11.1 The Three Lines Model in Assurance Coordination
Key Takeaways
- The 2020 IIA Three Lines Model replaces the legacy 'Three Lines of Defense' by transitioning from a defensive, siloed posture into a principle-based governance framework focused on both value creation and value protection.
- First-line roles directly deliver products and services to clients and own operational risks and internal controls; second-line roles provide specialized risk management, compliance, and quality expertise; third-line internal audit delivers independent, objective assurance.
- The governing body exercises fiduciary oversight over management (first and second lines) and internal audit (third line), establishing organizational risk appetite and ensuring third-line functional independence.
- Assurance coordination between second-line oversight monitors and internal audit requires a shared risk taxonomy, coordinated risk assessments, and synchronized schedules while strictly safeguarding internal audit's objectivity.
- When internal audit is requested to assume operational second-line duties (such as designing risk management frameworks), internal audit objectivity is impaired, requiring structured safeguards, Audit Committee disclosure, and separate assurance mechanisms.
11.1 The Three Lines Model in Assurance Coordination
[!NOTE] Evolution to Value Creation: In 2020, The Institute of Internal Auditors (IIA) updated the legacy 'Three Lines of Defense' framework to the IIA Three Lines Model. This update transitioned organizational governance from a defensive, siloed risk-containment posture into a collaborative, principle-based model focused on value creation and protection.
In modern governance, organizations face volatile, interconnected risks spanning cyber disruptions, regulatory changes, and business transformations. Managing these threats cannot occur in operational silos. The governing body and senior management require coordinated oversight where operational managers, specialized risk monitors, and independent auditors work in structured alignment. The IIA Three Lines Model provides the foundational architecture for orchestrating this governance and assurance coordination.
Foundational Principles and Structural Architecture
The IIA Three Lines Model articulates six core principles: governance structures enabling accountability and action; governing body oversight; management's first- and second-line roles; third-line independent assurance; third-line independence; and collective value creation. The model delineates governance responsibilities across three functional components:
1. The Governing Body
The governing body (e.g., Board of Directors, Audit Committee) holds ultimate fiduciary accountability to stakeholders. It defines organizational purpose, establishes risk appetite, delegates authority and resources to management, and oversees executive performance. It maintains functional oversight of the Chief Audit Executive (CAE), approving the internal audit charter, risk-based audit plan, and resource allocation, while receiving direct, unfiltered assurance reports.
2. First-Line Roles: Operational Management and Controls
First-line roles encompass operational units directly delivering products and services to clients. Operational managers directly own and manage risks, designing, executing, and monitoring day-to-day internal controls. First-line assurance is management self-assurance (supervisory reviews, control self-assessments). While essential, it carries inherent operational bias because managers are evaluated on commercial production targets.
3. Second-Line Roles: Specialized Expertise and Monitoring
Second-line roles provide specialized assistance, frameworks, monitoring, and challenge to first-line operations. Functions include Enterprise Risk Management (ERM), Regulatory Compliance, Information Security (CISO), Quality Assurance, and Legal. Second-line assurance is specialized management assurance. Although separate from frontline operations, second-line functions report to executive management (e.g., CRO, General Counsel, CCO) and therefore lack organizational independence from executive leadership.
4. Third-Line Roles: Independent Internal Audit Assurance
The third line is occupied exclusively by internal audit. Internal audit provides independent, objective assurance and advice on the adequacy and effectiveness of governance, risk management, and internal controls across first- and second-line activities. Internal audit achieves organizational independence through direct functional reporting to the governing body and strict avoidance of operational management duties.
Comparative Matrix: Delineating the Three Lines
| Governance Dimension | First Line (Operations) | Second Line (Specialized Oversight) | Third Line (Internal Audit) |
|---|---|---|---|
| Primary Focus | Direct product/service delivery; operational control execution | Risk frameworks, compliance monitoring, and policy challenge | Independent, objective assurance across governance, risk, and controls |
| Accountability | Accountable to executive management for operational delivery | Accountable to executive management for risk oversight & compliance | Accountable functionally to the Governing Body / Audit Committee |
| Independence | None; directly embedded in commercial operations | Limited; separate from operations but part of management hierarchy | Full; independent of management influence and operational execution |
| Nature of Assurance | Management self-assurance (inherent operational bias) | Specialized management assurance / secondary monitoring | Independent assurance conforming to Global Internal Audit Standards |
| Primary Deliverables | Operational metrics, supervisory sign-offs, self-assessments | Risk heat maps, compliance dashboards, exception tracking | Engagement audit reports, assurance opinions, systemic insight |
| Reporting Line | Operational division heads, COO, Executive Vice Presidents | Chief Risk Officer (CRO), Chief Compliance Officer, General Counsel | Direct functional reporting to Audit Committee; administrative to CEO |
Coordinating Assurance While Preserving Objectivity
Under GIAS Standard 9.5 (Coordination and Reliance), the CAE must coordinate internal audit activities with second-line functions to optimize coverage and eliminate duplicate testing. Coordination mechanisms include establishing a common risk taxonomy with standardized risk definitions and severity scales, sharing second-line risk registers and breach logs during audit planning, and synchronizing review calendars.
However, internal audit must vigorously safeguard its objectivity. Internal audit may utilize second-line monitoring data, but must never allow second-line managers to dictate internal audit scope or conclusions. When executive management pressures the CAE to assume operational second-line duties (such as facilitating ERM or administering the whistleblower hotline), strict safeguards under GIAS Standard 2.2 (Safeguarding Objectivity) must be instituted:
- The CAE's objectivity is formally impaired for auditing that operational area.
- The dual role must be approved by the Audit Committee and documented in the internal audit charter.
- Any required assurance over the managed area must be performed by an independent external party or separate team reporting directly to the board.
Eliminating Assurance Gaps and Alleviating Audit Fatigue
Uncoordinated assurance generates two severe governance pathologies: assurance gaps and audit fatigue.
An assurance gap arises when a critical enterprise risk receives no objective evaluation because each layer assumes another function is monitoring it (e.g., operations assumes compliance tracks vendor cybersecurity, compliance assumes internal audit scheduled an audit, and internal audit assumes operational scorecards suffice). To eliminate gaps, the CAE and second-line leaders must construct joint risk universe maps and hold quarterly alignment sessions to establish explicit oversight boundaries.
Conversely, audit fatigue occurs when operational units are overwhelmed by continuous, uncoordinated data requests, interviews, and audits by compliance, risk, internal audit, and external auditors. This churn disrupts business operations and fosters organizational friction. Leading CAEs resolve audit fatigue by establishing a centralized document repository where business units upload core evidence once annually, coordinating integrated testing schedules, and placing structured reliance on validated second-line testing under GIAS Standard 9.5.
An enterprise risk management (ERM) department completes a comprehensive risk assessment of the organization's treasury operations, concluding that foreign currency derivative controls are effective. During annual planning, executive leadership suggests that the Chief Audit Executive (CAE) omit treasury operations from the internal audit plan because the ERM department already evaluated the area. How should the CAE evaluate this request under the IIA Three Lines Model?
Operational managers at a global logistics hub express severe frustration regarding compliance fatigue, noting that they have undergone four separate control reviews by internal audit, trade compliance, quality control, and safety monitors within nine months, each demanding identical transaction samples and policy documentation. Which strategy should the Chief Audit Executive lead to resolve this problem?
Due to a sudden corporate resignation, the Chief Executive Officer requests that the Chief Audit Executive (CAE) temporarily take operational ownership of the organization's regulatory compliance and anti-money laundering (AML) department for six months. What is the most appropriate action for the CAE to take under Global Internal Audit Standards?