2.3 The Three Lines Model & Assurance Coordination

Key Takeaways

  • The IIA Three Lines Model (updated from the Three Lines of Defense) provides an agile governance framework establishing clear roles for operational management, oversight, and independent assurance.
  • The First Line (Operational Management) directly owns, assesses, and manages risks, executing daily operational controls and business processes.
  • The Second Line (Risk & Compliance Oversight) establishes risk management frameworks, policies, tools, and continuous compliance monitoring to support and challenge the First Line.
  • The Third Line (Internal Audit) provides independent, objective assurance directly to the Board / Audit Committee on the adequacy and effectiveness of First and Second Line governance and controls.
  • Assurance Coordination (Combined Assurance) eliminates audit fatigue, minimizes control testing redundancy, and harmonizes reporting across internal audit, external audit, and regulatory examiners.
Last updated: August 2026

2.3 The Three Lines Model & Assurance Coordination

To ensure that risk is managed comprehensively without gaps, blind spots, or organizational conflicts of interest, modern enterprises adopt the Three Lines Model, developed by the Institute of Internal Auditors (IIA).

Historically known as the Three Lines of Defense, the model was updated to emphasize that risk management is not merely a defensive posture aimed at preventing losses; it is an active, coordinated governance capability designed to protect and create organizational value through collaboration, alignment, and independent assurance.

+-----------------------------------------------------------------------------+
|                        THE IIA THREE LINES MODEL ARCHITECTURE               |
|                                                                             |
|                 +-----------------------------------------+                 |
|                 |             GOVERNING BODY              |                 |
|                 |  (Board of Directors / Audit Committee) |                 |
|                 +--------------------+--------------------+                 |
|                                      |                                      |
|                 Accountability to    |    Independent                       |
|                 Stakeholders & Direct|    Assurance &                       |
|                 Oversight            |    Reporting                         |
|                                      |                                      |
|                                      |                     +--------------+ |
|                                      |                     |  THIRD LINE  | |
|                                      |                     | Internal     | |
|                                      v                     | Audit        | |
|                 +--------------------+-------------------+ | (Independent | |
|                 |            EXECUTIVE MANAGEMENT        | |  Assurance)  | |
|                 +--------------------+-------------------+ +-------+------+ |
|                                      |                              |       |
|                 Delegated Authority  | Direction,                   |       |
|                 & Leadership         | Resources,                   |       |
|                                      | & Support                    |       |
|                                      v                              |       |
|         +----------------------------+----------------------------+ |       |
|         |                                                         | |       |
|         v                                                         v v       |
|   +--------------------------+              +-----------------------------+ |
|   |        FIRST LINE        |              |         SECOND LINE         | |
|   |  (Operational Mgmt)      | <----------> |     (Risk & Compliance)     | |
|   |                          |  Continuous  |                             | |
|   | - Own & manage risk      |  Challenge & | - Establish risk frameworks | |
|   | - Execute controls       |  Support     | - Monitor policy compliance | |
|   | - Deliver products/serv. |              | - Provide risk expertise    | |
|   +--------------------------+              +-----------------------------+ |
+-----------------------------------------------------------------------------+

1. Breakdown of the Three Lines

Each line in the model fulfills a distinct, non-overlapping mandate within the enterprise governance framework:

A. The First Line: Operational Management (Risk Ownership & Execution)

  • Who They Are: Frontline business unit leaders, application developers, systems engineers, plant operators, sales teams, and customer support managers.
  • Primary Mandate: Directly own and manage operational risks in their daily workflows.
  • Core Functions:
    • Design, embed, and execute internal control activities within business processes.
    • Identify emerging operational vulnerabilities and report risk events.
    • Conduct management self-assessments (Control Self-Assessments [CSA]) to verify control effectiveness.
    • Maintain operational compliance with enterprise policies and legal mandates.

B. The Second Line: Specialized Risk & Compliance Oversight

  • Who They Are: Enterprise Risk Management (ERM), Information Security (CISO Team), Regulatory Compliance, Data Privacy Office, Legal, and Quality Assurance.
  • Primary Mandate: Provide specialized expertise, establish policies and frameworks, monitor compliance, and actively challenge the First Line's risk decisions.
  • Core Functions:
    • Define enterprise-wide risk assessment methodologies, taxonomies, and scoring criteria.
    • Establish information security architecture, standards, and baselines.
    • Monitor organizational risk profiles against Board-approved Risk Appetite and Risk Tolerance limits.
    • Track Key Risk Indicators (KRIs) and provide aggregated risk reporting to Executive Management and the Risk Committee.
    • Provide training, tooling, and guidance to enable First Line teams to manage risk effectively.

[!NOTE] The Second Line's Independence Balance: While the Second Line maintains separation from frontline operational delivery (to ensure objective oversight), it remains part of Management and reports through the executive structure (e.g., CISO to CEO/CIO, CRO to CEO). The Second Line assists and advises, but does not own business assets.

C. The Third Line: Independent Assurance (Internal Audit)

  • Who They Are: The internal audit function, headed by the Chief Audit Executive (CAE).
  • Primary Mandate: Provide completely independent, objective assurance to the Governing Body (Board Audit Committee) and Executive Management on the adequacy, design, and operating effectiveness of governance, risk management, and internal controls.
  • Core Functions:
    • Evaluates whether First Line controls and Second Line oversight mechanisms are functioning effectively.
    • Conducts risk-based internal audits across all enterprise domains without operational bias.
    • Issues formal audit findings, tracks management remediation commitments, and reports directly to the Audit Committee.
+-----------------------------------------------------------------------------+
|                        THE THREE LINES COMPARISON MATRIX                    |
|                                                                             |
|   DIMENSION        FIRST LINE              SECOND LINE         THIRD LINE   |
|   ---------        ----------              -----------         ----------   |
|   Core Focus       Delivery & Execution    Oversight & Advice  Independent  |
|                                                                Assurance    |
|   Risk Role        Risk Owner & Operator   Risk Facilitator    Control      |
|                                            & Challenger        Evaluator    |
|   Reports To       Operational Execs       Executive Suite     Board / Audit|
|                                            (CEO/CRO/CISO)      Committee    |
|   Independence     None (Fully embedded)   Partial (Management Objective    |
|                                             oversight)         (No ops duty)|
+-----------------------------------------------------------------------------+

2. Maintaining Internal Audit Independence

A cornerstone principle of ISACA governance and the CRISC syllabus is preserving the strict independence and objectivity of the Third Line (Internal Audit).

+-----------------------------------------------------------------------------+
|                    INTERNAL AUDIT REPORTING ARCHITECTURE                    |
|                                                                             |
|   FUNCTIONAL REPORTING (Direct Independence)                                |
|   +---------------------------------------------------------------------+   |
|   |  BOARD OF DIRECTORS / AUDIT COMMITTEE                               |   |
|   |  - Approves the Internal Audit Charter and Annual Audit Plan        |   |
|   |  - Approves appointment, performance review, and compensation of CAE|   |
|   |  - Receives unfiltered audit reports and deficiency notifications   |   |
|   +-----------------------------------+---------------------------------+   |
|                                       ^                                     |
|                                       | (Functional Line)                   |
|                       +---------------+---------------+                     |
|                       | CHIEF AUDIT EXECUTIVE (CAE)  |                     |
|                       +---------------+---------------+                     |
|                                       | (Administrative Line)               |
|                                       v                                     |
|   ADMINISTRATIVE REPORTING (Day-to-Day Logistics)                           |
|   +---------------------------------------------------------------------+   |
|   |  CHIEF EXECUTIVE OFFICER (CEO) / GENERAL COUNSEL                    |   |
|   |  - Budget administration, office space, payroll, HR logistics       |   |
|   |  - NO authority to alter audit findings or restrict audit scope     |   |
|   +---------------------------------------------------------------------+   |
+-----------------------------------------------------------------------------+

[!CAUTION] CRISC Core Exam Trap — Never Let Auditors Design Controls: If an exam question asks whether Internal Audit should help configure a firewall, write an incident response plan, or select a new SIEM platform, the answer is ABSOLUTELY NOT. If Internal Audit designs, implements, or operates a control, they develop an inherent conflict of interest and cannot independently audit that control later. Internal Audit can provide advisory perspectives on control design criteria, but management must maintain 100% ownership of implementation.


3. Assurance Coordination & Combined Assurance

In large enterprises, organizations face a barrage of internal and external assessments, including:

  • First Line Control Self-Assessments (CSA)
  • Second Line information security vulnerability tests and compliance reviews
  • Third Line internal audits
  • External financial audits (e.g., Sarbanes-Oxley 404 testing by PCAOB-registered accounting firms)
  • Regulatory exams (e.g., Federal Reserve, OCC, SEC, European Data Protection Authorities)
  • Third-party customer vendor security audits (SOC 1, SOC 2 Type II, ISO 27001 certifications)

The Problem of "Audit Fatigue" & Siloed Testing

When multiple assurance providers work in isolation without coordination:

  1. Audit Fatigue: Operational and engineering teams spend hundreds of hours answering duplicate evidence requests from different auditors, crippling business productivity.
  2. Conflicting Conclusions: Different auditors evaluate the same system using different criteria, producing contradictory risk ratings.
  3. Assurance Gaps: While low-risk areas are tested redundantly, high-risk interconnected systems fall through the cracks.
+-----------------------------------------------------------------------------+
|                        COMBINED ASSURANCE FRAMEWORK                         |
|                                                                             |
|   [ENTERPRISE RISK TAXONOMY & REGISTER] (Single Source of Risk Truth)       |
|                               |                                             |
|                               v                                             |
|   +---------------------------------------------------------------------+   |
|   |                     COMBINED ASSURANCE MAPPING                      |   |
|   |                                                                     |   |
|   |   Enterprise Risk     1st Line        2nd Line   3rd Line  External |
|   |   ----------------    --------        --------   --------  -------- |
|   |   Cloud IAM Security  Self-Assess     CISO Scan  IA Audit  SOC 2 Rep|
|   |   Financial Reporting Fin. Controls   SOX PMO    SOX Audit Ext. CPA |
|   |   Data Privacy (GDPR) Ops Walkthrough DPO Review GDPR Audit DPA Reg |
|   +---------------------------------------------------------------------+   |
|                               |                                             |
|                               v                                             |
|   [HARMONIZED EXECUTIVE REPORTING] (Holistic Control & Residual Risk View)  |
+-----------------------------------------------------------------------------+

Mechanics of Combined Assurance:

  • Shared Risk Taxonomy: All lines and external assurance providers use standardized definitions for risk likelihood, impact, and control effectiveness.
  • Coordinated Audit Planning: Internal Audit, external auditors, and compliance teams cross-rely on testing workpapers where standards permit (e.g., external auditors relying on internal audit's SOX control testing under PCAOB standards).
  • Centralized Evidence Repositories: GRC software tools store policy documents, system configurations, and control testing artifacts in a centralized repository to eliminate redundant evidence requests.
  • Unified Risk Dashboard: The Board Audit Committee receives an aggregated, holistic report illustrating total assurance coverage across all three lines.

4. Exam Traps & Real-World Vignette

+-----------------------------------------------------------------------------+
|                  CRISC EXAM SCENARIO: THE SECOND LINE OVERSTEP              |
|                                                                             |
|   SCENARIO:                                                                 |
|   Due to severe staffing shortages in the IT department, the Chief Risk     |
|   Officer (CRO) directs the Second-Line Information Security team to take   |
|   over daily administrator account approvals and firewall rule changes.    |
|                                                                             |
|   QUESTION:                                                                 |
|   What is the GREATEST governance risk created by this arrangement?         |
|                                                                             |
|   ANALYSIS & CORRECT PERSPECTIVE:                                           |
|   By operating daily access controls, the Second Line has compromised its   |
|   ability to provide objective oversight. They are now auditing their own   |
|   operational decisions. If an unauthorized rule change is made, the risk   |
|   team has a direct conflict of interest in reporting the failure.         |
+-----------------------------------------------------------------------------+
Test Your Knowledge

Under the IIA Three Lines Model, which function is PRIMARY to the mandate of the Second Line?

A
B
C
D
Test Your Knowledge

To maintain independence and objectivity, how should the Chief Audit Executive (CAE) and the Internal Audit function be structured within the enterprise reporting hierarchy?

A
B
C
D
Test Your Knowledge

An enterprise is experiencing severe operational friction because frontline business managers claim that IT risk management is solely the responsibility of the security department. According to the Three Lines Model, which line of defense holds direct ownership and primary responsibility for managing operational risk?

A
B
C
D
Test Your Knowledge

An enterprise operating in highly regulated financial markets is experiencing severe 'audit fatigue' due to overlapping and redundant control testing requests from internal audit, external SOX auditors, regulatory examiners, and SOC 2 assessors. What is the BEST strategic approach to resolve this issue?

A
B
C
D