Skip to main content
Category: Internal Audit and Assurance

Second Line

Also known as: Second Line of Defense, Second Line Functions
Simply put

In corporate governance, the second line refers to the risk management and compliance functions that oversee and support the parts of an organization that own and manage risk day to day. These functions do not run the business directly; instead, they set policies, monitor how risks are being handled, and help ensure the organization stays within acceptable limits. The provided evidence does not contain governance-specific source material, so this entry describes the concept as generally understood in governance practice rather than from the supplied sources.

Formal definition

Under the widely referenced 'three lines' model of governance and assurance, the second line comprises specialist risk management, compliance, and other oversight functions that provide expertise, monitoring, and challenge to first-line operational management, which owns and manages risk directly. Second-line functions typically design and maintain risk and control frameworks, monitor adherence to policies and risk appetite, and report to senior management and the board or its committees; they are generally distinct from the independent assurance provided by the third line (internal audit). The precise composition, mandate, and reporting lines of the second line vary by jurisdiction, sector, entity type, and the framework an organization adopts, and this description is educational rather than legal, audit, or compliance advice. Note that the evidence packet provided did not include governance-domain sources for this term, so no source-specific citations are made.

Why it matters

The second line matters because it provides a structured way for organizations to challenge and monitor how risk is actually being managed, without being the same people who own and run the business activities. When first-line operational management is left to police itself, blind spots and conflicts of interest can go unaddressed; the second line exists to bring specialist risk and compliance expertise to bear, to test whether policies are being followed, and to escalate concerns before they become failures. This separation supports the credibility of an organization's risk and control environment in the eyes of the board, regulators, and other stakeholders.

Boards and senior management generally rely on second-line functions to translate broad risk appetite into workable policies and to give an informed, ongoing view of whether the organization is operating within acceptable limits. Weak, under-resourced, or poorly positioned second-line functions can leave leadership without reliable, independent-minded challenge to the business, which undermines the quality of risk oversight even when a third line (internal audit) is present. Because the second line sits between day-to-day risk owners and independent assurance, its effectiveness often shapes how much confidence the board can place in the information it receives.

The strength of the second line depends heavily on its mandate, resourcing, and reporting lines, all of which vary by jurisdiction, sector, and entity type. This entry describes the concept as generally understood in governance practice; the evidence packet provided did not include governance-domain sources, so no source-specific claims, incidents, or figures are asserted here. This description is educational and not legal, audit, or compliance advice.

Who it's relevant to

Board members and risk or audit committee chairs
Board and committee members generally rely on second-line functions for a monitored, challenge-oriented view of how risk is being managed across the organization. Understanding the second line helps directors assess whether risk and compliance functions are adequately resourced, appropriately positioned, and able to escalate concerns, and helps them distinguish this oversight and monitoring role from the independent assurance the board separately expects from internal audit.
Chief risk officers and chief compliance officers
These executives typically lead second-line functions and are responsible for designing risk and control frameworks, setting and maintaining policies, monitoring adherence to risk appetite, and reporting to senior management and the board. A clear articulation of the second line's role supports their efforts to define their own mandate, clarify boundaries with first-line risk owners, and preserve their distinction from the third line.
Operational and business-line management (first line)
Managers who own and manage risk day to day interact with the second line as a source of policy, expertise, monitoring, and challenge. Understanding the distinction clarifies that primary accountability for managing risk remains with the first line, while the second line supports and tests that activity rather than assuming ownership of it.
Internal auditors (third line)
Internal audit provides independent assurance and often evaluates the design and operation of second-line functions. A precise understanding of the second line's remit helps auditors keep their independent assurance role distinct from the monitoring and challenge role performed by risk and compliance, avoiding overlap or gaps in coverage.
General counsel and legal teams
Legal functions frequently operate within or alongside the second line, contributing to policy setting, monitoring, and oversight of legal and regulatory risk. Clarity on where the second line sits supports appropriate role definition, particularly where mandates and reporting lines vary by jurisdiction, sector, and entity type.

Inside Second Line

Risk Management Function
Typically a dedicated function that helps design, coordinate, and monitor the enterprise risk management framework, advising management on risk identification, assessment, and treatment without owning the underlying risks themselves.
Compliance Function
Generally responsible for advising on and monitoring adherence to applicable laws, regulations, listing rules, and internal policies, and for maintaining frameworks that help the organization meet its legal and regulatory obligations, which vary by jurisdiction, sector, and entity type.
Oversight and Challenge Role
The second line typically provides oversight, guidance, and constructive challenge to the first line (operational management), which owns and manages risk directly, but does not itself carry primary accountability for day-to-day risk-taking decisions.
Policy and Framework Stewardship
Often owns the design and maintenance of risk and compliance policies, methodologies, and reporting standards, helping ensure consistency across the organization while management remains responsible for implementation.
Monitoring and Reporting
Generally monitors the operation of controls and risk exposures and reports to senior management and, in many structures, to relevant board committees, distinct from the independent assurance provided by the third line (typically internal audit).
Position Within the Three Lines Model
Under models such as the widely referenced three lines framework, the second line sits between operational management (first line) and independent assurance (third line); the model is a non-binding organizing concept rather than a universal legal requirement, and structures vary in practice.

Common questions

Answers to the questions practitioners most commonly ask about Second Line.

Is the second line responsible for owning and managing risk on a day-to-day basis?
Generally, no. Under the widely referenced three lines model, day-to-day ownership and management of risk typically sits with the first line, the operational management that owns the processes generating the risk. The second line usually provides oversight, guidance, frameworks, and challenge to how the first line manages risk, but ownership and accountability for the risk itself generally remains with management in the first line. Conflating the two blurs the accountability that the model is designed to clarify. The precise allocation of responsibilities can vary by entity, sector, and how an organization has structured its functions.
Does the second line provide independent assurance to the board in the same way internal audit does?
Not in the same sense. The second line, typically functions such as risk management and compliance, generally supports and monitors the management of risk and provides expertise, oversight, and challenge, but it is usually part of, or closely aligned with, management. Independent assurance to the board and audit committee is generally associated with the third line, most commonly internal audit, whose independence is a defining feature. Because second line functions may be involved in designing or advising on controls, they are typically not regarded as fully independent of the activities they monitor. The specific reporting lines and degree of independence can differ across organizations and frameworks.
How should an organization decide which activities belong in the second line versus the first?
This generally depends on the organization's structure, size, sector, and risk profile, and on where management chooses to locate oversight versus operational responsibility. A common approach is to assign activities that generate and directly manage risk to the first line, and activities that set frameworks, monitor, advise, and challenge to the second line. Where a single team both performs an activity and monitors it, the potential conflict typically needs to be identified and managed. There is no single mandated allocation; the appropriate design is a matter of judgment and should be documented so accountabilities are clear.
How can the second line maintain effective challenge of the first line without undermining collaboration?
Organizations often address this through clear terms of reference, defined reporting lines, and a mandate that supports the second line's ability to raise concerns. Effective challenge generally depends on the second line having sufficient standing, access to information, and appropriate reporting routes, sometimes including a route to a board committee. At the same time, many organizations emphasize a constructive working relationship so that the second line is engaged early rather than only after decisions are made. The balance struck is a matter of organizational design and culture, and practices vary.
What should be considered when structuring reporting lines for second line functions?
Considerations typically include to whom the head of a second line function reports administratively versus functionally, and whether there is access or a reporting route to a relevant board committee to support the function's ability to escalate. Organizations often weigh proximity to management, useful for influence and information, against the need to preserve the function's ability to provide objective oversight. The appropriate arrangement generally depends on the entity, applicable regulatory expectations for the sector, and internal governance choices. This entry is educational and not a substitute for tailored governance, legal, or regulatory advice.
How can an organization avoid gaps or duplication between the first, second, and third lines?
A common practice is to map roles and responsibilities across the lines so that it is clear who owns a risk, who oversees and challenges its management, and who provides independent assurance. Coordination mechanisms, such as shared risk taxonomies, aligned planning, and periodic dialogue among the functions, are often used to reduce both unaddressed gaps and unnecessary overlap. The extent of coordination and how it is governed generally depends on the organization's size, complexity, and structure, and should be designed to preserve, rather than compromise, the distinct roles of each line.

Common misconceptions

The second line owns and is accountable for managing the organization's risks.
In most applications of the three lines model, operational management (the first line) owns and manages risk directly. The second line typically advises, coordinates, monitors, and challenges, but accountability for risk-taking generally remains with the first line and, ultimately, senior management and the board for oversight.
The second line provides independent assurance, so a separate internal audit function is unnecessary.
Second line functions are generally not fully independent of management, since they help design and operate parts of the risk and control framework. Independent assurance is typically the role of the third line, commonly internal audit, whose independence is a distinct feature of the model.
Risk management and compliance are the same activity and can be combined without distinction.
Although both commonly sit in the second line, risk management and compliance are related but separate disciplines with different focuses. Combining them in one team does not erase the distinction between managing enterprise risk broadly and monitoring adherence to specific legal and regulatory obligations.

Best practices

Clearly document where accountability sits, distinguishing the first line's ownership of risk from the second line's advisory, monitoring, and challenge role, and from the third line's independent assurance.
Define and separate the risk management and compliance mandates within the second line, recognizing them as related but distinct disciplines rather than a single function.
Establish reporting lines to senior management and appropriate board committees that preserve the second line's ability to provide constructive challenge without assuming operational risk ownership.
Tailor the second line structure to the organization's jurisdiction, sector, and entity type rather than assuming a single model applies universally, since the three lines concept is an organizing framework, not a binding requirement.
Maintain clear boundaries between second line functions and independent assurance to avoid compromising the independence expected of the third line.
Periodically review the design and operating effectiveness of second line monitoring activities as distinct considerations, and treat guidance here as educational rather than legal, audit, or compliance advice.