The Three Lines Model
The Three Lines Model is the Institute of Internal Auditors' framework for how responsibility for risk and control is distributed across an organisation. It was published in 2020, replacing the Three Lines of Defence model that had been in general use since the mid-2000s. The older name is still widely spoken, which causes some confusion about whether the two are the same thing. They are not identical, and the differences are more than cosmetic.
The three lines
The structure separates three kinds of role, not three departments.
- First line: the management roles that deliver products and services and that own and manage the associated risk directly. Operational management is the first line, whether or not anyone in it uses the term.
- Second line: expert functions providing support, advice and challenge on risk-related matters — risk management, compliance, quality, and in some organisations safety and legal.
- Third line: internal audit, providing independent and objective assurance to the governing body on the effectiveness of governance, risk management and control.
Above these sits the governing body, accountable for oversight, and this is one of the more significant changes in the 2020 version: the governing body is now an explicit part of the model rather than an assumed recipient of its output.
What the 2020 revision changed
Four differences matter in practice.
The defensive framing was dropped. "Defence" implied that the organisation's risk arrangements exist principally to protect against threat, and the revision reframes the purpose as both creating and protecting value. That is not a presentational change — it affects whether the second line is understood as a brake or as a contributor.
The lines became roles rather than boxes. The earlier model was frequently implemented as an org chart, with three named departments and a dispute about which one owned any given activity. The revision emphasises that the lines describe kinds of responsibility, which may be distributed differently across organisations, and that a single function may carry more than one. This distinction is particularly relevant to professionals undertaking an Operational Risk Management Training Course, where clear risk ownership and accountability are central to effective risk management.
The governing body was brought inside the model, with its own defined role in setting direction, delegating responsibility and holding management to account.
The model became principles-based, expressed as six principles covering governance, the roles of the governing body, management responsibilities across the first and second lines, the role of internal audit, internal audit independence, and the creation and protection of value.
Where implementation goes wrong
The failure modes are recognisable across sectors. Many of these issues are also addressed through an Operational Risk Management Training Course, particularly the practical challenges of risk ownership, control effectiveness, escalation and assurance across an organisation.
- The second line does the first line's work. Where operational management lacks capacity or capability, risk and compliance functions end up performing controls rather than challenging them, which removes the independence that made the structure worth having.
- The first line does not know it is the first line. Operational managers frequently understand risk management as something the risk department does. The model only functions if the people who own the risk understand that they own it.
- The third line is used as a resource. Internal audit being asked to design controls, then later to assure them, is common and quietly destroys the independence the third line exists to provide.
- The lines are read as a sequence rather than a structure. Risk arriving at the second line only after the first has finished with it, and at the third only after the second, produces slow escalation and late detection.
A criticism worth acknowledging
The model has attracted substantive criticism, particularly following institutional failures in which the structure was formally present and functionally absent. The recurring argument is that three lines can create an appearance of assurance that discourages scrutiny — everyone assumes a risk is covered by another line, and the aggregate is that nobody has looked at it closely.
The 2020 revision addresses part of this by emphasising alignment and communication between lines rather than separation, but the underlying tension has not been resolved and is unlikely to be by any structural model. The structure describes who should be doing what. It cannot make them competent, resourced or willing to escalate, and organisations that treat conformance with the model as evidence of effective governance are making a category error.
The practical response is to test the model rather than to declare it. Whether the second line has ever caused a first-line decision to change, and whether internal audit has ever reported something the executive did not want reported, tells you more than any organisational diagram.
Frequently asked questions
- What is the Three Lines Model?
The Three Lines Model is the Institute of Internal Auditors' risk governance framework, published in 2020. It distinguishes management roles that own and manage risk, expert functions that provide support and challenge, and internal audit, which provides independent assurance to the governing body.
- What is the difference between the Three Lines Model and the Three Lines of Defence?
The Three Lines Model replaced the Three Lines of Defence in 2020. It drops the defensive framing in favour of creating and protecting value, treats the lines as roles rather than as fixed departments, brings the governing body explicitly inside the model, and is expressed as six principles rather than as a structural diagram.
- What are the three lines?
First line: management roles that deliver products and services and own the associated risk. Second line: expert functions providing support and challenge on risk, compliance and related matters. Third line: internal audit, providing independent assurance to the governing body.
- Is the Three Lines Model mandatory?
No. It is guidance rather than a standard, and there is no certification against it. Some regulators expect arrangements consistent with it, and many organisations adopt it as an organising principle, but it is not a compliance requirement in itself.
- What are the criticisms of the Three Lines Model?
The main criticism is that formal conformance can create an appearance of assurance without the substance, with each line assuming a risk is covered elsewhere. The 2020 revision emphasises alignment and communication to reduce this, but the model describes how responsibility should be distributed and cannot by itself ensure that those holding it are resourced, competent or willing to escalate.
Related Training Courses
- Business Continuity Management System (BCMS) & Enterprise Risk Management (ERM)
- Advanced Enterprise Risk Management
- Operational Risk Management & Mitigation
- Risk Based Operational Decision Making