Governance and Assurance
DETAIL

The IIA's Three Lines Model: An Update of the Three Lines of Defense (2020, updated September 2024)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

The IIA's Three Lines Model is a position paper from The Institute of Internal Auditors that updates the earlier Three Lines of Defense. Published in 2020 and updated in September 2024 to reflect the glossary of the Global Internal Audit Standards, it helps organizations identify the structures and processes that best assist the achievement of objectives and facilitate strong governance and risk management.

The IIA is the international professional body for internal auditors and the publisher of the Global Internal Audit Standards. The model is not mandatory, but boards, audit committees, regulators, and supervisors across sectors use it as the common description of how management (first and second line roles), the internal audit function (third line), the governing body, and external assurance providers relate to one another.

Organizations apply the model by adopting a principles-based approach, adapting the lines to their objectives and circumstances, clarifying the roles and responsibilities of the governing body, management, and internal audit, and aligning activities with the prioritized interests of stakeholders. The paper describes six principles, the key roles, the relationships among them, and how to apply the model.

Why it Matters

The original Three Lines of Defense was widely used but often read as a rigid org chart focused only on protecting value. The 2020 update takes a principles-based view, broadens the scope to creating value as well as protecting it, and explains how the roles work together, which is why banking supervisors, GRC standards, and audit committees now cite it.

Key benefits include:

  • Clarify roles and accountability

State who is accountable for governance, who manages risk, and who provides independent assurance, and how they interact.

  • Strengthen governance

Give the governing body a clear basis for oversight, delegation to management, and reliance on internal audit.

  • Protect internal audit independence

Position the internal audit function with organizational independence from management so its assurance is objective.

  • Align assurance across providers

Coordinate first and second line monitoring, internal audit, and external assurance so coverage is complete without duplication.

  • Connect risk management to value

Treat risk management as a contribution to achieving objectives and creating value, not only as defense.

How it Works

The paper sets out six principles: governance requires appropriate structures and processes; the governing body ensures those structures exist and sets objectives and risk appetite; management's responsibility for objectives comprises first line roles that deliver products and services and second line roles that assist with managing risk; the internal audit function provides independent and objective assurance and advice on governance and risk management; third line independence from management is essential; and all roles together create and protect value when they are aligned with each other and with the prioritized interests of stakeholders.

Organizations implement the model by documenting the governing body's oversight arrangements, assigning first and second line roles within management, which may be blended or separated, establishing an internal audit function with direct reporting to the governing body, and defining how the lines communicate, cooperate, and collaborate. Regulated firms often map their risk, compliance, and audit charters to the model and use it in board reporting.

SmartSuite supports the model by recording the roles, charters, and responsibilities of each line, linking first and second line controls and monitoring to the risks they address, and tracking internal audit plans, findings, and management actions in one system with reporting to the audit committee.

Key Elements

  • Principle 1: Governance

Accountability by a governing body to stakeholders, actions by management to achieve objectives, and assurance and advice by an independent internal audit function.

  • Principle 2: Governing body roles

The governing body ensures appropriate structures and processes are in place and that organizational objectives and activities align with the prioritized interests of stakeholders.

  • Principle 3: Management and first and second line roles

First line roles deliver products and services to clients; second line roles assist with managing risk; the two may be blended or separated.

  • Principle 4: Third line roles

The internal audit function provides independent and objective assurance and advice on the adequacy and effectiveness of governance and risk management.

  • Principle 5: Third line independence

Internal audit's independence from management is critical to its objectivity, authority, and credibility.

  • Principle 6: Creating and protecting value

All roles working together contribute to the creation and protection of value when they are aligned through communication, cooperation, and collaboration.

  • External assurance providers

External providers add assurance to satisfy legislative and regulatory expectations and requests from management and the governing body.

Framework Scope

The model applies to all organizations, regardless of size, sector, or ownership, and covers the governing body, management in its first and second line roles, the internal audit function, and external assurance providers. It is used in charters, board and audit committee reporting, regulatory expectations for banks and insurers, and as the assurance backbone of GRC programs.

Framework Objectives

The IIA published the model so that organizations can identify the structures and processes that best support the achievement of objectives and strong governance and risk management.

Clarify and strengthen the principles that underpin the three lines.

Broaden the scope from defense alone to creating and protecting value.

Explain how the governing body, management, and internal audit work together.

Establish the independence of the internal audit function from management.

Enable a principles-based application adapted to each organization's objectives and circumstances.

Align the model's terminology with the Global Internal Audit Standards.

Framework in Context

The Three Lines Model is referenced by the Basel Committee's operational risk principles, by prudential regimes such as APRA CPS 230, by COSO's internal control and ERM frameworks, and by the OCEG Red Book, and it complements the Global Internal Audit Standards that govern the third line. Compliance program benchmarks such as USSG §8B2.1 and the DOJ's Evaluation of Corporate Compliance Programs rely on the same separation of operational, oversight, and independent assurance roles.

Common Framework Mappings

Organizations map the model's roles and principles to the governance, risk, and control frameworks they already use so that lines of responsibility are consistent across the program.

Mapped frameworks include:

COSO IC 2013

COSO ERM 2017

ISO 31000:2018

BCBS PSMOR 2021

BCBS Operational Resilience Principles

APRA CPS 230

OCEG Red Book 3.5

USSG §8B2.1

DOJ ECCP

SOX

COBIT 2019

Global Internal Audit Standards

At a Glance
The IIA's Three Lines Model: An Update of the Three Lines of Defense (2020, updated September 2024)
  • Classification
    Category
    Governance and Assurance
    Domain
    Risk Management
    Framework Family
    Other
  • Regulatory Context
    Type
    Guidance
    Legal Instrument
    Position Paper
    Sector
    Cross-Sector
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    Global
    Region Detail
    Global (The IIA)
    Publisher
    The Institute of Internal Auditors (IIA)
  • Versioning
    Version
    2020 (updated September 2024)
    Effective Date
    2020
    Issue Date
    Updated September 2024
  • Adoption
    Adoption Model
    Voluntary
    Implementation Complexity
    Medium
  • Official Reference
License Information

License included / downloadable: Yes

The IIA publishes the position paper free of charge in more than 25 languages, and the six principles and role descriptions are included with the platform as a requirement set.

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
The IIA's Three Lines Model position paper
The IIA's page for the model, with the September 2024 update note and downloads in more than 25 languages.
Three Lines Model (English PDF)
The position paper text: six principles, key roles, relationships among roles, and how to apply the model.
Global Internal Audit Standards
The IIA's 2024 Standards whose glossary the updated model adopts and which govern the third line.
IIA Standards and guidance
The IIA's standards hub covering the International Professional Practices Framework and related guidance.
SMARTSUITE

How SmartSuite Supports IIA Three Lines Model

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

For the Three Lines Model, SmartSuite records each line's roles and charters, links first and second line controls and monitoring to risks, and manages internal audit plans, findings, and management actions with reporting to the audit committee.

Roles and Principles Library

Hold the six principles, the roles of the governing body, management, and internal audit, and their charters as structured records linked to your program.

Ownership, Cadence, and Accountability

Assign first, second, and third line owners to controls, monitoring, and audits, set review cycles, and track governing body approvals.

Evidence Collection and Audit Trail

Attach monitoring results, second line reviews, and audit workpapers to the activities they evidence, with timestamps and reviewers.

Assurance Planning and Testing

Plan first and second line testing and internal audit engagements, record findings, and track management actions to closure.

Risk and Objective Alignment

Link risks, objectives, and controls across the lines so assurance coverage maps to what matters to stakeholders.

Board and Audit Committee Reporting

Produce combined assurance dashboards showing coverage, open findings, and independence arrangements for the governing body.

Related frameworks

COSO IC 2013

COSO ICFR guides organizations in designing and evaluating internal controls to ensure reliable financial reporting and regulatory compliance.

COSO ERM 2017

COSO ERM is a framework that helps organizations identify, assess, manage, and monitor enterprise risks to achieve objectives.

ISO 31000:2018

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

BCBS Operational Resilience Principles

The Basel Committee's seven Principles for Operational Resilience set the international baseline for how banks deliver critical operations through disruption.

APRA CPS 230

CPS 230 is an APRA standard requiring banks, insurers, and superannuation funds to manage operational risks and ensure resilience.

SOX

The Sarbanes-Oxley Act requires public companies to maintain reliable financial reporting and robust internal controls to prevent fraud.

COBIT 2019

COBIT 2019 is a governance framework that helps organizations govern and manage IT to meet business goals, risks, and compliance.

BCBS PSMOR 2021

The Basel Committee's twelve revised Principles for the Sound Management of Operational Risk set the supervisory baseline for how banks govern, identify, control, and report the risk.

ONBOARDING FAQS

Frequently Asked Questions For IIA Three Lines Model

What is the Three Lines Model?

It is The IIA's position paper describing how the governing body, management in first and second line roles, and the internal audit function work together to achieve objectives and support governance and risk management. It updates the earlier Three Lines of Defense.

What are the three lines?

First line roles deliver products and services to clients and manage the associated risk; second line roles assist with managing risk, such as compliance and risk functions; the third line is the internal audit function, which provides independent and objective assurance and advice.

What changed from the Three Lines of Defense?

The 2020 update takes a principles-based approach, broadens the focus from protecting value to creating and protecting value, clarifies that first and second line roles may be blended or separated, and explains the relationships among the roles rather than presenting a fixed org chart.

What was updated in September 2024?

The IIA updated the paper to reflect the glossary of the Global Internal Audit Standards, so terms such as board, internal audit function, and control now match the Standards.

Is the Three Lines Model mandatory?

No. It is a position paper that organizations adopt voluntarily, although regulators and supervisors frequently reference it, and the Basel Committee and prudential rules expect banks to operate clear lines of defence.

Where do external auditors and regulators fit?

The paper describes external assurance providers as a separate group that adds assurance to meet legislative and regulatory expectations and requests from management and the governing body.

How does SmartSuite support the Three Lines Model?

SmartSuite records each line's roles and charters, links first and second line controls and monitoring to the risks they address, and manages internal audit plans, findings, and management actions. Audit committees use it for combined assurance reporting across the lines.

Does the model apply to small organizations?

Yes. The IIA states the model applies to all organizations and is optimized by adapting it to organizational objectives and circumstances, so small organizations apply the principles with fewer formal structures.

Operationalize IIA Three Lines Model with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.