Skip to content
The Three Lines of Defense: Why Internal Audit Is Essential to Effective ERM
Internal Audit Management

The Three Lines of Defense: Why Internal Audit Is Essential to Effective ERM

William C Hord
William C HordChief Strategy Officer - ERM Pilot

The Three Lines of Defense: Why Internal Audit Is Essential to Effective ERM

Risk management is rarely successful because of one department, one policy, or one control. In a financial institution, effective risk governance depends on a series of responsibilities working together: the people closest to the risk must manage it, independent functions must provide oversight and challenge, and Internal Audit must provide objective assurance that the overall system is working as intended.

This is the foundation of the Three Lines Model, often referred to as the Three Lines of Defense.

The concept is straightforward, but putting it into practice is not always easy. Roles can overlap. Responsibilities can become blurred. Risk functions can become involved in operational decisions, while Internal Audit can sometimes become overly focused on checking compliance with policies rather than assessing whether the organization is actually managing risk effectively.

For management and the board, that distinction matters.

The real value of the Three Lines is not simply having three separate functions. It is creating three distinct perspectives on risk that, together, give leadership greater confidence in the organization's risk profile, controls, governance, and decision-making.

And that is where Internal Audit becomes particularly important.

The First Line: Risk Ownership Belongs to the Business

The first line consists of the people and functions that conduct the organization's activities and therefore own the risks those activities create.

Lending, finance, operations, information technology, vendor management, human resources, and other business functions all make decisions that carry risk. Those functions are responsible for identifying, assessing, managing, and monitoring the risks within their areas of responsibility.

That does not mean every employee has to be a risk professional. It means accountability for risk cannot simply be transferred to the Risk Management department.

The first line should be able to answer practical questions:

  • What could go wrong?
  • What controls are supposed to prevent or detect it?
  • Are those controls actually operating?
  • Has anything changed that alters the risk?
  • Is the remaining risk within the organization's tolerance?
  • What needs to be corrected?

The National Credit Union Administration describes business units as the first line and emphasizes their responsibility for managing the risks associated with their activities. The Basel Committee similarly describes the business line as having ownership and accountability for risk.

That principle is important because risk ownership should stay with the people making the operational decisions.

The Second Line: Oversight, Monitoring, and Challenge

The second line provides a different perspective.

Risk Management, Compliance, Information Security, Vendor Risk, BSA/AML, Privacy, and other specialized oversight functions can serve as second-line functions depending on the organization's structure.

Their responsibility is not to take over the first line's risks. Instead, they provide expertise, establish frameworks and expectations, monitor exposures, assess whether risk is being managed appropriately, and challenge the first line when necessary.

NCUA identifies risk oversight as the second line and describes its role in overseeing and assessing business-unit risk assessments. The Basel Committee similarly describes risk management and compliance as second-line functions that operate independently from the business line.

This distinction is worth paying attention to.

A second-line function that merely collects reports is not necessarily providing effective oversight. At the other extreme, a second-line function that begins making operational decisions or assuming ownership of business controls can blur the very accountability it was created to oversee.

A mature second line should be willing to say:

"We see the risk, we understand how you are managing it, and here is where we believe additional action or escalation is necessary."

That is a challenge—not ownership.

The Third Line: Independent Assurance

This is where Internal Audit becomes different from the other lines.

Internal Audit is not another operational control. It is not another layer of management. Its value comes from being positioned independently from the activities it evaluates.

The IIA's current Global Internal Audit Standards state that Internal Audit provides independent, risk-based, and objective assurance, advice, insight, and foresight. The Standards also emphasize that the Internal Audit function should be independently positioned, with direct accountability to the board.

The IIA's Three Lines Model similarly describes Internal Audit as providing independent and objective assurance and advice on the adequacy and effectiveness of governance and risk management, consistent with the broader Standards requirement that Internal Audit evaluate governance, risk management, and control processes.

That independence changes the question Internal Audit is asking.

The first line asks:

"Are we managing this risk?"

The second line asks:

"Are we managing it within the organization's framework and risk expectations?"

Internal Audit asks:

"Can the board and management reasonably rely on the governance, risk management, and control processes that are supposed to make this work?"

That is a fundamentally different responsibility.

Internal Audit Should Look Beyond Whether a Policy Exists

One of the easiest ways for Internal Audit to lose strategic value is to reduce an audit to a checklist.

For example, suppose an organization has a policy requiring annual assessments of critical third-party vendors.

A basic audit might determine whether those assessments were completed.

That is useful—but it may not answer the more important questions.

Were all critical vendors identified correctly? Are the criteria used to determine criticality appropriate? Did the organization recognize changes in vendor relationships or risk exposure? Were material findings escalated? Were corrective actions actually completed? Did the second line appropriately challenge the business? Was residual risk formally accepted where necessary? And did reporting to management and the board accurately reflect the organization's third-party risk?

Those questions move Internal Audit from "Did you follow the policy?" to "Does the process actually manage the risk?"

The OCC describes risk-based auditing as a methodology that links Internal Audit to the institution's overall risk management framework and directs audit attention toward areas of greatest risk. It also describes Internal Audit as the third line providing independent assurance and challenge over the policies, processes, personnel, and controls established by the first and second lines.

That is a much more meaningful form of assurance.

Independence Is More Than an Organizational Chart

Internal Audit cannot provide independent assurance if it becomes responsible for the activities it is expected to audit.

This can happen gradually.

Internal Audit may be asked to design a control. Then it may help implement that control. Later, it may be asked to evaluate whether the control is working.

At that point, the line between advising and owning becomes difficult to maintain.

The IIA's standards specifically emphasize independence from management responsibilities, while the Basel Committee states that the internal audit function should not be involved in designing, selecting, implementing, or operating specific internal control measures — the responsibility of the first and second lines.

NCUA likewise emphasizes that Internal Audit should maintain independence from business units and risk oversight, with the chief audit executive having unrestricted access to the supervisory or audit committee and, ideally, reporting directly to that committee.

Independence does not mean isolation.

The three lines should communicate, coordinate, and collaborate. The IIA explicitly recognizes the importance of coordination among the governing body, management, and Internal Audit. The distinction is that collaboration should not remove the independence necessary for objective assurance.

The Three Lines Are Separate Roles, Not Three Silos

One of the biggest misconceptions about the model is that each line operates independently of the others.

In practice, the opposite is closer to the model's intent.

The lines should interact continuously, but their accountabilities must remain clear.

A healthy relationship sounds something like this:

First line: "We own the risk and operate the controls."

Second line: "We establish the framework, monitor the risk, and challenge the first line."

Third line: "We independently assess whether the organization's governance, risk management, and controls are designed and operating effectively."

The IIA's current Three Lines Model emphasizes that these roles are distinct while requiring alignment, communication, coordination, and collaboration.

When those distinctions disappear, the organization can develop assurance gaps without realizing it.

The first line may assume Risk Management owns the problem. Risk Management may assume Internal Audit will identify the issue. Internal Audit may discover that nobody has actually owned the underlying risk.

The result is a risk that has been discussed repeatedly but not truly managed.

What Should the Board Be Looking For?

From a board or executive perspective, the question should not simply be whether the organization has a first, second, and third line.

The more useful questions are:

Is risk ownership actually where the risk is created?

Does the second line provide meaningful oversight and challenge?

Is Internal Audit independent enough to challenge both management and the second line?

Does the audit plan reflect the organization's current risk profile?

Does Internal Audit evaluate the effectiveness of the overall risk and control environment—not just individual policies?

Are audit findings identifying root causes, rather than simply documenting symptoms?

Does the board receive enough independent information to determine whether management's view of risk is reliable?

These questions move the conversation away from organizational structure and toward effectiveness.

That distinction is critical because having the right boxes on an organizational chart does not necessarily mean the Three Lines are functioning effectively.

Internal Audit as a Confidence Mechanism for ERM

This is ultimately where Internal Audit connects back to Enterprise Risk Management.

ERM is intended to give management and the board a meaningful view of the organization's risks, how those risks are changing, and whether they are being managed within established expectations.

But ERM depends on the quality of the information feeding it.

If risk assessments are incomplete, controls are ineffective, issues are not remediated, reporting is inaccurate, or second-line challenge is weak, the resulting enterprise risk picture may look more reliable than it actually is.

Internal Audit provides an important independent checkpoint.

It can evaluate whether risk identification is working. Whether assessments are credible. Whether controls are properly designed and operating. Whether issues are being addressed at their root cause. Whether risk reporting reflects reality. Whether management has accepted risk knowingly. And whether the governance processes surrounding those activities are functioning as intended.

The IIA's Global Internal Audit Standards describe internal auditing as strengthening an organization's ability to achieve its objectives by improving governance, risk management, and control processes, and by supporting sound decision-making and oversight through independent assurance, advice, insight, and foresight.

That makes Internal Audit more than the final step in an audit cycle.

It makes Internal Audit an important part of the organization's confidence mechanism.

The Real Strength of the Three Lines

The Three Lines Model is not really about creating three departments.

It is about creating three distinct perspectives on risk and accountability.

The first line owns and manages risk.

The second line provides expertise, oversight, monitoring, and challenge.

The third line provides independent and objective assurance.

When those responsibilities are clear, the organization gains more than another layer of controls. It gains a way to test whether the risk management system itself is functioning as intended.

And for management and the board, that may be the most important question of all:

Is the risk picture we are relying on actually reliable?

Internal Audit cannot answer that question alone. It depends on the effectiveness of the first and second lines.

But without an independent third line, management and the board have fewer ways to independently test whether the answers they are receiving can be trusted.

That is why Internal Audit remains such an important component of effective ERM—and why the strength of the Three Lines depends not only on having three lines, but on making sure each one performs the role it was designed to perform.

Sources

The Institute of Internal Auditors — 2024 Global Internal Audit Standards

2024 Global Internal Audit Standards

The Institute of Internal Auditors — The IIA's Three Lines Model (2020 update)

The IIA's Three Lines Model — An Update of the Three Lines of Defense

The Institute of Internal Auditors — Domain III: Governing the Internal Audit Function and the Three Lines Model

Global Internal Audit Standards, Domain III — Three Lines guidance

National Credit Union Administration — Three Lines of Defense

NCUA Examiner's Guide — Lines of Defense

Office of the Comptroller of the Currency — Internal and External Audits, Comptroller's Handbook

OCC Comptroller's Handbook — Internal and External Audits

Bank for International Settlements — Corporate Governance Principles for Banks (Basel Consolidated Framework)

BIS Basel Framework — Corporate Governance (CGO)

Bank for International Settlements — Internal Audit and Compliance Functions (Basel Consolidated Framework)

BIS Basel Framework — Internal Audit and Compliance (IAC)

Ready to transform your risk management?

Discover how ERM Pilot can streamline your compliance, automate workflows, and provide real-time insights for your organization.

Stay Updated on ERM Pilot

Join our newsletter to receive the latest news, feature updates, and expert insights on all things risk related.

We respect your privacy. Unsubscribe at any time.