Three lines of defense
Also known as: Three Lines Model, 3LoD Framework
A governance framework used to distribute risk management responsibilities across an organization. The first line consists of operational managers who own and manage risks; the second line comprises compliance and risk functions that provide oversight and policies; the third line is internal audit, providing independent assurance.
In practice
An auditor evaluates this by verifying that business units (first line) are executing controls while a separate compliance team (second line) monitors those controls for effectiveness. This prevents conflicts of interest by ensuring the party performing the work is not the same party auditing it.