The "three lines of defense" model is definitely under pressure, but the current direction is less about abandoning it and more about making it more dynamic, technology-enabled, and risk-centric. AI, particularly generative AI embedded in business processes, is accelerating this evolution because traditional governance assumes humans make operational decisions, while AI increasingly makes or influences them.
Here are the main themes emerging across regulators, industry groups, and large financial institutions.
1. From "three lines" to "distributed accountability"
The classic model remains conceptually sound:
- First line: owns risks and controls
- Second line: sets policy, provides challenge, oversight, and monitoring
- Third line: provides independent assurance
What's changing is the expectation that the first line becomes much more capable.
Historically:
- First line executed processes
- Second line designed many controls
- Third line tested controls periodically
Increasingly:
- First line owns risk decisions continuously
- AI assists operational decision-making
- Second line focuses on governance architecture rather than performing controls
- Third line evaluates whether governance itself is effective
The emphasis is shifting from "who performs the control" to who owns the risk outcome.
2. AI is strengthening—not weakening—the first line
Organizations are embedding AI into:
- customer onboarding
- transaction monitoring
- credit decision support
- procurement
- fraud detection
- compliance screening
- operational resilience
- software development
- model documentation
That means operational teams increasingly become AI supervisors rather than manual processors.
Consequently, first-line responsibilities now include:
- prompt governance
- AI output validation
- exception handling
- human override
- monitoring model drift
- documenting AI-assisted decisions
Risk ownership stays with the business even if AI performs much of the work.
3. Second line becomes a governance and challenge function
Rather than reviewing every decision, second-line risk functions are moving toward:
- AI governance frameworks
- model risk policies
- risk appetite
- control standards
- independent validation
- continuous monitoring dashboards
- challenge over AI deployment decisions
Instead of saying:
"Did Operations follow Procedure X?"
the question becomes:
"Is the AI-enabled process operating within approved risk tolerance?"
4. Continuous assurance replaces periodic testing
Traditional governance assumed:
- annual reviews
- quarterly testing
- sampling
AI changes the economics.
Organizations increasingly deploy:
- automated control monitoring
- real-time KRIs
- control telemetry
- AI-generated evidence
- continuous compliance testing
Third line then audits:
- monitoring capability
- governance
- effectiveness of automated controls
- management response
rather than manually re-performing thousands of transactions.
5. AI creates a "fourth participant" without creating a fourth line
One interesting debate is whether AI effectively creates a "fourth line."
The consensus is generally no.
AI is viewed as:
- an operational capability
- a decision-support tool
- a control technology
—not an independent governance function.
Independence remains uniquely human.
6. Model risk management is converging with operational risk
Historically:
- model risk belonged to quantitative teams
- operational risk belonged elsewhere
- technology risk was separate
Generative AI blurs these boundaries.
A single AI workflow may involve:
- model risk
- cyber risk
- privacy
- operational resilience
- conduct risk
- legal risk
- reputational risk
Many firms are therefore creating integrated AI governance committees that bring together these disciplines rather than treating AI as purely a model risk issue.
7. Governance is becoming capability-based rather than organizational
One of the most significant shifts is away from rigid organizational structures.
Instead of asking:
Which line owns this?
Organizations increasingly ask:
- Who owns the decision?
- Who sets standards?
- Who provides challenge?
- Who validates?
- Who assures?
These capabilities may be delivered by different organizational structures while preserving independence.
8. Regulators still support the three lines—but expect modernization
Major financial regulators generally continue to recognize the three-lines concept because it preserves clear accountability. However, they increasingly expect firms to demonstrate:
- clear accountability for AI-enabled decisions
- explainability where appropriate
- effective human oversight
- governance over third-party AI providers
- inventory and classification of AI use cases
- monitoring for bias, drift, and unintended outcomes
- evidence that boards understand material AI risks
The focus is less on organizational charts and more on whether governance remains effective as AI changes how work is done.
A practical target operating model
Many large organizations are converging on something like this:
| Function | Emerging role |
|---|
| First line | Owns AI-enabled business processes, validates outputs, manages exceptions, and remains accountable for risk outcomes |
| Second line | Defines AI governance, sets standards, challenges implementation, monitors risk indicators, and oversees compliance |
| Third line | Independently assesses whether AI governance, controls, and assurance processes are effective |
The key principle is that AI should not become a way to shift accountability. If an AI system recommends a credit decision, flags a suspicious transaction, or drafts a regulatory filing, the business function deploying that AI remains accountable for the outcome. Risk governance is evolving toward continuous monitoring, technology-enabled assurance, and clearer allocation of responsibilities—but the core principles of ownership, independent challenge, and independent assurance remain intact.