
The Three Lines Model is one of the most useful ideas in compliance and one of the most mangled. In 2012 HSBC paid around 1.9 billion dollars over money-laundering failures, having had the three lines of defence firmly in place on its org charts.1 The model did not fail. The bank used it as a diagram of who reports to whom, rather than as an answer to the only question the model exists to settle: for any given risk, who owns it, who oversees it, and who independently assures that both are working.
Strip away the jargon and it is simple. The first line is the people who do the work and therefore own the risk it creates. The second line is the specialists who set the rules and watch over that risk, compliance, risk, quality. The third line is internal audit, who answer to the board and independently check that the first two are actually doing their jobs. That is the whole model. Everything else is detail.
The mistake: thinking compliance is the first line's job
The most common and most damaging error is for the people doing the work to believe that managing their risk is someone else's job, usually "compliance". It is not. The first line owns the risk, because the first line creates it. The second line helps, guides and challenges, but it cannot own a risk it does not run day to day. When a salesperson thinks compliance owns sales-conduct risk, nobody owns it, because the second line cannot be in every conversation and the first line has been told it is not their problem. That gap is where HSBC's money moved.
The Three Lines Model updated, and why it matters
The Institute of Internal Auditors refreshed the model in 2020, deliberately dropping the word "defence" and softening the rigid lines.2 The point of the change was to stop people treating the lines as silos that throw risk over the wall at each other, and to stress that they should work together toward the same objectives, with clear roles. It is not three fortresses. It is three roles in one team, and the team only works when each knows which role is theirs.
The solution, as a three-lines RACI
For any real risk, fill this in
| Role | Who | Owns |
|---|---|---|
| First line | The people doing the work | Owns the risk and the controls, day to day |
| Second line | Compliance, risk, quality | Sets the framework, oversees, challenges, supports |
| Third line | Internal audit | Independently assures the first two work, reports to the board |
| Governing body | Board or owner | Sets the appetite, holds it all to account |
If you cannot name a person in each row for your biggest risk, that risk is not being governed, whatever the org chart says.
You do not need to be a bank to use it
A small business has three lines too, even if the same person wears more than one hat. The owner who does the work is the first line. When that owner steps back to set a rule for how the work is done, they are acting as the second line. When they bring in an outside pair of eyes to check the whole thing honestly, that is the third line. The value is not the bureaucracy. It is the discipline of separating doing the work, overseeing the work, and independently checking it, so that no risk falls into the gap where everyone assumes someone else has it.
Questions to test your three lines
- For our biggest risk, who in the first line actually owns it, by name?
- Does that person know they own it, or do they think compliance does?
- Is our second line supporting and challenging, or being treated as the owner?
- Is there anyone independent who checks the first two honestly?
- Where might a risk fall into the gap because everyone assumes someone else has it?
The Three Lines Model is not a compliance ritual. It is a way of making sure that every risk has an owner who runs it, a specialist who watches it, and an independent check that both are real. HSBC had the diagram and missed the point. Use it the other way round: start from your biggest risk, and make sure you can name a real person in every row. Do that and the model earns its keep. Draw the boxes and file them, and you have a chart, not a defence.
Notes and sources
- HSBC paid around 1.9 billion dollars in 2012 over anti-money-laundering failures despite having three lines of defence in place. Overview of major money-laundering cases. Link. ↩
- The IIA's Three Lines Model, updated in 2020, replacing the older Three Lines of Defence. Institute of Internal Auditors. Link. ↩
From the book
Key Compliance ModelsFifty-eight models of governance, risk and compliance, each explained in plain language and anchored to a real, sourced case.
