RUEN
Home/Materials/Three lines of defence
Risk management

Three lines of defence: who owns risk in a company

Who owns the risk, who sets the rules and who checks both. A short read on the three lines model and the three distortions that show up most often.

Updated: 17 August 2026 · Author: Evgeny Telenkov · ≈ 4 min read

The argument about who owns risk is settled once by a simple three-level model. It answers not "who is to blame" but "who does what".

First line — those who create the risk

Sales, operations, procurement, IT, HR. These units run the business and generate risk along the way. The risk owner always sits here. They make the decisions, control the resources and carry the consequences.

The practical consequence matters more than the model: if the register names a risk manager as owner, the model is broken. Only someone with authority to change the process can manage the risk. See risk management without bureaucracy.

Second line — those who set the rules

Risk management, compliance, security, continuity. The second line writes the methodology, consolidates the picture, watches limits and argues with the first line when it underestimates exposure.

What it does not do is decide on behalf of the first line. Its power is argument and the right to escalate, not a veto. Once the second line starts managing risks instead of the first, the system turns into reporting.

Third line — those who check the other two

Internal audit. Its job is to assess independently whether the first two lines work. Independence comes from reporting: audit answers to the board or audit committee, not to the management it reviews.

That is why the third line should not help build the system it will later audit. This is the most common compromise in smaller companies and the most common reason audit stops finding anything.

Three typical distortions

  • Second and third lines merged. Risk management builds the system and grades its own work. A saving on paper, a loss of independent assurance in practice.
  • The first line does not know it is the first line. Heads of business believe risk is somebody else's function. Fixed not by policy but by putting risk on the agenda before decisions are taken.
  • Lines exist, escalation does not. The second line reports a breach and nothing happens. The model only works when escalation has an addressee with authority — see risk appetite.

FAQ

Is the three lines model mandatory? For most companies it is management practice rather than law. Regulators and auditors use it as a reference, and in supervised entities the separation of lines is examined.

Do we need three separate departments? No. Below about a thousand staff the second line is often one combined role. What matters is separation of duties and reporting, not headcount.

Where does business continuity sit? In the second line: it sets methodology and consolidates the picture. Processes are restored by their owners, which is the first line.

Section 03 · Risk management Risk management system → · All guides in this section

From the risk register to management decisions

Check whether your risks reach the people who decide. The dashboard shows the state on one screen, the turnkey engagement makes it work.