The Three Lines Model in 2026: How Risk and Internal Audit Can Collaborate Without Blurring Accountability

August 20, 2026

What does the IIA's 2026 Three Lines update mean for risk and internal audit? Improve coordination without compromising accountability or independence.

In July 2026, The Institute of Internal Auditors (IIA) published two connected Statements of Position: an updated Three Lines Model and new guidance on the role of internal audit in enterprise risk management.

The core structure remains familiar. Management owns and manages risk. Second-line functions provide expertise, oversight, monitoring and challenge. Internal audit provides independent and objective assurance to the board.

The updated guidance pays much closer attention to assurance, advice, coordination and reliance between the three lines. It recognises that functions cannot work effectively in isolation, especially when risks, controls and business decisions are increasingly interconnected.

For Symbiant, the update reinforces the value of a true single source of truth. Our award-winning GRC software puts this into practice by connecting risks, controls, incidents, actions and audit activity within one platform, while preserving distinct ownership, permissions and accountability across all three lines.

That creates an important practical question: how can risk management and internal audit work from the same organisational picture without taking on each other’s responsibilities?

The answer is not to build stronger walls between the lines. It is to create clearer accountability, controlled collaboration and a shared source of reliable information.

The Three Lines Model: what remains unchanged?

The 2026 update does not redesign the model. It reinforces the distinct contribution of each line:

LinePrimary roleWhat it must retain
First line: management and operationsOwns and manages risk; designs, implements and operates processes and controlsOwnership of business decisions, risks, controls and responses
Second line: risk, compliance and specialist functionsProvides expertise, frameworks, support, monitoring and credible challengeResponsibility for helping management apply risk and compliance frameworks consistently
Third line: internal auditProvides independent, objective assurance and advice on governance, risk management, compliance and controlsIndependence from management decisions and freedom to determine audit scope, findings and conclusions


The distinction can be expressed simply:

  • The first line makes and owns decisions.

  • The second line improves the quality and consistency of those decisions.

  • The third line independently assesses whether the system around those decisions is effective.

The board remains responsible for setting direction, establishing risk appetite and overseeing whether the organisation’s governance arrangements work as intended.

RELATED GUIDE 

The Three Lines of Defence Model

Explore the roles of each line, common implementation challenges and how a connected approach strengthens accountability, oversight and assurance.

Read the Practical Guide →

 

Why do risk management and internal audit sometimes overlap?

The IIA organises enterprise risk management around five connected activities: identifying, assessing, managing, monitoring and reporting risk. Internal audit may provide advice or assurance across each activity, but it must not determine management’s approach, prioritise responses, implement controls or assume ownership of risk reporting. Management remains responsible for the decisions and their outcomes.

Risk professionals and internal auditors often use similar skills. Both may analyse risks, review controls, challenge assumptions, examine incidents and consider whether management information is reliable.

The difference is not necessarily the subject matter. It is the purpose, authority and accountability attached to the work.

A second-line risk team may challenge a business unit’s assessment, monitor whether exposure remains within appetite and help management improve a control. Internal audit may examine the same risk or control, but its purpose is to provide independent assurance on whether the wider process is adequately designed and operating effectively.

The IIA highlights that internal auditors need to understand how risks connect to strategy and objectives, how risk appetite and tolerance influence decisions, how risk culture affects behaviour, and how risk information supports decision-making. These capabilities are also fundamental to mature second-line risk management. The distinction therefore lies not simply in the skills each function possesses, but in the purpose of the work and who remains accountable for the outcome.

Overlapping expertise must never result in ambiguous accountability.

The boundary becomes harder to see when internal audit provides advisory support, facilitates risk discussions or helps coordinate assurance. The IIA’s 2026 ERM statement allows internal audit to contribute advice across the risk lifecycle, but it is equally clear that internal audit must not select or implement management’s risk responses.

Internal audit can challenge, advise and provide insight. Management must still decide and own the outcome.

Independence should not mean isolation

Internal audit needs access to the organisation’s objectives, risks, controls, incidents, performance indicators and previous assurance work. If that information is fragmented across spreadsheets, inboxes and separate systems, the third line may spend more time assembling evidence than evaluating it.

Isolation also creates wider problems:

  • different functions may use conflicting risk language or scoring methods;

  • audit plans can become disconnected from the current risk profile;

  • controls may be tested repeatedly while other areas receive little assurance;

  • findings and remediation actions may be duplicated or lost;

  • board reports may present inconsistent versions of risk and control performance.

The 2026 model therefore gives greater weight to coordination and appropriate reliance. Assurance providers may align methodologies, share risk information, coordinate plans and use assurance mapping to identify gaps or duplication.

This does not weaken independence. Done properly, it gives internal audit better evidence and a clearer organisation-wide view while preserving its authority to assess that evidence objectively.

Shared information, separated responsibilities

A connected GRC platform can allow all three lines to work from consistent information without giving every function the same permissions or authority.

That distinction matters. A single source of truth should not become a single set of responsibilities.

In practice, a connected model can work like this:

First line: capture and manage risk where it occurs

Operational teams can record risks, incidents and control activity as part of day-to-day work. Named owners remain responsible for assessments, responses and actions. Automated reminders help keep reviews and remediation moving without transferring ownership to the risk or audit function.

Second line: monitor, support and challenge

Risk and compliance teams can maintain frameworks, monitor exposure, review control information and challenge assessments. Shared taxonomies, configurable scoring and Key Risk Indicators make it easier to identify inconsistent treatment, emerging patterns and areas outside risk appetite.

Third line: access the evidence and retain an independent view

Internal audit can use live risk and control information to inform the audit universe, prioritise coverage and plan risk-based engagements. Auditors can then document evidence and conclusions within controlled audit working papers, link findings to the relevant risks and controls, and track agreed management actions without becoming the owner of those actions.

The information connects. The responsibilities remain distinct.

The IIA also recognises that organisational structures are not always neatly separated. In smaller or developing organisations, internal audit may temporarily perform second-line ERM activities, or the Chief Audit Executive may supervise a risk or compliance function. These arrangements are not automatically inappropriate, but they require clearly documented responsibilities, board oversight, separation between advisory and assurance work, transparency about potential conflicts and independent assurance over activities internal audit has helped operate.

Five controls that protect the boundaries between the lines

Technology cannot create independence by itself. Organisational structure, reporting lines, board oversight and professional judgement remain essential. However, the way a system is configured can make responsibilities clearer, reinforce safeguards and leave evidence that they were followed.

1. Define ownership at record level

Every risk, control, incident, finding and action should have a named owner. The system should distinguish between the person responsible for managing an item, the function reviewing or challenging it and the auditor providing assurance.

2. Use role-based permissions

Shared visibility does not require unrestricted editing. Granular permissions can allow internal audit to access relevant evidence while preventing inappropriate changes to management-owned records. They can also protect audit scopes, tests, findings and conclusions from management interference.

“ [With Symbiant GRC Software] Our 1LOD teams could add progress updates but not amend any action details. Our 2LOD teams could filter on & download the reports they needed. The incident management module made it very easy for 1LOD to report an incident. The format was very user friendly. We also had fields only visible for the 2LOD teams.”

Camilla Owen, Head of Non-Financial Risk (1st Line of Defence)

Read the Full Case Study.

3. Separate workflows and approvals

Advising on a risk response is different from approving it. Testing a control is different from operating it. Configured workflows should make these stages and authorities visible, with separate approvals where independence or segregation of duties matters.

4. Maintain a complete audit trail

Organisations should be able to see who created, reviewed, challenged, amended and approved information, and when. Traceability is particularly important where internal audit has provided advisory input or where responsibilities temporarily overlap.

5. Connect findings to remediation without transferring ownership

Internal audit should be able to monitor whether agreed actions are completed, while management remains responsible for implementation. A connected Audit Action Tracker gives findings clear owners and deadlines and provides visibility to audit committees without turning auditors into action owners.

What integrated assurance should achieve

The 2026 model positions internal audit as an important facilitator of integrated assurance. Its organisation-wide perspective and access to the board can help coordinate assurance plans, consolidate results and identify gaps or duplication. However, coordinating assurance should not make internal audit the owner of the ERM framework, risk taxonomy or second-line monitoring activities.

Integrated assurance is not about merging every function into one team. It is about giving the board a coherent view of whether important risks are being managed and where assurance is strong, duplicated or missing.

A practical approach should help the organisation answer:

  • Which strategic objectives and material risks are covered by assurance?

  • Which controls have been assessed, by whom and with what result?

  • Where are several functions repeating similar reviews?

  • Where are assurance gaps emerging?

  • What evidence supports reliance on another provider’s work?

  • Which findings and actions remain unresolved?

  • Has any advisory involvement created a real or perceived self-review risk?

These questions are difficult to answer when risk registers, audit plans, control assessments and remediation trackers sit in different tools. Connecting them creates a clearer chain from objective and risk through to control, evidence, assurance conclusion and action.

It also makes coordination more defensible. Reliance is no longer based solely on an informal conversation or a copied spreadsheet; it can be supported by documented methodology, evidence, ownership and review history.

A practical checklist for boards, risk leaders and chief audit executives

The 2026 guidance is an opportunity to review how the model operates in practice, not simply how it appears on an organisational chart.

Start by asking:

  1. Are first-, second- and third-line responsibilities documented clearly enough to show who decides, who challenges and who assures?

  2. Do risk and audit teams use a shared risk taxonomy and consistent links to business objectives?

  3. Can the board see assurance coverage, gaps, duplication and outstanding actions in one coherent view?

  4. Does internal audit have unrestricted access to relevant information without gaining responsibility for management-owned activity?

  5. Are advisory engagements, potential conflicts and safeguards formally recorded?

  6. Can audit planning respond to changes in risk exposure, incidents, control effectiveness and KRIs?

  7. Does the system preserve a reliable audit trail of ownership, review, approval and change?

If the answer to several of these questions is no, the problem may not be the Three Lines Model itself. The problem may be that the organisation is trying to operate a connected governance model through disconnected processes.


References

  1. The Institute of Internal Auditors, Three Lines Model: Assurance and Advice in Support of Effective Governance, 2026

  2. The Institute of Internal Auditors, The Role of the Internal Audit Function in Enterprise Risk Management, 2026

Make collaboration visible without compromising independence

The IIA’s 2026 update makes an important point: coordination and independence are not opposites. Organisations need both.

The first line must own risk. The second line must support, monitor and challenge. The third line must retain the objectivity and authority required to provide credible assurance. But all three need access to reliable, consistent and traceable information.

Symbiant’s connected Audit Management Software brings audit planning, working papers, findings and actions together with live risks, controls and incidents. Configurable roles, permissions and workflows help each line work from the same organisational picture while retaining its distinct responsibilities.

See how Symbiant can connect risk, decisions and assurance without blurring accountability.

Stafford Railway Building Society uses Symbiant to enhance compliance and governance