Three Lines Model
also called Three Lines of Defence
The organisational separation between those who own and manage risk, those who oversee and challenge, and those who provide independent assurance.
The model exists to ensure that the people assessing whether controls work are not the same people who built them, and it is worth understanding because it explains behaviour that otherwise looks obstructive.
The first line is the business and engineering teams that own the risk and operate the controls. They are accountable for outcomes. The second line is risk and compliance functions that set the framework, monitor and challenge — they advise and oversee but do not own the risk. The third line is internal audit, independent of both, reporting to the audit committee rather than to management, providing assurance that the whole arrangement functions.
Where architects encounter friction is the second line, and the friction usually comes from a misunderstanding of role: the second line is not there to design the solution, and asking them to approve a design converts oversight into ownership, which weakens the model and slows everything.
The practical value of knowing this: it tells you who to bring in and when. Design decisions and control implementation are first-line work, and involving the architect early is the way to get them right. Second line should be consulted on whether the control framework is satisfied, ideally through automated evidence rather than review meetings. Third line arrives afterwards to test, and the best preparation for that is the audit evidence the platform generates by default.