What is the three lines model for internal audit managers?
The three lines model for internal audit managers is a way of splitting risk work so internal audit stays independent. First line owns and manages risk in the business. Second line advises, monitors, and challenges. Third line, internal audit, gives the board independent assurance. The 2020 IIA update treats these as roles, not three departments on a chart.
That last point is the one that trips teams. Many organisations still run “three lines of defence” as an org chart: operations, a risk/compliance unit, and audit. The 2020 model keeps three kinds of responsibility, but it puts the governing body in the picture and drops the idea that risk work exists only to defend against threat. For an audit manager, the practical test is not whether the boxes exist. It is whether first line actually owns risk, second line can still say no, and you can still report what the executive would rather not hear.
This post is for people who run or sit in the third line. It is not a history of the IIA paper.
What should the first and second lines actually do?
First line is management that delivers the work and owns the risk that comes with it. They design controls, run them, and fix them when they fail. They are not “the people audit inspects.” They are the control owners.
Second line is specialist support and challenge: risk, compliance, quality, information security, and similar functions. They set frameworks, test whether first line is using them, and escalate when it is not. They do not take ownership away from the business, and they are not a substitute for internal audit.
If second line writes the control, performs it, and then “assures” it, you no longer have three lines. You have a second-line operation wearing two hats. That is a finding, not a footnote.
For managers building risk assessment training into first-line teams, the aim is identification and ownership in the job, not a once-a-year workshop that leaves the register with risk.
Where does internal audit sit, and what must stay independent?
Internal audit is the third line. You provide independent assurance to the board (or audit committee) on whether governance, risk management, and controls are designed and working. You do not own the risk. You do not run the control. You do not sign off first-line work so that management can treat the file as closed.
Independence is operational, not a sentence in the charter. Watch for:
- Management setting the audit plan without committee challenge
- The CAE reporting through the CFO for both pay and scope
- Audit being asked to “help implement” a control it will later review
- Combined assurance that quietly lets second line mark its own homework
Combined assurance is useful when it is a map of who tested what. It is harmful when it is a reason not to look.
This is also why control self-assessment belongs in first and second line. RCSA is management’s view of its own controls. Internal audit may use it as evidence. It is not third-line work.
How should an audit manager use the model in the annual plan?
Use the lines to decide what you will not audit as if you owned it.
Start with the board’s questions, not last year’s universe. Where is residual risk highest? Where is first-line ownership weak? Where is second-line challenge decorative? Those are third-line priorities.
Then be explicit in the plan:
- What first line is expected to evidence (KRIs, incidents, control performance)
- What second line will have already tested, and how you will re-perform or not
- Where you will go in depth because nobody else is independent enough to do it
Do not fill the plan with low-risk process audits because they are easy to staff. A three-line structure that never touches strategy, culture, or model risk is a filing system.
The same logic applies when you train people, not only when you audit them. Live practice still beats a module when the skill is judgement, which is why instructor led training vs e-learning for managers matters for audit teams as much as for operations.

What usually fails when organisations say they use three lines?
The failures are familiar, and they are managerial rather than theoretical.
First line treats the risk register as a reporting chore. Second line produces frameworks nobody uses. Internal audit is late, polite, and crowded out of the issues that would actually move the board. Everyone assumes someone else has the risk. The diagram looks complete.
A useful test, as an audit manager, is blunt:
- Has second line ever changed a first-line decision this year?
- Has internal audit reported something the executive did not want reported?
- Can a process owner name the control they own without looking at a slide?
If the answers are no, the model is on the wall and not in the work. Training that only recites the three boxes will not fix that. Training that makes first-line managers identify and escalate risk, and audit managers plan against residual risk, might.
If you need to put this into an annual plan, a control matrix, and fieldwork rather than another governance slide, review EPW’s five-day Risk Based Auditing and Internal Controls course. It is built for audit and risk managers who have to evidence the third line, not just name it.
FAQ
Is the three lines model the same as three lines of defence?
No. The IIA’s 2020 model keeps three kinds of role but drops the “defence” framing, treats the lines as responsibilities rather than three departments, and includes the governing body. Many firms still use the older name in conversation.
Can internal audit also do second-line work?
Only with a clear, time-limited mandate and a plan to restore independence. If audit designs or runs the control, it cannot later give independent assurance on that control.
Does every organisation need three separate departments?
No. Small organisations often combine first- and second-line tasks. What you cannot combine is independent assurance. If the same person owns the risk and “assures” it, you do not have a third line.

2 thoughts on “Three Lines Model for Internal Audit Managers”
Comments are closed.