The argument about who owns risk is settled once by a simple three-level model. It answers not "who is to blame" but "who does what".
First line — those who create the risk
Sales, operations, procurement, IT, HR. These units run the business and generate risk along the way. The risk owner always sits here. They make the decisions, control the resources and carry the consequences.
The practical consequence matters more than the model: if the register names a risk manager as owner, the model is broken. Only someone with authority to change the process can manage the risk. See risk management without bureaucracy.
Second line — those who set the rules
Risk management, compliance, security, continuity. The second line writes the methodology, consolidates the picture, watches limits and argues with the first line when it underestimates exposure.
What it does not do is decide on behalf of the first line. Its power is argument and the right to escalate, not a veto. Once the second line starts managing risks instead of the first, the system turns into reporting.
Third line — those who check the other two
Internal audit. Its job is to assess independently whether the first two lines work. Independence comes from reporting: audit answers to the board or audit committee, not to the management it reviews.
That is why the third line should not help build the system it will later audit. This is the most common compromise in smaller companies and the most common reason audit stops finding anything.
Three typical distortions
- Second and third lines merged. Risk management builds the system and grades its own work. A saving on paper, a loss of independent assurance in practice.
- The first line does not know it is the first line. Heads of business believe risk is somebody else's function. Fixed not by policy but by putting risk on the agenda before decisions are taken.
- Lines exist, escalation does not. The second line reports a breach and nothing happens. The model only works when escalation has an addressee with authority — see risk appetite.
FAQ
Is the three lines model mandatory? For most companies it is management practice rather than law. Regulators and auditors use it as a reference, and in supervised entities the separation of lines is examined.
Do we need three separate departments? No. Below about a thousand staff the second line is often one combined role. What matters is separation of duties and reporting, not headcount.
Where does business continuity sit? In the second line: it sets methodology and consolidates the picture. Processes are restored by their owners, which is the first line.