rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/three-lines-of-defence-australian-smb
Printed 28 August 2026
The three lines model applied to an Australian SMB
How the three lines model works without a compliance department: mapping the roles, keeping second line independent, and third-line options for an SMB.
What the three lines model says
The three lines model separates the people who own and manage risk day to day from the people who oversee it and from the people who provide independent assurance about both. First line owns and operates the controls. Second line sets the framework, advises and challenges. Third line gives the governing body independent assurance.
The separation exists to solve one problem: a person cannot credibly assure their own work. Every design decision in the model follows from that.
The model was published by the Institute of Internal Auditors and updated in 2020 as the IIA's Three Lines Model, replacing the earlier "three lines of defence" framing. Australian usage still commonly says "three lines of defence", and the two phrases refer to the same structure.
Why the 2020 update matters
The 2020 update changed three things that matter for a small business.
It reframed the lines as roles, not departments. The earlier framing invited organisations to conclude they could not apply the model without three separate teams. The updated model describes roles that can be held by different people in a small entity, and the roles are what the structure requires.
It put the governing body inside the model. The board is not an audience sitting outside three boxes. It is accountable for oversight, for establishing structures, and for ensuring assurance is independent. That is the point at which the model connects to directors' duties.
It emphasised alignment over defensiveness. "Defence" framed compliance as protection against management. The update frames the lines as collaborating toward objectives while preserving independence where it counts.
Mapping the lines onto a forty-person business
In a business of forty people there is no compliance department, and building one is not the answer. The roles map like this:
| Role | Who typically holds it in an SMB | What they actually do | What they must not do |
|---|---|---|---|
| Governing body | Board, or owner-directors | Approve the framework, set risk appetite, receive reporting, ensure assurance independence | Perform the testing themselves and call it assurance |
| First line | Operations, payroll, finance, sales, technology leads | Own obligations register rows, operate controls, self-check, report issues | Decide unilaterally that a control failure is immaterial |
| Second line | CFO, company secretary, GM, or a part-time compliance adviser | Maintain the registers, set standards, monitor, challenge, report to the board | Perform first-line work in the same area they monitor |
| Third line | External auditor, outsourced internal audit, independent reviewer, technical assessor | Independent assurance to the board on whether the framework works | Report only to management |
The practical constraint is that in a small business one person often holds two roles. That is workable. What is not workable is the same person operating a control, monitoring it, and assuring it. When roles must be combined, combine governing body with second line, or first line with second line in *different* domains — the payroll manager can hold second-line oversight of safety, and the operations manager can hold second-line oversight of payroll.
Keeping second line independent without hiring one
Independence in an SMB is achieved through reporting lines and mechanics rather than headcount:
- Reporting line. Whoever holds the second-line role reports compliance matters directly to the board or to the owner-directors, not through the executive whose area is being monitored.
- Domain swap. As above, assign second-line oversight of a domain to someone who does not operate in it.
- Documented challenge. Record the challenge, not just the conclusion. A monitoring result reading "tested, satisfactory" is weaker than one recording the sample tested, the exception found, the management response and the follow-up date.
- No self-assessment as the only evidence. First-line self-assessment is a legitimate input. It is not assurance.
- Escalation right. The second-line role must be able to put an item on the board agenda without executive filtering. Write that into the policy and record it in the board charter.
The director duties tool sets out the general duties directors carry when receiving that reporting, and directors' duties under section 180 and the business judgment rule covers the standard of care applied.
Third line options with no internal audit function
Independent assurance does not require an internal audit department. In order of cost:
- Regime-mandated independent evaluation. Some regimes require it and pay for itself in coverage. Reporting entities under the anti-money laundering regime must have their program independently evaluated at least once every three years under the reformed rules, with staggered first-evaluation deadlines set by the Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026 (checked August 2026); see AUSTRAC's guidance on independent evaluation and the AML/CTF program Part A and Part B explainer.
- Certification and surveillance audits. Where the business already holds a certification — quality, information security, sector accreditation — the surveillance audit provides independent assurance over the certified scope. The ISO 27001 gap assessment scopes that pathway for information security.
- Targeted external review. A scoped engagement over one or two high-residual-risk domains each year, rotating coverage. Cheaper than a standing function and adequate for most SMBs.
- Peer review across group entities. Where a group has multiple operating entities, staff from one review the controls of another.
- External audit observations. Management letter points from the statutory audit are assurance output and should be tracked in the issues log, not filed.
Whatever the source, the defining feature is that the report goes to the governing body, not to the manager of the area reviewed.
Where Australian regulators expect the lines to show
The model is not itself law in Australia, but several regimes assume its architecture:
- Prudential standards. APRA's framework distinguishes business-line risk ownership, an independent risk management function, and internal audit. CPS 230 operational risk management commenced 1 July 2025 and requires clearly defined roles and responsibilities for operational risk, plus independent review — see APRA's CPS 230 standard page.
- Accountability regimes. The Financial Accountability Regime allocates accountability to named individuals, which forces an explicit statement of who owns which line.
- Financial services licensing. The section 912A general obligations require adequate risk management systems and adequate resources, which regulators read as including oversight distinct from the business line.
- Anti-money laundering. The compliance officer role and the independent evaluation requirement create second and third lines by statute; see the AML/CTF compliance officer role.
- Work health and safety. Officers carry a due diligence duty that cannot be discharged solely by management assurances, which is a third-line argument in substance.
Evidence that the model is real, not a diagram
An auditor testing whether the model operates looks for artefacts, not organisation charts:
| Line | Evidence it is operating |
|---|---|
| Governing body | Board charter defining oversight, minutes recording challenge, approved risk appetite |
| First line | Control owners named on the obligations register, completed control records, self-identified issues logged |
| Second line | Monitoring plan and results, documented challenge with management responses, register maintenance evidence, direct board reporting |
| Third line | Independent report addressed to the board, scope and independence statement, findings tracked to closure |
The single strongest piece of evidence is a documented disagreement — second line raising an issue that first line initially disputed, resolved and recorded. It demonstrates the challenge function operates. A program with no recorded disagreements in two years is usually a program where challenge is not happening.
Frequently asked
Is the three lines model mandatory in Australia?
No Australian statute mandates the model by name. Several regimes assume its architecture: APRA prudential standards require an independent risk management function and internal audit for regulated entities; the anti-money laundering regime requires a compliance officer and periodic independent evaluation; and financial services licensing requires adequate risk management systems. For unregulated businesses it is a widely used structure rather than a legal requirement.
Can one person be both first and second line?
Not in the same domain. A person who operates a control cannot provide independent oversight of that control. In small businesses the workable pattern is a domain swap — one manager holds second-line oversight of a domain they do not operate in, and vice versa — with both reporting compliance matters directly to the board.
What are the third-line options for a business with no internal audit function?
Regime-mandated independent evaluations, certification surveillance audits, scoped external reviews rotating across high-risk domains, peer review between group entities, and tracking management letter points from the statutory audit. The defining requirement is that the report goes to the governing body rather than to the manager of the area reviewed.
How often must an AML/CTF program be independently evaluated?
Under the reformed regime the independent evaluation must occur at least once every three years, with the frequency set in the entity's own AML/CTF policies according to the nature, size and complexity of the business. The Anti-Money Laundering and Counter-Terrorism Financing Transitional Rules 2026 stagger the deadline for the first evaluation (checked August 2026). Confirm the applicable date against AUSTRAC guidance for your AUSTRAC account number.
Why did the Institute of Internal Auditors drop 'of defence' from the name?
The 2020 update reframed the lines as roles that collaborate toward organisational objectives rather than as barriers protecting the organisation from its own management, and brought the governing body explicitly inside the model. Australian practice still commonly uses 'three lines of defence'; both terms refer to the same structure.
Related
Related reading
APRA CPS 230 Operational Risk Management: The Standalone Deep Dive
Plain-English deep dive on Prudential Standard CPS 230, which commenced 1 July 2025 and replaced CPS 231 Outsourcing and CPS 232 Business Continuity.
Financial Accountability Regime (FAR): Commenced 15 March 2024
Financial Accountability Regime Act 2023 commenced 15 March 2024 for banking, with phased start for insurance and superannuation: accountable persons, accountability statements and statement of accountabilities.
Compliance monitoring and assurance plans: designing testing that proves the controls work
Building an annual compliance monitoring plan: design vs operating effectiveness, what to test and how often, sample sizes, and recording results.
Board and committee compliance reporting: what a report to directors must contain
The standing components of a board compliance report: status, breaches, regulatory change, assurance results, escalation thresholds and the minute.
Obligations covered
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/three-lines-of-defence-australian-smb