Skip to content

The Three Lines of Defence

  • 45 Minutes
  • For all staff
  • jurisdiction Global

The Three Lines of Defence model clarifies who owns risk, who oversees it and who provides independent assurance. This 45-minute global course explains how to interpret the model, identifies the roles of each line and the stakeholders involved, and covers the elements needed for the structure to function.

Most firms have the model on a slide and confusion in practice, usually where the first and second lines meet. Ownership gaps at that boundary are where risks sit unmanaged. Giving every function a shared understanding of the model turns an organisational chart into working accountability, and it makes internal audit findings considerably easier to act on.

objectives

What you’ll learn in
this course

  • Understand and interpret the Three Lines of Defence (3LoD) model
  • Identify the different roles and responsibilities of each line of defence and stakeholder in the 3LoD model
  • Appreciate the benefits of implementing the 3LoD model
  • Identify the key success factors that indicate the 3LoD model is being implemented effectively

Hear from our customers

A great LMS with a dedicated and knowledgeable team behind it. The LMS has a number of features that are gradually shared and which keeps on being developed.

Feefo Customer Rating  ★★★★★ 4.9/5

Ready to try this course?

Start your free trial of this course and get instant access today.

Want to explore more courses?

Browse all courses and search by topic to find what matters most to you.

Your questions, answered

How does conduct risk differ from compliance risk?

Conduct risk focuses on behaviour and outcomes, how actions affect customers and markets -  while compliance risk relates to failing to meet legal or regulatory requirements. Conduct risk is broader and more subjective, often tied to culture and ethics.

Who is responsible for managing conduct risk within a firm?

While senior leadership sets the tone, managing conduct risk is a shared responsibility across all levels, from front-line staff to compliance teams. Everyone plays a role in identifying and mitigating risky behaviour.

Can conduct risk exist in non-financial sectors?

Yes. Although the FCA regulates financial services, conduct risk principles apply across industries. Any business that interacts with customers or influences markets can face conduct-related challenges.

How can technology help reduce conduct risk?

Tools like automated monitoring systems, AI-driven analytics, and e-learning platforms can help detect risky patterns, reinforce ethical behaviour, and ensure consistent training across teams.

How often should proliferation financing risk assessments be updated?

Best practice suggests reviewing risk assessments annually or whenever there are significant changes in business operations, customer profiles, or geopolitical developments.

Why is risk scoring important for my business?

Identifying potential risks around your business is not enough. Tracking how your company manages them helps you implement policies to prevent them. The best way to get started is with a risk scoring matrix.

What is a risk scoring matrix?

A risk scoring matrix helps identify the level of risk for specific activities, such as personal data. By measuring the likelihood of something happening against how serious the consequences would be, it helps you see which areas to focus on. And what policies or procedures to put in place.