Enterprise risk & controls · Core
Three lines model
Also called: three lines of defence, three lines of defense
ELI5
A governance model distinguishing management, risk oversight and independent assurance roles.
Used in conversation
“Add three lines model to the risk register with an owner and mitigation.”
Pitch context
You will see “Three lines model” in board papers, contracts, policies, risk registers and compliance reports when the discussion reaches enterprise risk & controls.
Why it matters: In enterprise risk & controls, a loose definition can change rights, obligations, approval, disclosure or enforceability.
Caution
Meaning, enforceability and required process vary by jurisdiction and agreement; this definition is not legal advice.
Sources & evidence · 3
Direct term-level sources and supporting source families.
- OECD — G20/OECD Principles of Corporate Governance 2023Direct source · institutional · checked 2026-08-16
- National Institute of Standards and Technology — Computer Security Resource Center GlossaryDirect source · primary · checked 2026-08-16
- U.S. Securities and Exchange Commission — EDGAR and filing resourcesSupporting source family · primary · checked 2026-08-16