The Three Lines Model: Who Really Owns Risk in Your Organisation
What the Three Lines Model Actually Is
In 2020, the Institute of Internal Auditors updated its long-standing governance framework, moving away from the older “Three Lines of Defence” model to what is now called the Three Lines Model. The name change was not cosmetic. It reflected a shift in thinking: risk management is not just about defending the organisation from threats, it is also about helping the organisation create value responsibly.
Many organisations still use the two terms interchangeably, which causes confusion, because the two models are not the same. Understanding the difference matters for anyone responsible for governance, compliance, or internal audit.
The Three Lines, Explained Simply
The first line is operational management: the people running the day-to-day business, delivering products and services, and directly responsible for the risks that come with doing so. The second line is made up of specialist functions such as risk management, compliance, and quality assurance. Their job is to support and challenge the first line, providing expertise and oversight without taking over operational decisions. The third line is internal audit, which provides independent assurance to the governing body that risk management and controls are actually working — not just on paper.
The governing body itself was given a clearer, more explicit role in the 2020 update. Previously treated as a passive recipient of reports, it is now recognised as accountable for setting direction, delegating responsibility appropriately, and holding management to account.
Where the Model Breaks Down in Practice
One common failure is second-line overreach, where risk or compliance teams end up performing controls themselves — because the first line is stretched thin — rather than independently evaluating them. This blurs the line between doing the work and checking the work, which undermines the entire point of the structure.
A second failure is what might be called ownership blindness: operational managers assume that risk is “someone else’s job” — usually the risk department’s — instead of recognising that they own the risks created by their own decisions every day.
A third failure occurs when internal audit becomes involved in designing controls, and is later asked to audit those same controls. This compromises the independence that makes internal audit valuable in the first place.
Finally, many organisations treat the three lines as a sequence — first line acts, then second line reviews, then third line audits — rather than as three functions operating in parallel, with open communication between them. Treating it as a relay race rather than a team effort creates delays in spotting and escalating problems.
Why Structure Alone Is Not Enough
A number of well-publicised corporate failures have occurred inside organisations that had a Three Lines structure fully documented and formally in place. The lesson is sobering: having the model on paper does not guarantee it functions in reality. A structure can create a false sense of security, where each line assumes the others are covering a particular risk, and nobody actually investigates it closely.
The real test of whether the model is working is not whether the org chart looks right. It is whether second-line functions have genuinely influenced first-line decisions when it mattered, and whether internal audit has, at some point, delivered findings that were uncomfortable for management to hear. If neither of those things happens, the structure is decorative rather than functional.
The Takeaway
Mawa Events runs training programmes in governance, risk, internal audit, and compliance that help professionals apply frameworks like the Three Lines Model to real organisational challenges, rather than simply reciting the theory.