Back to all articles
Operational Risk

The Three Lines of Defence Model Doesn't Work for SMEs — Unless You Adapt It

Why the textbook three lines model collapses in a £20m PE-backed business, and the practical adaptation that restores genuine independent assurance.

The three lines of defence model is one of the most widely referenced frameworks in risk management. It's also one of the most poorly applied, particularly in businesses with fewer than 250 employees.

The model makes sense in theory. The first line owns and manages risk through day-to-day operations. The second line oversees risk and compliance. The third line provides independent assurance through internal audit. In a large bank or a listed corporate, the separation is clean: you have a front office, a risk function and an independent internal audit team.

In a £20m PE-backed business with a Finance Director, a Financial Controller and a team of four, the model breaks down almost immediately. The Finance Director is simultaneously first line (processing journals, managing the close), second line (reviewing controls, signing off reconciliations) and third line (providing assurance to the board). The independence that makes the model work has collapsed entirely.

The response most smaller businesses take is to ignore the model altogether. That's the wrong answer. The right answer is to adapt it.

Why the Model Matters Even When It's Imperfect

Before we talk about adaptation, it's worth understanding why the three lines model exists and why it matters even at smaller scale.

At its core, the model is about ensuring that someone independent is asking whether the controls that are supposed to be operating are actually operating. Without that independent check, problems compound silently. The journal that shouldn't have been processed. The approval that was bypassed once, then routinely. The access that was granted temporarily and never revoked. None of these will surface through normal operational activity, because the people running normal operational activity are the same people who created or perpetuated the problem.

In a large organisation, internal audit provides that independent check. In an SME, you need a different mechanism — but you still need the mechanism.

What Adaptation Actually Looks Like

Separate first and second line duties wherever possible. Even in a small team, there are usually opportunities to create separation between the person who processes a transaction and the person who reviews it. Monthly bank reconciliations reviewed by the FD rather than the FC who prepared them. Expense claims approved by a line manager before finance processes them. Purchase orders raised by operations and approved by finance. These aren't onerous — they're basic control hygiene that creates the separation the model requires, at SME scale.

Use the board and audit committee as a genuine third line. Too many SME boards treat the audit committee as a rubber stamp for the external audit process. A properly functioning audit committee — even a small one — can serve as an effective third line by reviewing management accounts critically, asking pointed questions about control exceptions, following up on audit findings and maintaining independent relationships with the external auditors. This requires the Finance Director to be genuinely transparent with the committee, including about weaknesses, not just successes.

Commission periodic independent reviews. When your organisation is too small to support a dedicated internal audit function, periodic external reviews fill the gap. A pre-audit readiness assessment, an ITGC review, a controls walk-through by an independent specialist — these are not expensive when done proportionately, and they provide something your internal team cannot: an objective, external view of whether your controls are designed appropriately and operating effectively.

Document what the model looks like for your business. This might seem bureaucratic, but it serves a practical purpose. When you can show your board, your auditors or a potential acquirer a clear picture of who owns what risk, who provides oversight and where independent assurance comes from, you demonstrate governance maturity. For PE-backed businesses preparing for exit, this kind of documented risk framework is increasingly expected by buyers' due diligence teams.

The Specific Risks of Getting This Wrong

Two categories of failure are particularly common in SMEs where the three lines model has collapsed.

The first is management override. When the Finance Director effectively operates across all three lines, the business has no mechanism to detect — let alone prevent — situations where management overrides controls. This doesn't require deliberate misconduct. It simply requires a well-intentioned Finance Director who, under time pressure, bypasses a control once and then normalises it. External auditors are trained to look for management override risk; a collapsed governance structure elevates it significantly.

The second is single points of knowledge. In businesses where one person understands both the operational and risk dimensions of a process, their departure creates an immediate control gap. The knowledge of what the controls are, how they operate and where the exceptions sit leaves with them. This is a resilience risk as much as a governance risk — and it's one that a properly documented three lines framework helps mitigate.

Starting Point for Finance Directors

If your risk framework is currently informal — policies exist but accountability is fuzzy, control ownership isn't documented, and the board receives assurance primarily through the Finance Director's confidence rather than through independent verification — the starting point is a frank assessment of where the gaps are.

That assessment should answer three questions: What are the key risks in the business? For each risk, who owns the first and second line response? And where does independent assurance over that response come from?

The answers won't always be comfortable. But they're far more useful than a three lines diagram that describes a large bank's governance model and has no bearing on how your business actually operates.