Governance
Three Lines of Defence
A governance model that separates risk work into three distinct roles: management that owns and controls risk, risk and compliance functions that oversee it, and internal audit that gives the board independent assurance that the first two are working.
Also known as Three Lines Model, 3LoD, Three lines of defense. First set out by No single author; codified by the Institute of Internal Auditors in 2013; the primary source is cited in full below.
Where this is contested
There is no single originator. The model spread through banking and financial-services practice in the 2000s, was recommended by FERMA and ECIIA in their 2010 guidance on the 8th EU Company Law Directive, was codified by the IIA's 2013 position paper, and was revised by the IIA in 2020 as the Three Lines Model with the defensive framing deliberately softened.
- Format
- Structural model
- Level
- Corporate · Business unit
- Best for
- Assess risk
- Decision stage
- Execute · Review
- Difficulty
- Intermediate
- Time to apply
- A day to map an existing organisation against the lines; months to change reporting lines and behaviour.
Plate · The model
The components
First line: management owns and controls risk
Operational management and the teams delivering products and services. They own the risks their activities create, design and operate the day-to-day controls, and are accountable for fixing what breaks.
Signals of strength
Managers describe risk as the risk team's responsibility · Controls exist only in policy documents, with no operator who can explain them · Remediation of findings is negotiated rather than owned
Second line: risk and compliance functions oversee
Specialist functions such as risk management, compliance, financial control and quality. They set frameworks and policy, challenge and support the first line, and monitor and report on risk across the organisation, without owning the controls themselves.
Signals of strength
The risk function writes and operates the controls it is meant to challenge · Compliance monitoring reports what the first line self-declares, unverified · Oversight functions report only to the executives they oversee
Third line: internal audit assures independently
Internal audit, reporting functionally to the governing body. It provides independent, objective assurance on the adequacy and effectiveness of governance, risk management and control, including the work of the first and second lines.
Signals of strength
Internal audit reports to the finance director rather than the audit committee · Audit plans avoid the risk function and senior management activity · Auditors are drawn into designing the controls they will later audit
When it earns its keep
- The organisation has grown, or its regulator has arrived, and risk work is happening everywhere without anyone being able to say who owns which control and who checks it.
- The board is receiving assurance from several directions and cannot tell which of it is management marking its own homework and which is genuinely independent.
- Audit findings keep recurring because remediation is treated as audit's job rather than management's, a classic symptom of first-line ownership never being established.
- You are designing or rebuilding a risk function and need a shared vocabulary for the board, the executive, compliance and audit before arguing about headcount.
And when it doesn't
- The organisation is small enough that the three lines would collapse into the same two people. Apply the principle of separating doing from checking proportionately rather than building a paper structure.
- The real problem is risk appetite or strategy. The model organises who does risk work; it says nothing about which risks are worth running, and a tidy structure around the wrong risks is tidy failure.
- You want the model to manage risk for you. It allocates roles; the controls, judgement and culture still have to be built, and regulators have repeatedly found firms with immaculate lines and dismal behaviour.
- Cross-cutting change is the risk in question. Fast-moving programmes, digital delivery and third-party ecosystems blur the lines badly, and mechanically enforcing separation can slow the response that would actually reduce the risk.
How to run it
Before starting, gather the inputs the analysis depends on:
- An inventory of the organisation's principal risks and the controls that are supposed to manage them, however rough.
- A map of who currently performs risk, compliance and audit activity, including the informal versions living inside operational teams.
- The governing body's committee structure and reporting lines, since the model only works if the third line reports to the board rather than to the executives it audits.
- A view on proportionality: regulatory expectations, sector norms and what the organisation can honestly resource.
- 1
Establish first-line ownership
Make explicit that operational management owns its risks and the controls over them. This is the load-bearing move. Where the first line believes risk belongs to the risk department, the whole structure is a facade.
- 2
Shape the second line to oversee, and only to oversee
Give risk and compliance functions the mandate to set policy, challenge, monitor and report. Keep them out of owning controls, because a second line that runs the controls can no longer credibly oversee them.
- 3
Secure genuinely independent assurance
Position internal audit, in-house or co-sourced, to report functionally to the board or audit committee. Its scope should cover the effectiveness of the first and second lines themselves, including the risk function.
- 4
Wire the lines to the governing body
Define what the board hears from each line and when. The 2020 revision stresses that the governing body is an active part of the model, accountable for oversight, rather than a spectator above it.
- 5
Coordinate and review the whole
Align assurance plans so the lines neither duplicate nor leave gaps, and revisit the design as the organisation changes. The 2020 Three Lines Model explicitly encourages collaboration across the lines rather than fortress behaviour.
Reading the result
A documented allocation of risk roles across the three lines and the governing body: who owns each principal risk and its controls, who oversees and challenges, who assures independently, and what each line reports to the board.
- Read the model as roles rather than departments. One person can wear first-line and second-line hats in a small organisation, provided the hats are named and never worn simultaneously for the same control.
- Test independence at the reporting line. Whoever the third line reports to is whoever it cannot credibly audit.
- Treat blurring as a finding. Wherever the second line is operating controls or the third line is designing them, the map has told you where assurance is weakest.
A worked example
A credit union rebuilds its risk oversight before a lending expansion
A credit union in the West of Scotland with 28,000 members wants regulatory comfort before expanding into larger home-improvement loans. Its internal auditor currently reports to the chief executive, helped write the lending policy last year, and the board risk committee receives a single combined report from the operations manager. The board maps the organisation against the Three Lines of Defence before the expansion.
- First line: management owns and controls risk
- Branch staff and the lending team own affordability checks, identity verification and arrears management. The mapping exposes that arrears follow-up is done 'when there is time', with no named owner. The lending manager is made explicitly accountable for the control, with a monthly worked-cases report.
- Second line: risk and compliance functions oversee
- A part-time risk and compliance officer sets lending policy, runs AML monitoring and samples first-line decisions. The mapping finds her also operating the sanctions-screening control herself, so oversight of that control is self-review. Screening moves to the operations team; she keeps the checking role.
- Third line: internal audit assures independently
- Internal audit is co-sourced to a specialist firm and re-pointed to report functionally to the audit committee rather than the chief executive. Because the incumbent helped draft the lending policy, the first audit of the new loan book is assigned to a different reviewer. Audit scope now explicitly includes the second line's own monitoring.
- Board and coordination across the lines
- The board risk committee replaces the single combined report with three short ones: management's control report, the risk officer's independent monitoring, and audit's opinion. An annual assurance map shows which principal risks are covered by which line, and reveals that cyber risk is covered by nobody beyond an IT supplier's assertion.
The read. The exercise does its job because it is proportionate. Nobody is hired; roles are renamed, reporting lines are moved, and two genuine exposures surface, self-reviewed sanctions screening and unassured cyber risk. The honest residual is that with a part-time second line, the model's independence remains thinner than the diagram implies, so the board weights the third line's testing towards the highest-risk lending controls.
Pitfalls
- Treating the model as an organisation chart to be staffed rather than a set of roles to be allocated. The IIA is explicit that lines are roles, and in smaller organisations one person may carry more than one.
- Letting the second line drift into operating controls. The moment risk or compliance runs the process, oversight of that process has quietly ceased to exist.
- Using the lines as a liability shield, where each line assumes another is watching. Boards of failed banks discovered that three lines can also mean three groups not looking.
- Keeping internal audit's reporting line inside the executive. Independence is a reporting-line fact, not a mission-statement aspiration.
- Applying the pre-2020 defensive framing so rigidly that the lines stop sharing information. The 2020 revision exists precisely because siloed, adversarial lines served governance badly.
- Assuming the structure manages the risk. The model distributes work on risk; it neither identifies the right risks nor guarantees anyone does that work well.
What the critics say
The lines blur in practice and the model can give boards false assurance. Davies and Zhivitskaya find the boundaries between lines contested and permeable in real financial institutions, second-line independence routinely overstated, and the neat diagram capable of substituting for actual scrutiny.
Davies, H. and Zhivitskaya, M. (2018) 'Three Lines of Defence: A Robust Organising Framework, or Just Lines in the Sand?', Global Policy, 9(S1), pp. 34-42.
The model demonstrably failed to prevent the governance breakdowns of the financial crisis. Arndorfer and Minto argue its incentive structures are misaligned, since first and second lines answer to the management they are meant to constrain, and propose a fourth line involving external auditors and supervisors.
Arndorfer, I. and Minto, A. (2015) 'The "four lines of defence model" for financial institutions', Financial Stability Institute Occasional Paper No. 11, Bank for International Settlements.
The strongest critique came from the model's own steward. The IIA's 2020 revision conceded that the defensive, compliance-oriented framing encouraged rigid separation, discouraged collaboration and underplayed risk-taking as value creation, renaming it the Three Lines Model. Critics note that renaming the diagram does not itself resolve the coordination and incentive problems the old name produced.
The Institute of Internal Auditors (2020) 'The IIA's Three Lines Model: An Update of the Three Lines of Defense', July 2020.
Run it as a workshop
Map the organisation as it actually operates today, not the org chart it aspires to. In a small business one person may honestly hold a first-line and a second-line role; the exercise is naming that clearly, not pretending three departments exist where there is one team wearing different hats.
Running order
| List the significant risks and controls in play today | 20 min |
| Allocate first-line ownership per risk | 25 min |
| Allocate second-line oversight per risk | 25 min |
| Allocate third-line independent assurance | 20 min |
| Test for roles quietly marking their own homework | 20 min |
| Total | 110 min |
You will need
- A pre-drafted list of the organisation's significant risks
- A three-lines grid, risks down the side, three role columns across
- Sticky notes to mark where one person is honestly holding two lines at once
- A parking-lot sheet for risks with no owner at any line
Traps to avoid
- Treating the model as an org chart to be staffed, which leads straight to hiring three departments a business this size does not need. The lines are roles, not headcount.
- Letting the second line drift into doing the operating control itself. The moment risk or compliance runs the process, oversight of that process has quietly disappeared.
- Using the structure as a liability shield, where every line assumes another is watching. That is exactly the failure pattern seen in governance post-mortems of collapsed institutions.
- Finding the board is taking comfort from assurance that is actually management marking its own homework, and not naming it plainly when it surfaces in the room.
Sources and further reading
- The Institute of Internal Auditors (2013) 'The Three Lines of Defense in Effective Risk Management and Control', IIA Position Paper, January 2013.
- The Institute of Internal Auditors (2020) 'The IIA's Three Lines Model: An Update of the Three Lines of Defense', July 2020. ↗
- ECIIA and FERMA (2010) 'Guidance on the 8th EU Company Law Directive, Article 41: Monitoring the effectiveness of internal control, internal audit and risk management systems'.
- Davies, H. and Zhivitskaya, M. (2018) 'Three Lines of Defence: A Robust Organising Framework, or Just Lines in the Sand?', Global Policy, 9(S1), pp. 34-42.