Three Lines Model
Ownership, oversight and independent assurance, and where architecture sits in it.
5 to work through
-
beginner Multiple choice
Your payroll SaaS vendor emails its SOC 2 Type II report covering January to December. The risk committee marks the vendor risk as covered and closes the item. What has that report actually given you?
3 min answer -
intermediate
An organisation adopts the three-lines model and it produces friction without assurance. What went wrong?
2 min answer -
intermediate
How does the three lines model apply to a technology organisation, and where does it go wrong?
2 min answer -
intermediate
How does the three-lines model apply to a modern engineering organisation, and what goes wrong when the second line is staffed by people who cannot read the systems?
2 min answer -
intermediate
To stop the risk function writing policies nobody can implement, a company embeds two risk engineers inside the platform team to build and operate the policy gate themselves. Time from policy publication to enforcement drops from two quarters to days. What has the company given up, and when does that bill arrive?
3 min answer
3 terms in this topic
Complementary User Entity Control
A control the service provider's auditor assumed the customer operates, so that a clean vendor opinion only holds for customers who are actually runn…
conceptIndependent Assurance
Assessment by a function with no involvement in designing or operating the control, which is what makes the assessment worth anything.
conceptThree Lines Model
The organisational separation between those who own and manage risk, those who oversee and challenge, and those who provide independent assurance.
Neighbouring topics
Assurance, Audit & Model Risk
General material on assurance, architectural governance and risk oversight.
Control Design vs Operation
A control that is well designed and never runs fails exactly like one that is absent.
Audit Evidence
Producing durable, tamper-evident proof as a by-product rather than as a project.
Certification Impact on Architecture
What SOC 2 and ISO 27001 actually require of a design, and what they do not.
Continuous Controls Monitoring
Testing controls continuously instead of sampling them once a year.
Segregation of Duties
Splitting authority so no single actor can both make and approve a change.
Change Advisory vs Automated Gates
Replacing a weekly board with evidence a machine produces on every change.
Risk Appetite
The stated tolerance that tells you which risks you are allowed to accept.
Risk Assessment Methods
Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.
Security Design Review
Reviewing an architecture for security while changing it is still cheap.
Architecture Compliance Checks
Automating conformance to standards so review effort goes to the genuinely novel.
Exception & Waiver Management
Time-boxed, owned deviations with a remediation date, rather than permanent silence.
Design Authority
How an ARB should decide, what it should not review, and how it avoids becoming a queue.
Model Risk Management
Inventory, validation, monitoring and challenge for models that make consequential decisions.
AI Risk Tiering
Classifying a use case by potential harm, and the obligations each tier triggers.
Model Documentation
Model cards, intended use, limitations, and the record a regulator will ask for.
Model Evaluation & Red-Teaming
Adversarial testing of a probabilistic system with no fixed expected output.
Bias & Fairness Controls
Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.
Human-in-the-Loop Design
Meaningful review rather than a rubber stamp, and designing against automation bias.