Three Lines Model

Three Lines Model - Umbrex Frameworks

1. What Is Three Lines Model?

The Three Lines Model is a governance and risk-accountability framework that clarifies who owns risk, who oversees and challenges risk management, and who provides independent assurance. In plain terms, it helps an organization answer a recurring question: when something goes wrong, or could go wrong, which part of the company was supposed to manage it, monitor it, or test it?

It is especially common in financial services, where regulators, boards, and executives need clear separation among frontline business teams, independent risk and compliance functions, and internal audit. Consultants often use the model as a practical diagnostic when a bank, insurer, asset manager, or other regulated firm is redesigning its control environment, responding to regulatory findings, or scaling its governance model.

The model is not a strategy tool and not a control checklist. It is a role-clarity framework. Its value lies in making accountabilities explicit so that risk management and control do not fall into the gaps between functions.

2. Origin and Background

The concept is evolutionary rather than attributable to a single inventor. Variants of the “three lines of defense” idea were in use in risk management and internal audit practice before the current model was formally named. The Institute of Internal Auditors, or IIA, gave the concept its most influential expression in its 2013 position paper on the “Three Lines of Defense,” and updated it in 2020 as “The IIA’s Three Lines Model.”

The update mattered. The earlier language emphasized defense and separation. The 2020 model kept the basic logic of distinct roles, but reframed it around governance, collaboration, accountability, and the shared goal of creating and protecting value. It was designed to solve a practical problem: many organizations had risk, compliance, finance, operations, and audit teams, but unclear boundaries between them. As a result, businesses sometimes assumed that control functions “owned” risk, second-line teams drifted into operating work, and boards received assurance that was fragmented or incomplete.

The model became widely known through internal audit and risk communities, board and audit committee practice, and strong resonance with regulatory expectations in banking, insurance, and other regulated sectors. Regulators do not all use the same label, but many supervisory frameworks reflect the same underlying logic: the business manages risk, independent functions oversee and challenge, and internal audit provides objective assurance.

3. How Three Lines Model Works

The core logic is simple. The model separates responsibilities into three broad lines of roles, with the governing body above them and external assurance around them. The first line runs the business and manages risk in day-to-day decisions. The second line provides expertise, standards, monitoring, and challenge. The third line, internal audit, assesses whether governance, risk management, and controls are working as intended.

The important nuance is that these are roles, not just boxes on an org chart. A function may perform mostly first-line work, mostly second-line work, or in some cases a mix of activities that must be carefully separated. The point is not to label departments. The point is to define responsibilities clearly enough that incentives, escalation paths, and assurance remain credible.

ElementPrimary responsibilityTypical examples
Governing bodySets direction, oversees management, approves risk appetite, and holds the organization accountableBoard, supervisory board, audit committee, risk committee
First lineDelivers products and services and owns the risks and controls embedded in operationsBusiness units, operations, product teams, customer-facing teams, process owners
Second lineProvides policies, frameworks, advice, monitoring, and challengeRisk management, compliance, financial control, information security, quality
Third lineProvides independent assurance and insight on governance, risk management, and internal controlInternal audit
External assuranceProvides additional assurance outside managementExternal auditors, regulators, certification bodies

In the IIA’s 2020 update, the model is also framed through principles covering governance, governing-body roles, management roles, third-line roles, internal-audit independence, and the objective of creating and protecting value. In practice, most consulting teams use the model to answer a few concrete questions: Is the business truly owning risk? Is the second line independent enough to challenge? Is internal audit focused on assurance rather than management work? And does the board receive a coherent view across all three?

4. When to Use Three Lines Model

The Three Lines Model is most useful when role ambiguity is the real problem. That is common in regulated firms that have grown quickly, merged, launched new products, digitized legacy processes, or received supervisory findings. It is especially powerful when executives suspect that risk, compliance, and audit are all active, yet key issues still recur because no one has clear end-to-end ownership.

Typical use cases include governance redesign, regulatory remediation, control-function operating-model reviews, issue-management redesign, internal-audit mandate clarification, and pre-growth or pre-IPO strengthening of oversight. It is relevant to large universal banks, insurers, and asset managers, but also to smaller regulated institutions that need proportionate separation of duties.

To use it well, teams typically need org charts, committee charters, policy inventories, risk taxonomies, control standards, reporting lines, key-process maps, issue logs, recent audit or regulatory findings, and interviews with business, risk, compliance, and audit leaders. A high-level diagnostic can often be completed in two to six weeks; a full redesign and implementation plan usually takes longer.

It is not a good fit when the problem is purely technical, such as designing a specific control or calculating a capital model. It can also mislead when applied too mechanically. If a firm treats it as a mandatory org chart, it may create bureaucracy without improving accountability. The model works best when several assumptions are true: management is willing to own risk, the second line has enough independence and skill to challenge constructively, internal audit is truly independent, and leadership wants clarity rather than turf protection. Modern practitioners therefore use it less as a rigid “defense” structure and more as a principles-based governance model tailored to the business.

5. How to Apply Three Lines Model: Step-by-Step

  1. Clarify the decision and scope. Start with the business question. Are you redesigning enterprise-wide governance, fixing a specific regulatory issue, or clarifying roles for one product, risk type, or legal entity? Define the time horizon, the parts of the organization in scope, and what decision management or the board must make at the end.

  2. Gather the required inputs and data. Collect formal documents and practical evidence. That includes policies, charters, org charts, committee terms of reference, risk and control frameworks, audit plans, issue logs, escalation records, and management information. Interviews are critical because the formal model and the lived model are often different.

  3. Define the units of analysis. Decide what you are mapping. It may be by risk type, process, product, customer journey, legal entity, or control activity. Poorly chosen units create confusion. For example, mapping at the department level is often too coarse; mapping at the activity level reveals where ownership and challenge actually sit.

  4. Construct the role map. For each activity, specify who owns execution, who sets standards, who monitors, who challenges, who escalates, and who provides assurance. A simple matrix often works well. The objective is to make the three lines visible across real decisions such as underwriting, trading-limit breaches, complaints handling, model changes, or vendor risk reviews.

  5. Analyze gaps, overlaps, and conflicts. Look for the common failure modes: first-line activities being done by second-line teams, second-line teams lacking authority to challenge, internal audit involved in management decisions, or no one owning issue closure. Distinguish healthy collaboration from blurred accountability. Two functions may both touch a topic, but they should not both believe the other one owns it.

  6. Translate findings into design choices. Convert the analysis into concrete recommendations on mandates, reporting lines, committee structures, escalation paths, policy ownership, staffing, and management information. This is where the model becomes useful: not as a picture, but as a basis for decisions about how risk governance should actually operate.

  7. Test sensitivities and proportionality. Challenge your own design. Would it still work if the business doubled in size, entered a new product line, or came under closer regulatory scrutiny? Could the same outcome be achieved with less complexity? Smaller firms often need clear separation of responsibilities without creating large standalone functions.

  8. Align stakeholders and iterate. Socialize the draft with business leaders, control functions, internal audit, and board stakeholders. Expect disagreement. Resolve it by returning to the core questions of accountability, independence, and effectiveness. Then refine the model, assign owners, set milestones, and establish how success will be measured after implementation.

6. Example: Three Lines Model in Action

The problem

A regional bank had expanded rapidly into digital small-business lending. After a regulatory review, it received findings on credit exceptions, weak complaint escalation, and unclear ownership of model monitoring. The chief risk officer believed the bank had enough people working on risk, but not enough clarity on who was responsible for what.

Why the model was chosen

The bank did not need another list of controls. It needed a role-and-governance redesign. The Three Lines Model was selected because the central issue was blurred accountability among the lending business, risk and compliance teams, and internal audit.

How it was applied

The team mapped the end-to-end lending journey, from marketing and onboarding through underwriting, servicing, complaints, and collections. For each step, it identified first-line owners, second-line policy and monitoring roles, and third-line assurance responsibilities. It also reviewed committee charters, model governance, and issue-management processes.

The key insights

The analysis showed that the compliance team had quietly taken on several operating tasks that should have remained in the business, while the business assumed the second line was accountable for certain control failures. Internal audit had also been pulled into design discussions in ways that threatened its independence. In short, all three lines were active, but the handoffs were weak and escalation was inconsistent.

The actions that followed

The bank reassigned complaint ownership and exception management to the business, clarified second-line monitoring authority, strengthened model-risk challenge, and reset internal audit’s role to independent assurance. It also redesigned reporting to the risk committee. The result was not more bureaucracy; it was cleaner accountability and a control environment that regulators and executives could both understand.

7. Strengths and Limitations

Strengths

  • Clarifies accountability. It makes explicit who owns risk, who challenges, and who assures.
  • Creates a common language. Boards, executives, regulators, and auditors can discuss governance using a shared structure.
  • Exposes gaps and overlaps. It quickly reveals where activities are duplicated or falling through the cracks.
  • Supports regulatory credibility. In financial services, it aligns well with supervisory expectations for segregation of duties and independent oversight.
  • Works across many risk types. The same logic can be applied to conduct, credit, operational, model, cyber, and compliance risk.

Limitations

  • It is a simplification. Real organizations are messier than three clean categories.
  • It can become overly structural. Teams sometimes focus on boxes and reporting lines rather than decision rights and behaviors.
  • It does not design controls by itself. It clarifies roles, but does not specify what controls or risk methods are needed.
  • It can encourage bureaucracy. Poor implementation may create handoffs, committees, and paperwork without improving outcomes.
  • It depends on culture. If the first line resists ownership or the second line lacks authority, the model will look sound on paper but fail in practice.

8. Common Pitfalls and How to Avoid Them

  • Treating lines as departments. Teams often label whole functions as first, second, or third line without examining the work those functions actually do. This matters because mixed activities create hidden conflicts. Map responsibilities at the activity level, not just the org-chart level.
  • Letting the second line own first-line risk. Risk and compliance teams sometimes end up operating controls or closing issues for the business. That weakens business accountability. Keep ownership in the frontline and make second-line monitoring and challenge explicit.
  • Confusing independence with isolation. Some firms separate the lines so rigidly that useful collaboration disappears. Independence does not mean silence. Encourage structured interaction while preserving decision rights and assurance objectivity.
  • Ignoring the board’s role. The model is not only about management layers. If board committees, reporting, and escalation are unclear, the design will remain incomplete. Define how the governing body receives, challenges, and acts on information.
  • Stopping at high-level diagrams. Attractive slides often hide unresolved process issues. Move quickly from the conceptual model to concrete decisions on policies, forums, reporting, and issue management.
  • Assuming one-size-fits-all. A large global bank and a smaller specialist lender do not need identical structures. Apply proportionality so the model improves accountability without adding unnecessary complexity.

9. How Three Lines Model Relates to Other Frameworks

COSO Internal Control and COSO ERM

COSO frameworks help define what good internal control and enterprise risk management should include. The Three Lines Model answers a different question: who is responsible for those activities. A common sequence is to use COSO to shape the control or ERM architecture, then use the Three Lines Model to assign accountabilities across business, oversight, and assurance.

RACI matrices

A RACI matrix is more granular. It spells out who is responsible, accountable, consulted, and informed for a specific process or decision. The Three Lines Model is broader and governance-oriented. In practice, many teams use the Three Lines Model first to set the governance logic, then RACI tools to operationalize that logic at the process level.

Combined assurance

Combined assurance focuses on how boards receive coordinated assurance from management, risk functions, internal audit, and external parties. It complements the Three Lines Model closely. Once line responsibilities are clear, combined assurance helps reduce duplication and close assurance gaps.

Risk appetite frameworks

Risk appetite frameworks define how much risk the organization is willing to take and how breaches are escalated. The Three Lines Model does not set those limits, but it helps assign who monitors them, who challenges exceptions, and who assures the framework is working.

If the main problem is what controls or risk processes should exist, use a control or ERM framework first. If the main problem is who should do what, the Three Lines Model is usually the better starting point.

10. Key Takeaways

  • The Three Lines Model is a governance framework for clarifying ownership, oversight, and assurance.
  • It is especially useful in financial services when accountability for risk and control has become blurred.
  • The first line manages risk in the business, the second line oversees and challenges, and the third line provides independent assurance.
  • Its main value is role clarity, not detailed control design.
  • It works best when applied pragmatically, with clear activity-level mapping and strong leadership alignment.
  • Its biggest risk is becoming a bureaucratic org-chart exercise instead of a tool for better decisions and stronger accountability.

11. FAQs About Three Lines Model

Is Three Lines Model still relevant today?

Yes. It remains highly relevant, particularly in regulated industries. What has changed is how it is used: leading organizations treat it as a flexible governance principle, not a rigid “three boxes” structure.

What is the difference between Three Lines Model and Three Lines of Defense?

The Three Lines Model is the IIA’s 2020 update to the older Three Lines of Defense concept. It keeps the core distinction among management, oversight, and internal audit, but places more emphasis on governance, collaboration, and value creation rather than a purely defensive mindset.

Can small or early-stage regulated companies use Three Lines Model?

Yes, but proportionately. A smaller firm may not have large standalone functions, yet it still needs clear separation of responsibilities, credible challenge, and some form of independent assurance. The model should be scaled to the business, not copied mechanically from a large bank.

How long does it typically take to apply Three Lines Model in a real project?

A focused diagnostic can often be done in two to six weeks. A broader redesign, stakeholder alignment process, and implementation roadmap usually takes two to four months, and full rollout can take longer depending on regulatory urgency and organizational complexity.

What data is needed to use Three Lines Model?

The minimum useful inputs are org charts, reporting lines, committee structures, policies, and interviews with business, risk, compliance, and audit leaders. The analysis becomes much stronger when you add process maps, issue logs, audit findings, regulatory observations, and evidence of how decisions and escalations actually happen in practice.

How to get started

1

arrow-down-blue

Tell us about your project

2

arrow-down-blue

Interview candidates

(We’ll provide bios within 48 hours on average)

3

Select your consultant and start work

Find a Consultant

or email us at: [email protected]