Three Lines. One Board. Fewer Places to Hide.
What the IIA’s updated Three Lines Model actually means
One point first.
This is not new legislation.
It is a 2026 Statement of Position from The Institute of Internal Auditors. It offers professional guidance that organisations can adapt to their size, risks and circumstances.
It may influence governance arrangements. It does not become law simply because it arrives in a serious-looking PDF.
Make it stand out
The board should not rely only on management saying, “Everything is fine.”
It needs three views:
Management runs the organisation and manages its risks and controls.
Risk and compliance monitor, support and challenge management.
Internal audit provides an independent view of the whole organisation.
A confident answer is not assurance. The board needs evidence from different sources.
The central idea
Boards need reliable information to make good decisions.
They cannot inspect every control, investigate every incident or attend every management meeting. They must rely on information provided by others.
But asking management, “Is everything under control?” and receiving a confident nod is not assurance. It is a conversation.
The Three Lines Model gives the board three different perspectives.
Make it stand out
The image shows how management, specialist functions and internal audit provide three different but complementary views, giving the board a clearer and more reliable picture of the organisation.
LineWho?What do they do?
First lineOperational managementRuns the organisation, owns risks and operates controls.Second lineRisk, compliance, security, quality and other specialist functionsSupports management, monitors risks and provides challenge.Third lineInternal auditProvides independent assurance and objective advice across the organisation.
The lines are different for a reason.
The first line knows the operation because it runs it. The second brings specialist knowledge and challenge. The third stands further back and considers whether the whole system can be trusted.
None sees the complete picture alone.
Five principles behind the model
The updated model sets out five principles. Together, they explain how assurance and advice support good governance.
1. The board sets the direction
The board defines the organisation’s purpose, risk appetite and expectations. It also oversees the pursuit of its strategic objectives.
Risk management cannot work without direction. Before asking how much risk the organisation faces, someone must decide how much it is prepared to accept—and why.
Otherwise, risk appetite becomes an attractive document looking for a decision.
2. Oversight requires reliable information
The board needs balanced information about performance, risks and controls.
The word balanced matters.
A report containing only good news may be pleasant to read. It is less useful for governing an organisation. Boards need to know what works, what does not and where management is relying more on hope than evidence.
Good oversight begins with an honest picture.
3. Accountability must be clear
The board and senior management must define roles and responsibilities.
Who owns the risk? Who operates the control? Who monitors it? Who challenges the result? Who provides independent assurance?
These are simple questions. They often produce surprisingly complicated answers.
If everybody is responsible, experience suggests that nobody will be available when something goes wrong.
4. Different sources of assurance build confidence
The board should receive assurance from different parts of the organisation, including an independent source such as internal audit.
This helps the board judge whether governance, risk management, compliance and control processes are working as intended. It also helps confirm whether the organisation is achieving its objectives and correcting weaknesses promptly.
Management can provide assurance over its own activities. Specialist functions can examine their areas more closely. Independent assurance adds something different: distance from the decisions and processes under review.
Distance does not guarantee wisdom. It does make an honest conclusion easier.
5. Advice complements assurance
Assurance asks: Is this working?
Advice asks: How could it work better?
Advisory services offer insights, perspectives and options. They can help management recognise emerging risks, improve processes and make better decisions.
Internal audit can advise as well as assure. But it must not cross a simple line. Advising management is not the same as becoming management.
The auditor may help read the map. Management still chooses the road.
Make it stand out
The image turns the model’s five principles into five practical questions.
Where are we going? Do we have balanced facts, including the inconvenient ones? Who owns the risk and the control? Is the board receiving different sources of assurance, including an independent view? And is internal audit advising management without quietly becoming management?
The symbols make the distinction clear. The compass represents direction. The scales represent balanced information. The key represents accountability. The different lenses represent assurance from several sources. The map and wheel show the boundary between advice and responsibility.
Assurance asks, “Is it working?” Advice asks, “How could it work better?” Internal audit may help read the map. Management still holds the wheel.
What else does the updated model emphasise?
Assurance and advice both matter
Assurance provides confidence. Advice supports improvement.
They are different, but they are not rivals. An organisation needs to understand whether its arrangements work today and how they may need to change tomorrow.
Independence does not mean isolation
Internal audit must remain independent. It must also communicate.
It should work with management, risk, compliance and other assurance providers. It should share relevant information, coordinate its work and understand what others are seeing.
Independence means being free to reach an honest conclusion. It does not mean avoiding everyone until the final report appears.
Internal audit can help coordinate assurance
Internal audit has an organisation-wide view and direct access to the board. This puts it in a useful position to coordinate with other assurance providers.
It can help identify duplicated work, conflicting messages and risks receiving little or no attention. It may also support assurance mapping, coordinated planning and integrated reporting.
But coordination is not ownership. Internal audit should not take responsibility for second-line activities simply because it can see across them.
Roles may overlap
Not every organisation needs—or can afford—three completely separate teams.
Roles may be combined, particularly in smaller organisations. The model allows flexibility. It does not excuse confusion.
Responsibilities should be clear. Overlaps should be disclosed. Safeguards should protect objectivity. The board should know who is doing what and whose work can genuinely be considered independent.
Outsourcing does not remove accountability
An organisation may outsource risk, compliance or internal audit work.
It cannot outsource accountability.
The board and management remain responsible for ensuring the work is appropriate, properly resourced and effective. A supplier may perform the activity. The organisation still owns the consequences.
Internal audit must not audit its own decisions
Assurance is difficult to trust when people review processes they designed, decisions they made or controls they operated.
Where someone previously managed an activity, the IIA indicates that a separation of at least 12 months will typically help protect objectivity before that person provides assurance over it.
Time helps. Proper reporting lines and independent review help too. Memory is not the only threat to objectivity.
What should the board do?
The board should:
set the organisation’s purpose, strategy and risk appetite;
define clear roles and responsibilities;
demand reliable and balanced information;
protect internal audit’s independence;
ensure important risks receive appropriate assurance; and
approve any unusual or expanded responsibilities given to internal audit.
The board does not need to perform the work. It does need to know that the right work is being done by the right people.
What should management do?
Management remains responsible for:
achieving the organisation’s objectives;
owning and managing risks;
designing and operating controls;
identifying and correcting weaknesses; and
providing honest information to the board.
Risk and compliance can support, monitor and challenge management. They cannot manage its responsibilities on its behalf.
A second line does not relieve the first line of ownership. It simply makes weak excuses harder to maintain.
What should internal audit do?
Internal audit should:
report functionally to the board;
determine its scope, methods and conclusions without interference;
have unrestricted access to people, systems and information;
have sufficient resources and expertise;
provide independent assurance and objective advice;
coordinate with other assurance providers where appropriate; and
avoid management responsibility and self-review.
Internal audit’s value does not come from knowing more about every process than management. It comes from examining the evidence, connecting the pieces and speaking honestly to the board.
The message in one sentence
Management manages. Specialists support and challenge. Internal audit independently tells the board whether the whole system can be trusted.
Source: IIA — Assurance and Advice in Support of Effective Governance, 2026.
Appendix: The Three Lines Model: 2024 → 2026
Make it stand out
The structure has not changed. There are still three lines. What has changed is the emphasis.
The 2024 model was mainly a governance map. It explained who was responsible for what. The 2026 update focuses more clearly on how assurance and advice help the board make better decisions.
All three lines now contribute assurance and advice, although with different levels of objectivity. The first line brings operational knowledge. The second provides specialist support, monitoring and challenge. Internal audit provides the independent, organisation-wide view.
Internal audit’s role is also stronger. It is described as the ultimate internal assurance provider and may help coordinate and integrate assurance across the organisation.
Coordination becomes more practical too. The new model introduces assurance maps, shared risk information, coordinated planning and integrated assurance. It also recognises that roles may overlap, provided clear safeguards protect independence and objectivity.
The foundations remain the same: the first line owns risk, the second supports and challenges, the third assures independently, and the board remains accountable.
The lines have not moved. Their purpose has become clearer.

