Table of Contents
ACAMS CAMS
Explore source-grounded summaries, flashcards, reference tools and realistic mock practice.
Quick answer: In the three lines of defence in AML, the first line owns and operates controls, the second line sets the framework and challenges performance, and the third line independently tests whether governance and controls work. Board and senior management remain accountable for the system as a whole.
The model is about role clarity, not three isolated departments. A control can fail when everyone assumes compliance owns it, when the second line performs the first line’s work, or when internal audit is asked to certify a process it helped design.
First Line: Own and Operate the Control
The first line includes business and operational teams that create or manage the risk. Their responsibilities can include:
- obtaining and maintaining customer information;
- operating onboarding and payment controls;
- identifying activity inconsistent with the expected profile;
- following escalation procedures;
- correcting process failures; and
- providing accurate records and data.
The first line should understand why the control exists, not simply complete a checklist. A relationship manager who treats due diligence as “compliance’s job” creates a visibility gap because the business often knows the customer and activity most directly.
Second Line: Framework, Advice and Challenge
The second line commonly includes AML, sanctions or wider AFC compliance functions. It may:
- translate applicable requirements into policy and standards;
- advise the business on risk and control design;
- oversee enterprise and customer risk assessment;
- monitor performance and emerging exposure;
- challenge decisions and exceptions;
- receive escalations; and
- report material issues to senior governance.
Challenge should be informed and evidenced. The second line should not approve weak activity merely because a form was completed, and it should not take over every operational decision in a way that removes first-line ownership.
Third Line: Independent Assurance
The third line assesses whether governance and controls are properly designed and operating in practice. The testing scope may include data, systems, files, decisions, escalation, training, issue management and prior remediation.
Independence is essential. A person cannot provide objective assurance over a control they own or perform. Where specialist knowledge is needed, the organisation can use qualified support while protecting the independence of the conclusion.
Interactive Playground
Explore our interactive learning tools below
Which CAMS knowledge point is defined or described by the following statement? Risk is dynamic and needs to be continuously managed, and the environment in which each organization operates is subject to continual change.
Board and Senior-Management Accountability
The three lines do not replace leadership. The board and senior management provide direction, approve governance, allocate resources, establish escalation access and require action on material weaknesses.
Risk appetite cannot authorise a breach of law or sanctions. It guides choices within lawful boundaries: which customers, products, markets and delivery channels the organisation is prepared to serve, under what controls and with what residual exposure.
Management information should distinguish activity from effectiveness. Training completion, alert counts and review volumes are useful operational measures, but they do not prove that staff understood the content, scenarios cover the material risks or investigations reached sound decisions.
A Control-Failure Example
Assume transaction-monitoring alerts are repeatedly closed with weak explanations.
- The first line should correct investigation quality, staffing, supervision and records.
- The second line should identify the pattern, challenge the closure standard, assess risk and escalate material weakness.
- The third line should independently test whether the redesigned process works and whether management addressed the root cause.
- Senior management should ensure ownership, resources and deadlines are clear.
If compliance rewrites every case itself, the immediate files may improve but the ownership problem remains. If audit designs the new workflow and later certifies it, assurance is weakened.
Outsourcing Does Not Remove Accountability
An organisation may use vendors for onboarding, screening, monitoring, data or investigation tools. Governance should address service scope, system and data access, jurisdiction, subcontracting, resilience, control performance, escalation and the ability to meet legal obligations.
The accountable organisation still needs to understand what the vendor does, validate outputs, manage changes and respond when the service fails. A contract cannot convert an ungoverned dependency into an effective control.
CAMS Exam Traps
- Compliance owns everything: first-line teams retain ownership of controls in their processes.
- Advice equals approval: clarify who has decision authority.
- Audit fixes the control: the owner fixes it; audit independently assesses the result.
- Policy equals effectiveness: test actual operation and outcomes.
- Completion equals learning: role-based training requires evidence beyond attendance.
- Outsourcing transfers responsibility: governance and accountability remain.
Link this model to the operational workflow in transaction monitoring alert investigation and to technology oversight in AML technology, AI and data quality.
For exam questions, first identify the actor, then ask whether the answer preserves ownership, challenge and independent assurance.
Frequently Asked Questions
1 What are the three lines of defence in AML?
The first line owns and operates business controls, the second line sets standards and provides oversight and challenge, and the third line supplies independent assurance over governance, design and operation.
2 Is compliance responsible for every AML control?
No. Business and operational teams remain responsible for controls embedded in their activities. Compliance establishes frameworks, advises, monitors and challenges without taking ownership away from the first line.
3 Why must internal audit remain independent?
Independent assurance cannot objectively assess a control it designed, owned or operated. Audit should evaluate governance, design and operating effectiveness without becoming part of the process it later tests.
4 Where do the board and senior management fit?
They sit above and across the lines by setting direction, approving risk appetite within legal limits, allocating authority and resources, receiving reporting and holding accountable owners to action.
5 Can a vendor become one of the lines of defence?
A vendor can perform activities or provide tools, but outsourcing does not automatically transfer the organisation's accountability. Ownership, oversight, access, performance, escalation and assurance still need clear governance.
Keep learning
Related Insights
Customer Due Diligence vs EDD: A CAMS Study Guide
Understand customer due diligence vs EDD, when deeper checks are justified, what evidence matters and how to avoid treating higher risk as prohibited.
AML Red Flags vs Suspicious Activity: What Is the Difference?
Learn how AML red flags differ from suspicious activity, what evidence an investigator should gather and when escalation becomes a defensible decision.
ACAMS CAMS Exam Guide: Current Domains, Format and Study Plan
Prepare for the ACAMS CAMS exam with the current four-domain weighting, 120-question format, official flashcards and a practical study plan.
Ready to Prepare for ACAMS CAMS?
Use source-grounded study tools and realistic practice to build accurate recall and exam-day confidence.
Explore Course Preparation