Three Lines of Financial Crime Defence
A bank does not prevent financial crime simply by having an AML department. It prevents financial crime when the people who create and manage customer, product, payment and channel risk understand what they own; when an appropriately independent compliance function sets standards and challenges management; when internal audit can independently assess whether governance and controls are genuinely effective; and when the board receives a sufficiently clear view of material risk to act.
That is the practical value of the Three Lines Model. It is not a drawing of three departments and it is not a rule that every bank must use identical job titles. It is a way of organising accountability, action, challenge and assurance so that important financial-crime risks do not fall into the spaces between business, operations, compliance, technology and audit.
The distinction matters because modern financial-crime controls are distributed. Customer due diligence may be performed by an onboarding operations team. Sanctions screening may run on a central technology platform. Transaction-monitoring alerts may be investigated by a shared service centre. Fraud teams may detect mule activity that AML investigators later assess. A country compliance officer may interpret local law while a group financial-crime function owns global standards. Data engineers may control the pipelines that determine whether millions of transactions ever reach a detection engine. If everyone assumes that “Compliance owns AML,” the bank can have excellent specialists and still fail because the operational ownership of the control was never made real.
The chapter therefore treats the Three Lines Model as a financial-crime accountability architecture. The first line is management: it owns activities, risks and controls. The second line is also part of management, but has specialist risk and compliance roles that provide expertise, monitoring and challenge. The third line is internal audit, which must retain the independence and objectivity necessary to give the governing body confidence about governance, risk management and control. The governing body or board sits above the model in an oversight role; regulators, financial intelligence units, external auditors and other external assurance providers sit outside it.
Start with the most important idea: ownership cannot be outsourced to Compliance
A relationship manager who introduces a corporate customer, a product owner who designs an instant-payment feature, an operations team that repairs payment data, a technology team that transforms ISO 20022 messages, and a business executive responsible for a correspondent-banking portfolio all make decisions that affect financial-crime exposure. They may rely heavily on specialist policy and advice, but the risk created by the business activity does not disappear because a compliance function exists.
This is why the first line is more than “the people who process transactions.” In a bank, first-line roles normally include the management and operational functions responsible for delivering products and services, taking business decisions, maintaining systems and data, and operating controls. Depending on the institution, that can include business units, customer onboarding, payment operations, product management, financial-crime operations, fraud operations, technology, data teams, service management and control offices. A central AML investigations team may also perform first-line activity if its job is to operate a management control, even if the word “AML” appears in the team name.
The second line does not remove that responsibility. Its purpose is to provide specialist capability and an independent-enough management perspective: translating law and risk appetite into frameworks, advising on implementation, monitoring adherence, challenging weaknesses, escalating material concerns and reporting its own view of risk. The second line may set the customer-risk-rating methodology, define sanctions-screening standards, approve financial-crime policy, challenge transaction-monitoring coverage or oversee suspicious-activity-reporting governance. But if the second line ends up running every operational control and fixing every first-line defect, it becomes difficult to distinguish ownership from oversight.
Internal audit then provides a different kind of confidence. It is not the “stronger compliance team.” Its value comes from being able to step outside management’s operation and oversight of risk and independently assess whether governance, risk management and controls are designed and operating effectively. It needs access to records, people, systems and evidence, and it needs sufficient standing to report significant conclusions to the board or audit committee without management filtering the message.
The model therefore rests on a simple sequence: management owns and acts; specialist management functions advise and challenge; internal audit independently assures; the governing body oversees. The quality of financial-crime governance depends on how clearly those responsibilities are translated into actual processes, systems, decisions and evidence.
The model is not a universal law
It is important to separate a governance model from binding legal obligations. The Institute of Internal Auditors’ Three Lines Model is a widely used governance framework, not a statute that automatically applies in identical form to every organisation. In July 2026, The IIA replaced its earlier position paper with a refreshed Statement of Position on the Three Lines Model. The current statement puts particular emphasis on accountability to the governing body, the distinct contribution of management and internal audit, and the value of coordination without weakening internal audit independence.
FATF takes a different route. The FATF Recommendations do not prescribe one global organisation chart called the Three Lines Model. Recommendation 18 and its Interpretive Note require financial institutions to maintain programmes against money laundering and terrorist financing that include internal policies, procedures and controls, appropriate compliance-management arrangements, employee screening and training, and an independent audit function to test the system. FATF also expects these arrangements to be risk-sensitive and proportionate to the business. Those requirements support many of the same governance principles, but banks should not describe “three lines” itself as a FATF legal requirement.
The Basel Committee likewise provides strong supervisory expectations for bank compliance and internal audit without insisting that every bank use one identical structure. The Basel Consolidated Guidelines published in 2026 describe an independent and sufficiently resourced compliance function as a key component of the second line of defence, and they expect its activities to be periodically and independently reviewed by internal audit. Basel’s internal-audit guidance stresses independence from audited activities, access to records and data, risk-based audit planning, board oversight and timely management action on findings. Those are highly relevant to financial-crime governance in banks, but they must still be read alongside national law and supervisory requirements.
In the European Union, the EBA Guidelines on internal governance under the Capital Requirements Directive provide another layer for in-scope institutions. They set expectations around the internal-control framework, control functions, governance, management-body responsibilities and independence. Other jurisdictions use their own legislation, supervisory handbooks and licensing conditions. An international bank therefore needs a global operating model that can accommodate different local legal responsibilities rather than assuming that one group RACI automatically answers every jurisdictional question.
The correct professional statement is: the Three Lines Model is a useful governance framework; specific legal responsibilities come from the laws, regulations, regulatory guidance, licences and corporate-governance arrangements applicable to the bank and its entities.
The governing body: oversight is not the same as operating the control
The board or equivalent governing body is not usually the team that decides whether a transaction-monitoring alert should be closed. Its responsibility is broader. It should ensure that the institution has appropriate governance, resources, accountability and risk management, and that material weaknesses are visible and acted upon. In financial crime, this means the board needs information that allows it to understand the institution’s exposure and the effectiveness of the framework rather than simply receiving large packs of operational statistics.
Useful board-level information connects risk to outcomes. A statement that “98 per cent of KYC reviews were completed within SLA” may look reassuring but can hide serious weaknesses if the two per cent overdue population contains the highest-risk customers. A sanctions dashboard that reports low alert volumes may be meaningless if an upstream data feed excluded a major payment channel. A transaction-monitoring report that celebrates fewer alerts may hide coverage reduction caused by a configuration change. Governance therefore depends on the quality of the story behind the metric.
The board should be able to understand where the institution is outside risk appetite, where a control is materially ineffective, whether remediation is realistic, whether regulatory notifications are required, whether customer harm is occurring, and whether management is allocating enough resources to the problem. It should also receive an independent perspective from internal audit and, depending on the structure, direct or sufficiently independent reporting from senior risk and compliance leaders.
Board oversight does not mean the board becomes an operational approval layer for routine cases. Overloading senior governance with low-level decisions can weaken accountability because managers begin escalating ordinary responsibilities rather than exercising them. Good governance defines thresholds: what can be managed in ordinary operations, what requires second-line escalation, what must reach senior management, and what is sufficiently material to reach a board committee or the full board.
First line: where financial-crime risk becomes real
The first line operates the bank. That sounds obvious, but in financial-crime programmes the boundary is frequently misunderstood because many operational teams are specialist control teams rather than revenue-generating businesses. The better test is not whether the team “makes money.” The test is whether the team is part of management and is responsible for delivering an activity, operating a control or managing the risk created by the activity.
Consider customer onboarding. A commercial-banking business decides which customer segment to serve and which products to offer. An onboarding operations team collects and validates customer information. A KYC platform checks required fields and routes cases. A sanctions-screening service screens the legal entity and connected parties. A relationship manager explains business purpose and expected activity. Data teams move customer information into downstream monitoring systems. These are different roles, but together they create and operate the first-line control environment.
First-line ownership normally includes knowing the relevant policy, translating requirements into procedures and technology, executing the control, recording evidence, managing exceptions, monitoring performance, identifying defects and fixing them. It also includes challenging impractical designs before implementation. A product owner should not wait until compliance testing finds that a new feature bypasses a screening step. Financial-crime requirements need to be part of product and architecture decisions from the beginning.
Technology ownership is particularly important. If a payment-screening engine works perfectly on the data it receives but a mapping defect drops the ultimate debtor from one message path, the financial-crime control still fails. The engineer or platform team may not own sanctions policy, but the first line owns the completeness and reliability of the process and data components within its responsibility. Control ownership must follow the entire chain rather than stop at the boundary of the compliance application.
The first line also owns remediation. Second-line compliance may challenge a weakness and internal audit may report a finding, but management should normally own the corrective action. If audit writes the solution, builds the control and then audits it, independence is compromised. If compliance permanently performs management’s remediation because the business does not have capability, accountability becomes blurred. Specialists can advise, but the responsible management owner must remain visible.
Second line: specialist oversight without becoming the operator of everything
Financial-crime compliance is a specialist discipline. It interprets regulatory expectations, understands typologies and risk, sets policy, advises management, oversees the programme and challenges whether controls are proportionate and effective. This is a substantial role. It is not merely reviewing first-line documents after decisions have already been made.
A strong second line starts with a clear mandate. It should know which policies and standards it owns, which decisions require its approval or concurrence, where it has authority to stop or escalate activity, how it reports to senior management and the board, and how it preserves sufficient independence from the business it challenges. The mandate should also distinguish advisory work from monitoring and formal compliance testing.
In AML and CFT, second-line responsibilities may include the enterprise or business-line risk assessment methodology, customer-risk policy, enhanced-due-diligence standards, suspicious-activity governance, regulatory interpretation, training requirements, quality expectations, thematic review, control monitoring and escalation. In sanctions, the second line may own sanctions policy, legal-regime interpretation, list and screening standards, ownership-and-control methodology, licensing guidance and escalation for potential true matches. Exact responsibilities depend on the bank and jurisdiction.
Second-line challenge must be evidence-based. Saying “we are not comfortable” may be a valid trigger for further analysis, but it is not a substitute for explaining the risk, policy requirement, control weakness and required action. The strongest compliance teams can articulate both the legal position and the risk rationale, distinguish mandatory requirements from risk appetite, and show what evidence would resolve the concern.
At the same time, independence does not mean isolation. Basel’s current compliance guidance explicitly recognises that an independent compliance function can work closely with business and management. Early involvement is often more effective than late rejection. A compliance specialist participating in the design of a new payment product can identify sanctions, CDD, monitoring and reporting requirements before architecture hardens. The key safeguard is that advice does not silently transfer management accountability to the adviser.
Third line: assurance must remain genuinely independent
Internal audit is the third line because its relationship to management is intentionally different. It is expected to form an independent view of the adequacy and effectiveness of governance, risk management and controls. In a bank, that can include the financial-crime framework, but also the second-line compliance function itself.
This last point is fundamental. Compliance cannot be the final judge of whether compliance is effective. The Basel Consolidated Guidelines state that the compliance function should be subject to periodic review by internal audit and that compliance and audit should be separate. Internal audit should be able to assess whether policy governance is effective, whether monitoring is sufficiently independent, whether issues are escalated, whether regulatory obligations are understood and whether the function has adequate authority and resources.
An AML audit should not consist only of checking that procedures exist. It should examine whether the control environment can reasonably achieve its purpose. For transaction monitoring, that may require looking at risk coverage, source-data completeness, transformation logic, scenario governance, alert generation, case quality, backlogs, tuning governance and suspicious-activity reporting. For sanctions, it may require evaluating list governance, customer rescreening, payment-screening coverage, name-matching configuration, ownership-and-control processes, interdiction operations and decision evidence.
Audit independence does not mean internal auditors must know nothing about a control until the day they test it. Modern governance depends on information sharing. Internal audit can observe major programmes, understand emerging risk, share general control insights and coordinate assurance activity. What it must avoid is assuming management responsibility in a way that later requires it to audit its own decisions.
The current IIA position is useful here: coordination and reliance among the lines can improve coverage, but safeguards are necessary when roles overlap. A practical bank should therefore document where internal audit provides advisory input, what decisions remain with management, and how objectivity will be protected if auditors have previously been involved in an area.
A role label is not enough
Large banks often create titles such as “Business Financial Crime Risk,” “First Line Financial Crime,” “Compliance Operations,” “Control Office,” “Financial Crime Centre of Excellence” or “Independent Testing.” None of these titles proves which line the team belongs to. A team’s line depends on its purpose, reporting, authority and activities.
A first-line financial-crime team can be entirely legitimate. For example, a business division may maintain specialist AML advisers who help product and operations teams implement controls while remaining part of management. A second-line team may perform monitoring or targeted testing to challenge first-line compliance. An internal-audit team may have deep sanctions specialists. The problem appears when the same control is described differently by different stakeholders or when nobody can identify the accountable owner.
This is why RACI charts are useful but insufficient. “Responsible,” “Accountable,” “Consulted” and “Informed” can help describe activity, but they do not override statutory responsibilities, regulated-function responsibilities or delegated authorities. A bank should connect the RACI to the control inventory, policy hierarchy, committee mandates, job descriptions, system ownership and escalation procedures.
Customer due diligence: an example of shared work without shared ambiguity
CDD shows why simplistic statements such as “KYC is a Compliance process” are dangerous. A bank may have a second-line policy that defines minimum identity, verification, beneficial-ownership, purpose, expected-activity and enhanced-due-diligence requirements. But first-line teams need to implement those requirements in customer journeys, operating procedures and systems.
Suppose a corporate customer has three ownership layers across different countries. The first line collects company documents, resolves ownership, verifies authorised representatives, obtains business-purpose information and records expected account activity. A second-line compliance team may define when enhanced evidence is required, advise on high-risk jurisdiction exposure, challenge whether the ownership chain has been adequately understood and approve a narrow set of high-risk relationships if policy assigns it that role. Internal audit may later assess whether the bank’s onboarding framework, data, risk rating and quality controls are effective.
If the first line simply sends every difficult question to compliance and treats a compliance response as ownership of the file, two problems arise. First, business and operations stop building expertise. Second, the second line becomes so involved in individual execution that its capacity to oversee population-level risk can weaken. A mature model reserves second-line involvement for defined decisions, high-risk matters and oversight while requiring first-line capability to handle normal complexity.
The same logic applies to periodic review. The first line should know which customers are due, obtain updated information, investigate material changes and complete the review. The second line should monitor whether the process is effective, challenge overdue high-risk populations and identify systemic weaknesses. Internal audit should assess the framework independently according to its risk plan.
Sanctions screening: policy ownership is not data ownership
Sanctions controls make line accountability particularly visible because legal consequences can be time-critical. Screening may involve customer data, payment messages, vessel or trade information, sanctions lists, fuzzy matching, alert queues and specialised legal decisions. No single team controls every dependency.
Second-line sanctions compliance may interpret applicable regimes and define what needs to be screened, what ownership-and-control tests apply, which lists are in scope, how potential matches should be escalated and what evidence is required for release, reject, block or freeze decisions. But the first line commonly owns the platforms, source systems, integrations, operational queues, service levels and data quality that make those standards executable.
Imagine a payment hub migrates from an older message model to ISO 20022. The screening engine receives debtor and creditor names, but an intermediary mapping accidentally omits ultimate-party data for one channel. The screening application itself remains available and its matching algorithm works as designed. Yet the end-to-end control is incomplete. The first-line technology and payment owners must treat that as a financial-crime control defect, not merely a technical mapping issue. The second line should challenge severity, affected population, interim controls and remediation. Internal audit may later review the programme, particularly if the issue was material or exposed weaknesses in change governance.
The strongest control inventories therefore identify not only “payment sanctions screening” but the important components that determine effectiveness: source-data ownership, message mappings, list ingestion, matching configuration, alert workflow, analyst decisioning, licence logic, case evidence, reconciliations and reporting. This makes accountability testable.
Transaction monitoring: the scenario is only one part of the control
Transaction monitoring is often described as a rules engine. In reality, the control begins much earlier. Customer and account data need to be accurate. Transactions from relevant products and channels need to be captured. Data transformations need to preserve meaning. Customer-risk attributes need to reach the engine. Scenarios or models need appropriate coverage and thresholds. Alerts need to be generated, prioritised and investigated. Cases need evidence and escalation. Suspicious activity may need reporting under local law.
First-line responsibilities therefore extend across data, technology, operations and remediation. A model or scenario owner should understand production behaviour, not only design logic. An investigations manager should understand ageing, productivity and quality but also whether analysts have the right data to make decisions. A data owner should know which financial-crime controls depend on a field before changing its format or source.
Second-line compliance should provide the risk framework and challenge whether monitoring coverage is proportionate to the institution’s risks. It may conduct thematic monitoring, review tuning governance, assess typology coverage, challenge backlogs and require evidence for material model changes. Depending on the bank, specialist model-risk functions may also play roles, but the line assignment should be explicit.
Internal audit can then independently test whether the whole chain works. It may sample source-to-engine completeness, evaluate governance over scenario changes, examine whether risk assessment informs monitoring, assess alert disposition quality and review the suspicious-activity-reporting process. If audit tests only analyst case notes while ignoring missing data, it can give false comfort.
Fraud, AML and mule activity: shared intelligence does not require blurred ownership
Fraud and AML frequently overlap. An authorised-push-payment scam can create an immediate customer-harm event for the sending bank and criminal proceeds for the receiving bank. A mule account may first be detected by fraud analytics, device intelligence or payment behaviour and later require AML investigation and regulatory reporting. These teams need to exchange intelligence quickly.
The Three Lines Model should not become a reason to create silos. First-line fraud and AML operations can share alerts, cases, account restrictions and intelligence where law and policy permit. Second-line financial-crime compliance can set governance for escalation and suspicious-activity reporting. Internal audit can assess whether the hand-off works and whether risks are lost between systems.
A frequent failure mode is “not my queue.” Fraud sees a scam but assumes AML will handle the beneficiary. AML sees unusual movement but assumes fraud already assessed it. Payments sees a recall request but does not link it to the customer risk profile. Effective governance defines triggers, ownership transfer, shared identifiers, evidence requirements and service levels.
This is a good example of why governance should follow the customer and value flow rather than the organisation chart. Criminal behaviour moves across products faster than internal teams do.
Suspicious-activity reporting: operational preparation and accountable legal decisioning
SAR or STR responsibilities vary significantly by jurisdiction. Some legal frameworks assign obligations to the institution; some create specific responsibilities for nominated officers or reporting officers; confidentiality and tipping-off rules also differ. A global bank should therefore avoid writing one universal RACI for the legal decision to report.
The Three Lines Model can still organise supporting responsibilities. First-line investigation teams may gather transaction history, customer information, linked parties, prior alerts and narrative evidence. Second-line AML compliance may set the reporting framework, oversee decision quality and, where local law and delegation provide, make or supervise reporting decisions. Technology and data teams must ensure cases and regulatory files contain required information. Governance teams track timeliness, quality and material issues.
Internal audit can assess the reporting framework but should not become the decision maker on individual disclosures. Its role is to evaluate whether governance, escalation, confidentiality, timeliness, data quality and control effectiveness are adequate.
The key principle is to document the actual legal and delegated authority. A workflow field labelled approvedByCompliance is not enough. Requirements should identify which role can make the decision, under what jurisdiction, what evidence must be retained, who can access the information, how deadlines are calculated and how conflicts or escalations are handled.
Correspondent banking and trade finance: line ownership becomes more complex
Correspondent banking combines customer risk, payment transparency, nested activity, sanctions exposure, respondent controls and cross-border legal complexity. The business relationship owner should understand the respondent, services provided, expected corridors and risk. First-line due-diligence and payment teams operate controls. Second-line compliance sets enhanced-due-diligence standards, challenges high-risk relationships and may participate in senior approvals. Internal audit assesses whether the framework works across onboarding and transaction activity.
Trade finance creates another layer because risk may depend on parties, goods, documents, vessels, ports, routes and sanctions restrictions. Operations may review documents while sanctions specialists assess potential restricted-party or goods exposure. Product and technology teams own system capability. Compliance defines standards and escalation. No single “sanctions team” can compensate for incomplete trade data or weak document capture.
In both areas, global-local governance is crucial. A group standard may require certain minimum controls, but a branch may face stricter local law. The operating model needs a method to identify, approve and implement local addenda without fragmenting the control environment beyond recognition.
A control lifecycle clarifies where each line contributes
Financial-crime controls should be governed through their whole lifecycle. A policy is not a control until it is translated into something that can be operated and evidenced.
The lifecycle normally begins with external obligations, risk assessment and risk appetite. The second line has a major role in translating those inputs into policy and minimum standards. Management then designs processes, data requirements, system logic, procedures and human decision points. The first line builds and tests the control, implements it, operates it and records evidence. The second line monitors, reviews and challenges whether implementation continues to meet the framework. Internal audit independently evaluates governance and effectiveness according to its risk-based plan. Issues and lessons then feed back into risk assessment and policy.
This lifecycle helps resolve a common argument: “Who owns the control design?” The answer can be split. Compliance may own the standard—for example, that all relevant payment parties must be screened against specified sanctions data using an approved risk-based matching approach. Management owns the operational design that makes the standard work in systems and procedures. Compliance challenges that design. Audit later assesses it independently.
The distinction is important for business analysts. A policy sentence such as “screen payments before execution” is not a sufficient requirement. The BA must ask which rails, messages, parties and fields are in scope; where screening occurs; what happens when data is missing; whether screening is synchronous or asynchronous; how list updates are applied; what constitutes a potential match; how holds are represented; how repair or release is controlled; how evidence is stored; and what happens during system failure.
Data ownership is financial-crime ownership
Banks increasingly understand that weak data can defeat otherwise sophisticated controls. Three-lines governance needs to reach into data architecture because screening, monitoring and investigation all depend on information created elsewhere.
Customer data may originate in several onboarding systems. Beneficial ownership may be stored in a graph or document repository. Payments may be transformed through channel, payment hub, gateway and correspondent formats. Merchant, device, card and digital-session information may sit in separate platforms. Screening lists and adverse information may come from external providers. Transaction-monitoring engines may enrich data with country risk, customer risk and product classifications.
The first line should own the quality and lineage of the data it creates or transforms. That means clear source owners, definitions, reconciliations, change controls and exception processes. The second line should define which data is risk-relevant and challenge whether coverage is adequate. Internal audit should be able to trace material controls through the source-to-decision chain rather than relying solely on application screenshots.
A mature control record therefore identifies critical data elements. For payment screening, these might include debtor, creditor, ultimate parties, agents, addresses, country data, remittance information and vessel or trade identifiers where relevant. For transaction monitoring, they may include customer identifier, account relationship, amount, currency, timestamp, channel, counterparty, country, transaction code and risk attributes. The precise set depends on the control.
The lineage also needs time. An investigator looking at an old alert may need to know which customer-risk rating, sanctions list, scenario version or mapping was in effect at the time. If systems overwrite configuration without version history, later assurance becomes difficult.
Control evidence: if the bank cannot reconstruct the decision, assurance is weak
Financial-crime decisions are often challenged months or years later. A customer may ask why a payment was delayed. A regulator may review a historical alert population. Internal audit may test a control after a system migration. Law enforcement may request information. The bank therefore needs evidence not just that a control existed, but what actually happened.
Good evidence answers practical questions. Which data was screened? Against which list version? Which rule or scenario generated the alert? What information did the analyst see? What additional evidence was obtained? Who made the decision? Was an override used? Which policy version applied? Was the transaction released, rejected, returned or blocked? Were subsequent customer or reporting actions triggered?
The first line should design systems and procedures so this evidence is created naturally rather than reconstructed manually. The second line should define evidence expectations for higher-risk controls and challenge gaps. Internal audit should test whether evidence is reliable and whether the audit trail can be independently reproduced.
This becomes especially important where artificial intelligence or machine learning is used. A model score is not self-explanatory evidence. Governance needs model version, inputs, thresholds, decision rules, human review and change history appropriate to the risk and legal context. The Three Lines Model still applies even when parts of the control become automated.
Monitoring, compliance testing and internal audit are not the same thing
Banks sometimes use the word “testing” for several different activities and then assume they are interchangeable. They are not.
First-line quality assurance may check whether analysts followed procedures and whether operational output meets required standards. First-line control testing may test whether a management control is functioning. Second-line monitoring or compliance testing provides a more independent management view on adherence to policy, regulatory obligations and control effectiveness. Internal audit provides independent third-line assurance over governance, risk management and controls, including the second line.
The methods can overlap. All three may sample cases, inspect system logic or review data. The difference lies in purpose, independence, reporting and accountability. Duplicating the same sample three times adds little value if nobody tests the upstream data that creates the risk. Mature assurance planning maps which risks and controls are covered by each activity and identifies gaps and unnecessary duplication.
Combined assurance can help, but it should not erase independence. If second-line testing is strong, internal audit may consider that work when planning or scoping, subject to its professional judgement and standards. It should not automatically rely on management assurance without assessing its quality, independence and relevance.
Governance forums should make decisions, not merely receive slides
Financial-crime governance often contains many committees: business risk committees, financial-crime committees, sanctions forums, transaction-monitoring governance, model committees, operational-risk forums, issue committees and board committees. More forums do not automatically mean stronger governance.
Every forum should have a defined purpose, membership, authority, escalation route and decision record. The agenda should distinguish information items from decisions. Minutes should record material challenge, not simply “noted.” Actions should have owners and dates. Risk acceptance should be explicit and permitted only by the authority defined in policy.
An effective financial-crime committee might review material risk-assessment changes, significant control weaknesses, high-risk customer or product trends, regulatory developments, suspicious-activity reporting themes, sanctions exposures, backlog risk, material data defects and remediation. It should be possible to trace an issue from the operational team through second-line challenge to senior governance and, where appropriate, the board.
Weak governance shows predictable symptoms: the same overdue issue appears for months with changing dates; metrics are green because thresholds are adjusted; difficult decisions are deferred to another committee; papers describe activity but not residual risk; and meeting minutes cannot show who accepted the risk. The Three Lines Model is valuable only when decision rights are real.
Risk appetite connects board intent to first-line behaviour
A board may approve a financial-crime risk appetite that states the institution has no appetite for knowingly facilitating prohibited activity and limited appetite for relationships or products that cannot be controlled effectively. That statement is only useful if it is translated into measurable and operational thresholds.
For example, the bank may establish limits or escalation triggers for overdue high-risk reviews, unresolved sanctions alerts, transaction-monitoring backlog age, critical data-quality defects, unassessed high-risk products, control failures or remediation delays. These metrics do not eliminate judgement, but they make deterioration visible.
The first line should manage within those limits and escalate breaches. The second line should independently challenge whether metrics truly reflect risk and whether management responses are adequate. The board or delegated committee should understand material breaches and persistent exceptions. Internal audit can assess whether the risk-appetite framework is connected to real decisions or exists only as governance documentation.
A particularly dangerous practice is to redefine the metric when performance deteriorates. Changing a threshold may be justified if the original measure was poorly designed, but the governance record should explain why. Otherwise, the bank can turn red risk into green reporting without reducing exposure.
Issue management: finding the problem is only the beginning
Financial-crime programmes generate findings from operations, compliance monitoring, quality assurance, internal audit, regulators, external reviews, incidents and technology controls. A mature bank does not treat these as separate universes. It uses a common or well-reconciled issue-management framework that preserves source, severity, ownership, due date, dependencies, evidence and closure authority.
First-line management should normally own remediation because it controls the process, system and resources required to fix the problem. Second-line compliance should challenge the proposed scope, assess residual risk and monitor material financial-crime issues. Internal audit should independently determine how it treats closure validation for audit findings and may assess broader remediation governance.
Root cause matters. If investigators missed suspicious activity because a field was not visible in the case tool, retraining analysts alone is unlikely to solve the problem. The root cause may sit in architecture, data mapping, requirements or change governance. Similarly, repeated KYC quality failures may reflect unclear policy, poorly designed workflow or unrealistic capacity rather than individual negligence.
Issue closure should prove that the control changed and that the change works. A project plan marked “100% complete” is not evidence of effectiveness. Closure evidence may include deployed code, reconciliations, test results, production monitoring, updated procedures, staff training and post-implementation quality results. Material issues may need a period of sustained performance before closure.
Outsourcing and third parties: activity can move, accountability cannot disappear
Banks frequently use external providers for screening technology, KYC utilities, case platforms, managed operations, cloud infrastructure, data, adverse media or specialist investigations. Outsourcing can improve capability, but it does not remove the bank’s responsibility to understand and govern the outsourced activity.
The first line should manage the service, performance, data, integration, incidents, change and exit arrangements. The second line should set relevant financial-crime expectations and challenge whether the service remains within risk appetite. Internal audit should be able to assess outsourced or co-sourced activities within its mandate. Basel’s internal-audit expectations explicitly recognise the need for authority to assess outsourced functions.
A service-level agreement is not sufficient if it measures only uptime. A screening vendor could meet 99.99 per cent availability while receiving incomplete customer data. A managed KYC provider could meet turnaround targets while producing weak ownership analysis. Vendor governance should include control outcomes, data quality, change management, security, regulatory access, evidence retention and business continuity.
Where the provider operates across jurisdictions, the bank must also understand data-location, privacy, secrecy and regulatory-access constraints. Those are not reasons to abandon group standards; they are requirements to design a lawful operating model.
Group versus local accountability
Global banks need consistency, but financial-crime obligations are implemented locally. A group function may own the global AML framework, central screening platform or enterprise monitoring technology while a local legal entity remains accountable to its supervisor and FIU. This creates a matrix that can work well only when responsibilities are explicit.
The group should define minimum standards, common taxonomy, shared systems where appropriate, data requirements, governance and escalation. Local entities should identify additional legal requirements, ensure local implementation, own relationships with local authorities and escalate conflicts. Where host-country law prevents implementation of a group measure or information sharing, the issue should be formally assessed rather than silently accepted.
FATF Recommendation 18 is relevant because it addresses group-wide AML/CFT programmes, information sharing and foreign branches and subsidiaries. It does not mean every entity should ignore local law in favour of a head-office rule. The FATF framework explicitly recognises the need to deal with host-country restrictions and additional measures.
For business analysts, this means requirements need jurisdiction attributes. A field such as reportingDecision may have different roles, deadlines and confidentiality constraints by legal entity. A global workflow should be configurable without allowing uncontrolled local variation.
Independence in practice: reporting lines, access and incentives matter
Calling a function “independent” does not make it independent. Real independence is supported by mandate, reporting line, access, authority, budget, appointment and removal arrangements, performance objectives and the ability to communicate concerns without retaliation.
For a second-line compliance function, independence from revenue pressure is important. A compliance officer who is assessed primarily on how quickly high-risk customers are onboarded may face conflicting incentives. Equally, a compliance function disconnected from commercial reality may create controls that are impossible to operate, encouraging workarounds. The answer is not isolation but clear authority and balanced incentives.
For internal audit, independence must be stronger because audit needs to assure the activities of management, including compliance. The head of internal audit should have sufficient access to the board or audit committee, and audit scope should not be constrained by the managers being audited. Auditors should also avoid auditing areas for which they recently had management responsibility without appropriate safeguards and cooling-off arrangements.
Access to data is part of independence. If audit can inspect only reports prepared by the control owner, it cannot fully test the control. Modern audit often requires access to raw or sufficiently granular data, configuration, logs, change records and case evidence.
Where the model breaks: the most common failure patterns
The first failure is compliance as the owner of everything. The business treats policy as somebody else’s problem, operations escalates every ambiguity, technology sees AML requirements as external requests, and compliance becomes a bottleneck. The institution may appear conservative but becomes fragile because control knowledge is concentrated in a function that does not own the underlying processes.
The second failure is first-line self-certification without challenge. Management reports that controls are effective based on completion statistics, while second-line monitoring is too weak or too close to the process to test the claim. The board receives confidence without evidence.
The third is audit as a design team. Internal audit identifies a weakness, prescribes detailed implementation, participates in operational decisions and later audits the same solution. Audit can provide advice, but management must own design choices and auditors must protect objectivity.
The fourth is committee diffusion. An issue passes through multiple forums but no person has authority or accountability to decide. Every committee is “informed”; nobody owns the risk.
The fifth is RACI without reality. A document says the product owner is accountable, but the product owner has no access to the monitoring data, no budget to fix the platform and no authority over the operations team. Governance must align accountability with capability.
The sixth is data outside the control model. Compliance owns the screening standard, operations owns alerts, technology owns the engine, but nobody owns the upstream feed. A missing interface therefore becomes everybody’s dependency and nobody’s control.
The seventh is local-group conflict. Group policy requires one approach, local law requires another, and teams implement informal exceptions without documented legal analysis or governance.
The eighth is assurance duplication. First-line QA, second-line testing and audit repeatedly sample the same completed cases while systemic data and model risks remain untested. The bank creates audit fatigue without better coverage.
The ninth is closure by document. A procedure is updated and an issue is closed before the system change is deployed or effectiveness is demonstrated.
The tenth is green dashboards built on weak definitions. Metrics look healthy because denominator logic excludes cases, ageing restarts when work is transferred, or risk is aggregated until severe pockets disappear.
What good three-lines governance looks like
Good governance is surprisingly observable. Ask a first-line product owner what financial-crime controls the product depends on. They can explain them. Ask who owns a critical transaction-monitoring data feed. There is a named owner. Ask second-line compliance why a standard exists. It can distinguish law, regulatory expectation and internal risk appetite. Ask internal audit how it chose the area for review. It can show a risk-based rationale independent of management preference.
Ask for the control inventory. It links risks, obligations, controls, systems, data, owners, evidence and testing. Ask for a material issue. The record shows detection, impact assessment, interim control, accountable owner, second-line challenge, governance decision, remediation, testing and closure evidence. Ask for a historical sanctions alert. The bank can reconstruct the data and decision.
Good governance also shows healthy disagreement. First and second line do not have to agree immediately. The important point is that challenge is evidence-based, decision rights are clear and unresolved material risk is escalated rather than buried. Internal audit can disagree with both and report its conclusion independently.
The objective is not bureaucracy. It is faster, safer decision-making because people know what they own.
Business analyst lens: turn governance language into requirements
A BA working on financial-crime change should treat roles and decision rights as functional requirements. “Compliance will review” is too vague. The requirement should define the trigger, role, input data, decision options, evidence, SLA, escalation and system status produced by that review.
Suppose a sanctions alert is created on an outbound payment. The BA should ask: Which system owns the payment hold? Which role can request additional customer information? Can operations release an obvious false positive? Which categories require specialist sanctions escalation? Who can approve release of a potential ownership-and-control concern? How is a legal licence recorded? What happens if the decision SLA is exceeded? Which status is sent back to the payment hub? What customer message is allowed? What evidence is retained? Which events feed management information?
For transaction monitoring, ask who owns scenario requirements, who approves changes, who validates source-data coverage, who operates alerts, who performs QA, who challenges tuning, who accepts temporary gaps and who can close a material issue. For KYC, ask who owns the customer-risk methodology, who can override a risk rating, which overrides require second-line approval and how periodic-review dates are recalculated.
These are governance questions expressed as system behaviour. If they are not captured, developers will make implicit decisions in workflow configuration, and implicit governance is difficult to defend.
Architecture lens: design for accountability and reconstructability
An architect should make it possible for the operating model to work. That means identity and access aligned to roles, segregation where necessary, immutable or well-controlled audit trails, versioned policies or decision rules where relevant, workflow states, maker-checker controls, escalation queues, evidence storage and reporting.
A good architecture does not hard-code organisational names if the bank operates globally. It models roles and entitlements so a jurisdiction can assign the appropriate authorised role. It preserves legal-entity context, customer context and transaction context. It can distinguish operational decisioning from compliance escalation and audit access.
Data lineage should identify source, transformation and destination for critical elements. Reconciliation should confirm that expected records reach the control platform. Changes to mappings, thresholds, list providers, scenarios and models should be traceable. Major control systems should provide enough evidence for independent testing without requiring production administrators to manually construct the audit trail.
Resilience is also a governance matter. If screening is unavailable, the architecture needs a controlled contingency: queue, stop, fallback or another approved mechanism depending on the payment type and policy. The first line owns operation of the contingency; second line should have challenged its appropriateness; internal audit may later assess it.
Testing lens: prove the control and the ownership model
Testing should cover more than the happy path. A functional test can prove that an alert appears when a known test name is entered, but financial-crime control testing also needs to prove data completeness, permissions, exception behaviour, status transitions, evidence, escalation and auditability.
For a screening workflow, tests might include a straightforward false positive, a potential true match, an alias, missing date of birth, an ownership-and-control escalation, a list update, a system outage, a duplicate alert, a repaired payment, an unauthorised release attempt and a historical evidence retrieval. Tests should confirm that only the correct role can take each action.
For transaction monitoring, tests can trace known transactions from source through transformation and scenario logic into alerts, then through case disposition and downstream reporting. Negative testing is equally important: transactions outside the scenario should not create unexplained alerts, and unauthorised users should not be able to suppress or alter outcomes.
UAT should involve operational users and, where appropriate, compliance subject-matter experts without converting second-line participation into first-line ownership. The test sign-off should say what each signatory is confirming. A compliance SME may confirm that policy requirements are represented; the product owner may remain accountable for the implementation.
Metrics for each line should answer different questions
First-line metrics should help management operate the process: volumes, ageing, exceptions, data-quality failures, processing times, alert backlogs, quality results, system incidents and remediation progress. They should be sufficiently granular to reveal where risk accumulates.
Second-line metrics should support challenge: high-risk customer exposure, policy exceptions, risk-appetite breaches, thematic findings, significant control deficiencies, suspicious-activity trends, sanctions escalations, persistent data issues and first-line remediation performance. The second line should be able to explain why a metric matters to risk rather than simply repeat operations reporting.
Internal audit metrics are different again. Audit coverage, overdue findings and issue themes can matter, but the core output is independent assurance and insight. Audit should not be judged by how many findings it produces. A low finding count could mean strong controls or shallow coverage; a high count could reflect effective challenge or serious weakness.
Board reporting should integrate these perspectives into an understandable risk story. The board does not need every operational statistic. It needs enough depth to see material exposure, trajectory, management action and independent challenge.
Mini case study: the missing payment field
Consider a fictional international bank, Northbridge Bank. It processes cross-border corporate payments through several channels. The bank has a central sanctions-screening engine and a group standard requiring specified payer, beneficiary and relevant connected-party data to be screened before release where applicable.
A payments modernisation programme migrates one corporate channel to a new ISO 20022 flow. Functional testing confirms that debtor and creditor names reach the screening engine and that known test names generate alerts. The release goes live.
Three months later, an analyst notices that alerts from the new channel never contain ultimate-debtor information even when the original customer message includes it. The issue is not immediately treated as severe because the primary debtor and creditor are still screened.
First-line response
The payment product owner becomes accountable for assessing the end-to-end control defect. Technology traces the message and finds that the channel captures ultimate-debtor data, but an intermediate canonical model does not map it into the screening request. Operations and sanctions-screening platform owners identify the affected payment population. The first line preserves evidence, assesses whether a temporary manual control is feasible and prevents further uncontrolled expansion of the affected flow.
The important point is that the first line does not say, “The sanctions engine belongs to Compliance, so this is their issue.” The defect is in the payment implementation and data lineage. Management owns the fix.
Second-line challenge
Sanctions compliance reviews the applicable policy and risk. It asks whether ultimate-party screening is required for the affected transaction types and jurisdictions, whether other fields are missing, whether the defect affects only one channel, whether the population contains high-risk corridors, and whether historical lookback or regulatory notification should be considered under applicable law and policy.
The second line challenges the first-line impact assessment because the original analysis sampled only completed payments and did not include rejected or repaired messages. It requires a broader population analysis and asks for evidence that no other migration mappings have the same weakness.
Compliance does not write the mapping code. It sets the risk expectation, challenges scope and escalates the issue because the control operated with incomplete data for three months.
Governance decision
The issue exceeds the bank’s defined tolerance for critical sanctions data defects, so it is escalated to a senior financial-crime risk committee. Management presents affected volumes, jurisdictions, interim controls, remediation plan and lookback proposal. Compliance presents its independent risk view. The committee approves urgent remediation and requires weekly reporting until the feed is fixed and historical exposure is assessed.
The board risk committee is informed because the defect meets the institution’s materiality threshold. It does not decide the XML mapping. It oversees the exposure, management response and whether the broader programme has a governance weakness.
Remediation and evidence
Technology adds the missing mapping, regression-tests related fields and deploys the change. The first line reconciles source messages to screening requests and proves that ultimate-debtor values are present. It adds a production data-quality control so future loss of the field creates an exception. The payment-change checklist is updated to require financial-crime critical-data validation.
The historical population is analysed according to the agreed lookback approach. Any resulting alerts or cases follow normal investigation and escalation processes. The second line reviews remediation evidence and challenges whether the new reconciliation covers all relevant message variants.
Third-line assurance
Internal audit had already planned a review of the payments transformation programme because of its scale. It adjusts scope to consider the incident while preserving independence. Audit assesses change governance, requirements traceability, data-lineage controls, testing, issue escalation and the relationship between payment teams and financial-crime control owners. It may use the incident as evidence of a broader pattern, but it independently determines its conclusions.
Audit finds that the immediate defect was fixed, but also identifies that critical financial-crime data elements were not formally classified in the enterprise data catalogue. Similar migrations could therefore miss fields without triggering mandatory reconciliation. The audit finding addresses the systemic governance gap, not just the already-fixed mapping.
What the case teaches
The engine, analyst and compliance policy were not enough. The control depended on payment architecture. First-line ownership enabled a real fix. Second-line challenge expanded the impact assessment. Governance gave visibility to material residual risk. Internal audit looked beyond the incident to the system of control. That is the Three Lines Model working as an accountability architecture rather than an organisation chart.
Another practical scenario: backlog pressure
Assume a bank has a transaction-monitoring alert backlog caused by rapid growth in instant-payment volumes. Operations proposes temporarily raising some thresholds to reduce alerts. The first line owns capacity and operational performance, but it should not unilaterally change detection logic merely to meet SLA.
A disciplined process would require the scenario owner to analyse which alerts are driving volume, whether they are productive, which customer segments are affected and what risk would be lost by threshold changes. Second-line AML compliance should challenge the analysis and determine whether the change remains consistent with risk assessment and policy. Model or analytics governance may also be required. If the backlog itself creates material risk, it should be escalated rather than disguised through tuning.
Internal audit is not the change-approval body. It may later assess whether scenario governance and backlog management were effective. The board should see a material sustained backlog if it represents a risk-appetite breach, not merely a productivity problem.
This scenario demonstrates a recurring principle: operational pressure does not change accountability. The first line still owns the problem; the second line still challenges risk; audit still assures independently.
Human judgement and escalation culture
No governance model works if people are afraid to escalate. Financial-crime controls involve ambiguity. An investigator may suspect that an apparently ordinary trading company is a front. A relationship manager may notice unexplained customer behaviour. An operations analyst may find that a screening field appears blank. A developer may discover that a reconciliation is not covering a new interface.
The institution needs a culture in which raising such concerns is expected. First-line managers should not punish teams for surfacing defects. Second-line compliance should not equate every question with a policy breach. Internal audit should distinguish genuine risk from hindsight criticism. Senior management should treat transparent escalation as evidence of a functioning control environment, while still holding owners accountable for timely action.
Conversely, “speak-up culture” cannot become a substitute for formal controls. Material concerns need documented assessment, ownership and decisioning. Informal messages and meetings are useful for speed, but the bank must preserve the evidence needed to demonstrate what it knew and what it did.
The model in smaller institutions
Not every bank has thousands of staff and separate teams for every line. Smaller institutions may combine roles, outsource activities or use shared specialists. The principle of proportionality is therefore important. FATF itself expects internal-control arrangements to reflect risk and size, and Basel guidance recognises that implementation can vary with size, complexity and legal framework.
A smaller bank can still protect role integrity. The same person might perform more than one management activity, but important decisions can have independent review. Internal audit may be outsourced, provided it has an appropriate mandate and independence. The board may take a more direct role in oversight. Compliance may be small but should have sufficient authority and access.
The test is not headcount. It is whether the institution can identify who owns the risk, who provides credible specialist challenge, who provides independent assurance, and whether conflicts are managed.
The model in highly automated digital banking
Automation changes the location of work, not the need for accountability. A digital bank may have straight-through onboarding, automated document verification, sanctions screening, behavioural monitoring and machine-assisted investigations. In that environment, first-line ownership may shift toward product, engineering, data and model teams.
The second line needs enough technical understanding to challenge automated controls. It should be able to ask how identity confidence is established, how sanctions matching is tuned, how monitoring coverage is validated, how models are changed, how bias or unintended exclusion is assessed where relevant, and how human escalation works.
Internal audit likewise needs data and technology capability. Reviewing a written procedure is insufficient when the real control is code, configuration and data lineage. Audit may need reproducible analytics, model review skills and access to change histories.
Automation can improve consistency but also scale defects. A manual error may affect one case; a faulty mapping can affect millions of transactions. Three-lines governance therefore becomes more important as controls become more technical.
Questions a professional should be able to answer
After studying this chapter, you should be able to explain why the first line owns financial-crime risk even when specialist compliance teams exist; why the second line should be independent enough to challenge but still collaborate with management; why internal audit must remain separate from compliance; and why the board oversees rather than operates routine controls.
You should also be able to look at a real process and identify ambiguity. If nobody can name the owner of a critical data feed, that is a governance gap. If compliance approves every ordinary case, first-line capability may be too weak. If internal audit designs the remediation it later audits, independence needs consideration. If a committee receives an issue but cannot accept risk or direct action, the escalation design may be ineffective.
Most importantly, you should be able to translate the governance model into practical requirements: ownership, authority, data, workflow, evidence, monitoring, escalation and assurance.
Outsourcing does not outsource the lines
Banks routinely place substantial financial-crime work with external providers: sanctions-screening utilities, KYC processing centres, transaction-monitoring operations, model development vendors and correspondent-agent arrangements. Outsourcing changes who performs the activity; it never changes where accountability sits. The first line retains ownership of the risk arising from the business, the second line retains policy and challenge responsibility, and internal audit retains independent assurance — each applied to vendor-performed work with the same rigour as internally performed work.
First-line vendor management therefore needs control substance rather than contract administration. Service definitions should specify data completeness, decision quality, turnaround standards and evidence formats in testable terms rather than generic diligence promises. Performance monitoring should measure control outcomes — screening completeness by population, verification accuracy by sampling, alert quality by conversion analysis — rather than activity volumes that busy vendors report reassuringly. Change control should govern vendor system, data and model changes with the same lineage discipline as internal change, since a vendor matching-engine upgrade can silently alter detection coverage across the bank's entire screened population overnight.
Second-line oversight of vendors requires access rights negotiated before dependence deepens: audit clauses permitting control testing, data access supporting independent validation, and exit provisions preserving evidence continuity where relationships end. Concentration risk deserves explicit treatment where one provider serves multiple critical controls, since vendor failure, acquisition or strategy change then becomes a single point of failure across supposedly independent defences. Fourth-party awareness extends the lens to subcontractors the vendor uses for data, analytics or operations, where the bank's assurance rarely reaches without deliberate design.
Internal audit's treatment of outsourced controls tests whether assurance followed the work. Auditing the vendor-management function while never testing vendor-performed control outcomes leaves the actual control unexamined. Effective programmes combine vendor assurance reports with independent testing of samples drawn from the bank's own populations, reconciling vendor-reported performance against bank-observed results and investigating divergence as a control finding rather than a reporting discrepancy.
Examination through a three-lines lens
Supervisory examinations of financial-crime control increasingly organise findings around accountability structure rather than isolated control defects, because defect patterns reveal which line failed. A population of similar alert-handling errors across teams indicates first-line procedure, training or capacity weakness rather than individual analyst failure. Repeated second-line approval of inadequate first-line work indicates challenge-function weakness where policies exist but challenge lacks authority, skill or independence. Audit reports that described controls as adequate shortly before supervisory findings exposed material weakness indicate assurance-scope or capability gaps that undermine reliance on the third line.
Banks that understand this prepare examinations by line rather than by topic. First-line preparation demonstrates that procedures reflect current typologies, that capacity matches workload with evidence, that data feeds are complete with reconciliation, and that decisions are documented with reasoning. Second-line preparation demonstrates policy currency, challenge records with rejected or returned work as evidence that challenge operates, thematic review findings with remediation tracking, and escalation records showing issues reached appropriate authority. Third-line preparation demonstrates audit planning driven by risk assessment rather than rotation habit, findings with genuine consequence including repeated-issue escalation, and follow-up verification that remediated controls actually operate rather than merely existing as updated documents.
Examination interviews test the model in person. Examiners ask first-line staff who owns a specific risk and what happens when controls fail, expecting operational answers rather than organisation-chart recitation. They ask second-line staff when they last disagreed with the business and what changed as a result, expecting examples rather than process descriptions. They ask audit what it chose not to cover and why, expecting risk-based reasoning rather than resource excuses. Preparation that rehearses honest answers to these questions strengthens the control environment genuinely; preparation that scripts evasive answers trains the behaviours examinations exist to detect.
Finding responses should also follow line discipline. Remediation that retrains analysts for a data-feed defect misattributes a technology failure to human performance and guarantees recurrence. Remediation that adds second-line review steps for a first-line capacity problem layers cost without addressing throughput. Each finding deserves root-cause analysis that identifies the failing line honestly, remediation directed at that line's mechanics, and validation evidence proving the specific failure mode no longer occurs under conditions resembling the original failure.
When the lines blur: a composite failure study
Consider a composite drawn from recurrent examination patterns rather than any single institution. A mid-sized bank's transaction-monitoring alerts grew steadily as volumes increased, while first-line investigator headcount stayed flat under cost discipline. Alert ageing lengthened quietly because performance reporting measured cases closed per analyst rather than risk-weighted queue health, and nobody owned the queue-ordering logic that processed alerts by arrival date. This was a first-line capacity and prioritisation failure developing over eighteen months.
The second line observed rising volumes in management information but accepted business assurances that temporary backlogs would clear after a planned system upgrade. Challenge was documented as questions asked rather than requirements imposed: no interim thresholds, no mandatory overtime or surge resourcing, no restriction on higher-risk onboarding while the queue deteriorated. The upgrade itself slipped twice without triggering reassessment of the interim position. This was a second-line challenge failure — oversight without consequence.
Internal audit's plan covered transaction monitoring on a three-year rotation and had rated it adequate two years earlier based substantially on procedure review and walkthroughs rather than outcome testing. The audit plan did not accelerate when queue metrics deteriorated because audit risk assessment consumed annual management information summaries rather than control-performance indicators. When supervisors examined, they found high-risk alerts unreviewed for months including patterns later linked to reported suspicious activity that timely review would have escalated far earlier.
Each line's failure was individually understandable and collectively catastrophic. First-line managers faced genuine cost pressure. Second-line challengers faced genuine prioritisation choices across many risks. Auditors faced genuine resource constraints. The lesson is structural rather than personal: management must have the resources and accountability to repair controls, the second line needs effective challenge and escalation rights under its mandate, and audit needs unrestricted access and direct reporting to the governing body. Audit can recommend remediation and assess whether management's action addresses a finding; management owns the action and the governing body resolves material inaction or disputed risk acceptance. Independence must be supported by access, reporting rights and follow-through without transferring management responsibility to audit.
Metrics that prove the model works
Three-lines reporting too often measures activity that each line generates rather than assurance each line provides. Case volumes, training completions, policy attestations and audit counts describe busyness. Model-effectiveness metrics instead test whether each line performs its distinct function, and the most revealing indicators are uncomfortable precisely because they measure friction the model is supposed to create.
First-line effectiveness shows in risk ownership evidence: queue health by risk priority rather than age, data-completeness reconciliation with breaks investigated, decision documentation quality sampled for reasoning rather than template completion, and self-identified issues volunteered before assurance discovery. A first line that never reports its own control gaps is either perfect or blind, and governance should assume the latter until outcome testing proves otherwise. Voluntary issue identification rates, tracked without punishment, indicate whether ownership culture operates or whether the first line treats assurance as adversary.
Second-line effectiveness shows in challenge friction: procedures returned for rework with recorded reasons, business proposals modified or rejected with documented challenge influence, thematic reviews producing findings that surprise management rather than confirming known positions, and escalation records demonstrating issues travelled upward against resistance. A second line whose records show universal agreement with the business is either perfectly aligned or captured, and the distinction is testable through sampled challenge quality. Challenge-to-acceptance ratios by risk area, interpreted with judgement rather than targets, reveal where challenge operates genuinely.
Third-line effectiveness shows in assurance consequence: findings that improve management's response where evidence warrants it, repeat-finding escalation that reaches the board, audit-plan changes responding to emerging control-performance signals, and follow-up testing that challenges inadequate remediation evidence. Assess the quality, coverage, objectivity and impact of audit work rather than whether findings please or displease management. Stakeholder feedback can identify problems with clarity or usefulness, but satisfaction or discomfort alone does not establish audit independence or effectiveness.
Boards should receive these effectiveness indicators alongside conventional volumes, with trend analysis distinguishing genuine improvement from metric management. When first-line self-identification rises while assurance findings fall, the model is maturing. When all lines report green while incidents accumulate, the metrics are measuring comfort rather than control, and the board's most important question is which line will deliver the first unwelcome truth.
Handoffs are where the model most often breaks
Every Three Lines failure study returns to the same terrain: the boundaries between lines. Ownership transfers lose context when first-line case files move to second-line review without the reasoning that shaped them. Challenge loses force when second-line findings arrive as recommendations the first line may defer without consequence or deadline. Assurance loses value when audit reports circulate without tracked remediation ownership. Each handoff needs defined format, quality standard, acceptance criteria and timeout — the same rigour the bank applies to payment messages, because governance information degrades in transit exactly as payment data does.
The most dangerous handoff failure is the silent one: each line assuming another line holds a risk that no line actually holds. Data-feed completeness owned by technology in principle but monitored by nobody in practice. Queue prioritisation assumed to be operations' judgement while operations assumes compliance set the rules. Model-risk coverage assumed by all three lines to sit with whichever team last touched the model. Periodic handoff mapping — naming every critical control, its owning line, its receiving line and the evidence that the transfer occurred — exposes these gaps before incidents do. A RACI matrix that nobody tests is decoration; handoff testing through sampled end-to-end traces proves the model operates as drawn.
Final perspective
The Three Lines Model is not valuable because the number three is special. It is valuable because banks need different perspectives on the same risk.
Management needs to act. Compliance and other second-line functions need to provide specialist standards, monitoring and challenge. Internal audit needs enough independence to tell the governing body whether the overall system is working. The governing body needs enough information and authority to ensure material risk is understood and managed.
Financial crime exposes every weakness in accountability because the control chain crosses customers, products, payments, countries, data, technology and people. Criminal networks do not care where one department’s responsibility ends. A bank therefore cannot allow its internal boundaries to create blind spots.
The practical standard is simple to state and difficult to achieve: every material financial-crime risk should have a clear management owner, credible specialist challenge, independent assurance appropriate to the risk, and an escalation path that reaches the people with authority to act. When that is true, the Three Lines Model becomes more than governance terminology. It becomes part of how the bank protects customers, meets legal obligations and preserves the integrity of the financial system.
References and further reading
- Institute of Internal Auditors — Statements of Position, including the refreshed Three Lines Model statement published 8 July 2026: https://www.theiia.org/en/resources/statements-of-position
- Institute of Internal Auditors — historical 2020 Three Lines Model position paper, now superseded by the 2026 Statement of Position: https://www.theiia.org/en/content/position-papers/2020/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense
- FATF — The FATF Recommendations, as amended June 2026; see Recommendation 18 and its Interpretive Note on internal controls, compliance management and independent audit: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- FATF — explanatory materials on Recommendation 18 group-wide programmes: https://www.fatf-gafi.org/en/publications/Fatfgeneral/Explanatory-materials-r18-r23.html
- Basel Committee on Banking Supervision — Basel Consolidated Guidelines, Internal audit and control: https://www.bis.org/committees/bcbs/basel-consolidated-guidelines/module/iac
- Basel Committee on Banking Supervision — IAC10 Internal audit and control frameworks, published 1 January 2026: https://www.bis.org/committees/bcbs/basel-consolidated-guidelines/module/iac/10
- Basel Committee on Banking Supervision — IAC20 Compliance functions, published 1 January 2026: https://www.bis.org/committees/bcbs/basel-consolidated-guidelines/module/iac/20
- Basel Committee on Banking Supervision — Compliance and the compliance function in banks: https://www.bis.org/publications/200504-guidelines-compliance-and-compliance-function-banks
- European Banking Authority — Guidelines on internal governance under the Capital Requirements Directive: https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/internal-governance/guidelines-internal-governance-under-crd