AI for Risk, Compliance & Audit
Aware · M24 · lesson 24 of 30 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
The Three Lines Model and AI: Where Oversight Fits
📖
now learning

The Three Lines Model and AI: Where Oversight Fits

10 min

Why the Three Lines Model Matters

Clarify where AI governance responsibility lies across the three lines of defense and how oversight functions fit into the model.

At the Awareness level, your primary goal is to build a solid conceptual foundation. You do not need to operate AI systems yourself at this stage—but you must understand what they do, how they work at a high level, and why they matter for oversight. This knowledge will be the bedrock upon which all subsequent levels build.

This lesson is designed to be accessible to professionals at all experience levels while providing the depth needed for practical application. Whether you are encountering these concepts for the first time or building on existing knowledge, the material ahead will strengthen your ability to navigate AI governance challenges with confidence and competence.

Why This Matters for Risk, Compliance, and Audit

Understanding concepts in the abstract is valuable, but the real test is whether you can apply them in professional practice. The Three Lines Model directly shapes how oversight functions divide responsibility for AI—who owns systems, who monitors them, and who provides independent assurance.

As you continue through this credential program, you will build on the foundation established in this lesson. Each subsequent lesson adds new dimensions to your understanding and expands your capability to work effectively with AI in oversight roles.

Core Concepts

The Three Lines Model, updated by the Institute of Internal Auditors in 2020, provides a powerful framework for structuring AI oversight responsibilities. Understanding how each line applies to AI governance helps organizations avoid gaps, overlaps, and accountability confusion.

First Line: AI Users and Operators

The first line comprises the business units and functions that directly use AI tools and systems. In the AI context, first-line responsibilities include using AI tools in accordance with organizational policies, performing initial quality checks on AI outputs before incorporating them into work products, documenting AI usage and verification steps, reporting anomalies or concerns about AI performance, and maintaining competency in AI tools relevant to their roles. First-line ownership is critical because it ensures that the people closest to AI operations take responsibility for day-to-day quality and compliance.

Second Line: AI Risk and Compliance Functions

Second-line functions provide oversight, guidance, and challenge to first-line AI activities. This includes developing AI policies, standards, and guidelines, monitoring compliance with AI governance requirements, providing expertise on AI risk assessment and mitigation, supporting AI-related training and awareness programs, and reporting on AI risk posture to senior management. The second line does not use AI directly in most cases—instead, it ensures that first-line AI use is controlled, compliant, and aligned with organizational risk appetite.

Third Line: Internal Audit of AI

Internal audit provides independent assurance over the entire AI governance framework. Third-line responsibilities include auditing the design and operating effectiveness of AI controls, assessing whether AI governance policies are adequate and being followed, evaluating the reliability and integrity of AI-related reporting, testing AI model governance and validation processes, and providing independent opinions on AI risk management effectiveness. The third line's independence is especially valuable in AI governance because AI adoption can create strong incentives (efficiency gains, competitive advantage) that may bias first- and second-line assessments.

Coordination Between Lines

Effective AI governance requires clear coordination between all three lines. This means establishing regular communication channels for AI-related risk information, defining escalation procedures for AI incidents or concerns, avoiding duplicative oversight that burdens AI users without adding value, and ensuring that lessons learned from audits inform first- and second-line practices. The governing body (board or equivalent) sets the tone from the top, establishing expectations for AI governance and ensuring that all three lines have the resources and authority needed to fulfill their roles effectively.

Practical Use Cases

Understanding concepts in the abstract is valuable, but the real test is whether you can apply them in professional practice. This section bridges the gap between theory and application with concrete scenarios drawn from oversight work.

If you are in compliance (second line):

Your responsibilities with regard to a vendor risk-scoring AI system:

  • Monitor that the finance first line is using the system appropriately (scores are being reviewed, high-risk vendors are investigated, overrides are documented)
  • Assess whether the system complies with regulations (are vendor decisions made fairly? Is the system transparent? Do vendors have a right to explanation?)
  • Recommend policies (bias monitoring required? What escalation process? How often is retraining needed?)
  • Escalate if material governance gaps exist

If you are in internal audit (third line):

Your responsibilities with regard to the same system:

  • Conduct an audit testing the control effectiveness of the system
  • Verify that first line is monitoring accuracy and bias
  • Verify that second line is monitoring appropriately
  • Provide independent assessment of governance effectiveness
  • Report findings and recommendations to management and audit committee

The following examples illustrate how the concepts from this lesson play out in real-world oversight scenarios. Each example is designed to help you recognize similar situations in your own work and respond with appropriate professional judgment.

Example 1: Second-Line Escalation of AI Risk

Scenario: The risk function (second line) monitors that business functions are governing AI appropriately. They discover: a fraud detection system is operating without bias monitoring.

Second-line response: Meet with the first-line business unit: "Your fraud detection system lacks bias monitoring. We require: stratified performance reports by vendor type, geography, and department, generated monthly. Due to us by [date]."

First-line response: "Understood. We will implement monthly bias reporting."

Follow-up: In 30 days, second line receives the first report and reviews it. If adequate bias monitoring is now in place, the issue is resolved. If the report shows bias (certain groups are flagged at higher rates), second line escalates: "Bias is evident in the system. We require: [specific actions to mitigate bias] by [date], OR discontinue use of the system."

Example 2: Third-Line Audit of AI Governance

Scenario: Internal audit includes, in the annual audit plan, an audit of AI systems in the organization.

Audit scope: Identify all AI systems in use (inventory). For each system, evaluate: Is it governed appropriately? Are controls in place? Test specific systems: Are they performing as intended? Is bias being monitored? Are escalations happening? Assess: Is the second line monitoring effectively? Are there governance gaps?

Audit findings (example):

  1. "Control risk assessment system lacks documented accuracy monitoring. Risk: The organization may rely on inaccurate risk scores. Recommendation: Implement quarterly accuracy testing."
  2. "Shadow AI identified: Compliance team is using ChatGPT to analyze internal documents without data security review. Risk: Proprietary information may be exposed. Recommendation: Prohibit use of public AI services for proprietary information without security approval; provide approved internal alternative."

Reporting: Findings are communicated to management for corrective action. Audit committee is briefed on material AI governance gaps. Follow-up is scheduled to verify corrective actions were taken.

Practical Alignment Exercise

Map your organization's current AI activities against the Three Lines Model. For each significant AI use case, identify who serves as first line (users), second line (oversight), and third line (assurance). Where you find gaps—particularly missing second- or third-line coverage—you have identified governance vulnerabilities that should be addressed as a priority.

Anti-Patterns

Anti-pattern 1: Unclear role responsibility for AI governance

The claim: "No one is specifically responsible for AI governance."

The risk: Without clear accountability, governance gaps go unaddressed. The three lines model clarifies: first line owns systems, second line monitors, third line audits.

Anti-pattern 2: Second line failing to escalate adequately

The claim: "The first line said they would improve AI governance; we'll monitor next quarter."

The risk: Material governance gaps should not be left unresolved for extended periods. If first line does not implement improvements, second line must escalate.

Anti-pattern 3: Audit operating without escalation authority

The claim: "Audit found that the AI system has significant bias, but we don't have authority to stop it."

The risk: Audit should escalate material findings to management and the audit committee. Governance structure should support audit escalation. If audit finds material risk and management doesn't address it, the board must be informed.

Anti-pattern 4: AI governance seen only as IT responsibility

The claim: "AI governance is IT's job."

The risk: The three lines model clarifies that multiple lines have responsibility. First line owns systems, second line monitors, third line audits. IT manages the technology, but governance spans across functions.

Human Judgment Checkpoints

For an AI system, clarify:

  1. Which line owns it? (First line business function)
  2. Who is responsible for monitoring in the second line? (Compliance, risk, or data governance?)
  3. Who audits it in the third line? (Internal audit)
  4. What is the escalation path? (First to second, second to third, third to board if necessary)
  5. Are roles clear and documented? (People know their responsibility)

Responsible AI Considerations

Governance documentation should clarify:

  • Which line owns the system
  • What each line's responsibilities are
  • How escalation works
  • Who has authority to override or discontinue the system
  • Reporting structure to the board if material issues arise

Practice and Reflection

  1. Your organization's structure: In the three lines model, which line are you in? What are your responsibilities with respect to AI?
  2. Specific system: For an AI system in your organization, identify: which line owns it, which line monitors it, which line audits it. Are roles clear?
  3. Escalation clarity: If you identified a material AI governance issue, where would you escalate it? Would the escalation path be clear?
  4. Board visibility: If a material AI risk were identified, how would it reach the board? Is there a clear reporting structure?

As you complete this lesson, keep these guiding principles in mind for immediate application:

  • Start with awareness: Begin observing where AI is currently being used—or proposed for use—in your organization. You do not need to evaluate it yet; simply notice it.
  • Build your vocabulary: Use the terminology from this lesson precisely. Clear language prevents misunderstandings that lead to governance gaps.
  • Ask questions: When colleagues mention AI, ask clarifying questions: What type of AI? What data does it use? How are outputs verified? Your questions alone improve organizational awareness.
  • Document what you learn: Keep brief notes on AI-related observations and questions. This habit will serve you well in later levels when formal documentation becomes a professional requirement.

Key Takeaways

  • The three lines model clarifies AI governance responsibility. First line owns systems; second line monitors; third line audits.
  • Each line has distinct responsibilities. Overlap and ambiguity should be clarified and documented.
  • Escalation is essential. If one line identifies an issue, they escalate appropriately.
  • Accountability for AI governance rests across multiple functions, not with IT alone.
  • The board should be informed of material AI risks. Third line audit plays a key role in escalation.

Frequently Asked Questions

Which line is responsible for governing an AI system? All three play a role: the first line (business users) owns and operates the system, the second line (risk and compliance) monitors and challenges its use, and the third line (internal audit) provides independent assurance over the governance framework.

What happens if a material AI risk is identified but not addressed? Escalation is essential. If the first line does not implement improvements, the second line escalates; if management does not act on audit findings, the board must be informed.

Is AI governance just IT's job? No. IT manages the technology, but governance responsibility spans multiple functions across all three lines.