Third Line
The third line refers to the internal audit function, which provides independent and objective assurance to the board and senior management about how well an organization manages its risks and controls. Unlike the functions that own risks day-to-day (the first line) or those that oversee and challenge risk management (the second line), the third line operates independently from both. Its role is to evaluate and report on the effectiveness of governance, risk management, and control processes.
Within the Three Lines of Defense model, the third line is typically the internal audit function, which delivers independent, objective assurance and advice on the adequacy and effectiveness of governance, risk management, and internal control. It is distinguished from the first line (operational management that owns and manages risk) and the second line (risk management, compliance, and other oversight functions that monitor and challenge the first line). To preserve objectivity, internal audit generally maintains organizational independence from management, often reporting functionally to the board or its audit committee. The scope, structure, and reporting arrangements of the third line vary by jurisdiction, sector, and entity type, and the Three Lines of Defense is a widely used framework rather than a universal legal mandate; specific requirements depend on applicable law, listing rules, and an organization's own governance arrangements. This entry is educational and not legal, audit, or compliance advice.
Why it matters
The third line matters because boards and senior management need assurance that comes from a source independent of the people who run day-to-day operations and the functions that oversee them. Operational management (the first line) owns and manages risk directly, and oversight functions such as risk management and compliance (the second line) monitor and challenge that work. Neither, however, is fully independent of the activities being assessed. The third line, typically internal audit, is positioned to operate independently from both, which allows it to evaluate whether governance, risk management, and control processes are actually working as intended rather than simply as designed.
Without a credible third line, a board can be left relying on self-reported assurance from the very functions responsible for managing or overseeing risk, which can obscure weaknesses in control design or operating effectiveness. Independent assurance helps the board and audit committee test the reliability of the information they receive and identify gaps before they escalate. Because the third line generally reports functionally to the board or its audit committee, its findings can reach those charged with oversight without being filtered through the management chain it is assessing.
It is important to keep the limits of this in view. The Three Lines of Defense is a widely used framework, not a universal legal mandate, and the scope, structure, and reporting arrangements of the third line vary by jurisdiction, sector, and entity type. Whether an internal audit function is required at all, and how it must be structured, depends on applicable law, listing rules, and an organization's own governance arrangements.
Who it's relevant to
Inside Third Line
Common questions
Answers to the questions practitioners most commonly ask about Third Line.