GovernanceInternal audit (model risk)

Third line of defense (model risk)

In the three-lines structure applied to model risk management, the third line is internal audit: it independently assesses whether the overall MRM program, governance, inventory discipline, validation function, is working as designed, rather than validating individual models itself. Distinct from the second-line model validation function, which reviews specific models.

Last updated: Last reviewed by: Model Risk Directory editorial team

How the term is used in model risk management

In the three-lines structure applied to model risk management, the third line is internal audit: it independently assesses whether the overall MRM program, governance, inventory discipline, validation function, is working as designed, rather than validating individual models itself. Distinct from the second-line model validation function, which reviews specific models. The exact implementation varies by institution, model type, risk rating, and governing framework. Use the linked regulatory pages and buyer guides below for scope-specific requirements.

Related glossary terms