testing of market risk capital charge models, review of rating models and challenge of stress assumptions all belong here, precisely because the model builders should not certify their own models. Similarly, the measurement of counterparty credit risk in banking and its aggregation across desks is a second-line responsibility, while the dealer who books the trade remains first line. Capital planning under the Basel III capital adequacy framework is drafted by the second line and approved by the board.

Risk governance also crosses subject boundaries. The KYC and AML control chain — onboarding checks at the branch, transaction monitoring by compliance, and periodic assurance by internal audit — is a clean three-lines illustration, which is why it is worth revisiting the CAIIB BRBL note on KYC and AML norms for banks alongside this chapter.

You can check the current text of the supervisory expectations on the Reserve Bank of India website, and browse more revision notes on our Risk Management (Elective) tag hub.

In Practice — Risk Management (Elective)
In Practice — Risk Management (Elective)

🧠 Practice MCQs: Three Lines of Defence in Banks

Q1. In the three lines of defence model, who owns the risk arising from a corporate loan? (a) Internal audit (b) The business unit that originated the loan (c) The Chief Risk Officer (d) The Audit Committee of the Board

Answer: (b) — The first line, i.e. the originating business unit, owns and manages the exposure it creates.

Q2. A bank's treasury back office that reconciles deals belongs to which line? (a) First line (b) Second line (c) Third line (d) It is outside the model

Answer: (a) — Embedded control units inside the business chain remain part of the first line.

Q3. Which of the following is NOT permitted for a Chief Risk Officer as per RBI's requirements? (a) Reporting to the Risk Management Committee of the Board (b) Vetting credit proposals in an advisory role (c) Being given business growth targets (d) Having a fixed minimum tenure

Answer: (c) — The CRO must not be given business targets, as that would destroy second-line independence.

Q4. Internal audit in a bank primarily reports to which body? (a) MD & CEO only (b) Audit Committee of the Board (c) Risk Management Committee of the Board (d) Credit Approval Committee

Answer: (b) — The third line provides independent assurance to the Audit Committee of the Board.

Q5. Under Risk Based Internal Audit, audit effort is allocated mainly on the basis of (a) alphabetical order of branches (b) the assessed risk of each auditable unit (c) branch deposit size only (d) a fixed calendar cycle for every unit

Answer: (b) — RBIA directs audit resources towards units assessed as higher risk rather than following a uniform cycle.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Is the three lines of defence model mandatory in India?

The model itself is a governance convention, but its components are mandatory. RBI requires scheduled commercial banks to have an independent Chief Risk Officer, a Chief Compliance Officer and a Risk Based Internal Audit function, which together create the second and third lines.

Can the CRO and the CCO be the same person?

No. The roles are separate, each requires independence and a fixed minimum tenure, and combining them would weaken both risk challenge and compliance testing.

Where do external auditors and RBI inspection fit in?

They are external assurance providers. Some texts call them a fourth line, but strictly they sit outside the bank's internal governance structure rather than within the three lines.

How much weight does risk governance carry in the CAIIB exam?

It is a small but reliable scoring area. Expect two to four objective questions on the roles of the lines, the CRO's independence conditions and the board committees, often framed as short scenarios.

🎯 Conclusion

The three lines of defence in banks is not an organogram to memorise — it is a rule about who may challenge whom. The first line takes and owns risk, the second line frames, measures and challenges it, and the third line independently assures the board that both are working. RBI's protections for the CRO and CCO, and its Risk Based Internal Audit approach, are simply the enforcement mechanism that keeps those boundaries real. Learn the boundary conditions, especially the ban on business targets for the second and third lines, and this chapter becomes free marks.

Ready to test yourself on the full Risk Management elective? Explore the structured syllabus coverage in our CAIIB course and lock in your revision with chapter-wise mocks.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading