The 3LoD model
As mentioned in the previous section, the purpose of the 3LoD model is to ensure appropriate segregation and accountability for individual business owners and other functions.
Let’s take a step back for a moment to establish the ownership of the risk – if there is a risk to the business, who will be the owner of the risk? The business owner. Therefore, the business owner will also be the risk owner as per the 3LoD model. Since the business owners are responsible for the day-to-day operational management of the business, they will be considered the first LoD for any risk that might occur to their business.
Now, these business owners might know a lot about the business, the risks, and the control environment, but they might not be the experts in remediating those risks. This is where the second LoD comes in. The second LoD is the risk monitoring and oversight function. They work closely with the first LoD to ensure that these risks are mitigated with...