Corporate governance dictates the distribution of rights and responsibilities among participants in the corporation, primarily the Board of Directors, executive management, and shareholders.
Role of the Board of Directors and Audit Committee
- The Board of Directors: Holds final accountability for risk oversight. They define the corporate risk appetite and review management’s execution of ERM strategies.
- The Audit Committee: A specialized subgroup of the board composed entirely of independent, non-management directors who are financially literate. They supervise internal and external audit mechanisms, manage relationships with independent evaluators, and oversee financial reporting controls.
The “Three Lines Model” of Governance
The Institute of Internal Auditors (IIA) outlines an operational governance model separating execution, oversight, and assurance.
+---------------------------------------+
| Governing Body / Board |
+---------------------------------------+
|
+---------------------------------------+
| Management |
+---------------------------------------+
| 1st Line: Operational Controls |
| 2nd Line: Risk Management & Comp. |
+---------------------------------------+
|
+---------------------------------------+
| 3rd Line: Internal Audit (Assurance) |
+---------------------------------------+
- First Line (Operational Management): Frontline business managers who own and manage risks daily. They are directly responsible for implementing and executing internal control activities.
- Second Line (Risk & Compliance Functions): Specialized units established by management to facilitate, monitor, and guide risk management practices. They provide the frameworks, tools, and compliance checks to ensure the first line is operating effectively.
- Third Line (Internal Audit): Provides independent, objective assurance to the Board and senior management on the effectiveness of governance, risk management, and internal controls. They must remain completely insulated from operational management choices.
Â