Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
The Three Lines Model and ERM Integration ReferenceEnterprise Risk Management
4 min readFor Internal Auditors

The Three Lines Model and ERM Integration Reference

Scope

This guide focuses on integrating the Institute of Internal Auditors' Three Lines Model with enterprise risk management (ERM) frameworks. It's designed for internal audit teams implementing the IIA's guidance on governance collaboration and for risk managers looking to align their ERM functions with assurance activities.

You'll find practical steps for implementation, role definitions, and a reference table mapping responsibilities across governance lines. This is a working document to help design coordination protocols and clarify accountability boundaries for stakeholders.

Key Concepts and Definitions

Three Lines Model: The IIA's governance framework outlines three roles in risk management:

  • First line: Operational management that owns and manages risk.
  • Second line: Risk management and compliance functions that provide oversight.
  • Third line: Internal audit, which offers independent assurance.

Enterprise Risk Management (ERM): A structured approach to managing risks across the organization. ERM typically resides in the second line, maintaining the risk universe, facilitating assessments, and reporting to the board.

Governance Collaboration: Coordination between lines through shared risk taxonomies, joint planning, and integrated reporting to prevent gaps and duplication in risk coverage.

The IIA's position papers emphasize that these models are adaptable. Your integration approach needs regular review as your risk environment evolves.

Requirements Breakdown

First Line Responsibilities

Your operational teams should:

  • Own risk identification and mitigation at the process level.
  • Implement controls for specific risks.
  • Report control effectiveness and risk events to second-line functions.
  • Participate in risk assessments facilitated by the ERM function.

The first line provides the essential data that makes ERM and audit effective.

Second Line Responsibilities

Your risk management and compliance functions should:

  • Maintain the organization's risk universe and taxonomy.
  • Facilitate enterprise-wide risk assessments.
  • Set risk appetite and tolerance thresholds.
  • Provide expertise to the first line.
  • Monitor aggregate risk exposure and report to senior management.

The ERM function should own the risk register but requires input from operational teams and validation from internal audit.

Third Line Responsibilities

Your internal audit function should:

  • Provide independent assurance on risk management processes.
  • Evaluate the design and effectiveness of controls.
  • Assess whether the first and second lines are functioning as intended.
  • Report directly to the audit committee on governance effectiveness.

Internal audit's independence is essential. Coordination should not be confused with co-management.

Implementation Guidance

Establish a Common Risk Language

Start with taxonomic alignment. If ERM, compliance, and audit use different risk categorization schemes, you'll waste time translating between them.

Create a single risk taxonomy for all three lines. Map it to relevant frameworks like ISO 31000 for ERM and COSO Internal Control-Integrated Framework for financial controls.

Design Coordination Protocols Without Compromising Independence

Regular touchpoints between lines are necessary, but structure them carefully:

  • Planning alignment: Internal audit should review the ERM risk assessment when building its annual audit plan but shouldn't be bound by ERM's priorities.
  • Information sharing: Second-line functions should share risk data with audit, and audit should share observations indicating emerging risks.
  • Joint reporting: Consider integrated risk dashboards for management, but maintain separate reporting lines to the board.

Coordination happens at the working level, while accountability remains distinct.

Integrate Risk Assessment Cycles

Synchronize risk assessment cycles so that:

  • ERM completes its assessment before audit finalizes its plan.
  • Audit shares preliminary findings before ERM locks its risk universe.
  • Compliance monitoring results feed into both ERM and audit scoping.

Design handoffs that prevent information loss without forcing everyone onto the same schedule.

Define Escalation Paths

When the first line identifies a risk that exceeds tolerance, who gets notified? When audit finds a control deficiency, does it go to the risk owner, the ERM function, or both?

Document these paths explicitly. Include timing expectations, such as "material control deficiencies escalated to the audit committee within 48 hours."

Common Pitfalls

Treating ERM as a compliance exercise: If your ERM function exists just to satisfy the board, it won't generate the insights internal audit needs. ERM should drive decision-making, not just documentation.

Blurring audit's independence: When internal audit facilitates risk workshops or co-designs controls, it crosses into the second line. You can't audit what you helped build.

Duplicating coverage without coordination: If audit and compliance test the same controls independently, you're wasting resources. Map your coverage and divide it intentionally.

Ignoring the first line: The most sophisticated ERM framework fails if operational teams see it as someone else's job. Integration starts with making risk management part of how managers run their business.

Building integration for its own sake: Coordination has a cost. Don't create integration mechanisms that consume more time than they save. Cancel meetings that produce no actionable outcomes.

Quick Reference Table

Activity First Line Second Line (ERM) Third Line (Audit)
Risk identification Identifies operational risks Facilitates enterprise view Validates completeness
Risk assessment Assesses impact and likelihood Aggregates and reports Audits assessment process
Control design Designs and implements Provides standards and guidance Evaluates design adequacy
Control testing Self-assessment Monitoring and testing Independent testing
Risk reporting Reports to management Reports to executive/board Reports to audit committee
Risk ownership Owns and manages Oversees and challenges Provides assurance
Remediation Executes corrective action Tracks remediation Validates closure

Use this table to explain accountability to new team members or when stakeholders question why multiple functions are involved in the same risk area. The answer isn't duplication, it's defense in depth, with each line playing a distinct role.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like