The Three Lines of Defense That Actually Work

The three lines of defense model has been the risk management framework the banks and the consultancies have been selling the board for fifteen years. In practice, the third line usually does not exist, the second line usually does not…

A single brass shield on a dark wood surface, dim warm amber side light, deep navy shadows, no people visible.

The three lines of defense model has been the risk management framework the banks and the consultancies have been selling the board for fifteen years. In practice, the third line usually does not exist, the second line usually does not have authority, and the first line usually does not have the time. The model that the risk committee approved last year serves as the the model the next incident will prove does not work, and the audit team that signed off on the model will be the first to acknowledge the gap when the postmortem lands. The honest framing matters here, because the three lines of defense that the regulator expects. the the three lines the enterprise has been pretending to operate.

What follows runs as the working version of the field guide. The shorter version is what the risk leader actually has time to read.

What the model is supposed to be

Three lines, in roughly that order of how much each one matters. The first runs as the operational management, where the business owner of the risk runs the control, the first line that owns the day to day execution of the risk management. The business owner of the cyber risk is what the CIO, the CTO, the head of product, the business owner who actually builds and runs the system. The second runs as the risk management and compliance, where the independent function oversees the first line, the second line that sets the policy, the standard, the framework, the oversight that the first line cannot provide for itself. The second line , the the risk officer, the compliance officer, the CISO, the function that has the authority to challenge the first line. The third runs as the internal audit, where the independent assurance function provides the assurance to the board, the third line that audits the first and the second, the third line that reports directly to the audit committee, the third line that the regulator expects to be functionally independent from the first and the second.

What it usually looks like

Three gaps, in roughly that order of how often each one shows up. The first runs as the missing third line, where the internal audit function does not exist or sits under the CFO who also sits over the first line, the independence the model requires sits missing, the third line that the regulator expects serves as the third line the enterprise does not have. The second runs as the underpowered second line, where the risk and compliance function sits staffed at a tenth of the size the first line requires, the second line that should challenge the first line cannot challenge the first line because the second line does not have the headcount, the budget, the authority. The third runs as the time poor first line, where the business owner of the risk sits consumed by the operational fire, the day to day execution that leaves no time for the risk management the model requires, the first line that should own the control ends up treating the control as the compliance checkbox.

How to make it actually work

Three moves if you are the risk leader that wants the three lines to actually operate as the model describes. Resource the second line, because the second line that has the headcount, the budget, the authority to challenge the first line is essentially the the second line that the model requires, the second line that the enterprise under funds serves as the second line that the regulator will cite. The second line that has the authority to block the project serves as the second line that prevents the project the risk committee never approved. Make the third line independent, because the internal audit function that reports to the audit committee, that does not report to the CFO, that has the authority to audit the second line serves as the third line the model describes. The independence costs the political capital the risk leader will need to spend. Restore the first line’s time, because the business owner of the risk who has the time to do the risk management, the time that the operations team protects on the calendar, the time that the risk committee measures, the first line that has the time serves as the first line that actually owns the control. The risk leader who resources, makes independent, and restores the time serves as the leader who has made the three lines actually work.

Abstract three lines of defense as glowing cyan layered arc on a dark navy surface, dramatic chiaroscuro lighting from above.
The three lines in 2026: 3 things the model is supposed to be, 3 things it usually looks like, 3 moves to make it actually work.

The bottom line

The three lines of defense in 2026 sit as the model the regulator expects and the enterprise rarely operates. The resource the second line, make the third line independent, restore the first line’s time, those three moves are what closes the gap. The enterprise that does the three moves has the three lines that work. The enterprise that has the three lines on the org chart does not.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading