Skip to content
eQomply
  • Platform

    Platform

    • Governance
    • Risk Management
    • Compliance Management
    • Integrations
    0 +

    Evidences Tracked

    0 +

    Regulatory Workflows

  • GRC Solutions

    By Role

    • For Compliance Leaders
    • For Chief Risk Officers
    • For Data Protection Officers
    • For CISOs
    • For Internal Audit Teams

    by industry

    • Banks & NBFCs
    • Insurance
    • Capital Markets
    • Pharma & Healthcare
    • More..

    by regulations

    • RBI Compliance
    • SEBI Compliance
    • IRDAI Compliance
    • DPDP Act
    • More..

    Featured Resource

    • How to Measure Compliance Training Effectiveness
    • Fourth-Party Risk Management Explained
  • Resources
  • Company
eQomply
Request Demo
GRC

Three Lines of Defense: How the Model Works in Practice

August 11, 2026 Pritesh Baviskar No comments yet

The three lines of defense model remains the foundational governance structure for risk management across regulated industries globally. In India, where regulatory expectations from RBI, SEBI, IRDAI, and CERT-In continue to intensify, this model provides the structural clarity that boards and management need to demonstrate accountability. Yet in practice, most Indian enterprises operate with a version of this model that exists on paper while the actual flow of risk ownership tells a different story.

This post breaks down what the model is, how Indian regulators reference it, where it typically fails in practice, and what it takes to make each line genuinely operational.

The Three Lines of Defense Model Explained

The model divides risk governance responsibilities across three distinct functions, each with a clear mandate and reporting line. The logic is straightforward: separate the people who create and manage risk from the people who oversee it, and separate both from the people who provide independent assurance.

First Line: Business Operations

The first line comprises business units, operational teams, and front-line managers who own and manage risk as part of their daily activities. In a bank, this includes branch operations, lending teams, and customer-facing functions. In a pharmaceutical company, this covers manufacturing, quality control, and distribution. These teams generate risk through their activities, and the model expects them to identify, assess, and mitigate risks within defined parameters.

The first line owns the controls. They execute processes, follow standard operating procedures, escalate exceptions, and maintain the evidence that demonstrates compliance with internal policies and external regulations.

Second Line: Risk and Compliance Functions

The second line includes the risk management function, compliance teams, information security, and any specialized oversight functions. Their role is to design frameworks, set policies, monitor the first line’s adherence, and provide guidance on regulatory requirements. They do not execute business processes, but they ensure the first line has the tools, knowledge, and guardrails to manage risk effectively.

In Indian regulated enterprises, the second line typically handles regulatory interpretation, maps new circulars to internal controls, manages compliance calendars, and reports to the board risk committee. For a deeper understanding of how GRC frameworks structure these responsibilities, this explanation of GRC frameworks provides useful context.

Third Line: Internal Audit

The third line is internal audit, providing independent and objective assurance to the board and senior management on the effectiveness of governance, risk management, and internal controls. Internal audit does not own risk or design controls. It evaluates whether the first and second lines are functioning as intended, identifies gaps, and reports findings with recommendations.

The third line’s independence is its defining characteristic. It reports to the audit committee of the board, not to management, which gives it the authority to challenge both business operations and risk functions without conflicts of interest.

How Indian Regulators Reference This Model

Indian regulators do not merely suggest the three lines of defense model. They embed its logic into their governance expectations, sometimes explicitly naming it and sometimes structuring requirements that only work if the model is operational.

RBI’s Governance and Risk Management Expectations

RBI’s guidelines on corporate governance for banks and NBFCs explicitly reference the three lines model. The Master Direction on Risk Management and Inter-Bank Dealings expects banks to demonstrate clear separation between risk-taking units (first line), the risk management function (second line), and internal audit (third line). RBI’s recent emphasis on compliance culture, articulated through multiple circulars on compliance function in banks, places specific expectations on the second line’s independence from business units.

For NBFCs in the upper layer under the Scale-Based Regulation framework, RBI now expects governance structures equivalent to banks, including a CRO who reports to the board and operates independently of business verticals. This is the second line’s independence codified into regulation.

SEBI’s Cybersecurity and Governance Frameworks

SEBI’s Cybersecurity and Cyber Resilience Framework for regulated entities (stock exchanges, depositories, mutual funds, stockbrokers) implicitly demands all three lines. Business units must implement security controls (first line), the CISO function must oversee and monitor (second line), and periodic audits must provide assurance (third line). SEBI’s insistence on board-level reporting of cyber risk posture assumes this separation exists and functions reliably.

IRDAI’s Corporate Governance Guidelines

IRDAI’s corporate governance guidelines for insurers mandate a compliance function that operates independently of business units, an appointed actuary function with specific oversight responsibilities, and an internal audit function with direct board access. The structure mirrors the three lines model precisely, even where the terminology differs.

CERT-In’s Incident Reporting Requirements

CERT-In’s 2022 directives on incident reporting within six hours create an operational reality where first-line detection, second-line assessment, and third-line review must operate in compressed timeframes. Organizations that have not clarified which function does what during an incident find themselves scrambling when the six-hour clock starts.

Common Breakdowns: Where the Model Fails in Practice

The structural elegance of the model often collapses under operational reality. Two patterns dominate in Indian regulated enterprises, and both create risk exposure that regulators increasingly penalize.

Breakdown One: The First Line Does Not Own Risk

Consider an NBFC managing compliance across RBI’s master directions and CERT-In’s incident reporting requirements simultaneously. The lending team originates loans, but treats compliance requirements as someone else’s problem. KYC exceptions get escalated to the compliance team rather than resolved at source. Data handling practices in branch operations do not align with the DPDP Act requirements because business managers see data protection as a “compliance function issue.”

When the first line abdicates risk ownership, the second line becomes a bottleneck. Compliance officers end up performing operational tasks, chasing business units for evidence, filling control attestations on behalf of teams that should be doing it themselves. This creates three structural problems that most risk functions are not equipped to handle: capacity constraints that prevent strategic work, accountability gaps when things go wrong, and a false sense of security because the second line “has it covered.”

Breakdown Two: The Second Line Does Everything

In many mid-sized financial services firms, the compliance team has evolved into an operational function that identifies risks, designs controls, implements them, monitors adherence, collects evidence, and reports to the board. The second line has become the first line by default, which means there is no genuine oversight layer. When regulators examine this structure during inspections, they find that no independent challenge exists between risk creation and risk monitoring.

This pattern intensifies during regulatory change. When RBI issues a new circular on digital lending or SEBI updates its cybersecurity framework, the compliance team absorbs all the implementation work because business units have never been expected to own regulatory requirements. The result is a compliance function that is perpetually reactive, overworked, and unable to provide the strategic risk perspective that boards need.

Breakdown Three: The Third Line Lacks Access and Authority

Internal audit teams in some Indian enterprises operate with limited access to systems, data, and evidence repositories. Their audit cycles are annual rather than continuous, their findings take months to reach closure, and their recommendations get deprioritized when business pressures mount. The relationship between internal audit and compliance functions often lacks the collaborative structure needed for effective governance. The dynamics of this relationship, and how to strengthen it, are explored in detail in this piece on internal audit and compliance collaboration.

Making the Three Lines of Defense Model Operational

Moving from a theoretical model to an operational one requires clarity on three dimensions: who does what, how work flows between lines, and what evidence demonstrates that each line is functioning.

Defining Ownership with Specificity

Generic RACI matrices do not solve the ownership problem. What works is mapping every regulatory obligation to a specific first-line owner, with the second line explicitly named as the oversight and guidance function. For example, under RBI’s outsourcing guidelines, the business unit that manages the vendor relationship (first line) must own the risk assessment and ongoing monitoring. The compliance team (second line) sets the policy, defines the assessment criteria, and reviews adherence. Internal audit (third line) evaluates whether the process works as designed.

This mapping must be granular enough that when a regulator asks “who is responsible for ensuring compliance with clause 7.3 of this circular,” the answer is immediate, specific, and backed by evidence.

Establishing Escalation Protocols

The model functions when information flows predictably between lines. First-line teams need clear thresholds for escalation: what level of risk triggers second-line involvement, what constitutes a material exception, and what requires immediate notification to internal audit. These protocols must be documented, trained, and tested periodically.

Evidence as the Connective Tissue

Each line generates evidence that the next line consumes. The first line produces control execution evidence (completed checklists, approval records, exception logs). The second line produces monitoring evidence (review reports, testing results, compliance assessments). The third line produces assurance evidence (audit reports, findings, follow-up status). When this evidence chain is intact and accessible, the model demonstrates its value during regulatory inspections and board reporting.

Where Technology Fits in Each Line of Defense

Technology’s role differs meaningfully across the three lines, and conflating these roles leads to poor implementation decisions.

First Line: Workflow Integration and Evidence Capture

For the first line, technology must embed compliance activities into existing workflows rather than creating parallel processes. Control attestations, exception reporting, and evidence submission should happen within the systems business teams already use or through interfaces that require minimal additional effort. The goal is reducing the friction that causes first-line teams to avoid risk ownership responsibilities.

Automated evidence capture is particularly valuable here. When a first-line team completes a control activity, the system should capture the evidence automatically, timestamped, with an audit trail that neither the first nor second line can alter retroactively.

Second Line: Monitoring, Analysis, and Regulatory Intelligence

The second line needs technology that consolidates risk and compliance data across business units, maps regulatory requirements to internal controls, tracks compliance status against deadlines, and generates the reports that boards and regulators expect. A unified risk register that connects regulatory obligations to control activities to evidence to findings gives the second line the visibility it needs to perform genuine oversight rather than administrative task management.

Regulatory intelligence capabilities matter significantly for Indian regulated enterprises. When RBI issues a new master direction or SEBI updates its framework, the second line needs to assess impact, map requirements to existing controls, identify gaps, and assign remediation tasks to first-line owners. This workflow, from regulatory change to operational response, determines whether compliance is proactive or perpetually catching up.

Third Line: Independent Access and Assurance Analytics

Internal audit needs independent access to the same evidence repositories, risk registers, and compliance tracking systems that the first and second lines use, with read-only access that preserves independence. The ability to see real-time control status, identify patterns in exceptions, and focus audit efforts on high-risk areas transforms audit from a periodic exercise into a continuous assurance function.

Findings management and closure tracking are equally critical. When audit identifies a gap, the technology should enable structured follow-up: assigned owners, remediation deadlines, evidence of closure, and verification by audit that the fix is effective.

A Unified Platform Across All Three Lines

The table below illustrates how a GRC platform serves different needs across the three lines while maintaining a single source of truth:

Line of Defense Primary Technology Need Key Outcome
First Line (Business Operations) Embedded workflows, evidence capture, task completion Risk ownership becomes operational, not theoretical
Second Line (Risk/Compliance) Regulatory mapping, monitoring dashboards, compliance tracking Oversight with visibility, not administrative overhead
Third Line (Internal Audit) Independent access, findings management, assurance reporting Continuous assurance with board-ready outputs

This is precisely the architecture that eQomply provides. Built for India’s regulatory landscape, eQomply gives each line of defense the capabilities it needs while maintaining a consolidated view that connects policy to risk to compliance to evidence to audit findings. The platform’s pre-mapped regulatory workflows for RBI, SEBI, IRDAI, and CERT-In requirements mean the second line spends time on oversight and analysis rather than manual regulatory interpretation and spreadsheet management.

Moving to Accountability

The three lines of defense model works when it creates genuine accountability at each level. In Indian regulated enterprises facing increasing regulatory scrutiny, the cost of a non-functional model is measurable: regulatory findings, penalties, board-level escalations, and reputational impact.

The shift from theoretical to operational requires three investments. First, organizational clarity on who owns what, documented at the level of individual regulatory obligations. Second, evidence infrastructure that makes compliance activities visible across all three lines without creating additional manual work. Third, technology that connects the lines rather than siloing them into separate tools and spreadsheets.

Indian regulators are moving toward examining not just whether controls exist, but whether the governance structure that supports those controls functions with the independence and rigor the model demands. Regulated enterprises that can demonstrate an operational three lines of defense model, backed by evidence and supported by integrated technology, are in a fundamentally stronger position during inspections, audits, and board reviews.

If your organization is working to operationalize this model across regulatory requirements from RBI, SEBI, IRDAI, or CERT-In, a conversation with the eQomply team can help you see how each line of defense maps to platform capabilities built specifically for Indian regulated enterprises.

  • governance
  • GRC
  • risk management
  • three lines of defense
Pritesh Baviskar
Pritesh Baviskar

Founder at eQomply. Writes about compliance, regulatory shifts, and what it takes to build GRC functions that actually work.

Post navigation

Previous
Next

Search

Categories

  • Board Reporting (5)
  • CERT-In (5)
  • Compliance Management (12)
  • DPDP Act (10)
  • Evidence Management (6)
  • GRC (9)
  • Guides (5)
  • IRDAI Compliance (5)
  • Perspectives (1)
  • RBI Compliance (10)
  • SEBI Compliance (6)
  • Third Party Risk (5)
  • Uncategorized (4)

Recent posts

  • Fintech Compliance Challenges in India
  • SEBI Investor Grievance Compliance: Key Requirements
  • Three Lines of Defense: How the Model Works in Practice

Tags

AML audit audit readiness banking banking compliance BFSI board reporting brokers capital markets case-studies CERT-In circulars compliance CRO CSCRF cybersecurity data fiduciary data protection documentation DPDP DPO enforcement evidence framework governance GRC gst compliance incident reporting inspection insurance IRDAI IT governance multi-regulator NBFC outsourcing penalties privacy RBI regulation risk management SEBI spreadsheets stock market third party risk vendor risk

Related posts

Compliance Management

Whistleblower Compliance in India: Key Requirements

August 6, 2026 Pritesh Baviskar No comments yet

Understand whistleblower compliance requirements in India, including SEBI, RBI, and Companies Act obligations along with protection measures.

GRC

How to Evaluate GRC Tools: A Buyer’s Checklist

July 29, 2026 Pritesh Baviskar No comments yet

Evaluate GRC tools using criteria like regulatory coverage, scalability, reporting, deployment, integrations, and total cost of ownership.

Compliance Management

Understanding the Overlap Between CISO and CCO Roles

July 27, 2026 Pritesh Baviskar No comments yet

Explore how CISOs and CCOs collaborate on cybersecurity, regulatory compliance, vendor risk, incident response, and board reporting

Subscribe to Field Notes

    Enterprise GRC for regulated industries

    Platform
    • Overview
    • Policy Management
    • Risk Management
    • Compliance
    Solutions
    • By Role
    • By Industry
    • By Regulation
    Resources
    • Field Notes
    • Guides
    • Regulatory Library
    • Terms of Services
    • Privacy Policy

    © QomplySuite Private Limited Copyright 2026