Nordiska's three lines of defence
Three lines of defence
The Board of Directors has the ultimate responsibility for limiting and monitoring risk exposure within Nordiska. In order for us to have an effective organisation with clear roles and areas of responsibility within risk management and internal control, we follow the principle of three lines of defence.
Together, the three lines of defence form the framework for internal control, which will develop and maintain systems so as to ensure:
- Effective and efficient business operations
- Adequate risk control
- Business governance
- Reliable financial and non-financial reporting (both internal and external)
- Compliance with applicable regulations
The first line of defence
The first line of defence consists of the CEO and the employees of the who are involved in the creation and selling of products and services, or operationally supporting customers, products and services. They are responsible for ensuring that operations are managed within the framework of established risk exposure and internal control, as well as in accordance with established external and internal rules that apply to Nordiska.
The first line of defence has a well-functioning governance model and an effective process to identify, measure, evaluate, monitor, minimise and report risk.
The second line of defence
The second line of defence consists of the Risk Control and Compliance.
Compliance shall constitute a support for the Board of Directors, the CEO and the operational activities to ensure the regulatory compliance within Nordiska. Risk Control is responsible for checking that all significant risks to which Nordiska is exposed to, or may be exposed to, are identified and managed by the relevant functions and controls. They are also responsible for ensuring that the internal regulations are appropriate and effective and that changes are proposed where necessary.
Furthermore, the Risk Control must support and verify that the business implements the requirements set out in external regulations and continuously work for and contribute to a good risk awareness within the organisation.
The independence of the functions is ensured by the fact that they are not carried out by those whom are involved in the day to day business activities. This means that the functions may not be part of Nordiska's business operations.
The third line of defence
The third line of defence consists of the function for internal audit.
The function for internal audit is the Board's tool for meeting the requirements for a good and effective internal governance and control and is in this context organisationally separate from Nordiska's other functions and operations.
The internal audit function is responsible for reviewing and regularly evaluating whether internal control is effective and appropriate. Within the framework of the assignment, the function for internal audit shall, among other things, review and regularly evaluate the company's risk management, compliance with regulations, financial information and the second line of defence.