BLITZ RESEARCH

SBV Circular 83: Having Three Lines of Defence Is Not the Same as Being Able to Evidence Them

7 September 20267 min readGovernance, Compliance, Vietnam

Vietnamese banks already know the three-lines-of-defence model. Circular 83 raises a harder question: can a bank show how those lines actually worked when a real risk decision was made?

Summary

Circular 83/2025/TT-NHNN was issued by the State Bank of Vietnam on 31 December 2025 and took effect on 1 July 2026. Article 4(2) requires the internal control system of commercial banks and foreign bank branches to have three independent lines of defence, and Article 8 requires a management information system to collect, process, store and provide information for decision-making.

Vietnamese banks are already familiar with the three-lines model, so this paper examines a narrower operational question: when a material risk decision was made, can the bank show who acted, under what authority, where independent review occurred, and what evidence remains?

The decision-level evidence test set out here is proposed by Blitz Research. It is not an additional requirement of Circular 83, and this paper is not legal advice.

Vietnamese banks are already familiar with the three-lines-of-defence model. Circular 83/2025/TT-NHNN does not introduce the concept from scratch. It places the model inside a more detailed internal-control framework and makes the responsibilities of the three lines explicit.

The more useful question is therefore not whether a bank has three lines on its organisation chart. It is whether the bank can show how those lines worked when an actual risk decision was made.

Can the bank reconstruct who acted, under what authority, where independent review occurred, and what evidence remains?

This paper examines that question. It distinguishes the requirements stated in Circular 83 from an operational test proposed by Blitz Research. The test is not presented as an additional SBV requirement.

1. Start with what Circular 83 actually requires

Circular 83 was issued on 31 December 2025 and took effect on 1 July 2026. It regulates the internal control systems of commercial banks and foreign bank branches.

Article 4(2) requires the internal control system to have three independent lines of defence.

The first line consists of risk-taking units, including units generating revenue, making risk decisions, allocating risk limits and carrying out other activities that create risk. Its role includes identifying, controlling, monitoring and mitigating risk.

The second line includes at least the compliance and risk management functions. It develops risk-management policies and internal rules and measures, monitors and controls risk across the bank.

The third line is internal audit.

This is an organisational and control requirement. Circular 83 does not say that the three lines must be implemented through a particular software platform.

2. The Circular also puts weight on information

The three-lines requirement should be read together with the Circular's requirements for management information.

Article 4 requires a management information system that provides reliable, complete and timely management information. Article 8 goes further. It requires the bank to establish a management information system to collect, process, store and provide information for management, administration and decision-making.

Article 8 also refers to responsibilities for managing and using the information system, processes for collecting and storing information, data used for decision-making, internal reports, technology infrastructure and backup arrangements.

This matters because a control structure is difficult to assess if the information showing how it operated is incomplete or scattered.

3. Appendix I turns structure into an assessment question

Appendix I is particularly useful when considering what implementation means in practice.

The self-inspection and assessment report requires a bank to describe its control activities according to the three-lines principle. It also calls for assessment of internal regulations, compliance with those regulations, the results of self-inspection and assessment, and the management information system.

This does not create a requirement for an end-to-end digital record of every decision.

It does, however, raise a practical evidence question. If the bank is required to assess how its control activities operate, what evidence is available to support that assessment?

4. The difficult part may be the hand-off

A three-lines model can be clear at organisational level and still become difficult to follow at transaction or case level.

Consider an investigation or other material risk matter. The original event may arise in one system. Customer or transaction information may sit elsewhere. An investigator may record findings in a case-management system. A supervisor may approve an action in another workflow. Compliance or risk may intervene later. Some discussion may take place outside the main system.

None of this necessarily means the control framework is deficient. Banks operate complex technology environments.

The problem appears when the bank later needs to establish how responsibility moved through that environment.

The hand-off is therefore worth testing: when responsibility moved from one person or function to another, did the control obligation move with it in a clear and traceable way?

5. A decision-level evidence test

Circular 83 does not use the term 'decision lineage'. The questions below are therefore an operational test proposed by Blitz Research, not a statement of the regulation.

  • Who made or initiated the decision?
  • What role and authority did that person hold at that time?
  • What policy, procedure or internal rule applied?
  • Was independent review, challenge or approval required?
  • If it was required, who performed it and when?
  • What caused an escalation or exception?
  • If normal procedure was overridden, who authorised the override and why?
  • Can the sequence be reconstructed later without relying mainly on memory, email searches or manual interviews?

A bank may already be able to answer these questions using its existing systems and controls. If so, there may be no additional technology problem to solve.

If it cannot, the weakness may not be in the three-lines structure itself. The weakness may be in the evidence connecting the structure to actual operations.

6. Evidence is not the same as centralisation

It would be easy to jump from this problem to the conclusion that banks need one central system containing every decision. Circular 83 does not say that, and operationally it may not be necessary.

Evidence can remain distributed. The more important issue is whether the relevant records can be connected reliably enough to establish what happened.

For example, a bank may keep the alert in one system, the investigation in another and the approval in a third. That arrangement may still be workable if identity, authority, policy, review, escalation and outcome can be reconstructed with sufficient reliability.

The issue is therefore not necessarily system consolidation. It is control continuity across the systems involved.

7. What Circular 83 does not require

  • It does not require a decision-governance platform.
  • It does not require every decision to be stored in one central repository.
  • It does not prescribe a specific case-management or workflow architecture.
  • It does not state that technology itself establishes independence between the three lines.
  • It does not expressly create a requirement called 'decision lineage'.

These distinctions matter. Technology may support the internal-control environment, but the regulatory obligation belongs to the bank's governance and control framework.

8. A practical test banks can perform

One way to examine the issue is to work backwards from completed material decisions rather than starting from policies or organisation charts.

  1. Select a small sample of completed material cases or decisions.
  2. Reconstruct each case from initiation to final outcome.
  3. Identify every person, function and system involved.
  4. Map the interventions to the relevant line of defence.
  5. Check the authority held by each person when the action occurred.
  6. Identify where independent review or challenge was required and locate the evidence that it happened.
  7. Record every point where the sequence cannot be established without assumption, manual reconciliation or interviews.

This exercise does not establish compliance with Circular 83. It is a narrower operational test: whether the bank can observe its documented control model in actual decisions.

9. Why this question becomes harder as banking automates

Automation does not remove the three lines. It can, however, change where decisions occur.

A decision may be initiated by a rule, model or automated process, reviewed by a human, escalated by another system and finally approved by a different function. The more distributed that process becomes, the less useful it is to rely only on the organisation chart to understand accountability.

Circular 83 itself recognises model risk as an area requiring three independent lines of defence. That does not mean all automated decisions fall under the model-risk provisions. It does show that the Circular treats separation of responsibilities as relevant even where models are involved.

For banks increasing their use of automation and AI, the practical issue will increasingly be whether authority and oversight remain visible as decisions move between systems and people.

10. The question worth asking

The three lines of defence are normally discussed as an organisational model. Circular 83 keeps that structure but places it within a wider framework of internal control, management information, self-assessment and senior-management oversight.

That suggests two different questions.

Structure: Do we have three independent lines of defence?

Evidence: Can we show how those lines operated when an actual decision was made?

The first question is familiar. The second may reveal more about how the control framework works in practice.

Research note

This paper discusses selected operational implications of Circular 83/2025/TT-NHNN. It is not legal advice. Where this paper refers to a decision-level evidence test, control continuity or reconstruction of a decision, these are Blitz Research interpretations and not terms presented as explicit requirements of Circular 83.

Banks should assess the official Vietnamese text of Circular 83 against their own organisational structure, internal policies, systems and regulatory obligations.

Primary references

  • State Bank of Vietnam, Circular 83/2025/TT-NHNN, issued 31 December 2025, effective 1 July 2026.
  • Article 4 — Requirements for the internal control system, including three independent lines of defence and management-information requirements.
  • Article 8 — Management information system.
  • Appendix I — Report on results of self-inspection and assessment of control activities.
  • Article 56(7) — Three independent lines of defence for model risk management.

Discuss your institution’s governance journey

Talk to our team about operationalising Circular 83/2025 in your environment.

Contact an expert