The Three Lines of Defence
A standard way large financial firms organize risk oversight into three distinct layers — the people taking risk, the people monitoring it independently, and the people auditing the whole system — so that no single group is checking its own work.
Financial firms use the three lines of defence framework to keep risk oversight independent of risk-taking. The first line is the business itself — traders and portfolio managers who take on risk and are the first ones responsible for managing it day to day. The second line is independent risk and compliance functions that set limits, monitor exposures, and can override or block the first line, reporting up a separate management chain so they aren't beholden to the traders they oversee. The third line is internal audit, which periodically checks that both the first and second lines are actually doing what they're supposed to, independent of both.
The point of separating the lines is that the people generating P&L are never the same people certifying that risk limits were respected — a trader who is also their own risk monitor has an obvious incentive to look the other way on a limit breach that's working out. Keeping the lines genuinely independent, with separate reporting chains and separate incentives, is what makes the framework work in practice rather than just on an org chart.
Worked example
A trader (first line) breaches a position limit intraday while a trade is working well. The risk desk (second line), monitoring limits independently and with no stake in that trader's P&L, flags the breach and forces a reduction regardless of how the position is performing. Months later, internal audit (third line) reviews a sample of limit breaches across the desk and confirms the risk desk consistently enforced limits rather than granting informal exceptions to favored traders.
The three lines of defence separate risk-taking (first line), independent risk monitoring (second line), and independent audit of the whole system (third line) into distinct reporting chains, so the people making money are never the same people certifying that risk was properly controlled.
Further reading
- Institute of Internal Auditors, 'The Three Lines Model' (2020)