Three Lines Model

Also known as: Three Lines of Defense

framework · governance and compliance · organizing-schema

IIA framework distinguishing operational management, risk and compliance functions, and internal audit assurance.

The Three Lines Model articulates the division of risk management responsibilities across an organization, distinguishing operational management (first line, owning and managing risks within the business), risk and compliance functions (second line, providing policy, oversight, and challenge), and internal audit (third line, providing independent assurance to the governing body). The Institute of Internal Auditors codified the older 'Three Lines of Defense' framing in a 2013 position paper that became widely adopted in financial services governance, and substantially updated it in 2020 as the 'Three Lines Model' — dropping the militaristic 'defense' metaphor, emphasizing collaboration over rigid line boundaries, and explicitly bringing in the governing body and external assurance providers. Adoption is widespread but the model remains a conceptual organizing schema rather than a binding standard, and implementation varies considerably across institutions.

Originators

Institute of Internal Auditors (IIA) high

Year / Decade

2013 (Three Lines of Defense position paper); 2020 (Three Lines Model update) high

Primary sources

IIA (2013). The Three Lines of Defense in Effective Risk Management and Control, IIA (2020). The IIA's Three Lines Model: An update of the Three Lines of Defense high

Band notes

2020 IIA update renamed and refined the older 'Three Lines of Defense' framing; conceptual framework rather than a codified standard.

Core components

Primary use case

Organizing risk and assurance responsibilities in financial institutions and large enterprises; common reference in regulatory expectations for risk governance.

Common criticisms

Lineage

Siblings
COSO ERM, ISO 31000, COSO Internal Control-Integrated Framework