Back to dictonary

THE KYC DICTIONARY

Three Lines of Defense (LoD) Model

Definition

The Three Lines of Defense (LoD) model is a risk management framework that provides a structured approach for organizations to clearly define and separate responsibilities related to three distinct layers of accountability: governance, risk management and disclosure. 

Originally formalized in 2011 by the Basel Committee - the main world-wide standard setter for the prudential regulation of banks, serving as a forum for cooperation on banking supervisory matters - within the “Principles for the sound management of operational risk, the model establishes three distinct lines of defense to ensure robust oversight and accountability:

  1. First Line of Defense: Business Units
    1. Operates within business functions and owns day-to-day risk management.
    2. Implements internal controls and ensures adherence to policies and procedures.
    3. Identifies, monitors and reports emerging risks, escalating concerns when necessary.
  1. Second Line of Defense: “Risk and Compliance” - An independent Corporate Operational Risk Function (CORF); also known as the corporate operational risk management function in many jurisdictions
    1. Generally complements the business unit’s operational risk management activities with oversight and support in risk policies, tools and training.
    2. Independently monitors the risk profile and challenges risk decisions when needed.
    3. Tracks regulatory developments to ensure ongoing compliance.
  1. Third Line of Defense: Independent Review / Audit
    1. Conducts independent reviews of the first two lines to evaluate their effectiveness.
    2. Assesses internal control systems, governance structures and risk mitigation practices.
    3. Reports findings directly to the board or audit committee - ensuring impartial oversight.

This layered approach ensures comprehensive risk management by distributing responsibilities while maintaining checks and balances within the institution.

Related terms

No items found.
Have more KYC questions?
Avallone is here for you. Connect with one of our KYC professionals who can address your questions, concerns and needs.

STAY UPDATED WITH KYC TRENDS

Related Articles

View all articles

Why KYC is no longer just for regulated companies

For years, Know Your Customer (KYC) processes were considered the domain of regulated financial institutions. But today, that mindset is outdated...

Sep 22, 2025
Read article

Why KYC is no longer just for regulated companies

For years, Know Your Customer (KYC) processes were considered the domain of regulated financial institutions. But today, that mindset is outdated...

Sep 22, 2025
Read article

Why KYC is no longer just for regulated companies

For years, Know Your Customer (KYC) processes were considered the domain of regulated financial institutions. But today, that mindset is outdated...

Sep 22, 2025
Read article
No items found.

See the Avallone Platform in Action!

Get a demo

What we offer

Avallone’s Products and Services

Whatever your needs, our products and services work together seamlessly - enabling your team to confidently respond to KYC requests, collect information safely and securely from counterparties, maintain data accuracy and escalate concerns effectively.

KYC Responder

Say goodbye to manual handling of incoming KYC requests. Easily save, store and re-use responses to avoid endless duplication.

KYC Collector

Save time collecting and verifying KYC data from counterparties. Streamline screening, compliance and risk scoring in one easy-to-use platform.

Screening

Real-time monitoring for sanctions, PEPs, adverse media and more

KYC Hub

One single source of truth for managing and visualizing legal entity structures and documents across your entire organization.

Managed Services

Hands-on support to relieve your KYC / CDD workload. Our experts work alongside your team to provide scalable support where and when you need it most.

Advisory Services

Trust our expert team with +30 years of financial crime prevention and compliance experience to help define processes, develop frameworks and tackle complex KYC challenges.

Outreach KYC Services

Designed for banks and financial institutions looking to simplify their KYC document collection. Let us take care of the time-consuming communication and follow-up, and elevate the experience for your customers.

Remediation Services

For regulated companies seeking proactive solutions to meet their compliance deadlines. Tap into remediation support to refresh and verify customer profiles quickly and accurately.

KYC 360° Full Suite

Experience the full power of Avallone with every product and service at your fingertips. The most complete way to manage KYC end-to-end.