Who Owns Risk Under the Three Lines Model
Three groups will each tell you, confidently, that one of the others has it.
The model was written to settle exactly this argument, and in a bank it mostly does. On a major capital program it settles less than people expect, because the dispute is rarely about who is accountable for the risk. It is about who is responsible for the judgment inside the number, and the framework does not address that at all.
Published
Key Takeaways
- The Three Lines Model assigns ownership of risk to the first line, expertise and challenge to the second, and independent assurance to the third. The 2020 update dropped the word defense and made the governing body explicit, but did not change that allocation.
- The documented failure mode is diffusion rather than overlap. Davies and Zhivitskaya described clear lines becoming lines in the sand, and Bantleon and colleagues found empirical difficulty in delimiting second and third line responsibilities and in information exchange between them.
- On a quantified program the resolving test is not the org chart. It is who selected the range. Whoever chose the distribution has made the risk judgment, and if that is the analyst then the second line has quietly taken a first line decision.
Research foundation
The model itself is the Institute of Internal Auditors' 2020 position paper, which supersedes the 2013 Three Lines of Defense paper. The critical literature is Davies and Zhivitskaya (2018) in Global Policy and the empirical study by Bantleon and colleagues (2021) in the International Journal of Auditing. Role allocation is anchored in ISO 31000:2018 and COSO ERM (2017). The distribution ownership argument is field experience, marked as such. The Four A's are the executive lens applied on top.
Ask the question in a room containing a program director, a risk manager and an internal auditor and watch what happens. The program director will say risk is managed by the risk team, that is what they are for. The risk manager will say the risk team facilitates and the program owns its risks. The auditor will say neither of those is a control and ask to see the evidence.
All three answers are defensible and the combination is a governance failure, because it means the risk is currently owned by whoever is least able to decline it.
What is the Three Lines Model?
The framework is the Institute of Internal Auditors' description of how responsibility for risk distributes across an organization, and its logic is simpler than the diagram suggests.
The first line is the people doing the work. They deliver the product, they run the service, they build the thing, and because they make the decisions that create the exposure, they own and manage the risk that comes with it. The second line provides expertise, support, monitoring and challenge on risk matters: risk management, compliance, quality, safety, the functions that know more about a category of risk than the delivery team does and whose job is to make sure that knowledge is applied. The third line is internal audit, which provides independent and objective assurance to the governing body about whether the first two are actually working. Above all three sits the governing body, accountable to stakeholders.
The essential claim is a separation claim. Owning a risk and providing assurance about that risk cannot be the same job, because the person doing both has an interest in the answer.
What did the 2020 update change?
In July 2020 the IIA replaced the 2013 Three Lines of Defense position paper with the Three Lines Model. Three changes matter.
The word defense went, and its removal was substantive rather than cosmetic. Defense frames risk as something arriving from outside to be repelled, which is a reasonable description of fraud and a poor description of a construction program, where the significant risks are consequences of choices the organization made on purpose. An organization that thinks in defensive terms treats risk work as protective overhead rather than as an input to what it decides to do.
The rigid assignment of activities to lines softened into a principles-based account of roles. The 2013 version invited an unhelpful game of sorting each task into a numbered bucket. The update accepts that a function can play more than one role and that the important thing is that the roles are distinct, not that the boxes are.
And the governing body became explicit within the model rather than an assumed audience above it, with its own named accountability. That change reads as a small diagram edit and is not one. It is the difference between a board that receives the output of a risk process and a board that is part of it.
What did not change: first line owns and manages risk. Every version of this framework has said so and organizations have been misreading it for a decade.
Why does it keep failing?
Because it is a map of accountability and it gets used as a map of work.
Davies and Zhivitskaya put the problem sharply in Global Policy, asking whether the three lines constitute a robust organizing framework or just lines in the sand. Their concern was that a structure designed to guarantee coverage can instead manufacture gaps, because each line looks at a risk and sees a boundary rather than an obligation. The clarity is on the diagram. The ambiguity is in the space between the boxes, and complex failures live in exactly that space.
Bantleon and colleagues took the question to practitioners and found the same thing empirically. The difficulties they document are about delimiting responsibilities between the second and third lines and about the exchange of information between them. Not disagreement about principle. Difficulty in application, which is a harder problem to fix because everyone involved believes they are complying.
Here is the shape it takes on a program. The schedule is built by planning. The risk register is maintained by a risk lead. The quantitative analysis is run by a specialist, sometimes external. An owner's representative or oversight consultant reviews it. Internal audit tests whether the process was followed. Five parties, each doing their part correctly, and if you ask who owns the P80, four of them point sideways and the fifth says it is an output.
Who owns the number?
This is where the framework runs out, and where the argument actually is.
A quantitative risk analysis is not a calculation applied to facts. It is a calculation applied to judgments. Every three-point range in the model is somebody's opinion about how bad this could get. Every probability on a discrete risk event is somebody's opinion about how likely that is. Every correlation coefficient is somebody's opinion about what moves together. The arithmetic is objective and everything it operates on is not.
So the ownership question has a sharper form than the model provides: who chose the range?
If a risk analyst sat down with the register, applied a standard set of uncertainty bands, ran the simulation and presented a P80, then the analyst has made every material risk judgment on the program. The delivery manager who receives that number and approves it has approved a conclusion without owning any of its premises. The org chart says first line owns the risk. The actual decision was made in the second line, by someone with no authority to change the plan and no accountability for the outcome.
Whoever picked the distribution owns the risk. Everything else is documentation of a transfer that already happened.
This is not an argument against specialist analysts, and it is worth being clear about that. Elicitation is a skill, the biases are well documented, and an untrained estimator produces ranges that are far too narrow. The point is about what the specialist owns. The specialist owns the method: which distribution shape fits, how correlation is handled, whether the sample converged, whether the model reflects the logic of the schedule. The accountable manager owns the content: this activity could take that long, this event is that likely, these two things fail together.
What this looks like when it is right
The mechanism is procedural and it is not expensive.
Ranges are elicited from the person accountable for the work, in a conversation, with the analyst asking the questions and recording the answers. The record carries a name. Not a team, a name. When the model is presented, the significant drivers are traceable to the person who supplied them, so that a tornado chart is not an abstract ranking of variables but a list of colleagues who each said something specific and can be asked about it.
That single change does more for risk ownership than any restructuring, because it makes ownership visible at the level where it operates. It also improves the model, since people asked to defend a range in front of peers produce better ranges than people filling in a template.
The second line keeps the role it should have: challenge. The analyst who thinks a range is too narrow says so, in the record, and the owner either widens it or explains why not. That disagreement is an asset. It is also, incidentally, exactly the evidence a governing body needs to demonstrate that challenge occurred, which is a question the assurance functions will eventually ask anyway.
Where the model genuinely does not fit
Two honest caveats.
The framework assumes an organization large enough to staff three distinct roles. A public agency running a significant capital program with a risk function of one and a half people cannot separate the second and third lines and should not pretend to. The correct adaptation is to buy the third line rather than fake it, which is what an independent review or an oversight consultant provides. The failure is not the absence of a third line, it is the claim to have one.
And the model says nothing about the risks that are nobody's to own because naming them is politically costly. Those are not distributed badly across three lines. They are absent from all three, and no reorganization will surface them.
Evidence matrix
| Claim | Evidence tier | Source |
|---|---|---|
| First line owns and manages risk; second line provides expertise and challenge; third line provides independent assurance | Institutional standard | IIA, The Three Lines Model (2020) |
| The framework can produce diffusion of responsibility rather than coverage | Peer reviewed | Davies & Zhivitskaya (2018), Global Policy 9(S1) |
| Delimiting second and third line responsibilities is empirically difficult in practice | Peer reviewed | Bantleon et al. (2021), Int. J. Auditing 25(1) |
| Risk roles, authorities and accountabilities must be assigned and communicated | International standard | ISO 31000:2018, clause 5.4.3 |
| Ordinal risk scores do not support the arithmetic organizations perform on them | Peer reviewed | Hubbard & Evans (2010), IBM J. Res. Dev. 54(3) |
| The Three Lines Model resolves ownership of modelling assumptions | Not established | The framework does not address elicitation ownership |
| Whoever selects the range has made the risk decision | Named field experience | Capital program practice, Mission Intelligence Systems |
What to do with this
Open the last quantitative risk analysis and pick the three inputs that drive the most variance. For each one, find out whose judgment produced it. If you can put a name to all three and that name is someone accountable for delivering the work, the ownership question is settled and the framework is doing its job. If the answer is that the ranges came from a standard template, or from the analyst, or from last time, then the risk is currently owned by a document.
That is a finding you can act on this week, and it does not require anyone to redraw a governance chart.
References
- Institute of Internal Auditors. The IIA's Three Lines Model: An Update of the Three Lines of Defense. IIA, July 2020. theiia.org.
- Davies, Howard, and Maria Zhivitskaya. “Three Lines of Defence: A Robust Organising Framework, or Just Lines in the Sand?” Global Policy, vol. 9, no. S1, 2018, pp. 34–42. doi.org/10.1111/1758-5899.12568.
- Bantleon, Ulrich, Anne d'Arcy, Marc Eulerich, Anja Hucke, Burkhard Pedell, and Nicole V. S. Ratzinger-Sakel. “Coordination Challenges in Implementing the Three Lines of Defense Model.” International Journal of Auditing, vol. 25, no. 1, 2021. doi.org/10.1111/ijau.12201.
- International Organization for Standardization. Risk Management: Guidelines. ISO 31000:2018, clause 5.4.3 on roles, authorities, responsibilities and accountabilities. iso.org/standard/65694.html.
- Committee of Sponsoring Organizations of the Treadway Commission. Enterprise Risk Management: Integrating with Strategy and Performance. COSO, 2017. coso.org/guidance-erm.
- Hubbard, Douglas W., and Dylan Evans. “Problems with Scoring Methods and Ordinal Scales in Risk Assessment.” IBM Journal of Research and Development, vol. 54, no. 3, 2010. doi.org/10.1147/JRD.2010.2042914.
- U.S. Government Accountability Office. Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs. GAO-20-195G, March 2020. gao.gov/products/gao-20-195g.
- Basel Committee on Banking Supervision. Corporate Governance Principles for Banks. Bank for International Settlements, July 2015. bis.org/bcbs/publ/d328.htm. The supervisory articulation of three lines in financial services.
- Ward, Stephen, and Chris Chapman. “Transforming Project Risk Management into Project Uncertainty Management.” International Journal of Project Management, vol. 21, no. 2, 2003, pp. 97–105. doi.org/10.1016/S0263-7863(01)00080-1.
About the Author
Dan Flynn
Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build
Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and took a federal data platform from one release every six months to seventy-two every two weeks by changing organizational conditions: not people.
His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.
