Skip to main content
Why Your Three Lines Model Isn't WorkingEnterprise Risk Management
5 min readFor Risk Managers

Why Your Three Lines Model Isn't Working

You've implemented the Three Lines Model. You've mapped roles across management, risk and compliance, and internal audit. Yet when emerging risks surface, the model feels like a bureaucratic chart rather than a functioning defense system. The problem isn't the model itself but the myths that undermine its implementation.

The Institute of Internal Auditors has published two position papers addressing how the Three Lines Model and enterprise risk management (ERM) must evolve to meet accelerating organizational risks. These documents emphasize collaboration across governance functions, including compliance, but many organizations still operate under outdated assumptions that prevent effective integration.

Myth 1: The Three Lines Are Independent Silos

The Reality: The model describes coordination, not separation. First-line operational management owns risks and controls. Second-line functions like compliance and risk management provide oversight, frameworks, and challenge. Third-line internal audit provides independent assurance. But these aren't isolated towers.

The IIA's position papers stress collaboration between governance functions because risks don't respect organizational boundaries. When your compliance team identifies a regulatory gap, that information must flow immediately to operational owners who can remediate it and to internal audit for validation. When your risk function spots an emerging threat pattern, compliance needs that intelligence to update control frameworks.

Consider how cyber risk actually manifests: IT operations (first line) manage technical controls, information security and compliance (second line) set standards and monitor adherence, and internal audit (third line) validates the entire control environment. A breach happens when these lines fail to communicate, not when they communicate too much.

Myth 2: ERM Is a Risk Management Department Function

The Reality: Enterprise risk management is an organizational capability, not a departmental activity. Your risk management function facilitates ERM, but every business unit must own its risk profile.

The COSO ERM Framework explicitly describes ERM as integrated across strategy-setting, performance management, and review processes. When you centralize risk ownership in a single department, you create a reporting exercise rather than a management discipline.

Effective ERM integration means your procurement team assesses supply chain risks using frameworks your risk function provides, your HR team evaluates talent risks against strategic objectives, and your finance team models capital risks within board-approved appetite statements. The risk function coordinates, challenges, and reports up, but it doesn't own every risk register in your organization.

Myth 3: Compliance Sits in the Second Line, So It Doesn't Need First-Line Involvement

The Reality: Compliance functions provide oversight and frameworks, but compliance outcomes depend entirely on first-line execution. You can write brilliant policies, but if operational managers don't embed them into workflows, you've built a paper program.

The IIA's emphasis on collaboration between compliance and other governance functions reflects this dependency. Your compliance team should be designing controls with first-line input, testing them in operational contexts, and adjusting frameworks based on implementation feedback. When compliance operates as a separate function that issues requirements without understanding operational constraints, you get checkbox compliance rather than effective risk mitigation.

Practical integration looks like this: Your compliance officer sits in product development meetings to identify regulatory implications before launch, not after. Your operational managers have direct access to compliance expertise when they encounter gray areas, not just during annual training. Your compliance metrics measure control effectiveness in business processes, not just policy acknowledgment rates.

Myth 4: Internal Audit Validates What the Other Lines Do, So Coordination Isn't Critical

The Reality: Internal audit's independence requires information access, not isolation. Your audit function needs a deep understanding of first-line operations and second-line frameworks to design meaningful assurance activities.

When internal audit operates in isolation, you get audits that test documented controls rather than actual risk management effectiveness. Your auditors need to understand what risks your business units are actually managing, what frameworks your compliance and risk functions have deployed, and where gaps exist between design and execution.

This doesn't compromise independence. Your audit committee still approves the audit plan, your CAE still reports functionally to the board, and your auditors still maintain objective judgment. But your audit function should be coordinating scope with second-line functions to avoid duplication, using first-line risk assessments to prioritize activities, and sharing findings that help other lines improve their effectiveness.

Myth 5: If You Have ERM, You Don't Need the Three Lines Model (or Vice Versa)

The Reality: ERM and the Three Lines Model address different aspects of governance. ERM provides the methodology for identifying, assessing, and managing risks across your organization. The Three Lines Model defines roles, responsibilities, and accountability for that risk management.

The IIA's paired position papers on these topics reflect their complementary nature. Your ERM framework tells you what risks to manage and how to assess them against your risk appetite. Your Three Lines structure tells you who owns those risks, who provides oversight, and who validates the entire system.

Consider strategic risk management: Your ERM framework requires strategy-level risk assessment during planning cycles. Your first line (business unit leaders) conducts those assessments. Your second line (strategic planning, risk, compliance) provides assessment frameworks and challenges assumptions. Your third line (internal audit) validates that the process actually happens and produces reliable outputs. Without ERM, you don't know what to assess. Without the Three Lines, you don't know who's accountable.

What to Do Instead

Start by mapping actual risk management activities, not theoretical responsibilities. Document who currently identifies risks, who assesses them, who designs controls, who monitors effectiveness, and who provides assurance. You'll likely find overlaps, gaps, and confusion.

Then clarify accountability using the Three Lines Model as your structure and ERM as your process. First-line managers should own risk registers for their areas, updated quarterly with assessment criteria your risk function provides. Second-line functions should maintain enterprise-wide risk frameworks, conduct independent monitoring, and challenge first-line assessments. Third-line audit should validate that the system works as designed and produces reliable risk information for your board.

Build formal coordination mechanisms. Your risk committee (or equivalent) should include representatives from all three lines, meeting quarterly to review enterprise risks, discuss emerging threats, and coordinate responses. Your internal audit plan should explicitly consider second-line activities to ensure complementary coverage. Your compliance function should have structured touchpoints with operational leaders to understand implementation challenges.

Finally, test integration under pressure. When a significant risk event occurs, your response will reveal whether you have genuine collaboration or just coordinated reporting. Organizations with effective Three Lines and ERM integration respond faster, with clearer accountability and better information flow, because the coordination already exists.

The IIA's position papers signal that governance expectations are rising. Your model needs to function as a system, not as a chart.

You Might Also Like