🏹 Happy Dussehra — victory of good over evil!

Three Lines of Defense Model in Bank Risk Management

RM By Ashish Jain · IIBF STORE Editorial · 18 August 2026 · Updated 01 Oct 2026 · 11 min read · 62 views
Three Lines of Defense Model in Bank Risk Management

Every bank regulator conversation about who is accountable when a control fails eventually circles back to one idea: the three lines of defense model. For IIBF Risk Management (RM) certificate candidates, this framework is not an org-chart curiosity — it is the backbone of how RBI expects Indian banks to structure risk ownership, independent oversight and assurance. Get the three lines of defense model wrong in an exam answer and you will confuse who "owns" a risk with who merely reviews it. This article walks through each line, how supervisory expectations map onto it, and where the 2020 update from the Institute of Internal Auditors changed the vocabulary without changing the substance.

🛡️ What Is the Three Lines of Defense Model?

The three lines of defense model is a governance structure that separates risk-taking, risk oversight and risk assurance into three distinct groups so that no single team is grading its own homework. The idea was popularised by the Basel Committee and the Institute of Internal Auditors (IIA) in the early 2000s and was quickly absorbed into Indian banking supervision because it gives the Board a clean, testable answer to a hard question: if a loss event happens, which layer should have caught it?

In practice the framework rests on a simple division of labour. The first line runs the business and lives with the risk every day. The second line designs the policies, sets limits and challenges the first line's decisions. The third line — internal audit — periodically tests whether the first two lines are actually doing what the policy manual says they should be doing, and reports its findings straight to the Board. Each line has a distinct reporting line, a distinct mandate, and — critically for an RM exam answer — a distinct degree of independence from day-to-day risk-taking.

Indian banks embed this structure into their Risk Management Committee of the Board (RMCB), their Chief Risk Officer's charter, and their Audit Committee's terms of reference. Candidates should remember that the model is not optional guidance; it is the default assumption behind almost every RBI circular on internal controls, operational risk and corporate governance in banks.

🏦 First Line: Business Units That Own the Risk

The first line of defense is made up of business and operational units — branches, credit desks, treasury dealers, digital lending teams — who originate transactions and therefore own the risk at the point it is created. Ownership here is not passive; the first line is expected to design and run its own embedded controls, maintain segregation of duties at the desk level, and self-report control breaks rather than wait to be caught.

This is also where day-to-day risk identification tools live. Business heads run the risk and control self-assessment exercise covered in our chapter on RCSA and key risk indicators, and they own the key risk indicators that flag when a process is drifting out of tolerance. A branch manager who ignores a red KRI is a first-line failure; a risk department that never asks why the KRI turned red is a second-line failure — that distinction is exactly what examiners test.

The exam-relevant point is accountability: under this framework, no amount of central risk policy absolves the first line of owning the outcome. Risk management is embedded in how the business is run, not bolted on afterwards.

💡 Exam Tip: If a question asks "who is primarily responsible for managing a specific risk on a day-to-day basis," the answer under the three lines of defense model is almost always the first line — not risk management, not audit.
Key Concepts — Risk Management
Key Concepts — Risk Management

🔍 Second Line: Risk Management and Compliance

The second line is the independent risk management and compliance function — typically headed by the Chief Risk Officer and the Chief Compliance Officer — that sets the policy framework the first line must operate within, monitors aggregate exposure, and challenges business decisions that stray outside approved boundaries. This line does not run the transactions; it watches, measures and escalates.

Second-line teams build the enterprise-wide operational risk framework that the first line's controls plug into. Our chapter on the operational risk and management framework explains how this function aggregates loss events, control ratings and KRI breaches across every branch and product line into one enterprise picture for the Board. Compliance sits alongside risk management in this second line, translating regulatory circulars into internal policy and testing adherence independent of the business.

What separates the second line from the third in this framework is proximity to management: the second line is still part of the management structure, reporting largely to the CEO with a dotted line to the Board's risk committee, whereas the third line answers to the Board directly and has no operational stake in the outcome it reviews.

🕵️ Third Line: Internal Audit and Independent Assurance

Internal audit is the third line of the three lines of defense model, and its defining feature is independence: it reports functionally to the Audit Committee of the Board, not to the CEO, precisely so that it can test both the first and second lines without a conflict of interest. Where the first line manages risk and the second line monitors it, the third line asks a narrower, sharper question — did the controls that were supposed to catch this actually work, on the evidence?

Internal audit's raw material overlaps heavily with the second line's data. When auditors sample the bank's collection of loss data, they are not re-collecting losses; they are testing whether the process that collected them was complete, timely and correctly categorised. This is also where corporate governance in banks connects most directly to the exam syllabus: the reporting chain from internal audit to the Audit Committee, and from the Audit Committee to the full Board, is the mechanism that keeps the framework honest rather than merely decorative.

⚠️ Common Mistake: Candidates often place internal audit and risk management in the same "oversight" bucket. Under the three lines of defense model they are functionally distinct — risk management is a management function; internal audit is an independent assurance function reporting to the Board.
📌 Remember: First line owns and manages, second line sets policy and monitors, third line independently tests and reports to the Board. Three verbs, three lines.
Process & Framework — Risk Management
Process & Framework — Risk Management

📋 Three Lines of Defense vs the 2020 IIA Three Lines Model

In 2020 the Institute of Internal Auditors revised its guidance and renamed the framework the "Three Lines Model," dropping the word "defense" and adding the governing body (the Board) explicitly at the top of the structure, alongside a stronger emphasis on the three lines working together rather than as adversarial checkpoints. For IIBF purposes the substance candidates need to know is unchanged; the terminology update mostly matters for recognising both names in a question stem.

The table below is the fastest way to revise which line does what, and which line is genuinely independent of the risk it is reviewing — a distinction examiners like to probe with "who reports to whom" questions.

LineWhoPrimary RoleReports ToIndependent of Day-to-Day Risk-Taking
First lineBusiness & operational unitsOwns and manages risk at source; runs embedded controlsBusiness head / CEO❌
Second lineRisk management & compliance functionsSets policy, monitors exposure, challenges the first lineCEO, dotted line to Board risk committee❌
Third lineInternal auditIndependently tests lines one and two, reports gapsAudit Committee of the Board✅

Reading this table correctly is the difference between a pass and a fail on governance questions: only the third line is structurally independent of management, which is exactly why the three lines of defense model gives internal audit — and only internal audit — a direct, unfiltered reporting line to the Board.

The same layered logic RBI expects in this model echoes through the supervisory review and evaluation process under Basel Pillar 2, where the regulator itself effectively acts as a fourth, external check on a bank's internal three lines. Similarly, the limits the second line polices — for instance the market risk limits in banks set by treasury risk teams — only work as a control if the third line periodically verifies they are being monitored, not just documented. And the capital consequences of first-line risk-taking, discussed in our piece on economic capital allocation in banks, ultimately trace back to how well the model is functioning at the point risk is originated.

In Practice — Risk Management
In Practice — Risk Management

🧠 Practice MCQs: Three Lines of Defense Model

Q1. Under the three lines of defense model, which line is primarily responsible for owning and managing a risk on a day-to-day basis? (a) Internal audit (b) The Board (c) The first line - business units (d) External auditors

Answer: (c) — Business and operational units originate transactions and own the risk at source, making embedded, day-to-day control their responsibility.

Q2. Which line in the three lines of defense model is structurally independent of the risk it reviews and reports directly to the Board's Audit Committee? (a) First line (b) Second line (c) Third line - internal audit (d) Compliance function

Answer: (c) — Internal audit's independence from management, with a direct reporting line to the Audit Committee, is the defining feature of the third line.

Q3. Who typically heads the second line of defense in an Indian bank's risk governance structure? (a) Branch Manager (b) Chief Risk Officer (c) Head of Internal Audit (d) Statutory Auditor

Answer: (b) — The Chief Risk Officer, alongside the Chief Compliance Officer, heads the second line, which sets policy and monitors the first line.

Q4. What did the IIA's 2020 update rename the three lines of defense model to? (a) Two Lines Model (b) Three Lines Model (c) Four Pillars Framework (d) Unified Assurance Model

Answer: (b) — The IIA dropped "defense" for "Three Lines Model" in 2020, explicitly adding the governing body and emphasising collaboration over adversarial checkpoints.

Q5. A branch ignores a persistently red key risk indicator without escalating it. Under the three lines of defense model, whose failure is this primarily? (a) Third line (b) First line (c) External regulator (d) Shareholders

Answer: (b) — Monitoring and escalating its own KRIs is a first-line responsibility; failing to act on a red signal is a first-line control failure.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ FAQs on the Three Lines of Defense Model

What is the three lines of defense model in banking?

It is a risk governance structure that separates risk ownership (first line), risk oversight and policy-setting (second line), and independent assurance (third line, internal audit) so accountability for any control failure can be traced to a specific layer.

Why did the IIA rename it the Three Lines Model in 2020?

The 2020 update dropped the word "defense" to move away from an adversarial framing, added the governing body explicitly at the top of the structure, and stressed collaboration and communication between the lines rather than isolated checkpoints — though the core division of roles is unchanged.

Is internal audit part of the second line of defense?

No. Internal audit is exclusively the third line. Because it tests both the first and second lines, it must remain organisationally independent, reporting functionally to the Audit Committee of the Board rather than to management.

How does the three lines of defense model relate to corporate governance in banks?

It is the operational expression of a bank's corporate governance in banks framework: the Board delegates risk-taking to the first line, oversight to the second line, and relies on the third line's independent reporting to know whether that delegation is being honoured in practice.

The three lines of defense model is one of those IIBF Risk Management topics that looks simple until an exam question forces you to place a specific role — CRO, branch manager, statutory auditor, internal auditor — into the correct line. Revise it alongside corporate governance and the layered accountability that governs recovery once a risk crystallises, such as the moratorium under Section 14 of IBC, and you will have a complete picture of how Indian banks are expected to catch — and be caught — when controls fail. For more coverage, browse our Risk Management study articles, and when you are ready to test yourself, take a full-length IIBF Risk Management mock test built around exactly this kind of governance question.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading