Three Lines of Defense risk-governance model
It assigns risk ownership to the first line, challenge to the second, and independent assurance to the third, which is an Authority and Structure design whose control testing produces Evidence a third party can audit.
Institute of Internal Auditors (IIA), 2013
The origin of the framework, as the directory records it. The mark grades the origin, not this page.
Umbrex, Three Lines of Defense risk-governance model
The directory entry this score was read from. Umbrex is a consultancy network; its summary is the reference, not a primary source.
Scored against the twelve cells, it loads three: Authority, Evidence, and Structure. The other nine it leaves to you. Of Composition, Evidence, and Mastery, the three cells that go blank first when an agent enters a workflow, it loads Evidence.
Updated 2020 as the IIA Three Lines Model; scored per the brief's own anchor example.
It describes the The Gated Pipeline shape; the shape page lists it under Described in the literature.
This is not a summary of the framework. Umbrex has one; the link under Sources goes there.
Which decisions may an agent make alone, and who is able to stop it?
What would you show an auditor, and can the system produce it without being asked?
What is the smallest unit that can own a customer outcome end to end?
