Governance & Risk

The Three Lines of Defence: Why Most Casinos Get It Wrong

The three lines of defence model is the standard governance framework for risk and compliance. Most casino operators implement it poorly — blurring accountabilities, undermining compliance independence, and failing to give audit the authority it needs.

Governance & Risk 8 min read

The three lines of defence model has been the standard governance framework for risk and compliance in regulated industries for more than two decades. It is referenced in regulatory guidance, audit standards, and governance codes across jurisdictions. Most regulated casino operators claim to operate it. A much smaller number actually do.

The gap between claimed and actual implementation creates a specific set of risks. A governance structure that looks like the three lines model on an organisation chart but operates differently in practice provides false assurance — to the board, to regulators, and to the operator's own risk function. When things go wrong, the gap between the structure on paper and the reality of how decisions were made is one of the first things a regulator or forensic investigator will examine.

The Model: What It Actually Requires

The three lines of defence model assigns risk accountability across three distinct functions, each with a defined role and reporting relationship:

First Line
Operational Risk Ownership
Business units and operational management. Own and manage risks daily. Responsible for implementing controls. The line that creates the risk and is accountable for controlling it at source.
Second Line
Risk and Compliance Oversight
Compliance, risk management, legal, and financial control functions. Set policy, provide oversight, monitor first-line performance, and report on the risk and compliance environment to leadership and the board.
Third Line
Independent Assurance
Internal audit. Independently assesses whether the first and second lines are working as intended. Reports directly to the board or audit committee. Must be genuinely independent of the functions it audits.

The model works when accountability is clearly distributed, each line has genuine authority to perform its function, and the reporting lines preserve independence. It fails when these conditions are not met — and in casino environments, the conditions are frequently not met.

The Common Failure Modes

The failures in casino three lines implementation are largely predictable. They recur across operators of different sizes and ownership structures because they arise from the same structural pressures: revenue priority, small teams wearing multiple hats, and executive resistance to functions whose purpose is to constrain operational discretion.

🔀
Blurred First and Second Line
Compliance officers taking ownership of operational decisions — approving transactions, signing off on customer access — rather than advising and overseeing. Once compliance owns the decision, it cannot independently assess it.
📊
Second Line Reporting to Commercial Management
The compliance or risk function reporting to a COO or commercial director rather than the CEO or board. Creates structural pressure to align compliance decisions with commercial interests.
🎯
Audit Without Authority
Internal audit that reports to executive management rather than the board or audit committee — and whose findings can be suppressed, modified, or ignored by the management it is supposed to hold to account.
👥
Dual Roles Across Lines
Individuals holding both first-line operational roles and second-line compliance or risk functions simultaneously. Common in small operators but structurally incompatible with the model.
📋
Policy Without Monitoring
Second-line functions that produce policies and procedures but do not systematically monitor whether first-line operations follow them. Oversight without monitoring is decoration.
🚨
Risk Culture Capture
Risk and compliance functions that have been culturally captured by the commercial priorities of the business — providing assurance to unlock activity rather than independently assessing whether the activity is appropriate.

"A compliance officer who approves the transaction, processes the CDD, and signs the SAR decision has provided all three lines themselves. That is not the three lines of defence — it is one person doing everything and calling it governance."

What Regulators Actually Expect

Gaming regulators across major jurisdictions have been increasingly explicit about their expectations for governance structure in licensed operators. The common thread is that the three lines model is expected to have genuine operational substance — not just documentation that describes it and an organisation chart that maps to it.

The specific regulatory expectations that most commonly create enforcement exposure are:

Regulatory Precedent

Multiple gaming enforcement actions in the UK and EU have specifically cited governance structure failures as a contributing factor — including findings that the compliance function lacked independence from commercial management, that audit findings were not escalated to the board, and that first-line operational teams were making compliance decisions without second-line oversight. Structure is not merely administrative — it is a regulatory obligation.

Small Operators: Proportionality Without Compromise

The three lines model is sometimes dismissed by smaller operators as a framework designed for large institutions. This is a misreading of the principle. The model is scalable — what a single-venue land-based operator implements will look different from a multi-jurisdiction online group — but the underlying accountability structure is not optional regardless of size.

In a small operation, the practical implementation of genuine three-lines governance typically involves:

The key test for any governance structure is whether a regulator examining the records of a specific decision could identify who was responsible for it, what line of defence that represented, and what independent oversight or challenge was applied. If the answer to any of those questions is "it is not clear," the structure needs work.

The Monitoring Gap: Testing That Controls Work

The most common practical failure in casino three lines implementation is not in the structure itself — it is in the monitoring that should give the structure substance. A second-line compliance function that sets policies but does not systematically test whether first-line operations follow them is providing a form of assurance that has no evidential basis.

Compliance monitoring in a casino environment should cover at a minimum: transaction monitoring alert handling, CDD completion rates and quality, SAR decision documentation, training completion and assessment, and first-line application of responsible gambling procedures. Each of these monitoring activities should have a schedule, a methodology, documented outputs, and a clear escalation path when issues are identified.

The outputs of compliance monitoring should be reported to senior management and the board — not held within the compliance function as operational records. The board's ability to exercise governance over risk depends on receiving accurate, unfiltered information about how controls are performing. If compliance monitoring only ever produces positive findings, either the monitoring methodology is not robust or the reporting is being filtered before it reaches the board.

Governance structure review and gap analysis

Wise Key Solutions provides governance structure assessments for casino and gaming operators, identifying three lines implementation gaps and producing practical recommendations for remediation. Contact us to discuss your requirements.

Speak to our team →

This article reflects the operational perspective of the Wise Key Solutions founding team, drawing on experience across regulated gaming and financial services environments in the UK and Europe. It does not constitute legal or regulatory advice.