The IIA's Three Lines Model: An Update of the Three Lines of Defense (2020, updated September 2024)
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The IIA's Three Lines Model is a position paper from The Institute of Internal Auditors that updates the earlier Three Lines of Defense. Published in 2020 and updated in September 2024 to reflect the glossary of the Global Internal Audit Standards, it helps organizations identify the structures and processes that best assist the achievement of objectives and facilitate strong governance and risk management.
The IIA is the international professional body for internal auditors and the publisher of the Global Internal Audit Standards. The model is not mandatory, but boards, audit committees, regulators, and supervisors across sectors use it as the common description of how management (first and second line roles), the internal audit function (third line), the governing body, and external assurance providers relate to one another.
Organizations apply the model by adopting a principles-based approach, adapting the lines to their objectives and circumstances, clarifying the roles and responsibilities of the governing body, management, and internal audit, and aligning activities with the prioritized interests of stakeholders. The paper describes six principles, the key roles, the relationships among them, and how to apply the model.
Why it Matters
The original Three Lines of Defense was widely used but often read as a rigid org chart focused only on protecting value. The 2020 update takes a principles-based view, broadens the scope to creating value as well as protecting it, and explains how the roles work together, which is why banking supervisors, GRC standards, and audit committees now cite it.
Key benefits include:
- Clarify roles and accountability
State who is accountable for governance, who manages risk, and who provides independent assurance, and how they interact.
- Strengthen governance
Give the governing body a clear basis for oversight, delegation to management, and reliance on internal audit.
- Protect internal audit independence
Position the internal audit function with organizational independence from management so its assurance is objective.
- Align assurance across providers
Coordinate first and second line monitoring, internal audit, and external assurance so coverage is complete without duplication.
- Connect risk management to value
Treat risk management as a contribution to achieving objectives and creating value, not only as defense.
How it Works
The paper sets out six principles: governance requires appropriate structures and processes; the governing body ensures those structures exist and sets objectives and risk appetite; management's responsibility for objectives comprises first line roles that deliver products and services and second line roles that assist with managing risk; the internal audit function provides independent and objective assurance and advice on governance and risk management; third line independence from management is essential; and all roles together create and protect value when they are aligned with each other and with the prioritized interests of stakeholders.
Organizations implement the model by documenting the governing body's oversight arrangements, assigning first and second line roles within management, which may be blended or separated, establishing an internal audit function with direct reporting to the governing body, and defining how the lines communicate, cooperate, and collaborate. Regulated firms often map their risk, compliance, and audit charters to the model and use it in board reporting.
SmartSuite supports the model by recording the roles, charters, and responsibilities of each line, linking first and second line controls and monitoring to the risks they address, and tracking internal audit plans, findings, and management actions in one system with reporting to the audit committee.
Key Elements
- Principle 1: Governance
Accountability by a governing body to stakeholders, actions by management to achieve objectives, and assurance and advice by an independent internal audit function.
- Principle 2: Governing body roles
The governing body ensures appropriate structures and processes are in place and that organizational objectives and activities align with the prioritized interests of stakeholders.
- Principle 3: Management and first and second line roles
First line roles deliver products and services to clients; second line roles assist with managing risk; the two may be blended or separated.
- Principle 4: Third line roles
The internal audit function provides independent and objective assurance and advice on the adequacy and effectiveness of governance and risk management.
- Principle 5: Third line independence
Internal audit's independence from management is critical to its objectivity, authority, and credibility.
- Principle 6: Creating and protecting value
All roles working together contribute to the creation and protection of value when they are aligned through communication, cooperation, and collaboration.
- External assurance providers
External providers add assurance to satisfy legislative and regulatory expectations and requests from management and the governing body.
Framework Scope
The model applies to all organizations, regardless of size, sector, or ownership, and covers the governing body, management in its first and second line roles, the internal audit function, and external assurance providers. It is used in charters, board and audit committee reporting, regulatory expectations for banks and insurers, and as the assurance backbone of GRC programs.
Framework Objectives
The IIA published the model so that organizations can identify the structures and processes that best support the achievement of objectives and strong governance and risk management.
Clarify and strengthen the principles that underpin the three lines.
Broaden the scope from defense alone to creating and protecting value.
Explain how the governing body, management, and internal audit work together.
Establish the independence of the internal audit function from management.
Enable a principles-based application adapted to each organization's objectives and circumstances.
Align the model's terminology with the Global Internal Audit Standards.
Framework in Context
The Three Lines Model is referenced by the Basel Committee's operational risk principles, by prudential regimes such as APRA CPS 230, by COSO's internal control and ERM frameworks, and by the OCEG Red Book, and it complements the Global Internal Audit Standards that govern the third line. Compliance program benchmarks such as USSG §8B2.1 and the DOJ's Evaluation of Corporate Compliance Programs rely on the same separation of operational, oversight, and independent assurance roles.
Common Framework Mappings
Organizations map the model's roles and principles to the governance, risk, and control frameworks they already use so that lines of responsibility are consistent across the program.
Mapped frameworks include:
COSO IC 2013
COSO ERM 2017
ISO 31000:2018
BCBS PSMOR 2021
BCBS Operational Resilience Principles
APRA CPS 230
OCEG Red Book 3.5
USSG §8B2.1
DOJ ECCP
SOX
COBIT 2019
Global Internal Audit Standards
- ClassificationCategoryGovernance and AssuranceDomainRisk ManagementFramework FamilyOther
- Regulatory ContextTypeGuidanceLegal InstrumentPosition PaperSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionGlobalRegion DetailGlobal (The IIA)PublisherThe Institute of Internal Auditors (IIA)
- VersioningVersion2020 (updated September 2024)Effective Date2020Issue DateUpdated September 2024
- AdoptionAdoption ModelVoluntaryImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The IIA publishes the position paper free of charge in more than 25 languages, and the six principles and role descriptions are included with the platform as a requirement set.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports IIA Three Lines Model
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For the Three Lines Model, SmartSuite records each line's roles and charters, links first and second line controls and monitoring to risks, and manages internal audit plans, findings, and management actions with reporting to the audit committee.
Roles and Principles Library
Hold the six principles, the roles of the governing body, management, and internal audit, and their charters as structured records linked to your program.
Ownership, Cadence, and Accountability
Assign first, second, and third line owners to controls, monitoring, and audits, set review cycles, and track governing body approvals.
Evidence Collection and Audit Trail
Attach monitoring results, second line reviews, and audit workpapers to the activities they evidence, with timestamps and reviewers.
Assurance Planning and Testing
Plan first and second line testing and internal audit engagements, record findings, and track management actions to closure.
Risk and Objective Alignment
Link risks, objectives, and controls across the lines so assurance coverage maps to what matters to stakeholders.
Board and Audit Committee Reporting
Produce combined assurance dashboards showing coverage, open findings, and independence arrangements for the governing body.
Related frameworks

COSO ICFR guides organizations in designing and evaluating internal controls to ensure reliable financial reporting and regulatory compliance.

COSO ERM is a framework that helps organizations identify, assess, manage, and monitor enterprise risks to achieve objectives.

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

The Basel Committee's seven Principles for Operational Resilience set the international baseline for how banks deliver critical operations through disruption.

CPS 230 is an APRA standard requiring banks, insurers, and superannuation funds to manage operational risks and ensure resilience.

The Sarbanes-Oxley Act requires public companies to maintain reliable financial reporting and robust internal controls to prevent fraud.
Frequently Asked Questions For IIA Three Lines Model
It is The IIA's position paper describing how the governing body, management in first and second line roles, and the internal audit function work together to achieve objectives and support governance and risk management. It updates the earlier Three Lines of Defense.
First line roles deliver products and services to clients and manage the associated risk; second line roles assist with managing risk, such as compliance and risk functions; the third line is the internal audit function, which provides independent and objective assurance and advice.
The 2020 update takes a principles-based approach, broadens the focus from protecting value to creating and protecting value, clarifies that first and second line roles may be blended or separated, and explains the relationships among the roles rather than presenting a fixed org chart.
The IIA updated the paper to reflect the glossary of the Global Internal Audit Standards, so terms such as board, internal audit function, and control now match the Standards.
No. It is a position paper that organizations adopt voluntarily, although regulators and supervisors frequently reference it, and the Basel Committee and prudential rules expect banks to operate clear lines of defence.
The paper describes external assurance providers as a separate group that adds assurance to meet legislative and regulatory expectations and requests from management and the governing body.
SmartSuite records each line's roles and charters, links first and second line controls and monitoring to the risks they address, and manages internal audit plans, findings, and management actions. Audit committees use it for combined assurance reporting across the lines.
Yes. The IIA states the model applies to all organizations and is optimized by adapting it to organizational objectives and circumstances, so small organizations apply the principles with fewer formal structures.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.
