An Integrated System for Protection, Oversight, and Sustainability


"I firmly believe that governance is not just a set of procedures we execute, but a culture we live by, an awareness that protects capital, and a proactive behavior that precedes the crisis."

Crises do not start out big; they stem from small decisions whose deviations were not detected in time.

Therefore, a company’s survival relies on having a multi-tiered oversight ecosystem that does not depend on a single individual or a single department.

The Five Lines of Defense model ensures integration of roles, distribution of responsibility, independence of evaluation, smooth flow of information, and external oversight


The Ultimate Goal: Protecting capital, enhancing trust, and achieving sustainability.


Details of the Five Lines of Defense Model

1. The First Line of Defense: Executive Management

Process Owners and Execution Officers

  • The Role:
  • Executing operations in accordance with approved policies and procedures.
  • Managing daily risks within the boundaries of designated authorities.
  • Achieving operational objectives with efficiency and effectiveness.
  • Ensuring data quality and the integrity of reports.
  • Providing early notification of deviations and risks.


2. The Second Line of Defense: Risk Management and Compliance

Ensuring Compliance and Enterprise Risk Management

  • The Role:
  • Identifying and measuring key and emerging risks.
  • Developing policies, supervisory frameworks, and monitoring compliance.
  • Providing consultation and controls to mitigate risks.
  • Monitoring adherence to regulations, legislations, and standards.
  • Submitting risk reports and recommendations to senior management.


3. The Third Line of Defense: Internal Audit

Independent and Objective Evaluation of Company Controls and Operations

  • The Role:
  • Evaluating the effectiveness of governance, risk management, and internal controls.
  • Reviewing operations and systems independently to ensure their quality.
  • Providing recommendations for improvement and tracking their implementation.
  • Verifying data quality and information integrity.
  • Submitting periodic reports to the Audit Committee.


4. The Fourth Line of Defense: The Audit Committee and Board of Directors

Oversight, Accountability, and Sound Governance

  • The Role:
  • Overseeing the effectiveness of control systems, governance, and risk management.
  • Reviewing material reports and assessing the adequacy of internal controls.
  • Ensuring the complete independence of the internal audit function.
  • Supporting management in achieving objectives and managing risks.
  • Safeguarding the interests of shareholders and stakeholders.


5. The Fifth Line of Defense: External Auditor and Regulatory Authorities

Independent External Verification and Public Oversight

  • The Role:
  • Auditing financial statements and reports to provide independent assurance.
  • Verifying the fairness of disclosures and compliance methodologies with accounting standards.
  • Submitting reports to regulatory bodies in accordance with legal frameworks.
  • Regulatory bodies monitor compliance with laws to promote public interest.
  • Enhancing transparency and investor confidence in both the company and the markets.


What Does This Model Achieve?

  • Supporting Sustainability: And building long-term value.
  • Ensuring Compliance: With laws and standards while minimizing legal risks.
  • Improving Decision Quality: And raising performance efficiency and profitability.
  • Early Detection of Deviations: Before they escalate into major problems.
  • Enhancing Trust: Among investors, stakeholders, and the community.


"Governance is not an expense; it is an investment that protects capital, safeguards reputation, and shapes the future of the company."


By: Mohammed bin Saleh

Specialist in Management and Finance