Third Line of Defense
The third line of defense is the part of an organization that independently checks whether its risk controls are actually working. In most financial institutions this role is carried out by the internal audit function, which reports separately from the managers who run day-to-day operations and design controls. Its purpose is to give senior leadership and the board objective assurance about how well risk is being managed.
Within the 'three lines' governance framework, the third line of defense refers to roles that provide independent and objective assurance over the design and effectiveness of governance, risk management, and internal controls, including those relating to financial crime and AML compliance. It is typically discharged by the internal audit function, whose defining characteristic is independence from management, distinguishing it from first line operational ownership of risk and second line risk and compliance oversight. Under the IIA's Three Lines Model (updated in 2020, superseding the earlier 'Three Lines of Defense' terminology), this line supports accountability to the governing body rather than to operational management. The concept is a governance and organizational-design model rather than a specific legal requirement; the precise structure, mandate, and reporting arrangements of the third line may vary by institution and by jurisdiction, and should be confirmed against applicable regulatory expectations for the relevant obliged entity.
Why it matters
The third line of defense matters because the effectiveness of an AML program cannot be judged solely by the people who design and operate its controls. First line operational teams own and manage risk day to day, and second line risk and compliance functions provide oversight, but both are ultimately part of management. Without an independent check, weaknesses in control design or gaps between documented policy and actual practice may go unnoticed until they are exposed by a regulator, an external event, or a failure. The third line's defining characteristic, independence from management, is what allows it to give senior leadership and the governing body an objective view of whether controls are genuinely working rather than simply presumed to work.
For financial crime and AML purposes, this independent assurance supports accountability to the board rather than to operational management, helping ensure that assurance over governance, risk management, and internal controls is not compromised by the same reporting lines responsible for the controls being assessed. This structure is a governance and organizational-design model rather than a specific legal requirement, and it does not guarantee that financial crime risk is eliminated; it is a mechanism to detect and surface control weaknesses so they can be addressed.
Because the concept is a model rather than a rule, the precise mandate, structure, and reporting arrangements of the third line may vary by institution and by jurisdiction. Compliance professionals should confirm the specific expectations that apply to their obliged entity against the relevant regulatory framework rather than assuming a single, uniform standard applies everywhere.
Who it's relevant to
Inside Third Line of Defense
Common questions
Answers to the questions practitioners most commonly ask about Third Line of Defense.