Governance Structure - Three Lines of Defense
First Line of Defense

The first line of defense owns and manages risks. Contrary to how risk management is perceived, individual risks and the controls that mitigate them are not owned by risk or compliance professionals. Rather, operational management and senior leadership are responsible for ongoing activities that include:
- Owning and managing risks.
- Identifying, assessing and mitigating risks.
- Implementing corrective actions.
- Implementing and maintaining internal controls.
- Conducting evaluations of internal controls.
- Executing risk and control procedures on a daily basis.
Second Line of Defense

The second line of defense oversees risks. It is at this line of defense where functions associated with risk are found, including Enterprise Risk Management . Functions of the second line of defense include:
- Ensuring that operational management and senior leadership are implementing effective risk management practices.
- Assisting risk owners with risk evaluation by taking into account the institution’s risk appetite.
- Helping risk owners report risk-related information throughout the institution.
- Providing updates on the status of risk and resiliency to executive management and the Board of Trustees Audit Committee.
Third Line of Defense
