The three lines model is the most widely used way to describe who does what in risk management and assurance. It clarifies that management owns and manages risk, that risk and compliance functions support and challenge, and that internal audit provides independent assurance, all under the oversight of a governing body. Applied well, it removes confusion and gaps. Applied badly, it becomes a chart on the wall while everyone argues about who is responsible.
This guide explains the three lines model as updated by the Institute of Internal Auditors in 2020, what each role does, how it fits into enterprise risk management, how to allocate responsibilities in practice and which mistakes to avoid. It is general guidance and should be adapted to your organization.
What the three lines model is
The three lines model, published by the Institute of Internal Auditors, sets out roles in governance and how they work together. It replaced the older “three lines of defense” idea with a version that puts more emphasis on collaboration, value creation and principles rather than a rigid hierarchy. You can read the paper at the Institute of Internal Auditors’ Three Lines Model.
The model does not prescribe a structure. It offers principles: governance requires accountability and oversight, management actions to achieve objectives include managing risk, internal audit provides independent assurance, independence is essential and alignment across lines creates value. These principles sit comfortably alongside frameworks such as COSO ERM and ISO 31000.
The governing body: accountability and oversight
The governing body, usually the board and its committees, is accountable to stakeholders for organizational oversight. It sets the direction, defines risk appetite, ensures that appropriate structures exist and receives assurance that they work. It does not manage risks day to day, but it must be informed and ask hard questions.
Free enterprise risk assessment
Which of your business risks sit above your appetite?
Set your criteria and appetite, pick from 36 strategic, financial, operational and compliance scenarios, rate them and decide how to treat each. Built to ISO 31000, and free.
Run the free enterprise risk assessment → or View premium report sample
In practice this means approving policy, reviewing reports, testing that the lines are resourced and independent, and holding management to account. See risk appetite for how boards define how much risk the organization will take.
First line: owning and managing risk
First line roles are those closest to delivering products and services. They own the risks in their activities, and they design and operate controls to manage them. A head of operations owns operational risk in their area. A product manager owns product risk.
The first line must have real ownership, not just a form to complete. That means identifying risks, assessing them, deciding treatments, monitoring indicators and reporting honestly. Where the first line treats risk as someone else’s job, the whole model weakens. Building risk culture is central to making ownership real.
| Role | Main responsibility | Examples |
|---|---|---|
| Governing body | Accountability to stakeholders, sets direction and oversight | Board, audit and risk committees |
| First line (management) | Owns and manages risk, delivers products and services | Business unit heads, process owners |
| Second line (management) | Provides expertise, support, monitoring and challenge | Risk, compliance, security, quality functions |
| Third line (internal audit) | Independent assurance and advice on governance and risk | Internal audit function |
| External providers | Additional assurance and specialist input | External audit, regulators, certification bodies |
- Own and manage risk in daily activities
- Design, operate and improve controls
- Report risks, incidents and indicators honestly
- Respond to challenge and assurance findings
Second line: expertise, support and challenge
Second line roles help the first line manage risk. They provide frameworks, tools, training and advice, and they monitor and challenge how risk is managed. Typical functions include risk management, compliance, information security, quality, health and safety and legal.
The second line should be independent enough to challenge but close enough to add value. It sets policy, such as the risk management policy, maintains the enterprise risk register framework, aggregates results across the organization and reports to management and the governing body. It should not take over ownership of risks from the first line.
Third line: independent assurance
Internal audit provides independent and objective assurance and advice on the adequacy and effectiveness of governance and risk management. It reports to the governing body and is independent of management responsibilities. Its work checks whether the first and second lines are doing what they should, and whether the whole system works.
Independence is the defining feature. Internal audit must not design or run the controls it later assesses, and it needs direct access to the governing body. External providers, such as external auditors, regulators and certification bodies, add further assurance outside the organization.
Making the three lines model work in practice
Turn the model into a role map. For each significant risk category, name who owns it in the first line, who advises in the second line and how internal audit covers it. Write this into policies and job descriptions, and use it in the enterprise risk register, where each risk has a named owner.
Meet regularly across lines to share information and avoid duplication. A combined assurance approach maps who tests which controls, so the same area is not audited five times while another is never examined. Keep roles clear, but encourage communication, which is the main change from older interpretations.
Adapting the three lines model to small organizations
A small organization may not have separate functions. One person may combine second line duties, or the second line may be outsourced. That is acceptable if conflicts are managed: the person who challenges should not be the person who owns the risk being challenged, and independent assurance should still be provided, for example by an external reviewer once a year.
Document how roles are covered and how conflicts are handled. Keep it proportionate. The point is clarity about who is responsible for what, not headcount.
Common mistakes with the three lines model
Frequent problems include the second line taking over risk ownership, the first line assuming risk is the second line’s problem, internal audit acting as consultant on controls it later audits, unclear roles between risk and compliance, duplicated effort across lines, weak reporting to the governing body and treating the model as a rigid hierarchy. Another is limiting it to financial controls when it applies to all objectives.
Avoid these by writing role descriptions, mapping risks to owners and holding regular cross-line meetings. Review the arrangement annually, and after major change.
Combined assurance and avoiding duplication
A combined assurance map lists significant risks, the controls that address them and who tests each one: management self-assessment, second line monitoring, internal audit, external audit or regulators. It shows where several groups test the same control and where nobody does. Use it to plan the audit programme, reduce duplicate requests to control owners and focus effort on higher risks. Review the map annually with the audit committee, and adjust when the risk profile changes.
Encourage lines to share findings. An issue found by the second line should inform the audit plan, and an audit finding should be tracked by management until closed. The model works best when information moves freely and roles stay clear.
A short worked example
A logistics company maps its risks. For driver safety, the operations director is the first line owner, the health and safety manager provides second line policy, training and monitoring, and internal audit reviews the whole safety management system every two years. The board risk committee receives quarterly reporting.
When incident data shows rising near misses, the second line challenges the operations director, who agrees actions. Internal audit later confirms the actions were effective. Each role had a distinct job, and the overall system improved without duplication.
Linking the model to risk reporting
Reporting should flow along the lines. The first line reports risk information and indicators to the second line, which aggregates and challenges it and reports to executives and the governing body. Internal audit reports on assurance results directly to the governing body. Consistent formats help, such as the same risk categories and scales across lines; see KRI reporting and risk heat maps.
Check that the governing body sees both the risk picture and the assurance picture. If the reports only say what managers believe, without independent checking, the board is missing information it needs to discharge its oversight duty.
Structuring the assessment
If you want a report and workbook that connect enterprise risks, owners, controls and reporting, the Enterprise Risk Assessment Report and Workbook provides a structured layout for enterprise risk assessment that supports clear roles under the three lines model. Whichever tool you use, good practice with the three lines model means clear accountability, honest challenge and independent assurance working together.
Three lines model FAQ
What are the three lines?
The first line is management owning and managing risk, the second line provides expertise, support and challenge, and the third line is internal audit providing independent assurance, all under governing body oversight.
How is the current model different from three lines of defense?
The 2020 update emphasises principles, collaboration and value creation rather than a rigid defensive hierarchy, and places the governing body and external providers in the picture.
Can one person cover more than one line?
In small organizations, yes, but manage conflicts. The person challenging a risk should not own it, and independent assurance should still be provided.
Who owns risk in the model?
Management, especially the first line, owns risk. The second line advises and challenges, and internal audit provides independent assurance.
Does the model apply outside financial services?
Yes. It applies to any organization and to all objectives, not only financial risk.