The three lines of defence is a model for splitting responsibility so that nobody is marking their own homework. It answers a question every governance discussion eventually reaches: who actually owns this risk, and who checks that the owner is doing something about it?
The three lines
First line - the people who own and manage the risk
Operational management. The engineers who configure systems, the team that grants access, the managers who approve payments. They own the risk because they create it and control it day to day, and they operate the controls.
The most common misconception is that the first line is "the business" and risk belongs to someone else. It does not. A control operated by the first line is where compliance actually happens.
Second line - oversight and challenge
Risk management, compliance, information security governance. They set the framework, define policy, monitor whether the first line is doing what it should, and challenge when it is not. They advise and oversee - they do not own the underlying risk.
The second line's independence is limited by design: they help build the controls, so they cannot objectively assure them.
Third line - independent assurance
Internal audit. Provides objective assurance to the board and audit committee on whether the first and second lines are working. Independence is the whole point: internal audit reports to the board or audit committee, not to the executives whose activities it examines.
What it is really solving
Without separation, you get self-assessment all the way up. The team that built a control reports that the control works, the manager who owns the outcome confirms it, and the board hears good news. The model exists so that assurance comes from somewhere with nothing to lose from bad news.
A useful test: when your board is told controls are effective, how many steps back does that claim trace to someone who was not involved in operating them? If the answer is "none", you do not have a third line, whatever the org chart says.
Give each line the view it needs
GRC Copilot gives control owners their tasks, gives the second line oversight of coverage and evidence, and gives assurance a defensible trail - from one system.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Common failure modes
- The second line doing the first line's job. Compliance ends up performing access reviews because the business will not. It gets done, but nobody independent is checking it, and ownership never transfers.
- No third line at all. Common in smaller organisations, and acceptable if acknowledged - not if the board is told otherwise.
- Internal audit reporting to the CISO or CFO. That reporting line destroys the independence the third line exists to provide.
- Lines used to deflect. "That is second line's problem" is usually a sign the first line has not accepted ownership.
- Assurance duplication. Three functions testing the same control while a different area goes unexamined - which is what assurance mapping is meant to prevent.
Applying it when you are small
You do not need three departments. You need the separation of duties that the model represents:
- Control owners named in the business, not in security.
- Someone with a governance remit who reviews and challenges - even if part-time.
- Independent assurance obtained externally: an external auditor, an independent internal audit engagement, or a consultant reporting to the board rather than to management.
Frameworks recognise this. ISO 27001 requires an internal audit but permits it to be performed by anyone sufficiently independent of the area being audited - including an external party.
How it shows up in frameworks
- ISO 27001 - internal audit and management review are mandatory clauses, and auditor independence is explicitly required.
- SAMA CSF and NCA ECC - expect governance structures with defined roles and independent review.
- SOC 2 - the control environment criteria address organisational structure, authority and accountability.
- DORA and NIS2 - place accountability explicitly on management bodies, reinforcing the oversight layer.
Frequently asked questions
Is the model outdated?
It has been refined - newer guidance emphasises collaboration between lines rather than rigid separation, and clarifies the governing body's role. The core principle, that assurance should be independent of operation, remains sound.
Where does external audit sit?
Outside the three lines, providing external assurance to shareholders, regulators or customers. It complements internal audit rather than replacing it.
Can one person cover two lines?
In small organisations, often unavoidable - but document it and compensate. Someone cannot independently assure a control they operate; obtain that assurance externally.
Who owns risk in this model?
The first line, always. The second line oversees and advises; the third assures. If risk ownership drifts to the second line, the model has broken.
Key takeaways
- First line owns and operates; second oversees; third independently assures.
- The point is that assurance comes from someone with nothing to lose from bad news.
- Compliance performing first-line work is the most common failure.
- Small organisations need the separation, not the headcount.