Article

Operational risk and the three lines of defence in UK financial institutions: is three really the magic number?

Citation

Mabwe K, Ring PJ & Webb R (2017) Operational risk and the three lines of defence in UK financial institutions: is three really the magic number?. The Journal of Operational Risk, 12 (1), pp. 53-69. https://doi.org/10.21314/JOP.2017.187

Abstract
There has been growing interest in the need for financial services firms to develop and implement robust systems and structures for managing operational risk. While there now appears to be some consensus in terms of definitions, quantification and modelling, firms are struggling with the qualitative side of operational risk management, particularly in relation to financial institutions’ operational risk governance, where the three-lines of defence model has become standardised. At the same time, corporate scandals post-financial crisis continue to indicate deficiencies in operational risk governance. As a result, our paper examines the three lines of defence in the context of operational risk management in UK financial institutions, focusing upon roles and responsibilities and then analyses the effectiveness of the traditional three lines of defence model. We find a lack of common understanding of the lines of defence in financial institutions which is leading to duplication of roles and gaps in coverage. This is concerning for the industry, the economy and regulators.

Keywords
Governance; Operational Risk; Risk Management; Three lines of defence

Journal
The Journal of Operational Risk: Volume 12, Issue 1

StatusPublished
FundersUniversity of Nottingham
Publication date31/03/2017
Publication date online14/02/2017
Date accepted by journal16/08/2016
URLhttp://hdl.handle.net/1893/30571
PublisherInfopro Digital Services Ltd
ISSN1744-6740
eISSN1755-2710