A manufacturer's risk register was built by internal audit, scored by internal audit, and presented to the board by internal audit. The audit committee liked the efficiency. The external quality assessor called it a structural failure, and the exam agrees.
Risk management belongs to management. Internal audit provides assurance about whether that risk management works. The distinction sounds obvious in the abstract and dissolves the moment a resource-poor organization asks its auditors to help.
The Three Lines Model is the IIA's public framework for allocating that responsibility. It replaced the older "three lines of defense" language and, importantly, dropped the defensive framing: the lines exist to achieve objectives, not merely to block losses.
- Governing body: The board accepts accountability to stakeholders, delegates to management, and establishes the internal audit function with the independence and authority to serve it.
- Management, first line: The people who own and deliver products and services. They own risks directly and design, operate, and maintain the controls that treat them.
Common mistakes
- Treating second-line monitoring as assurance to the board. Compliance and risk functions monitor on management's behalf and report to management. Only the third line's functional board reporting produces board-level independent assurance.
- Assuming disclosure cures an impairment. Disclosure informs the board; it does not restore objectivity. The affected engagement still needs a non-involved reviewer, rotation, or an external provider.
- Confusing facilitation with ownership. Running a risk workshop is permitted. Scoring the risks, setting appetite, choosing responses, or signing the register is management's job and off limits.
Bottom line
- Three Lines Model: governing body oversees; first line owns risks and controls; second line provides risk and compliance expertise and monitoring; third line, internal audit, provides independent assurance to the board.
- Both first and second lines are management functions and report to management; only internal audit reports functionally to the governing body.
- Permitted assurance roles: evaluating risk process design, risk identification, risk ratings, responses against appetite, and the accuracy of risk reporting to the board.
- Permitted advisory roles with safeguards: facilitating workshops, supplying methodology, benchmarking, championing risk management, consolidating management's reporting.
Exam shortcut
Scan the stem for the verb attached to internal audit. Facilitate, evaluate, advise, benchmark, and review are safe. Decide, approve, set, own, implement, sign, and vote are impairments. That one word usually resolves the question. Next ask who is accountable when the risk materializes. If the answer is internal audit, the role is prohibited. If it is a named manager, an advisory engagement with documented ownership works.
The full lesson (about 2,539 words, 17 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 8
Browse all free CIA Part 1 lessons or jump into free CIA Part 1 practice questions.