Three Lines Model

The IIA's Three Lines Model

The IIA's Three Lines Model is a governance and risk-management model that assigns distinct roles to a governing body, management (split into first-line and second-line roles), and an independent internal audit function, the third line. Internal audit practitioners and the IIA apply this same structure to AI governance: first-line roles build, deploy, and operate AI systems and own the resulting risk; second-line roles provide AI-specific risk expertise, monitoring, and challenge; and internal audit provides independent assurance that AI risk is being governed and managed effectively. It is a principles-based model meant to be adapted to an organization's structure rather than a prescriptive control checklist.

Quick answer

The IIA's Three Lines Model assigns AI risk roles to three groups: first-line teams that build and operate AI and own its risk, second-line functions that provide risk expertise and challenge, and third-line internal audit, which gives independent assurance. Updated by the IIA in July 2020.

Issuing body
The Institute of Internal Auditors (IIA)
Official reference
www.theiia.org/globalassets/site/about-us/advocacy/three-lin

What it covers

  • Six principles: governance; governing body roles; management and first and second line roles; third line roles; third line independence; and creating and protecting value
  • First line roles: provision of products and services to clients, including building and operating AI/ML systems, and managing the associated risk
  • Second line roles: expertise, support, monitoring, and challenge on risk-related matters, which can include model risk, data governance, and AI compliance functions
  • Third line, internal audit: independent and objective assurance and advice on all matters related to the achievement of objectives, reporting primarily to the governing body
  • Governing body: delegates responsibility and resources to management, determines risk appetite, and establishes and oversees an independent internal audit function
  • The IIA's AI Auditing Framework is explicitly built on this model to delineate AI governance, management, and audit responsibilities
  • Updated by the IIA in July 2020 from the earlier 'Three Lines of Defense' model to emphasize value creation alongside risk protection

Adoption status

Published by the IIA in July 2020 as an update to the 2013 Three Lines of Defense model; it is voluntary professional guidance applied internationally across industries. Its application to AI governance specifically is discussed in IIA practitioner guidance and articles rather than as a separate standalone standard, and adoption does not constitute or guarantee compliance with any law or regulation.

Reference only. This page explains what Three Lines Model covers; it is not a claim that Model Governance Index or any listed vendor satisfies it. Verify alignment directly against the issuing body's own current text before relying on it.

Sources. source 1 · source 2 · source 3. Data as of 2026-07-13. See methodology.

Related guides