Three lines of defense
Also known as: IIA Three Lines Model, 3LoD
This is a governance model used to distribute risk management responsibilities across an organization. The first line manages risks through daily operational controls, the second line sets policies and monitors compliance, and the third line provides independent assurance via internal audits. It ensures that no single group is solely responsible for both executing a task and verifying its correctness.
Why it matters
Without this separation, "marking your own homework" occurs, leading to undetected systemic failures or fraud. An auditor will conclude that the control environment is ineffective if oversight functions are absent or compromised. Such gaps often result in heavy regulatory fines from bodies like GDPR supervisory authorities or financial regulators. Ultimately, the Board of Directors and senior executives are held accountable for these governance collapses.
In practice
During a compliance assessment, an auditor interviews representatives from each line to verify their distinct roles. This typically occurs during the fieldwork phase of the engagement. Evidence requested includes policy documents created by the second line and evidence of control execution—such as system logs or signed approvals—from the first line. This process produces a Risk Control Matrix (RCM) that maps specific owners to their respective checks. In a first-year engagement, auditors focus on whether the structure exists; in repeat engagements, they test if the lines actually communicate and challenge one another effectively.
Worked example
FinTechCorp implemented an automated KYC (Know Your Customer) check to prevent money laundering. The Compliance Officer (second line) set the risk threshold in January 2023, while the Onboarding Team (first line) processed new clients. During a Q3 audit, the auditor requested samples of "high-risk" flags and evidence of how they were resolved. They found that the Onboarding Team was overriding alerts without secondary approval from Compliance. The result was a "Major Non-Conformance" finding requiring an immediate update to the access control matrix.
Common mistakes
- Merging the first and second lines by making the person who performs a task also the one who approves it, which removes independent oversight.
- Treating internal audit as part of management rather than an independent function reporting to the board.
- Confusing policy creation with enforcement; the second line defines the rule, but the first line must execute it daily.
- Failing to document the hand-off between lines, leaving auditors unable to prove that oversight actually occurred.
Frequently asked questions
What is the difference between the second and third lines of defense?
The second line monitors risk in real-time and supports management through policy and oversight. The third line performs periodic, independent reviews to ensure both previous lines are functioning correctly.
Does a small company need all three lines?
While roles may be combined due to limited headcount, the functions must remain separate. For example, an external consultant can act as the third line if no internal auditor is employed.
What evidence proves the second line is working?
Evidence includes risk registers, monthly compliance reports, and documented "challenge" meetings where policies were updated based on observed failures.
When should I implement this framework?
It should be implemented during the design of the organizational structure or when preparing for regulatory certifications like ISO 27001 or SOC 2.
How does this relate to Segregation of Duties (SoD)?
SoD is a specific technical control at the operational level, whereas this framework is a high-level governance strategy that incorporates SoD across the entire organization.
More terms
Risk assessment · Remediation · Risk appetite · Unqualified opinion · Qualified opinion · Working papers · SOC 2 Type II · Control environment