AI Governance, Risk & Red Teaming
Strategic · M25 · lesson 25 of 25 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Three Lines of Defense for AI - From SR 11-7 to ISO 42001 Leadership
📖
now learning

Three Lines of Defense for AI - From SR 11-7 to ISO 42001 Leadership

15 min

The Acme Inc internal audit committee asked one question at the May 2026 meeting that nobody had agreed on the answer to: "Who actually owns AI risk?" The Chief Information Officer said the AI Platform team owned it. They built the models, they deployed them, they monitored the dashboards. The Chief Compliance Officer said the AI Compliance Office owned it. They wrote the policy stack, they ran the FRIAs, they signed the conformity packs. The Chief Audit Executive said internal audit owned it. They performed the assurance, they reported to the audit committee, they had the independence. Three executives. Three answers. Three different reporting lines into the boardroom. The audit committee chair closed the meeting with a sentence that triggered a six-month operating-model rebuild: "If three of you believe you own AI risk, then nobody owns it, because each of you is doing pieces the other two should be challenging." Lesson 073 is the L4 leadership rebuild: the Three Lines of Defense (now the Three Lines Model after the IIA's 2020 update) applied to AI in 2026, the origin in SR 11-7 and OCC Bulletin 2011-12, the modern grounding in PRA SS1/23 and EU AI Act Article 17 and ISO 42001 A.3 + A.4, the per-line AI-specific roles and independence tests, the four-pillar operating model the L4 leader actually designs, the RACI matrix that closes the ambiguity Acme exposed, the common failure modes 2026 examiners are already citing, and a worked Acme Inc operating model with reporting lines drawn.

From SR 11-7 to the IIA 2020 Three Lines Model - What the Framework Actually Says

The framework that the audit committee chair invoked at Acme Inc has a 40-year operating history and a 2020 modernisation that most AI governance leaders have not absorbed. Five anchor documents shape the 2026 conversation.

Federal Reserve SR 11-7 (April 2011). Issued as Supervisory Letter 11-7 by the Federal Reserve, SR 11-7 organised Model Risk Management around three pillars (sound development; effective challenge; governance) and implicitly assumed a three-line organisational chassis. The model developer is the first line; the independent validation function is the second line; internal audit is the third line. "Effective challenge", the central concept of Pillar 2, is enforceable only when the validation function is independent of model development. SR 11-7 did not invent Three Lines of Defense, but it codified the operating assumption that every U.S. bank examiner has applied since 2011.

OCC Bulletin 2011-12 (April 2011). Co-released with SR 11-7, the OCC bulletin extended the same three-line assumption to national banks and federal savings associations. The 2023-2025 supervisory updates from the OCC explicitly named the Three Lines of Defense as the expected organisational structure for AI/ML model risk management.

IIA Three Lines of Defense (1999-2013) and the 2020 Three Lines Model update. The Institute of Internal Auditors (IIA) formalised the original Three Lines of Defense (3LoD) framework in the late 1990s and early 2000s as a model for risk and control across the enterprise. In July 2020, the IIA published a major update, "The IIA's Three Lines Model", that re-framed the structure in five ways every AI governance leader needs to absorb. First, the language shifted from "lines of defense" (defensive posture, military metaphor) to "lines" (operational posture, value-creation oriented). Second, the model became principles-based rather than structure-based, accommodating organisations that cannot maintain rigid line separation. Third, the model added the governing body and senior management explicitly as the principal accountability holders. They are not "above" the lines, they are part of the governance structure. Fourth, the model added external assurance providers (auditors, regulators, certification bodies) as recognised contributors to assurance. Fifth, the model emphasised collaboration and alignment across lines while preserving independence and objectivity of the third line. The 2020 update did not replace the operating logic; it sharpened the principles and reduced the risk that "lines of defense" be misread as silos that hand off rather than collaborate. AI governance leaders in 2026 should reference the 2020 Three Lines Model as the modern statement, while acknowledging that supervisory letters (SR 11-7, OCC 2011-12) and many industry policies still use the original 3LoD language.

PRA SS1/23 (May 2023, effective 17 May 2024). The Bank of England Prudential Regulation Authority modernised UK Model Risk Management around five principles. Principle 4, independent model validation, explicitly requires a function with the authority and resources to challenge models throughout the lifecycle. The PRA Dear CEO letters (2024 and 2025) confirmed the framework applies to AI and large language models and that the three-line organisational chassis is the expected operating structure.

EU AI Act Article 17 (QMS) + ISO/IEC 42001:2023 A.3 (leadership) + A.4 (organisational structure) + A.5 (policy). The 2024-2026 regulatory stack codifies the Three Lines Model implicitly through quality-management and AI-management-system obligations. Article 17 requires a documented QMS that includes responsibilities, risk-management procedures, and post-market monitoring, operationalised through a three-line structure in any organisation above modest scale. ISO 42001 A.3 names leadership accountability for the AI management system; A.4 names the organisational structure (including roles, responsibilities, and authorities); A.5 names the policy framework. The certification body for ISO 42001 will assess whether the organisational structure provides independence in the second and third lines.

The 2026 reading: SR 11-7 + OCC 2011-12 + PRA SS1/23 + EU AI Act Article 17 + ISO 42001 A.3 + A.4 all converge on the same operating model: an accountable governing body, a first line that owns and operates AI risk in the business, a second line that provides risk management and compliance oversight, a third line that provides independent assurance to the board, and external assurance providers (auditors, certification bodies) that augment the third line. The L4 governance leader's job is to design this structure for their organisation and defend its independence properties at examination.

First, Second, and Third Line AI Roles in 2026 Detail

Generic 3LoD diagrams do not survive a supervisory conversation about AI. The 2026 examiner asks for the specific roles, the named accountable owners, the independence tests, and the reporting lines. The per-line breakdown below is the level of specificity the L4 governance leader must produce.

First line (1L), operational ownership of AI risk. The 1L for any AI system is the function that owns the model in the business and operates it day-to-day. For an AI-augmented underwriting workflow, the 1L is the underwriting business unit; for an HR resume-screening system, the 1L is Talent Acquisition. Within the 1L, four named roles appear on every Tier 1 AI system: (a) Model owner, the accountable owner per ISO 42001 A.3 and named in the AI use inventory; final accountability for the model's behaviour, performance, and remediation rests with this role. (b) Business sponsor: the executive (typically a VP or SVP) who authorised the spend, owns the business benefits realisation, and represents the model in the AI Governance Committee. (c) Technical lead: the engineering lead responsible for development, fine-tuning, system-prompt design, evaluation suite, and production engineering; typically a Principal or Staff Engineer for high-stakes deployments. (d) Deployment SRE / production engineer: the site-reliability or production engineer responsible for the live system's uptime, monitoring, rollback capability, and incident response. The 1L performs its own self-monitoring, runs its own QA, and self-attests in the model inventory; the 2L does not replace this self-attestation. It challenges and validates it.

Second line (2L), risk management and compliance oversight of AI. The 2L provides independent challenge and oversight without operating the AI system. In 2026, the 2L for AI is a multi-function structure with five named roles. (a) AI Compliance Officer: the named owner of the Article 17 Quality Management System, the AI policy stack (lessons 022-025), the Article 4 literacy programme, the FRIA register, and the conformity assessment evidence. Reports to the Chief Compliance Officer. (b) Model Risk Management (MRM) validator, the independent validation function descended from SR 11-7 Pillar 2. Performs Independent Model Validation (IMV) on every Tier 1 and Tier 2 model. Skills: evaluation methodology, prompt analysis, adversarial testing, statistical validation under non-determinism. Reports to the Chief Risk Officer. The MRM validator is independent of the model developer. This is the load-bearing independence test. (c) Data Protection Officer (DPO), the GDPR Article 37 owner for personal-data processing within AI systems. The DPO operates as 2L for privacy and data-protection nexus, including the GDPR DPIA / EU AI Act FRIA coordination. (d) CISO function for AI security: the security oversight function applied to AI systems, including model security (weights, fine-tunes), data security (training and inference data), supply-chain security (vendor SOC 2 + AI, ML-BOM under CycloneDX 1.7), and adversarial robustness against OWASP LLM Top 10 / OWASP Agentic Top 10 / MITRE ATLAS threats. (e) AI Risk Office (or AI Risk Management Function): the integrating function that runs the AI risk register, aggregates risk signals from MRM + DPO + CISO + AI Compliance, and reports the consolidated AI risk picture to the AI Governance Committee and the board. In many 2026 organisations, the AI Risk Office is the operational arm of the second line and the AI Compliance Officer + MRM + DPO + CISO-for-AI report through or partner with it.

Third line (3L), independent assurance over the AI risk framework. The 3L is internal audit, with two AI-specific roles. (a) AI internal audit specialist: an internal auditor with AI competence (model risk, evaluation methodology, AI policy stack, regulatory cross-walk) who plans and executes assurance engagements over the operation of the AI risk framework. The 3L does not validate models (that is the 2L MRM job); the 3L assures that the validation function operates with independence, sound methodology, and appropriate coverage. (b) Audit Committee reporting line, the 3L reports findings to the Audit Committee of the Board, not to executive management. This independence-of-reporting is the load-bearing independence test for the third line. External assurance providers complement the 3L. ISO/IEC 42001 certification body audits provide external assurance against the AIMS; SOC 2 + AI (and the emerging SOC for AI) provides assurance to vendors and customers; statutory auditors increasingly include AI controls in scope; the EU AI Act notified-body conformity assessment serves as the regulator-recognised external assurance for Article 43 routes. In 2026, the AI internal audit team typically uses external assurance reports as evidence within its own assurance plan, not as a substitute for the 3L's own work.

Reporting lines that are load-bearing for independence. The L4 governance leader must verify three reporting lines on the organisational chart. 1L reports to the business unit head (and ultimately the CEO or CIO depending on the function). 2L reports to the Chief Risk Officer (CRO) and/or Chief Compliance Officer (CCO), not to the CIO or any 1L executive. If AI compliance reports to the CIO, the independence test fails, the CIO is the executive accountable for delivery, and compliance reporting to delivery is the classic 2L breach. 3L reports to the Audit Committee of the Board, with a dotted line to the CEO for administrative purposes only. If internal audit reports to the CFO or CEO substantively, the independence test fails. The 2026 examiner reads the organisational chart for these three reporting lines as the first check on the operating model.

Independence Tests Per Line and the AI-Specific Twist

Independence is the load-bearing property of the Three Lines Model. The 2020 IIA update softened the language but did not soften the independence requirement for the third line and the structural separation for the second line. The L4 governance leader applies three independence tests and addresses one AI-specific twist that did not exist before 2024.

Test 1, 1L cannot review its own work. The model owner cannot perform the model's independent validation. The technical lead cannot sign off on the conformity assessment. The deployment SRE cannot certify the post-market monitoring report. Self-attestation is part of the 1L role, but self-attestation is challenged by the 2L; without that challenge, every model is "fine" until an external event proves otherwise. The Acme Inc rebuild discovered that the AI Platform team had been performing both development and validation on its own models for three years; the 2026 reorganisation moved validation to a separate MRM team reporting to the CRO.

Test 2, 2L cannot have built the model it validates. The MRM validator did not write the training pipeline, did not design the system prompt, did not select the evaluation suite, and did not approve the production deployment. The independence breach is operationally subtle: a validator who consulted on the model design, even informally, is no longer independent of that model. The 2026 supervisory expectation is documented separation: validation team members must not have contributed to the model's development beyond ordinary cross-team collaboration that is logged and assessed for independence implications. The AI Risk Office, if it functions as both an advisory body and a validation body, must internally separate the advisory role from the validation role with documented Chinese walls.

Test 3, 3L cannot report into 1L or 2L. Internal audit reports to the Audit Committee of the Board. The Chief Audit Executive (CAE) reports administratively to the CEO but substantively to the Audit Committee chair, with direct access to the chair and the ability to escalate findings without management intermediation. If internal audit reports to the CRO (a 2L role) or to the CIO (a 1L role), the structure has collapsed two lines into one and the third-line independence does not exist. The AI internal audit specialist within the 3L function reports through the CAE chain, not into the AI Risk Office or AI Compliance.

The AI-specific twist, when the AI system itself becomes part of the assurance stack. 2026 introduced a structural challenge that did not exist in pre-AI 3LoD: the model itself can be deployed as an oversight tool. LLM-as-judge architectures, automated red-team agents, AI-powered evidence-gathering tools, and ML-based monitoring systems are increasingly used in the 2L (independent validation) and 3L (internal audit) functions. This creates a 3LoD-blurring risk with three concrete failure patterns. Pattern A, same vendor judges itself. Using Claude 4 as a judge model to evaluate a Claude 4 production deployment creates within-vendor circularity; the judge inherits the same training data, the same alignment biases, and the same blindspots. The 2026 mitigation is cross-vendor judging (Claude judging GPT, GPT judging Claude, Gemini judging both) plus human spot-check. Pattern B - AI tooling without independent validation of the tool. An MRM team using an AI-powered evidence-gathering tool that has not been independently validated has imported a new dependency that itself requires the same 3LoD treatment. The judge model and the red-team agent are first-class models that appear in the inventory and undergo validation. Pattern C, overreliance reduces human challenge. If the MRM team accepts AI-judge outputs without sampling and human review, the effective-challenge property erodes, the 2L becomes a pipeline rather than a function. The 2026 control is documented human override authority, sampled review of AI-judge outputs at defined rates, and periodic blind comparison of AI judging against human judging for drift detection. The L4 governance leader must explicitly address these three patterns in the 2L and 3L operating manuals; the supervisory letters do not yet name them, but examiners are asking about them in 2026 conversations.

The Four-Pillar AI Governance Operating Model and the Lifecycle RACI

The L4 leader who answers "who owns AI risk?" produces a four-pillar operating model that integrates governance bodies, policies, processes, and people. The four pillars are not interchangeable; each one is necessary, and the Three Lines Model runs through all four.

Pillar 1 - Governance bodies. Three bodies anchor the operating model. (a) AI Governance Committee (AIGC): the cross-functional executive body chaired by the AI Officer (or CRO in some banks), with members from Legal, Compliance, Risk, Security, Engineering, HR, Procurement, and business units. The AIGC reviews and approves Tier 1 AI deployments, sets the AI risk appetite (lesson 074), receives consolidated AI risk reporting, and escalates to the board. (b) Board AI Subcommittee: a standing subcommittee of the board (sometimes a dedicated AI committee, sometimes incorporated into the existing Risk Committee or Audit Committee) that holds the board-level accountability for AI strategy, AI risk appetite, AI ethics, and material AI incidents. (c) AI Risk Office: the operational 2L function that runs the AI risk register, supports the AIGC with analysis, and serves as the integrating layer between the named 2L roles. Some organisations call this the AI Centre of Excellence and split it operationally from the AI Risk Office; in others, the two are merged. The L4 leader chooses the structure that fits the organisation's scale and risk profile.

Pillar 2 - Policies and standards. The AI policy stack (lessons 022-025), Enterprise AI Acceptable Use Policy, Generative AI Use Policy, AI Vendor Risk Policy, AI Incident Response Policy, provides the rule-set the 1L operates within and the 2L oversees. The policy stack is layered with standards (technical specifications), procedures (operational steps), and guidelines (recommended practices). The board approves the top-level policies; the AIGC approves standards; the named owners approve procedures and guidelines. Each policy names its owner, its review cycle, and its escalation path.

Pillar 3 - Processes. Four core processes drive AI lifecycle risk management. (a) AI intake and FRIA: the entry point where every proposed AI use enters the inventory, receives a risk tier, and triggers a Fundamental Rights Impact Assessment for high-risk Annex III systems (Article 27). (b) Independent Model Validation (IMV), the 2L MRM process that validates Tier 1 and Tier 2 systems before deployment and on substantial modification. (c) Red-team and adversarial testing: the structured adversarial evaluation against OWASP LLM Top 10, OWASP Agentic Top 10, and MITRE ATLAS threats, run by the 2L (with internal red-team or commissioned external red-team). (d) AI incident response: the operational process triggered by an AI incident, with Article 73 notification within 15 days for serious incidents, root-cause analysis, and remediation tracking. Each process names the 1L, 2L, and 3L roles involved.

Pillar 4 - People and culture. The Three Lines Model only functions if the people in each line have the skills and authority to perform their role. The L4 leader designs an AI literacy programme (Article 4) that covers all roles, a hiring profile for each 2L and 3L role, and an external advisory bench for capability gaps the organisation cannot build internally fast enough. Culture, the norm that effective challenge is welcomed, not punished, is the load-bearing property; without it, every other pillar collapses into compliance theatre.

The lifecycle RACI matrix. The matrix below shows responsibility (R), accountability (A), consulted (C), and informed (I) across the AI lifecycle for the named roles. Six lifecycle stages: Intake, FRIA / risk tiering, IMV, Deployment approval, Post-market monitoring, Decommissioning / retirement.

Intake: R = Business sponsor (1L); A = Model owner (1L); C = AI Compliance Officer (2L), AI Risk Office (2L); I = AIGC, Internal audit (3L).

FRIA / risk tiering: R = AI Compliance Officer (2L); A = AI Officer / AIGC chair; C = Model owner (1L), DPO (2L), Legal; I = Board AI Subcommittee for Tier 1.

IMV: R = MRM validator (2L); A = Head of MRM (2L); C = Model owner (1L), Technical lead (1L); I = AIGC, AI Compliance Officer, Internal audit (3L).

Deployment approval: R = Model owner (1L); A = AIGC for Tier 1, AI Officer for Tier 2, Business sponsor for Tier 3/4; C = AI Compliance Officer (2L), MRM (2L), CISO function (2L), Legal; I = Board AI Subcommittee for Tier 1, Internal audit (3L).

Post-market monitoring: R = Deployment SRE (1L), Technical lead (1L); A = Model owner (1L); C = MRM (2L), AI Risk Office (2L); I = AIGC, Internal audit (3L).

Decommissioning / retirement: R = Model owner (1L); A = Business sponsor (1L); C = AI Compliance Officer (2L), AI Risk Office (2L); I = AIGC, Internal audit (3L).

The RACI closes the ambiguity the Acme Inc audit committee chair exposed. Each lifecycle stage has exactly one accountable role; consulted roles include the 2L challengers; informed roles include the 3L assurance function and the governance bodies. The L4 leader publishes the RACI as part of the AI Risk Framework document and references it in the AI Policy stack.

Common Failure Modes in 2026 AI Programmes and the Capability Buildout

The 2026 examiner conversations (Fed, OCC, PRA, Commission, certification bodies) have surfaced four recurring failure modes in 3LoD implementations for AI. The L4 leader designs the operating model with explicit controls for each.

Failure mode 1 - MRM team built the model (independence breach). The most common 2026 finding. An organisation has an MRM function on paper, but the same team that built the AI evaluation suite is performing the independent validation. The independence test fails. The remedy: separate the development and validation teams structurally, document the separation in the AI Risk Framework, and pre-clear cross-team contribution against an independence policy. At the Acme Inc rebuild, the AI Platform team retained its evaluation engineering function (1L self-assessment) while a separate MRM team of four was created in the AI Risk Office (2L) reporting to the CRO.

Failure mode 2 - AI compliance reports to the CIO (reporting-line breach). The second most common finding. The AI Compliance Officer reports administratively and substantively to the CIO, who is the 1L executive accountable for AI delivery. Compliance challenge to a CIO-reporting boss collapses under pressure. The remedy: AI compliance reports to the Chief Compliance Officer (or to the CRO, depending on the organisation's structure), with a dotted line to the CIO for operational coordination. The substantive reporting line carries the independence weight. The supervisory expectation is unambiguous: the 2L reports to a risk or compliance executive, not to a delivery executive.

Failure mode 3 - Internal audit has no AI competence (3L capability gap). Internal audit teams in 2026 are scrambling for AI competence. An audit team that does not understand model evaluation, prompt-as-code, RAG validation, or the OWASP LLM Top 10 cannot perform effective assurance over the AI risk framework. The audit committee asks "did you audit the AI controls?" and the answer is "we tested whether the documents exist, but we did not test whether the controls work." The 2026 supervisory expectation is that the 3L either has trained AI auditors in-house or commissions external co-source partners with AI competence. The Acme Inc remedy was a 1-person AI internal audit specialist hire plus a rotational engagement with a Big 4 firm's AI assurance practice for capacity and skills augmentation.

Failure mode 4 - Vendor SOC 2 + AI not reviewed independently. Many 2026 organisations have outsourced critical AI components (foundation models, evaluation tooling, vector databases, judge models) to vendors. The vendor produces a SOC 2 + AI report, an ISO 42001 certificate, or an AI-specific attestation. The organisation accepts the vendor report at face value and treats the controls as covered. The independent-assurance principle is breached when the 3L internal audit does not independently assess the relevance, scope, and limitations of the vendor's attestation. The remedy: a vendor assurance review by the 3L that maps the vendor's attestation scope against the organisation's own controls, identifies the assurance gaps, and recommends compensating controls or further diligence. The AI Vendor Risk Policy (lesson 024) names this review as a required process.

Three-line capability buildout plan. The L4 leader produces a capability buildout plan with three components. (a) Skills training: Article 4 literacy at three depths: basic literacy for all staff, role-specific deeper training for 1L technical and business roles, and advanced training for 2L and 3L oversight functions. The 2L MRM team requires training in evaluation methodology, prompt analysis, statistical validation under non-determinism, OWASP LLM Top 10, OWASP Agentic Top 10, MITRE ATLAS, and the regulatory cross-walk (EU AI Act, NIST AI RMF, ISO 42001, SR 11-7). The 3L AI auditor requires the same training plus internal audit methodology and IIA assurance standards. (b) Hiring profile: the 2L MRM hiring profile combines model-risk experience (banking MRM, model validation, statistical modelling) with AI experience (ML engineering, evaluation, prompt engineering); the cross-skill profile is scarce in 2026, and the hiring plan must account for 6-12 month time-to-fill. The 3L AI auditor hiring profile combines internal audit experience with AI competence; some organisations rotate AI engineers into audit for fixed terms to build capability. (c) External advisory bench: a roster of pre-cleared external advisors (law firms with AI practices, consulting firms with AI assurance specialisations, academic experts for fundamental-rights and bias questions, technical specialists for adversarial testing) that the 2L and 3L can call into engagements without procurement delay. The L4 leader establishes the bench, runs annual relationship reviews, and tracks utilisation.

Acme Inc Worked Operating Model and the Regulatory Cross-Walk

Concrete operating numbers anchor the operating model. The Acme Inc rebuild that followed the May 2026 audit committee meeting produced the structure below.

Governance bodies. AI Governance Committee chaired by the newly-appointed Chief AI Officer (CAIO), 12 voting members from Compliance, Risk, Security, Legal, HR, Procurement, Engineering, and four business units, meeting monthly with an emergency-convene clause for Tier 1 incidents. Board AI Subcommittee, three independent directors plus the audit committee chair as observer, meeting quarterly with the CAIO and CRO. AI Risk Office, newly created reporting to the CRO, headed by an SVP-level AI Risk Officer.

2L staffing. AI Risk Office at 6 FTEs: AI Risk Officer (SVP), AI Compliance Officer (VP, Article 17 QMS owner), AI Policy and Standards lead, AI Risk register operations lead, and 2 AI Risk analysts. Separate MRM team at 4 FTEs (sitting alongside the AI Risk Office in the 2L but reporting through the CRO via the Head of MRM): Head of MRM for AI, 2 Senior Validators, 1 Validator. DPO and CISO-for-AI are existing roles with AI scope explicitly added to their charters. The AI Risk Office and the MRM team coordinate but do not merge, the structural separation preserves the IMV independence test (MRM cannot have built the model, and the AI Risk Office's advisory work does not contaminate the validation work).

3L staffing. 1 AI internal audit specialist in the Internal Audit function (reports to the CAE; CAE reports to the Audit Committee). Plus a rotational engagement with a Big 4 firm's AI assurance practice, contracted for 200-400 hours per year for skills augmentation, with the option to scale on incident.

Reporting lines diagrammed. 1L (business units, AI Platform engineering, model owners) reports to business heads and ultimately to the CEO via the CIO and business CEOs. 2L (AI Risk Office, MRM, DPO, CISO function for AI, AI Compliance Officer) reports to the CRO and CCO. 3L (AI internal audit specialist) reports through CAE to the Audit Committee. The three reporting paths converge only at the board level, preserving structural independence at the executive layer. The supervisory letter response Acme could write in 2026, and could not write in 2025, is "Three Lines of Defense for AI is implemented with documented independence at every reporting level."

Regulatory cross-walk. The same operating model satisfies multiple supervisory frameworks simultaneously. EU AI Act: Article 9 (risk management) is operationalised by the AI Risk Office's risk register and the IMV process; Article 17 (QMS) is owned by the AI Compliance Officer and supported by the AI Policy stack; Article 26 (deployer obligations) is operationalised by the 1L post-market monitoring; Article 27 (FRIA) is operationalised by the FRIA process under 2L oversight; Article 43 (conformity assessment) is managed by the AI Compliance Officer; Article 73 (incident notification) is operationalised by the AI Incident Response Policy. NIST AI RMF: Govern 1.1 (board accountability), Board AI Subcommittee; Govern 2.1 (roles and responsibilities), the RACI; Govern 3.1 (workforce competence), the AI literacy programme; Govern 4.1 (organisational commitment), the AIGC; Govern 5.1 (legal and regulatory compliance), the AI Compliance Officer; Govern 6.1 (engagement), the external advisory bench and stakeholder process. ISO 42001: A.3 (leadership), the CAIO and the AIGC; A.4 (organisational structure), the 3LoD operating model with reporting lines; A.5 (policies for AI), the AI Policy stack. SR 11-7 + OCC 2011-12: three pillars satisfied by the 1L development, 2L MRM validation, and 3L internal audit assurance, with the model inventory expansion for LLM/agent components (lesson 067). PRA SS1/23: five principles satisfied by the same operating model with the explicit tiering and mitigants documentation.

Penalty exposure. A 3LoD failure under SR 11-7 typically arrives as a Matter Requiring Attention (MRA), escalating to MRIA and consent-order territory. Under the EU AI Act, Article 17 QMS failures and Article 26 deployer-obligation failures fall under Article 99(3), administrative fines up to €15 million or 3% of worldwide annual turnover, whichever is higher. Article 99(5), €7.5M / 1%, applies to misleading information supplied to authorities during a 3LoD assessment. The PRA SS1/23 escalation pathway runs through Section 166 skilled-person review under FSMA, which is expensive and public. The convergence of regulator pressure means the L4 governance leader who builds the operating model once, with documented independence and capability across all three lines, is positioned for every supervisory conversation simultaneously. The leader who relies on three different VPs giving three different answers to "who owns AI risk?" is positioned for a 2026 finding.

Key Takeaways

  • The IIA's July 2020 Three Lines Model is the modern statement of what SR 11-7 (April 2011), OCC Bulletin 2011-12, and PRA SS1/23 (May 2023, effective 17 May 2024) all assume operationally: an accountable governing body, a first line that owns and operates AI risk, a second line that provides risk management and compliance oversight, a third line that provides independent assurance, and external assurance providers that augment the third line. The 2020 update sharpened principles around collaboration and external assurance without softening the independence requirement for the third line.
  • First line (1L) for AI in 2026 has four named roles per Tier 1 system: Model owner (ISO 42001 A.3 accountable owner), Business sponsor (executive authoriser), Technical lead (development and evaluation engineering), Deployment SRE (production and monitoring). The 1L self-attests; the 2L challenges.
  • Second line (2L) for AI is a multi-function structure with five named roles: AI Compliance Officer (Article 17 QMS owner), MRM validator (Independent Model Validation, descended from SR 11-7 Pillar 2), DPO (GDPR Article 37 nexus), CISO function for AI security, AI Risk Office (integrating function with the AI risk register). The 2L reports to the CRO and CCO, not to the CIO.
  • Third line (3L) for AI is internal audit with AI competence: an AI internal audit specialist plus external assurance providers (ISO 42001 certification body, SOC 2 + AI auditor, statutory auditors, notified bodies for conformity assessment). The 3L reports to the Audit Committee of the Board, not to executive management. The 3L assures the operation of the framework, not the models themselves.
  • Three independence tests govern the design: 1L cannot review its own work (self-attestation is challenged by 2L); 2L cannot have built the model it validates (MRM separation from AI Platform development); 3L cannot report to 1L or 2L (Audit Committee reporting line is load-bearing). The 2026 examiner reads the org chart first.
  • The AI-specific independence twist: when AI tooling (LLM-as-judge, automated red-team, ML-based monitoring) is deployed in the 2L or 3L, three failure patterns appear: same-vendor circularity, AI tooling without its own validation, and overreliance reducing human challenge. The 2026 mitigations are cross-vendor judging, judge-model inventory and validation, and documented human override authority with sampled review.
  • The four-pillar operating model integrates everything: (1) governance bodies (AIGC + Board AI Subcommittee + AI Risk Office); (2) policies and standards (the AI Policy stack from lessons 022-025); (3) processes (intake/FRIA, IMV, red-team, incident response); (4) people and culture (AI literacy + role design + RACI + external advisory bench). The lifecycle RACI closes the accountability ambiguity.
  • Four 2026 failure modes recur in examiner conversations: (1) MRM team built the model (independence breach); (2) AI compliance reports to the CIO (reporting-line breach); (3) internal audit has no AI competence (3L capability gap); (4) vendor SOC 2 + AI not reviewed independently. The Acme Inc rebuild produced a 6-person AI Risk Office plus a 4-person separate MRM team in 2L, a 1-person AI internal audit specialist in 3L plus rotational Big 4 augmentation, with all three reporting lines diagrammed and converging only at the board level.
  • One operating model satisfies multiple frameworks. EU AI Act Articles 9, 17, 26, 27, 43, 73 + NIST AI RMF Govern 1.1/2.1/3.1/4.1/5.1/6.1 + ISO 42001 A.3 + A.4 + A.5 + SR 11-7 three pillars + OCC 2011-12 + PRA SS1/23 five principles all map to the same Three Lines Model with documented independence. Article 99(3) penalty exposure is €15M / 3% for Article 17 QMS + Article 26 deployer failures; Article 99(5) is €7.5M / 1% for misleading information during 3LoD assessment; SR 11-7 escalation runs MRA → MRIA → consent order; PRA SS1/23 escalation runs through FSMA Section 166 skilled-person review.