Skip to main content
Rules Mate

The three lines model applied to an Australian SMB

Rules Mate Editorial6 min read

How the three lines model works without a compliance department: mapping the roles, keeping second line independent, and third-line options for an SMB.

What the three lines model says

The three lines model separates the people who own and manage risk day to day from the people who oversee it and from the people who provide independent assurance about both. First line owns and operates the controls. Second line sets the framework, advises and challenges. Third line gives the governing body independent assurance.

The separation exists to solve one problem: a person cannot credibly assure their own work. Every design decision in the model follows from that.

The model was published by the Institute of Internal Auditors and updated in 2020 as the IIA's Three Lines Model, replacing the earlier "three lines of defence" framing. Australian usage still commonly says "three lines of defence", and the two phrases refer to the same structure.

Why the 2020 update matters

The 2020 update changed three things that matter for a small business.

It reframed the lines as roles, not departments. The earlier framing invited organisations to conclude they could not apply the model without three separate teams. The updated model describes roles that can be held by different people in a small entity, and the roles are what the structure requires.

It put the governing body inside the model. The board is not an audience sitting outside three boxes. It is accountable for oversight, for establishing structures, and for ensuring assurance is independent. That is the point at which the model connects to directors' duties.

It emphasised alignment over defensiveness. "Defence" framed compliance as protection against management. The update frames the lines as collaborating toward objectives while preserving independence where it counts.

Mapping the lines onto a forty-person business

In a business of forty people there is no compliance department, and building one is not the answer. The roles map like this:

RoleWho typically holds it in an SMBWhat they actually doWhat they must not do
Governing bodyBoard, or owner-directorsApprove the framework, set risk appetite, receive reporting, ensure assurance independencePerform the testing themselves and call it assurance
First lineOperations, payroll, finance, sales, technology leadsOwn obligations register rows, operate controls, self-check, report issuesDecide unilaterally that a control failure is immaterial
Second lineCFO, company secretary, GM, or a part-time compliance adviserMaintain the registers, set standards, monitor, challenge, report to the boardPerform first-line work in the same area they monitor
Third lineExternal auditor, outsourced internal audit, independent reviewer, technical assessorIndependent assurance to the board on whether the framework worksReport only to management

The practical constraint is that in a small business one person often holds two roles. That is workable. What is not workable is the same person operating a control, monitoring it, and assuring it. When roles must be combined, combine governing body with second line, or first line with second line in *different* domains — the payroll manager can hold second-line oversight of safety, and the operations manager can hold second-line oversight of payroll.

Keeping second line independent without hiring one

Independence in an SMB is achieved through reporting lines and mechanics rather than headcount:

  • Reporting line. Whoever holds the second-line role reports compliance matters directly to the board or to the owner-directors, not through the executive whose area is being monitored.
  • Domain swap. As above, assign second-line oversight of a domain to someone who does not operate in it.
  • Documented challenge. Record the challenge, not just the conclusion. A monitoring result reading "tested, satisfactory" is weaker than one recording the sample tested, the exception found, the management response and the follow-up date.
  • No self-assessment as the only evidence. First-line self-assessment is a legitimate input. It is not assurance.
  • Escalation right. The second-line role must be able to put an item on the board agenda without executive filtering. Write that into the policy and record it in the board charter.

The director duties tool sets out the general duties directors carry when receiving that reporting, and directors' duties under section 180 and the business judgment rule covers the standard of care applied.

Third line options with no internal audit function

Independent assurance does not require an internal audit department. In order of cost:

  1. Regime-mandated independent evaluation. Some regimes require it and pay for itself in coverage. Reporting entities under the anti-money laundering regime must have their program independently evaluated at least once every three years under the reformed rules, with staggered first-evaluation deadlines set by the Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026 (checked August 2026); see AUSTRAC's guidance on independent evaluation and the AML/CTF program Part A and Part B explainer.
  2. Certification and surveillance audits. Where the business already holds a certification — quality, information security, sector accreditation — the surveillance audit provides independent assurance over the certified scope. The ISO 27001 gap assessment scopes that pathway for information security.
  3. Targeted external review. A scoped engagement over one or two high-residual-risk domains each year, rotating coverage. Cheaper than a standing function and adequate for most SMBs.
  4. Peer review across group entities. Where a group has multiple operating entities, staff from one review the controls of another.
  5. External audit observations. Management letter points from the statutory audit are assurance output and should be tracked in the issues log, not filed.

Whatever the source, the defining feature is that the report goes to the governing body, not to the manager of the area reviewed.

Where Australian regulators expect the lines to show

The model is not itself law in Australia, but several regimes assume its architecture:

  • Prudential standards. APRA's framework distinguishes business-line risk ownership, an independent risk management function, and internal audit. CPS 230 operational risk management commenced 1 July 2025 and requires clearly defined roles and responsibilities for operational risk, plus independent review — see APRA's CPS 230 standard page.
  • Accountability regimes. The Financial Accountability Regime allocates accountability to named individuals, which forces an explicit statement of who owns which line.
  • Financial services licensing. The section 912A general obligations require adequate risk management systems and adequate resources, which regulators read as including oversight distinct from the business line.
  • Anti-money laundering. The compliance officer role and the independent evaluation requirement create second and third lines by statute; see the AML/CTF compliance officer role.
  • Work health and safety. Officers carry a due diligence duty that cannot be discharged solely by management assurances, which is a third-line argument in substance.

Evidence that the model is real, not a diagram

An auditor testing whether the model operates looks for artefacts, not organisation charts:

LineEvidence it is operating
Governing bodyBoard charter defining oversight, minutes recording challenge, approved risk appetite
First lineControl owners named on the obligations register, completed control records, self-identified issues logged
Second lineMonitoring plan and results, documented challenge with management responses, register maintenance evidence, direct board reporting
Third lineIndependent report addressed to the board, scope and independence statement, findings tracked to closure

The single strongest piece of evidence is a documented disagreement — second line raising an issue that first line initially disputed, resolved and recorded. It demonstrates the challenge function operates. A program with no recorded disagreements in two years is usually a program where challenge is not happening.

Frequently asked

Is the three lines model mandatory in Australia?

No Australian statute mandates the model by name. Several regimes assume its architecture: APRA prudential standards require an independent risk management function and internal audit for regulated entities; the anti-money laundering regime requires a compliance officer and periodic independent evaluation; and financial services licensing requires adequate risk management systems. For unregulated businesses it is a widely used structure rather than a legal requirement.

Can one person be both first and second line?

Not in the same domain. A person who operates a control cannot provide independent oversight of that control. In small businesses the workable pattern is a domain swap — one manager holds second-line oversight of a domain they do not operate in, and vice versa — with both reporting compliance matters directly to the board.

What are the third-line options for a business with no internal audit function?

Regime-mandated independent evaluations, certification surveillance audits, scoped external reviews rotating across high-risk domains, peer review between group entities, and tracking management letter points from the statutory audit. The defining requirement is that the report goes to the governing body rather than to the manager of the area reviewed.

How often must an AML/CTF program be independently evaluated?

Under the reformed regime the independent evaluation must occur at least once every three years, with the frequency set in the entity's own AML/CTF policies according to the nature, size and complexity of the business. The Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026 stagger the deadline for the first evaluation (checked August 2026). Confirm the applicable date against AUSTRAC guidance for your AUSTRAC account number.

Why did the Institute of Internal Auditors drop 'of defence' from the name?

The 2020 update reframed the lines as roles that collaborate toward organisational objectives rather than as barriers protecting the organisation from its own management, and brought the governing body explicitly inside the model. Australian practice still commonly uses 'three lines of defence'; both terms refer to the same structure.

Related

Related reading