Skip to main content
Category: Board Structure and Roles

Lines of Accountability

Also known as: LoA, Accountability Lines, Lines of Accountability Model
Simply put

Lines of accountability describe how an organization assigns clear ownership of results, decisions, and actions to specific individuals or roles, so that it is evident who is answerable for what. They help ensure that each person understands their part in carrying out and overseeing activities, and that there are consequences, positive or negative, tied to whether expected actions are taken. The exact structure varies by organization, and the concept is generally presented as a management and governance practice rather than a legal requirement.

Formal definition

Lines of accountability refer to the defined pathways through which ownership of outcomes, decisions, governance, and implementation is allocated across an organization's roles and hierarchy. Under models such as the Lines of Accountability (LoA) framework, each individual's roles and responsibilities are specified so that accountability, the assumption of ownership for results, can be distinguished from responsibility for performing particular tasks. In applied contexts such as risk management policy, accountability is typically assigned to designated owners (for example, tiered risk owners charged with establishing, updating, and reviewing risks on a periodic basis), with consequences attaching to action or inaction. The specifics depend on organizational structure, policy, and jurisdiction; this entry describes the concept generally and is not legal, audit, or compliance advice. Formal governance concepts such as the three lines model of assurance are related but distinct and are out of scope here.

Why it matters

Clear lines of accountability address a persistent governance problem: when ownership of a result is diffuse or undefined, decisions can go unmade, tasks can fall between roles, and no one can be readily identified as answerable when something goes wrong. By tying accountability to specific individuals or roles, an organization makes it evident who is expected to deliver a given outcome and who must answer for it. Accountability in this sense generally means that a consequence, positive or negative, attaches to whether a person takes or does not take an expected action, which is part of how organizations reinforce desired behavior and correct failures.

The concept also matters because accountability is distinct from responsibility. A person may be responsible for performing particular tasks while accountability, the ownership of the result, rests with a designated role. Blurring these can leave a gap where many people touch an activity but no one owns the outcome. Well-defined lines of accountability help close that gap so that ownership of actions, decisions, governance, and implementation is explicitly assigned rather than assumed.

Because the specifics depend on organizational structure, policy, and jurisdiction, lines of accountability are generally treated as a management and governance practice rather than a legal requirement. This entry is educational and not legal, audit, or compliance advice, and organizations should design their accountability structures to fit their own circumstances.

Who it's relevant to

Boards and their committees
Directors rely on clearly defined lines of accountability to understand who within management owns particular outcomes and who is answerable for them. Note that the board's role is generally one of oversight rather than executing operational tasks, and accountability structures should reflect that distinction.
Senior management and executives
Executives typically design and maintain lines of accountability across the organization, allocating ownership of results to specific roles. They also serve as accountable parties themselves for outcomes within their remit, distinct from the individuals responsible for performing underlying tasks.
Risk and compliance functions
In applied settings such as risk management policy, accountability may be assigned to designated owners, for example, tiered risk owners charged with establishing, updating, and periodically reviewing their respective risks. These functions help define and document who owns what, though the specific structure depends on the organization's own policy.
Human resources and people leaders
Because accountability involves consequences, positive or negative, tied to whether expected actions are taken, HR and supervisors are often involved in translating accountability into performance expectations, recognition, and corrective measures.
Managers and individual contributors
Every role benefits from understanding whether it holds accountability for an outcome or responsibility for performing a task. Clear lines help individuals understand their part in carrying out and overseeing activities and how their actions or inaction may carry consequences.

Inside LoA

Board oversight accountability
The board holds ultimate accountability for the governance of the organization, including setting strategic direction, overseeing risk, and holding management to account. This is an oversight role rather than an operational one; the board generally does not execute controls or run day-to-day activities.
Management operational accountability
Management is typically accountable for designing, implementing, and operating the systems of internal control and for managing risk within the framework and risk appetite approved by the board. Under the three lines model, this corresponds to first and second line responsibilities.
First line accountability
Operational management that owns and manages risks directly, typically accountable for the design and operating effectiveness of controls embedded in business processes.
Second line accountability
Risk management and compliance functions that generally provide oversight, frameworks, monitoring, and challenge to the first line, but do not own the underlying business risks.
Third line accountability
Internal audit, which typically provides independent and objective assurance to the board and its committees on the effectiveness of governance, risk management, and controls. Its independence distinguishes it from the second line's oversight role.
Committee delegation
Boards commonly delegate specific accountabilities to committees (for example, audit, risk, or remuneration committees) while retaining overall accountability. Delegation clarifies who scrutinizes particular matters without transferring ultimate board responsibility.
Reporting and escalation lines
Defined pathways through which information, assurance, and issues flow between the first, second, and third lines, management, and the board, so that accountability is supported by transparent and timely reporting.

Common questions

Answers to the questions practitioners most commonly ask about LoA.

Do the lines of accountability mean that compliance and risk functions own the risks they oversee?
Generally, no. Under the commonly cited three lines model, ownership of risk and controls typically sits with the first line (management and operational functions that take on and manage risk day to day). Second line functions, such as risk management and compliance, generally support, challenge, and monitor rather than own the underlying risks. Treating oversight or advisory functions as risk owners tends to blur accountability. That said, the precise allocation depends on how an organization defines roles, and the model is a framework of good practice rather than a universal legal requirement.
Are lines of accountability the same as the three lines of defense?
Not exactly. The three lines model (originally described as the three lines of defense and later updated by some bodies to simply the three lines) is one widely used framework for organizing roles across the first line, second line, and internal audit. Lines of accountability is a broader concept describing to whom individuals and functions answer for their duties, which includes the board, its committees, management, and assurance providers. The three lines model can help structure those accountabilities, but it is a voluntary framework, not the only way to express accountability, and its labels should not be treated as prescriptive law.
How should an organization map its lines of accountability in practice?
A common approach is to document, for each significant activity or risk area, who performs the work, who oversees it, and who provides independent assurance. Many organizations use a responsibility matrix that distinguishes first line ownership, second line oversight and challenge, and internal audit assurance, and that clarifies where board or committee oversight sits. The aim is generally to avoid gaps and overlaps. The specific structure depends on the entity's size, sector, complexity, and applicable requirements, and it typically benefits from periodic review as the organization changes.
Where does the board fit within lines of accountability, and how does that differ from management?
The board generally holds an oversight role: it sets or approves the tone, oversees the effectiveness of governance, risk, and control arrangements, and holds management to account. Management, by contrast, typically holds operational responsibility for designing and running processes and controls. Attributing operational execution to the board, or oversight-only status to management, tends to misstate accountability. In many governance codes and frameworks the board may delegate specific oversight to committees such as audit or risk, but the board usually retains ultimate accountability for the effectiveness of the system as a whole.
What are common signs that lines of accountability are unclear or overlapping?
Typical warning signs include the same control being monitored by multiple functions with none treating it as their responsibility, second line functions performing first line tasks and then assuring their own work, gaps where no function clearly owns an emerging risk, and inconsistent reporting to the board about who is accountable for what. Independence concerns can also arise where assurance providers lose sufficient separation from the activities they assess. Identifying these issues usually calls for professional judgment and depends on the organization's particular facts and structure.
How can an organization preserve the independence of assurance functions within its accountability structure?
Independence is often supported by clear reporting lines, for example internal audit reporting functionally to the audit committee or board rather than solely to management, and by separating those who perform and own activities from those who provide independent assurance over them. Organizations generally seek to avoid situations where a function assures work it also performed. The appropriate arrangements vary by entity type, sector, and any applicable standards or listing requirements, and they should be assessed against the organization's own circumstances rather than a single fixed template.

Common misconceptions

The board is accountable for operating the organization's controls and managing risk day to day.
The board's accountability is generally one of oversight and direction. Designing and operating controls and managing risk within the approved appetite typically sits with management. Attributing operational execution to the board misstates where accountability sits under most governance frameworks.
The three lines represent a strict hierarchy where the third line supervises the second and the second supervises the first.
The three lines describe distinct roles and accountabilities rather than a chain of command. The first line owns risks, the second provides oversight and challenge, and the third provides independent assurance. Internal audit's independence means it is not simply a higher tier of management control.
Delegating a matter to a board committee transfers accountability away from the board.
Delegation to a committee generally allocates focused scrutiny of a topic while the board retains overall accountability. Committees support the board's work rather than relieving it of ultimate responsibility.

Best practices

Document who is accountable at each of the three lines and at board level, making explicit the distinction between oversight responsibilities and operational responsibilities to avoid gaps or overlaps.
Preserve the independence of the third line so that internal audit reports its assurance findings to the board or audit committee rather than being absorbed into second line oversight activities.
Define clear reporting and escalation lines between management, the assurance functions, and the board so that accountability is supported by transparent, timely information.
Clarify in committee terms of reference which matters are delegated for scrutiny while affirming that the board retains overall accountability.
Periodically review that accountabilities remain aligned with the organization's structure, jurisdiction, and applicable frameworks, recognizing that arrangements vary by entity type and sector.
Confirm that management, not the board, owns the design and operating effectiveness of controls, and that the second line's role remains oversight and challenge rather than ownership of business risks.