Summary The three-lines model was designed for large institutions. In mid-size firms, applying it verbatim can produce duplication and cost without proportionate benefit. The model still works, but it must be sized to the institution.
Proportionality in design Small second-line and internal audit functions can be effective if their remits are focused, their access rights are clear, and their reliance on the first line is documented. What cannot be compressed is independence.
The first line The first line owns risk, operates controls, and is accountable for outcomes. In mid-size firms, dedicated first-line risk roles (business risk officers, control managers) often make the model workable at proportionate cost.
The second line The second line sets policy, monitors compliance with policy, and challenges first-line assessments. In a proportionate design, monitoring is targeted at areas of higher inherent risk rather than blanket.
Internal audit Internal audit provides independent assurance over the design and operation of the framework as a whole. Co-sourcing specialist skills — model risk, cyber, financial crime — is common practice and does not compromise independence when governance is clear.
Common pitfalls The second line drifting into control operation is the most damaging pitfall. It is usually a symptom of first-line under-resourcing; the fix is upstream.
Limitations The model does not eliminate risk. It structures accountability so that failures are visible and correctable.
Related expertise See [Governance, Risk and Compliance](/expertise/grc).
Frequently asked questions
What should risk leaders know about proportionality in design?
Small second-line and internal audit functions can be effective if their remits are focused, their access rights are clear, and their reliance on the first line is documented. What cannot be compressed is independence.
What should risk leaders know about the first line?
The first line owns risk, operates controls, and is accountable for outcomes. In mid-size firms, dedicated first-line risk roles (business risk officers, control managers) often make the model workable at proportionate cost.
What should risk leaders know about the second line?
The second line sets policy, monitors compliance with policy, and challenges first-line assessments. In a proportionate design, monitoring is targeted at areas of higher inherent risk rather than blanket.
What should risk leaders know about internal audit?
Internal audit provides independent assurance over the design and operation of the framework as a whole. Co-sourcing specialist skills — model risk, cyber, financial crime — is common practice and does not compromise independence when governance is clear.
What should risk leaders know about common pitfalls?
The second line drifting into control operation is the most damaging pitfall. It is usually a symptom of first-line under-resourcing; the fix is upstream.