Skip to main content

Three Lines of Defense

What is the 3 lines of defense model?

3 lines of defense model distinguishes the three interrelated functions of an effective enterprise risk management program. These are:

1) Own and manage
2) Oversee
3) Independent Assurance


What is the role of first line in the 3 lines of defense model?

The first line is responsible for managing risks and maintaining effective internal controls. It is a bottom up approach where risk assessments are performed and include - RCSA - Risk Control Self Assessment, KRI - Key Risk Indicators, Risk Profile and Escalation process.



What is the role of second line in the 3 lines of defense model?

The second line is responsible for design and implementation of risk program. It provides the framework used by the 1st line to assess and manage risks.  The goal is to connect dots by taking a portfolio view of risks across the enterprise. Primarily provides top down view relative to strategy and risk appetite. 


What is the role of third line in the 3 lines of defense model?

The third line is responsible for independent internal audit and assurance. It provides periodic evaluation of the effectiveness of risk management program. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes. The scope of
internal audit work can encompass all aspects of an organization’s operations and activities.  Internal auditors do not design or implement controls as part of their normal responsibilities and are not responsible for the organization’s operations.


Interested in learning more?
visit us at www.ermgovernance.com or contact us at info@ermgovernance.com to get your free ERM 3-lines-of-defense Program Evaluation / Assessment.




Comments

Popular posts from this blog

Essential elements of ERM

Essential elements of ERM Create your own and tailored #ERM #framework with ease! We have worked hard to incorporate changes from #COSO and #ISO #31000 so that you can benefit without having to invest a lot of time and resources.  Email us at  info@ermgovernance.com  for more details.

Five Step Plan for an Enterprise Risk Management (ERM) Program

Enterprise Risk Management (ERM): is a process of planning, organizing, leading, and controlling the activities of an organization in order to minimize the effects of a risk to an organization.  It expands beyond a daily run of the mill operational management! A true ERM program will have its scope expand to strategic, financial, reputational, human resource and business continuity as well as operational and legal risks. Most organizations, as they mature embark on a journey of establishing a robust Enterprise Risk Management (ERM) Program! The 5-step plan outlined here can be used for rolling out any organization-wide change. Step 1: Organize effort for a successful change Identify your team! Make this group a core part of the ERM work Assess current organizational change saturation and establish a process to address any road blocks Engage the Executive Leadership Team (ELT) for support Have a clear plan of action Ensure that ERM beco...

How to benefit from a Fishbone or Ishikawa Diagram for Root Cause Analysis

    What is root cause analysis? Root cause analysis is a structured process that helps healthcare, manufacturing and service sector managers and leaders in identifying contributing factors or causes of an accident, error, problem, event or occurrence. An accident, error, problem, event or occurrence are usually a result of a system rather than an individual mistakes. Understanding the system itself and contributing factors or causes of a system failure can help in preventing recurrences. Actions that are taken to address system failure helps in sustaining the improvements or corrective actions.   What is a fishbone or ishikawa diagram? Each and every outcome or effect is an end result of actions taken/omitted or in general causes/ A cause and effect diagram representing this relationship between cause and effect is called a called a fishbone or ishikawa diagram. A fishbone diagram is a visual way to represent cause and effect. It is a more structu...