modern auditing

Glossary

Three Lines Model

Also known as: three lines of defence, 3LOD

The IIA's model distinguishing management's ownership of risk (first line), its oversight functions (second line), and internal audit's independent assurance (third line).

The IIA updated the model in 2020, dropping “of defence” and reframing it around roles and relationships rather than a wall of sequential barriers. The first line owns and manages risk while delivering products and services. The second line provides expertise, support, monitoring and challenge. The third — internal audit — provides independent, objective assurance and advice to the governing body.

The model’s practical purpose is to locate accountability, and its practical failure mode is drift. Internal audit builds a monitoring capability because it has the analytics skills; second line takes on remediation because it is faster than waiting; first line stops owning controls because someone else is watching them. Each step is locally sensible, and the aggregate is a function providing assurance over work it performed.

This matters more in a modernisation programme than it did before, because the tooling makes drift easy. The same platform can run management’s monitoring and audit’s testing; the same agent can be pointed at either. Independence now has to be maintained deliberately through scope and permissions rather than by the natural friction of separate systems — which means someone has to decide it, and write it down.


Related


Part of the Modern Auditing glossary. See also the maturity model and theartifact library.