What is the 'three lines of defense' model in risk management?
-
A
A risk governance structure where business units, risk/compliance functions, and internal audit provide layered oversight
-
B
A cybersecurity framework using firewalls, encryption, and monitoring
-
C
A board governance model with independent directors, audit committee, and external auditors
-
D
A regulatory model using company filings, SEC review, and judicial enforcement