Governance
The ERMF is built around a robust governance structure. The 'three lines of defence' are an important part of this structure, providing clearly defined roles and responsibilities.
First line: day to day risk management is delegated from the Board to the Group Chief Executive and, through a system of
delegated authorities and limits, to business managers.
Second line: risk oversight is provided by the Chief Risk Officer and Group Actuary and established risk management
committees. These management committees are supported by the specialist risk management and compliance functions across
the Group.
Third line: the Group Internal Audit function advises business managers on the extent to which the systems of risk management
and control are adequate and effective to manage business risks. It provides objective assurance on risk and control to senior
management and the Audit, Risk and Compliance Committee.



