Three lines of defense
A governance structure in which the first line (model owners/developers) builds and operates models, the second line (an independent risk or model validation function) provides effective challenge and oversight, and the third line (internal audit) independently assesses whether the overall model risk management program itself is functioning as intended.
How the term is used in model risk management
A governance structure in which the first line (model owners/developers) builds and operates models, the second line (an independent risk or model validation function) provides effective challenge and oversight, and the third line (internal audit) independently assesses whether the overall model risk management program itself is functioning as intended. The exact implementation varies by institution, model type, risk rating, and governing framework. Use the linked regulatory pages and buyer guides below for scope-specific requirements.