What it means
Businesses need to take risks to achieve goals, and the model clarifies who makes decisions, who helps monitor them and who gives independent assurance. Start with the governing body: a board or equivalent oversees strategy, risk and accountability, and it is not an extra "fourth line" of daily operations.
Management owns action, so teams delivering a service, selling products or running systems are first-line roles that identify and manage risks in their work. A warehouse manager, for example, controls access and checks stock because the warehouse is the manager's operation, and risk ownership cannot simply be passed to compliance.
Second-line roles provide expertise and challenge, so risk, compliance, quality or security teams may set methods, monitor performance and advise management. Second-line functions are still part of management, and their precise reporting arrangements vary, but they do not automatically have the independence of internal audit.
Third-line internal audit assesses whether governance, risk management and controls work as intended, and it reports independently enough to give credible assurance. Protect that independence, because an auditor who owns the process being audited cannot objectively assess its own management decision.
Advice is possible, since internal audit can recommend improvements while avoiding taking responsibility for the operational decision it later reviews. External assurance providers may contribute, but they do not replace internal role clarity, as financial auditors or regulators have distinct remits.
Keep lines connected, because a security team can advise a product manager and internal audit can ask both for evidence, and separation does not mean silence. Avoid the old defensive metaphor alone, since the updated IIA model covers creating and protecting value, not only stopping bad events.
Adapt the structure, because a small business may not have separate departments for every role but should still understand conflicts and independent review needs, and map responsibilities by naming, for each key risk, the manager who owns action, any specialist who supports oversight and who can assess independently. Do not insist on a named person in every line for every tiny risk, because the model is a governance guide, not a universal staffing formula, and a simple risk-ownership check might show 18 of 20 key risks have a named first-line owner, or 90%, which says nothing by itself about whether the controls work.
Check decision rights, since a risk function may challenge a proposal but the authority to approve or reject it should be explicit in policy, and check escalation, because if management ignores a serious issue, second-line functions and internal audit need routes to the right leaders and board. Check information quality, since reports should be timely, evidence-based and clear about unresolved risks, avoid duplicate work through coordinated assurance that does not weaken independent judgment, and consider outsourcing, because an organisation may use an outside internal-audit provider but the board still needs appropriate authority and reporting arrangements, and review the map after change, since new products, acquisitions and systems can blur ownership.
The IIA updated the Three Lines Model in 2020 and refreshed its paper in September 2024 for new standards terminology, and its position paper describes board accountability, management's first and second line roles, and internal audit independence, so for an owner the model asks three practical questions: who owns the risk, who supports and challenges them, and who can give independent assurance that the system works.
In practice
Real-world examples.
Example
A store manager runs stock controls while a risk team sets a common method and monitors exceptions.
Example
Internal audit tests whether payment controls work without operating the payment process.
Example
A board receives management risk reports and independent audit findings on a major system change.
Formula
Calculation
The framework has no required numerical formula. An optional ownership measure is key risks with a named first-line owner / key risks reviewed x 100. Eighteen of twenty is 90%, but this is not a measure of control effectiveness.Case study
Seen in the real world.
Fictional case: Falcon Finance let its compliance team both operate a payment process and certify its controls. The board reassigned operation to business management, kept compliance as an adviser and monitor, and asked internal audit for independent review. The roles became clearer without assuming issues would disappear. This fictional case shows why ownership and assurance should not be confused.
Watch out
Common mistakes.
- Treating risk or compliance as the owner of every operating risk.
- Asking internal audit to run a process it is later meant to review independently.
- Using a role chart as proof that controls are effective.
Questions
People also ask.
Is the board one of the three lines?
No. The governing body oversees and remains accountable for governance in the IIA model.
Is the second line independent?
It is a management role with challenge and support responsibilities, not the same independence as internal audit.
Can a small business use it?
Yes, by clarifying responsibilities and conflicts even when it lacks separate departments.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%