The three-lines-of-defence model is the dominant framework for organising risk governance in banks and other financial institutions. It was formulated by the Institute of Internal Auditors and endorsed by regulators including the PRA and FCA as the expected structure for managing risk across a firm. Nearly every major bank's governance documentation references it; nearly every regulatory review assesses whether the firm's structure actually reflects it. Understanding how the model works — and where it breaks down — is essential context for anyone working in a capital markets environment.

The First Line: Business Ownership of Risk

The first line of defence is the business itself — in a capital markets context, the trading desks, sales teams, and the operations and technology functions that support them. The first line owns the risks it takes. It does not merely create risk and pass it to risk management to deal with; it is responsible for identifying, assessing, and managing the risks inherent in its activities within the limits and controls set by the firm.

In practice, this means that a rates trading desk is responsible for managing its interest rate risk within DV01 and VaR limits. The desk's head is responsible for ensuring traders understand and comply with those limits. Operations is responsible for ensuring that settlements are processed correctly and that breaks are investigated and resolved. Technology is responsible for the reliability and integrity of the systems it operates.

The first line has embedded controls — pre-trade checks in the order management system that prevent orders outside authorisation limits, position reconciliations that flag discrepancies before they escalate, and mandatory sign-off processes for new products or exceptions to standard terms. These embedded controls are the operational expression of first-line ownership. A first line that relies entirely on the second line to catch its mistakes is not, in regulatory terms, functioning as a first line at all.

The Business Risk Function

Many capital markets businesses have a dedicated first-line risk function — sometimes called the Business Risk Management (BRM) or Business Control Unit (BCU). These teams sit within the business line, report to the business head, and are responsible for overseeing the control framework from within. They maintain the risk and control self-assessment (RCSA), coordinate responses to internal audit findings, and act as the interface between the trading desk and the second line. The BRM role is a common entry point for people moving from operations into risk management.

The Second Line: Independent Oversight

The second line of defence comprises the independent risk management and compliance functions. In a capital markets bank, the second line typically includes Market Risk, Credit Risk, Operational Risk, and Compliance. These functions report independently of the business — to a Chief Risk Officer (CRO) or Chief Compliance Officer (CCO) who has a direct reporting line to the board or board risk committee, separate from the business head's line.

The second line does not own the risk — that is the first line's responsibility — but it sets the framework within which the first line operates. Market Risk sets and monitors trading limits. Credit Risk sets and monitors counterparty credit limits. Compliance sets and monitors the conduct framework. Operational Risk owns the firm-wide RCSA methodology and oversees the loss data collection process. The second line also challenges the first line: if a trading desk requests an increase in its DV01 limit, Market Risk assesses whether that is appropriate given the desk's performance, the market environment, and the firm's overall risk appetite.

Second-line functions provide management information (MI) to senior management and the board — daily P&L and limit utilisation reports, monthly risk committee packs, escalation reports on limit breaches or compliance incidents. This MI is what allows the board and senior management to exercise oversight of the risks the firm is running.

The Compliance Function

Within the second line, compliance plays a distinct role. It oversees adherence to regulatory requirements and the firm's own code of conduct. In a capital markets context, compliance monitors trading activity for potential market abuse, reviews communications and trade surveillance outputs, manages regulatory relationships (including responding to information requests from the FCA or PRA), and approves new products and marketing materials. Compliance also owns the training and certification framework — ensuring that staff are properly trained and certified for the products and activities they are involved in.

The Third Line: Internal Audit

The third line of defence is internal audit. Internal audit provides independent assurance to the board and senior management that the first and second lines are operating effectively. It does not manage risk or set control frameworks — that is the first and second lines' job. Audit's role is to assess, test, and report on whether those frameworks are fit for purpose and functioning as intended.

Internal audit in a capital markets business covers a wide range of topics: trading controls (limit setting, limit monitoring, escalation processes), valuation and P&L processes, regulatory reporting, operational controls (settlement, reconciliation, payments), model governance, information barriers, and the adequacy of the second-line oversight functions themselves. Audit findings are rated by severity — typically on a scale from advisory to critical — and management is required to agree remediation actions and deadlines.

The PRA and FCA place significant weight on the quality and independence of internal audit. They expect the Chief Internal Auditor (CIA) to have direct access to the board audit committee, to be able to raise concerns without interference from management, and to have the resources and skills to audit the full range of the firm's activities, including technically complex areas like model risk and algorithmic trading.

How the Lines Interact

The three lines are not siloed: they interact continuously. The first line raises issues and incidents; the second line provides guidance, oversight, and challenge; the third line assesses both. There are formal interaction mechanisms — audit findings are addressed by first-line management with second-line oversight of remediation; second-line risk frameworks are periodically reviewed by internal audit; regulatory findings from second-line compliance reviews can trigger internal audit coverage.

The board and its committees — typically a Risk Committee, Audit Committee, and in larger banks a Conduct and Ethics Committee — receive reporting from all three lines and provide governance oversight. The board is responsible for setting the risk appetite within which all three lines operate.

Where the Model Breaks Down

The three-lines model is conceptually clear but operationally fragile. The most common failure modes include:

  • Line blurring: Second-line functions that become too embedded in first-line decisions lose their independence. A compliance officer who approves every trade structure is no longer providing oversight — they have become part of the first line, removing the independent check.
  • First-line abdication: Business teams that treat risk management as someone else's problem — assuming that if second-line didn't object, it must be acceptable — have abandoned their ownership responsibility. This is a cultural failure that regulators take seriously.
  • Resource imbalance: A chronically under-resourced second line, challenged by a large and sophisticated first line, cannot provide effective oversight. This is a board-level governance failure.
  • Audit capture: An internal audit function whose findings are routinely downgraded under pressure from management, or whose access to information is restricted, is not functioning independently.

The PRA's supervisory framework explicitly assesses whether the three-lines model is functioning effectively in practice, not merely on paper. Firms that demonstrate genuine first-line ownership, effective second-line challenge, and genuinely independent audit receive more supervisory credit than those whose governance documentation describes the model but whose practice does not reflect it.