Three Lines of Defence for AI

Created: 2026-05-17 Updated: 2026-09-17 Source count: 9

Updated 2026-09-17 based on S-2026-09-15-workiva-agent-studio-audit-testing (daily AI-governance vendor-intelligence scan) — vendor agents are moving into third-line evidence collection and sampling. Workiva (15 Sep 2026, Amplify) launched “Automated Testing for Internal Audit and GRC”, an agentic workflow that “orchestrat[es] evidence, attribute, and testing agents” to replace “manual evidence collection, sample selection, attribute testing, and documentation … with full traceability at every step”, plus no-code Agent Studio for building further agents inside its reporting platform. One day earlier Archer put “AI Operators” into audit, third-party-risk and operational-risk work [S-2026-09-14-archer-evolv-foundation-workplace]. The 3LoD implication (this vault’s [inference], not either vendor’s claim) is twofold: the agents generating third-line evidence are themselves AI systems that need a place in the firm’s inventory, validation and oversight — so the third line inherits a model-risk dependency on its vendor — and internal audit’s independence now has to be evidenced against vendor-selected samples and vendor-asserted “traceability”. No standard (IIA GIAS, ISO/IEC 42001), regulator or FS customer is named; the only customer voice is a consumer-goods CAE. Source count reconciled to the Sources list (8 entries before this addition). Added as this banner, a Key Point, an Open Question and a Source entry. [S-2026-09-15-workiva-agent-studio-audit-testing]

Updated 2026-08-28 based on S-2026-08-26-eba-oprisk-rts-cp (daily regulatory-intelligence scan) — the EBA’s draft RTS on the operational risk management framework (Art 323(2) CRR3, 26 Aug 2026) is a prudential codification of a three-lines structure for operational risk: it clarifies the roles and responsibilities of the management body and senior management (governance/oversight), an independent operational risk management function (2LoD), and validation and audit (3LoD). Although it is an operational-risk (not AI) instrument, it is a directly transferable template for how a technology-neutral regime expects risk-ownership lines and an independent second-line function to be defined and evidenced — the same structure EBA/ECB apply to AI oversight, and the same “revisit accountability mapping, separating model risk, information security, data governance and operational risk lines” prescription in Paul’s framing. ICT risk is carved out to DORA. Draft, consultation to 31 December 2026 — not yet in force ⚠️; the AI read-across is inference, not the EBA’s claim. Added as a Key Point. See Operational Resilience and Third Party Risk and EBA — European Banking Authority. [S-2026-08-26-eba-oprisk-rts-cp] Updated 2026-07-01 based on S-2026-06-30-rbi-model-risk-management and S-2026-06-30-fsb-ai-sound-practices — two June-2026 items reinforce 3LoD as the supervisory anchor from outside the EU/ECB frame. The RBI draft MRM guidance (consultation to 24 July 2026) explicitly formalises AI/ML model governance through the three-lines-of-defence model with independent validation before deployment [S-2026-06-30-rbi-model-risk-management]. The FSB’s voluntary “Sound Practices” structures its 12 practices as organisation-wide governance (1–4), lifecycle risk management (5–10) and third-party/cyber (11–12) — a governance-then-lifecycle split that maps naturally onto 1st/2nd/3rd-line ownership [S-2026-06-30-fsb-ai-sound-practices]. Both are secondary-sourced (medium/medium). Added as Key Points and Sources. Updated 2026-06-30 based on a vendor-scan item: Diligent — AI Governance: A Guide for Boards, Risk and Audit Leaders (June 2026) (22 Jun 2026). A GRC platform vendor published a board/risk/audit guide that allocates AI oversight across the three lines of defence and maps to the EU AI Act, NIST AI RMF and OECD AI Principles. It is vendor thought-leadership (content marketing), not an independent standard — but it independently echoes, from the corporate-governance/GRC side, the same 3LoD-as-anchor frame this page documents from the supervisory (EBA/ECB) side. Added as a Key Point, a Detail note, and a Source. Low authority; primary guide not fetched directly (captured via a secondary aggregator) [S-2026-06-22-diligent-board-ai-governance-guide].

TL;DR

The three-lines-of-defence (3LoD) model is the structural anchor that EBA and ECB use to discuss AI risk ownership inside banks. EBA flags that 2LoD and 3LoD AI oversight is inadequate at most firms. The ECB position (echoed in practitioner commentary) is that AI governance should be supervised by the CRO anchored in the 3LoD model. Practitioner-side commentary disagrees on whether 3LoD is the right structure at all (versus a cross-functional AI committee model) — surfaced as a tension on Model Risk Management and Agentic AI. This page documents the 3LoD anchoring as a frame, not as a settled answer.

Key Points

  • Third-line work is being delegated to vendor agents (Sep 2026): Workiva’s Automated Testing for Internal Audit and GRC orchestrates “evidence, attribute, and testing agents” to replace manual evidence collection, sample selection, attribute testing and documentation, claiming “full traceability at every step”, expanded sampling capacity and broader risk coverage; no accuracy evidence, standard or regulator cited; non-FS customer voice only [S-2026-09-15-workiva-agent-studio-audit-testing]. Read with Archer’s AI Operators in audit/risk processes [S-2026-09-14-archer-evolv-foundation-workplace], the agents doing second- and third-line work are AI systems that need their own inventory entry, validation and oversight [inference].
  • EBA reports that 2LoD / 3LoD AI oversight is inadequate at most firms [S-2025-11-eba-ai-act-mapping].
  • Sunando Roy (AI and the Chief Risk Officer, 14 Feb 2026) and CDO Magazine New York Financial Forum (25 March 2026, featuring JPMorganChase, Citi, Truist) both report the ECB position that effective AI governance should be supervised by the CRO anchored in the 3LoD model with the CRO maintaining a central register covering both internal models and generative AI tools.
  • Paul’s AI Assurance Pathway lists an AI 3LoD RACI as a core practitioner artefact [S-2026-05-06-paul-ai-data-pathway].
  • EBA’s CRD revision tightens board oversight, ICT / third-party risk and internal governance arrangements — second-line risk owners gain explicit coverage [S-2025-11-eba-ai-act-mapping].
  • EBA/CP/2026/03 brings heads of control functions and CFOs under the suitability regime — second-line and finance leadership now within formal suitability obligations [S-2025-11-eba-ai-act-mapping].
  • FCA links 3LoD coverage to SM&CR via prescribed responsibilities (notably SMF24 for CDO; SMF4 for risk oversight) [S-2026-01-27-fca-mills-review].
  • Paul’s framing: clients should “revisit accountability mapping for AI risk — separating model risk, information security, data governance, and operational risk lines” and “embed ‘governance as code’ into the model lifecycle rather than treating it as an end-of-pipeline compliance gate”.
  • The GRC-vendor side is converging on the same frame: Diligent’s board/risk/audit guide (22 Jun 2026) allocates AI oversight across the three lines of defence, prescribes fairness/bias audits, third-party AI risk assessment, chartered cross-functional AI ethics committees and director AI-literacy, and maps recommendations to the EU AI Act, NIST AI RMF and OECD AI Principles. Vendor thought-leadership, not an independent standard, and generic (jurisdiction tag EU, no FS specifics or named reference) [S-2026-06-22-diligent-board-ai-governance-guide].
  • A regulator outside the EU now hard-wires 3LoD into AI/ML model governance: the RBI draft MRM guidance (consultation to 24 July 2026) “formalizes governance through the three-lines-of-defence model”, with independent validation before deployment and a comprehensive model inventory covering AI/ML and third-party models [S-2026-06-30-rbi-model-risk-management].
  • The FSB’s voluntary AI “Sound Practices” (June 2026) group into organisation-wide governance (practices 1–4), lifecycle risk management (5–10) and third-party/cyber resilience (11–12) — a structure that maps cleanly onto first-line ownership, second-line validation and third-line assurance [S-2026-06-30-fsb-ai-sound-practices].
  • The EBA’s draft RTS on the operational risk management framework (Art 323(2) CRR3, 26 Aug 2026) hard-wires a three-lines structure for operational risk: it clarifies the roles of the management body and senior management, an independent operational risk management function (2LoD), and validation and audit (3LoD). An operational-risk (not AI) instrument, but a directly transferable EU-prudential template for how a technology-neutral regime expects an independent second-line function and clear risk-ownership lines to be defined and evidenced — ICT risk carved out to DORA; draft, consultation to 31 December 2026 [S-2026-08-26-eba-oprisk-rts-cp][inference].

Detail

Why 3LoD is the supervisory anchor

The three-lines model is the operating frame supervisors already trust for credit, market, and operational risk. EBA and ECB extending it to AI is consistent with the broader “CRR/CRD technology-neutral” posture: AI risk lives inside existing risk taxonomies, supervised through the existing three lines. The CRO is positioned as the second-line risk owner; internal audit (3LoD) provides independent assurance. BCBS othp90 reinforces this by requiring skilled developers, validators, users, and independent auditors [S-2025-11-19-bcbs-othp90].

Where the model is strained

The EBA finding that 2LoD / 3LoD AI oversight is inadequate at most firms is consequential — it implies that the supervisory posture (3LoD-as-anchor) does not match operational reality. EBA’s framing is “catch up to the existing model”; some practitioner sources read the same data and argue the existing model is wrong for AI specifically — see the contradiction documented on Model Risk Management and Agentic AI.

Vendor-side convergence on the 3LoD frame

The 3LoD-as-anchor frame is not only a supervisory position; the GRC-tooling market is now packaging it for boards. Diligent’s AI Governance: A Guide for Boards, Risk and Audit Leaders (22 Jun 2026) explicitly allocates AI oversight across the three lines, and its stated value is that the 3LoD framing “forces compliance, risk, and internal audit functions to delineate ownership of AI controls explicitly, exposing gaps where AI risk management currently sits in no one’s formal mandate” — the same 2LoD/3LoD ownership-gap EBA flags, reached from the corporate-governance side [S-2026-06-22-diligent-board-ai-governance-guide]. Two cautions for an assurance practitioner: (1) this is a GRC vendor’s content marketing, self-interested and not an independent standard, so it weights but does not settle a structuring decision; and (2) it is generic to EU AI Act / NIST / OECD and does not carry the FS-specific EBA/ECB CRO-anchoring or SM&CR mapping that this page documents — so it is a corroborating frame, not a substitute for the supervisory sources [S-2026-06-22-diligent-board-ai-governance-guide][inference]. Its practical contribution is a checklist a client can self-assess against (board AI-risk reporting thresholds, a chartered AI ethics committee, director AI-literacy, multi-framework vendor due diligence) before an Independent Governance Assurance review tests whether those structures actually hold.

Practical artefacts

The AI 3LoD RACI is the headline mapping artefact [S-2026-05-06-paul-ai-data-pathway]. Around it sit:

  • AI System Inventory (1LoD-owned, 2LoD-validated).
  • Model Validation Report (2LoD review of 1LoD development).
  • Internal Audit AI Engagement Plan (3LoD).
  • AI Risk Board Pack (reporting up from 2LoD).
  • Annual AI Assurance Plan + AI Control-Evidence Calendar (2LoD / 3LoD operating cadence).

Practical Applications

  • Build an explicit AI 3LoD RACI for any client AI governance review.
  • Map AI risks into existing risk taxonomies rather than create parallel ones, consistent with the EBA / BCBS / FCA convergence [S-2025-11-eba-ai-act-mapping].
  • Audit the 2LoD capability gap. EBA’s finding is a credible opening for Service Line — Independent Governance Assurance reviews.

Open Questions

  • Whether the EBA’s “2LoD / 3LoD inadequate” framing will translate into specific control expectations during the 2026–2027 supervisory convergence programme.
  • Whether 3LoD is the right structural anchor for AI at all — sources disagree, see Model Risk Management and Agentic AI Tensions.
  • When internal audit’s evidence collection and sampling run on a vendor’s agents (Workiva) and second-line work on a GRC vendor’s “Operators” (Archer), who validates those agents, where do they sit in the firm’s AI inventory, and how is third-line independence from the vendor’s models evidenced? [S-2026-09-15-workiva-agent-studio-audit-testing][S-2026-09-14-archer-evolv-foundation-workplace]

Sources