Skip to content

The Three Lines in 2026: Where does internal audit end and risk management begin?

The Institute of Internal Auditors released two intertwined Statements of Position in July 2026: one on the 3 Lines Model1, and the other on Internal Audit’s role in enterprise risk management2.

While they are separate, the enterprise risk paper references the 3 Lines Model paper, stating that together they provide a consistent framework.

Let’s start with the 3 Lines Model.

Download Risk in motion: A guide to connected, continuous risk management

What’s new in the 3 Lines Model?

There are a few claims throughout the document, including that the update:

  • Addresses a recurring challenge faced by boards and senior management on how to structure and align assurance and advisory capabilities
  • Clarifies how assurance and advisory activities support effective governance
  • Highlights that assurance and advisory are distinct but complementary

While this document does expand on some of these, it isn’t materially different from the 2020 version, and the IIA itself acknowledges the core structure is unchanged. Independence is still core to the 3 Lines Model; Line 1 manages outcomes, Line 2 (risk management and related roles) provides advice, oversight and challenge, and Line 3 (internal audit) provides independent assurance and advice to the board.

That independence is also where some of the tension lies across both of the new documents.

A brief history of the 3 Lines Model

The concept of internal control has been recorded as early as 3600 BC. Moving closer to our lifetime, while the 3 Lines has been formalised into documents like those produced by the IIA, they codified what was already emerging practice. While managing risk has always been within the remit of management, risk management as a discipline to support management began evolving in the latter half of the 20th century, particularly in financial services. In a 2003 paper, the Financial Services Authority (FSA) in the UK noted that many firms had adopted a ‘three lines of defence’ approach.3

In 2010 the Federation of European Risk Management Associations (FERMA) and the European Confederation of Institutes of Internal Audit (ECIIA) jointly released guidance on article 41 of the 8th EU Company Law Directive; namely, how to monitor the effectiveness of internal control, internal audit and risk management systems. It explicitly included the Three Lines of Defence model, including a graphical representation that has inspired IIA versions.4

The Institute of Internal Auditors formalised and internationally popularised its Position Paper on the 3 Lines of Defence model in January 2013, adapting the FERMA model. It became the dominant version due to the international reach of the IIA. Of note in this version is that senior management appeared graphically separated from Line 1 and Line 2.5

That was addressed in the 2020 IIA update, where Line 1 and Line 2 were rolled into management, and the document moved to a principles-based governance model with more emphasis on collaboration. Most importantly, it dropped the word ‘Defence’ and became the 3 Lines Model. This was a welcome change, as you don’t just defend against risk; you need appropriate risk-taking to succeed.6

While the IIA promotes the 3 Lines Model for all organisations, during the 2010s the basic model became increasingly referenced by financial services regulators. Basel referenced the Three Lines of Defence in its Corporate Governance Principles for Banks in 2015, helping embed the terminology across international banking and the broader financial services landscape.7 Some financial services regulators continue to use ‘defence’ terminology, while others have adopted the newer language. The Reserve Bank of New Zealand is a recent example, referring explicitly to the Three Lines Model in its 2026 draft guidance for deposit takers.8

Who integrates assurance?

The Executive Summary opens by emphasising the roles and their contributions. It states that “Management (first line) owns and manages risks and is responsible for the design and operation of processes and controls.” Sure, but management are primarily concerned with achieving objectives and meeting performance targets. I would have liked to see more context here, and that implementing processes and controls is aligned with the pursuit of sustainable performance.

Page 4 states that the internal audit function is the integrator of assurance. This implies it is core to the role, but later it says that internal audit ‘may facilitate’ assurance mapping and developing shared risk taxonomies. Reading between the lines and based on personal experience, I’m not convinced that does or will happen much in practice (though perhaps this is IIA positioning for it to happen in future). I’ve built an assurance map in a second-line capacity, combining planned assurance activities from the risk team’s internal activities, alongside quality and assurance activities performed in the first line, combined with the internal audit plan. Internal audit being outsourced may have played a part in that specific example, but Line 2 seems like a better conduit for this activity, particularly as it tends to work more closely with Line 1 on some of the more operational controls assurance activities.

I agree on risk taxonomies to an extent. It doesn’t make sense to have two completely separate taxonomies, especially if those are used for aggregate reporting purposes. But that seems like something for a centralised risk function to lead, with internal audit providing independent challenge and collaboration.

From assurance coordination to risk management

Part II outlines how to use the model in practice, and outlines the distinct value of each line. The end of the document dives further into the blending of the two roles, which is a good time to shift focus to the other document, The Role of the Internal Audit Function in Enterprise Risk Management. It opens early with the statement that management is responsible for managing risks and implementing enterprise risk processes, and that internal audit assesses the effectiveness of enterprise risk processes. That sounds perfectly fine, but it gets a little murky as we get into the details.

Blurring the lines on enterprise risk

Page 7 spells out the skills and capabilities of internal audit. This includes understanding concepts such as linking risks to objectives, how risk appetite and tolerance are applied, evaluating risk culture and linking risk information to decision-making – all skills that risk management should also have. Shared competence does not mean shared accountability.

Page 8 provides a graphic that includes the more common steps in a risk process: identify, assess, manage, monitor and report. Littered across the visual are what internal audit should and should not do. However, many of these are performed by mature Line 2 functions as well:

  • Provide advice to improve risk identification (e.g. facilitate a workshop) without owning the risks
  • Advise on risk responses without selecting or implementing them
  • Provide assurance over risk responses, which might be performed by Line 2 in an assurance capacity or as part of its challenge remit

The document also includes this statement: “Because the internal audit function is positioned to take an organizationwide view, it can provide integrated conclusions about the coherence of risk management across the organization, rather than only evaluating isolated components.” A properly structured enterprise risk management framework will also have this organisation-wide view, and continuous improvement should already be part of an enterprise risk framework. A clearer distinction is that Line 2’s enterprise-wide view supports management decisions, trade-offs, aggregation, reporting and escalation. Internal audit’s enterprise-wide view independently assesses whether the overall risk management system is coherent and effective.

Maintaining internal audit’s independence

Common across both documents are recommendations to preserve the independence of internal audit if it is playing in the enterprise risk arena. These are all sound practices, such as clearly defined roles, separation across advisory and assurance work, and transparency on actual or perceived conflicts.

The second half of the enterprise risk paper provides guidance related to a couple of operating models organisations may find themselves in: where internal audit is performing some enterprise risk management work, and where the risk management function reports to the Chief Audit Executive. The advice here is largely sensible, recommending safeguards and (hopefully) temporary measures, and avoiding making decisions on behalf of management. Some of these may be more difficult in practice; providing advice on response options or potential ways to design a control (without telling management which option is best) walks a fine line, but might also be in the best interests of the organisation if internal audit has unique expertise in that context.

A clearer distinction between the three lines

This may articulate what I believe should be Line 2’s value-add, which is decision support. An effective Line 2 may have specific expertise that enables it to support management: highlighting assumptions that need to be challenged, improving understanding and measurement of uncertainty, and providing aggregated views of risk to support decisions. A clearer distinction here may be:

  • Line 1 makes decisions
  • Line 2 improves decision quality
  • Line 3 provides assurance over decision-making processes.

Keeping distinct purposes in view

The 2026 Three Lines paper does not materially change the model established in 2020. Its main contribution is to expand the discussion of assurance, advice, coordination, reliance and overlapping organisational roles.

The accompanying enterprise risk paper goes further by legitimising a broad range of internal audit involvement in activities that may otherwise sit with a second-line risk function. The proposed safeguards are sensible, but safeguards do not resolve every practical concern about self-review, duplicated capability or unclear accountability.

The papers are understandably written from an internal audit perspective. Read less charitably, the papers may be seen as expanding internal audit’s permissible territory into activities commonly performed by second-line risk functions. Whether this becomes constructive integration or institutional boundary expansion will depend on how boards and CAEs interpret the safeguards.

The more useful debate is therefore not who owns which territory. It is whether the three lines have clearly differentiated purposes: management achieves objectives and owns risk; the second line strengthens decisions through expertise, frameworks and challenge; and internal audit provides independent assurance and advice. Coordination matters, but it should not erase those distinctions.

Connect risk, decisions and assurance with Protecht

Clear responsibilities are essential, but they are difficult to sustain when each line works from separate risk registers, control records, assurance plans and reports.

A connected enterprise risk management platform gives management, risk teams and internal audit a shared view of the organisation’s objectives, risks, controls, incidents and actions, while allowing each line to retain its distinct role.

Protecht brings this information together so Line 1 can own and manage risk, Line 2 can provide informed challenge and decision support, and Line 3 can plan and deliver independent assurance with access to consistent, traceable information.

Request a Protecht demo

References

  1. The Institute of Internal Auditors, Three Lines Model: Assurance and Advice in Support of Effective Governance (Back to citation)
  2. The Institute of Internal Auditors, The Role of the Internal Audit Function in Enterprise Risk Management (Back to citation)
  3. Financial Services Authority, Building a framework for operational risk management: the FSA’s observations, 2003 (Back to citation)
  4. FERMA and ECIIA, Guidance on the 8th EU Company Law Directive, article 41, 2010 (Back to citation)
  5. The Institute of Internal Auditors, The Three Lines of Defense in Effective Risk Management and Control, 2013 (Back to citation)
  6. The Institute of Internal Auditors, The IIA’s Three Lines Model, 2020 (Back to citation)
  7. Basel Committee on Banking Supervision, Corporate governance principles for banks, 2015 (Back to citation)
  8. Reserve Bank of New Zealand, Risk Management Standard draft guidance, 2026 (Back to citation)

About the author

Michael is Head of Risk Research and Knowledge at Protecht. He is passionate about the field of risk management and related disciplines, with a focus on helping organisations succeed using a ‘decisions eyes wide open’ approach. His experience includes managing risk functions, assurance programs, policy management, corporate insurance, and compliance. He is a Certified Practicing Risk Manager whose curiosity drives his approach to challenge the status quo and look for innovative solutions.