Governance · Risk management · Roles

The Three Lines of Defence model: who does what in the face of risk

«Who is responsible for risk management within the company?» The answer lies in a simple and proven model — the three lines model — which clearly allocates roles between management, control functions and internal audit. A valuable reference for any executive and director.

Category: Governance Reading time: 4 minutes Series: Understanding internal audit (2/7)

Formalised by the Institute of Internal Auditors (IIA), the three lines model addresses a fundamental governance question: within an organisation, who owns risk, who oversees it, and who provides an independent view of it? Its strength lies in its simplicity. It avoids two classic pitfalls: believing that «everyone is looking after it» (and therefore no one is) or, conversely, thinking that risk management is the concern of a single department.

A model for clarifying responsibilities

1st line The professions that take and manage risks
2nd line Risk and compliance, which govern
3rd line Internal audit: independent assurance

First and second lines: act and regulate

The first line, these are the business functions: sales, production, IT, finance... Those who create value also take risks, and bear primary responsibility for them. They apply the controls integrated into their processes on a daily basis.

The second line brings together the functions that provide oversight and monitoring: risk management, compliance, internal control and security. These functions set the rules, provide support to the business units and alert senior management. They form part of the management team: they advise and monitor, but remain within the management’s line of authority.

The third line: independent assurance

L'internal audit function forms the third line of defence. Its distinctive feature — and its greatest value — is its independence: it does not carry out the processes it assesses and is not dependent on operational management. It checks that the first and second lines are doing their jobs properly, and then reports directly to the board or the audit committee. It is this objectivity that enables a credible assessment.

An image: on a building site, the teams are constructing (1re line), the control body checks the standards along the way (2e line), and an independent expert validates the structural integrity of the work before it is commissioned (3e line). All three are necessary; none replaces the others.

The role of the board in this scheme

The board of directors sits at the top of the structure. It sets the direction, defines the acceptable level of risk and oversees the whole. Its role is notably to guarantee the independence of the third line: without internal audit reporting at the right level and genuinely listened to, the model loses its purpose. Understanding these three lines means being able to ask the right questions and identify areas where responsibilities overlap — or, conversely, where no one assumes them.

Clarify the roles within your risk management framework.

ARCAD helps to position each line — and to reinforce the third.

Schedule an exchange →

References & further reading

  • The Three Lines Model, Institute of Internal Auditors (IIA), 2020.