The three lines of defence model is usually described for banks, where each line is a department with its own head: the Basel Committee's guidelines on money laundering risk place the business units in the first line, the chief AML officer and compliance function in the second, and internal audit in the third. A money transfer operator with 25 staff has a compliance team of two or three, an operations team that also answers the phone, and a board that meets quarterly. The model still works at that size, but only if you decide on purpose where the lines blur and what you do about it.
This guide is for founders, MLROs, compliance heads and operations leads at money transfer businesses of roughly 10 to 50 people. It covers who sits in each line, what each line owns for AML and fraud, a RACI table you can adapt, the segregation of duties that matters most, and the records that let an independent reviewer test it all. Where RemitSo's admin panel helps, we say so; designing the programme and making the judgement calls remains your team's job.
Understand what each line is for
The model splits responsibility for financial crime risk into three roles. The point is not the org chart. The point is that the people who run a control are not the only people who judge whether it works.
- First line: operations and the front office. The people who onboard customers, process transfers, release payouts and talk to customers. They own the risk in the work they do and they run the day-to-day controls.
- Second line: compliance and risk. The people who set the policy, design the controls, rule on what the first line escalates, file suspicious activity reports and monitor whether the first line is following the rules.
- Third line: independent review. An internal auditor or, in most firms this size, an external reviewer who tests whether the first two lines work, and reports to the board, not to the people being tested.
Above all three sits the board or senior management, which owns the firm's risk appetite and must act on what the third line finds. For a small MTO the practical question is simple: can you show who runs each control, who checks it, and who checks the checkers?
A useful test: for any control, name the person who performs it, the person who reviews it, and the last time someone independent of both looked at it. If one name fills two of those three slots, you have found a blurred line. That may be acceptable, but it should be written down.
Decide what the first line owns, not just what it does
In a small MTO the first line is usually customer service and onboarding, payments and treasury, and any agents or branch staff. Their AML and fraud duties are not optional extras on top of "real" work. Collecting the right document at the right point, noticing a customer who suddenly sends to six new recipients, refusing to release a payout whose details look wrong: these are the controls.
What the first line should own:
- Customer due diligence as it happens. Collecting identity documents, checking they are readable and match the profile, and escalating anything that does not fit.
- Transfer handling. Working the queues of transfers that need action, chasing missing documents and keeping customers informed.
- Payout release. Making sure what goes out matches what was approved.
- Spotting and escalating. Raising internal reports of unusual activity to the MLRO or nominated officer, quickly and in writing.
What the first line should not own: deciding whether a possible sanctions match is a true match, changing the rules that decide which transfers are held, or deciding whether to file a suspicious activity report. Those belong to the second line, because the first line has a natural interest in getting transfers moving.
Give the second line the decisions and the rulebook
In a firm of 10 to 50 people the second line is often the MLRO plus one or two analysts, sometimes with a part-time risk lead. It sets the policy and owns the judgement calls.
- The firm-wide risk assessment and the customer risk assessment that flows from it.
- The rules. Transaction limits, document thresholds, risk rules and watch lists. Changes should be deliberate, recorded and explained.
- Decisions on escalations. Sanctions matches, held transfers, enhanced due diligence and unusual activity reports from the first line.
- Suspicious activity reports. Deciding whether to file, filing, and keeping the record of decisions not to file.
- Monitoring the first line. Sampling onboarding files, checking queues are worked on time, and checking training is complete.
The second line also needs a view of the whole programme in one place. We cover what goes on that view in how to build a compliance dashboard, and how to run cases from alert to closure in AML investigation and case management.
Make the third line independent, even if you buy it in
Very few MTOs of this size employ an internal auditor. That is fine. Independent review can be an external firm or consultant engaged for a periodic review of the AML programme, reporting to the board or a non-executive director. What matters is that the reviewer did not design or run the controls they are testing.
A useful independent review of an MTO tests, at minimum:
- whether the risk assessment reflects the corridors, products and customers the firm actually has;
- whether a sample of onboarding files meets the firm's own policy;
- whether a sample of sanctions decisions was reasonable and recorded;
- whether rule changes were approved and match the policy;
- whether internal reports reached the MLRO and were decided on, including those not filed;
- whether training was completed and signed off by someone other than the trainee;
Most of those tests depend on records. If the review has to rely on what people remember, it is testing memory, not controls. Preparing for this is covered in your first regulatory audit.
Map activities to lines with a RACI table
A RACI table names, for each activity, who is Responsible for doing it, who is Accountable for it, who is Consulted and who is Informed. Adapt the version below and keep it as a controlled document: an independent reviewer will compare it with how people actually work.
| Activity | Line 1: operations and front office | Line 2: compliance and risk | Line 3: independent review | Board |
|---|---|---|---|---|
| Firm-wide risk assessment | C | R | I (tests it) | A |
| AML policy and procedures | C | R | I (tests it) | A |
| Collecting ID and documents | R | A | — | — |
| Approving or rejecting KYC documents | R (standard cases) | A (and R for higher risk) | I (samples) | — |
| Ruling on possible sanctions matches | I | R/A | I (samples) | I (confirmed matches) |
| Setting transaction limits and document tiers | C | R/A | I (tests changes) | I |
| Changing risk rules and watch lists | C | R/A | I (tests changes) | — |
| Working held transfers and document requests | R | A | — | — |
| Internal unusual activity reports | R (raises) | A (decides) | I (samples) | — |
| Filing suspicious activity reports | — | R/A | I (tests process) | I (numbers only) |
| Releasing approved payouts | R | I | — | — |
| Assigning and signing off training | R (completes) | A (assigns and signs off) | I (tests records) | I |
| Granting staff access | C (requests) | C | I (tests) | A (via admin owner) |
| Periodic independent review | C | C | R | A |
Two choices in the table matter more than the rest. First, the second line both writes the rules and rules on the matches they produce, so the third line must test rule changes specifically. Second, the board is accountable for the independent review, not the MLRO. If the MLRO commissions and receives the review, it is not independent of the person it is mainly reviewing.
Spot where small teams blur the lines
Blurring is normal at this size. The risk is blurring nobody has noticed. Common patterns:
- The founder-MLRO. The person responsible for growth is also the person who decides whether a large customer is suspicious. Commercial pressure lands directly on the compliance decision.
- The compliance officer who works the queues. When operations is short-staffed, compliance clears document requests itself, then reviews its own work at month end.
- The operations lead who edits rules. Limits are loosened "temporarily" to clear a backlog, without a second-line decision or a record of why.
- The consultant who wrote the policy and then audits it. Convenient, and not independent.
- The administrator with everything. One technical person can grant access, change rates and see every customer file.
Watch for: blurred lines that appear only under pressure. A firm can look well separated on paper and still let operations clear sanctions hits during a holiday week. Check what happened during the busiest and quietest weeks of the year, not just an ordinary Tuesday.
Keep the critical duties apart, and compensate where you cannot
You cannot separate everything with 15 people. Separate the duties where one person acting alone could cause the most harm, and add a compensating review where you cannot.
| Duty pair | Why it matters | If one person must hold both |
|---|---|---|
| Changing a rule / ruling on what it catches | Someone can loosen a rule so a known customer passes | Third line reviews every rule change against the change history quarterly |
| Onboarding a customer / approving their higher-risk documents | The person under pressure to onboard decides the risk | Second line samples approvals each month |
| Raising an unusual activity report / deciding not to file | Reports can disappear quietly | Log every internal report and its outcome; board sees counts |
| Completing training / signing it off | Training records become self-certified | Not acceptable; always use a second person |
| Granting access / using sensitive functions | An administrator can give themselves anything | Quarterly access review by someone outside technology |
For the full role design, including how to build roles from permissions, see role-based access control for money transfer operators.
Scenario: one quarter in a 25-person MTO
The firm, people and numbers here are illustrative, not drawn from any real operator.
The firm has 25 staff, including an MLRO and one compliance analyst, eight in customer service and onboarding, and four in payments and treasury. An external consultant does an annual AML review for the board.
Week 2. The onboarding team sees a run of new customers sending to the same small group of recipients. An onboarding agent raises an internal report. The MLRO reviews it, finds linked patterns, and decides to file one suspicious activity report and to watch two further customers. The decision, including the two not filed, is recorded.
Week 5. Operations asks for a higher document threshold on one corridor because customers are dropping off. The MLRO agrees to a smaller change than requested and records the reason. The rule's change history shows who changed it and when.
Week 8. The compliance analyst is on leave. A possible sanctions match comes in. Operations can see the transfer is held, but its roles carry no right to rule on a screening match. The transfer waits until the MLRO rules, the next morning.
Week 12. The external reviewer arrives. They sample 30 sanctions decisions, 20 KYC approvals, every rule change in the quarter, and the training records. They find that four of the 20 approvals were made by the analyst on files the analyst had also onboarded during a staff shortage. The board accepts the finding; the firm now routes those files to the MLRO.
What the scenario shows: the first line spotted the pattern and escalated, the second line decided and wrote down why, access rights stopped operations from clearing a sanctions hit under pressure, and the third line found a blurred line the firm had not noticed. Every step was testable because it left a record.
Know which records each line produces
The third line can only test what the first two lines recorded. Before your next review, check that you can produce:
- Each person's role and access rights, and when they last signed in.
- Every sanctions screening decision, with who decided and when.
- Every KYC approval and rejection, with reasons.
- The change history of AML rules and limits, with who changed them.
- Internal reports and suspicious activity reports, including decisions not to file.
- Training assignments, completions and sign-offs by a second person.
For the case for keeping these records, see why audit logs are critical for remittance compliance.
Doing it with RemitSo
RemitSo's admin panel gives each line its own view and keeps the records the third line tests. See the admin features.
- Seven pre-set departments (Senior Management and Board; Compliance; Customer Service and Onboarding; Payments and Treasury; Finance; Technology; Agents and Branch Staff): map your lines to real teams from day one.
- 89 permissions grouped into roles with parent roles: give operations the queues and compliance the decisions, without one all-powerful role.
- Screens granted part by part: operations sees Scout's transfer and payout figures without the compliance queues; a board member sees Compliance Dashboard screening figures without the customer worklist.
- Screening decisions recorded per officer: sanction lookup shows every screening, what it matched and what an officer decided, so the third line can sample rulings.
- AML rules with a history of changes, showing who last changed each rule: rule changes become testable rather than a matter of memory.
- Suspicious activity reports generated, managed and submitted from the console: the second line's filing record sits next to the transactions behind it.
- Training where nobody signs off their own (an optional add-on), with department heads told when someone falls behind: signed records instead of self-certification.
- Login sessions with MFA status for every staff sign-in: evidence that access controls hold.
Your team still decides who sits in which line, writes the policy, makes the compliance judgements and engages an independent reviewer.
Read the release notes, or book a demo to see how roles, screening decisions and rule history fit your team structure.
Sources
Checked October 2026. Regulations change; confirm current requirements with the regulator or your adviser.
Frequently asked questions
Do we need an internal audit function to have a third line?
No. Most MTOs of this size use an external reviewer or consultant. What matters is independence: they must not have designed or run the controls they test, and they should report to the board.
Can our MLRO also run operations?
It happens in very small firms, but it puts commercial pressure on compliance decisions. If you cannot avoid it, have the board or a non-executive review the MLRO's key decisions, and make sure the independent review tests them specifically.
Which line owns AML risk?
The first line owns the risk in its day-to-day work and runs the controls. The second line sets the policy, makes the compliance decisions and monitors the first line. The third line tests both. The board owns the firm's risk appetite overall.
How often should the third line review the AML programme?
Many firms review annually, and more often after a significant change such as a new corridor, product or ownership. Check your supervisor's expectations and record the frequency in your policy.
What is the first segregation of duties to fix in a small team?
Separate whoever changes AML rules and limits from whoever is under pressure to move transfers, and make sure nobody signs off their own training. Then add a regular independent look at rule changes and sanctions decisions.