Summary
The three-lines model is widely adopted and unevenly implemented. The most common failure is assigning ownership at the level of a risk category rather than at the level of a process, which leaves nobody accountable for the controls that actually operate.
Ownership at process level
Risk ownership is meaningful when it identifies a named accountable executive for a defined process, with authority over the resources, systems and people that operate the controls. Ownership at the level of "credit risk" or "operational risk" is a taxonomy, not an accountability.
The role of the second line
The second line sets the framework, challenges first-line assessments, and monitors aggregate exposures. It does not operate controls. Where the second line runs controls — a common drift under resource pressure — the model has collapsed into two lines and internal audit's assurance is compromised.
RCSAs as an accountability instrument
Risk and control self-assessments are only useful when the first line owns them. A second-line-authored RCSA is not an assessment; it is a checklist. RCSAs should identify inherent risk, control design, control effectiveness (tested), residual risk and remediation actions with owners and dates.
Escalation and issue management
Issues should escalate on defined thresholds, not on judgement calls. Aging, ownership and remediation status belong in standard committee reporting.
Limitations
Cultural readiness matters. Firms that promote the model without investing in first-line risk capability tend to produce shadow second-line teams inside the business, which recreate the original problem.
Related expertise
See Governance, Risk and Compliance.
Current compliance reading
About the author
Jonas Adam Mohamed Osman Abdelghafour is a Chief Risk Officer, Risk & Compliance Director and governance expert advising banks, insurers and regulated firms. See the professional profile, about and qualifications.
Frequently asked questions
What should risk leaders know about ownership at process level?
Risk ownership is meaningful when it identifies a named accountable executive for a defined process, with authority over the resources, systems and people that operate the controls. Ownership at the level of "credit risk" or "operational risk" is a taxonomy, not an accountability.
What should risk leaders know about the role of the second line?
The second line sets the framework, challenges first-line assessments, and monitors aggregate exposures. It does not operate controls. Where the second line runs controls — a common drift under resource pressure — the model has collapsed into two lines and internal audit's assurance is compromised.
What should risk leaders know about rCSAs as an accountability instrument?
Risk and control self-assessments are only useful when the first line owns them. A second-line-authored RCSA is not an assessment; it is a checklist. RCSAs should identify inherent risk, control design, control effectiveness (tested), residual risk and remediation actions with owners and dates.
What should risk leaders know about escalation and issue management?
Issues should escalate on defined thresholds, not on judgement calls. Aging, ownership and remediation status belong in standard committee reporting.
What should risk leaders know about about the author?
Jonas Adam Mohamed Osman Abdelghafour is a Chief Risk Officer, Risk & Compliance Director and governance expert advising banks, insurers and regulated firms. See the [professional profile](/jonas-adam-mohamed-osman-abdelghafour), [about](/about) and [qualifications](/qualifications).