Skip to content
Final StateThe Three Lines Model: Independence Is a Role, Not a Headcount
VOL. I  ·  NODE 122▢  ATLAS

THREE HATS, ONE HEAD

The Three Lines Model: Independence Is a Role, Not a Headcount

The Three Lines Model separates management's action and challenge from internal audit's independent assurance to the governing body.

THREE ROLES, ONE SYSTEM

Management acts; management challenges; internal audit independently assures

Three Lines Model diagram showing governing body, management first and second line roles, and internal audit independently reporting to the governing body.The figure places first and second line roles inside management and the third line outside management with direct accountability to the governing body.THE THREE LINESGOVERNING BODYMANAGEMENTFIRST LINEDELIVER +MANAGE RISKSECOND LINESUPPORT +MONITORCHALLENGETHIRD LINEINTERNALAUDITINDEPENDENTASSURANCEDIRECTREPORT
  • First line: delivers products or services and manages risk
  • Second line: supplies expertise, support, monitoring, and challenge as part of management
  • Third line: independently assures and advises the governing body

The IIA's current model is flexible about structure: first- and second-line roles may blend or separate; the third line's independence is the non-negotiable distinction.

A second approval is not a third line

More reviewers can improve a decision, but formal independent assurance requires authority, access, objectivity, and freedom from responsibility for the work being examined.

THE MODEL CHANGED

2013: defense. 2020: governance, relationships, and value.

Two-date timeline from the IIA's 2013 Three Lines of Defense paper to its 2020 Three Lines Model revision.The timeline avoids an invented origin story and focuses on the documented IIA publications and the shift from defensive silos toward governance relationships.DOCUMENTED IIA HISTORY2013THREE LINESOF DEFENSEDEFENSIVESILOS2020THREE LINESMODELGOVERNANCERELATIONSHIPS+ VALUEHISTORY, NOT MYTHNO SINGLE BANKING ORIGINNO 2008 CREATION CLAIM
  • 2013: the IIA published its Three Lines of Defense position paper
  • 2020: the IIA replaced it with the Three Lines Model
  • The update stresses governing-body accountability, management action, and independent audit

The documented history supports an IIA framework and a 2020 revision; it does not support a single banking birthplace or a claim that the model was created by the 2008 crisis.

Two ratifiers can still share one frame

An approval chain can add useful challenge without becoming independent assurance. If both reviewers inherit the same target, incentives, evidence, and authority, they remain one management system, not two independent lines.

LOCK THE DECISION EARLY

Registered Reports decide publication before results are known

Bar exhibit comparing 96.05 percent positive first hypotheses in 152 standard reports with 43.66 percent in 71 Registered Reports.The figure shows the observational difference and the key format change: peer review and in-principle publication acceptance occur before results are known.POSITIVE FIRST HYPOTHESIS96.05%43.66%STANDARD146 OF 152REGISTERED31 OF 71PLAN → REVIEW → ACCEPTBEFORE RESULTSOBSERVATIONALCOMPARISONNOT RANDOMIZEDSCHEEL ET AL. · 2021
Scheel, Schijen & Lakens, 2021: first hypothesis in psychology reports; SR N=152, RR N=71; observational comparison, not random assignment.

Scheel, Schijen and Lakens argue that results-blind in-principle acceptance can reduce publication bias and analytical flexibility; different hypotheses and authors may also contribute to the gap.

  • Standard psychology reports: 146 of 152 first hypotheses positive, 96.05%
  • Registered Reports: 31 of 71 first hypotheses positive, 43.66%
  • Observational format comparison: the study does not randomly assign papers to formats

THE SEALED NOTE

Precommitment constrains your later self; it does not make you independent

A dated precommitment note sealed before results, with later deviations logged and a boundary marking that it is not independent audit.The figure stages criterion, exclusions, and analysis plan before results, then routes any deviation into a visible log instead of treating precommitment as independence.CONSTRAIN THE LATER SELFBEFORE LAUNCHSUCCESSCRITERIONEXCLUSIONSREAD-OUT PLANLOCKRESULTCOMPARELOGDEVIATIONCONSTRAINT, NOT AUDITTHE OWNER IS STILL THE SAME
  • Before launch, date the success criterion, exclusions, and read-out plan
  • After results, report deviations rather than silently moving the rule
  • Use outside review when consequences require genuinely independent assurance

A sealed note is a useful verification constraint, but it is not a substitute for internal audit: the same person still owns the work and the interpretation.

BORROW THE LOGIC

For solo work: constrain, challenge, then buy independence where it matters

  1. 01Constraint: seal criteria and analysis before seeing the answer
  2. 02Challenge: run an adversarial pass with a different brief or reviewer
  3. 03Assurance: schedule a conflict-free outsider with access and authority to report

This adaptation borrows the model's logic without claiming equivalence: only the outside reviewer can supply the separation a solo operator cannot manufacture internally.

Solo-work adaptation moving from precommitment to adversarial challenge to conflict-free outside assurance.The process labels the first two steps as internal constraints and reserves independent assurance for an outside reviewer with access and reporting authority.BORROW THE LOGIC01CONSTRAINSEALED CRITERIAINTERNAL02CHALLENGEADVERSARIAL PASSINTERNAL03ASSUREOUTSIDE REVIEWINDEPENDENTONLY 03 ADDS SEPARATIONDO NOT CLAIM EQUIVALENCE

THE INTERVENTION LOG

Did challenge change the decision, or merely decorate it?

Local intervention log segmented by decision type, showing revisions and escalations alongside possible explanations for a falling rate.The exhibit rejects a universal healthy intervention rate and treats a downward trend as a prompt to investigate task mix, proposal quality, and reviewer behavior.INTERVENTION LOGTIMEREVISED · REJECTED · ESCALATEDHIGH-STAKESROUTINEA FALL IS A QUESTIONCHECK MIX · QUALITY · REVIEWNO UNIVERSAL HEALTHY RATE
illustrative local metric; no universal healthy intervention rate is asserted.

The intervention log is a local monitoring instrument, not a validated benchmark. It can reveal deskilling or automation bias, but a low rate may also reflect better proposals or easier work.

  • Log revisions, rejections, escalations, and reasons
  • Segment by consequence and decision type; one aggregate rate can mislead
  • A decline triggers investigation, not an automatic target for more disagreement

INDEPENDENCE, NOT HEADCOUNT

Ask what the reviewer can see, change, and report

  • See: access to records, people, and contrary evidence
  • Change: authority to escalate without the operator's permission
  • Report: a route to the governing party, not only the work's owner

That is the portable lesson behind building the check: headcount can add challenge, but independence requires a relationship the work's owner does not control.

Read the transcript

01 · THREE HATS, ONE HEAD

A solo operator makes the decision, challenges the decision, and signs off on the decision. Three activities happened. Independence did not. The Institute of Internal Auditors' Three Lines Model distinguishes management's work from internal audit's assurance to the governing body. A person can add checks, change prompts, and return with fresh eyes. They cannot become independent of their own management choices by changing hats. That is the structural problem this page owns.

02 · THREE ROLES, ONE SYSTEM

The current model begins with governance, not three rigid departments. First-line roles deliver products and services and manage the risks in that work. Second-line roles remain part of management, supplying expertise, support, monitoring, and challenge. Those roles may blend or separate depending on the organization. The third line is different. Internal audit provides independent and objective assurance and advice, accountable to the governing body and independent from management's responsibilities. The diagram is flexible. The distinction around the third line is not.

03 · THE POINT IS INDEPENDENCE

A second approval is not automatically a third line. More reviewers can add expertise and catch mistakes. Formal independent assurance asks harder questions. Does the reviewer have access to the records and people they need? Can they report an uncomfortable finding without the work's owner suppressing it? Are they free from responsibility for the activity they are examining? Effort helps. Headcount helps. Neither creates those conditions by itself.

04 · THE MODEL CHANGED

Keep the history to what the record supports. In 2013, the Institute of Internal Auditors published its position paper on the Three Lines of Defense. In 2020, it replaced that paper with the Three Lines Model. The revision moved emphasis away from defensive silos and toward governance, relationships, collaboration, and the creation and protection of value. The documented dates do not prove one banking birthplace, and they do not prove the 2008 crisis created the framework. What they show is a professional model revised as its own limits became clearer.

05 · APPROVAL IS NOT ASSURANCE

This is why an approval chain can look stronger than it is. Two ratifiers may be useful. They may still share the same target, evidence, incentives, and authority. If neither can reach outside that frame, the chain remains one management system with two signatures. Challenge and assurance are both valuable, but they are not synonyms. Calling every approval independent does not strengthen the control. It hides which relationship is missing.

06 · LOCK THE DECISION EARLY

Registered Reports show one way structure can change what reaches the record. Before results are known, authors submit hypotheses, methods, and an analysis plan for peer review. A journal can then grant in-principle acceptance, committing to publish regardless of whether the hypothesis is supported, provided the plan and quality conditions are met. Scheel, Schijen, and Lakens compared the first hypothesis in two bodies of psychology papers. One hundred forty-six of one hundred fifty-two standard reports were positive, or 96.05 percent. Thirty-one of seventy-one Registered Reports were positive, or 43.66 percent. This was an observational format comparison, not random assignment. The authors identify reduced publication bias and inflated error as plausible contributors while noting that different hypotheses, authors, and journals may also matter.

07 · THE SEALED NOTE

A small operator can borrow one part of that discipline. Before launch, date the success criterion, exclusions, and read-out plan. After results arrive, report deviations instead of silently moving the rule. This constrains your later self. It does not make you independent. You still own the work and interpret the outcome. For reversible, low-consequence experiments, the constraint may be enough. Where consequences demand independent assurance, a sealed note cannot replace an outsider with access, objectivity, and a reporting route.

08 · Advertisement · Bubble AI App Builder

Some ideas do not need another document before they become testable. With Bubble AI, you describe the app you want, and Bubble creates a working starting point: interface, data, and logic you can inspect. From there, you refine visually, connect AI models and services, and turn the first version into something real enough to use.

09 · BORROW THE LOGIC

For solo work, borrow the logic without pretending you rebuilt the institution. First, constrain: seal the criteria and analysis before seeing the answer. Second, challenge: commission an adversarial pass with a different brief, evidence set, or reviewer. Third, buy independence where the consequence warrants it: schedule a conflict-free outsider who can inspect the record and report an uncomfortable conclusion. The first two steps improve management's own checks. Only the third supplies separation the operator cannot manufacture inside one head.

10 · THE INTERVENTION LOG

Then monitor whether challenge changes anything. Log revisions, rejections, escalations, and the reason for each. Segment the record by decision type and consequence, because one aggregate rate can mislead. A falling intervention rate is a question, not a verdict. Reviewers may be rubber-stamping. Proposals may have improved. The task mix may have become easier. There is no universal healthy percentage. The value of the log is that it makes those explanations testable instead of letting a signature stand in for scrutiny.

11 · INDEPENDENCE, NOT HEADCOUNT

End with three tests. What can the reviewer see? They need records, people, and contrary evidence. What can the reviewer change? They need a route to escalate without asking the work's owner for permission. Where can the reviewer report? Meaningful assurance reaches the governing party, not only the management being examined. More people can improve challenge. Independence is a relationship, with access and authority, that the work's owner does not control.

01 / 11 · THREE HATS, ONE HEAD0:00 / 7:24