Quick Summary: What This Guide Covers
This guide explains the three lines of defence in AML. The 3 lines of defence model is the standard way of dividing responsibility for financial crime risk, and it is worth understanding properly before you build anything around it. You will learn what the first line (your customer-facing staff), the second line (your compliance officer and risk function) and the third line (independent audit) are each responsible for, and where the boundaries between them sit.
It includes a task-by-task responsibility table covering onboarding through to reporting, an explanation of where the board fits in, what changed when the model was renamed in 2020, how small businesses can run three lines without three departments, what evidence UAE supervisors ask for when they test each line, and the weaknesses that cause the model to fail in practice.
There is a practical setup checklist at the end, plus answers to the questions people most often ask.
What Are the Three Lines of Defence in AML?
The three lines of defence in AML is a way of dividing responsibility for financial crime risk across three separate groups. The first line is the staff who deal with customers day to day. The second line is the compliance function that sets the rules and makes the judgement calls. The third line is an independent audit that checks whether the first two are working.
That is the whole model. Everything else is detail.
The three lines in one sentence each
- First line: the people who deal with customers. They collect the information, notice when something looks wrong, and escalate it. They do not decide what happens next.
- Second line: compliance and risk oversight. Your compliance officer or MLRO owns the policy, reviews what the first line escalates, and decides whether a report goes to the authorities.
- Third line: independent audit. Someone with no stake in the outcome tests whether the first two lines did their jobs, and reports what they find to the owners or the board.
Why it is called a “line of defence”
The idea is layered protection. The 3 lines of defence against money laundering work in sequence: if a risk slips past the first group, the second should catch it, and if both miss it, the third should find the gap when it reviews the work afterwards.
That layering is the point. A single control, however good, eventually fails. Three independent layers fail far less often, because they fail for different reasons.
Is it “defence” or “defence”?
Both spellings refer to the same model. Searches for the “three lines of defence” return the same framework as searches for the three lines of defence – “defence” is the British spelling used across most UAE and Commonwealth guidance, and “defence” is the American form. You will also see the framework called the 3 lines of defence model or shortened to 3LoD. Use whichever spelling your own policy documents already use and stay consistent.
Why the Three Lines of Defence Model Matters for AML Compliance
Most compliance failures are not caused by someone deciding to break the rules. They are caused by nobody being sure whose job it was.
A relationship manager assumes compliance will catch the odd transaction. Compliance assumes the relationship manager would have said something if the customer seemed strange. Nobody is being careless. The responsibility simply never landed anywhere. The three lines of defence model exists to stop that from happening, by writing down who owns what before anything goes wrong.
What happens when nobody owns the risk
Consider a corporate service provider onboarding a new client. The paperwork arrives incomplete. The onboarding staff accept it because the introducer is a long-standing contact and the client is in a hurry. Nobody flags it, because nobody has been told that incomplete files must be flagged. Eight months later the client’s structure turns up in an investigation, and the firm cannot show a single record of anyone questioning anything.
Nothing dramatic happened at any single point. That is precisely what makes it dangerous.
How the model supports a risk-based approach
UAE law requires regulated entities to identify, understand and manage their own financial crime risks in a way that is proportionate to the nature and size of their business. A risk-based approach only works if someone is accountable for acting on what the risk assessment says. The three lines give each finding an owner: the first line applies the controls, the second line designs and monitors them, the third line tests whether they held up.
What UAE regulators expect to see
Supervisors are not looking for a diagram. They look for three things: documented internal policies and procedures approved by senior management, a compliance officer appointed at management level with genuine independence in decision-making, and an independent audit function that tests whether those policies and controls are effective. Those requirements sit in Article 21 of Cabinet Resolution No. 134 of 2025, and between them they describe all three lines of defence without ever using the phrase.
In other words, the model is not a management theory borrowed from banking. In the UAE it is close to a description of what the AML/CFT compliance framework is already required to contain.
The First Line of Defence: Your Frontline Team
The first line of defence is where financial crime risk enters your business. Every customer relationship, every transaction, every document begins with someone in this group, which is why the first of the three lines of defence carries more practical weight than its position in the sequence suggests.
Who sits in the first line
More people than most firms assume. The obvious ones are relationship managers, sales staff, brokers, agents, branch teams and onboarding officers. But the first line also includes anyone who handles cash, processes payments, prepares documents, or has direct contact with customers and suppliers. In a property firm that includes the agent showing the unit. In a precious metal business, it includes whoever is behind the counter.
If a person can see a customer’s behaviour before compliance does, they are in the first line.
What the first line is responsible for
Collecting and verifying customer information. This is where know your customer work happens in practice. The first line gathers identity documents, ownership information and the details needed for customer due diligence, and confirms that what they have been given is genuine and complete.
Understanding who is really behind the customer. Corporate structures are the most common place for first line work to go thin. Establishing beneficial ownership properly, rather than accepting the name on the front of the file, is a first-line task.
Spotting red flags. Unusual payment routes, reluctance to explain the source of funds, transactions that make no commercial sense, structures that seem designed to obscure something. The first line does not have to prove anything. It only must notice.
Following the policy rather than improvising. A well-written procedure exists so that staff do not have to make judgement calls under pressure. Where the policy says escalate, the answer is escalated.
Escalating to the compliance officer. Internally, promptly, and in writing.
Keeping records. What was collected, when, from whom, and what was done with it.
What the first line is not responsible for
This is the distinction that causes the most confusion, so it is worth stating plainly.
The first line does not decide whether something is suspicious. It does not decide whether a report is filed. It does not investigate. Those decisions belong to the second line, and for good reason, they require independence, context across the whole customer base, and access to information a single staff member does not have.
The first line’s job ends at a well-documented escalation. That is not a lesser role. An escalation that never happens cannot be fixed by anyone further down the chain.
One more point worth correcting, because it appears in a surprising number of training materials: the risk management function is not the first line. Risk management sits in the second line. The first line is the business itself.
Why training makes or breaks the first line
Staff cannot escalate what they cannot recognise. This is why the law does not treat training as optional, Article 21 of Cabinet Resolution No. 134 of 2025 requires periodic programmes and workshops to build the capabilities of both the compliance function and other relevant employees, and the same article requires screening procedures to ensure staff are fit and proper before they are appointed.
Effective AML training is role specific. A cashier and a relationship manager face completely different risks and need completely different examples. Generic annual training that covers “what money laundering is” produces staff who can define the stages of money laundering and still miss the customer in front of them.
Common first-line failures
- Due diligence treated as a document-collection exercise rather than an assessment
- Files accepted as complete when they are not, because the client is valuable or impatient
- Staff who notice something but say nothing, for fear of losing a relationship
- Tipping off the customer while asking follow-up questions
- No record that anything was ever questioned
The Second Line of Defence: Compliance and Risk Management
If the first line is where risk enters, the second line of defence is where it gets assessed, challenged and decided upon. This is the layer most people picture when they think about the three lines of defence, and it is also the layer that most often exists in name only.
Who sits in the second line
The compliance officer or MLRO sits at the centre of this line. Around them sit the compliance team, the risk management function, and supporting functions such as HR and IT where they own controls that matter for financial crime staff vetting, system access, data quality.
UAE law uses the term “Compliance Officer” and requires the appointment to be made at management level. In practice many firms use the title MLRO, or Money Laundering Reporting Officer. The label matters less than the authority attached to it.
What the second line is responsible for
Writing and maintaining the policy. The AML policies and procedures than the first line follows are drafted here, approved by senior management, and updated as the business and the law change.
Owning the risk methodology. How customers are scored, what makes a relationship high risk, when enhanced measures apply. This flows from the business-wide risk assessment down into customer risk assessment at the individual level.
Running screening and monitoring. Name screening, sanctions screening against the relevant lists including the local terrorist list, and transaction monitoring systems all sit under second-line ownership including the uncomfortable work of tuning them, so they produce usable alerts.
Handling high-risk relationships. PEP and high-risk customer management decisions, including approval to take on or continue such a relationship, belong here.
Reviewing escalations and deciding on reporting. The compliance officer receives what the first line escalates, examines it, and decides whether to notify the authorities or to keep the matter internally with the reasons recorded. Where suspicion exists, Federal Decree-Law No. 10 of 2025 requires the report to go to the Financial Intelligence Unit without delay. The mechanics of STR and goAML reporting sit with this line, not the first.
Reporting upward. Periodic reports go directly to senior management, along with what management decided to do about them.
Training the first line. Developing, delivering and documenting it.
The two jobs of the second line: support and challenge
The second line must do two things that pull in opposite directions. It advises the business helping the first line apply the rules sensibly to real situations. And it challenges the business pushing back when the first line wants to proceed with something it should not.
Firms that get this wrong usually collapse the second job into the first. Compliance becomes a helpdesk: pleasant, responsive, and structurally unable to say no. The advice function survives. The challenge function quietly disappears.
Both jobs must be visible. If your compliance function has never blocked anything, that is not evidence of a low-risk customer base.
Why the second line must be independent
Independence is not a courtesy here. It is a requirement the compliance officer must have independence in decision-making, along with appropriate competence and experience.
The practical test is simple: can this person refuse a deal that the business wants? If the compliance officer reports to the head of sales, or holds a revenue target, or is the owner’s relative who also runs operations, then the answer is no, regardless of what the org chart says. And a second line that cannot refuse anything is not a line of defence. It is documentation.
Common second-line failures
- A compliance officer with the title but no authority, and no route to senior management
- The role held alongside a commercial position, creating a direct conflict
- Alerts closed in bulk with no recorded rationale, often a symptom of alert fatigue
- Screening systems that were configured once at go-live and never tuned since
- Policies that describe a business the firm no longer is
The Third Line of Defence: Independent Audit
The third line of defence answers a question the first two cannot answer about themselves: is any of this working? Without it, the three lines of defence collapse into two lines and a hopeful assumption.
Who sits in the third line
Internal audit, where a firm is large enough to have one. Where it is not, an external independent reviewer. Article 21 of Cabinet Resolution No. 134 of 2025 requires an independent audit function to test the effectiveness and adequacy of internal policies, controls and procedures – it does not require that function to be an in-house department.
Outsourcing the third line is normal, accepted, and for most UAE firms the only way to achieve real independence.
What an independent AML audit looks at
Whether the policy matches the actual business. A policy written for a firm with ten local clients does not fit the same firm three years later with cross-border customers and a new product line.
Whether controls are followed in practice. This is the heart of an AML internal audit. Not whether a procedure exists, but whether sampled files show it was applied. Documentation and behaviour diverge quietly, and only testing reveals the gap.
Whether screening and monitoring are configured sensibly. Thresholds, match rules, scenario logic, and whether anyone can explain why they were set that way.
Whether reports were filed when they should have been. Including the harder question: where there matters closed internally that a reasonable reviewer would have escalated?
Whether training reached the right people. Attendance records, content relevance, and whether staff can demonstrate they understood it.
Whether records hold up. Retention requirements run to at least five years, and records must be organised well enough to reconstruct individual transactions on request. Audit tests whether they genuinely are.
Why the third line cannot report to the second
An auditor who reports to the person whose work they are reviewing is not providing assurance. They are providing a second opinion from an interested party.
Third-line findings go to the board, the owners, or whoever sits above management. In a small firm that means the owner reads the report directly. That is uncomfortable by design the discomfort is the mechanism. A broader internal audit function operates on the same principle across other risk areas.
How often the third line should review
Risk-based, but annually is the working default for most regulated entities, with additional reviews triggered by significant change: a new product, a new market, an acquisition, a regulatory shift, or a serious incident.
What happens to audit findings
This is the step almost everyone skips, and it is where inspections most often go badly.
A finding needs a named owner, a deadline, and evidence that it was closed. An audit report that identifies eight weaknesses and is followed by no visible action is worse than no audit at all, because it proves the firm knew. Findings register that show the same open items year after year are among the clearest signals a supervisor can find that governance is not working.
Common third-line failures
- The audit performed by the person who wrote the policy
- A report that describes the framework rather than testing it
- Findings with no owner and no closure date
- Reviews that happen only when a licence renewal or inspection is approaching
How the Three Lines Work Together: A Simple Responsibility Table
Descriptions of the model tend to stay abstract. Here are the three lines of defence expressed instead as ownership of actual tasks, which is how they need to be written into your own procedures.
| Activity | First Line | Second Line | Third Line |
|---|---|---|---|
| Customer onboarding and KYC | Performs | Sets standards; reviews quality | Tests samples |
| Sanctions and PEP screening | Runs at onboarding; escalates hits | Owns the system; adjudicates matches | Tests configuration and outcomes |
| Customer risk rating | Applies the methodology | Designs the methodology | Tests whether ratings are consistent |
| Enhanced due diligence | Gathers additional information | Decides scope; approves the relationship | Tests whether EDD was applied where required |
| Ongoing transaction monitoring | Observes customer behaviour | Runs systems; reviews alerts | Tests alert handling and rationale |
| Investigating an alert | Provides context on request | Investigates and concludes | Tests the quality of conclusions |
| Deciding to file a report | Escalates concerns | Decides | Tests whether decisions were reasonable |
| Filing with the FIU | No role | Files | Tests timeliness and completeness |
| Record-keeping | Creates records | Sets retention rules | Tests retrievability |
| Staff training | Attends and applies | Designs and delivers | Tests reach and effectiveness |
| Business-wide risk assessment | Provides input on the business | Prepares and maintains | Tests whether it reflects reality |
| Testing whether all of the above worked | No role | No role | Owns |
Where the first and second line overlap
Ongoing monitoring is the genuine grey area, and it is where most people get the model wrong.
The honest answer is that ongoing monitoring is shared. The first line sees behaviour a system cannot: the client who suddenly changes how they pay, the explanation that does not match last months. The second line runs the monitoring systems, reviews alerts and makes the call. Neither line owns it alone and treating it as purely a compliance function is how firms end up with monitoring that only sees what the software was configured to look for.
How information should flow between the lines
Escalation runs upward. Feedback must run back down, and this is the part almost every framework omits.
If a staff member escalates a concern and never hears what happened, they learn that escalation is a formality. Do that three or four times and escalations stop arriving. The second line does not have to disclose the outcome of a report confidentiality rules prevent that, but it can acknowledge receipt, confirm the escalation was correct, and coach on what to look for next time. Without that loop, the first line goes quiet, and a quiet first line looks identical to a clean customer base right up until it isn’t.
Where the Board and Senior Management Fit In
Senior management is not one of the three lines of defence. It sits above them, and it is accountable for all three.
The board is not a fourth line
The governing body’s role is oversight, not execution. It approves the internal policies, resources the compliance function, receives the compliance officer’s reports, and decides what to do about them. It does not run controls.
What senior management is accountable for
Approving the policies. Appointing a compliance officer who is genuinely competent and genuinely independent. Giving that person enough budget, staff and system access to do the work. Reading the periodic reports and recording decisions on them. Arranging independent testing and acting on the findings.
In an owner-managed business, all this lands on one or two people, and it cannot be delegated away. Sound governance and compliance arrangements are what turn three separate functions into a working system rather than three parallel silos.
Why “tone from the top” is more than a phrase
Culture is set by exceptions, not by policy documents.
Override the compliance officer once, visibly, for a client who matters commercially, and the entire first line learns something durable: the rules apply until they are inconvenient. No amount of training reverses that lesson. The three lines of defence rely on people believing the structure is real, and leadership behaviour is the only evidence they have.
Three Lines of Defence vs the Three Lines Model: What Changed in 2020
Here is something almost no AML article mentions. In July 2020 the Institute of Internal Auditors updated the framework and dropped the word “defence” from the name. It is now formally called the Three Lines Model.
Why the word “defence” was dropped
The reasoning was that “defence” encouraged the wrong instincts. It framed risk as something purely to be repelled, and it encouraged the lines to operate as separate fortifications rather than as functions that talk to each other. The updated model emphasises collaboration, alignment and the role of the governing body, and treats risk management as something that supports the organisation’s objectives rather than only protecting against loss.
What changed, and what didn’t
The underlying division of responsibility did not change. Business functions still own their risks, compliance and risk still oversee and challenge, internal audit still provides independent assurance. What changed is emphasis: less siloed defence, more coordination, and a clearer articulation of where the board sits.
Which term should you use in your own policy?
Whichever your regulator, your auditors and your existing documents already use. “Three lines of defence” remains the dominant phrase across AML guidance and supervisory language, and there is no advantage in unilaterally renaming things in your policy manual. Just be internally consistent.
Is there a fourth line of defence?
Some frameworks propose one, usually external auditors and regulators, on the basis that they provide assurance from outside the organisation entirely. It is a reasonable observation but not the standard model, and no UAE requirement is built around it. Treat external audit and supervision as important context rather than as a line you are responsible for operating.
Lines of Defence vs Pillars of AML: What’s the Difference?
These two get mixed up constantly, and the distinction is genuinely simple.
Pillars describe what your programme contains. Depending on which framework you read, an AML programme is described as having three, four, five or six pillars risk assessment, internal controls, a designated compliance officer, training, independent testing, and sometimes customer due diligence as a separate pillar. The count varies because the frameworks vary. There is no single correct number.
Lines of defence describe who owns each part. The model says nothing about what controls you need. It says who is accountable for operating them, who oversees them, and who tests them.
They fit together directly. Training is a pillar; the second line designs it and the first line receives it. Independent testing is a pillar; the third line performs it. If you are building a programme, the pillars tell you what to build and the three lines of defence tell you who to hand each piece to.
How the Three Lines Apply to Different Types of Business
The model is the same everywhere. Its depth scales with size and risk.
Banks and financial institutions. The fullest version: dedicated first-line control teams, a large compliance function, and an in-house internal audit department. This is where the three lines of defence in banking originated, and where most published material about the model is still aimed.
DNFBPs. Real estate agents, dealers in precious metals and stones, accountants and auditors, lawyers and legal professionals and corporate service providers all fall within scope. The obligations in the AML laws for DNFBPs are real, but the structure is usually much flatter often one compliance officer and an outsourced audit.
Virtual asset service providers. VASPs carry the same three lines with additional technical demands: wallet screening, blockchain analytics and travel rule controls all sit in the first and second lines, and the third line needs enough technical understanding to test them meaningfully.
Insurance, asset management and other regulated sectors. Firms in the insurance sector and asset managers and investment firms tend to have strong risk functions already. Their common weakness is a second line built for prudential and market risk, with financial crime bolted on as an afterthought.
Mainland and free zone entities. Supervisory expectations differ depending on which authority licenses you, and free zone regulators often examine governance evidence in more detail than firms anticipate. The underlying requirement for three lines of defence does not change with the licence.
Can a Small Business Have Three Lines of Defence?
This is the objection that stops most smaller firms from building anything at all: we have eleven people; we do not have three departments.
Fair. But the three lines of defence ask you to separate roles, not to hire three teams.
You separate roles, not necessarily people
In a small firm, one person can hold first-line duties, and another can hold second-line duties, even if both also do other things. What matters is that the two sets of duties are not held by the same person for the same transaction, and that the second-line role has real authority behind it.
What one person can and cannot do
Workable: the office manager handles onboarding paperwork while a director acts as compliance officer and reviews the files. Different people, different roles, documented.
Not workable: the person who onboards the client is also the only person who reviews that file. There is no second look, so there is no second line.
Not workable: the compliance officer audits their own compliance function. Independence cannot be self-declared.
Why the third line usually must be outsourced
In a firm of fifteen people, there is no one left who is independent of the first two lines. Every candidate either helped build the framework or reports to someone who did. That is not a failure of the firm; it is arithmetic. Bringing in an external reviewer is the standard and expected solution, and supervisors treat it as such.
A workable structure for a small team
For a ten-person DNFBP: client-facing staff and administration form the first line, collecting documents and escalating anything unusual. One director is appointed compliance officer at management level, owns the policy and risk assessment, reviews every escalation, and reports to the owners in writing each quarter. An external firm conducts an annual independent review and reports to the owners directly.
Three lines, three people deep in places, and entirely defensible.
How Regulators Test Your Three Lines of Defence
Supervisors do not ask whether you have three lines of defence. They ask you to prove each one functioned. The difference matters, because the answer is always documents.
What proves the first line is working
Completed due diligence files with verification evidence, not just collected documents. Training attendance records tied to specific roles. Internal escalations that were raised a firm with zero escalations across two years has either an extraordinary customer base or a silent first line.
What proves the second line is working
Alert and escalation records with the reasoning written down, including for matters closed without a report. An updated risk assessment with a visible revision history. Periodic reports to senior management, with management’s decisions recorded against them. Evidence that the compliance officer’s independence is structural and not just asserted.
What proves the third line is working
A documented audit scope and methodology. Findings register with owners and dates. Evidence that findings were closed, with the supporting proof attached. Reports that went to the board rather than to the compliance function.
The documents to have ready
- Board-approved AML policies and procedures, with version history
- The business-wide risk assessment and its supporting workings
- The compliance officer’s appointment letter and reporting line
- Periodic compliance reports to senior management, with recorded decisions
- Training plan, materials and attendance logs
- A sample of completed customer files across risk categories
- Screening and monitoring configuration documentation, including tuning rationale
- The most recent independent audit report and the findings register
- Records demonstrating retention and retrievability
Firms that maintain this continuously find inspections uneventful. Firms that assemble it in the two weeks before one rarely does, which is the entire premise of regulatory inspection readiness work.
Common Weaknesses in the Three Lines of Defence Model
The model itself is sound. Implementations of the three lines of defence frequently are not. These are the failures that recur.
Roles that exist on paper only. Everything is documented; nothing is practised. The clearest tell is asking three staff members what they would do if a customer’s payments suddenly came from a different jurisdiction and getting three different answers.
The “not my job” reflex. The most-cited criticism of the model, and the reason “defence” was eventually dropped from its name. Lines treat their boundaries as walls. The first line stops noticing because monitoring is compliance’s problem. Compliance stops asking the business anything because it has systems. Risks land in the gap between them.
A compliance officer without real authority. Appointed at the wrong level, reporting to the wrong person, holding a commercial role alongside the compliance one, or with no path to senior management.
Policies that were never updated. The UAE AML framework was substantially rewritten in 2025. Firms still operating on procedures drafted under the previous regime are not only out of date, but they are also following instructions that reference instruments that no longer exist.
Weak training. Annual, generic, and unrelated to what staff handle.
Manual tools doing work they cannot do. Spreadsheets used for transaction monitoring. Screening done by eye against a downloaded list. These do not scale, and they leave no reliable audit trail.
Audit findings that never close. Discussed above, and worth repeating: an open finding from two years ago is evidence of a governance failure, not a scheduling problem.
No feedback loop. Escalations go up and nothing comes back, so the first line stops escalating.
How Technology Supports All Three Lines
Technology does not replace a line of defence. It changes what each of the three lines of defence spends its time on.
The first line gets faster verification, cleaner onboarding workflows, and screening that runs at the point of contact rather than days later.
The second line gets automated monitoring across the whole customer base, risk scoring that updates itself, and case management that records decisions as they are made rather than reconstructing them afterwards. Choosing well matters here, which is why deliberate AML software selection is worth more than it appears the wrong system creates work for years. Our guide on how to choose AML software covers the evaluation in detail.
The third line gets something more valuable than efficiency: audit trails. When every alert decision, threshold change and approval is logged, audit can test what happened rather than asking people to recall it.
Where technology creates new risk
Automation introduces obligations of its own. UAE law requires firms to assess the risks arising from new technologies and new delivery mechanisms before launching or using them, and to take measures to manage those risks. In practice that means someone must be able to explain who configured the system, who approved the thresholds, and on what basis. The growing use of AI in AML compliance sharpens this model nobody can explain is difficult to defend in an inspection, however well it performs. And a system that produces thousands of alerts nobody reviews is not a control. It is a record of everything you failed to look at.
How to Set Up the Three Lines of Defence: A Practical Checklist
Building the three lines of defence from scratch is less daunting than it sounds. Work through these steps in order.
- Map who currently does what. Write down every AML-related task and the name of the person doing it. The gaps and the overlaps will be obvious immediately.
- Assess the risks your business faces. Customers, products, geographies, delivery channels. Document it and keep the workings.
- Appoint a compliance officer at management level with independence in decision-making and a direct reporting line to senior management.
- Document the policy and the escalation route and get senior management to approve it.
- Train each line on its own responsibilities, not on money laundering in general.
- Set up the internal controls that turn the policy into daily practice and make sure someone owns each one.
- Arrange independent testing. Externally, if you cannot achieve genuine independence in-house.
- Fix what testing finds, with named owners and closure dates.
- Review at least annually, and immediately whenever the business, the customer base or the law changes.
Signs your three lines need attention
- No internal escalations have been raised in the past twelve months
- Your compliance officer also carries revenue responsibility
- Nobody can explain why your screening thresholds are set where they are
- Your last independent review was more than a year ago, or has never happened
- Findings from the last review are still open
- Your policy still refers to the pre-2025 AML framework
- Staff describe compliance as “the department that slows things down”
How GRC Advisors Strengthens All Three Lines
Most firms we work with do not need the three lines of defence explained to them. They need to know which of their three lines will not survive contact with a supervisor, and what to do about it before that happens.
GRC services is a UAE-based governance, risk and compliance consultancy working with firms regulated by the Central Bank of the UAE, VARA, the CMA, ADGM FSRA, DIFC DFSA, and federal authorities including the Ministry of Economy and Tourism. Our work reflects how these frameworks are examined locally, during inspections, licensing and remediation, rather than how they read on paper.
Frequently Asked Questions
What are the three lines of defence in AML?
They are the three groups that share responsibility for financial crime risk: frontline staff who deal with customers, the compliance and risk function that oversees them, and an independent audit function that tests whether the first two are working. Each layer is meant to catch what the previous one missed.
What is the first line of defence in AML?
Your customer-facing staff. They collect and verify customer information, notice unusual behaviour, follow the policy, escalate concerns to the compliance officer, and keep records of what they did.
What is the second line of defence?
The compliance officer or MLRO, together with the risk and compliance function. They write the policy, own the risk methodology, run screening and monitoring, review what the first line escalates, and decide whether a report goes to the authorities.
What is the third line of defence?
Independent audit. It tests whether the first and second lines work, identifies gaps, and reports its findings to the board or the business owners rather than to management.
Under the three lines of defence model, which line is responsible for independent assurance?
The third line. Independent assurance requires a reviewer with no involvement in designing or operating the controls being tested, which is why the third line reports above management rather than into it.
Who conducts ongoing monitoring?
Both the first and second line, as applicable. The first line observes customer behaviour directly; the second line runs the monitoring systems, reviews alerts and decides what they mean. Treating it as a compliance-only task is a common and costly mistake.
Is the risk management function the first or second line of defence?
The second. Risk management provides oversight, expertise and challenge. The first line is the business itself the people carrying out customer-facing activity.
Which group advises and challenges the first line of defence?
The second line. It supports the business by helping apply the rules to real situations and challenges the business by pushing back when it should not proceed. Both functions must be visible.
What is the difference between the first and second line of defence?
The first line does the work and owns the risk in daily operations. The second line sets the standards for that work, oversees it, and makes the judgement calls the first line is not permitted to make.
Is there a fourth line of defence?
Some frameworks add external auditors and regulators as a fourth line. It is a defensible way to think about external assurance, but it is not the standard model, and no UAE requirement is built around it.
What is the difference between the three lines of defence and the Three Lines Model?
The Institute of Internal Auditors renamed the framework in 2020, dropping “defence” to discourage siloed thinking and to emphasise collaboration and the governing body’s role. The division of responsibility is unchanged. “Three lines of defence” remains the more widely used term in AML.
How many pillars does an AML programme have?
It depends on the framework — three, four, five or six, depending on which source you read. Pillars describe the components of your programme, such as risk assessment, controls, a compliance officer, training and independent testing. Lines of defence describe who owns each component.
Do small businesses need three lines of defence?
Yes, but scaled. You separate roles rather than build departments, and the third line comes from outside because genuine independence is not achievable internally in a small team.
Can the third line of defence be outsourced?
Yes, and for most UAE firms it should be. The requirement is for an independent audit function, not an in-house audit department.
What happens if one line of defence fails?
The next layer should catch it, which is the entire purpose of the design. Serious incidents almost always involve two or three lines failing at once, usually because the same underlying weakness affected all of them.
Do the three lines of defence apply to DNFBPs and VASPs, or only to banks?
To all regulated entities. The requirements for internal controls, a compliance officer and independent audit apply across financial institutions, DNFBPs and virtual asset service providers alike. Only the depth scales with size and risk.