Governance & GRC

Risk ownership and accountability under the three-lines model

Practical guidance on assigning risk ownership so that the three-lines model produces accountability rather than paperwork.

By Jonas Adam Mohamed Osman AbdelghafourPublished 10 December 2025Last reviewed 28 August 2026

Summary

The three-lines model is widely adopted and unevenly implemented. The most common failure is assigning ownership at the level of a risk category rather than at the level of a process, which leaves nobody accountable for the controls that actually operate.

Ownership at process level

Risk ownership is meaningful when it identifies a named accountable executive for a defined process, with authority over the resources, systems and people that operate the controls. Ownership at the level of "credit risk" or "operational risk" is a taxonomy, not an accountability.

The role of the second line

The second line sets the framework, challenges first-line assessments, and monitors aggregate exposures. It does not operate controls. Where the second line runs controls — a common drift under resource pressure — the model has collapsed into two lines and internal audit's assurance is compromised.

RCSAs as an accountability instrument

Risk and control self-assessments are only useful when the first line owns them. A second-line-authored RCSA is not an assessment; it is a checklist. RCSAs should identify inherent risk, control design, control effectiveness (tested), residual risk and remediation actions with owners and dates.

Escalation and issue management

Issues should escalate on defined thresholds, not on judgement calls. Aging, ownership and remediation status belong in standard committee reporting.

Limitations

Cultural readiness matters. Firms that promote the model without investing in first-line risk capability tend to produce shadow second-line teams inside the business, which recreate the original problem.

Related expertise

See Governance, Risk and Compliance.

Current compliance reading

About the author

Jonas Adam Mohamed Osman Abdelghafour is a Chief Risk Officer, Risk & Compliance Director and governance expert advising banks, insurers and regulated firms. See the professional profile, about and qualifications.

Frequently asked questions

What should risk leaders know about ownership at process level?

Risk ownership is meaningful when it identifies a named accountable executive for a defined process, with authority over the resources, systems and people that operate the controls. Ownership at the level of "credit risk" or "operational risk" is a taxonomy, not an accountability.

What should risk leaders know about the role of the second line?

The second line sets the framework, challenges first-line assessments, and monitors aggregate exposures. It does not operate controls. Where the second line runs controls — a common drift under resource pressure — the model has collapsed into two lines and internal audit's assurance is compromised.

What should risk leaders know about rCSAs as an accountability instrument?

Risk and control self-assessments are only useful when the first line owns them. A second-line-authored RCSA is not an assessment; it is a checklist. RCSAs should identify inherent risk, control design, control effectiveness (tested), residual risk and remediation actions with owners and dates.

What should risk leaders know about escalation and issue management?

Issues should escalate on defined thresholds, not on judgement calls. Aging, ownership and remediation status belong in standard committee reporting.

What should risk leaders know about about the author?

Jonas Adam Mohamed Osman Abdelghafour is a Chief Risk Officer, Risk & Compliance Director and governance expert advising banks, insurers and regulated firms. See the [professional profile](/jonas-adam-mohamed-osman-abdelghafour), [about](/about) and [qualifications](/qualifications).