The Three Lines of Defense in Effective Risk Management and Control¶
Institute of Internal Auditors. (2013). The Three Lines of Defense in Effective Risk Management and Control.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Coordination-Overhead Inversion
- Financial-services audit: quality assurance, regulatory reporting, and oversight grow until audit cost exceeds the substantive activity; the "three lines of defence" becomes a multi-layer scaffold demanding its own governance.
This sourceDefines the three-lines-of-defence model (operational management, risk/compliance functions, internal audit); the model is widely documented to produce duplication of assurance effort and proliferating second/third-line functions demanding their own coordination. (Resolves needs-source-803; supports the three-lines model growing into a multi-layer assurance scaffold.)
- Financial-services audit: quality assurance, regulatory reporting, and oversight grow until audit cost exceeds the substantive activity; the "three lines of defence" becomes a multi-layer scaffold demanding its own governance.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:c6c78b0eb5e6 · see in the full table