Understanding the Three Lines Model (Formerly Three Lines of Defense)
A deep dive into the Three Lines of Defense model studying it's purpose, caveats and necessities
Shubham Ghotankar
7/10/20265 min read


Every organization faces uncertainty—from operational failures and cyberattacks to regulatory breaches and fraud. Effective governance requires more than identifying risks; it requires clearly defining who owns risk, who oversees it, and who provides independent assurance.
The Three Lines Model, developed by the Institute of Internal Auditors (IIA), provides a practical framework for allocating these responsibilities. Rather than viewing governance as the responsibility of a single department, it recognizes that management, oversight functions, and internal audit each play distinct but complementary roles in protecting and creating organizational value.
In 2020, the Institute of Internal Auditors updated the "Three Lines of Defense" to the "Three Lines Model." The revision shifted the emphasis from defensive thinking toward collaboration, governance, and value creation while retaining the principles of clear accountability and independent assurance.
Defining the Three Lines of Responsibility
At the heart of the model is a clear distinction between three critical roles that, while separate, must work in a complementary fashion to protect and create value:
The First Line (Management): These roles are responsible for the day-to-day ownership and management of risks. Management designs and operates the processes and controls necessary to achieve organizational objectives.
The distinct value of the first line (Management) lies in its deep operational knowledge and real-time awareness of performance drivers and risks. Because they are closest to day-to-day activities, they can respond quickly and adjust processes to ensure objectives are met while managing risks. Their primary value is in the ownership and direct execution of the controls and structures that create and sustain value for stakeholders
Ex: A Loan Servicing Manager ensures customer requests are processed accurately, reviews exceptions, and performs maker-checker controls.
The Second Line (Support and Specialized Roles): This line consists of roles providing specialized expertise, support, and challenge to the first line.
The second line provides value through specialized expertise in areas such as compliance, cybersecurity, safety, and financial crime. Their distinct contributions include:
Expert Support and Guidance: They help the first line navigate complex regulatory obligations and specialized risk profiles.
Objective Challenge: Because they are typically separate from the operational reporting hierarchy, they provide a more objective perspective to monitor and challenge first-line activities.
Domain-Specific Monitoring: They conduct thematic reviews and monitoring within their specific specialist domains to identify systemic patterns or emerging risks
Ex: The Operational Risk team performs an RCSA, challenges whether controls are effective, reviews incidents, and monitors KRIs.
The Third Line (Internal Audit): This function delivers independent and objective assurance on the effectiveness of the entire governance and risk management system. It also provides advisory insights without assuming management responsibilities.
The third line (Internal Audit) offers a holistic, organizationwide view that the other lines cannot provide. Its unique value includes:
Highest Level of Objectivity: Due to its functional reporting line to the board, it provides the most credible and independent assurance.
Integration of Assurance: It acts as an "integrator," examining how the first and second lines work together and providing a comprehensive perspective on the overall coherence of the governance system.
Unrestricted Access: It maintains the authority to access all assets, facilities, and information, allowing it to report sensitive or significant issues directly to the board without management interference.
Ex: Internal Audit independently reviews whether both the Loan Servicing team and Operational Risk team are fulfilling their responsibilities and whether governance is effective.
The three lines work best together through a principles-based approach centered on collaboration, coordination, and transparency. Rather than operating in silos, the lines should align their methodologies, share risk information, and coordinate their planning to ensure that independence does not lead to isolation.
How They Best Work Together
The Internal Audit Function as Integrator: While all lines contribute, the internal audit function (third line) acts as the primary integrator. It facilitates coordination and consolidation because it can draw on the insights and monitoring performed by the first and second lines while maintaining a systemwide perspective.
Coordinated Planning and Reliance: The lines work effectively when they engage in thoughtful reliance on each other's work. This involves using shared risk taxonomies, assurance maps, and aligned reporting to ensure all risks are covered without unnecessary duplication.
Integrated Assurance: In more mature organizations, this coordination develops into integrated assurance. This structured approach aligns and communicates all assurance and advisory activities across the organization, providing a unified and reliable view of performance to the board.
The Result of Successful Collaboration
When the three lines are effectively aligned and coordinated, the organization achieves several key outcomes:
A Holistic Perspective: The board receives a coherent, systemwide view of how governance, risk management, and control processes operate together to support organizational objectives.
Enhanced Decision-Making: By providing balanced and reliable information, the three lines enable senior management and the board to make better-informed strategic decisions.
Efficiency and "Reduced Fatigue": Effective coordination reduces overlap and duplication of effort, addressing gaps in coverage and preventing "assurance fatigue" within the organization.
Long-Term Value and Trust: Ultimately, this synergy strengthens governance and accountability, improves resilience and adaptability to change, and builds the trust necessary to create sustainable value for stakeholders
Drawbacks and Risks
The primary drawbacks of this approach stem from the potential for roles to become blurred, which can compromise the very independence and clarity the model seeks to establish:
Misunderstood Independence: If independence is not clearly understood or thoughtfully exercised, it can unintentionally lead to isolation, limiting cross-functional communication and contributing to a misalignment of roles.
Familiarity and Self-Review Threats: Because advisory work is inherently collaborative, it can create familiarity risks. Significant risks arise if the same person or function designs, monitors, and then later evaluates the effectiveness of a process, leading to self-review threats.
Role Confusion: Blending activities can create confusion regarding who is responsible for operating controls, who is supervising them, and who is independently assessing them.
Reduced Board Clarity: If reporting lines or accountabilities are not clearly articulated, the board’s ability to fully rely on assurance may be limited.
Assurance Coverage Gaps: Relying on the work of others (coordination) requires high-quality work; if quality expectations are not met, the internal audit function must be independent enough to choose not to rely on that work to avoid gaps in systemwide assurance.
Safeguards to Protect Clarity and Objectivity
Foundational Safeguards:
Transparent Documentation: Responsibilities must be clearly defined and documented, such as in an internal audit charter.
Board Oversight: The board must provide explicit approval for any expanded remits for the Chief Audit Executive (CAE) to ensure they understand the associated risks.
Communication of Risks: Any potential or perceived threats to objectivity must be communicated to the board promptly and explicitly.
Activity-Specific Safeguards:
Separation of Duties: There must be a clear separation between advisory activities and subsequent assurance work.
Independent Verification: Areas where a CAE has dual responsibilities or supervisory oversight should undergo periodic independent reviews by an outside party to mitigate self-review threats.
The 12-Month Rule: For individuals moving between roles, a period of at least 12 months is typically required before providing assurance on a process they were previously responsible for.
Safeguards for Overlapping Roles:
Documented Justification: If internal audit performs second-line tasks, there must be a clear, documented reason why the arrangement is necessary.
Alternative Assurance Providers: When internal audit is involved in second-line activities, the organization should ensure another independent party (internal or external) provides assurance over that specific area.
Operational Separation: When the CAE supervises a second-line function, the operational activities of that function must remain structurally separate from the internal audit function’s own assurance work.
The Three Lines Model should not be viewed as a rigid organizational chart but as a governance philosophy. Organizations derive the greatest value when accountability remains with management, specialist functions provide constructive challenge, and internal audit delivers independent assurance. In today's environment—characterized by rapid technological change, increasing regulatory expectations, and heightened operational resilience requirements—the effectiveness of the model depends less on organizational structure and more on collaboration, transparency, and clearly defined accountability.
References:
Institute of Internal Auditors (2020), The IIA's Three Lines Model.
Institute of Internal Auditors, Global Internal Audit Standards (2024).
Basel Committee guidance on governance and operational risk.
Portfolio
Showcasing my skills, education, and experiences online.
Connect
shubhamghotankar@gmail.com
+32 0465 86 03 92
© 2025. All rights reserved.