Governance, Risk & Compliance

Three Lines of Defense: The Risk Governance Model

Standarity Editorial Team·GRC and Internal Audit Practitioners
··6 min read

The Three Lines of Defense is a risk governance model that assigns clear accountability across three roles: operational management that owns and manages risk, risk and compliance functions that provide oversight, and internal audit that delivers independent assurance. It was introduced by the Institute of Internal Auditors in 2013.

Why the model exists

Large organizations run many activities that each carry risk, and without a shared map of who does what, controls get duplicated in some places and left uncovered in others. The Three Lines of Defense model solves this by separating three responsibilities that must never collapse into one: doing the work and managing its risk, overseeing how risk is managed, and independently checking that the whole system works. When these roles are distinct, the governing body can trust the assurance it receives.

The model is deliberately simple so it can apply to a bank, a hospital, or a software company. It does not prescribe an org chart. Instead it describes a set of duties that need clear owners. This is why it sits at the center of most GRC operating models, and it pairs naturally with control self-assessment. Our guide to the RCSA process shows how the first line documents and rates its own controls, while our GRC operating model post explains how the three lines connect to committees and reporting lines.

The three lines explained

Each line has a distinct job. The relationships between them are built on collaboration, oversight, and independence. Here is what each one owns, with concrete examples.

  • First line (operational management): owns and manages risk in day-to-day work. It designs and operates controls. Examples include a lending officer applying credit checks, a wire-transfer team enforcing dual approval, or a developer running code scans before release.
  • Second line (risk and compliance): provides oversight, frameworks, policies, and monitoring. It sets risk appetite and challenges the first line. Examples include a compliance team tracking regulatory breaches or an operational risk function maintaining the risk register.
  • Third line (internal audit): provides objective, independent assurance on whether the first and second lines work. Internal auditors evaluate governance, risk, and control processes and report findings straight to the audit committee.
  • Governing body and board: sits above the three lines, sets direction, delegates authority to management, and relies on the third line for independent assurance about the whole system.

The Institute of Internal Auditors introduced the Three Lines of Defense in 2013 and issued a major update in July 2020, renaming it the Three Lines Model to stress value creation alongside protection (Source: The IIA, July 2020 position paper).

What the 2020 update changed

In July 2020 the IIA released an important update. It shortened the name from Three Lines of Defense to Three Lines Model to de-emphasize a purely defensive posture. The reasoning was that risk-based decisions are as much about seizing opportunities as about protecting value, so a defensive metaphor undersold what good risk management contributes. The updated model is principles-based, and it puts more weight on the roles of the governing body and on collaboration between the lines rather than rigid walls.

One notable shift is that the updated model expressly permits an organization to blur the first and second line roles where that helps, while keeping the third line firmly separate so it can still provide independent and objective assurance. In other words, some flexibility between doing and overseeing is acceptable, but assurance must stay independent.

Common criticisms and pitfalls

The model is widely used, but practitioners have documented recurring failure modes. Understanding them helps you apply the framework rather than turn it into a paperwork exercise.

  • Second line doing first line work: when the second line takes on control operation because the first line lacks knowledge or motivation, ownership erodes and no one truly owns the risk.
  • Blurred lines that go too far: some overlap is now allowed, but if the third line loses independence, its assurance is worthless.
  • Adversarial relationships: the first line wants to take more risk while the second line wants to hold it down, and walls can form that block honest challenge.
  • Weak second line independence: a risk function sitting too close to profit-seekers, or lacking the skills to challenge, cannot provide real oversight.
  • Paperwork over change: applying the labels to existing practice without changing behaviour turns the model into a compliance ritual.

How it maps to GRC and operational risk

In a mature GRC program, the three lines give every activity a home. The first line performs risk and control self-assessments and remediates issues. The second line aggregates those results into an enterprise risk register, sets appetite, and reports to a risk committee. The third line audits both. Operational risk programs lean heavily on this structure because loss events, control failures, and near misses all need an owner, an overseer, and an independent checker. When you design roles this way, board reporting becomes coherent and gaps become visible.

The lesson is that the Three Lines model is not an org chart to copy but a set of duties to assign clearly. Keep ownership with the first line, keep oversight meaningful in the second, and keep the third line independent, and the model does its job.

Frequently Asked Questions

What is the Three Lines of Defense model?

It is a risk governance framework that assigns three distinct roles: operational management that owns and manages risk, risk and compliance functions that provide oversight, and internal audit that provides independent assurance. The IIA introduced it in 2013.

Why is it now called the Three Lines Model?

In July 2020 the IIA renamed it from Three Lines of Defense to Three Lines Model to move away from a purely defensive metaphor and stress that good risk management also enables value creation and seizing opportunities.

Who owns risk in the first line of defense?

Operational management, meaning the process owners closest to the activity, own and manage risk. They design, operate, and implement the controls that keep day-to-day work within acceptable limits.

What does the second line of defense do?

The second line provides oversight. It sets frameworks, policies, and monitoring, defines risk appetite, and challenges the first line. It does not own the risk; it helps ensure the first line manages it well.

What is the difference between the second and third lines?

The second line oversees and supports risk management as part of management. The third line, internal audit, is independent of management and provides objective assurance on whether the first and second lines are actually working.

Explore Courses on Udemy

Intermediate

Implement GRC (Governance, Risk, Compliance) Step by Step

Intermediate

Implement Operational Risk Management Step by Step

Intermediate

CRISC Certification — IT Risk Management with AI Tools