ICAEW Registered Auditors  ·  90+ UK-Based Experts

The Three Lines of Defence Model — and Its 2020 Successor

AC
Acumon Chartered Accountants ·5 min read

The three lines of defence model is the standard way organisations organise risk management and assurance: management owns and controls risk (first line), risk and compliance functions oversee and challenge it (second line), and internal audit provides independent assurance over both (third line). It is how regulators expect financial firms to be built, how boards structure their assurance maps — and, since a 2020 overhaul by the Institute of Internal Auditors, officially called the Three Lines Model, with "defence" deliberately dropped from the name — a framework the IIA refreshed again in July 2026 with a new statement of position.

That rename was not cosmetic, and for UK boards the model has just acquired a sharper edge: from 2026, the Corporate Governance Code asks boards to declare, in the annual report, that their risk and control framework actually works. Suddenly the diagram everyone nodded at in training has to hold weight.

The three lines, properly understood

First line — management. The people who run the business own its risks and the controls over them: the finance team reconciling accounts, the operations manager enforcing safety procedures, the sales director approving credit terms. Risk-taking and risk management happen here, in the doing. Everything else in the model exists to support and verify this line, not substitute for it.

Second line — risk, compliance and specialist functions. Risk management, compliance, financial control, health and safety, information security: functions that set frameworks, monitor exposures, advise and challenge, but do not own the underlying business decisions. The second line's authority is expertise and escalation, and its classic failure mode is drift — either absorbed into management's reporting lines until challenge disappears, or so detached it produces frameworks nobody uses.

Third line — internal audit. Independent, objective assurance over the first two lines, reporting not to management but to the governing body, usually through an audit committee. Independence is the entire value: internal audit can assess whether the second line's monitoring works and whether the first line's controls exist outside the policy manual. Administrative reporting to the executive can coexist with that — what matters is the functional line to the governing body and the safeguards around it; internal audit answerable only to the people it audits has become a slightly awkward part of the first line.

Why the IIA rebuilt it in 2020

The original "three lines of defence" drew persistent criticism: it framed risk purely as a threat to be defended against, encouraged siloed thinking, and said almost nothing about governance. The 2020 Three Lines Model reframed it around six principles with the governing body placed explicitly at the top — accountable for oversight, appointing and overseeing internal audit, setting appetite. It also made the model principles-based rather than an org chart: the point is that the roles of ownership, oversight and independent assurance all exist and stay distinct, not that an organisation has three departments with particular names. Risk, in the current framing, is about achieving objectives — seizing opportunity as much as preventing loss.

The IIA's July 2026 statement of position — "Assurance and Advice in Support of Effective Governance" — replaces the 2020 paper and pushes the same direction further: assurance and advisory work treated as distinct but complementary, explicit emphasis on coordination and reliance across assurance providers (external ones included), and practical guidance for organisations without separate assurance functions. In practice, both updates legitimised what good organisations already did: collaboration across the lines, proportionate structures in smaller firms (where one person may wear a second-line hat part-time), and outsourced or co-sourced third lines where an in-house function makes no sense.

The UK regulatory reality

For FCA- and PRA-regulated firms, the model is embedded supervisory expectation. The systems-and-controls rules require clear apportionment of risk responsibilities, and the Senior Managers regime attaches named individuals to them — a supervisor reviewing a firm will ask, in effect, to be shown the three lines and who owns each. Weak second lines and absent third lines feature in a large share of enforcement narratives.

The newer development reaches beyond financial services — though not to every UK board. Provision 29 of the 2024 UK Corporate Governance Code applies to the listed companies that report against the Code, on its usual comply-or-explain basis, for financial years beginning on or after 1 January 2026: boards describe how they have monitored the risk management and internal control framework and declare its effectiveness over material controls as at the balance sheet date. The FRC prescribes no particular framework — but a declaration needs evidence, evidence needs an assurance map, and an assurance map is, in substance, the three lines thinking written down with names, scopes and outputs. Boards making their first declarations in 2027 annual reports are doing that mapping now — and the gaps it exposes (controls nobody tests, assurance nobody consolidates) are precisely the model's second and third lines missing in action.

Making it real in a mid-size organisation

The model scales down further than its banking origins suggest, if you hold onto the substance:

  • Write the assurance map. One page: key risks down the side; who owns each, who oversees it, who independently checks it. An empty third column means no independent assurance; a crowded row is a prompt to check whether the layers complement each other or duplicate cost — three well-designed entries can be exactly right.
  • Give the second line an escalation route. A compliance function that can only escalate to the person creating the exposure is decorative. Board or committee access, in the terms of reference, used at least occasionally.
  • Buy the third line rather than pretending. Most organisations below a few hundred staff cannot justify an internal audit department — but co-sourced and outsourced internal audit delivers the independence and reach at a fraction of a headcount, with specialist skills (IT, cyber, regulatory) borrowed per engagement.
  • Test the model annually. The question is not "do we have three lines" but "did anything reach the board this year through the second or third line that management would not have volunteered". A "no" is not proof of failure — but it is the right prompt to test coverage, objectivity and whether the escalation routes genuinely work.

Used honestly, the model is less a diagram than a discipline: decisions owned, oversight resourced, and someone independent allowed to say the uncomfortable thing to the people who govern. Organisations that have that survive surprises far better than their control manuals would predict.

Acumon builds and runs third-line functions for clients — internal audit, co-sourced and fully outsourced — alongside corporate governance and risk management support for boards facing Provision 29 for the first time. If your first effectiveness declaration is due in the next reporting cycle, the assurance-mapping work belongs in this year's plan, not next year's crisis.

Get in Touch

Ready for Accountants Who Move Your Business Forward?

Tell us what you need. Within one business day, a qualified accountant will be in touch to talk it through and give you a clear, fixed-fee quote — no obligation.

Visit us1-2 Craven Road, Ealing, London, W5 2UA

Speak to a Specialist

Fill this in and we'll come back to you within one business day.

No obligation. Your details stay private.
Call Now Get in Touch