9.2 Risk Governance, the Three Lines of Defence, and COSO ERM

Key Takeaways

  • Risk governance requires the board to set the organization's risk appetite, approve the enterprise risk management framework, and maintain continuous oversight under ASX Corporate Governance Principle 7.
  • ISO 31000:2018 defines risk as the 'effect of uncertainty on objectives' and establishes an integrated architecture of principles, framework, and process across identification, analysis, evaluation, and treatment.
  • The COSO 2017 Enterprise Risk Management (ERM) Framework organizes risk into five core components—Governance & Culture, Strategy & Objective-Setting, Performance, Review & Revision, and Information, Communication & Reporting—underpinned by 20 principles.
  • The Institute of Internal Auditors (IIA) Three Lines Model delineates accountability: First Line owns and manages operational risks, Second Line provides compliance and risk oversight, and Third Line (Internal Audit) provides independent, objective assurance.
  • Under Section 295A of the Corporations Act and ASX Recommendation 4.2, the CEO and CFO must provide written declarations confirming that financial records are maintained properly and that internal control systems are operating soundly.
Last updated: September 2026

9.2 Risk Governance, the Three Lines of Defence, and COSO ERM

Core Principle: In contemporary corporate governance, risk management is not a defensive compliance ritual; it is an active strategic capability. The board of directors is ultimately accountable for establishing the organization's risk governance architecture, articulating its risk appetite, approving the enterprise risk management (ERM) framework, and ensuring that management maintains an effective system of internal control. Under Australian and international standards, effective risk governance balances value preservation (protecting assets and maintaining compliance) with value creation (calculated risk-taking to achieve strategic objectives).


1. Risk Governance and the Board's Responsibility

The Nature of Enterprise Risk

In traditional management literature, risk was often viewed narrowly as a negative event—a hazard, loss, or peril to be avoided or insured against. Modern governance frameworks, notably ISO 31000:2018, define risk more dynamically as the "effect of uncertainty on objectives." This definition encompasses two dimensions:

  • Downside Risk (Threats): The probability and impact of adverse events that erode value, disrupt operations, impair financial viability, or trigger regulatory penalties (e.g., cyber breaches, fraud, equipment failure, supply chain collapse).
  • Upside Risk (Opportunities): The uncertainty associated with strategic initiatives that create shareholder and stakeholder value (e.g., entering new geographical markets, capital expenditure on innovative technology, mergers and acquisitions).

Effective risk governance ensures that an enterprise does not suffer from reckless risk-taking (gambling shareholder capital without adequate safeguards) nor from excessive risk aversion (stagnation and failure to adapt, leading to competitive obsolescence).

+-------------------------------------------------------------------------------------------------+
|                            THE DUAL SPECTRUM OF ENTERPRISE RISK                                 |
+------------------------------------+------------------------------------------------------------+
| DOWNSIDE RISK (Value Preservation) | UPSIDE RISK (Value Creation)                               |
+------------------------------------+------------------------------------------------------------+
| * Operational breakdowns & outages | * R&D investments in disruptive technology                 |
| * Regulatory non-compliance & fines| * Strategic market expansion & acquisitions                |
| * Financial fraud & embezzlement   | * Product innovation & commercial experimentation          |
| * Reputational damage & litigation | * Capital restructuring to lower weighted cost of capital  |
| GOAL: Mitigate, control, and insure| GOAL: Exploit, optimize, and capture strategic returns     |
+------------------------------------+------------------------------------------------------------+

The Board's Fiduciary Oversight under ASX Principle 7

Under Principle 7 of the ASX Corporate Governance Principles and Recommendations (Recognise and manage risk), a listed entity must establish a sound risk management framework and periodically review the effectiveness of that framework. The board's specific responsibilities include:

  1. Setting the Risk Appetite: Defining the nature and extent of the principal risks the entity is willing to take in pursuing its strategic objectives.
  2. Approving the Risk Management Framework (RMF): Formulating and approving the enterprise-wide policies, appetite statements, reporting hierarchies, and methodologies for managing risk.
  3. Recommendation 7.1 (Risk Committee): The board should establish a committee to oversee risk that has at least three members, a majority of whom are independent directors, and is chaired by an independent director. While smaller entities may delegate this function to a combined Audit and Risk Committee or retain it at the full board level (subject to "if not, why not" disclosure), dedicated risk oversight is essential for complex enterprises.
  4. Recommendation 7.2 (Annual Review of the Framework): The board or its committee must review the entity's risk management framework at least annually to satisfy itself that it continues to be sound and that the entity is operating with due regard to the risk appetite set by the board.
  5. Recommendation 7.3 (Internal Audit Oversight): The entity must disclose whether it has an internal audit function, how that function is structured, and what role it performs in evaluating risk and control efficacy.
  6. Recommendation 7.4 (Environmental and Social Risks): The entity must disclose whether it has any material exposure to environmental or social risks (including climate-related risks) and how it manages or intends to manage those exposures.

Defining the Boundaries: Risk Capacity, Appetite, and Tolerance

A foundational task of the board is establishing unambiguous boundary lines across three critical risk parameters:

Governance ParameterDefinitionPractical Corporate Example
Risk CapacityThe maximum amount of risk an organization can absorb before violating regulatory solvency thresholds, defaulting on debt covenants, or threatening its survival. Set by financial and operational constraints.A commercial bank's capital adequacy reserves under APRA standards dictate it cannot endure more than $2 billion in aggregate credit default losses without regulatory insolvency.
Risk AppetiteThe broad, board-approved level and type of risk an entity is consciously willing to accept in pursuit of its commercial objectives and value creation strategy.The board declares an appetite to allocate up to $150 million of venture capital into renewable energy technologies, accepting high commercial volatility for long-term growth.
Risk ToleranceThe operational, tactical boundaries and acceptable variances around specific risk targets. Expressed in measurable operational metrics.The manufacturing division specifies that product defect rates must not exceed 0.05% of production runs, or project cost variances must remain within ±4% of budget.
+-------------------------------------------------------------------------------------------------+
|                       RISK BOUNDARIES: CAPACITY, APPETITE, AND TOLERANCE                        |
+-------------------------------------------------------------------------------------------------+
| [ RISK CAPACITY ]   Absolute maximum risk the firm can survive before insolvency               |
|         |                                                                                       |
|         v                                                                                       |
| [ RISK APPETITE ]   Strategic level of risk the board actively chooses to take                 |
|         |                                                                                       |
|         v                                                                                       |
| [ RISK TOLERANCE ]  Operational tactical variance limits (e.g., ±5% budget variance, SLA limits)|
|         |                                                                                       |
|         v                                                                                       |
| [ CURRENT EXPOSURE ] Actual residual risk profile resulting from ongoing operations             |
+-------------------------------------------------------------------------------------------------+

2. Key Enterprise Risk Management Frameworks: ISO 31000 and COSO ERM

To operationalize risk governance, boards and management rely on internationally recognized frameworks. Two predominant standards dominate global and Australian corporate practice: ISO 31000:2018 and COSO ERM (2017).

ISO 31000:2018 (Risk Management — Guidelines)

Developed by the International Organization for Standardization (ISO), ISO 31000 provides principles, a framework, and a systematic process for managing any form of risk across all organization types and sizes. It is structured around three interconnected pillars:

  1. Principles (The Purpose and Value): The primary purpose of risk management is value creation and protection. ISO 31000 identifies eight guiding principles: integrated, structured and comprehensive, customized, inclusive, dynamic, based on best available information, considers human and cultural factors, and continually improves.
  2. Framework (The Governance Architecture): Centered on Leadership and Commitment, the framework ensures risk management is integrated into all organizational activities through five iterative stages: Design, Implementation, Evaluation, Improvement, and Integration.
  3. Process (The Operational Execution): The systematic application of policies, procedures, and practices across six core phases:
    • Communication and Consultation: Engaging internal and external stakeholders at every stage.
    • Scope, Context, and Criteria: Establishing the external environment (regulatory, economic, social), internal capabilities, and risk evaluation criteria.
    • Risk Assessment: Comprising three distinct sub-activities:
      • Risk Identification: Uncovering what, why, and how events can occur.
      • Risk Analysis: Developing an understanding of the risk, its sources, positive/negative consequences, and likelihood.
      • Risk Evaluation: Comparing analysis results against established risk criteria to determine whether treatment is required.
    • Risk Treatment: Selecting and implementing options: avoiding the risk, accepting the risk to pursue an opportunity, removing the risk source, changing likelihood, changing consequences, sharing the risk (insurance/hedging), or retaining the risk.
    • Monitoring and Review: Continuous surveillance to detect changes in internal/external contexts.
    • Recording and Reporting: Documenting outcomes and communicating risk profiles to governance bodies.

The COSO Enterprise Risk Management (ERM) Framework (2017)

Published by the Committee of Sponsoring Organizations of the Treadway Commission (COSO), the updated 2017 publication, Enterprise Risk Management — Integrating with Strategy and Performance, shifts risk management from a peripheral audit checklist into an integral element of strategic planning.

The framework is structured around 5 Core Components supported by 20 Underpinning Principles:

+-------------------------------------------------------------------------------------------------+
|                          COSO ERM (2017): 5 COMPONENTS & 20 PRINCIPLES                          |
+-----------------------------------+-------------------------------------------------------------+
| CORE COMPONENT                    | GOVERNANCE FOCUS & UNDERPINNING PRINCIPLES                  |
+-----------------------------------+-------------------------------------------------------------+
| 1. Governance and Culture         | Establishes the tone at the top, oversight structures, and  |
|                                   | ethical culture across the organization.                    |
|                                   | * Principle 1: Exercises board risk oversight               |
|                                   | * Principle 2: Establishes operating structures             |
|                                   | * Principle 3: Defines desired culture                      |
|                                   | * Principle 4: Demonstrates commitment to core values       |
|                                   | * Principle 5: Attracts, develops, and retains capable staff|
+-----------------------------------+-------------------------------------------------------------+
| 2. Strategy & Objective-Setting   | ERM integrates with strategy; sets risk appetite alongside  |
|                                   | business objectives.                                        |
|                                   | * Principle 6: Analyzes business context                    |
|                                   | * Principle 7: Defines risk appetite                        |
|                                   | * Principle 8: Evaluates alternative strategies             |
|                                   | * Principle 9: Formulates business objectives               |
+-----------------------------------+-------------------------------------------------------------+
| 3. Performance                    | Identifies, assesses, and responds to risks that impact     |
|                                   | strategy execution.                                         |
|                                   | * Principle 10: Identifies risk                             |
|                                   | * Principle 11: Assesses severity of risk                   |
|                                   | * Principle 12: Prioritizes risks                           |
|                                   | * Principle 13: Implements risk responses                   |
|                                   | * Principle 14: Develops portfolio view                     |
+-----------------------------------+-------------------------------------------------------------+
| 4. Review and Revision            | Evaluates how well ERM capabilities function over time in   |
|                                   | light of substantial organizational change.                 |
|                                   | * Principle 15: Assesses substantial change                 |
|                                   | * Principle 16: Reviews risk and performance                |
|                                   | * Principle 17: Pursues improvement in ERM                  |
+-----------------------------------+-------------------------------------------------------------+
| 5. Information, Communication,    | Continuous process of obtaining and sharing relevant risk   |
|    and Reporting                  | data across management and the board.                       |
|                                   | * Principle 18: Leverages information systems               |
|                                   | * Principle 19: Communicates risk information               |
|                                   | * Principle 20: Reports on risk, culture, and performance   |
+-----------------------------------+-------------------------------------------------------------+

Framework Synthesis: ISO 31000 vs. COSO ERM (2017)

AttributeISO 31000:2018COSO ERM (2017)
OriginInternational standard (ISO, Geneva).Sponsoring accounting/auditing bodies (AICPA, IIA, AAA, FEI, IMA - USA).
Core PhilosophyRisk as the "effect of uncertainty on objectives"; highly adaptable, open-systems approach.Risk deeply embedded in strategy formulation, mission, and operational performance.
StructurePrinciples, Framework, Process (three pillars).5 Components and 20 Principles (integrated ribbon model).
TerminologyBroadly accessible across engineering, health, corporate, public sector.Heavily aligned with accounting, internal auditing, and corporate finance.
Internal ControlsTreats internal controls as one element of risk treatment.Strongly linked to the COSO Internal Control — Integrated Framework (2013).

3. The Three Lines Model (IIA)

To ensure that risk management and internal controls operate effectively throughout an enterprise without dangerous coverage gaps or wasteful duplication, organizations deploy the Three Lines Model (formulated and updated by the Institute of Internal Auditors - IIA).

+-------------------------------------------------------------------------------------------------+
|                            THE IIA THREE LINES MODEL ARCHITECTURE                               |
+-------------------------------------------------------------------------------------------------+
|                                 GOVERNING BODY / BOARD / AUDIT COMMITTEE                        |
|                   (Accountability to stakeholders, oversight, setting risk appetite)             |
|                                                |                                                |
|                 +------------------------------+------------------------------+                 |
|                 |                                                             |                 |
|                 v                                                             v                 |
|       SENIOR MANAGEMENT                                             THIRD LINE                  |
|       (Operational responsibility)                                  INTERNAL AUDIT              |
|                 |                                                   (Independent & objective    |
|        +--------+--------+                                           assurance to Board/Audit)  |
|        |                 |                                                    |                 |
|        v                 v                                                    |                 |
|   FIRST LINE         SECOND LINE                                              |                 |
|   Operational        Risk Management, Compliance, Quality,                    |                 |
|   Management         Legal (Monitoring, challenge, policy)                    |                 |
|   (Owns & manages    (Advises, facilitates, and challenges                    |                 |
|    risks & controls)  first line management)                                  |                 |
|        |                 |                                                    |                 |
|        +-------->--------+----------------------------------------------------+                 |
|                                  |                                                              |
|                                  v                                                              |
|                         EXTERNAL ASSURANCE PROVIDERS                                            |
|             (External Audit, Statutory Regulators: APRA, ASIC, ACCC)                            |
+-------------------------------------------------------------------------------------------------+

The Operational Mechanics of the Three Lines

1. The First Line: Operational Management (Risk Ownership)

  • Who: Business unit heads, frontline supervisors, factory managers, sales executives, software engineers.
  • Role: Owns and manages risk directly. The first line designs, implements, executes, and monitors internal controls as an embedded element of daily commercial operations.
  • Key Functions: Identifying emerging risks in client transactions, ensuring operational procedures follow safety and financial controls, correcting control deficiencies, and maintaining compliance on the front line.

2. The Second Line: Risk Management and Compliance Functions (Oversight and Challenge)

  • Who: Chief Risk Officer (CRO), Chief Compliance Officer (CCO), information security officers, legal counsel, environmental compliance teams.
  • Role: Oversees, monitors, and challenges the first line. The second line does not own operational commercial assets. Instead, it provides specialized risk expertise, sets organization-wide risk policies, designs risk reporting templates, monitors regulatory compliance, and actively challenges the risk assessments performed by business unit managers.
  • Key Functions: Establishing the enterprise risk framework, running stress-testing and scenario analyses, aggregating portfolio risk profiles for executive management, and escalating non-compliance.

3. The Third Line: Internal Audit (Independent, Objective Assurance)

  • Who: Chief Audit Executive (CAE) and the internal audit team (or outsourced internal audit service providers).
  • Role: Provides independent, objective assurance to the governing body (Board and Audit Committee). The third line evaluates the adequacy, efficiency, and effectiveness of both first-line controls and second-line risk governance frameworks.
  • Independence Safeguards: To preserve absolute objectivity, internal audit must remain completely independent of operational management:
    • Dual Reporting Structure: Internal audit reports functionally to the Audit Committee / Board of Directors (for charter approval, audit plan approval, budget, and CAE compensation) and administratively to the CEO (for daily office administration, payroll, and corporate travel).
    • Strict Prohibition on Operational Ownership: Internal auditors must never design, implement, or operate internal controls or risk management systems. If internal audit designs a control, it cannot subsequently provide objective assurance on its efficacy.

4. External Assurance Providers

Operating outside the internal structure, external assurance providers include external financial statement auditors (providing statutory audit opinions under AASB/Corporations Act), prudential regulators (APRA conducting supervisory reviews), conduct regulators (ASIC), and independent engineering/environmental auditors.


4. Internal Control Systems: Taxonomies, Limitations, and Section 295A

Taxonomies of Internal Control

An internal control system consists of the policies, procedures, cultural behaviors, and automated mechanisms established by an entity's board and management to provide reasonable assurance regarding the achievement of three core objectives:

  1. Effectiveness and Efficiency of Operations (safeguarding assets, preventing waste).
  2. Reliability of Financial and Corporate Reporting (accurate, GAAP/AASB-compliant reporting).
  3. Compliance with Applicable Laws and Regulations (Corporations Act, taxation, workplace health and safety).

Controls are classified according to their operational timing and structural nature:

+-------------------------------------------------------------------------------------------------+
|                                 INTERNAL CONTROL CLASSIFICATIONS                                |
+---------------------+---------------------------------------------------------------------------+
| TIMING / FUNCTION   | OPERATIONAL MECHANICS & PRACTICAL EXAMPLES                                |
+---------------------+---------------------------------------------------------------------------+
| Preventive Controls | Designed to deter and block errors, irregularities, or fraud BEFORE they  |
|                     | occur. Proactive in nature.                                               |
|                     | * Examples: Segregation of duties, two-factor authentication, required    |
|                     |   dual authorization on wire transfers > $50,000, physical server locks.  |
+---------------------+---------------------------------------------------------------------------+
| Detective Controls  | Designed to identify and expose errors, unauthorized activity, or control |
|                     | failures AFTER they have occurred.                                        |
|                     | * Examples: Monthly bank reconciliations, inventory physical stocktakes,  |
|                     |   variance analysis (actual vs. budget), internal audit compliance checks.|
+---------------------+---------------------------------------------------------------------------+
| Corrective Controls | Designed to rectify identified errors, recover assets, and prevent        |
|                     | recurrence following a detective control trigger.                         |
|                     | * Examples: Disaster recovery backup restoration, disciplinary action,    |
|                     |   adjusting journal entries, updating firewall configurations post-breach.|
+---------------------+---------------------------------------------------------------------------+

Inherent Limitations of Internal Control

No internal control system, regardless of sophistication, can provide absolute assurance. Boards and auditors must recognize the inherent limitations of internal control:

  • Human Judgment and Error: Personnel make errors in judgment, experience fatigue, misunderstand instructions, or commit careless calculation mistakes.
  • Management Override: Executives possessing administrative authority can circumvent established control procedures for personal gain, fraudulent financial reporting, or short-term KPI inflation.
  • Collusion: Segregation of duties breaks down when two or more employees conspire together to perpetrate and conceal fraud (e.g., a purchasing officer colluding with an accounts payable clerk to approve fictitious invoices).
  • Cost-Benefit Constraints: The cost of implementing an elaborate control mechanism must not exceed the economic benefits derived or the risk reduction achieved.
  • Changing Environmental Context: Controls calibrated for past operational environments become obsolete during rapid corporate restructuring, system migrations, or sudden remote-work transitions.

The Section 295A CEO/CFO Declaration

In Australia, financial reporting integrity and internal controls are bound together by a critical statutory provision: Section 295A of the Corporations Act 2001 (Cth).

Before the directors can sign off on the annual financial statements and make their formal Directors' Declaration under Section 295, they must receive a written declaration from the Chief Executive Officer (CEO) and Chief Financial Officer (CFO) (or persons performing those functions).

Under Section 295A(2), the CEO and CFO must formally declare in writing that, in their opinion:

  1. The financial records of the company for the financial year have been properly maintained in accordance with Section 286 of the Corporations Act;
  2. The financial statements and notes comply with the Australian Accounting Standards (AASB);
  3. The financial statements and notes give a true and fair view of the financial position and performance of the company; and
  4. Any other matters prescribed by the regulations relating to financial reporting are satisfied.

Intersection with ASX Recommendation 4.2

Recommendation 4.2 of the ASX Corporate Governance Principles expands upon Section 295A by requiring the board of a listed entity to receive from its CEO and CFO a declaration that the financial records have been properly maintained and that the financial statements comply with accounting standards and give a true and fair view, and that:

"...that opinion has been formed on the basis of a sound system of risk management and internal control which is operating effectively."

Crucially for CPA candidates, Section 295A and Recommendation 4.2 do NOT absolve the board of directors from liability. As established in the landmark case ASIC v Healey [2011] FCA 717 (the Centro case), directors cannot blindly rely on the Section 295A declarations of executive management or external auditors. Directors retain an irreducible personal, non-delegable duty under Section 180(1) to read, understand, and critically evaluate the financial statements before approving them.


5. Practical Scenario: Operational Breakdown at Austral Mining Ltd

The Context

Austral Mining Ltd, an ASX-listed gold producer, operates a high-capacity processing facility in Western Australia. Over a twelve-month period, the plant experienced catastrophic cyanidation effluent leaks resulting in environmental contamination, an EPA suspension order, and a $45 million share valuation collapse.

Breakdown Across the Three Lines

Line of DefenceObserved Operational FailureGovernance Defect
First Line (Plant Engineers & Site Manager)Plant operators noticed sensor alerts indicating pipe corrosion in tailing valves but manually overrode the automatic alarm system to avoid shutting down production and missing quarterly volume bonuses.Prioritization of short-term volume KPIs over control integrity. Culture of bypass without immediate consequence.
Second Line (Environmental Compliance & Enterprise Risk)The compliance team operated with two junior officers who were treated as an administrative nuisance. When the compliance officer flagged valve maintenance delays, the Chief Operating Officer dismissed the memo, and the CRO lacked a direct escalation channel to the board.Second line lacked structural authority, independence, and direct access to the board Risk Committee. Second line was silenced by commercial operations.
Third Line (Internal Audit)Internal audit's annual plan was focused 90% on financial controls (payroll, procurement) and excluded environmental safety systems, because the executive team insisted environmental safety was an "engineering operational matter."Internal audit plan was captured by management. The Audit Committee failed to ensure internal audit coverage aligned with the company's principal enterprise operational risks.
Governing Body (Board of Directors)The board received quarterly executive summaries reporting "all environmental systems green" and never reviewed raw incident logs or challenged the absence of engineering audits.Board failed to exercise active oversight under ASX Principle 7; relied uncritically on executive assertions without demanding independent third-line assurance.

6. Critical Distinctions and Exam Traps

⚠️ Exam Alert: Common Pitfalls

  • Trap 1: Confusing Second-Line Monitoring with Third-Line Independence. Exam questions frequently describe a Chief Risk Officer (CRO) auditing a business unit and providing "independent assurance." Correction: The CRO is Second Line; they set risk policies and monitor compliance, but they are not independent of management. Only Internal Audit (Third Line) provides independent and objective assurance directly to the Board/Audit Committee.
  • Trap 2: Believing Internal Audit Can Design or Implement Internal Controls. If management requests internal audit to design the company's new accounts payable internal control software, internal audit must refuse. Designing controls is a management function (First/Second Line). If internal audit designs a control, its independence is fundamentally impaired because it cannot objectively audit its own creation.
  • Trap 3: Treating Risk Appetite as a Zero-Risk Mandate. A risk appetite statement that states "the company has zero tolerance for any commercial failure" is unworkable. In business, achieving returns requires taking calculated risks. Zero tolerance is appropriate for matters such as bribery, safety breaches, and intentional illegal acts, but not for commercial market ventures.
  • Trap 4: Believing Section 295A Shields Directors from Insolvent Trading or Accounting Errors. Directors frequently plead: "The CEO and CFO signed the Section 295A declaration, so the directors cannot be blamed for errors in the accounts." The Federal Court in the Centro case categorically rejected this argument: management declarations provide assurance, but they do not relieve directors of their statutory duty of care and diligence to scrutinize the financial reports.
Loading diagram...
The IIA Three Lines Model: Governance Oversight and Reporting Hierarchy
Test Your Knowledge

Under the Institute of Internal Auditors (IIA) Three Lines Model, what is the defining structural characteristic of the Second Line (Risk Management and Compliance functions) in comparison to the Third Line (Internal Audit)?

A
B
C
D
Test Your Knowledge

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) issued an updated Enterprise Risk Management (ERM) Framework in 2017 titled 'Integrating with Strategy and Performance'. Which of the following correctly identifies one of the five core components of the 2017 COSO ERM Framework?

A
B
C
D
Test Your Knowledge

Prior to the directors of an ASX-listed company approving the financial statements for the financial year, the CEO and CFO provide a written declaration under Section 295A of the Corporations Act. What is the precise legal effect of this declaration on the board of directors' fiduciary duty of care and diligence under Section 180(1)?

A
B
C
D