Second Line
In corporate governance, the second line refers to the risk management and compliance functions that oversee and support the parts of an organization that own and manage risk day to day. These functions do not run the business directly; instead, they set policies, monitor how risks are being handled, and help ensure the organization stays within acceptable limits. The provided evidence does not contain governance-specific source material, so this entry describes the concept as generally understood in governance practice rather than from the supplied sources.
Under the widely referenced 'three lines' model of governance and assurance, the second line comprises specialist risk management, compliance, and other oversight functions that provide expertise, monitoring, and challenge to first-line operational management, which owns and manages risk directly. Second-line functions typically design and maintain risk and control frameworks, monitor adherence to policies and risk appetite, and report to senior management and the board or its committees; they are generally distinct from the independent assurance provided by the third line (internal audit). The precise composition, mandate, and reporting lines of the second line vary by jurisdiction, sector, entity type, and the framework an organization adopts, and this description is educational rather than legal, audit, or compliance advice. Note that the evidence packet provided did not include governance-domain sources for this term, so no source-specific citations are made.
Why it matters
The second line matters because it provides a structured way for organizations to challenge and monitor how risk is actually being managed, without being the same people who own and run the business activities. When first-line operational management is left to police itself, blind spots and conflicts of interest can go unaddressed; the second line exists to bring specialist risk and compliance expertise to bear, to test whether policies are being followed, and to escalate concerns before they become failures. This separation supports the credibility of an organization's risk and control environment in the eyes of the board, regulators, and other stakeholders.
Boards and senior management generally rely on second-line functions to translate broad risk appetite into workable policies and to give an informed, ongoing view of whether the organization is operating within acceptable limits. Weak, under-resourced, or poorly positioned second-line functions can leave leadership without reliable, independent-minded challenge to the business, which undermines the quality of risk oversight even when a third line (internal audit) is present. Because the second line sits between day-to-day risk owners and independent assurance, its effectiveness often shapes how much confidence the board can place in the information it receives.
The strength of the second line depends heavily on its mandate, resourcing, and reporting lines, all of which vary by jurisdiction, sector, and entity type. This entry describes the concept as generally understood in governance practice; the evidence packet provided did not include governance-domain sources, so no source-specific claims, incidents, or figures are asserted here. This description is educational and not legal, audit, or compliance advice.
Who it's relevant to
Inside Second Line
Common questions
Answers to the questions practitioners most commonly ask about Second Line.