DigiTrustAsia
Risk Management

The Three Lines of Defense Model, Explained for Risk Professionals

More exam questions can be answered by correctly identifying which line an actor belongs to than by almost any other single fact. Here is the model that makes it click.

Ask a roomful of risk practitioners to define the three lines of defense and most will manage it. Ask them to assign a specific actor in a messy scenario to the correct line — a security operations analyst, a CISO sitting on a steering committee, an internal auditor asked to help design a control — and the room divides. That assignment skill is exactly what CRISC, CISM and CISSP test, repeatedly.

The model in brief

The three lines structure who does what in managing risk, so that doing, overseeing and assuring never collapse into the same hands.

LineWhoRole in one phrase
FirstOperational management and staffOwn and manage risk — they run the controls
SecondRisk management, compliance, security governance functionsOversee and challenge — frameworks, policies, monitoring
ThirdInternal auditIndependent assurance to the board

Around the lines sit two anchors: senior management and the board, who set appetite and receive assurance, and external audit and regulators, sometimes informally called a fourth line, outside the organisation entirely.

The test for any actor: do they operate the control, oversee the control, or assure the control? Operate is first line. Oversee is second. Assure — independently, reporting to the board — is third.

The classifications that trip people up

The firewall administrator is first line. Security staff feel like "the risk people," but anyone operating a control is first line. The SOC analyst triaging alerts, the DBA applying patches, the HR officer running background checks — all first line, because they own and execute.

The CISO is usually second line — but context decides. A CISO setting policy, defining standards and reporting risk posture is second line. A CISO who also directly runs security operations is wearing a first-line hat for those activities. Exams exploit this: read what the person is doing in the scenario, not their title.

Internal audit must never design what it will later assure. The moment audit builds or operates a control, its independence over that control is impaired. Scenario questions where management asks audit to "help implement" the fix are testing whether you'll protect the third line's independence — the BEST answer keeps audit advisory at most, with management owning the implementation.

Risk ownership never moves to the second line. The risk function facilitates assessments, maintains the register and challenges assumptions — but the owner of an IT risk is the manager of the business or IT area where the risk lives. Any answer that makes the risk function the risk owner is a distractor.

Why the model earns its exam weight

It encodes segregation of duties at the organisational scale. If the same function operates, oversees and assures a control, every failure mode is correlated — the error, the missed oversight and the missed assurance all share one blind spot. The three lines de-correlate them. That is also why the model maps cleanly onto governance questions: the board can only rely on assurance that is independent of the thing being assured.

The 2020 IIA refresh renamed it the "Three Lines Model" and softened the military framing, emphasising collaboration over rigid separation — worth knowing if a question uses the newer language. The assignment logic, which is what gets tested, is unchanged.

A drill that makes it stick

Take your own organisation and place ten real roles on the model — including the awkward ones (a GRC analyst embedded in an engineering team; a DevSecOps engineer writing policy-as-code; an MSSP running your SOC). Every awkward case resolves through the same question: operate, oversee, or assure? Do that drill once and the exam's scenario questions start reading like roles you've already classified.

One closing connection: the model pairs naturally with the accountability/responsibility distinction. First line is responsible for managing risk; the board remains accountable for it. Hold both ideas together and an entire band of governance questions — across CRISC, CISM and CISSP — falls into place.

Put it into practice.

700+ exam-weighted questions, every one with a rationale. Your first practice exam is free.

Start free