The three lines of defence model — business operations, risk oversight, internal audit — is close to universal in financial services, and in most institutions I've reviewed, it has quietly stopped functioning as designed. Not because the model is wrong, but because ownership within each line drifts after every reorganisation, and nobody updates the governance documentation to match.
The pattern is consistent: a control gets assigned to a named role. That role gets restructured eighteen months later, and the control's ownership is informally absorbed by whoever seems closest to it, without a formal reassignment. Multiply this across a decade of reorganisations and most institutions have controls whose documented owner and actual owner have diverged, sometimes considerably.
This is invisible until it fails. Audit reviews check whether a control is documented, not whether its documented owner is genuinely engaged with it in practice — and a control can pass a documentation review while being functionally unowned.
The fix isn't a fourth line of defence, which is the reflexive response I see most often. It's a recurring, structured exercise — not an annual tick-box review, but a genuine re-verification — that checks whether each control's documented owner can describe, specifically, what they did to exercise oversight in the last quarter. If they can't, the control is theatre regardless of what the org chart says.
Risk theatre is comfortable because it looks identical to risk culture on paper. The difference only shows up when something actually fails, and by then it's too late to have the conversation calmly.