The Three Lines of Defence: Compliance Miracle or Mirage?

The Three Lines of Defence: Compliance Miracle or Mirage?

The Three Lines of Defence: Compliance Miracle or Mirage?

In the complex environment of financial services, there is increasing discontent with the 3LOD model.” Martin, Clive and Willman, Paul and Boukens, Roy and Rockley, Oliver, Risk Management Formations – An Alternative Approach to the 3 Lines of Defense Model (November 29, 2014). Journal of Financial Perspectives, Vol. 2, No. 3, 2014, Available at SSRN: https://ssrn.com/abstract=3079701

The Three Lines of Defence (3LOD) model is well-known, poorly-understood and often implemented compliance framework embraced by many financial services licensees. 

Initially developed by the Institute of Internal Auditors in the early 2000s, the model was designed to create structured accountability for managing risk and compliance. The concept has evolved over time, rooted in simplicity, becoming a central tenet of risk management and compliance across the industry. The model’s widespread adoption is partly due to its strong endorsement by Big Consultancies, who find it particularly attractive due to its scalability and the standardised framework it provides for risk and compliance, making it easier to sell advisory services and assessments to large institutions. But is it as effective as it’s often claimed to be? Do even large institutions benefit from the model?

Let’s explore the theoretical advantages of the 3LOD model, alongside its practical disadvantages and consider why it may be wholly inappropriate for all but the largest institutional licensees (and probably inappropriate even for them).

Understanding the Three Lines of Defence Model

The 3LOD model divides the responsibilities of risk management into three distinct “lines”:

  1. First Line: Business Operations — The individuals within the business who are responsible for day-to-day risk management. Their primary focus is identifying, assessing, and controlling risks as they arise in their operational activities.
  2. Second Line: Risk Management and Compliance Functions — A separate function responsible for overseeing the implementation of effective risk management practices. It serves as the guide, supporting the first line but also challenging the effectiveness of their controls.
  3. Third Line: Internal Audit—This line provides an independent review of the first and second lines, assessing the adequacy and effectiveness of the risk management and compliance functions.

This model is praised for its clarity in role separation, which helps prevent conflicts of interest and ensures that responsibilities for risk and compliance are not concentrated in a single area.

The Theoretical Advantages

Many organisations implement standardised risk management frameworks more for signalling purposes than for their actual effectiveness, leading to minimal impact on managing risks.” Mikes, A. and Kaplan, R.S. (2015), When One Size Doesn’t Fit All: Evolving Directions in the Research and Practice of Enterprise Risk Management. Journal of Applied Corporate Finance, 27: 37-40. https://doi.org/10.1111/jacf.12102

The attractiveness of the 3LOD model lies in its theoretical advantages:

  • Role Clarity: The model seeks to delineate roles and responsibilities across the organisation, ensuring that business units, oversight functions, and auditors each have their specific domain of focus.
  • Structured Oversight: By formalising oversight across three distinct levels, the model allows for a structured and comprehensive review process to enhance compliance standards.
  • Accountability: Ideally, each line is accountable for its specific part of the risk management ecosystem, ensuring that each risk aspect—from identification to mitigation and audit—is appropriately managed.
  • Segregation of Duties: The separation of responsibilities is designed to reduce conflicts of interest and ensure independent scrutiny of processes, creating additional control layers.

Practical Disadvantages and Limitations

3LoD is not effectively ensuring good decisions [and] … is inherently slow, reactive, laborious and is not adding value”. Rethinking the three lines of defence, Hans Læssøe

Despite its conceptual appeal, the 3LOD model faces significant practical challenges when applied, particularly for non-institutional licensees. Critics highlight concerns about its effectiveness and bureaucratic nature, as well as its rigidity and lack of collaboration. Even its most vocal proponents recognise that it “can lead to fragmented risk management activities and excessive bureaucracy.’

It’s not uncommon to dismiss the 3LOD as an evergreen consulting income stream that is “more about appearances than effectiveness.’ The reality is that strict adherence creates complex structures that only sometimes lead to better risk oversight. It’s a model often only adopted superficially, resulting in minimal impact on actual risk management practices. Like the idea of a parliamentary road to socialism, the 3LOD fails to deliver on its promises. Instead of utopia, it more frequently creates bureaucracy, formalism, and box-ticking. We believe that substance matters and it’s important to recognise the practical limitations of 3LOD:

1. Turf Wars and Demarcation Disputes

The rigid separation between the three lines often results in disputes regarding where responsibilities begin and end. Theoretically, the first line handles the operational risks, but the boundaries between the first and second lines can blur, leading to arguments about accountability. In practice, the handover between lines isn’t always seamless, and disputes about where oversight ends and operational responsibility begins are commonplace.

In smaller organisations, the absence of clear demarcation leads to duplication of work or, conversely, vital risk areas being overlooked because no line assumes ownership. Rather than improving clarity, the demarcation lines sometimes create confusion, especially in less-resourced licensees.

2. Loss of Clear Accountability

One of the greatest ironies of the 3LOD model is that, despite being designed to foster accountability, it often leads to a dilution of individual responsibility. The segmented nature of the model may cause overlap in responsibilities, resulting in critical compliance elements being “everyone’s responsibility, and therefore no one’s.” Individuals within each line may assume that someone in another line will take responsibility, especially where the division between duties is not adequately managed.

This blurring effect is particularly noticeable in businesses that lack the structural complexity to support distinct functional teams. In such scenarios, the model’s intended accountability quickly erodes, becoming more of a theoretical concept than a practical reality.

3. Complexity and Duplication

Another significant limitation is the model’s inherent complexity. Large institutions might have the resources and staffing required to separate and manage these lines adequately, but the structure creates unnecessary bureaucracy and inefficiencies for smaller licensees or advisers. This excessive complexity can deter effective risk management as small teams struggle to maintain clarity across functions. What may start as an effort to improve governance often adds layers of formality that bog down decision-making processes.

Duplicative efforts between the second and third lines can be costly and time-consuming, leaving smaller licensees to navigate a system that doesn’t scale well to their needs. In reality, such duplication is often an unnecessary use of resources that many businesses can’t afford.

4. A Facade of Control

For many organisations, the 3LOD model becomes more of a checkbox exercise—an administrative burden that is adopted because it is considered best practice rather than because it genuinely improves outcomes. There is an inherent risk that these structures, when not properly integrated or tailored to the organisation’s needs, become a façade—a structure that appears effective but lacks substantive depth. The implementation is often patchy, the lines indistinct, and the practical value of the model becomes marginal.

In practice, there is a risk that the 3LOD model becomes an overly rigid framework, focusing on adherence to the structure rather than addressing the practical realities of compliance. Smaller organisations, attempting to mimic the institutional approach, may find themselves distracted by the ceremonial elements of compliance, losing sight of the practical outcomes and tailored risk controls that are actually required.

3 lines of defense model

Wholly Inappropriate for Non-Institutional Licensees

While it provides a useful structural framework, it falls short in addressing the complex realities of risk management in banking [and] fails to account for the nuanced interactions, power dynamics, and behavioural factors that significantly influence risk management.” Lim, C. Y., Woods, M., Humphrey, C., & Seow, J. L. (2017). The paradoxes of risk management in the banking sector. British Accounting Review, 49(1), 75-90. https://doi.org/10.1016/j.bar.2016.09.002

Given the obvious limitations, the 3LOD model is wholly inappropriate for many non-institutional licensees. Unlike large banks or insurers, many licensees and smaller advisory firms lack the resources to fully staff these three functions. The model is premised on the independence of the lines, which may be theoretically possible in large organisations but is nearly impossible in small financial services businesses.

  • Resourcing Challenges: Small—and medium-sized businesses may simply lack the capacity to staff distinct roles for the three lines, making the model impractical without substantial adaptation.
  • Operational Disconnect: The 3LOD model’s institutional heritage suits entities with segregated functions and formalised divisions. For smaller licensees, the operational disconnect it fosters can create more barriers than it removes.
  • Flexibility Is Key: Smaller firms benefit from adaptable, integrated approaches to compliance, which allow them to address risks as they arise nimbly. The rigid 3LOD model, focusing on segmentation, is poorly suited to the dynamic realities of a small business that needs its personnel to work across multiple risk areas.
  • Culture is critical. The 3LOD presumes and requires formally and structurally independent lines. Functional independence is less important than the business’s compliance culture, and risks may be more effectively managed in small to medium businesses by consolidating compliance, risk management, and internal audit functions.

Moving Beyond Three Lines

Employees operate within a social context, one that works by informal social norms and peer pressures. While important, formal processes, systems and incentive structures hold far less sway than many business leaders (and regulators) would like to believe. Without explicit appreciation of this, the Three Lines Model is not just impoverished, it is effectively inoperable.” Hoefer, E., Cooke, M., & Curry, T. (2020, August 21). Three Lines of Defense: Failed Promises & What Comes Next. Starling Trust Sciences.[p. 4]

Given the limitations of the 3LOD model for non-institutional licensees, smaller businesses must explore more effective approaches to risk management and compliance. For instance:

  • Integrated Risk and Compliance Functions: Unlike rigid lines, smaller licensees may benefit from integrating risk management and compliance into core operational activities. Encouraging a culture of collective responsibility across the business can be more effective than attempting to emulate the institutional segmentation of the 3LOD. This is our preferred approach and one embedded in our cloud-based compliance platform, [complye].
  • Scaled Oversight Models: A scaled oversight model, which adjusts the level of review and independence according to the size and nature of the risk, allows smaller businesses to effectively prioritise resources without creating undue complexity. Like ASIC, companies should consider their operations’ nature, scale, and complexity and tailor their framework accordingly.
  • Focus on Outcomes, Not Process: The emphasis should shift from adhering to a model’s structure to achieving genuine compliance outcomes. Licensees must focus on clear processes, ownership of risks, and proactive management of issues as they arise.

Transition to effective risk management

Start your own journey.

  1. Conduct regular assessments of power dynamics between business units and compliance functions.
  2. Develop practical metrics to evaluate the effectiveness of interactions between the three lines of defence.
  3. Invest in targeted training programs focusing on the behavioural aspects of risk management.
  4. Create open forums for dialogue across different functions to address tensions and foster mutual understanding.
  5. Regularly adapt risk management practices to emerging challenges and opportunities beyond the scope of the traditional 3LOD model.
  6. Use behavioural analytics to provide insights into organisational culture and employee behaviour.
  7. Foster cross-functional collaboration to encourage operational, compliance, and audit team engagement.
  8. Implement systems to monitor and provide early warnings of potential misconduct or process breakdowns.
  9. Enhance cultural awareness through focused training and resources to improve understanding of informal social dynamics.
  10. Review incentive structures to ensure they align with the desired risk management behaviours throughout the organisation.
  11. Leverage technological solutions, including AI and machine learning, to improve risk management capabilities.
  12. Conduct a thorough assessment of current risk management practices and identify gaps in accountability, coordination, and technology use.
  13. Develop a strategy for evolving the risk management model, with buy-in from leadership and cross-functional teams.
  14. Invest in technology solutions that enhance data management and analytics capabilities across all compliance functions.
  15. Establish clear communication processes to enhance coordination between risk, compliance, and audit functions.

Ditch 3LOD

The Three Lines of Defence model remains a cornerstone of many large institutional compliance frameworks, but it is crucial to recognise its limitations, particularly for smaller financial services licensees. While it offers theoretical clarity and structured oversight, it can create unnecessary complexity, blur accountability, and be reduced to little more than a façade of control.

For non-institutional licensees, an adaptive approach that integrates compliance into the heart of business operations may be a far more effective alternative. By focusing on simplicity, flexibility, and outcomes, licensees can ensure that their compliance frameworks serve the purpose they were intended for—protecting clients, managing risks, and meaningfully meeting regulatory obligations.

See more on how Assured Support can assist in developing practical, outcomes-focused compliance strategies tailored to your needs.

Black swan

 

If you liked this article, we recommend that you read:

Living with Risk

Respecting “risk culture”

The Role of Risk Management in Practice Growth: How Financial Advisers Can Leverage Risk Management for Sustainable Growth and Increased Valuation.

Keep exploring

The Three Lines of Defence: Compliance Miracle or Mirage?

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?