Three Lines of Defense Model in AML Compliance: Roles & Responsibilities
The Three Lines of Defense (now the IIA's Three Lines Model) explained for AML: roles, who owns risk, FINTRAC and BSA mapping, and a practical MSB example.

Key takeaways
- The Three Lines Model separates risk ownership, compliance oversight, and independent assurance. First-line management owns and manages operational risk; second-line compliance supports, monitors, and challenges; internal audit provides formal third-line assurance.
- The IIA now uses the term Three Lines Model, although βThree Lines of Defense/Defenceβ remains the widely searched terminology.
- FINTRAC does not mandate the Three Lines Model by name, but Canadian AML compliance-program requirements can be mapped to similar operational, oversight, and independent-review roles.
- U.S. BSA/AML governance depends on institution type; MSB requirements under 31 CFR 1022.210 are distinct from the 2016 CDD Rule that applies to covered financial institutions.
- Smaller MSBs can use proportionate or outsourced arrangements, but role overlap and outsourcing do not remove the need for clear accountability and appropriate independence.
The Three Lines Model divides risk-management responsibilities across three groups: the people who run the business, the specialist risk and compliance functions that support and challenge them, and an independent internal audit function that provides assurance to the board. The first line owns and manages risk. The second line supports, monitors, and challenges how that risk is managed. The third line independently assesses whether the whole system works.
"Three Lines of Defense" and "Three Lines of Defence" β including the exact phrase "three lines of defence model" β are the names most people search for and still recognize; "defence" is the common spelling in Canada, the UK, and other Commonwealth markets. The Institute of Internal Auditors (IIA), which maintains the framework, now calls it the Three Lines Model. This article uses the modern model's substance while using the historical, widely searched name where it helps.
What Is the Three Lines of Defense Model?
The model answers a governance question every organization faces: who's responsible for managing risk day to day, who checks it's managed well, and who independently confirms the system holds up? Splitting those jobs keeps any one group from grading its own work.
The governing body β a board of directors, or an equivalent oversight body in a smaller company β sits above all three lines, setting risk appetite, holding management accountable for the first and second lines, and relying on internal audit's independent assurance to know whether that accountability is working.
Why the IIA Now Calls It the Three Lines Model
The IIA moved from "Three Lines of Defense" to the "Three Lines Model" in 2020, dropping the defensive framing since risk management also supports achieving objectives, not just guarding against threats. On July 8, 2026, the IIA published a refreshed Statement of Position on the Three Lines Model, alongside a companion statement on internal audit's role in enterprise risk management, replacing the 2020 paper. The core structure didn't change, but the update sharpens guidance on governance, accountability, and coordination between the lines, and gives much more explicit treatment of overlapping or blended roles without losing independence.
That last point matters more for smaller regulated businesses than the name change itself, and it resurfaces later when discussing how a small MSB can apply the model without three full standalone departments.
1st Line of Defense: Business Operations Own and Manage Risk
The first line β sometimes written as the first line of defence β is normally the people who run the processes that create and manage risk: operational and customer-facing staff, and the managers responsible for them. In AML, common first-line activities include customer onboarding, collecting KYC information, following CDD procedures, spotting red flags during day-to-day work, applying built-in operational controls, escalating unusual activity, and maintaining the resulting operational records.
Which specific controls sit with the first line varies by business. Some organizations have front-line staff perform initial sanctions or PEP screening at onboarding; others centralize that screening within compliance instead. Neither is universally correct β it depends on the business's size, systems, and governance model, not on what's common elsewhere.
2nd Line of Defense: Compliance Supports, Monitors and Challenges
The second line brings the specialist expertise that keeps first-line risk management honest: compliance, an AML compliance officer, an MLRO or BSA officer depending on jurisdiction, and the broader financial-crime risk function. Typical responsibilities include designing AML policy, setting risk methodology, monitoring how well first-line controls operate, challenging decisions that don't hold up, interpreting regulatory requirements, managing escalations, and reporting to management and the board.
It's worth being precise here, since this is where a lot of AML writing goes wrong: first-line management owns and manages the risks arising from its own operations β the second line does not universally "own" AML risk. A regulatory compliance officer or MLRO often carries specific, personally-attached legal responsibilities under the applicable framework, which is different from owning every AML risk the business generates. A fractional MLRO or in-house compliance officer performing this role well holds the business accountable for its own risk, rather than absorbing that risk personally.
3rd Line of Defense: Independent Assurance
Under the IIA model, internal audit is the third line, providing independent, objective assurance to the governing body on whether governance, risk management, and controls across the first two lines are actually working β not designing or operating those controls itself. Independence is what makes this meaningful: internal audit reports functionally to the board or an audit committee, separate from the management chain it's assessing, so its findings aren't shaped by the people whose work it reviews.
It's a common shortcut to describe the third line as "internal and external auditors" together, but that blurs two different things. External auditors, regulatory examiners, and outside consultants can provide valuable assurance that complements the third line β but under the IIA model, they aren't automatically the organization's third line, which specifically refers to its own independent internal audit function reporting to its own governing body. Treating an occasional external review as a full substitute misses part of the model.
Which Line of Defense Owns AML Risk?
This is worth answering directly, since it's the point most commonly gotten wrong. First-line management owns and manages the risks arising from its own activities. Second-line compliance provides expertise, sets standards, monitors, and challenges β it doesn't own the risk itself. Third-line internal audit independently assesses whether governance, risk management, and controls are working, without owning or managing risk at all. The board or governing body retains ultimate oversight and accountability for the whole system.
This traces back to the business's inherent risk assessment, which identifies where exposure sits before any line applies a control. Regulatory frameworks can layer specific legal obligations onto a compliance officer or MLRO personally β reporting duties, program-implementation responsibilities β without making that person the sole owner of every AML risk. Ownership of the underlying risk stays with the operations that generate it.
How the Three Lines Work Together in an AML Program
This is an illustrative governance model, not a universal assignment. Exact responsibilities depend on the jurisdiction, institution type, regulatory requirements, operating model, and internal governance structure.
Note the risk-assessment row: compliance leading the methodology is not the same as compliance owning the underlying business risk. Operational management owns the risks arising from its own activities; compliance's role is methodological and governance support, not risk ownership by another name. A properly built AML compliance program maps its own version of this table explicitly, rather than leaving the allocation implicit.
Three Lines of Defense Example for an MSB
A remittance customer sending modest, predictable amounts abruptly sends significantly larger transfers to a new corridor, with a stated purpose that doesn't reconcile with their occupation on file.
First line: The teller or onboarding analyst notices the mismatch and escalates it through the defined escalation route, rather than deciding alone whether it's a problem.
Second line: Compliance reviews the escalation, determines it warrants enhanced due diligence, gathers additional information, documents its findings and reasoning, decides whether to file a suspicious transaction report, and adjusts ongoing monitoring if the relationship continues.
Third line / internal audit: Later, as part of a scheduled sample, internal audit independently tests whether the escalation, EDD, reporting, and monitoring controls worked as designed β was escalation timely, was the EDD decision documented with a clear rationale, was any required report filed correctly, and did monitoring actually change afterward. The point isn't relitigating the original decision; it's confirming the process around it worked.
Small MSB / external assurance: Where the MSB has no internal audit function, an independent AML audit performed by an appropriately independent external reviewer can test the same file as part of the required effectiveness review β genuine external independent assurance, but not automatically the formal IIA third line.
Three Lines of Defense Under FINTRAC in Canada
FINTRAC does not prescribe or mandate the Three Lines Model by name β there's no PCMLTFA provision requiring a Canadian reporting entity to structure itself this way. What FINTRAC does require is a specific set of compliance-program elements that map naturally onto a Three Lines governance approach, even though FINTRAC never uses that term.
Viewed through a Three Lines lens, operational controls generally map to first-line roles, while the appointed compliance officer typically maps most closely to second-line oversight β running the compliance program, including written policies and procedures, the documented risk assessment, and ongoing AML training. FINTRAC does not require or use those labels, and the exact allocation varies with the size and structure of the reporting entity. FINTRAC guidance does add a useful independence note: as a best practice, the appointed compliance officer of a larger business should not be directly involved in the receipt, transfer, or payment of funds, and should have a direct line to senior management or the board β the same separation-of-duties logic the model is built on, framed as best practice rather than legal requirement.
The closest regulatory analogue to independent third-line assurance is the mandatory two-year effectiveness review. FINTRAC guidance states that, as a best practice, this review should be impartial and should not be performed by someone directly involved in the reporting entity's compliance-program activities β precisely the independence the third line is meant to provide. Where an external independent AML auditor performs that review, it provides independent assurance but does not automatically become the organization's formal IIA third line. An independent AML audit can commonly be used to perform this effectiveness review where the required independence and scope are satisfied.
This separation scales with the business β a large MSB can typically staff all three roles distinctly, while a small one may need to combine them proportionately (covered in detail below). See ComplyFactor's PCMLTFA requirements guide for the full compliance-program obligations this maps to, and how a fractional compliance officer can fill the second-line role where an in-house hire isn't justified.
How the Model Applies to U.S. BSA/AML Compliance
In the U.S., the mapping depends on institution type. For MSBs, 31 CFR 1022.210 requires written policies, procedures, and internal controls; a designated compliance officer; ongoing training; and independent review to monitor and maintain an adequate program. Banks and other institutions subject to FinCEN's 2016 CDD Rule (31 CFR 1010.230) also carry customer-due-diligence obligations commonly discussed alongside the traditional BSA/AML "four pillars." These requirements can be organized using Three Lines principles, but the underlying legal requirements aren't identical across institution types β the CDD Rule doesn't apply to MSBs the way it applies to banks, mutual funds, and certain securities and futures firms.
For MSBs, the independent-review requirement is more flexible than the IIA's internal-audit definition: 31 CFR 1022.210 allows the review to be conducted by an officer or employee of the MSB, as long as that person isn't the individual who runs the compliance program, or by a qualified outside party β either can satisfy the requirement depending on the business's structure and the risk its services present. The FFIEC BSA/AML Examination Manual describes detailed independent-testing expectations, but it's written for banks, savings associations, and credit unions examined by the federal banking agencies β it doesn't directly govern MSB requirements, which arise separately under FinCEN's own BSA rules.
Can Small MSBs and Fintechs Use the Three Lines Model?
Yes β and this is where the model earns its keep for smaller businesses, though not by literally building three standalone departments most MSBs can't justify. A proportionate structure typically looks like operational staff as the first line, an internal or fractional compliance officer / MLRO providing second-line support, and internal audit providing third-line assurance where such a function exists. Where a smaller firm has no internal audit function, an appropriately independent external reviewer may perform required regulatory testing or effectiveness reviews without automatically becoming the formal IIA third line.
The IIA's 2026 refresh is directly relevant here: it gives much more explicit guidance on blended and overlapping roles, treating them as something requiring deliberate safeguards rather than something to avoid mentioning. Outsourcing doesn't automatically create independence β a fractional MLRO or fractional compliance officer functions as second-line support only if scope, authority, and reporting line are actually structured that way β and whoever performs third-line testing needs to be independent of whoever built the program being tested, not simply a different name on the invoice.
Where roles genuinely overlap β an owner acting as both a first-line manager and the named compliance officer β that's legitimate as long as it's acknowledged, and independent testing stays genuinely separate from whoever runs the program day to day.
Common Three Lines of Defense Failures in AML
- Compliance performing first-line controls and then monitoring its own work β collapses the second line's independence
- Business teams assuming compliance "owns all AML risk" β lets first-line risk ownership quietly disappear
- Unclear escalation responsibilities β nobody is sure who decides what
- A compliance officer lacking real authority β a title without standing to challenge decisions isn't a functioning second line
- Audit designing the controls it later tests β destroys third-line independence
- Third-line findings never reaching senior management or the board
- No documented division of responsibilities β an undocumented allocation is one nobody can be held to
- Small-company role overlap with no safeguards
- Outsourcing a role without defining accountability
Building Clear AML Accountability Across the Three Lines
Turning the model into something that holds up means making a few things explicit: document who's responsible for what, define escalation routes, establish reporting lines that reach the board, set clear control ownership, preserve genuine independence for third-line testing, coordinate the lines so they aren't duplicating each other's work, and revisit the model when the business changes materially β a structure built for a five-person MSB doesn't necessarily fit at fifty.
Three Lines of Defense FAQs
What do 1LoD, 2LoD and 3LoD mean?
Shorthand for the three lines: 1LoD is the first line (operations that own and manage risk), 2LoD is the second line (compliance and risk functions that support, monitor, and challenge), and 3LoD is the third line (independent assurance, typically internal audit). The abbreviations show up often in governance documents and job titles.
Can second-line compliance perform control testing?
Yes, depending on the governance model β second-line compliance commonly performs monitoring, quality assurance, and thematic reviews, including certain control testing. What it shouldn't be called is independent third-line assurance: testing performed by the same function that designed or owns a control doesn't carry the independence the third line is meant to provide, even when the work itself is useful.
Is a FINTRAC two-year effectiveness review the same as internal audit?
Not automatically. A FINTRAC effectiveness review is a regulatory compliance-program review with its own independence and impartiality expectations; internal audit is the formal third line under the IIA model, reporting to the governing body as an ongoing function. A reporting entity may use an appropriately independent internal or external reviewer to satisfy the effectiveness review, and that reviewer may or may not also be the business's internal audit function.
Does outsourcing AML compliance transfer accountability to the provider?
No. Outsourcing can provide specialist capability and strengthen second-line support, but it doesn't transfer the regulated entity's own governance and accountability. The arrangement still needs clearly defined scope, authority, reporting lines, and oversight.
If your program doesn't have a clear answer for who owns a given AML risk, who's checking it, and who's independently testing the result, that gap is worth closing before an examiner finds it first. ComplyFactor helps MSBs, PSPs, and fintechs clarify AML responsibilities across the three lines, strengthen second-line compliance oversight through fractional MLRO / compliance officer support, build governance into an AML compliance program, and independently test program effectiveness through an AML audit.
Related insights
Book a free Canada AML consultation
Tell us about your business and we'll confirm which services you need β free, no obligation, 30 minutes.