As recently as 10 years ago, enterprise risk management (ERM) was still in its formative stage. As recently as 10 years ago, enterprise risk management (ERM) was still in its formative stage. (iStock)

Any discussion about organizing and governing risk management in a financial services company typically includes the "three lines of defense" model.

There are different interpretations of the three lines' roles and which functional departments fit into each line, which are broadly defined as follows:

  1. First line: Those that own and manage risk
  2. Second line: Those that oversee risk
  3. Third line: Independent assurance

What also differs is how successful this model has been over the last 15 years.

Want to continue reading?
Become a Free PropertyCasualty360 Digital Reader

  • All PropertyCasualty360.com news coverage, best practices, and in-depth analysis.
  • Educational webcasts, resources from industry leaders, and informative newsletters.
  • Other award-winning websites including BenefitsPRO.com and ThinkAdvisor.com.
NOT FOR REPRINT

© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.