Applying the Three Lines of Defence to AI Governance

Back to Blog·Governance

Applying the Three Lines of Defence to AI Governance

Marcus Lim
Principal GRC Consultant
7 min read

The three lines of defence model provides a proven accountability structure for risk management. Applying it to AI governance clarifies roles, prevents gaps, and ensures independent oversight of AI systems.

First Line: AI System Owners and Developers

The first line of defence owns and operates AI systems. Their responsibilities include implementing AI governance controls, conducting pre-deployment risk assessments, monitoring system performance, and escalating issues to the second line.

Second Line: AI Risk and Compliance Functions

The second line provides oversight, challenge, and guidance to the first line. This includes maintaining the AI governance framework, conducting independent model validation, monitoring regulatory developments, and reporting to senior management.

Third Line: Internal Audit

Internal audit provides independent assurance over the effectiveness of AI governance and risk management. AI audit programmes should cover governance framework adequacy, control design and operating effectiveness, regulatory compliance, and model risk management.

Tagged:Governance

Ready to Strengthen Your AI Governance?

Take our free AI Governance Assessment or speak with one of our experts.