Three Lines Model
The Three Lines Model is a framework that clarifies who does what across an organization when it comes to managing risk and maintaining good governance. It defines distinct roles for the people who own and manage risk day to day, the functions that oversee and support risk management, and the independent assurance function that reports to governing bodies. It is an updated version of the earlier Three Lines of Defense model published by the Institute of Internal Auditors (IIA).
The Three Lines Model, published by the Institute of Internal Auditors as an update to the familiar Three Lines of Defense, is a governance framework that identifies the structures, processes, roles, and responsibilities needed to support effective risk management and governance. It distinguishes first-line roles that own and manage risk, second-line roles that provide oversight and expertise in risk and compliance functions, and third-line roles that provide independent assurance. The 2020 update reframes and strengthens the underpinning principles rather than treating the lines as rigid, defensive silos, and it remains among the most widely adopted frameworks for structuring enterprise risk management programs. In the context of security leadership, the model helps clarify accountability boundaries, though how it is applied and where a security leadership role sits within the lines will vary by organization and engagement scope.
Why it matters
The Three Lines Model matters because one of the most common failures in risk management is ambiguity about who is actually responsible for what. When the people who own and manage risk day to day, the functions that oversee and advise on risk, and the independent assurance function all blur together, gaps and overlaps emerge that leave real exposures unaddressed. The model gives organizations a shared vocabulary for assigning these roles, which supports effective governance and helps a governing body understand where accountability sits.
For security leadership, the model is especially useful in clarifying accountability boundaries. A virtual or fractional CISO often advises and directs across governance, risk, and program development, but the model helps make explicit that owning and managing risk day to day, providing oversight and compliance expertise, and delivering independent assurance are distinct functions. This matters because legal and organizational accountability for security decisions typically remains with the client organization and its officers, not with an advisory role. Mapping a security leadership engagement against the lines helps prevent the assumption that bringing in a CISO transfers accountability rather than adding expertise and direction.
The framework remains among the most widely adopted approaches for structuring enterprise risk management programs, which makes it a practical reference point when a security leader is helping an organization stand up or mature its governance. Its value, however, depends on how it is applied. The 2020 update deliberately reframes the lines away from rigid, defensive silos, and where exactly a security role sits within the lines will vary by organization, maturity, and engagement scope.
Who it's relevant to
Inside Three Lines Model
Common questions
Answers to the questions practitioners most commonly ask about Three Lines Model.