Three Lines Model: what the 2026 version changes

19/8/26
6
min de lecture
Cyril Amblard-Ladurantie
Modèle des trois lignes IIA version 2026 : assurance et conseil coordonnés.
13

Years and 2 updates

5

principles

3

lines, one framework

Partager
Cet article vous a plu ? Faite le savoir !
Partager
Cet article vous a plu ? Faite le savoir !

The IIA has updated its Three Lines Model. The roles remain the same: the real action happens between the lines.

It started with a goal: to strengthen risk management frameworks. And an observation: without coordination between teams, "unnecessary redundancies" persist here, "control gaps" there—enough to put the organization at risk. In the spirit of continuous improvement, the IIA published the second update to its model in July 2026.

⏳ From 2013 to 2026: what the updates have changed

Three distinct lines, numbered one through three: the model's terminology might suggest three watertight compartments. With every update, the IIA takes care to dispel this interpretation.

In 2020, the institute moved away from defensive language. The Three Lines of Defense became the Three Lines Model : protecting value is no longer the only goal of the framework; creating value is just as important. The text clarifies that the word lines "is not used to designate structural elements but to distinguish between different roles" and that the three operate simultaneously. The board of directors is now part of the model, and the focus shifts to what connects these roles: "communication, cooperation, and collaboration".

The 2026 version, aimed at boards of directors, executive management, and internal audit heads, makes this collaboration a key focus and moves toward practical application: overlapping roles, outsourcing, and coordination.

🎯 Strength in numbers

The 2026 version acknowledges the limitations of each line.

  • First line : objectivity is constrained by operational ownership. It may "underestimate or rationalize" control weaknesses, and management may bypass certain controls.
  • Second line : its reporting goes through management, which can sometimes distort it. It may limit itself to procedural compliance rather than providing real depth of assurance.
  • Third line : coverage is risk-based, and therefore periodic. Low-risk areas and emerging risks are reviewed less frequently.

Three qualities define the value of a risk perspective: operational proximity, specialized expertise, and independence. No single line can combine all three at once. Each one sees what the others miss, which is why their coordination is essential.

🚧 Independence does not mean isolation

The text establishes independence as a cornerstone of governance. In the same chapter, it warns against a common misconception: independence must not be interpreted as isolation.

This warning was already present in 2020 regarding the dialogue between management and internal audit. The 2026 version extends it to all roles and provides the tools to manage it: a designated mechanism and clear obligations.

The mechanism: if independence is misunderstood or applied indiscriminately, the perception of it can unintentionally limit cross-functional communication and create misalignment between roles.

In other words, independence can become an excuse to avoid collaboration.

The obligations apply at two levels. All roles are required to foster transparency, clear responsibilities, and constructive engagement with one another. Furthermore, the function responsible for independent assurance—primarily internal audit—is provided with specific means to protect its independence: a functional reporting line to the board of directors, unrestricted access to information, and control over its own resources.

🤝 Assurance and consulting: both, across all three lines

The core theme of the 2026 version is captured in two definitions:

  • 🛡️ Assurance confirms whether governance, risk management, compliance, and control frameworks are adequate and effective.
  • 💡 Consulting identifies emerging issues, areas for improvement, and drivers of performance and resilience.

Both are provided by the three lines. Notably, the 2026 version makes consulting by the first line explicit : the kind delivered by management closest to execution. The closer a role is to operations, the more precise its contribution; the more independent it is, the broader its overview. The board of directors and executive management thus strengthen their oversight without needing to know every operational detail.

However, the board has a cost, which the text highlights: because it is collaborative, it creates risks of familiarity and self-review for those who must later independently evaluate what they helped build. Three safeguards frame advisory missions: clearly defined roles, an advisor who refrains from making management decisions, and a board of directors informed of their nature and scope.

😮‍💨 Assurance fatigue

A new term enters the 2026 version: assurance fatigue (assurance fatigue).

The first line performs self-assessment. The second monitors. The third audits. Added to these three lines are external audits and regulatory reviews. The same people may end up answering the same questions four times, using different frameworks, in different formats, at different times. Everyone has done their job, yet the system ends up becoming a burden on those it is meant to serve.

The proposed solution: coordination and reasoned trust in the work of others, under the supervision of the board of directors. The promised benefits: fewer duplicates, optimized assurance coverage, less fatigue, and a more integrated understanding of risks.

🗺️ Integrated assurance and the assurance map

When coordination becomes structured, it takes a name:integrated assurance (integrated assurance).

The text remains cautious: this is not a structural requirement, but a more mature form of coordination, which is all the more useful as risks become complex and interconnected. Its design must reflect the organization's context.

Four tools are cited to achieve this:

  1. 🗺️ An assurance map (assurance map): a summary document that lists risk coverage across the entire organization, including all insurance providers, and highlights both gaps and overlaps in coverage.
  2. 🏷️ Shared risk taxonomies : the same risk is identified by the same name throughout the entire organization.
  3. 📊 Aligned reporting : reports built on the same definitions and timeframes, making them directly comparable.
  4. 📅 Coordinated planning between insurance providers.

Rather than operating in silos, insurance providers can align their methods, share risk information, and coordinate their planning. The expected benefits: greater transparency, less redundant work, and clarity on what is and isn't covered.

This is where the 2026 version formalizes the role of internal audit and gives it a name: theassurance integrator (integrator of assurance). Because it reports to the board of directors and has visibility across the entire organization, the IIA recognizes it as having the most complete and integrated view of the system. It can rely on the work of the first and second lines, choose not to rely on them if the quality is insufficient, and must be careful not to take over second-line activities.

💡 From principles to tools

The model is based on principles, and the IIA does not prescribe any specific tools. In practice, however, the four levers of coordination share one requirement: that assessments, controls, incidents, and audit recommendations all refer to the same data. A shared taxonomy struggles to survive in multiple competing versions; an assurance map loses its value as soon as it becomes outdated; and aligned reporting is difficult to build from scattered files.

This is our approach at Delta RM: a single repository shared by the Risk Management, Internal Control, Internal Audit, and Insurance modules. The three lines work on the same objects, each with its own permissions, scope, and validation level: the first line performs self-assessments, the second provides challenge, and the third conducts audits, all without re-entering data that has already been documented.

Two initial choices support this approach. An unlimited user model to engage all three lines, from the field to the audit committee: risk management is a collective effort, and we want to democratize it and open it up to as many people as possible. Furthermore, the platform was built by risk professionals who practiced the trade before creating the tools, is hosted in France, and is ISO/IEC 27001:2022 certified.

Independence is not isolation, says the IIA. We share this conviction: risk is only a threat to those who face it alone.

❓ Frequently Asked Questions

What is the Three Lines Model?

It is a governance framework published by the IIA (Institute of Internal Auditors) that clarifies where a board of directors finds the assurance and advice it needs. The first line is management, which owns and manages risks and operates controls. The second line brings together the expertise and support functions that assist, challenge, and monitor. The third line is internal audit, which provides independent and objective assurance, including on the second line.

Should we say "lines of defense," "lines of control," or "the three lines"?

The three lines. The other two expressions refer to the original model from January 2013: "Three Lines of Defense" in English, "Les Trois Lignes de Maîtrise" in the IFACI translation. In 2020, the IIA renamed its framework "Three Lines Model" and the 2026 version confirms this choice. The old terms are still used in France, but they refer to a version that has been superseded since 2020.

What does "assurance" mean in the Three Lines Model?

In IIA terminology, assurance is a statement intended to build stakeholder confidence in governance, risk management, compliance, and control systems. It is the same sense of the word as in "insurance provider" or "insurance card." Several functions provide this assurance, each at its own level: internal control, compliance, risk management, and internal audit. The term therefore covers more than just insurance policies and programs: insurance coverage is one of the responses to risk, managed by the insurance function; assurance in the context of the model, however, relates to confidence in the entire system. The two complement each other without being confused.

Does the new model change the roles of the three lines?

No, and it didn't change them much in 2020 either. The 2013 architecture still holds: management owns and manages risks, specialized functions support and challenge, and internal audit provides independent assurance, including on the second line. Two notable changes since the beginning: the board of directors and senior management were located outside the three lines in 2013 and have been integrated into the model since 2020; and the text, once intended for the audit profession, is now addressed to executives. What changes in 2026 concerns the coordination between roles, not their content.

What are the five principles of the Three Lines Model?

The 2026 version reorganizes the model around five principles, down from six in 2020:

  1. The governing body determines the purpose, risk appetite, and expectations, and oversees the pursuit of strategic objectives.
  2. Effective oversight depends on reliable and balanced information regarding performance, risks, and controls.
  3. The governing body and management establish responsibilities by defining the roles of each party.
  4. Distinct sources of assurance, including an independent one, provide the governing body with confidence in the functioning of systems and the initiation of corrective actions.
  5. Advisory services complement assurance by providing perspectives and options for improvement and decision-making.

The six principles of 2020 primarily described the roles of each stakeholder; the five principles of 2026 start from the needs of the governing body: reliable information, assurance, and advice.

What is assurance fatigue?

The exhaustion caused by uncoordinated assurance work: the same teams being solicited multiple times on the same topics by different stakeholders, using different frameworks and formats.

What is an assurance map?

A summary document that identifies risk coverage by all of the organization's assurance providers. It is used to identify overlaps and, more importantly, gaps in coverage.

Can internal audit provide advisory services?

Yes, and this is nothing new: the 2020 version already stated that it provides "independent and objective assurance and advice". The 2026 version provides a framework for this: advice is delivered from a cross-functional perspective, without assuming management responsibility or decision-making power. Furthermore, advisory services are not reserved for the third line: all three lines provide them.

Is a GRC tool required to apply the Three Lines Model?

The IIA does not mandate it: the model is principle-based and does not prescribe any specific structure or tool, with integrated assurance presented as a sign of maturity. In practice, applying these principles without a tool quickly becomes difficult: maintaining a living assurance map, shared taxonomies, and aligned reporting in separate files is precisely what causes the assurance fatigue that the model seeks to reduce. A GRC tool—also known as an IRM or RMIS depending on the market—manages these four levers within a single repository.

📄 Go to the source

Learn more

Are your three lines working from the same framework?

Risks, controls, audits, incidents, assurance: a single database, role-based permissions, and no redundant data entry.

Request a demo

Une fonctionnalité manque à votre dispositif ?

Notre roadmap se construit avec vous. Vous exprimez un besoin. 
S’il est partagé, il devient une priorité produit.

Resources

Risk intelligence, by those who practice it.

The latest analyses from our experts to better manage your risks.

Modèle des trois lignes IIA version 2026 : assurance et conseil coordonnés.
Methods & Best Practices
Internal Control & Audit
6
min read
Three Lines Model: what the 2026 version changes

In July 2026, the IIA released the second update to its Three Lines Model. Coordination, assurance fatigue, assurance mapping: what’s changing, and why the real action happens between the lines.

Read the article
Methods & Best Practices
Internal Control & Audit
2
min read
Digitizing internal audit: questions to ask before you get started

The IFACI guide (with EY and Ingena) for scoping an internal audit digitalization project: 9 practical fact sheets in 3 stages and the key questions to ask.

Read the article
Behind the Scenes Delta RM
Press & Media
4
min read
They talk about us: "We are targeting revenue growth of over 30% in 2024"

Ahead of the 2024 AMRAE edition, Chantal CARNEL, CEO and co-founder of DELTA RM, and Pierre SOREL, Head of Business Development, shared their vision and growth objectives for the company specializing in risk management.

Read the article