The three lines model exists to answer a question every board eventually asks: who exactly does what about risk. It separates three roles: management owns and manages risk, specialist risk and compliance functions support and challenge, and internal audit provides independent assurance. Without this separation, organisations get gaps that nobody covers and controls that three teams duplicate. For the board, the model is a map showing where each piece of comfort comes from.
The model is anchored in the risk management policy, function charters and often a RACI matrix over key risk activities. Applied to continuity: service owners in the first line write and maintain their plans, the BCM or risk function in the second line sets the method, coordinates exercises and challenges quality, and internal audit periodically reviews whether the whole programme works. Each line reports upward through its own route, which is what makes the picture trustworthy. The IIA restated the model in 2020, stressing collaboration across the lines rather than walls between them.
The classic distortion is turning the second line into police, so the first line hides problems instead of raising them, or the opposite, first-line managers deciding that risk belongs to the risk department. Both defeat the purpose: risk stays with those who run the business, and the second line exists to make their job easier and their claims testable. Another error is letting internal audit design the controls it will later audit. The assurance logic behind the model is examined in ERGP module M6, on assurance.
This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.
Explore the ERGP programme