Independent Assurance
Assessment by a function with no involvement in designing or operating the control, which is what makes the assessment worth anything.
The three lines describe who does what. The first line owns and operates the control — engineering, operations, the business. The second provides oversight, policy and challenge — risk, compliance, security governance. The third provides independent assurance, typically internal audit, reporting to the board rather than to management.
The property that gives the third line its value is that it did not design or operate what it assesses. A security team assessing its own controls has an interest in them being effective; an internal audit function has an interest in finding out whether they are.
The failure that hollows this out is the second line drifting into the first. A security team that writes the policy, builds the tooling, operates the scanning and also assesses compliance is providing no independent view of any of it — a pattern common in organisations where security was given delivery responsibility because nobody else would take it.
For an architect the practical implication is knowing which conversation is happening. Second-line engagement is collaborative and improves the design. Third-line engagement is an assessment, its findings go to the board, and the appropriate response is evidence rather than persuasion.