Skip to main content
The Three Lines Model Just Changed Again, And Lost Its WayEnterprise Risk Management
4 min readFor GRC Leaders

The Three Lines Model Just Changed Again, And Lost Its Way

Recent Changes

The Institute of Internal Auditors (IIA) released an update to its Three Lines Model in 2024, marking the second revision since 2020. This change redefines second-line roles from oversight functions that "set policies, define standards, and monitor adherence" to providers of "specialized expertise, support, monitoring, and challenge to enhance risk management, compliance, and control practices."

This shift blurs the distinction between assurance providers and decision-support functions. By broadening the second-line definition, the IIA removed specific examples of second-line functions provided in 2013, such as risk management and compliance, replacing them with a vague description applicable to many roles within your organization.

Evolution of the Model

2013: The IIA introduced the Three Lines of Defense model, clearly positioning second-line functions as "various risk control and compliance oversight functions established by management," with specific examples like risk management and compliance.

2020: The model was renamed to the Three Lines Model, reframing the second line as teams that "oversee the first line," focusing on setting policies and monitoring adherence.

2024: The latest revision describes second-line roles as providing "specialized expertise, support, monitoring, and challenge," removing all example functions and stating that "management may also establish particular roles (second line) to review, support, monitor, and/or provide advice in specific risk areas."

Governance Implications

The failure here is conceptual. The Three Lines Model was meant to clarify the relationship between internal audit, the board, management, and other assurance providers. The 2024 revision undermines three critical governance controls:

Role clarity: The new definition no longer distinguishes between assurance providers and decision-support functions. For example, Information Security designs and operates controls (first line) while also providing specialized expertise and monitoring (second line). Under the 2024 definition, many roles could claim second-line status, leading to confusion.

Assurance mapping: Your organization needs clarity on who provides independent assurance on which risks. The 2013 model identified second-line functions as distinct assurance providers. The 2024 version says management "may" establish second-line roles but lacks criteria for qualification, complicating coordination with assurance providers.

Governance Disclosure: Boards and audit committees rely on structured reporting from assurance providers. When the second line includes any function that provides "support, monitoring, and challenge," systematic assurance coverage mapping becomes difficult. The model no longer clarifies who is responsible for independent assurance and their relationship to internal audit.

Standards and Frameworks

The IIA's International Standards for the Professional Practice of Internal Auditing (Standard 2050) requires the Chief Audit Executive to "share information, coordinate activities, and consider relying upon the work of other internal and external assurance and consulting service providers to ensure proper coverage and minimize duplication of efforts."

Effective coordination requires clear role definitions. The 2013 model supported this by identifying second-line functions as distinct assurance providers. The 2024 version undermines Standard 2050 by making it unclear which functions qualify as assurance providers.

The COSO ERM Framework describes risk management as integrated into decision-making, not as an oversight function. It positions risk management as providing "information to support decisions about strategy and objectives in the context of risk," which conflicts with a model grouping risk management with compliance and other monitoring functions under a single "second line" label.

Actionable Steps for Your Organization

Discontinue using the Three Lines Model as a governance framework. If your organization is structured around the model's line definitions, recognize that these definitions no longer provide meaningful boundaries. The model was never intended as a governance framework, and the 2024 revision should prompt you to abandon that practice.

Develop your own assurance map. Create a taxonomy of functions that provide independent assurance on risk, compliance, and control effectiveness. Use criteria relevant to your organization: reporting lines, scope of examination, frequency of review, and level of independence. Don't rely on the Three Lines Model for this task.

Reevaluate your risk function's role. If risk management is positioned as a second-line oversight function, reconsider this approach. Risk management serves decision-makers by providing analysis, quantification, and scenario planning, not assurance. It should report on the organization's risk profile and support strategic choices.

Clarify internal audit's coordination responsibilities. Your Chief Audit Executive should coordinate with other assurance providers by identifying them by function and scope, not by line designation. Document which functions provide assurance, what they examine, and how internal audit relies on or validates their work. Update your audit committee reporting to reflect these relationships without referencing the Three Lines Model.

Challenge vague role definitions. If a function claims second-line status under the new model, determine what that means in practice. Do they provide assurance through systematic examination? Do they report independently to the board or audit committee? Or do they provide expertise and support to decision-makers? The answer will guide your coordination efforts.

The 2024 Three Lines Model may better fit risk management's role by acknowledging its support function, but it dilutes the concept of the second line to the point of meaninglessness. It's more effective to build your own assurance map.

You Might Also Like