Log in
Home / Publications / No. 088
The three lines model separates three jobs that most small firms perform with the same people. Understanding the separation matters even when you cannot fully achieve it.
Position as at August 2026
First line. The business. The people who onboard clients and handle transactions. They own the risk. They perform the customer due diligence, they notice the unusual thing, and they raise it.
Second line. Compliance. Sets the policy, monitors whether the first line is following it, and owns the reporting. Your compliance officer sits here.
Third line. Independent assurance. Tests whether the first two actually work. Internal audit, or an external reviewer.
Each line checks the one before it.
The first line will miss things, because they are focused on serving the client and are the least detached.
The second line will not catch everything, because it sets the rules and is not fully independent of them.
The third exists because someone has to test the second. A compliance function nobody reviews drifts toward whatever is convenient, and does so slowly enough that nobody notices.
You may have six people. You cannot staff three lines.
What you can do is avoid the arrangement that fails completely, which is one person occupying all three. The person onboarding clients cannot also be the compliance officer who monitors onboarding and the reviewer who tests the monitoring.
First line: whoever onboards clients does the due diligence and the screening.
Second line: a named compliance officer, not the person doing most of the onboarding, who reviews files and owns reporting.
Third line: an annual independent review, bought in for a day or two.
That is achievable in a firm of six, and it satisfies the principle even if it does not resemble a bank's structure.
The compliance officer who is also the busiest fee earner.
The role gets deprioritised because client work is urgent and monitoring is not. Files go unreviewed for months, and the gap only appears in an inspection.
If your compliance officer has no protected time, the function exists on paper.
Not whether the policy is good. Whether it is being followed.
Take twenty client files. Is the identification there? Is beneficial ownership recorded? Is there dated evidence of screening? Was screening repeated? Where something was escalated, what happened next?
That test takes a day and tells you more than reviewing the policy document.
Inspections look for evidence, not intent.
The three lines model matters because it produces evidence as a by-product. First line does the work, second line reviews it, third line tests the review. Each layer leaves a record.
A firm with one person doing everything may be doing it perfectly and cannot demonstrate it.
We act as the third line for firms that need an independent AML review, and we run this structure in our own practice.
Have a question on this?
AskCALX searches the official corpus and answers with the article quoted, word for word.
Newsletter
Latest in UAE business, tax and technology, once a month.
Thank you, you are on the list.
Office 1316, Aspin Commercial Tower
Sheikh Zayed Road, P.O. Box 10415, Dubai
Open in Google Maps →