Skip to main content
Category: Compliance Program Governance

Third Line of Defense

Also known as: Third Line, Internal Audit Function (in the Three Lines context)
Simply put

The third line of defense is the part of an organization that independently checks whether its risk controls are actually working. In most financial institutions this role is carried out by the internal audit function, which reports separately from the managers who run day-to-day operations and design controls. Its purpose is to give senior leadership and the board objective assurance about how well risk is being managed.

Formal definition

Within the 'three lines' governance framework, the third line of defense refers to roles that provide independent and objective assurance over the design and effectiveness of governance, risk management, and internal controls, including those relating to financial crime and AML compliance. It is typically discharged by the internal audit function, whose defining characteristic is independence from management, distinguishing it from first line operational ownership of risk and second line risk and compliance oversight. Under the IIA's Three Lines Model (updated in 2020, superseding the earlier 'Three Lines of Defense' terminology), this line supports accountability to the governing body rather than to operational management. The concept is a governance and organizational-design model rather than a specific legal requirement; the precise structure, mandate, and reporting arrangements of the third line may vary by institution and by jurisdiction, and should be confirmed against applicable regulatory expectations for the relevant obliged entity.

Why it matters

The third line of defense matters because the effectiveness of an AML program cannot be judged solely by the people who design and operate its controls. First line operational teams own and manage risk day to day, and second line risk and compliance functions provide oversight, but both are ultimately part of management. Without an independent check, weaknesses in control design or gaps between documented policy and actual practice may go unnoticed until they are exposed by a regulator, an external event, or a failure. The third line's defining characteristic, independence from management, is what allows it to give senior leadership and the governing body an objective view of whether controls are genuinely working rather than simply presumed to work.

For financial crime and AML purposes, this independent assurance supports accountability to the board rather than to operational management, helping ensure that assurance over governance, risk management, and internal controls is not compromised by the same reporting lines responsible for the controls being assessed. This structure is a governance and organizational-design model rather than a specific legal requirement, and it does not guarantee that financial crime risk is eliminated; it is a mechanism to detect and surface control weaknesses so they can be addressed.

Because the concept is a model rather than a rule, the precise mandate, structure, and reporting arrangements of the third line may vary by institution and by jurisdiction. Compliance professionals should confirm the specific expectations that apply to their obliged entity against the relevant regulatory framework rather than assuming a single, uniform standard applies everywhere.

Who it's relevant to

Internal auditors
Internal audit typically carries out the third line role, providing independent and objective assurance over the design and effectiveness of AML and financial crime controls. Their value depends on maintaining independence from the management functions whose controls they assess and on reporting to the governing body.
Boards and audit committees
The governing body relies on third line assurance to form an objective view of how well financial crime and other risks are being managed. Because the third line supports accountability to the board rather than to operational management, directors and audit committee members are its primary audience for independent findings.
Compliance and second line risk functions
Second line compliance and risk teams provide oversight of controls but are themselves within scope of third line review. Understanding the distinction between second line oversight and third line independent assurance helps these functions avoid conflating oversight with independent testing.
First line operational owners
Teams that own and manage financial crime risk in day-to-day operations are subject to third line assessment of whether their controls are designed and operating effectively. Clarity on the three lines helps them understand where operational ownership ends and independent assurance begins.
Senior management and program leadership
Executives responsible for the AML program use third line findings, alongside first and second line reporting, to identify control weaknesses and gaps between documented policy and actual practice. They should confirm that their institution's three lines structure aligns with the regulatory expectations applicable to their entity and jurisdiction.

Inside Third Line of Defense

Internal Audit Function
The third line of defense is typically embodied by an independent internal audit function that provides objective assurance to the board and senior management on the design and effectiveness of the AML/CFT control framework. It is distinct from the first line (business units and customer-facing staff who own and manage risk) and the second line (compliance and risk management functions that set policy and monitor).
Independence and Objectivity
A defining characteristic is organizational independence from the activities it reviews. Auditors generally should not have operational responsibility for the controls they assess, and reporting lines commonly run to the board or an audit committee rather than to line management, to preserve objectivity.
Assurance Over the Whole Framework
The third line evaluates whether first- and second-line controls are adequately designed and operating as intended, covering areas such as CDD/EDD processes, transaction monitoring, sanctions and PEP screening, suspicious activity/transaction reporting, governance, and training. Its role is assurance and testing, not day-to-day execution of controls.
Independent Testing Expectations
In many jurisdictions, obliged entities are expected to subject their AML programs to independent review or audit. For example, US BSA/FinCEN expectations for an AML program commonly reference independent testing as a program pillar, and other regimes such as the UK Money Laundering Regulations and standards informed by the FATF Recommendations contemplate independent audit of the AML/CFT framework. Exact requirements, frequency, and who may perform the testing vary by jurisdiction and entity type and should be confirmed against the applicable regulation.
Reporting and Escalation
Findings from the third line are typically documented and escalated to the board or audit committee, with tracking of remediation actions. This closes the assurance loop and informs governance decisions about the risk-based AML program.
Scope Boundaries
The three-lines model is a governance and operational framework rather than a single legally defined test, and its application depends on the size, complexity, and risk profile of the entity. Smaller obliged entities may implement the function differently or outsource independent testing, subject to the requirements of their jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Third Line of Defense.

Does the third line of defense audit or approve individual transactions and alerts?
No. The third line, internal audit, provides independent assurance over the design and effectiveness of the AML program as a whole; it does not perform first-line operational activities such as clearing alerts, approving transactions, or making customer risk decisions. Those are functions of the business (first line), while the compliance function's oversight and monitoring (second line) sits between them. Internal audit's role is to evaluate whether those controls are adequately designed and operating as intended, not to run or own them. Confusing assurance with operational execution undermines the independence that gives the third line its value.
Is having an internal audit function a guarantee that an AML program is effective and compliant?
No. Internal audit provides independent assurance, but assurance is not a guarantee of prevention or of full compliance. Audit typically works on a risk-based, sampled, and periodic basis, so it may not detect every control failure or every instance of financial crime. Its purpose is to help the organization detect, assess, and remediate weaknesses in the control environment and to give the board and senior management an informed view of residual risk. The existence of a third line should be understood as one element of an effective program, not as evidence that risk has been eliminated.
How is the independence of the third line typically maintained in practice?
Independence is generally supported by structural and functional separation: internal audit usually reports functionally to the board or its audit committee rather than to the management it reviews, and auditors are expected not to have operational responsibility for the controls they assess. Many frameworks emphasize that audit staff should not have designed, implemented, or operated the first- or second-line controls under review. Where the third line's scope, resourcing, or reporting line is compromised, its assurance value is correspondingly weakened. Specific governance expectations vary by jurisdiction and regulator and should be confirmed against applicable rules and supervisory guidance.
What does a third-line review of an AML program typically cover?
Scope is generally risk-based and may include governance and accountability arrangements, the enterprise-wide risk assessment methodology, customer due diligence and enhanced due diligence processes, transaction monitoring and sanctions and PEP screening systems, suspicious activity or suspicious transaction reporting processes, training, and the adequacy of second-line oversight. Reviews often assess both control design and operating effectiveness. Coverage in any given cycle is typically driven by an audit plan and is unlikely to examine every control every period, so scope boundaries and rationale should be documented.
How often should the third line assess the AML program?
Frequency is typically determined on a risk-based basis through an audit plan approved by the board or audit committee, with higher-risk areas often reviewed more frequently than lower-risk ones. There is no single universal interval, and specific expectations vary across regimes and supervisors. Some frameworks and regulators indicate expectations around periodic independent testing; exact requirements or recommended intervals should be confirmed against the applicable regulation and supervisory guidance for the relevant jurisdiction and type of obliged entity.
How should findings from the third line be tracked and escalated?
Findings are generally reported to senior management and the board or audit committee, often with severity ratings, agreed remediation actions, ownership, and target dates. Effective practice typically includes tracking issues through to closure and validating that remediation has been implemented and is working, rather than treating a management response as resolution in itself. Escalation pathways for significant or unremediated issues, and any onward reporting obligations, should be defined in governance documentation and aligned with applicable regulatory expectations.

Common misconceptions

The third line of defense prevents money laundering or guarantees the AML program will catch financial crime.
Independent audit is an assurance measure that helps detect weaknesses and manage risk; it does not eliminate financial crime risk or guarantee prevention. It assesses whether controls are designed and operating effectively, but no single line or control guarantees outcomes.
The three lines are interchangeable, so compliance monitoring by the second line satisfies the need for a third line.
The second line (compliance and risk management) sets policy and monitors on an ongoing basis, whereas the third line provides independent assurance over both the first and second lines. Because independence and objectivity are central, a function that owns or operates the controls generally cannot provide the same assurance as an independent audit.
A specific frequency or method of independent testing applies uniformly across all jurisdictions and entities.
Requirements for independent audit or testing, including frequency, who may perform it, and its scope, vary by regime and by the entity's size and risk profile. Exact obligations should be confirmed against the applicable regulation rather than assumed to be universal.

Best practices

Preserve the independence of the third line by ensuring auditors have no operational ownership of the AML controls they review and by reporting findings to the board or audit committee rather than to line management.
Scope audits to cover the full AML/CFT framework, including CDD/EDD, transaction monitoring, sanctions and PEP screening, suspicious activity reporting, governance, and training, rather than isolated components.
Adopt a risk-based approach to audit planning so that higher-risk areas, products, and customer segments receive proportionate depth and frequency of review, calibrated to the entity's size and complexity.
Document findings clearly, escalate them appropriately, and track remediation to closure so that the assurance loop informs governance decisions.
Confirm the applicable independent testing or audit obligations against the relevant regime (for example, US BSA/FinCEN expectations, the UK Money Laundering Regulations, or standards informed by the FATF Recommendations) rather than assuming a single global requirement.
Where the function is outsourced or performed by smaller teams, verify that the provider or team has sufficient independence, competence, and access to information to deliver objective assurance.