<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US">
	<id>https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3AThird_line_of_defence</id>
	<title>Definition:Third line of defence - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3AThird_line_of_defence"/>
	<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Third_line_of_defence&amp;action=history"/>
	<updated>2026-05-02T21:25:15Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://www.insurerbrain.com/w/index.php?title=Definition:Third_line_of_defence&amp;diff=20612&amp;oldid=prev</id>
		<title>PlumBot: Bot: Creating new article from JSON</title>
		<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Third_line_of_defence&amp;diff=20612&amp;oldid=prev"/>
		<updated>2026-03-18T02:34:37Z</updated>

		<summary type="html">&lt;p&gt;Bot: Creating new article from JSON&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;🛡️ &amp;#039;&amp;#039;&amp;#039;Third line of defence&amp;#039;&amp;#039;&amp;#039; is the [[Definition:Internal audit | internal audit]] function within an insurance organization, responsible for providing independent and objective assurance to the [[Definition:Board of directors | board]] that the first and second lines — operational management and [[Definition:Risk management | risk management]]/[[Definition:Compliance | compliance]] oversight, respectively — are functioning effectively. Within the broader [[Definition:Three lines of defence model | three lines of defence model]] widely adopted across the global insurance industry, the third line occupies a uniquely independent position: it reports directly to the board or its [[Definition:Audit committee | audit committee]], free from management influence, and has unrestricted access to people, records, and systems across the organization.&lt;br /&gt;
&lt;br /&gt;
🔎 In practice, the third line conducts risk-based audit plans that examine whether an insurer&amp;#039;s [[Definition:Underwriting | underwriting]] controls, [[Definition:Claims management | claims processes]], [[Definition:Reserving | reserving]] practices, [[Definition:Regulatory compliance | regulatory compliance]] arrangements, and [[Definition:Information security | information security]] controls operate as designed. Unlike the second line, which monitors and advises on an ongoing basis, the third line performs periodic, structured reviews and issues formal findings with remediation timelines. Under [[Definition:Solvency II | Solvency II]], internal audit is one of four mandatory [[Definition:Key function | key functions]] that every insurer must maintain, and the [[Definition:Prudential Regulation Authority (PRA) | PRA]] in the UK and [[Definition:European Insurance and Occupational Pensions Authority (EIOPA) | EIOPA]] both expect the function to have sufficient stature, resources, and expertise to challenge senior management credibly. In the United States, the [[Definition:National Association of Insurance Commissioners (NAIC) | NAIC&amp;#039;s]] Model Audit Rule imposes similar expectations for internal audit independence at insurers above certain premium thresholds.&lt;br /&gt;
&lt;br /&gt;
💡 The credibility of the third line rests on its genuine independence — a principle that regulators test rigorously. When the third line is under-resourced, conflicted, or marginalized, governance failures tend to follow, as demonstrated in several notable insurance scandals where internal audit either missed or was prevented from escalating critical control weaknesses. For [[Definition:Managing general agent (MGA) | MGAs]] and [[Definition:Coverholder | coverholders]] operating under [[Definition:Delegated underwriting authority (DUA) | delegated authority]], capacity providers increasingly expect evidence that a credible third-line function — whether in-house or outsourced — reviews delegated operations. In fast-growing [[Definition:Insurtech | insurtech]] firms, establishing even a lean internal audit capability signals to [[Definition:Reinsurance | reinsurers]] and regulators that the organization takes assurance seriously beyond what the first and second lines can self-certify.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Related concepts:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
{{Div col|colwidth=20em}}&lt;br /&gt;
* [[Definition:Three lines of defence model]]&lt;br /&gt;
* [[Definition:Internal audit]]&lt;br /&gt;
* [[Definition:First line of defence]]&lt;br /&gt;
* [[Definition:Second line of defence]]&lt;br /&gt;
* [[Definition:Audit committee]]&lt;br /&gt;
* [[Definition:Solvency II]]&lt;br /&gt;
{{Div col end}}&lt;/div&gt;</summary>
		<author><name>PlumBot</name></author>
	</entry>
</feed>