<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US">
	<id>https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3AThree_lines_of_defence</id>
	<title>Definition:Three lines of defence - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3AThree_lines_of_defence"/>
	<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Three_lines_of_defence&amp;action=history"/>
	<updated>2026-05-02T16:18:35Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://www.insurerbrain.com/w/index.php?title=Definition:Three_lines_of_defence&amp;diff=20749&amp;oldid=prev</id>
		<title>PlumBot: Bot: Creating new article from JSON</title>
		<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Three_lines_of_defence&amp;diff=20749&amp;oldid=prev"/>
		<updated>2026-03-18T03:16:01Z</updated>

		<summary type="html">&lt;p&gt;Bot: Creating new article from JSON&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;🛡️ &amp;#039;&amp;#039;&amp;#039;Three lines of defence&amp;#039;&amp;#039;&amp;#039; is a widely adopted [[Definition:Governance | governance]] and [[Definition:Risk management | risk management]] framework that organizes an insurance organization&amp;#039;s controls and oversight into three distinct layers, each with clearly separated responsibilities. Originally popularized in the banking sector and subsequently embraced across the global insurance industry, the model assigns frontline operational management as the first line, [[Definition:Compliance | compliance]] and risk oversight functions as the second line, and [[Definition:Internal audit | internal audit]] as the third line. Insurance regulators worldwide — from the [[Definition:Prudential Regulation Authority (PRA) | PRA]] and [[Definition:Financial Conduct Authority (FCA) | FCA]] in the UK to the [[Definition:National Association of Insurance Commissioners (NAIC) | NAIC]] framework in the United States and [[Definition:Solvency II | Solvency II]] governance requirements in Europe — expect insurers to demonstrate a functioning model of this kind as part of their supervisory obligations.&lt;br /&gt;
&lt;br /&gt;
⚙️ In practice within an insurance company, the first line consists of the business units and operational teams that own and manage risk daily — [[Definition:Underwriter | underwriters]] assessing and pricing risks, [[Definition:Claims | claims]] teams handling settlements, and [[Definition:Distribution | distribution]] managers overseeing intermediary conduct. These teams operate within the risk appetite and authorities set by senior leadership. The second line comprises functions such as the [[Definition:Chief risk officer (CRO) | chief risk officer&amp;#039;s]] team, the [[Definition:Actuarial function | actuarial function]], and compliance officers who set policies, monitor adherence, and challenge the first line&amp;#039;s decisions without being directly involved in day-to-day operations. The third line — internal audit — provides independent assurance to the [[Definition:Board of directors | board]] that both the first and second lines are functioning effectively. This separation matters enormously in insurance because the products create long-duration obligations: an [[Definition:Underwriting | underwriting]] error or a [[Definition:Reserving | reserving]] misjudgment today may not surface for years, making robust independent oversight essential.&lt;br /&gt;
&lt;br /&gt;
💡 The framework has proven especially critical in the context of [[Definition:Delegated underwriting authority (DUA) | delegated authority]] arrangements, where an insurer grants [[Definition:Binding authority agreement | binding authority]] to external parties such as [[Definition:Managing general agent (MGA) | MGAs]] or [[Definition:Coverholder | coverholders]]. Here, the three lines of defence must extend beyond the insurer&amp;#039;s own walls: the first line includes the delegated partner, the second line must monitor that partner&amp;#039;s compliance with authority limits and conduct standards, and internal audit must periodically verify that oversight mechanisms are working. The [[Definition:Lloyd&amp;#039;s | Lloyd&amp;#039;s]] market, for example, has placed significant emphasis on how managing agents govern their coverholder networks through this lens. While some organizations have updated the model — the Institute of Internal Auditors revised its guidance in 2020 to emphasize principles and coordination over rigid structural separation — the core logic remains embedded in how insurers globally structure their governance and satisfy regulatory expectations under regimes as varied as [[Definition:C-ROSS | C-ROSS]] in China and the [[Definition:Insurance Core Principles (ICP) | Insurance Core Principles]] of the [[Definition:International Association of Insurance Supervisors (IAIS) | IAIS]].&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Related concepts:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
{{Div col|colwidth=20em}}&lt;br /&gt;
* [[Definition:Risk management]]&lt;br /&gt;
* [[Definition:Internal audit]]&lt;br /&gt;
* [[Definition:Compliance]]&lt;br /&gt;
* [[Definition:Governance]]&lt;br /&gt;
* [[Definition:Solvency II]]&lt;br /&gt;
* [[Definition:Delegated underwriting authority (DUA)]]&lt;br /&gt;
{{Div col end}}&lt;/div&gt;</summary>
		<author><name>PlumBot</name></author>
	</entry>
</feed>