Sort the Three Lines Without Blurring Ownership
Classify activities under first line, second line, third line, or governing body oversight.
Assign each risk activity to its primary Three Lines role. First line management owns and operates Second line supports and challenges Third line provides independent assurance Governing body oversees Approve privileged-access exceptions for production systems before access is granted Define enterprise access-risk methodology and monitor overdue exceptions Independently test whether access reviews are designed and operating effectively Approve risk appetite and receive reports on major unresolved access risks Remove terminated users from systems according to the access procedure Challenge whether business units are accepting too many access exceptions Report assurance conclusions on identity governance to the audit committee Hold executives…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in