itriskcarriere.nl

Is the Three Lines of Defense Paradigm Dead?

Nieuws
31-05-2024
Clifford Rossi
A three-pronged approach to risk management has been widely employed by the financial services industry for the past 10 years. This model, however, has relegated ERM to second-tier status while causing friction between different business units – and adjustments are therefore needed.

By Clifford Rossi, Professor University of Maryland

The three lines of defense (3LoD) doctrine has been one of the major pillars of enterprise risk management at banks and regulators for more than a decade. But has it outlived its usefulness? If so, should it be revised or replaced?

Serious risk events of various types continue to occur with some regularity, so the effectiveness of 3LoD is highly questionable. Last year’s bank failures grabbed headlines, but, over the past decade, we’ve also seen risk fiascoes at Wells Fargo, Credit Suisse, Citigroup and even JP Morgan, among other high-profile banks.

Given the recurrence of risk failures in the banking system, it is logical to revisit the efficacy of the 3LoD model and ask if there are better ways to strengthen the way banks manage risk.

What’s Wrong with Three Lines of Defense?

The concept of 3LoD in banking surfaced as far back as 2003, when it was mentioned by the Financial Services Authority. But it really took off after the Institute of Internal Auditors fleshed out the idea more broadly in 2013. The IIA itself recommended an update to 3LoD as recently as 2019, but, at its core, it hasn't changed much.

[….]

Lees verder op: GARP

Gerelateerde vacatures

Geïnteresseerd in een carrière bij organisaties in ditzelfde vakgebied? Bekijk hieronder de gerelateerde vacatures en vind de perfecte match voor jou!
SVB
5.416 - 7.252
Senior
Amstelveen
Als Directiesecretaris IT bij SVB ondersteun en adviseer je de Directeur IT en MT IT: je bereidt MT-overleggen voor, bewaakt kwaliteit van stukken, coördineert de stukkenstroom naar Directieteam/RvB, stuurt planning...
PGB Pensioendiensten
7.541 - 10.056
Senior
Amstelveen
Als Information Security Officer (ISO) bij PGB Pensioendiensten stuur je op informatiebeveiliging en risicomanagement: beleid, raamwerk en compliance (DORA, AVG, ISO 27001), risicoanalyses, incidentregistratie, monitoring/rapportage, security by design en bewustwording.
NN
4.324 - 5.765
Junior, Medior
Den Haag
As a Junior/Medior Information Security Officer at NN, you manage information security risks with DevOps and product owners, perform risk assessments, verify security controls, support audits, conduct threat modelling, review...
Top vacature
Alliander
5.310 - 7.586
Medior, Senior
Arnhem
Als Continuity Officer bij Alliander versterk je digitale weerbaarheid: je voert risico- en impactanalyses (BIA) uit, vertaalt afhankelijkheden naar DRP/RTO/RPO, onderhoudt en test herstelplannen, monitort compliance en adviseert management.