Skip to main content
INTERNAL-AUDITING5 MIN READ

Sort the Three Lines Without Blurring Ownership

Classify activities under first line, second line, third line, or governing body oversight.

Assign each risk activity to its primary Three Lines role. First line management owns and operates Second line supports and challenges Third line provides independent assurance Governing body oversees Approve privileged-access exceptions for production systems before access is granted Define enterprise access-risk methodology and monitor overdue exceptions Independently test whether access reviews are designed and operating effectively Approve risk appetite and receive reports on major unresolved access risks Remove terminated users from systems according to the access procedure Challenge whether business units are accepting too many access exceptions Report assurance conclusions on identity governance to the audit committee Hold executives…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us