Does the Three Lines Model Still Work? Accountability, Challenge and Decision Quality

Updated: 5 days ago

The Three Lines Model (formerly known as 3LoD) remains one of the most widely recognised approaches to organising risk management, oversight and assurance. Its underlying logic is straightforward: management owns and manages risk, specialist functions provide expertise and challenge, and Internal Audit provides independent assurance.
Yet the model continues to attract criticism when governance fails.
The problem is often attributed to the structure itself. In practice, many of the weaknesses associated with Three Lines arise from how organisations implement it. Accountability becomes blurred. Risk and Compliance accumulate responsibilities that belong with management. Specialist oversight functions multiply including through so-called 1.5 lines. Assurance operates at a distance from emerging decisions. Information moves vertically through individual functions while important connections across the organisation remain difficult to see.
Our recent polling illustrates the challenge. When asked about their biggest question concerning the Three Lines Model, only 17% selected role clarity. Practical implementation was the leading concern at 32%, followed by integration at 27% and accountability at 24%.
This points to a more useful question than whether the Three Lines Model still works.
Do the Three Lines operate as complementary governance roles that improve organisational decision-making, or have they become three organisational silos?
This article revisits the model through that lens. It examines where implementation breaks down, why management accountability must not be delegated to Risk, how independence can coexist with connectivity, and why decision quality should ultimately be the test of whether the Three Lines are working effectively.
Executive Takeaways
For readers scanning rather than reading in full, five governing insights frame the argument:
The Three Lines Model remains relevant when it creates clear accountability rather than organisational boundaries.
The model provides a valuable distinction between management responsibility, specialist expertise and challenge, and independent assurance. Its effectiveness depends on whether those roles reinforce accountability and informed decision-making rather than becoming separate governance silos.
Management accountability for risk cannot be delegated to Risk or Compliance.
Risk is inherent in decisions about strategy, customers, products, technology, outsourcing and organisational change. Second-line involvement can strengthen those decisions through expertise, monitoring and challenge, while accountability for managing the associated risks remains with the management making them.
Effective second-line functions strengthen decisions rather than accumulate ownership.
Risk and Compliance create greater value when they help management understand uncertainty, test assumptions and evaluate trade-offs while choices remain open. As specialist oversight functions multiply, clear responsibilities and effective coordination become increasingly important to prevent duplicated activity, fragmented perspectives and dependency on the second line.
Independence and connectivity are both essential to effective challenge and assurance.
Risk, Compliance and Internal Audit need sufficient independence to form their own views, challenge management and escalate concerns. Independence does not require isolation. Relevant information, emerging signals and assurance insights must connect across the Three Lines while preserving distinct responsibilities for ownership, challenge and assurance.
The ultimate test of the Three Lines Model is the quality of the decisions it enables.
Risk assessments, controls, monitoring, governance forums and assurance activity provide important mechanisms for managing risk. Their value increases when they help leaders recognise material exposure, understand trade-offs, challenge assumptions, escalate concerns and learn from experience. Connected governance strengthens these relationships by connecting information, accountability and decision-making across organisational boundaries.
The Three Lines Model does not need more lines. It needs clearer accountability and stronger connections between them.
The Three Lines Model Is Not the Problem
The Three Lines Model has become an easy target when risk governance fails. Questions are raised about role clarity, duplication, excessive oversight and whether three distinct lines remain appropriate for increasingly complex organisations.
Yet many of these weaknesses say more about how organisations have implemented the model than about the model itself.
The Three Lines Model establishes an important governance principle:
management retains responsibility for achieving objectives and managing the risks associated with its decisions, specialist functions provide expertise and challenge, and Internal Audit provides independent assurance. The value comes from combining these different contributions around organisational objectives.
Problems emerge when organisations translate these roles into organisational boundaries rather than governance relationships.
The first line can gradually become dependent on Risk and Compliance to determine what constitutes an acceptable risk decision. We work with organisations where the level of business self identification of risks and issues is well below 50% for the most important issues. Then, the second line can accumulate processes, controls and approvals that bring it closer to managing the risks it is expected to oversee. For example, we came across situations where the risk function was approving - and the sole approver - of risk acceptance. Internal Audit can remain independent while becoming too distant from the information and decisions shaping emerging risk. It also typically gets involved in control testing and policy assurance, than should sit with both business and risk.
The individual roles may still exist. The governance system connecting them becomes weaker.
Recent Aevitium polling points towards this implementation challenge. When professionals were asked about their biggest question concerning the Three Lines Model:
32% identified practical implementation
27% identified integration
24% identified accountability
17% identified role clarity
The significance of those results extends beyond uncertainty about job descriptions. The challenge increasingly sits in the space between the lines:
how responsibilities connect, how information travels, how challenge influences decisions and how accountability remains clear throughout.
This becomes particularly important as organisations add specialist functions to address cyber risk, operational resilience, financial crime, data, privacy, third-party risk and other areas of expertise. Each function can perform its mandate effectively while the organisation accumulates overlapping assessments, competing priorities and multiple views of the same exposure.
More oversight does not automatically produce better oversight.
The Three Lines Model works when differentiation of roles creates better governance rather than organisational separation. Management needs to remain accountable for its decisions. Second-line functions need enough proximity to understand and challenge those decisions without assuming ownership of them. Internal Audit needs independence alongside sufficient organisational awareness to identify patterns that matter.
The implementation question is therefore deeper than deciding where Risk, Compliance or Internal Audit sit on an organisational chart. It is about designing the relationships between ownership, challenge and assurance so that each strengthens the quality of organisational decision-making.
That is where the continuing relevance of the Three Lines Model should be judged.
What the Three Lines Model Actually Means
The terminology matters because the model itself has evolved.
The Institute of Internal Auditors (IIA) moved away from the “Three Lines of Defense” terminology when it introduced the Three Lines Model. The change reflected a broader conception of governance. The model is concerned with how organisations create and protect value through effective governance, risk management and control, rather than positioning risk functions primarily as successive layers of defence. It provides a structure for understanding how risk management responsibilities, oversight and assurance contribute to effective governance.
At its core, the model brings together several distinct contributions to governance:
The governing body is accountable to stakeholders for organisational oversight. It sets direction, establishes appropriate governance structures and delegates responsibility to management while retaining oversight.
First-line roles are closest to the delivery of products and services. Management leads and directs actions, including managing the risks associated with achieving organisational objectives.
Second-line roles provide complementary expertise, support, monitoring and challenge on risk-related matters. Their contribution can include developing frameworks, monitoring risk exposures, supporting effective risk management and challenging how risks are understood and managed.
Third-line roles, principally the Internal Audit function, provides independent and objective assurance and advice on the adequacy and effectiveness of governance, risk management and internal controls. Its organisational independence enables it to provide the governing body with a perspective distinct from management and second-line oversight.

This distinction is important because the model is sometimes reduced to a simple organisational formula: the business is the first line, Risk and Compliance are the second, and Internal Audit is the third.
That interpretation can make the model appear much more rigid than it is.
The lines describe roles and relationships, not departments
The Three Lines Model is fundamentally about accountability, contribution and relationships, rather than requiring every organisation to divide itself neatly into three groups of departments.
A single organisational function may contain different responsibilities, and the allocation of second-line activities can vary according to the organisation's size, complexity, regulatory environment and operating model. What matters is clarity over the nature of the role being performed and the accountability attached to it.
This becomes particularly relevant as organisations develop specialist capabilities across areas such as operational resilience, cyber security, data, privacy, financial crime, conduct and third-party risk. Simply assigning each specialist team to a particular “line” does little to explain how the overall governance system should operate.
The more useful question is what role that function performs in relation to a particular decision, risk or objective.
Does it own and manage the activity? Does it provide expertise and challenge to those responsible for it? Does it provide independent assurance over how effectively the organisation is managing it?
These distinctions preserve something fundamental within the model: different governance roles need different degrees of independence from the activities they assess.
Second-line independence supports credible challenge while allowing close engagement with management. Third-line independence is different in nature and provides the governing body with assurance that is independent from management responsibilities.
Separation needs connection
Clear distinctions between the lines support accountability. Their value depends equally on the relationships connecting them.
Management needs specialist insight to understand the implications of its decisions. Second-line functions need access to business information and sufficient organisational context to provide meaningful challenge. Internal Audit needs visibility across the organisation to form an independent view of whether governance and risk management are operating effectively.
The Three Lines Model therefore provides a governance architecture for ownership, challenge and assurance. It does not prescribe three organisational silos.
That distinction becomes critical when assessing whether the model works in practice. An organisation can assign every function to the correct line and document every responsibility while still producing fragmented information, duplicated oversight and unclear decision accountability.
The strength of the model comes from preserving distinct roles while ensuring they operate as part of the same governance system.
Regulatory Case Study: MS Amlin and the Consequences of Fragmented Governance
The PRA's 2022 enforcement against MS Amlin Underwriting Limited provides a useful example of how weaknesses in the Three Lines can form part of a much broader governance failure.
The insurer was fined £9.695 million for failings between 2014 and 2019 relating to the governance and oversight of underwriting, underwriting controls, management information, data quality, and risk management strategies and systems. Without the 30% settlement discount, the penalty would have been £13.85 million.
The PRA identified interconnected weaknesses across the organisation, including:
Risk culture: the firm had failed to embed a strong or effective risk culture.
First and second-line accountability: responsibilities were not clearly delineated, creating blurred roles and confusion over who was accountable for actively managing risk.
Risk mitigation: identified weaknesses in areas including business planning, data quality controls, technical pricing and monitoring were not addressed sufficiently effectively or promptly.
Governance and decision-making: the governance structure was fragmented across committees and functions, with unclear responsibilities and weaknesses in effective challenge, management and decision-making.
Board information: management information was not consistently adequate or available to provide a reliable basis for Board discussions and decisions.
Data and controls: weaknesses existed in the firm's data repository, data quality controls and underwriting controls.
Remediation: weaknesses identified by the PRA were not addressed effectively and in a timely manner.
The PRA concluded that these failings breached Fundamental Rule 5, requiring effective risk strategies and risk management systems, and Fundamental Rule 6, requiring firms to organise and control their affairs responsibly and effectively.
The significance of the case for the Three Lines Model lies in how these weaknesses interacted. This was not simply a failure to define where the first line ended and the second line began. Accountability, governance, information, controls, risk mitigation and remediation were all affected.
It illustrates a central argument of this article: an organisation can establish formal risk functions, committees and controls while the governance system connecting them remains ineffective. Clearer lines alone would not have resolved all of these weaknesses. Effective implementation also requires information to reach decision-makers, challenge to influence decisions, identified weaknesses to trigger action and accountability to remain clear across organisational boundaries.
The Three Lines can exist on an organisational chart while the governance system connecting them fails in practice.
Why Simple Principles Become Complex in Practice
At its core, the Three Lines Model reflects a relatively simple governance principle: responsibilities for managing activities, providing oversight and challenge, and delivering independent assurance should remain sufficiently distinct.
Yet applying that principle proportionately becomes harder as organisations grow.
Few organisations deliberately design an overly complicated risk governance structure. Complexity tends to accumulate gradually as the organisation responds to legitimate needs. Regulatory requirements introduce new expertise and oversight, incidents lead to stronger controls, findings generate additional scrutiny, and growth creates new risks and dependencies that require specialist attention. Each response may be proportionate when considered individually, yet over time their cumulative effect can create overlapping responsibilities, additional governance processes and greater distance between those making decisions and those overseeing them.
With that, the problem is rarely one individual governance decision. It is the accumulated effect of many individually reasonable decisions on the clarity of the overall system.
Each response can be individually reasonable. Collectively, they can gradually change how accountability operates.
Several forces contribute to this.
Specialisation fragments responsibility. As organisations develop specialist functions across Compliance, Cyber, Operational Resilience, Data, Conduct, Financial Crime and Third-Party Risk, more people acquire legitimate interests in the same decision. Expertise increases, while responsibility can become harder to locate.
Control responses accumulate faster than they simplify. When something goes wrong, organisations are generally better at adding controls, approvals and oversight than removing those that no longer add sufficient value. Over time, proportionality can give way to accumulated governance activity.
Challenge can gradually become approval. Management seeks certainty from specialist functions, while Risk and Compliance seek greater influence over potentially significant exposures. Review becomes sign-off, sign-off becomes approval and second-line involvement can eventually be interpreted as shared ownership.
Accountability encourages defensive governance. Where individuals face significant personal or regulatory accountability, additional evidence, consultation and approval can feel safer than relying on clearly delegated decision rights. The result can be more governance without necessarily producing better decisions.
Organisational structures reinforce functional boundaries. Reporting lines, objectives, budgets, systems and committees are typically organised vertically. The Three Lines can therefore become institutionalised as separate functions even though the model describes roles and relationships.
Human behaviour can blur otherwise clear responsibilities. The Three Lines Model assumes that people will exercise distinct roles in practice, but incentives often pull them in another direction. Managers may seek Risk approval because it provides reassurance or distributes responsibility. Second-line professionals may become more involved because they fear being held accountable for risks they identified but did not prevent. Following incidents or regulatory scrutiny, leaders may add approvals because visible intervention feels safer. These behaviours are understandable individually, but collectively they can turn challenge into approval, oversight into involvement and management accountability into shared ambiguity.
Organisational politics can reshape the model around functions rather than responsibilities. Governance structures also create influence, status, resources and career opportunities. Functions can expand their mandates, leaders can protect organisational territory, and specialist teams can build parallel governance processes to demonstrate control or relevance. These dynamics become particularly visible in so-called 1.5-line functions. When people move from second-line roles into first-line risk or control teams, they can bring the practices and mindset of independent oversight with them. Instead of helping management embed risk management into business decisions and processes, the new function may recreate second-line monitoring, challenge, assessment and reporting inside the first line. The organisation then gains another layer of oversight while responsibility for actually managing risk becomes even less clear.
These dynamics help explain why Three Lines structures tend to expand rather than simplify. Governance is shaped by more than regulatory requirements and organisational design. It is also shaped by how people interpret their roles, protect themselves, exercise influence and respond to previous failures. Once teams, committees, reporting processes and control activities become established, removing or redefining them can also mean challenging existing mandates, budgets and organisational status.
Then, this also explain another apparent paradox. The more organisations invest in risk management, control and specialist oversight, the easier it can become to obscure the simple segregation of responsibilities on which the model depends.
The objective should therefore be proportionality rather than structural purity. Organisations need enough separation to preserve accountability, credible challenge and independent assurance, while maintaining sufficient connectivity for expertise and information to influence decisions.
Effective implementation requires organisations to resist the accumulation of governance complexity that gradually turns clear roles into blurred accountability.
Accountability Cannot Be Delegated to Risk
Risk is inherent in decisions across the organisation. A new product, outsourcing arrangement, technology investment, customer proposition or strategic change all involve choices about uncertainty, trade-offs and acceptable exposure.
The people making those decisions remain accountable for managing the associated risks.
This is where the Three Lines Model can become distorted in practice. Risk and Compliance functions may become increasingly involved in reviewing, approving or shaping business decisions. Over time, management can begin to treat second-line involvement as a transfer of responsibility: Risk approved it, Compliance signed it off, or the relevant committee accepted it.
That weakens accountability.
The second line has an important role in providing expertise, establishing frameworks, monitoring exposure and challenging assumptions. Challenge should strengthen management decisions rather than replace them.
This distinction also matters when difficult trade-offs arise. Risk functions can assess exposure, challenge whether assumptions are credible and escalate concerns. Management must ultimately decide how to pursue its objectives within the organisation's governance and risk appetite.
Risk is inherent in everybody's decisions, but accountability for managing it must remain clear.
Where Three Lines Breaks Down in Practice
The Three Lines Model becomes less effective when organisations focus on defining individual responsibilities without giving equal attention to how those responsibilities connect in practice.
Aevitium's polling provides a useful indication of where the pressure sits. Practical implementation and integration accounted for 59% of responses when professionals were asked about their biggest question concerning the Three Lines Model. Accountability accounted for a further 24%.
These challenges often reinforce one another.
Second-line functions can gradually become owners of risk processes, assessments and reporting that management increasingly relies upon. First-line teams may then look to Risk or Compliance for decisions that sit within their own accountability. As specialist oversight functions develop across cyber, resilience, conduct, data, financial crime and third-party risk, management can also face multiple assessments, controls and reporting requirements addressing different dimensions of the same underlying activity.
More risk activity can create more fragmentation rather than greater organisational awareness.
This can manifest through:
Unclear decision rights, particularly where challenge, approval and risk acceptance become difficult to distinguish.
First-line dependency, with Risk increasingly relied upon to interpret exposures or determine acceptable action.
Second-line process ownership, reducing the distinction between managing risk and providing oversight and challenge.
Fragmented specialist oversight, creating separate views of exposures that interact at enterprise level.
Duplicated controls, assessments and reporting, increasing governance activity without necessarily improving insight.
Weak integration across the Three Lines, limiting the organisation's ability to connect emerging signals and identify broader patterns.
The third line can encounter the consequences later. Independent assurance may identify recurring weaknesses, control failures or governance gaps after the underlying decisions have already been made. Its greater contribution comes when those findings feed back into organisational learning, influencing how management and second-line functions approach similar decisions in future.
The issue is therefore rarely one isolated failure within one line. Weakness accumulates through the relationships between ownership, challenge and assurance.
A Three Lines Model can look complete on an organisational chart while producing a fragmented governance experience in practice. Its effectiveness depends on whether those different perspectives ultimately converge around the decisions and risks that matter.

The Second Line as an Enabler
Addressing these weaknesses does not require Risk and Compliance to become less influential. It requires greater clarity about where that influence creates value.
Second-line functions are most effective when they help management understand uncertainty, evaluate trade-offs and take risk within clearly understood boundaries. Their role extends beyond risk reduction or process compliance towards providing the expertise and challenge that support informed risk-taking.
That requires second-line functions to:
Bring relevant expertise into decisions while choices remain open.
Challenge assumptions and trade-offs without assuming management accountability.
Connect risk perspectives where specialist oversight has become fragmented.
Simplify governance activity where multiple assessments, controls and reporting processes create duplication.
Strengthen risk awareness by helping management understand how everyday decisions affect organisational objectives and exposure.
Shared involvement should never become shared ambiguity. Many people may contribute expertise, challenge and assurance to a decision, but that does not dilute management's accountability for making it and managing the associated risk.
This changes the emphasis from Risk and Compliance acting as gatekeepers of acceptable activity towards functions that strengthen the organisation's capacity to make informed decisions.
An effective second line does not take risk on management's behalf. It helps management take risk with greater awareness, transparency and discipline.
Independence Does Not Require Isolation
Independence is fundamental to effective risk oversight and assurance. It gives Risk, Compliance and Internal Audit the authority to form their own views, challenge management and escalate concerns when necessary.
Independence, however, does not require organisational distance.
Effective challenge depends on context. Second-line functions need to understand the decisions being considered, the commercial and operational constraints involved, and how different risks interact. Engagement with management provides that understanding and allows challenge to influence decisions while options remain open.
Internal Audit requires a greater degree of independence from management responsibilities. That independence can coexist with strong organisational connectivity. Access to information, engagement with management and awareness of emerging issues strengthen Internal Audit's ability to identify patterns and provide relevant assurance.
Problems arise when independence is interpreted as separation. Risk functions can become involved too late to influence decisions. Assurance can focus on whether established processes were followed rather than providing insight into the governance conditions that produced the outcome.
The opposite creates its own governance weakness. Excessive involvement can blur the distinction between making a decision, challenging it and providing assurance over it.
The objective is connected governance without blurred accountability. Management owns decisions. The second line brings expertise and challenge. The third line provides independent assurance. Effective relationships between them allow each role to contribute at the point where it adds the greatest value.
Independence protects the quality of challenge. Connection makes that challenge useful.
The Real Test Is Decision Quality
The effectiveness of the Three Lines Model can easily become measured through activity. Risk assessments are completed, controls are tested, committees meet, reports are produced and audits are delivered.
These activities matter. Their value ultimately depends on whether they improve the decisions the organisation makes.
A stronger test considers what happens around the decision itself:
Does management understand the trade-offs, including the risks created, accepted or transferred by its chosen course of action?
Does challenge arrive while choices remain open, allowing alternative perspectives to influence the decision?
Are weak signals connected across functions, enabling patterns to emerge from information that may appear insignificant in isolation?
Can concerns escalate effectively when they exceed local authority or require a broader organisational response?
Does assurance create organisational learning, influencing how similar decisions are approached in future?
This shifts attention from the volume of risk activity towards its contribution to decision quality.
It also creates a different perspective on the Three Lines. The first line brings knowledge of the decision and its operational context. The second line adds specialist expertise, challenge and a wider view of exposure. The third line provides independent insight into whether governance and risk management are working as intended and where lessons need to be carried forward.
The value of the Three Lines Model is realised when these different perspectives improve decisions before, during and after they are made.
Decisions Depend on the Assumptions Behind Them
Governance structures can provide clear accountability, relevant information and effective challenge while decision quality still depends on the assumptions leaders bring to the decision.
Processes are often designed around expected conditions, typical customers and established operating scenarios. The resulting decisions may appear reasonable within those assumptions while giving insufficient consideration to less visible customers, dependencies or operating conditions.
This is another reason the contribution of the Three Lines should extend beyond process compliance. Effective challenge should test the assumptions underlying a decision, including whose experience has been considered, which dependencies may have been overlooked and how the decision performs outside expected conditions.
The objective is stronger organisational judgement. Management retains accountability for the decision, while effective challenge helps reveal consequences that may not be visible from the decision-maker's immediate perspective.
From Three Lines to Connected Governance
The Three Lines Model clarifies important relationships between management, oversight and independent assurance. Those relationships operate within a much wider organisational system.
As organisations become more specialised, information, expertise and accountability are distributed across functions, governance forums and organisational boundaries. The Three Lines experience the same challenge. Each can perform its individual role effectively while the organisation still struggles to develop a coherent enterprise view.
Connected governance addresses the connections between them.
Aevitium's Governance Connectivity Model identifies three capabilities that are particularly relevant:
Information Connectivity ensures relevant risk information, emerging signals and assurance insights move beyond the function or governance forum where they originate.
Accountability Connectivity maintains clear ownership as decisions, risks and outcomes cross functional and Three Lines boundaries.
Decision Connectivity brings together the information, expertise, challenge and authority required when decisions have wider organisational implications.

These capabilities allow the Three Lines to contribute to enterprise awareness while preserving their distinct roles.
Board oversight, risk appetite, management information, escalation, issues management and assurance remain important governance mechanisms. Their contribution increases when information and decisions connect effectively across them. An issue identified through assurance can inform risk assessment.
Emerging risk information can influence management decisions. Escalation can transfer decision authority when an issue extends beyond an individual's mandate.
This is the relationship between the two concepts.
Connected governance does not replace the Three Lines Model or add another layer to it. It strengthens the connections that allow its distinct roles to operate as part of one enterprise system.
The Board Creates the Conditions for Three Lines to Work
The Three Lines Model ultimately operates within the governance environment established by the Board and senior leadership.
The governing body sets direction, establishes expectations for risk-taking and oversees whether management is delivering against the organisation's objectives. It also determines whether accountability is sufficiently clear, whether governance arrangements provide effective challenge and whether the organisation has the capabilities and resources required to operate within its risk appetite.
This matters because many weaknesses attributed to the Three Lines cannot be resolved by Risk, Compliance or Internal Audit alone. Unclear decision rights, conflicting incentives, insufficient resources and weak responses to challenge are governance conditions that shape how effectively each line can perform its role.
Board oversight should therefore look beyond whether the Three Lines exist and whether their respective frameworks and committees are operating. It should consider whether the system is producing the outcomes it was designed to support: clear accountability, credible challenge, effective escalation, organisational learning and better decisions.
The Board does not manage the Three Lines. It creates and oversees the conditions in which they can work effectively.
Five Questions Board Directors Should Ask About the Three Lines Model
1. Is accountability for managing risk genuinely clear?
The Board should understand whether management remains accountable for the risks arising from its decisions, or whether responsibility has gradually shifted towards Risk, Compliance or other specialist functions. Extensive second-line involvement should strengthen management accountability rather than obscure who ultimately owns the decision and its consequences.
2. Does second-line challenge improve decisions while choices are still open?
Risk and Compliance create greater value when their expertise and challenge can influence decisions before commitments become difficult to reverse. Directors should consider whether second-line functions are sufficiently connected to understand the context and trade-offs involved, while retaining the independence required to provide credible challenge.
3. Are specialist risk and oversight functions creating a connected view of exposure?
Organisations may have extensive expertise across risk, compliance, cyber, resilience, conduct, data, financial crime and third-party risk. Boards should consider whether these perspectives connect effectively enough to reveal cumulative exposures, dependencies and emerging patterns, rather than producing multiple assessments of the organisation through separate functional lenses.
4. Does independent assurance strengthen organisational learning?
Internal Audit provides independent assurance over governance and risk management, but its contribution should extend beyond identifying whether individual controls and processes operated as expected. Directors should consider whether assurance findings are connected to recurring weaknesses, management decisions and wider patterns so that lessons influence how the organisation operates in the future.
5. Are the Three Lines collectively improving the quality of important decisions?
This is ultimately the test that matters. Boards should look beyond the volume of risk assessments, committee papers, controls, monitoring and assurance activity and consider whether the Three Lines help decision-makers understand uncertainty, challenge assumptions, recognise trade-offs, escalate concerns and make better-informed decisions.
The Board's objective is not to make the Three Lines more active. It is to ensure that distinct roles in management, challenge and assurance operate as one effective governance system, with clear accountability and sufficient connectivity to support better decisions.
Conclusion: So, Does the Three Lines Model Still Work?
Yes. Its continuing value comes from the clarity it can create around ownership, challenge and assurance.
The more important question is how effectively those roles operate together.
The model becomes weaker when the Three Lines harden into organisational boundaries. Management looks to Risk for decisions. Second-line functions accumulate ownership of processes they are expected to oversee. Independent assurance identifies recurring weaknesses without those insights consistently shaping future decisions. Each line can remain active while the governance system connecting them becomes fragmented.
Effective implementation produces a different outcome. Management owns decisions and their associated risks. The second line brings expertise, perspective and credible challenge. The third line provides independent assurance. Information and insight move between them without diluting those distinct accountabilities.
This is why the future of the Three Lines Model depends less on redesigning the lines and more on strengthening the relationships between them.
As organisations become more complex and specialised, that connectivity becomes increasingly important. Risk rarely respects functional boundaries, and neither should the information, challenge and organisational learning required to understand it.
The Three Lines Model remains relevant when three distinct roles contribute to one connected governance system.
About the Author: Julien Haye
Managing Director of Aevitium LTD and former Chief Risk Officer with over 26 years of experience in global financial services and non-profit organisations. Known for his pragmatic, people-first approach, Julien specialises in transforming risk and compliance into strategic enablers. He is the author of The Risk Within: Cultivating Psychological Safety for Strategic Decision-Making and hosts the RiskMasters podcast, where he shares insights from risk leaders and change makers.
Frequently Asked Questions
Is the Three Lines Model mandatory for regulated firms?
The Three Lines Model is a widely recognised governance model rather than a universal regulatory requirement in itself. Regulatory expectations vary by jurisdiction and sector, but regulated firms are commonly expected to demonstrate clear management accountability, effective risk oversight, appropriate independence and credible assurance. The Three Lines Model can provide a useful structure for achieving those outcomes when applied proportionately.
Can smaller organisations use the Three Lines Model?
Yes. The Three Lines describe roles and relationships rather than requiring three separate teams or functions. In smaller organisations, individuals may perform multiple responsibilities, provided potential conflicts are understood and appropriate independence is maintained where necessary. The structure should reflect the organisation's size, complexity and risk profile.
Can the same person perform first-line and second-line responsibilities?
Potentially, particularly in smaller or less complex organisations, but the allocation requires careful consideration. Combining responsibilities can create conflicts where someone is expected both to manage an activity and independently challenge how its risks are being managed. Governance should make clear which role is being performed, where independent challenge is required and how conflicts are addressed.
Where do specialist functions such as Cyber, Operational Resilience and Data Risk sit within the Three Lines?
Their position depends on the responsibilities they perform rather than their function name. A cyber team managing security operations may perform first-line responsibilities, while a specialist technology risk function providing independent monitoring and challenge may perform second-line responsibilities. Organisations should therefore map responsibilities according to ownership, expertise and challenge, and assurance, rather than automatically assigning whole functions to a particular line.
How should the Three Lines Model change as an organisation grows?
Growth often increases specialisation, dependencies and the number of people involved in governance. Organisations should periodically reassess whether responsibilities remain clear, whether new specialist functions have created overlaps or gaps, and whether information and challenge still reach the people making important decisions. Scaling the Three Lines effectively therefore involves strengthening governance connectivity as well as adding capability.
.png)