
Key Compliance Models · No. 01
The Three Lines Model
Business, compliance and audit: three separate lines
Three teams were watching the risk.
All three had gone slack at the same time.
That is the HSBC story in one line.
The business chased the profitable, high-risk work. Compliance was under-resourced and overruled. Audits flagged the problems, and the board did not force the issue.
On paper, three separate lines of protection. In practice, nobody was really watching.
The result: at least 881 million dollars of cartel money moved through the bank, and a 1.9 billion dollar settlement in 2012.
The Three Lines Model exists to stop exactly this.
First line: the business, which owns the risk and runs the controls. Second line: risk and compliance, who set the framework and challenge the first line. Third line: internal audit, independent, telling the board the truth.
The trick most people miss is that the diagram is worthless on its own.
What matters is whether each line is genuinely separate, genuinely funded, and genuinely able to say no.
A second line that can be overruled by the profit centre is not a second line. It is decoration.
Draw your three lines this week. Then ask the harder question: could line two actually stop line one?
If the answer is no, you do not have three lines. You have one, wearing a costume.
Sources: US Department of Justice: HSBC settlement, 2012; US Senate: HSBC money laundering case history report, 2012; IIA: Three Lines Model statement of position.
Longer read: The Three Lines Model, explained without the jargon









































