<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US">
	<id>https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3AThree_lines_of_defence_model</id>
	<title>Definition:Three lines of defence model - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3AThree_lines_of_defence_model"/>
	<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Three_lines_of_defence_model&amp;action=history"/>
	<updated>2026-05-02T19:08:11Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://www.insurerbrain.com/w/index.php?title=Definition:Three_lines_of_defence_model&amp;diff=20614&amp;oldid=prev</id>
		<title>PlumBot: Bot: Creating new article from JSON</title>
		<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Three_lines_of_defence_model&amp;diff=20614&amp;oldid=prev"/>
		<updated>2026-03-18T02:34:41Z</updated>

		<summary type="html">&lt;p&gt;Bot: Creating new article from JSON&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;🏛️ &amp;#039;&amp;#039;&amp;#039;Three lines of defence model&amp;#039;&amp;#039;&amp;#039; is a governance and risk management framework that organizes an insurance organization&amp;#039;s control activities into three distinct layers: operational management (first line), [[Definition:Risk management | risk management]] and [[Definition:Compliance | compliance]] functions (second line), and [[Definition:Internal audit | internal audit]] (third line). Adopted widely across the global insurance industry — and embedded into regulatory expectations under [[Definition:Solvency II | Solvency II]], the UK&amp;#039;s [[Definition:Senior Managers and Certification Regime (SM&amp;amp;CR) | SM&amp;amp;CR]], and supervisory guidance from bodies like the [[Definition:International Association of Insurance Supervisors (IAIS) | IAIS]] — the model provides a structured way to ensure that risk-taking, risk oversight, and independent assurance remain separate and effective. The Institute of Internal Auditors updated the framework in 2020 (rebranding it as the &amp;quot;Three Lines Model&amp;quot;), but the original terminology remains dominant in insurance regulatory discourse.&lt;br /&gt;
&lt;br /&gt;
🔄 Each line carries a distinct mandate. The [[Definition:First line of defence | first line]] — which includes [[Definition:Underwriter | underwriters]], [[Definition:Claims | claims]] teams, [[Definition:Distribution channel | distribution]] managers, and operational staff — owns the risks inherent in daily business activities and is responsible for implementing controls. The [[Definition:Second line of defence | second line]] comprises specialist functions such as the [[Definition:Chief risk officer (CRO) | chief risk officer&amp;#039;s]] team, [[Definition:Actuarial function | actuarial function]], and compliance department; these functions design frameworks, set [[Definition:Risk appetite | risk appetite]] parameters, monitor the first line&amp;#039;s adherence, and challenge decisions where necessary. The [[Definition:Third line of defence | third line]] — internal audit — operates independently of both, providing the [[Definition:Board of directors | board]] and [[Definition:Audit committee | audit committee]] with objective assurance that the other two lines are functioning as intended. In practice, the boundaries require careful calibration: an [[Definition:Managing general agent (MGA) | MGA]] operating under [[Definition:Delegated underwriting authority (DUA) | delegated authority]] effectively extends an insurer&amp;#039;s first line beyond its own walls, demanding that the insurer&amp;#039;s second and third lines extend their reach accordingly.&lt;br /&gt;
&lt;br /&gt;
📊 The model&amp;#039;s strength lies in creating accountability without duplication — when it works well, each line understands its role and does not encroach on or neglect the others. Regulators frequently assess the effectiveness of the three lines during supervisory visits and [[Definition:Own Risk and Solvency Assessment (ORSA) | ORSA]] reviews, and weaknesses in any single line can trigger enhanced supervision or capital add-ons. Criticism of the model typically centers on the risk that it becomes a checkbox exercise, with the three lines operating in silos rather than engaging in dynamic, two-way communication. For smaller insurers and [[Definition:Insurtech | insurtech]] startups, strict separation can be challenging to resource, leading to proportionate approaches where, for example, the compliance and risk management functions may share personnel but maintain distinct reporting lines. Despite these tensions, the three lines of defence model remains the dominant structural paradigm for insurance governance worldwide.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Related concepts:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
{{Div col|colwidth=20em}}&lt;br /&gt;
* [[Definition:First line of defence]]&lt;br /&gt;
* [[Definition:Second line of defence]]&lt;br /&gt;
* [[Definition:Third line of defence]]&lt;br /&gt;
* [[Definition:Internal audit]]&lt;br /&gt;
* [[Definition:Risk management]]&lt;br /&gt;
* [[Definition:Corporate governance]]&lt;br /&gt;
{{Div col end}}&lt;/div&gt;</summary>
		<author><name>PlumBot</name></author>
	</entry>
</feed>