Three Lines of Defense
The Three Lines of Defense is a governance model separating risk ownership (operations), risk oversight (risk and compliance functions), and independent assurance (audit). CRISC uses it to clarify risk roles and responsibilities.