4.2 Three Lines Model & Risk Management Role

Key Takeaways

  • The IIA's Three Lines Model (2020) clarifies governance roles: first line owns risk/control, second line enables/monitors, third line provides independent assurance
  • Internal audit is the third line; taking ongoing first- or second-line duties threatens organizational independence and objectivity
  • Designing controls, owning risk registers, or running compliance monitoring as a standing duty can impair independence if IA later must assure those areas
  • When IA must perform or is perceived to perform first- or second-line work, apply safeguards: board approval, time limits, separate staffing, and disclosure
  • Safeguards reduce but do not erase the threat—disclosure to the board and careful role design remain essential
Last updated: July 2026

Why the Three Lines Model Matters for Independence

Domain A does not treat independence as an abstract reporting-chart problem alone. Independence is also threatened when internal audit does management's job—owning risks, designing controls, or running ongoing compliance and risk-monitoring activities—and then tries to give assurance over the same terrain. The IIA Three Lines Model (2020) is the framework the exam uses to keep those roles straight.

The 2020 model updated earlier "three lines of defense" language. It emphasizes collaboration under board and management governance rather than rigid silos, but it still draws a bright line: internal audit's core role is independent assurance and advice as the third line. Blurring that line is how well-intentioned "extra help" becomes an independence impairment.

The IIA Three Lines Model (2020) at a Glance

Governing bodies and senior management set the direction. Beneath that umbrella, accountability for risk and control is distributed across three lines:

LinePrimary playersCore dutiesIndependence implication for IA
First lineOperational management and staffOwn and manage risk; design and operate controls; deliver products/services within risk appetiteIf IA operates or owns these duties ongoing, it cannot independently assure them
Second lineRisk management, compliance, financial control, security, quality, and similar specialistsProvide expertise, monitoring, challenge, and frameworks that help the first line manage riskIf IA runs second-line monitoring or owns the ERM framework as a standing duty, assurance over those areas is compromised
Third lineInternal auditProvide independent and objective assurance and advice on governance, risk management, and control to the board and senior managementIA preserves independence by staying in this lane, with dual reporting and unrestricted access

Key 2020 messaging you should be able to paraphrase:

  • First line is not "the enemy of audit"; it is accountable for day-to-day risk and control.
  • Second line supports and monitors; it does not replace first-line ownership, and it is not a substitute for third-line independent assurance.
  • Third line has a unique independence mandate. Coordination with first and second lines is encouraged for efficiency and insight, but coordination is not the same as absorbing their responsibilities.
  • External assurance providers (regulators, external auditors) sit outside the three lines but interact with them; they do not relieve the board of the need for a robust internal third line.

First-Line Duties That Impair Internal Audit Independence

First-line work is management ownership of processes and controls. Internal audit impairs independence when it becomes the standing owner or operator of what it may later need to assure. High-yield examples:

  • Designing or implementing controls, policies, or procedures that management will rely on as the control environment—then providing assurance that those controls are effective.
  • Operating a control on behalf of the business (approving transactions, performing reconciliations that are a management control, administering user access as the system owner).
  • Owning operational performance for a process (acting as process owner for procure-to-pay, acting as backup business continuity commander as a permanent role).
  • Making management decisions that belong to first-line leaders (selecting vendors, setting prices, hiring for the business unit).

Why impairment occurs: assurance requires the ability to evaluate without defending one's own prior design or operational choices. Self-review and advocacy threats appear immediately. Even if a different auditor is later assigned, stakeholders may perceive the function as part of management.

Limited, clearly advisory input—such as recommending control options during a consulting engagement, while management retains decision rights and implementation ownership—is different from IA becoming the control designer-implementer of record. The exam cares about who owns the outcome and whether IA will later need to assure it.

Second-Line Duties That Impair Internal Audit Independence

Second-line functions help the organization identify, measure, monitor, and report risk and compliance. They are essential—and they are management. Independence problems arise when internal audit is the second line on an ongoing basis, including:

  • Serving as the organization's chief risk officer or owning the enterprise risk management (ERM) process end-to-end (maintaining the corporate risk register as the accountable owner, facilitating appetite decisions as decision-maker rather than advisor).
  • Running ongoing compliance monitoring, mandatory training administration, or regulatory filings as the compliance function.
  • Acting as management's continuous control monitoring team with operational accountability for fixing exceptions.
  • Owning information security operations or privacy program management while also auditing those domains.

A temporary project to help stand up an ERM framework, with a clear handoff to a second-line owner, is often manageable with safeguards. A permanent arrangement where "internal audit is risk management" collapses the third line into the second. The board then lacks an independent assurers of risk management effectiveness—the very assurance Domain A expects internal audit to provide.

Perception counts. If business leaders introduce IA as "our risk and compliance department," stakeholders will treat IA reports as management self-assessment even when engagement letters say "assurance."

Internal Audit's Proper Risk Management Role

Internal audit does evaluate risk management. That is third-line work, not second-line ownership. Appropriate IA roles include:

  • Assessing whether risk governance, appetite, identification, assessment, response, and reporting processes are designed and operating effectively.
  • Providing assurance to the board on the adequacy of first- and second-line risk activities.
  • Offering advice (consulting) on improving risk practices, without taking ownership of risk responses or becoming the ERM owner.
  • Coordinating with second-line teams to reduce duplication of coverage while preserving the right to re-test and challenge.

Inappropriate role creep includes drafting the corporate risk appetite for board approval as if IA were management, deciding residual risk acceptance for the business, or being the sole facilitator who also "signs off" that ERM is effective without independent evaluation criteria.

Safeguards When IA Performs—or Is Perceived to Perform—First- or Second-Line Work

Sometimes small organizations lack a separate second line, a crisis requires surge support, or management asks IA to implement a control after a failed audit. The Standards do not pretend this never happens; they require safeguards so independence is protected to the extent possible and impairments are transparent.

Effective safeguards—often used in combination:

  1. Board (audit committee) awareness and approval before IA accepts significant first- or second-line responsibilities, including discussion of independence impact.
  2. Time-boxing: define the assignment as temporary, with a documented end date and handoff to management ownership.
  3. Segregation of personnel: staff who designed, implemented, or operated the activity do not provide assurance over it; use different auditors, co-sourcing, or external providers for subsequent assurance.
  4. One-year / cooling-off logic (aligned with objectivity rules): avoid assurance over areas where the same individuals recently had operating responsibility until sufficient time and independent review intervene.
  5. Charter and role clarity: written statements that management retains accountability; IA's extra work is support, not ownership of risk.
  6. Disclosure: communicate the nature of the dual role and residual independence/objectivity limitations to the board (and engagement clients as appropriate) so users of assurance do not over-rely.
  7. Supervision and quality review by individuals not involved in the first/second-line activity.

Safeguards mitigate; they do not license indefinite role collapse. If IA permanently runs compliance monitoring, no amount of disclosure fully restores the third line's unique value. The preferred long-term fix is to return first- and second-line duties to management and keep IA in assurance and advisory mode.

Worked scenarios

Management asks the CAE to "own SOX testing" indefinitely because finance is short-staffed, and later wants IA to opine on control effectiveness for the audit committee.

Ongoing ownership of management's control testing is second-line (or first-line support) work. Accepting it without safeguards impairs independence. Better path: board-approved temporary assistance, handoff plan, separate assurance providers or staff for any opinion-level reporting, and clear disclosure of limitations.

IA facilitates workshops to help management build a risk register, management chooses ratings and responses, and a different IA team later assures the ERM process.

Facilitation with management ownership is closer to acceptable advisory support. Safeguards still matter: document that management owned decisions, keep facilitators off the assurance team, and avoid marketing the workshop as "IA certified the risk ratings."

Employees routinely say "call audit—they approve all new vendor setups."

Perception of first-line approval authority is itself a problem. The CAE should stop the approval practice, return authority to management, communicate the independence issue to the board if the practice was material, and redesign the control so IA is not a required approver.

Exam Decision Rules

  • If the stem asks who owns risk and controls day to day → first line (management).
  • If the stem describes frameworks, monitoring, and compliance challenge → second line.
  • If the stem asks who provides independent assurance to the board on those activities → third line (internal audit).
  • If IA is designing, operating, approving, or continuously monitoring as a standing duty → flag an independence impairment and look for safeguards + disclosure + handoff, not silent acceptance.
  • Coordination and reliance on second-line work can be efficient; replacing the second line is not.

Mastering the Three Lines Model lets you spot independence threats that never appear in an org chart—because the threat is what internal audit has agreed to do, not only to whom the CAE reports.

Test Your Knowledge

Under the IIA Three Lines Model (2020), which statement best describes internal audit's role?

A
B
C
D
Test Your Knowledge

The CAE agrees that internal audit will permanently maintain the enterprise risk register, facilitate risk appetite decisions, and report residual risk to the board as the organization's ERM owner. Which independence concern is most directly raised?

A
B
C
D
Test Your Knowledge

A small organization asks internal audit to design and temporarily operate a new vendor-approval control for six months while management hires a process owner. Which combination of safeguards best protects independence?

A
B
C
D