The 'three lines of defense' model in operational risk management assigns risk management roles as:
-
A
Board, senior management, and internal audit
-
B
Front office, middle office, and back office
-
C
Business units, risk and compliance functions, and internal audit
-
D
Credit, market, and operational risk departments