Quaintitative

For Risk & Compliance

The three lines of defence for AI

The three lines of defence are how AI risk is run inside a firm, and from the second line's seat two things hold the whole structure up: that one approach governs AI risk across the firm, and that you can challenge that approach without ending up accountable for the outcome you were meant to challenge. I wrote the AIRG and led the thematic review of how banks actually manage AI model risk, and the second lines that work keep both. The ones that do not have usually given one of them away.

We have been told to set up AI governance. What operating model should we build - a central AI function, hub-and-spoke, a team in every unit? And should we appoint a Chief AI Officer to own it all?

A clean structure feels like progress. So I ask back: if you design and run the structure, who is left to challenge it independently? And if one person owns all of AI, do they actually hold the levers, or just the blame?

You do not run the second line by owning a shape or a title. You run it by enforcing one consistent approach across the firm, as the control function, and by keeping your challenge genuinely independent of the business that builds. None of this is new. The AIRG does not invent a new structure or a new accountable persona. It slots AI straight into the three lines of defence you already run, which is the point of this whole book: extend what you have, do not start over.

The spine is yours to enforce

The first thing to hold is not a diagram. It is whether the firm does the same few things the same way everywhere AI runs. Found the same way in every unit. Rated on one scale. Held in one inventory. Controlled on the same basis. Reviewed at a consistent intensity. That consistency is the spine, and enforcing it is your job, because you are the control function the AIRG puts in charge of what counts as AI and how material each use is.

Why it falls to you: without the spine, the numbers you report upward stop meaning anything. If one unit calls a model AI and another does not, your inventories do not reconcile, and the firm-wide picture you give the board and the supervisor is fiction. If a "high" on one desk is a "medium" on the next, you are adding up units that cannot be summed. The business can run excellent controls in three places and still have no spine, and it is the missing spine that will hurt the firm, because what threatens it rarely sits inside one well-run unit. It sits in the gaps between them, where no single owner is looking. The gaps are yours to watch.

So do not try to mandate that AI be centralised, or distributed. Let the business choose the shape. Enforce that the method is consistent whichever shape it picks, and that it would still hold if AI moved from a central team out to the desks, or back.

Where you sit, and where you must not

Now the harder half. The three lines are the structure, and your independence is the thing inside it you have to protect.

The business is the first line. It owns the risk it takes and runs the first-line controls, but it does not sign off on its own work. You are the second line. You challenge and validate, and for a material system that validation is required, not a favour, performed by people genuinely independent of the builders, with the standing to send a system back. Audit is the third line, and checks that both of you are doing your jobs. That is the whole machine, and AI changes none of it.

The trap, and it is a common one, is being handed AI risk to own end to end. It feels like authority. It is the loss of your independence. If you both run a control and sign off that the residual risk is acceptable, then no one independent has actually said yes, and you have quietly become the first line you were meant to challenge. The business owns the risk because the business takes it and earns from it. You do not mark its homework by taking the pen. You keep the pen that says yes or no, and you keep it clean.

Owning it end to end is not authority. It is the loss of your independence.

A function resourced to the estate

A second line that cannot cover the estate is not oversight. It is intent with a job title. So the least glamorous number is the one to fight for: your headcount and budget against the number, complexity, and risk of the AI systems deployed. A two-person team notionally validating three hundred models is not independent assurance, it is a queue, and the controls will quietly lapse under the load while the policy still says they run.

This is also where the model-risk muscle helps you. You already know how to argue for validation capacity against a model inventory. AI stretches that inventory; it does not change the argument. Size the function to the estate, and name the gap plainly when you cannot, because an unresourced second line is a finding the supervisor will make for you if you do not make it first.

Escalation that bites, and your two audiences

The last thing the structure needs is a reporting line that actually carries bad news upward in time to act. Material AI risk and breaches of a threshold should reach the board quickly, in terms it can act on, not get absorbed two layers down because raising them was awkward. You are the one who carries that, so build the path and use it.

Remember your two audiences. The board, which sets the approach and the appetite and needs enough grasp of AI to challenge what you bring it. And the supervisor, who will one day ask you to show the spine, the inventory, the ratings, and a decision your challenge actually changed. A second line that has never said no to the business has nothing to show either of them. Your credibility, up and out, is the record of the times you held the line.

For the second line

What to own. The spine - one consistent approach across the firm, enforced by you as the control function that arbitrates what counts as AI and how material it is, whatever operating model the business chooses. Your independence - challenge and validate, and for material systems validate as people genuinely separate from the builders; never both run a control and sign off its residual risk. A function resourced to the estate, with the gap named plainly when it is not. And escalation that reaches the board in time, plus a record of decisions your challenge actually changed, for the two audiences you answer to: the board above and the supervisor outside.

Ask the first line:

  • Do we govern AI the same way across the whole firm, and would that hold if we moved AI from a central team out to the desks?
  • For this system, who in the business is accountable for the outcome when it is wrong, by name, and what can they actually change?
  • Where is the independent validation on this, and was the validator genuinely separate from the people who built it?
  • Have we updated the model, operational, technology, and third-party risk policies for AI, or bolted on a separate AI policy beside them?
  • When did a material AI risk or a breach last reach the board, and how long did it take to get there?

Work with me

I train risk and compliance teams on turning AI risk management into a working system. See the courses and workshops, read more on AI risk management, or get in touch.