Use this button to switch between dark and light mode.

Governance, Risk Management and Compliance Across the Three Lines of Defence

A counterparty can be assessed three times inside the same firm and produce three different answers. The business team runs a check at onboarding, the compliance function reviews an escalation two months later, and internal audit samples the file at year end, each working from its own sources. The three lines of defence model is designed to separate duties, not to fragment facts. This article maps governance, risk and compliance responsibilities to each line and describes how a shared intelligence layer keeps ownership where it belongs while every line works from the same underlying record.

Mapping GRC Responsibilities to the Three Lines

The model allocates responsibility by proximity to the risk. The first line is the business itself: relationship managers, procurement teams and operations staff who onboard customers, engage suppliers and execute transactions. They own the risk because they create it, and they carry out the compliance checks that sit inside those processes.

The second line comprises the risk and compliance functions. They set screening policy, define risk appetite, monitor exceptions and take escalations. In regulated firms this is where the role of the MLRO sits, alongside the specialists who apply deeper scrutiny when a case demands it. The second line does not own the customer relationship; it owns the control framework the first line operates within.

The third line is internal audit, which assures the board that the first two lines are doing what the operating model says they do. Audit tests decisions, not just policies: whether screening was performed, whether escalation criteria were applied, and whether outcomes were recorded.

The structure is sound. The failure mode is informational. When each line researches counterparties independently, the first line checks a free web source, the second line queries a subscription database and audit reconstructs events from correspondence, the firm produces three versions of the same fact base. Integrated GRC rarely fails because responsibilities blur; it fails because the evidence fragments. Duplicated research wastes analyst time. Contradictory research is worse, because it turns every escalation into a dispute about sources rather than a decision about risk.

First Line: Screening at the Point of Onboarding and Transacting

Business teams do not need investigative depth; they need a reliable answer inside the workflow they already run. At the point of onboarding or transacting, that means a fast entity screen covering sanctions, watchlists and adverse media, a risk assessment recorded against the counterparty, and a clear signal on whether to proceed, decline or escalate.

Nexis Diligence+™ supports this by letting the first line run consistent, policy-aligned checks without becoming compliance specialists. A relationship manager runs the same structured search every time, covering corporate records, beneficial ownership, sanctions lists and licensed news in a single pass. Adverse media screening draws on licensed sources rather than open web results, so an onboarding decision never rests on an unverifiable link. The considerations behind negative news screening for UK compliance teams apply from the first check, not only at escalation.

Two things separate this from an ad hoc search. First, the checks are configured to policy, so the first line applies the firm's risk appetite rather than its own judgement about what looks acceptable. A clean result proceeds; a hit against defined criteria escalates. Second, every check produces a dated, sourced record: what was searched, which sources were covered, what was found and what decision followed. The record is created as a by-product of doing the work, not as a separate documentation step.

That record is the handoff. When a case escalates, the second line receives the evidence, not a summary of it.

Second Line: Oversight and Escalations Without Re-Research

The second line's work starts where the first line's certainty ends. Escalations arrive when screening produces a hit, when ownership cannot be resolved, or when a counterparty falls outside appetite. In many firms the reviewer's first act is to repeat the research from scratch, partly from habit and partly because the first line's evidence is unavailable or untrusted.

A shared record changes the escalation workflow. The reviewer opens the case and sees exactly what the first line saw: the search parameters, the sources covered, the items flagged and the rationale recorded. Nothing needs to be requested, forwarded or reconciled. The question shifts from establishing the facts to weighing them, which is the judgement the second line exists to apply. Where escalation warrants enhanced scrutiny, the reviewer extends the same file, adding historical adverse coverage, deeper ownership analysis and jurisdictional context, rather than opening a parallel one.

Oversight improves for the same reason. Screening policy means little if the second line cannot see how it is applied. With first line activity captured in one place, compliance monitors exceptions as they occur, spots patterns across business units and adjusts thresholds with evidence of their effect. Reporting on AML compliance draws on the same records, so regulatory obligations are evidenced from live workflow data rather than assembled retrospectively. The approaches described in solutions for regulatory risk management depend on precisely this visibility.

Version conflicts are what stall escalations. When both lines cite the same sourced record, that category of delay disappears.

Third Line: Auditing Decisions Against the Original Evidence

Internal audit does not re-run the firm's due diligence; it tests whether the decisions made were justified by the evidence available at the time. That distinction only holds if the evidence still exists in the form the decision-makers saw it.

A complete record lets audit verify four things about any sampled decision: what was searched, what was found, who decided and on what basis. An auditor sampling a supplier onboarding can open the original screen, confirm the sources covered matched policy, see the adverse item that was flagged and read the recorded rationale for proceeding. The test is direct, against the control framework, and it produces findings about controls rather than arguments about facts.

The alternative is reconstruction. Where evidence is scattered across inboxes, spreadsheets and screenshots, audit spends its budget assembling a picture of what probably happened, and its findings inherit the uncertainty. Reconstructed evidence also ages badly: a web page cited at onboarding may have changed or disappeared by the time audit reads the file, leaving no way to test the decision at all. A dated, sourced record removes both problems. Audit coverage widens because each sample takes hours rather than days, and the assurance given to the board rests on what was actually seen.

Running All Three Lines on One Intelligence Layer

Brought together, the model runs on one platform providing entity research, adverse media screening and ongoing monitoring, with each line drawing what its role requires. The first line takes embedded screening and a recorded outcome. The second line takes oversight dashboards, escalation files and the ability to extend research without repeating it. The third line takes the archive: complete, dated and sourced. The same layer extends to third-party risk management, where supplier and intermediary decisions follow the identical pattern.

Consistent source coverage has a precise consequence: the three lines can disagree on judgement, but never on facts. A dispute about whether a counterparty's adverse history sits within appetite is a productive disagreement between the first and second line, and the model is designed to host it. A dispute about whether the adverse history exists is not; it is a symptom of fragmented sourcing, and it consumes the time the model was meant to save. Reviews of whether AI can ease compliance officers' workloads reach the same conclusion from another direction: automation helps most when it operates over one governed evidence base.

Far from blurring the lines, a shared layer sharpens them. When the facts are common, accountability for each decision is unambiguous.

See How Nexis Diligence+ Supports All Three Lines

Final Thoughts

The three lines of defence model works when ownership is clear and the underlying facts are shared. Those two conditions are often treated as a trade-off, as though separation of duties requires separation of evidence. The opposite is true. When business teams, compliance functions and internal audit work from the same dated, sourced record, each line is freed to do its actual job: the first to decide, the second to oversee, the third to assure. The duplication disappears, the escalations move, and the audit trail exists before anyone asks for it. For GRC leads structuring roles across the three lines, the practical question is not which team owns which check, but whether all three are reading from the same facts. Platforms such as Nexis Diligence+ provide that common layer without collapsing the distinctions between the lines. The facts stay consistent; the accountability stays exactly where the model puts it.