Three Lines Model
Also known as: Three Lines of Defense
IIA framework distinguishing operational management, risk and compliance functions, and internal audit assurance.
The Three Lines Model articulates the division of risk management responsibilities across an organization, distinguishing operational management (first line, owning and managing risks within the business), risk and compliance functions (second line, providing policy, oversight, and challenge), and internal audit (third line, providing independent assurance to the governing body). The Institute of Internal Auditors codified the older 'Three Lines of Defense' framing in a 2013 position paper that became widely adopted in financial services governance, and substantially updated it in 2020 as the 'Three Lines Model' — dropping the militaristic 'defense' metaphor, emphasizing collaboration over rigid line boundaries, and explicitly bringing in the governing body and external assurance providers. Adoption is widespread but the model remains a conceptual organizing schema rather than a binding standard, and implementation varies considerably across institutions.
Core components
- Governing body (oversight, accountability)
- First line (operational management owning risks)
- Second line (risk and compliance functions providing oversight and expertise)
- Third line (internal audit providing independent assurance)
- External assurance providers
- Six principles (in 2020 model)
Primary use case
Organizing risk and assurance responsibilities in financial institutions and large enterprises; common reference in regulatory expectations for risk governance.
Common criticisms
- Rigid line boundaries can encourage silos and a 'not my job' culture
- original 'defense' metaphor framed risk as adversarial rather than business-enabling (addressed in 2020 update)
- over-reliance on second line as risk owner rather than challenger
- small organizations cannot realistically support three independent lines
- combined-assurance integration with external audit and consulting often muddled in practice.
Lineage
- Siblings
- COSO ERM, ISO 31000, COSO Internal Control-Integrated Framework