Phoenix Compliance Essentials #19
Today’s focus: lines of defence within the AML/CFT-P-C framework
Compliance is not only about having procedures in place, but also about how they are implemented. The lines of defence provide the structure for that implementation.
➡️ What are the lines of defence?
A line of defence represents a level of responsibility in the management of ML/FT-P-C risks:
– First line: detect
– Second line: prevent and decide
– Third line: monitor and improve
The objective is to ensure the effective implementation of AML/CFT-P-C obligations, secure decision-making and demonstrate effective risk management through complementary controls.
➡️ Who is involved?
AML/CFT-P-C is everyone’s responsibility: a risk may be identified by any member of staff, whether in operations, compliance or senior management.
An effective framework therefore relies not on a single individual, but on a well-organised governance structure.
➡️ Practical example: a real estate agency faced with an unusual transaction
A client wishes to acquire a property in Monaco through a foreign entity with a complex ownership structure and a source of financing that lacks transparency.
👉 First line of defence – Operations
Who? The real estate agent
Actions:
– Collects KYC information (customer, beneficial owner, source of funds)
– Identifies red flags (lack of transparency, inconsistencies, unusual urgency)
– Applies internal procedures
– Escalates the matter to Compliance
💡 First level of risk detection
👉 Second line of defence – Compliance
Who? The AML/CFT-P-C Manager
Actions:
– Analyses the situation
– Assesses the level of risk
– Decides on the appropriate measures (additional information, refusal to proceed, suspicious transaction report)
– Acts as the interface with senior management and, where appropriate, the competent authorities
💡 Risk management and decision-making.
👉 Third line of defence – Audit and Direction
Who? An external audit firm appointed by Direction.
Actions:
– Verifies the adequacy and effective implementation of procedures
– Assesses first- and second-line controls
– Identifies weaknesses (training, traceability, governance)
– Recommends an improvement plan
💡 An independent and strategic view of the framework.
➡️ How does it work?
The framework relies on the effective flow of information: any risk identified by the first line of defence must be escalated without delay. Communication between the different lines of defence is a key factor in ensuring an appropriate and effective response.


