Three Lines of Defense

Three Lines of Defense

The three lines of defense is a governance model that divides responsibility for managing risk into three layers: the business that owns risk, the compliance and risk functions that oversee it, and internal audit that independently checks both. In AML, it clarifies who does what.

Key takeaways

  • The three lines of defense is a model for organizing risk management.
  • The first line is the business, which owns and manages risk day to day.
  • The second line is compliance and risk, which sets policy and oversees.
  • The third line is internal audit, which independently checks the first two.
  • In AML, it clarifies who is responsible for what.
  • The IIA updated it to the Three Lines Model in 2020.

3

Lines: the business, oversight, and audit

Source: IIA Three Lines Model

2020

Year the IIA updated it to the Three Lines Model

Source: IIA

$3.09B

TD Bank penalty after its lines of defense failed, 2024

Source: US Department of Justice

What is the three lines of defense?

The three lines of defense is a way of organizing who manages risk in a firm. It splits the job into three distinct layers, each with its own role, so responsibility is clear and no single group is left marking its own homework.

The model is used across risk and compliance, and it fits anti-money laundering especially well. AML involves many people, from front-line staff to auditors, and the three lines make clear where each fits.

It underpins how a firm structures oversight. Read more: it shapes a firm’s AML governance.

The three lines

Each line has a different job, and together they form a layered defense. If one misses a risk, the next should catch it.

  • First line: the business. The people who take on and manage risk day to day.
  • Second line: oversight. The compliance and risk functions that set the rules and watch the first line.
  • Third line: internal audit. The independent function that checks whether the first two actually work.

The word defense captures the idea: each line is a barrier, and layering them makes it far harder for a risk to slip all the way through.

The first line of defense

The first line is the business itself, the staff who deal with customers and transactions. They own the risk, because they are the ones creating and managing it.

In AML terms, the first line is where customers are onboarded, activity is watched, and the initial checks are done. Front-line staff are often the first to see something wrong, which makes their role central. A strong first line stops many risks before they go anywhere.

The second line of defense

The second line is the compliance and risk functions that oversee the first. They do not deal with customers directly; they set the rules and check the business is following them.

This is where the compliance team and the MLRO sit. The second line writes the policies, monitors how well the first line applies them, and provides expertise. It is oversight, not front-line work, and its independence from the business is part of its value.

The third line of defense

The third line is internal audit, which independently checks the first two. It answers a question the others cannot answer about themselves: is any of this actually working?

Internal audit stands apart from both the business and compliance, which is what lets it judge them honestly. In AML, the third line is closely tied to the independent AML audit, testing the whole program and reporting to the board. Its independence is the source of its credibility.

Set out roles in your AML policy

Generate a tailored AML policy draft that records who owns, oversees, and audits your controls.

Open the AML Policy Generator →

The three lines in AML

Applied to AML, the model maps neatly onto how a program runs. Each line has a clear AML job.

  1. First line. Onboards customers, runs initial checks, and watches activity.
  2. Second line. Sets AML policy, monitors the first line, and owns the framework.
  3. Third line. Independently tests the program and reports to leadership.

When the lines work together, a risk missed by the business is caught by compliance, and any gap between them is caught by audit. When they blur, that safety net frays.

The 2020 update to the model

The model was refreshed a few years ago to reflect how firms actually work. It kept the core idea but broadened it.

In 2020, the Institute of Internal Auditors, which developed the framework, updated the old Three Lines of Defense into what it calls the Three Lines Model. The change stressed that risk management is about seizing opportunities as well as defending against threats, and clarified how the roles work together rather than in isolation. Many firms still use the older defense language, and the underlying structure is the same.

Worth knowing. The three lines only work if they are genuinely separate. When the same people own the risk, oversee it, and audit it, the model collapses into a single point of failure. The value comes precisely from the independence between the lines, which is why blurring them, often to save cost, tends to be where the model breaks down.

Common weaknesses

The model is simple, but it fails in familiar ways. A few weaknesses recur.

  • Blurred lines. The first and second lines merging, so oversight is not independent.
  • A weak second line. Compliance without the authority to challenge the business.
  • A toothless third line. Internal audit that is not truly independent or is ignored.
  • Confused ownership. No one clear on which line owns a given risk.

Most of these come down to independence, or the lack of it. When each line keeps its distinct role, the model holds; when they merge, it stops being three lines at all.

Get an indicative AML risk rating

See where your money laundering risk is concentrated so each line knows where to focus.

Try the AML Risk Assessment →

Support the first line with screening

Run one search across sanctions, PEP, and adverse media data as part of front-line customer checks.

Try Combined AML Screening →

Frequently asked questions

What is the three lines of defense?

The three lines of defense is a governance model that divides responsibility for managing risk into three layers: the business that owns and manages risk day to day, the compliance and risk functions that set policy and oversee it, and internal audit that independently checks both. In AML, it clarifies who is responsible for what across a program.

What are the three lines of defense in AML?

In AML, the first line is the business, which onboards customers, runs initial checks, and watches activity. The second line is compliance and risk, including the MLRO, which sets policy and oversees the first line. The third line is internal audit, which independently tests the whole program and reports to leadership. Together they form a layered defense.

What is the first line of defense?

The first line of defense is the business itself, the staff who deal with customers and transactions. They own the risk because they create and manage it. In AML, the first line onboards customers, does the initial checks, and watches activity. Front-line staff are often the first to see something wrong, which makes their role central to the model.

What is the second line of defense?

The second line of defense is the compliance and risk functions that oversee the first line. They do not deal with customers directly; they set the rules, monitor how well the business follows them, and provide expertise. In AML, this is where the compliance team and the MLRO sit. Its independence from the business is part of its value.

What is the third line of defense?

The third line of defense is internal audit, which independently checks the first two lines. It stands apart from both the business and compliance, which lets it judge them honestly. In AML, the third line is closely tied to the independent AML audit, testing the whole program and reporting to the board. Its independence is the source of its credibility.

Why is it called the three lines of defense?

It is called the three lines of defense because each line acts as a barrier against risk, and layering them makes it far harder for a risk to slip all the way through. If the first line misses something, the second should catch it, and if both miss it, the third should. The word defense captures this layered, barrier-by-barrier approach.

What changed in the 2020 Three Lines Model?

In 2020, the Institute of Internal Auditors updated the Three Lines of Defense into the Three Lines Model. The change kept the core structure but stressed that risk management is about seizing opportunities as well as defending against threats, and clarified how the roles work together rather than in isolation. Many firms still use the older defense language.

Who created the three lines of defense model?

The three lines model is associated with the Institute of Internal Auditors, which formalized and later updated it. The IIA released the updated Three Lines Model in 2020 as a revision of the older Three Lines of Defense, which had been widely adopted for organizing governance and risk management across many industries, including financial services and AML.

How do the three lines apply to AML?

Applied to AML, the first line onboards customers, runs initial checks, and watches activity; the second line sets AML policy, monitors the first line, and owns the framework; and the third line independently tests the program and reports to leadership. When the lines work together, a risk missed by one is caught by the next, which is the point of the model.

What happens when the three lines blur?

When the three lines blur, the model collapses into a single point of failure. If the same people own the risk, oversee it, and audit it, there is no independent check. The value of the model comes precisely from the independence between the lines, so blurring them, often to save cost, tends to be where the model breaks down.

Is the three lines of defense a legal requirement?

The three lines of defense is a widely adopted governance model rather than a specific legal requirement in most places. However, regulators expect firms to have clear roles, independent oversight, and independent audit, which the model provides. Many firms use it because it satisfies these expectations and gives a clear structure for managing AML and other risks.

What is the difference between the second and third lines?

The second line is compliance and risk, which sets policy and oversees the business on an ongoing basis. The third line is internal audit, which independently checks whether the first two lines are actually working. The second line is active oversight built into daily operations, while the third line is a periodic, independent review that stands apart from both.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 12, 2026 · 11 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: the three lines of defense is a governance model that splits risk duties into three: the business that owns risk, the oversight that monitors it, and audit that checks both.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.