In practice · 03 of 09
We cannot prove this to the regulator.
The second line of defence has no independent evidence, so it ends up asking the first line it is supposed to be challenging.
The circularity nobody says out loud
Three lines of defence assumes the second line can test the first. In technology it frequently cannot, because the only people who know how a control is actually implemented are the people who implemented it. So the challenge function sends a questionnaire to the team it is challenging, receives an answer, and reports the answer upward as assurance.
Everybody involved knows this. It survives because the alternative has historically been expensive: an audit team rebuilding the picture by hand, system by system, over months. And because it takes months, the picture is stale on the day it is delivered. The organisation then does it again next year, from scratch, at the same cost.
Where policy and implementation drift apart
The interesting question is not whether a control exists on paper. It is where the control logic actually sits. In a long-lived estate those two answers separate slowly and without anyone deciding they should.
- A validation described in policy as a single control is implemented in four places, three of which agree.
- A limit that governance believes is configurable is compiled in.
- A control retired two years ago is still enforced by a job nobody owns.
- A rule that policy locates in one system is actually enforced by a downstream consumer that was never in scope for the review.
None of these are misconduct. They are the ordinary residue of twenty years of change. They matter because each one is a finding waiting to happen, and because a supervisor asking "how do you know" is entitled to an answer that does not begin with "the team told us".
A record that refreshes rather than being rebuilt
We locate where control logic actually sits against where policy says it sits, from the systems themselves rather than from a questionnaire, and leave a record that can be refreshed rather than reconstructed. The distinction matters more than it sounds. A rebuilt picture is a project every time and is out of date on arrival. A refreshed picture has a marginal cost and a date on it.
That record is also what makes the second line's challenge real. It gives the challenge function an independent starting position, which is the thing the model always assumed it had.
Independence is now the regulatory point, not a preference. Nobody can credibly assure a transition they are also delivering. When a supervisor asks how you knew a transition was safe rather than reported as safe, the answer has to come from somewhere that is not the delivery party. Any firm that both delivers the change and assures it has a problem the moment that question is asked.
Dated obligations change the shape of the work
An obligation with a date attached, operational resilience regimes among them, converts an open-ended improvement into a deadline with an evidence requirement. That changes what good looks like. The deliverable is not a better understanding, it is a dated, attributable record that survives being questioned, and a repeatable way of producing the next one.
Common questions
We already have an audit function. What is different here?
Internal audit reports to the board and is rightly bounded by its own independence rules and its own cycle. This is not a replacement for it. It is the independent evidence base that both the second line and internal audit currently have to construct by hand, produced once and kept current, so that the challenge is about interpretation rather than about whose spreadsheet is right.
Does the evidence hold up under supervisory questioning?
The test we design for is a specific one: a supervisor asking how you knew a transition was safe rather than reported as safe. That means the record has to be dated, attributable to a party independent of delivery, and reproducible. If it cannot survive that question it has not been built properly.
Does any of our source code or data leave our environment?
No. Analysis runs inside your own tenant or on your premises, air-gapped where required, and with your own model if you prefer one. Source code does not leave and is not used to train anything. For several of the institutions this work suits, that is the entry condition rather than a feature.
When this comes up. Comes up after a regulator finding, before a scheduled audit, or against a dated obligation such as DORA.
How it is delivered
Vault is the centre of gravity here, with Compass to establish the starting position and Watch to keep the record current between audits. Each module is a fixed deliverable behind a go or no-go gate, and the baseline earns the design. The full set of modules is here.
Related situations
- Independent estate assessmentBuild the estate picture independently, and separate what is locked in from what is portable.
- Technology and software due diligenceRead the estate inside the deal window instead of sampling it.
- Legacy modernisationRetire the dead logic before the programme commits to carrying it.
Tell us what you are trying to land.
A short conversation about your situation and whether an independent accountable role is the right instrument. If it is not, we will say so. No deck follows automatically.