THE KYC DICTIONARY
Three Lines of Defense (LoD) Model
Definition
The Three Lines of Defense (LoD) model is a risk management framework that provides a structured approach for organizations to clearly define and separate responsibilities related to three distinct layers of accountability: governance, risk management and disclosure.
Originally formalized in 2011 by the Basel Committee - the main world-wide standard setter for the prudential regulation of banks, serving as a forum for cooperation on banking supervisory matters - within the “Principles for the sound management of operational risk”, the model establishes three distinct lines of defense to ensure robust oversight and accountability:
- First Line of Defense: Business Units
- Operates within business functions and owns day-to-day risk management.
- Implements internal controls and ensures adherence to policies and procedures.
- Identifies, monitors and reports emerging risks, escalating concerns when necessary.
- Second Line of Defense: “Risk and Compliance” - An independent Corporate Operational Risk Function (CORF); also known as the corporate operational risk management function in many jurisdictions
- Generally complements the business unit’s operational risk management activities with oversight and support in risk policies, tools and training.
- Independently monitors the risk profile and challenges risk decisions when needed.
- Tracks regulatory developments to ensure ongoing compliance.
- Third Line of Defense: Independent Review / Audit
- Conducts independent reviews of the first two lines to evaluate their effectiveness.
- Assesses internal control systems, governance structures and risk mitigation practices.
- Reports findings directly to the board or audit committee - ensuring impartial oversight.
This layered approach ensures comprehensive risk management by distributing responsibilities while maintaining checks and balances within the institution.
Related terms
STAY UPDATED WITH KYC TRENDS
Related Articles
See the Avallone Platform in Action!
.jpg)
What we offer
Avallone’s Products and Services
Whatever your needs, our products and services work together seamlessly - enabling your team to confidently respond to KYC requests, collect information safely and securely from counterparties, maintain data accuracy and escalate concerns effectively.
KYC Responder
Say goodbye to manual handling of incoming KYC requests. Easily save, store and re-use responses to avoid endless duplication.
KYC Collector
Save time collecting and verifying KYC data from counterparties. Streamline screening, compliance and risk scoring in one easy-to-use platform.
Screening
Real-time monitoring for sanctions, PEPs, adverse media and more
KYC Hub
One single source of truth for managing and visualizing legal entity structures and documents across your entire organization.
Managed Services
Hands-on support to relieve your KYC / CDD workload. Our experts work alongside your team to provide scalable support where and when you need it most.
Advisory Services
Trust our expert team with +30 years of financial crime prevention and compliance experience to help define processes, develop frameworks and tackle complex KYC challenges.
Outreach KYC Services
Designed for banks and financial institutions looking to simplify their KYC document collection. Let us take care of the time-consuming communication and follow-up, and elevate the experience for your customers.
Remediation Services
For regulated companies seeking proactive solutions to meet their compliance deadlines. Tap into remediation support to refresh and verify customer profiles quickly and accurately.
KYC 360° Full Suite
Experience the full power of Avallone with every product and service at your fingertips. The most complete way to manage KYC end-to-end.

.png)