Three Lines of Defense for AI: Who Owns the Numbers When the Model Is the Author
When an AI agent writes the figure, the three-lines model breaks unless you reassign who owns assumptions, who validates, and who audits the trail.
By The Rexfin team
A controller signs the quarterly pack. That signature has always meant something specific: I own these numbers, I can defend every line, and I know where each one came from. Now an agent drafted the variance commentary, pulled the figures, and computed the ratios. The controller still signs. But who actually owns the number?
This is the question the three-lines-of-defense model was never built to answer, and it is the one keeping risk committees up at night going into 2026.
A framework that assumed a human author
The three lines model is the backbone of governance in financial services. The Institute of Internal Auditors formalized it in 2013 and refreshed it in 2020, and the structure is simple enough to recite from memory. The first line owns and manages risk in the business. The second line, risk and compliance, frames, oversees, and challenges. The third line, internal audit, provides independent assurance that the first two are doing their jobs.
It works because of an unstated assumption: a person made the number. When a financial analyst builds a forecast, you can ask them why they assumed 4% churn. When the FP&A team computes adjusted EBITDA, you can trace the formula to a sheet someone wrote. Accountability flows to a name.
An LLM breaks that chain. The model is now, in effect, the author of the output. It selected the figures, applied the reasoning, and produced the commentary. It cannot own anything. It cannot be challenged in a meeting, it does not remember why it chose one assumption over another between runs, and it will produce a slightly different answer next Tuesday if you let it do the math. Drop a non-deterministic author into a framework that assumed a human one, and the lines blur exactly where they need to be sharpest.
Where each line actually fails
Run through the three lines with an agent in the loop and the cracks show up fast.
The first line was supposed to own assumptions. When a planner sets a growth rate, ownership is obvious. When an agent infers a growth rate from prior periods and surfaces it inside a forecast, who owns that assumption? The business user who accepted the output without seeing the assumption? The data team that wired up the connection? Nobody, usually, which is the problem. The assumption gets owned only after it turns out to be wrong.
The second line was supposed to validate. Validate what? The classic playbook validated a model you could open and inspect. You cannot inspect the weights of a vendor LLM, and even if you could, last quarter’s validation tells you little about this quarter’s output because the same prompt can yield a different number. Validation has to move from the model to the output: what did the system retrieve, what did it compute, and does that tie out to the ledger?
The third line was supposed to audit the trail. With a human, the trail is the workpaper. With an agent answering in natural language over PDFs and spreadsheets, there often is no trail. The agent said revenue grew 18%. From which source? Computed how? An auditor who cannot replay the number cannot assure it, and “the AI said so” is not an audit position anyone will sign.
The fix is architectural, not a new policy memo
You can rewrite the RACI chart all you like. If the underlying system cannot tell you where a number came from and how it was computed, the three lines have nothing to defend. The reassignment of ownership only sticks when the architecture makes ownership observable.
That means three things have to be true before the governance model can hold:
- Every figure traces to source. Not “the model summarized the 10-K,” but this number equals this line in the ledger, with lineage you can click through. Traceability is what lets the first line own an assumption instead of discovering it later.
- The math is deterministic and replayable. The same inputs produce the same figure every time, computed by an engine rather than predicted by the language model. This is what gives the second line something stable to validate and the third line something to replay.
- The reasoning and the arithmetic are separated. The LLM is allowed to reason, phrase, and explain. It is not allowed to do the calculation. The moment the model computes the ratio, you have handed it authorship of a number nobody can defend.
This is the design Rexfin is built around. It connects to your accounting and financial-data platforms (QuickBooks, Xero, NetSuite, Sage, SAP, Oracle, your warehouse) or to uploaded statements, and builds one reconciled financial model that ties out to the ledger. The AI retrieves figures from that model and runs every calculation through a deterministic engine, not the LLM. What-if scenarios live in versions on top of the reconciled base, never in the base itself. Each answer carries its lineage back to source.
Put that underneath the three lines and the ownership questions get answers again. The first line owns assumptions because the assumptions are explicit and visible, not buried in a model’s hidden reasoning. The second line validates outputs against a reconciled ground truth instead of squinting at weights it cannot see. The third line replays any number the same way it would re-check a formula, because the figure was produced deterministically and carries its trail.
What this does not solve
Architecture does not absolve anyone. A reconciled, traceable layer makes ownership possible; it does not assign it. You still have to decide which human owns each assumption, who signs off on the validation cadence, and what the agent is allowed to do unsupervised versus what needs a person in the loop. Those are governance decisions, and they belong to your risk committee, not your vendor. What the layer changes is whether those decisions are enforceable or merely aspirational.
It also will not make a bad assumption good. If the growth rate is wrong, deterministic math will compute the wrong forecast perfectly every time. The point of traceability is not correctness; it is accountability. You can find the wrong assumption, see who owns it, and fix it before it reaches the board.
The takeaway
The three lines of defense still work for AI in finance, but only after you accept that the model is the author and rebuild the foundation so authorship can be traced back to a human. Ownership of assumptions, validation of outputs, and audit of the trail all collapse onto the same requirement: a reconciled numbers layer where every figure traces to source and every calculation is deterministic. Get that right and the framework holds. Skip it, and you are signing numbers no one can defend.
Worth reading next on how validation changes when you cannot see the weights: output-based validation for vendor LLMs, and the broader shift in the 2026 model-risk framework. The whole pillar on governing AI in finance sits one level up.
If you want to see traceable, deterministic numbers under your own three lines, book a demo and bring a figure you currently cannot prove.
Part of Governing AI in Finance: Model Risk, Controls, and Validation for the LLM Era