Finance & Banking

Applying the Three Lines Model Across Risk, Compliance and Internal Audit

Trains risk, compliance and audit professionals to apply the IIA Three Lines Model, clarify accountabilities across the three lines and build coordinated assurance that avoids gaps and duplication.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Ask a risk manager, a compliance officer and an internal auditor at the same organisation who owns a particular control, and it is not unusual to get three different answers, or worse, to find that all three believe someone else is testing it. The Institute of Internal Auditors' Three Lines Model sets out how operational management, risk and compliance functions, and independent assurance should relate to each other and to the governing body, but applying it well means more than drawing three boxes on an organisation chart. This course works through the accountabilities of each line, how second line functions should oversee without taking over first line ownership of risk, and how internal audit maintains independence while still contributing to a coordinated view of assurance. Participants build an assurance map for a real set of key risks, identify where lines are duplicating effort or leaving gaps, and design reporting that gives a governing body genuine confidence rather than three separate, inconsistent narratives.

Expected Learning Outcomes

01

Explain the accountabilities of each line under the Institute of Internal Auditors' Three Lines Model.

02

Distinguish first line risk ownership from second line oversight and support responsibilities.

03

Assess how internal audit maintains independence while contributing to coordinated assurance.

04

Build an assurance map that identifies coverage gaps and duplicated testing across the three lines.

05

Design escalation routes that connect operational risk issues to the governing body without delay.

06

Evaluate combined assurance reporting formats that give a coherent view to senior stakeholders.

07

Identify organisational structures or incentives that undermine effective separation between the lines.

Who Should Attend

01

Risk managers and compliance officers clarifying second line accountabilities.

02

Internal auditors reviewing their function's role within a Three Lines Model structure.

03

Chief risk officers and heads of compliance redesigning assurance frameworks.

04

Audit committee members overseeing the effectiveness of the three lines in practice.

05

Operational managers accountable for first line risk ownership and control performance.

06

Governance professionals mapping assurance coverage across risk, compliance and audit.

Course Modules

Select any module to see its sessions and points.

01

Foundations of the Three Lines Model

2 sessions · 8 points

Session 1Structure and Purpose of the Model

  • Explain the roles of the governing body, management and internal audit within the Three Lines Model.
  • Compare the current Three Lines Model with the earlier Three Lines of Defence terminology and structure.
  • Identify the principles the model expects organisations to adapt rather than apply as a rigid template.
  • Assess how the model applies differently across organisations of different size and risk profile.

Session 2First Line Accountability for Risk Ownership

  • Define first line accountability for owning and managing risk within day-to-day operations.
  • Assess how first line management should design and operate controls over its own risks.
  • Identify common failures where first line teams treat risk ownership as someone else's job.
  • Evaluate management information that demonstrates genuine first line risk ownership.
02

Second Line Risk Management and Compliance Functions

2 sessions · 8 points

Session 1Defining Second Line Oversight and Support

  • Distinguish second line oversight and challenge activities from first line operational ownership.
  • Assess how risk management and compliance functions set frameworks, policy and risk appetite guidance.
  • Identify where second line functions risk crossing into first line execution or decision-making.
  • Evaluate second line monitoring and reporting that supports rather than duplicates first line controls.

Session 2Coordinating Multiple Second Line Functions

  • Coordinate risk management, compliance, quality and other second line functions to avoid conflicting requirements.
  • Resolve overlapping mandates between second line functions covering related risk areas.
  • Design joint risk assessment processes that reduce duplicated requests to first line teams.
  • Assess resourcing and skills needed for second line functions to provide credible challenge.
03

Third Line Independent Assurance

2 sessions · 8 points

Session 1Internal Audit Independence and Objectivity

  • Assess organisational and reporting arrangements that protect internal audit's independence.
  • Identify threats to objectivity when internal audit reviews activities close to its own history or relationships.
  • Evaluate internal audit charter provisions that define scope, authority and reporting lines.
  • Determine appropriate limits on internal audit's involvement in advisory or consulting work.

Session 2Delivering Coordinated Assurance

  • Build a risk-based internal audit plan informed by first and second line risk assessments.
  • Coordinate internal audit work with second line monitoring to avoid duplicated testing.
  • Communicate audit findings in a way that respects management ownership while ensuring accountability.
  • Assess reliance placed on second line work when scoping internal audit engagements.
04

Assurance Mapping and Governing Body Reporting

2 sessions · 8 points

Session 1Building an Assurance Map

  • Construct an assurance map that links key risks to the assurance activity covering each one.
  • Identify assurance gaps where no line is providing adequate coverage of a material risk.
  • Identify duplicated assurance activity that could be streamlined without reducing coverage.
  • Prioritise remediation of assurance gaps based on risk significance and stakeholder exposure.

Session 2Reporting to the Governing Body

  • Design combined assurance reporting that gives the governing body a coherent, consistent view.
  • Reconcile conflicting risk narratives from different lines before they reach the governing body.
  • Advise the governing body on residual risk exposure after accounting for all assurance activity.
  • Establish a periodic review process that keeps the assurance map current as risks change.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course