Second Line of Defense
The second line of defense refers to the risk management and compliance functions within a financial institution that oversee and support the day-to-day business operations that make up the first line. Rather than executing transactions directly, these functions set standards, monitor risks, and check that the business is managing risk appropriately. It is one part of the widely used Three Lines of Defense governance model in financial services.
Within the Three Lines of Defense governance model commonly applied in financial services, the second line of defense (2LoD) comprises the specialized risk management and compliance functions that oversee, support, and challenge the risk-taking activities carried out by the first line (business and operational units). These functions typically design and maintain risk and compliance frameworks, policies, and controls; monitor adherence to them; and provide independent oversight of how risks are identified and managed, though they generally do not own or execute the underlying business transactions themselves. As a conceptual governance framework rather than a single binding legal standard, the precise composition, mandate, and independence expectations of the second line vary by institution and by jurisdiction and should be confirmed against applicable regulatory expectations and internal governance arrangements.
Why it matters
The second line of defense addresses a structural problem in how financial institutions manage risk: the units that generate revenue and execute transactions cannot be relied upon to be the sole judges of whether they are managing risk appropriately. By separating risk ownership and execution (the first line) from independent oversight, standard-setting, and challenge (the second line), the Three Lines of Defense model creates a check on the day-to-day business. In an AML and financial crime context, this means the compliance function can design and maintain the frameworks, policies, and monitoring that the business must operate within, rather than leaving those judgments entirely to commercially motivated units.
The distinction matters because supervisors and internal governance arrangements generally expect risk and compliance functions to have sufficient standing, resources, and independence to challenge the business effectively. Where the second line is under-resourced, subordinated to revenue-generating units, or unable to escalate concerns, the oversight it is meant to provide can be undermined in practice even if it exists on paper. The Three Lines model is a conceptual governance framework rather than a single binding legal standard, so the precise mandate, composition, and independence expectations of the second line vary by institution and by jurisdiction and should be confirmed against applicable regulatory expectations.
Who it's relevant to
Inside 2LoD
Common questions
Answers to the questions practitioners most commonly ask about 2LoD.