The Three Lines of Defense - Office of Internal Audit (2024)

The Three Lines of Defense - Office of Internal Audit (1)

The three lines of defense model provides guidance for effective risk management and governance. Each of the three lines plays a distinct role with the University’s control environment.

First Line of Defense – Management

The first line of defense lies with the business and process owners. Operational management is responsible for maintaining effective internal controls and for executing risk and control procedures on a day-to-day basis. This consists of identifying and assessing controls and mitigating risks. Additionally, business and process owners guide the development and implementation of internal policies and procedures and ensure activities are consistent with University goals and objectives. Mid-level managers may design and implement detailed procedures that serve as controls and supervise execution of those procedures by their employees.

Second Line of Defense – Risk Management and Compliance

The second line supports management to help ensure risk and controls are effectively managed. Management establishes various risk management and compliance functions to help build and/or monitor the first line-of-defense controls. Typical functions in this second line of defense include:

  • “A risk management function (and/or committee) that facilitates and monitors the implementation of effective risk management practices by operational management and assists risk owners in defining the target risk exposure and reporting adequate risk-related information throughout the organization.
  • A compliance function to monitor various specific risks such as noncompliance with applicable laws and regulations. In this capacity, the separate function reports directly to senior management.
  • A controllership function that monitors financial risks and financial reporting issues.”

Management establishes these functions to ensure the first line of defense is properly designed, in place, and operating as intended. The second line of defense serves an important purpose but because of their management function, they cannot be completely independent.

Third Line of Defense – Internal Audit

The third line of defense provides assurance to senior management and the board that the first and second lines’ efforts are consistent with expectations. The main difference between this third line of defense and the first two lines is its high level of organizational independence and objectivity. Internal Audit may not direct or implement processes, but they can provide advice and recommendations regarding processes. Additionally, Internal Audit may support enterprise risk management but may not implement or perform risk management other than inside of its own function. Internal auditors accomplish their objectives by bringing a systematic approach to evaluating and improving the effectiveness of risk management, control, and governance processes.

External Auditors

External auditors are responsible for expressing an opinion on the fairness (accuracy within a degree of materiality) of the financial statements in conformity with certain accounting standards. Additionally, external auditors may provide assurance to the Board of Trustees regarding institutional compliance requirements (such as Title IV funding of financial aid).

For additional information regarding the Three Lines of Defense, see IIA Position Paper: The Three Lines of Defense in Effective Risk Management and Control (PDF).

References:

COSO’s Take on the Three Lines of Defense

Leveraging COSO across the Three Lines of Defense, July 2015

The Three Lines of Defense - Office of Internal Audit (2024)
Top Articles
Airbnb Automation: 7 Ways To Autopilot Your Business | iGMS
How to Track a Solana Wallet | BlockSec Blog
Antisis City/Antisis City Gym
Caesars Rewards Loyalty Program Review [Previously Total Rewards]
Rek Funerals
360 Training Alcohol Final Exam Answers
Obituaries
10000 Divided By 5
Corpse Bride Soap2Day
Www Thechristhospital Billpay
Wmlink/Sspr
Cube Combination Wiki Roblox
The Weather Channel Facebook
Cvs Learnet Modules
104 Whiley Road Lancaster Ohio
Unlv Mid Semester Classes
What is Rumba and How to Dance the Rumba Basic — Duet Dance Studio Chicago | Ballroom Dance in Chicago
Puretalkusa.com/Amac
Who called you from +19192464227 (9192464227): 5 reviews
Never Give Up Quotes to Keep You Going
Greenville Sc Greyhound
[PDF] PDF - Education Update - Free Download PDF
Baldur's Gate 3: Should You Obey Vlaakith?
Ihub Fnma Message Board
A Christmas Horse - Alison Senxation
Weathervane Broken Monorail
Craigslist Pasco Kennewick Richland Washington
Dhs Clio Rd Flint Mi Phone Number
Keshi with Mac Ayres and Starfall (Rescheduled from 11/1/2024) (POSTPONED) Tickets Thu, Nov 1, 2029 8:00 pm at Pechanga Arena - San Diego in San Diego, CA
Ordensfrau: Der Tod ist die Geburt in ein Leben bei Gott
5 Star Rated Nail Salons Near Me
25Cc To Tbsp
Mia Malkova Bio, Net Worth, Age & More - Magzica
Craigslist Maryland Baltimore
NIST Special Publication (SP) 800-37 Rev. 2 (Withdrawn), Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
Shiftwizard Login Johnston
Beth Moore 2023
Ni Hao Kai Lan Rule 34
House Of Budz Michigan
KITCHENAID Tilt-Head Stand Mixer Set 4.8L (Blue) + Balmuda The Pot (White) 5KSM175PSEIC | 31.33% Off | Central Online
Telegram update adds quote formatting and new linking options
Myql Loan Login
Hellgirl000
Karen Wilson Facebook
Southwest Airlines Departures Atlanta
Youravon Com Mi Cuenta
Unit 11 Homework 3 Area Of Composite Figures
Hdmovie2 Sbs
bot .com Project by super soph
Pronósticos Gulfstream Park Nicoletti
San Pedro Sula To Miami Google Flights
211475039
Latest Posts
Article information

Author: Jonah Leffler

Last Updated:

Views: 6297

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Jonah Leffler

Birthday: 1997-10-27

Address: 8987 Kieth Ports, Luettgenland, CT 54657-9808

Phone: +2611128251586

Job: Mining Supervisor

Hobby: Worldbuilding, Electronics, Amateur radio, Skiing, Cycling, Jogging, Taxidermy

Introduction: My name is Jonah Leffler, I am a determined, faithful, outstanding, inexpensive, cheerful, determined, smiling person who loves writing and wants to share my knowledge and understanding with you.