Skip to main content
Category: Governance & Leadership

Three Lines Model

Also known as: Three Lines of Defense, IIA Three Lines Model, 3 Lines Model
Simply put

The Three Lines Model is a framework that clarifies who does what across an organization when it comes to managing risk and maintaining good governance. It defines distinct roles for the people who own and manage risk day to day, the functions that oversee and support risk management, and the independent assurance function that reports to governing bodies. It is an updated version of the earlier Three Lines of Defense model published by the Institute of Internal Auditors (IIA).

Formal definition

The Three Lines Model, published by the Institute of Internal Auditors as an update to the familiar Three Lines of Defense, is a governance framework that identifies the structures, processes, roles, and responsibilities needed to support effective risk management and governance. It distinguishes first-line roles that own and manage risk, second-line roles that provide oversight and expertise in risk and compliance functions, and third-line roles that provide independent assurance. The 2020 update reframes and strengthens the underpinning principles rather than treating the lines as rigid, defensive silos, and it remains among the most widely adopted frameworks for structuring enterprise risk management programs. In the context of security leadership, the model helps clarify accountability boundaries, though how it is applied and where a security leadership role sits within the lines will vary by organization and engagement scope.

Why it matters

The Three Lines Model matters because one of the most common failures in risk management is ambiguity about who is actually responsible for what. When the people who own and manage risk day to day, the functions that oversee and advise on risk, and the independent assurance function all blur together, gaps and overlaps emerge that leave real exposures unaddressed. The model gives organizations a shared vocabulary for assigning these roles, which supports effective governance and helps a governing body understand where accountability sits.

For security leadership, the model is especially useful in clarifying accountability boundaries. A virtual or fractional CISO often advises and directs across governance, risk, and program development, but the model helps make explicit that owning and managing risk day to day, providing oversight and compliance expertise, and delivering independent assurance are distinct functions. This matters because legal and organizational accountability for security decisions typically remains with the client organization and its officers, not with an advisory role. Mapping a security leadership engagement against the lines helps prevent the assumption that bringing in a CISO transfers accountability rather than adding expertise and direction.

The framework remains among the most widely adopted approaches for structuring enterprise risk management programs, which makes it a practical reference point when a security leader is helping an organization stand up or mature its governance. Its value, however, depends on how it is applied. The 2020 update deliberately reframes the lines away from rigid, defensive silos, and where exactly a security role sits within the lines will vary by organization, maturity, and engagement scope.

Who it's relevant to

Security and risk leaders
Virtual, fractional, and interim CISOs use the Three Lines Model to clarify where their advisory and governance role fits and to make accountability boundaries explicit. Because a security leader typically advises and directs rather than assuming legal or organizational accountability, the model helps set expectations with clients about which functions own risk, which provide oversight, and which deliver independent assurance.
Boards and governing bodies
Governing bodies rely on the model to understand how risk is managed and assured across the organization and to receive independent assurance from the third line. It supports effective governance by defining roles and responsibilities so that directors can see whether oversight and assurance are structured appropriately.
Executives and officers
Because accountability for security and risk decisions generally remains with the organization and its officers, executives benefit from the model's clarity on first-line ownership. It helps them distinguish the risk they own and manage from the oversight and expertise provided by second-line functions and any external security leadership they engage.
Internal audit and assurance functions
The model, published by the Institute of Internal Auditors, positions internal audit as the third line providing independent assurance to the governing body. It helps assurance teams define their independence from the operational and oversight functions they evaluate.
Compliance and risk functions
Second-line risk and compliance teams use the model to define their oversight and support role relative to the first line that owns risk. It clarifies that they provide expertise and monitoring without taking ownership of the underlying operational risks.

Inside Three Lines Model

First Line (Operational Management)
The functions that own and manage risk directly through day-to-day operations, controls, and processes. In a security context this includes IT teams, application owners, and business units that implement and operate security controls as part of their normal work.
Second Line (Risk and Compliance Oversight)
Functions that provide oversight, expertise, monitoring, and challenge to the first line, such as risk management, compliance, and information security governance. A virtual CISO frequently supports or occupies aspects of this line by setting policy, defining risk appetite guidance, and monitoring the effectiveness of controls, while advising rather than performing hands-on operational tasks.
Third Line (Internal Audit)
Independent assurance that provides objective evaluation of the effectiveness of governance, risk management, and controls. This line typically reports to the board or audit committee and remains separate from the functions it evaluates to preserve independence.
Governing Body and Management
The updated model emphasizes the roles of the governing body (such as the board) and senior management in setting objectives, delegating responsibility, and remaining accountable for risk and governance outcomes. Legal and organizational accountability for security decisions generally rests here, not with an external advisor.
Principles-Based Structure
The model is intended as a principles-based framework for organizing roles and relationships around risk and governance, rather than a rigid set of separate departments. Lines describe responsibilities and relationships and may overlap in practice depending on organizational size and maturity.

Common questions

Answers to the questions practitioners most commonly ask about Three Lines Model.

Does adopting the Three Lines Model mean a virtual CISO belongs to a specific line and assumes accountability for security outcomes?
No. The Three Lines Model is a governance structure for organizing roles in risk management, and a virtual CISO does not neatly occupy one line in a way that transfers accountability to them. In many engagements a vCISO advises and directs first-line and second-line functions, but legal and organizational accountability for security decisions typically remains with the client organization and its officers. The model clarifies who owns risk, who oversees it, and who provides assurance, rather than shifting that ownership to an external advisor. Where a vCISO sits often varies by engagement scope and how the client defines the relationship.
Is the Three Lines Model a rigid separation where each line works in isolation?
That is a common misreading. The updated model emphasizes coordination and communication among the lines rather than strict silos, and it moved away from the earlier defense oriented framing that suggested rigid barriers. In practice the lines interact, and a virtual CISO may help facilitate that collaboration. Treating the lines as isolated compartments tends to undermine the model's purpose, which is to make roles and accountability clear while still enabling the lines to work together toward the organization's objectives.
How does a virtual CISO typically position their role within the Three Lines Model?
This often varies by engagement and how the client structures its risk functions. A vCISO frequently provides strategy, governance, and oversight that align with a second-line role, helping establish policies, risk frameworks, and monitoring expectations, while operational execution stays with first-line teams. In some engagements a vCISO also advises leadership and the governing body on how the lines interact. Because a vCISO generally advises and directs rather than performing hands-on operational tasks, defining their position relative to the lines at the start of the engagement helps avoid confusion over responsibility and accountability.
What should an organization clarify before using the Three Lines Model to structure a vCISO engagement?
It helps to define which functions constitute the first line of operational risk ownership, which provide second-line oversight, and which provide independent assurance, before layering a vCISO onto that structure. Organizations should also clarify what is in and out of the vCISO's scope, since a vCISO typically does not perform first-line operational tasks such as tool administration or incident response execution unless explicitly contracted. Establishing stakeholder access and reporting relationships early tends to make the model more effective, because the value of the structure depends on client cooperation and clearly defined scope.
How can the Three Lines Model help avoid confusion between a vCISO's advisory role and internal execution?
The model provides a shared vocabulary for separating who owns and manages risk day to day, who oversees and challenges it, and who provides independent assurance. Mapping a vCISO's advisory and governance contributions against these roles can make it clearer that the vCISO directs and advises while internal teams execute. This distinction matters because security leadership is a governance and business risk function, not solely a technical one, and the model helps document where responsibility for execution remains inside the organization rather than with the external advisor.
What limitations should be considered when applying the Three Lines Model in a vCISO engagement?
The model is a governance structure, not a guarantee of effective risk management, and its usefulness depends on organizational maturity, defined roles, and stakeholder cooperation. In smaller or less mature organizations the lines may overlap or be staffed by the same people, which can complicate the intended separation. A vCISO can help interpret and adapt the model to the organization's context, but the framework does not by itself assure compliance, certification, or specific security outcomes, and its effect depends on how well the organization implements and sustains the defined roles.

Common misconceptions

The three lines must be three separate teams or departments.
The model describes roles and responsibilities, not a mandatory org chart. In smaller organizations one person or function may carry responsibilities across lines, though independence of assurance activities should be preserved as far as practical. Where a vCISO supports second-line oversight, care is needed to avoid compromising the independence of any third-line assurance.
A virtual CISO placed in the second line becomes accountable for the organization's risk outcomes.
A vCISO typically advises, sets direction, and provides oversight support, but legal and organizational accountability generally remains with the governing body and senior management unless a contract explicitly states otherwise. The model reinforces that accountability sits with the governing body, not with an external advisory role.
The Three Lines Model is itself a compliance framework that guarantees a specific certification or regulatory outcome.
It is an organizing model for governance and risk roles, not a certification standard such as ISO 27001 or SOC 2. Applying it may support readiness and clearer accountability, but it does not by itself guarantee compliance, certification, or breach prevention, and its value depends on organizational maturity and stakeholder cooperation.

Best practices

Map existing security roles to first, second, and third line responsibilities before assuming new structures are needed, and document where responsibilities overlap in smaller organizations.
Clarify in the engagement scope which line a virtual CISO supports, typically second-line oversight and governance, and explicitly state what remains out of scope such as hands-on operational controls or independent audit.
Preserve the independence of third-line assurance by avoiding arrangements where the same party sets, operates, and audits the same controls.
Keep accountability for risk decisions with the governing body and senior management, and confirm this allocation in writing rather than assuming an advisor absorbs it.
Use the model to structure reporting relationships and escalation paths so risk information reaches the governing body clearly and consistently.
Revisit the allocation of responsibilities as organizational maturity, staffing, and stakeholder access change, since the effectiveness of the model depends on cooperation and defined scope.