The three lines of defence model has been the standard governance framework for risk and compliance in regulated industries for more than two decades. It is referenced in regulatory guidance, audit standards, and governance codes across jurisdictions. Most regulated casino operators claim to operate it. A much smaller number actually do.
The gap between claimed and actual implementation creates a specific set of risks. A governance structure that looks like the three lines model on an organisation chart but operates differently in practice provides false assurance — to the board, to regulators, and to the operator's own risk function. When things go wrong, the gap between the structure on paper and the reality of how decisions were made is one of the first things a regulator or forensic investigator will examine.
The Model: What It Actually Requires
The three lines of defence model assigns risk accountability across three distinct functions, each with a defined role and reporting relationship:
The model works when accountability is clearly distributed, each line has genuine authority to perform its function, and the reporting lines preserve independence. It fails when these conditions are not met — and in casino environments, the conditions are frequently not met.
The Common Failure Modes
The failures in casino three lines implementation are largely predictable. They recur across operators of different sizes and ownership structures because they arise from the same structural pressures: revenue priority, small teams wearing multiple hats, and executive resistance to functions whose purpose is to constrain operational discretion.
"A compliance officer who approves the transaction, processes the CDD, and signs the SAR decision has provided all three lines themselves. That is not the three lines of defence — it is one person doing everything and calling it governance."
What Regulators Actually Expect
Gaming regulators across major jurisdictions have been increasingly explicit about their expectations for governance structure in licensed operators. The common thread is that the three lines model is expected to have genuine operational substance — not just documentation that describes it and an organisation chart that maps to it.
The specific regulatory expectations that most commonly create enforcement exposure are:
- Independence of the MLRO/compliance function: The Money Laundering Reporting Officer must have genuine independence to make reporting decisions without commercial interference. This means direct board access, protection from employment consequences for reporting decisions, and a reporting line that does not route through commercial management.
- Adequate resourcing of oversight functions: A compliance team of one person in a 400-seat casino operation is not adequate resourcing. Regulators assess whether the size and capability of the oversight function is proportionate to the risk environment it is supposed to monitor.
- Board-level risk governance: The board is expected to actively receive, review, and act on risk and compliance information — not just receive a summary from executive management that filtered the reporting before it arrived. Direct reporting lines from the second and third line to the board or a board-level committee are the standard.
- Internal audit independence: Where internal audit exists, it must have genuine independence. The internal audit function cannot report to the functions it audits without undermining the purpose of the third line entirely.
Multiple gaming enforcement actions in the UK and EU have specifically cited governance structure failures as a contributing factor — including findings that the compliance function lacked independence from commercial management, that audit findings were not escalated to the board, and that first-line operational teams were making compliance decisions without second-line oversight. Structure is not merely administrative — it is a regulatory obligation.
Small Operators: Proportionality Without Compromise
The three lines model is sometimes dismissed by smaller operators as a framework designed for large institutions. This is a misreading of the principle. The model is scalable — what a single-venue land-based operator implements will look different from a multi-jurisdiction online group — but the underlying accountability structure is not optional regardless of size.
In a small operation, the practical implementation of genuine three-lines governance typically involves:
- Clear written delineation of who owns which decisions and at which line — even where the same individual performs multiple functions, the capacity in which they are acting for each decision type should be documented
- External or outsourced second-line functions where internal capacity does not support a full-time compliance resource with genuine independence
- External audit rather than internal where the organisation is too small to field a genuinely independent internal audit function
- Board-level review of compliance and risk information at a frequency proportionate to the risk environment — not delegation of all oversight to executive management
The key test for any governance structure is whether a regulator examining the records of a specific decision could identify who was responsible for it, what line of defence that represented, and what independent oversight or challenge was applied. If the answer to any of those questions is "it is not clear," the structure needs work.
The Monitoring Gap: Testing That Controls Work
The most common practical failure in casino three lines implementation is not in the structure itself — it is in the monitoring that should give the structure substance. A second-line compliance function that sets policies but does not systematically test whether first-line operations follow them is providing a form of assurance that has no evidential basis.
Compliance monitoring in a casino environment should cover at a minimum: transaction monitoring alert handling, CDD completion rates and quality, SAR decision documentation, training completion and assessment, and first-line application of responsible gambling procedures. Each of these monitoring activities should have a schedule, a methodology, documented outputs, and a clear escalation path when issues are identified.
The outputs of compliance monitoring should be reported to senior management and the board — not held within the compliance function as operational records. The board's ability to exercise governance over risk depends on receiving accurate, unfiltered information about how controls are performing. If compliance monitoring only ever produces positive findings, either the monitoring methodology is not robust or the reporting is being filtered before it reaches the board.
Governance structure review and gap analysis
Wise Key Solutions provides governance structure assessments for casino and gaming operators, identifying three lines implementation gaps and producing practical recommendations for remediation. Contact us to discuss your requirements.
Speak to our team →This article reflects the operational perspective of the Wise Key Solutions founding team, drawing on experience across regulated gaming and financial services environments in the UK and Europe. It does not constitute legal or regulatory advice.