2.3 Building a Risk-Aware Culture and the Three Lines Model
Key Takeaways
- A healthy risk culture is driven by tone at the top, psychological safety, transparent communication, and alignment of incentives with risk appetite.
- The 2020 IIA Three Lines Model replaces the traditional defensive model with a holistic governance framework focused on value creation and protection.
- 1st Line roles (Operational Management) directly own, identify, assess, and manage operational risks and controls during execution.
- 2nd Line roles (Risk & Compliance) provide specialized expertise, framework monitoring, policy guidance, and constructive challenge to the 1st line.
- 3rd Line roles (Internal Audit) maintain complete operational independence to provide objective assurance to the governing body.
2.3 Building a Risk-Aware Culture and the Three Lines Model
No matter how sophisticated an organization's risk management policies, software tools, or governance structures may be, they will prove ineffective if unsupported by a strong risk-aware culture. The human element remains the single most critical factor determining whether risks are proactively identified and managed or ignored until failure occurs.
To institutionalize risk management, organizations combine cultural transformation initiatives with clear governance frameworks, most notably The IIA Three Lines Model (updated by the Institute of Internal Auditors in 2020).
Drivers of a Risk-Aware Organizational Culture
Risk culture refers to the shared values, beliefs, attitudes, knowledge, and understanding about risk that influence decision-making and behaviors across an enterprise. A strong risk culture encourages employees to actively look for risks, escalate concerns without fear, and take responsibility for managing risk within their operational domains.
Primary Culture Drivers
- Tone at the Top: Executive leadership and governing bodies must model risk-aware behaviors. When leaders demonstrate that risk management is integral to decision-making, employees emulate those priorities.
- Psychological Safety and Open Communication: Creating an environment where staff can report errors, near-misses, and emerging threats without fear of retaliation or punitive reprisal. Suppressing bad news is a primary cause of catastrophic organizational failure.
- Incentive Structure Alignment: Compensation, bonuses, and promotion criteria must reward prudent risk management and long-term value preservation, rather than solely rewarding short-term volume or revenue achieved through excessive risk-taking.
- Clear Accountability: Every employee must understand their explicit role in risk management. Risk is recognized as the responsibility of all staff, not merely the risk department.
- Continuous Learning and Capability Building: Conducting regular risk training, analyzing operational near-misses, and embedding lessons learned into business workflows.
| Organizational Attribute | Healthy Risk-Aware Culture | Vulnerable / Toxic Risk Culture |
|---|---|---|
| Treatment of Bad News | Escalated promptly; treated as learning opportunity | Suppressed or concealed due to fear of punishment |
| Incentives & Bonuses | Tied to risk-adjusted long-term performance | Linked exclusively to short-term revenue/volume |
| Risk Ownership | Owned directly by line managers & operational staff | Delegated entirely to the risk/compliance department |
| Tone at the Top | Transparent, ethical, risk-conscious leadership | Profit-at-all-costs leadership; rules ignored for VIPs |
The IIA Three Lines Model (2020 Revision)
In 2020, the Institute of Internal Auditors (IIA) updated the classic "Three Lines of Defense" framework, renaming it The IIA Three Lines Model. This update represented a major conceptual shift: moving away from a purely defensive, reactive posture focused on protection to a flexible governance model emphasizing value creation, value protection, alignment, and collaboration.
The Three Lines Model defines how organizational roles interact to achieve effective governance, risk management, and internal control.
+-----------------------------------------------------------------------------------+
| GOVERNING BODY |
| Accountability to stakeholders for organizational oversight |
+---------------------------------------+-------------------------------------------+
| (Oversight & Directives)
v
+---------------------------------------+-------------------------------------------+
| EXECUTIVE MANAGEMENT |
+---------------------------------------+-------------------------------------------+
| 1st LINE ROLES | 2nd LINE ROLES |
| Operational Management | Risk & Compliance Functions |
| - Provision of products/services | - Expertise, support, and monitoring |
| - Owning and managing operational | - Policy development & risk framework |
| risks and controls | - Constructive challenge to 1st line |
+---------------------------------------+-------------------------------------------+
^
| (Independent Assurance & Escalation)
+---------------------------------------+-------------------------------------------+
| 3rd LINE ROLES: INTERNAL AUDIT |
| - Independent, objective assurance and advice to Governing Body |
+-----------------------------------------------------------------------------------+
Detailed Examination of the Three Lines
1. First-Line Roles: Operational Management
First-line roles are executed by operational managers, department heads, and front-line staff who directly deliver products and services to customers. First-line responsibilities include:
- Risk Ownership: Directly identifying, assessing, owning, and mitigating risks inherent in daily operations.
- Control Design and Execution: Designing, implementing, and maintaining effective internal operational controls.
- Compliance Execution: Ensuring daily business activities adhere to legal, regulatory, and internal policy standards.
Exam Tip: On the exam, remember that the 1st Line ALWAYS owns the risk. The risk department does not own operational risk.
2. Second-Line Roles: Risk Management and Compliance Functions
Second-line roles provide specialized expertise, oversight, guidelines, and monitoring to assist first-line management. Key second-line functions include enterprise risk management (ERM), regulatory compliance, information security (CISO), quality assurance, and environmental health and safety. Responsibilities include:
- Framework Development: Establishing risk tools, assessment templates, and standardized criteria.
- Monitoring and Reporting: Monitoring 1st line risk management practices and aggregating enterprise risk profiles.
- Constructive Challenge: Analyzing 1st line risk assessments and challenging over-optimistic risk assumptions.
3. Third-Line Roles: Internal Audit
Third-line roles are fulfilled by Internal Audit, which provides independent and objective assurance and advice to the governing body and senior management. Responsibilities include:
- Independent Assurance: Assessing the adequacy, efficiency, and effectiveness of governance, risk management, and 1st/2nd line controls.
- Process Auditing: Evaluating whether 1st line controls and 2nd line oversight are functioning as intended.
- Direct Escalation: Reporting audit findings directly to the Board Audit Committee without management filtering.
| Model Layer | Primary Functions | Key Roles | Reporting Line | | :--- | :--- | :--- | | Governing Body | Enterprise oversight, stakeholder accountability | Board of Directors, Audit Committee | To External Stakeholders | | 1st Line | Owns and manages risks & operational controls | Line Managers, Operations, Sales, IT Ops | To CEO & Senior Management | | 2nd Line | Expertise, support, monitoring, constructive challenge | Enterprise Risk Team, Compliance, CISO | To Executive Management | | 3rd Line | Independent, objective assurance & advice | Internal Audit, Chief Audit Executive | Directly to Governing Body |
Safeguarding Independence and Overcoming Silos
A critical exam topic is the preservation of 3rd Line Independence. To maintain objectivity, internal audit staff must not engage in 1st line operational management or 2nd line control design. If internal audit designs a control, it cannot objectively audit that control later.
Additionally, the Three Lines Model requires active collaboration. Organizations must avoid creating rigid silos where 2nd line functions (such as compliance and risk) duplicate testing efforts or create audit fatigue for 1st line staff. Regular alignment meetings ensure audit plans and risk monitoring are coordinated enterprise-wide.
Real-World Exam Example: Three Lines Restructuring
Following a significant regulatory compliance fine, a global commercial bank restructured its operational risk model. Previously, line managers assumed the central compliance team was solely responsible for risk checks (confusing 1st and 2nd line duties). The bank clarified that branch managers (1st Line) owned customer compliance checks, while the compliance department (2nd Line) provided policy monitoring, and Internal Audit (3rd Line) conducted independent sampling. Within one year, control testing coverage doubled and compliance errors fell by 60%.
Summary of Key Exam Concepts
On the PECB ISO 31000 Risk Manager exam, remember that 1st line operational management owns and manages risk, 2nd line functions provide framework oversight and challenge, and 3rd line internal audit provides independent assurance directly to the governing body. A healthy risk culture, fostered by leadership tone and psychological safety, is what enables all three lines to function effectively.
In the IIA Three Lines Model, what is the primary responsibility of 1st line operational management roles?
How does the 2020 IIA Three Lines Model differ conceptually from the traditional 'Three Lines of Defense' framework?
What mechanism is essential to preserve the objective assurance capability of 3rd line Internal Audit functions?