Business A.M
No Result
View All Result
Monday, March 2, 2026
  • Login
  • Home
  • Technology
  • Finance
  • Comments
  • Companies
  • Commodities
  • About Us
  • Contact Us
Subscribe
Business A.M
  • Home
  • Technology
  • Finance
  • Comments
  • Companies
  • Commodities
  • About Us
  • Contact Us
No Result
View All Result
Business A.M
No Result
View All Result
Home Analyst Insight

Lines of defence in information governance

by Admin
January 21, 2026
in Analyst Insight

In information governance and more particularly, in the management of risks embedded within any information governance framework, there needs to be an effective and consistent way in managing risks. The lines of defence model serves as the basis for risk management within business functions and departments in most organisations. In this piece, I explore the three lines of defence and how they serve companies.
The first line of defence covers the management of risk. This line of defence ensures that process owners that perform daily operational activities have thorough understanding of the risk environment within business units. For example, the process owner for the movement of documents within customer contact centres should ensure that the processes of managing such information assets align with the overall business goals and adhere to any existing policy demands within the business and the department.
In addition to that, the first line requires that the process owner ensures that appropriate controls are implemented within their business unit. Here, the process owner must ensure that controls, for example, policies, industry standard and procedures, are strictly adhered to within the department or business process. Furthermore, there is the consistent review of the control environment to ensure that control deficiencies are addressed immediately and they monitor control effectiveness on an on-going basis.
The first line of defence places high responsibility on business process owners in the management of risks within those highlighted business functions and they could be considered as the risk owner. They are responsible for keeping the risk within the risk appetite of the company.
The second line of defence covers the risk and compliance functions. They ensure that risk management and ethical functions are considered throughout the business. The second line of defence develops organisation wide risk management framework, policies, and procedures. For example, the data privacy officer falls within the remit of this defence and would ensure that the day-to-day management of information aligns with the organisation’s set framework.
Monitoring and overseeing the risk management procedures across the organisation falls within the second line of defence. This is usually achieved by working closely with the first line of defence to help keep a close eye on how information assets are managed according to the overarching business strategy. Here, the company can determine the current risk profile of the organisation and give clear risk management status to senior management.
The third line of defence is the audit function. This is considered as the independent function reporting directly to the board of directors about the status of risks within the organisation and giving detailed plans with regards to how those attendant risks will be managed or mitigated. This line of defence assesses the conformation of the risk management programme against risk management policies, standards, and procedures.
A key area of the third line of defence is the evaluation of the effectiveness of the first line and the second line of defence. They test, on agreed timeframes (quarterly or monthly) the effectiveness of these lines of defence. They provide attestation and assurance of all business functions.
Maintaining a three lines model helps companies to define roles and responsibilities in the management of risks within information governance. It goes without saying that this helps improve the effectiveness of risk management activities. In the absence of a clear methodology, there may be conflicting management processes which may hinder the effectiveness of the overall risks embedded within an information governance framework.

Admin
Admin
Previous Post

Putting economic value into Nigeria’s agro-commodities

Next Post

FirstBank sees oil recovery, e-Naira checking parallel market in 2022

Next Post

FirstBank sees oil recovery, e-Naira checking parallel market in 2022

  • Trending
  • Comments
  • Latest
Igbobi alumni raise over N1bn in one week as private capital fills education gap

Igbobi alumni raise over N1bn in one week as private capital fills education gap

February 11, 2026

Glo, Dangote, Airtel, 7 others prequalified to bid for 9Mobile acquisition

November 20, 2017

How UNESCO got it wrong in Africa

May 30, 2017

CBN to issue N1.5bn loan for youth led agric expansion in Plateau

July 29, 2025

6 MLB teams that could use upgrades at the trade deadline

Top NFL Draft picks react to their Madden NFL 16 ratings

Paul Pierce said there was ‘no way’ he could play for Lakers

Arian Foster agrees to buy books for a fan after he asked on Twitter

Threat, opportunities: Generative AI and Nigeria’s future of work

Generative AI: Accelerating Nigeria’s digital economy beyond oil

March 2, 2026
Stress-testing systems:A financial imperative, not technical exercise

Cyber resilience not IT line item, but boardroom obligation

March 2, 2026
Delta names Long MD, Alliances for Europe, Africa

Delta names Long MD, Alliances for Europe, Africa

March 2, 2026
SAHCO boosts service efficiency with ultra-modern equipment

SAHCO boosts service efficiency with ultra-modern equipment

March 2, 2026

Popular News

  • Igbobi alumni raise over N1bn in one week as private capital fills education gap

    Igbobi alumni raise over N1bn in one week as private capital fills education gap

    0 shares
    Share 0 Tweet 0
  • Glo, Dangote, Airtel, 7 others prequalified to bid for 9Mobile acquisition

    0 shares
    Share 0 Tweet 0
  • How UNESCO got it wrong in Africa

    0 shares
    Share 0 Tweet 0
  • CBN to issue N1.5bn loan for youth led agric expansion in Plateau

    0 shares
    Share 0 Tweet 0
  • Insurance-fuelled rally pushes NGX to record high

    0 shares
    Share 0 Tweet 0
Currently Playing

CNN on Nigeria Aviation

CNN on Nigeria Aviation

Business AM TV

Edeme Kelikume Interview With Business AM TV

Business AM TV

Business A M 2021 Mutual Funds Outlook And Award Promo Video

Business AM TV

Recent News

Threat, opportunities: Generative AI and Nigeria’s future of work

Generative AI: Accelerating Nigeria’s digital economy beyond oil

March 2, 2026
Stress-testing systems:A financial imperative, not technical exercise

Cyber resilience not IT line item, but boardroom obligation

March 2, 2026

Categories

  • Frontpage
  • Analyst Insight
  • Business AM TV
  • Comments
  • Commodities
  • Finance
  • Markets
  • Technology
  • The Business Traveller & Hospitality
  • World Business & Economy

Site Navigation

  • Home
  • About Us
  • Contact Us
  • Privacy & Policy
Business A.M

BusinessAMLive (businessamlive.com) is a leading online business news and information platform focused on providing timely, insightful and comprehensive coverage of economic, financial, and business developments in Nigeria, Africa and around the world.

© 2026 Business A.M

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Technology
  • Finance
  • Comments
  • Companies
  • Commodities
  • About Us
  • Contact Us

© 2026 Business A.M