Governance · Risk management · Roles
The Three Lines of Defence model: who does what in the face of risk
«Who is responsible for risk management within the company?» The answer lies in a simple and proven model — the three lines model — which clearly allocates roles between management, control functions and internal audit. A valuable reference for any executive and director.
Formalised by the Institute of Internal Auditors (IIA), the three lines model addresses a fundamental governance question: within an organisation, who owns risk, who oversees it, and who provides an independent view of it? Its strength lies in its simplicity. It avoids two classic pitfalls: believing that «everyone is looking after it» (and therefore no one is) or, conversely, thinking that risk management is the concern of a single department.
A model for clarifying responsibilities
First and second lines: act and regulate
The first line, these are the business functions: sales, production, IT, finance... Those who create value also take risks, and bear primary responsibility for them. They apply the controls integrated into their processes on a daily basis.
The second line brings together the functions that provide oversight and monitoring: risk management, compliance, internal control and security. These functions set the rules, provide support to the business units and alert senior management. They form part of the management team: they advise and monitor, but remain within the management’s line of authority.
The third line: independent assurance
L'internal audit function forms the third line of defence. Its distinctive feature — and its greatest value — is its independence: it does not carry out the processes it assesses and is not dependent on operational management. It checks that the first and second lines are doing their jobs properly, and then reports directly to the board or the audit committee. It is this objectivity that enables a credible assessment.
The role of the board in this scheme
The board of directors sits at the top of the structure. It sets the direction, defines the acceptable level of risk and oversees the whole. Its role is notably to guarantee the independence of the third line: without internal audit reporting at the right level and genuinely listened to, the model loses its purpose. Understanding these three lines means being able to ask the right questions and identify areas where responsibilities overlap — or, conversely, where no one assumes them.
ARCAD helps to position each line — and to reinforce the third.
References & further reading
- The Three Lines Model, Institute of Internal Auditors (IIA), 2020.