16/04/2026

Compliance Essentials #19 – Lines of defence within the AML/CFT-P-C framework

Phoenix Compliance Essentials #19

Today’s focus: lines of defence within the AML/CFT-P-C framework

Compliance is not only about having procedures in place, but also about how they are implemented. The lines of defence provide the structure for that implementation.

➡️ What are the lines of defence?

A line of defence represents a level of responsibility in the management of ML/FT-P-C risks:
– First line: detect
– Second line: prevent and decide
– Third line: monitor and improve

The objective is to ensure the effective implementation of AML/CFT-P-C obligations, secure decision-making and demonstrate effective risk management through complementary controls.

➡️ Who is involved?

AML/CFT-P-C is everyone’s responsibility: a risk may be identified by any member of staff, whether in operations, compliance or senior management.

An effective framework therefore relies not on a single individual, but on a well-organised governance structure.

➡️ Practical example: a real estate agency faced with an unusual transaction

A client wishes to acquire a property in Monaco through a foreign entity with a complex ownership structure and a source of financing that lacks transparency.

👉 First line of defence – Operations

Who? The real estate agent

Actions:
– Collects KYC information (customer, beneficial owner, source of funds)
– Identifies red flags (lack of transparency, inconsistencies, unusual urgency)
– Applies internal procedures
– Escalates the matter to Compliance

💡 First level of risk detection

👉 Second line of defence – Compliance

Who? The AML/CFT-P-C Manager

Actions:
– Analyses the situation
– Assesses the level of risk
– Decides on the appropriate measures (additional information, refusal to proceed, suspicious transaction report)
– Acts as the interface with senior management and, where appropriate, the competent authorities

💡 Risk management and decision-making.

👉 Third line of defence – Audit and Direction

Who? An external audit firm appointed by Direction.

Actions:
– Verifies the adequacy and effective implementation of procedures
– Assesses first- and second-line controls
– Identifies weaknesses (training, traceability, governance)
– Recommends an improvement plan

💡 An independent and strategic view of the framework.

➡️ How does it work?

The framework relies on the effective flow of information: any risk identified by the first line of defence must be escalated without delay. Communication between the different lines of defence is a key factor in ensuring an appropriate and effective response.