Governance & GRC

Risk ownership and accountability under the three-lines model

Practical guidance on assigning risk ownership so that the three-lines model produces accountability rather than paperwork.

By Jonas Osman AbdelfourPublished December 10, 2025

Summary The three-lines model is widely adopted and unevenly implemented. The most common failure is assigning ownership at the level of a risk category rather than at the level of a process, which leaves nobody accountable for the controls that actually operate.

Ownership at process level Risk ownership is meaningful when it identifies a named accountable executive for a defined process, with authority over the resources, systems and people that operate the controls. Ownership at the level of "credit risk" or "operational risk" is a taxonomy, not an accountability.

The role of the second line The second line sets the framework, challenges first-line assessments, and monitors aggregate exposures. It does not operate controls. Where the second line runs controls — a common drift under resource pressure — the model has collapsed into two lines and internal audit's assurance is compromised.

RCSAs as an accountability instrument Risk and control self-assessments are only useful when the first line owns them. A second-line-authored RCSA is not an assessment; it is a checklist. RCSAs should identify inherent risk, control design, control effectiveness (tested), residual risk and remediation actions with owners and dates.

Escalation and issue management Issues should escalate on defined thresholds, not on judgement calls. Aging, ownership and remediation status belong in standard committee reporting.

Limitations Cultural readiness matters. Firms that promote the model without investing in first-line risk capability tend to produce shadow second-line teams inside the business, which recreate the original problem.

Related expertise See [Governance, Risk and Compliance](/expertise/grc).

Frequently asked questions

What should risk leaders know about ownership at process level?

Risk ownership is meaningful when it identifies a named accountable executive for a defined process, with authority over the resources, systems and people that operate the controls. Ownership at the level of "credit risk" or "operational risk" is a taxonomy, not an accountability.

What should risk leaders know about the role of the second line?

The second line sets the framework, challenges first-line assessments, and monitors aggregate exposures. It does not operate controls. Where the second line runs controls — a common drift under resource pressure — the model has collapsed into two lines and internal audit's assurance is compromised.

What should risk leaders know about rCSAs as an accountability instrument?

Risk and control self-assessments are only useful when the first line owns them. A second-line-authored RCSA is not an assessment; it is a checklist. RCSAs should identify inherent risk, control design, control effectiveness (tested), residual risk and remediation actions with owners and dates.

What should risk leaders know about escalation and issue management?

Issues should escalate on defined thresholds, not on judgement calls. Aging, ownership and remediation status belong in standard committee reporting.