The distinct roles and operational interfaces of Internal Audit, Corporate Risk Management, and Compliance are defined under the global Three Lines Model established by the Institute of Internal Auditors (IIA).
┌────────────────────────────────────────┐
│ BOARD / AUDIT COMMITTEE │
└───────────────────▲────────────────────┘
│ (Independent Assurance)
┌───────────────────┴────────────────────┐
│ INTERNAL AUDIT (LINE 3) │
└───────────────────▲────────────────────┘
│ (Objective Oversight)
┌───────────────────┴────────────────────┐
│ RISK & COMPLIANCE UNITS (LINE 2) │
└───────────────────▲────────────────────┘
│ (Daily Management)
┌───────────────────┴────────────────────┐
│ FRONT-LINE BUSINESS (LINE 1) │
└────────────────────────────────────────┘
The model structures governance, oversight, and assurance roles across three clear lines:
- Line 1 (Front-Line Business Operations): Comprises revenue-generating business units, customer-facing staff, and operational transaction processors. Line 1 owns and manages risks directly within daily workflows, executing baseline controls and reporting operational anomalies.
- Line 2 (Risk Management and Compliance Functions): Comprises specialized risk functions, compliance testing teams, financial controllers, and data privacy officers. Line 2 establishes corporate policy standards, provides risk assessment tools, monitors key indicators, and challenges Line 1’s self-assessments. Line 2 reports to executive management but operates independently of front-line execution.
- Line 3 (Internal Audit Function): Comprises the internal audit team, operating under the leadership of the Chief Audit Executive (CAE). Line 3 provides completely independent, objective assurance regarding the design and operating effectiveness of both Line 1’s control execution and Line 2’s oversight framework. Line 3 reports directly to the Audit Committee, independent of executive management lines.