Risk management

Three lines of defence: who owns risk in a company

Who owns the risk, who sets the rules and who checks both. A short read on the three lines model and the three distortions that show up most often.

Updated: 17 August 2026 · Author: Evgeny Telenkov · ≈ 4 min read

The argument about who owns risk is settled once by a simple three-level model. It answers not "who is to blame" but "who does what".

First line — those who create the risk

Sales, operations, procurement, IT, HR. These units run the business and generate risk along the way. The risk owner always sits here. They make the decisions, control the resources and carry the consequences.

The practical consequence matters more than the model: if the register names a risk manager as owner, the model is broken. Only someone with authority to change the process can manage the risk. See risk management without bureaucracy.

Second line — those who set the rules

Risk management, compliance, security, continuity. The second line writes the methodology, consolidates the picture, watches limits and argues with the first line when it underestimates exposure.

What it does not do is decide on behalf of the first line. Its power is argument and the right to escalate, not a veto. Once the second line starts managing risks instead of the first, the system turns into reporting.

Third line — those who check the other two

Internal audit. Its job is to assess independently whether the first two lines work. Independence comes from reporting: audit answers to the board or audit committee, not to the management it reviews.

That is why the third line should not help build the system it will later audit. This is the most common compromise in smaller companies and the most common reason audit stops finding anything.

Three typical distortions

FAQ

Is the three lines model mandatory? For most companies it is management practice rather than law. Regulators and auditors use it as a reference, and in supervised entities the separation of lines is examined.

Do we need three separate departments? No. Below about a thousand staff the second line is often one combined role. What matters is separation of duties and reporting, not headcount.

Where does business continuity sit? In the second line: it sets methodology and consolidates the picture. Processes are restored by their owners, which is the first line.

Section 03 · Risk management Risk management system → · All guides in this section