Financial services
Three lines of defense, no owner for the answer
The three lines model gives every risk an owner. Ask which line owns the knowledge an AI assistant answers from, and the question tends to go quiet.
Cognatum Team · Sep 23, 2026 · 6 min read
Every regulated firm can name the owner of a risk. The first line runs the business and owns the risks it creates. The second line sets the standards and monitors adherence to them. The third line audits independently and reports to the board. The map is clean, familiar and examined against.
Cognatum governs the entry
source · version · approver · permissions
Then an AI assistant answers a question about a policy, and the map runs out. Someone owns the tool. Someone owns the model risk. Someone owns the control testing. Ask who owns the document the answer was drawn from, whether that document was still current, and whether a named person ever approved what it says, and the honest answer is usually that it depends who you ask.
What the three lines actually allocate
The Institute of Internal Auditors published the Three Lines Model in July 2020 as an update of the Three Lines of Defense, keeping the allocation of roles while dropping the defensive framing in favor of governance and value creation. The division of labor itself survived largely intact.
Deloitte's account of the same structure is blunt about that division. Management in the first line owns and manages the risks of day to day operations and designs, operates and implements the controls. The second line supplies frameworks, policies, tools and oversight. The third line provides objective and independent assurance and reports to the board and the audit committee.
Roles, not material
Read the allocation closely and it assigns people, processes and controls. It does not assign the content those people work from. For decades that was a reasonable omission. A person reading a procedure brings judgment to it, notices the date on the cover page, and asks a colleague when something looks off. Retrieval does none of that.
The question the model was never asked
An assistant that answers from company documents inherits whatever is in them. It cannot tell a ratified policy from a superseded draft that nobody deleted, and it has no way of knowing that the deck it is quoting was assembled for one client meeting three years ago.
Each line has a defensible reason to treat that as someone else's problem. The first line owns the process, not the library. The second line owns the framework, not the file. The third line tests whether controls operated, and there is no control to test where nobody was ever assigned the content.
Everyone's concern, nobody's job
So the gap is not negligence. It is a boundary that three well drawn roles happen to leave uncovered, and retrieval based AI walked straight into it.
Regulators already assume someone owns it
FINRA's Regulatory Notice 24-09 reminds member firms that its rules are intended to be technology neutral and continue to apply when firms use generative AI. It is specific about supervision. If a firm uses these tools as part of its supervisory system, its policies and procedures should address technology governance, including model risk management, data privacy and integrity, reliability and accuracy of the AI model.
Notice what that quietly requires. Accuracy is not a property of a model in isolation. An assistant that retrieves faithfully from an out of date source is accurate about the source and wrong about the firm.
Logging is not ownership
The EU AI Act requires high risk systems to allow the automatic recording of events over their lifetime. The NIST AI Risk Management Framework asks organizations to document and trace what their systems do. ISO/IEC 42001 sets out requirements for managing AI as a system. All three are worth the effort, and none of them establishes who approved the content an answer rests on, or when it was last reviewed.
Holding it is not standing behind it
The same distinction sits under BCBS 239, which followed a crisis that showed many banks, including global systemically important ones, could not aggregate risk exposures and identify concentrations fully, quickly and accurately. The information existed somewhere in the building. Holding it and being able to stand behind it are different things.
Grounding does not close the gap
The usual answer is to ground the assistant in approved sources. That helps, and it is not sufficient. The first preregistered evaluation of commercial AI legal research tools found that retrieval based systems from LexisNexis and Thomson Reuters hallucinated between 17 and 33 percent of the time, despite vendor claims of eliminating the problem.
Retrieval improves the odds. It does not tell you who stands behind the retrieved text, and it cannot settle the case where two documents in the same repository flatly disagree.
What owning the knowledge looks like
This is the work the Cognatum Knowledge Loop is built around. Knowledge comes in from the systems a company already uses, is cleaned and enriched, and then reaches a gate where a named person approves it. The AI does the finding, gathering and surfacing, then routes the item to a human. The human decides what is true.
Everything downstream inherits that decision. Each entry carries an approver, a date and a source, so an answer traces back to a person rather than to a file path. Where two documents contradict each other, both positions are surfaced and the disagreement is named, rather than settled silently in favor of whichever one ranked higher.
Notified, not rewritten
When a source changes, Cognatum notifies the people whose answers depend on it. It does not quietly rewrite those answers on its own, which would only swap one unexamined output for another.
No migration required
Departmental repositories are normal and fine. Finance keeps its folders, legal keeps its own, and nobody has to move anything. Cognatum works bidirectionally with those systems rather than housing the content itself, so the governed layer sits above the split instead of demanding the split be undone first.
What a reviewer actually asks
Three questions decide whether an AI answer survives scrutiny. Who approved this, and were they the right person to. What source does it rest on, and which version of it. What did that source say on the day the answer was given, rather than today.
The third question is the one that catches firms out. An answer given in March is judged against what was approved in March. A system that can only show the current state of a document cannot reconstruct the answer it produced six months ago, which is precisely the period a reviewer will want to walk through.
Not a fourth line
The fix is not another function with another mandate. Knowledge is the material all three lines already work from, and it has simply never been assigned to any of them. Give it an owner, an approval state and a timestamp, and the model that has served risk governance for years starts working on AI answers as well as it works on everything else.
Your company's knowledge isn't missing. It's unusable. Cognatum changes that. See how the Loop works at cognatum.ai/the-loop.
Sources
- The IIA's Three Lines Model, July 2020 (theiia.org)
- Modernizing the three lines of defense model (deloitte.com)
- Regulatory Notice 24-09, generative AI and large language models (finra.org)
- Principles for effective risk data aggregation and risk reporting, BCBS 239 (bis.org)
- AI Risk Management Framework, NIST AI 100-1 (nist.gov)
- Article 12: Record-Keeping, EU AI Act (artificialintelligenceact.eu)
- ISO/IEC 42001:2023, AI management systems (iso.org)
- Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools (arxiv.org)
- The Cognatum Knowledge Loop (cognatum.ai)
Common questions
Questions this raises.
What is the three lines of defense model?
It is a risk governance structure in which the first line owns and manages the risks created by day to day operations, the second line sets frameworks and provides oversight, and the third line, internal audit, gives independent assurance to the board. The Institute of Internal Auditors updated it as the Three Lines Model in July 2020, keeping the allocation of roles and shifting the emphasis toward governance rather than defense alone.
Does the three lines model cover AI assistants?
It covers the people, processes and controls around them. Firms routinely assign the tool, the model risk and the control testing across the three lines. What tends to go unassigned is the underlying knowledge the assistant retrieves from, because the model allocates roles rather than content, and a human reader used to supply the missing judgment.
Which line should own the knowledge an AI answers from?
In practice the subject matter expert in the first line is the one who can say whether a statement is correct, so approval belongs with a named person there, with the second line setting the standard for what approval requires and the third line testing that it happened. The point is less which line than that the ownership is explicit and recorded.
Is an audit log enough to show an AI answer was governed?
A log shows what the system did. It does not show who approved the content the system used, when that content was last reviewed, or what it said on the date the answer was given. Record keeping obligations such as those in the EU AI Act sit alongside that question rather than answering it.
Do we have to consolidate our content into one system first?
No. Departmental repositories are a normal way for an organization to work, and the problem is that nothing sits above them. Cognatum works bidirectionally with the systems already in use rather than housing the content itself, so governance can be applied without a migration project in front of it.