<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-US">
	<id>https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3AThree_lines_of_defense</id>
	<title>Definition:Three lines of defense - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.insurerbrain.com/w/index.php?action=history&amp;feed=atom&amp;title=Definition%3AThree_lines_of_defense"/>
	<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Three_lines_of_defense&amp;action=history"/>
	<updated>2026-05-01T04:23:33Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://www.insurerbrain.com/w/index.php?title=Definition:Three_lines_of_defense&amp;diff=19088&amp;oldid=prev</id>
		<title>PlumBot: Bot: Creating new article from JSON</title>
		<link rel="alternate" type="text/html" href="https://www.insurerbrain.com/w/index.php?title=Definition:Three_lines_of_defense&amp;diff=19088&amp;oldid=prev"/>
		<updated>2026-03-16T10:00:37Z</updated>

		<summary type="html">&lt;p&gt;Bot: Creating new article from JSON&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;🏗️ &amp;#039;&amp;#039;&amp;#039;Three lines of defense&amp;#039;&amp;#039;&amp;#039; is a [[Definition:Governance | governance]] and [[Definition:Risk management | risk management]] framework widely adopted by [[Definition:Insurance carrier | insurers]], [[Definition:Reinsurer | reinsurers]], and financial institutions to structure accountability for identifying, managing, and overseeing risk. In insurance, the model has become a cornerstone of regulatory expectations across major jurisdictions: [[Definition:Solvency II | Solvency II]] in the European Union, the [[Definition:Senior Managers and Certification Regime (SM&amp;amp;CR) | Senior Managers and Certification Regime]] in the United Kingdom, and comparable frameworks in markets like Hong Kong, Singapore, and Japan all presuppose that firms organize their internal controls along these three lines. The framework provides clarity about who owns risk, who oversees it, and who provides independent assurance — a delineation that becomes critical in organizations where [[Definition:Underwriting | underwriting]], [[Definition:Claims management | claims]], [[Definition:Investment management | investment]], and [[Definition:Reinsurance | reinsurance]] functions each generate distinct risk profiles.&lt;br /&gt;
&lt;br /&gt;
⚙️ The first line consists of the business and operational functions — [[Definition:Underwriter | underwriters]], [[Definition:Claims adjuster | claims handlers]], [[Definition:Distribution channel | distribution]] teams — that own and manage risk on a day-to-day basis. They are expected to operate within defined risk appetites and to apply controls as part of their normal workflows. The second line comprises oversight functions such as [[Definition:Risk management | risk management]], [[Definition:Compliance | compliance]], and [[Definition:Actuarial function | actuarial control]], which set policies, monitor adherence, challenge first-line decisions, and report to senior management and the board. The third line is [[Definition:Internal audit | internal audit]], which operates independently of both the first and second lines to provide objective assurance to the board and its committees that the overall framework is functioning effectively. In practice, the boundaries between lines can blur — particularly in smaller insurers or [[Definition:Managing general agent (MGA) | MGAs]] with lean teams — and regulators pay close attention to whether the separation is genuine rather than merely structural on paper.&lt;br /&gt;
&lt;br /&gt;
💡 Effective implementation of the three lines of defense is not just a regulatory checkbox; it directly influences an insurer&amp;#039;s ability to detect emerging exposures, prevent [[Definition:Fraud | fraud]], and maintain [[Definition:Solvency | solvency]]. Regulatory examinations and [[Definition:Own Risk and Solvency Assessment (ORSA) | ORSA]] processes routinely probe whether the framework operates with adequate independence, resources, and board-level engagement. Failures in the model — such as a second-line risk function that lacks authority to challenge aggressive [[Definition:Underwriting | underwriting]] decisions, or an internal audit team reporting to the CFO rather than the audit committee — have contributed to notable insurance failures and supervisory interventions. The framework has also evolved in response to guidance from the Institute of Internal Auditors, which updated its model in 2020 to emphasize collaboration and value creation alongside oversight, a shift that forward-thinking insurers are incorporating into their own governance structures.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Related concepts:&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
{{Div col|colwidth=20em}}&lt;br /&gt;
* [[Definition:Enterprise risk management (ERM)]]&lt;br /&gt;
* [[Definition:Internal audit]]&lt;br /&gt;
* [[Definition:Compliance]]&lt;br /&gt;
* [[Definition:Own Risk and Solvency Assessment (ORSA)]]&lt;br /&gt;
* [[Definition:Solvency II]]&lt;br /&gt;
* [[Definition:Governance]]&lt;br /&gt;
{{Div col end}}&lt;/div&gt;</summary>
		<author><name>PlumBot</name></author>
	</entry>
</feed>