What is the 'three lines of defense' model in operational risk governance?
-
A
Three separate risk databases: internal, external, and scenario data
-
B
A governance framework where business units (1st line) own risk, risk management functions (2nd line) oversee it, and internal audit (3rd line) independently assesses it
-
C
Three levels of regulatory oversight: local, national, and international
-
D
Three approval layers required before any new financial product can be launched