Skip to main content
Category: Internal Audit and Assurance

Third Line

Also known as: Third Line of Defense, Internal Audit Function
Simply put

The third line refers to the internal audit function, which provides independent and objective assurance to the board and senior management about how well an organization manages its risks and controls. Unlike the functions that own risks day-to-day (the first line) or those that oversee and challenge risk management (the second line), the third line operates independently from both. Its role is to evaluate and report on the effectiveness of governance, risk management, and control processes.

Formal definition

Within the Three Lines of Defense model, the third line is typically the internal audit function, which delivers independent, objective assurance and advice on the adequacy and effectiveness of governance, risk management, and internal control. It is distinguished from the first line (operational management that owns and manages risk) and the second line (risk management, compliance, and other oversight functions that monitor and challenge the first line). To preserve objectivity, internal audit generally maintains organizational independence from management, often reporting functionally to the board or its audit committee. The scope, structure, and reporting arrangements of the third line vary by jurisdiction, sector, and entity type, and the Three Lines of Defense is a widely used framework rather than a universal legal mandate; specific requirements depend on applicable law, listing rules, and an organization's own governance arrangements. This entry is educational and not legal, audit, or compliance advice.

Why it matters

The third line matters because boards and senior management need assurance that comes from a source independent of the people who run day-to-day operations and the functions that oversee them. Operational management (the first line) owns and manages risk directly, and oversight functions such as risk management and compliance (the second line) monitor and challenge that work. Neither, however, is fully independent of the activities being assessed. The third line, typically internal audit, is positioned to operate independently from both, which allows it to evaluate whether governance, risk management, and control processes are actually working as intended rather than simply as designed.

Without a credible third line, a board can be left relying on self-reported assurance from the very functions responsible for managing or overseeing risk, which can obscure weaknesses in control design or operating effectiveness. Independent assurance helps the board and audit committee test the reliability of the information they receive and identify gaps before they escalate. Because the third line generally reports functionally to the board or its audit committee, its findings can reach those charged with oversight without being filtered through the management chain it is assessing.

It is important to keep the limits of this in view. The Three Lines of Defense is a widely used framework, not a universal legal mandate, and the scope, structure, and reporting arrangements of the third line vary by jurisdiction, sector, and entity type. Whether an internal audit function is required at all, and how it must be structured, depends on applicable law, listing rules, and an organization's own governance arrangements.

Who it's relevant to

Boards and audit committees
The board and its audit committee are the primary recipients of third-line assurance. Because internal audit often reports functionally to them, they rely on its independent evaluation of governance, risk management, and control processes to test the reliability of information provided by management and oversight functions. Committees generally have a role in maintaining the independence of the internal audit function within their governance arrangements.
Internal auditors
Internal auditors typically constitute the third line itself. Their role is to provide independent, objective assurance and advice on the effectiveness of governance, risk management, and internal control, while maintaining organizational independence from the first and second lines they assess.
Senior management
Senior management receives third-line assurance alongside the board and uses it to understand where governance, risk, and control processes may need strengthening. Management should recognize the distinction between its own accountability for owning and overseeing risk and the independent assurance role the third line provides.
Risk and compliance functions (second line)
Second-line functions such as risk management and compliance are among the activities the third line evaluates. Understanding where their oversight role ends and independent assurance begins helps preserve the separation of duties that gives the Three Lines model its value.

Inside Third Line

Internal Audit Function
The third line is typically embodied by internal audit, an assurance function that provides independent, objective evaluation of the adequacy and effectiveness of governance, risk management, and internal controls.
Independence and Objectivity
A defining characteristic of the third line is its independence from the activities it reviews; it generally reports functionally to the board or audit committee rather than to operational management, which supports objective assurance.
Assurance Over the First and Second Lines
The third line evaluates whether first-line operational controls and second-line oversight functions (such as risk management and compliance) are designed appropriately and operating effectively, rather than owning or managing those controls itself.
Reporting to the Board or Audit Committee
Under many governance frameworks, the third line communicates findings and assurance conclusions directly to the board or its audit committee, reinforcing accountability and oversight separate from management.
Position Within the Three Lines Model
The third line is one component of the widely referenced three lines model, which distinguishes those who own and manage risk (first line), those who provide oversight and expertise (second line), and those who provide independent assurance (third line).

Common questions

Answers to the questions practitioners most commonly ask about Third Line.

Does the third line audit the first and second lines, meaning compliance and risk management are simply part of internal audit?
No. Under the model articulated in the IIA's Three Lines guidance, the second line (functions such as risk management and compliance) and the third line (internal audit) are typically distinct. The second line generally supports and monitors risk and compliance activities as a management function, while the third line provides independent, objective assurance over the effectiveness of governance, risk management, and control, including over how the second line performs. Treating them as interchangeable conflates a management support role with an independent assurance role. The precise structure varies by entity type, sector, and jurisdiction.
Is the third line responsible for owning or managing the organization's risks?
No. Risk ownership generally sits with management in the first line, with the second line providing oversight, frameworks, and monitoring. The third line typically provides independent assurance over whether those arrangements are designed and operating effectively; it does not own risks, set risk appetite, or make management decisions. Where internal audit takes on management responsibilities, its independence and objectivity may be impaired, which is why many frameworks emphasize safeguards to preserve that separation.
To whom should the third line report to preserve its independence?
In many governance arrangements, the head of internal audit reports functionally to the board or its audit committee and administratively to senior management. This dual reporting line is generally intended to protect independence and give the function direct access to those charged with governance. The specific reporting structure depends on the entity's governance model, applicable listing rules, and jurisdictional requirements, and should be documented in an internal audit charter approved by the board or audit committee. This is a general description, not a prescription for any particular organization.
How does the third line coordinate with the second line without compromising its objectivity?
Coordination typically involves sharing risk information, aligning assurance coverage to avoid gaps and duplication, and using approaches such as combined or integrated assurance mapping. To preserve objectivity, the third line generally maintains clear boundaries: it may consider and rely on second-line work where appropriate, but it independently evaluates the effectiveness of second-line activities rather than simply adopting their conclusions. The balance between coordination and independence is a matter of professional judgment and should be reflected in the audit charter and methodology.
How does the third line plan its work and prioritize what to audit?
Internal audit functions commonly use a risk-based approach, developing an audit plan informed by the organization's risk profile, the assurance provided by other lines, and input from the board or audit committee and senior management. Prioritization generally weighs factors such as the significance of the risk, the adequacy of existing controls, and areas of change. The plan is typically reviewed and approved by the audit committee and revisited periodically as risks evolve. Methodologies vary across organizations and professional standards.
How can the third line assess whether controls are effective, not just well designed?
Assurance work generally distinguishes control design from operating effectiveness. Evaluating design considers whether a control, if operating as intended, would address the relevant risk; evaluating operating effectiveness considers whether the control has actually functioned consistently over a period. The third line typically tests operating effectiveness through methods such as inspection, reperformance, observation, and sampling, and reports conclusions on both dimensions. The appropriate scope, testing approach, and level of evidence depend on the engagement objectives and professional judgment. This entry is educational and not audit, legal, or compliance advice.

Common misconceptions

The third line owns and manages risk and controls alongside the business.
Owning and managing risk is generally a first-line responsibility. The third line provides independent assurance over how risk and controls are managed; it does not manage them itself, as doing so would compromise its independence.
Internal audit and compliance are the same function because both check that rules are followed.
Compliance monitoring is typically a second-line oversight activity that supports and advises management, whereas internal audit is a third-line assurance function that independently evaluates the effectiveness of both first- and second-line activities, including compliance itself.
A three lines structure and an independent third line are legally mandatory for every entity.
The three lines model is generally a voluntary framework and best-practice reference rather than a universal legal requirement. Whether an internal audit function is required, and how it is structured, varies by jurisdiction, sector, listing status, and entity type.

Best practices

Establish functional reporting from the internal audit function to the board or audit committee to protect its independence from the management activities it assesses.
Clearly delineate responsibilities so that the third line provides assurance rather than owning first-line controls or performing second-line oversight tasks, avoiding conflicts that undermine objectivity.
Scope third-line assurance to evaluate both the design and the operating effectiveness of governance, risk management, and control processes, treating these as distinct assessments.
Coordinate with, but remain independent of, second-line risk and compliance functions to reduce duplication while preserving the third line's ability to objectively assess those functions.
Tailor the internal audit mandate to the entity's jurisdiction, sector, and regulatory obligations rather than assuming a single model applies universally.
Communicate assurance conclusions and identified weaknesses directly to the board or audit committee so that accountability for oversight remains distinct from management.