The Value Gap in the Three Lines Model
The Three Lines model is the dominant governance operating system, yet it leaves a structural value gap. This chapter explains why the model, as implemented, cannot supply continuous, independent challenge at board level, and where the gap between assurance activity and governance value opens up.
Internal audit spends 75% of its time on routine assurance. [1] This single statistic captures the value gap at the heart of the Three Lines Model. The model, updated by the Institute of Internal Auditors in July 2020, remains the dominant governance architecture in medium-to-large organisations. Its structural limitations were examined theoretically in Section 3. This section examines the empirical reality, the measurable gap between what the second and third lines are asked to do and what they have the capacity to deliver.
The Three Lines Model does what it was designed to do. The problem is that what it was designed to do, layered assurance in an environment of bounded complexity, falls short of what the current risk environment demands, where risk velocity, regulatory volume, and stakeholder expectations have long outpaced its design assumptions. The characterisation is not rhetorical. The World Economic Forum’s Global Risks Report [2], drawing on the Global Risks Perception Survey of over 1,300 senior risk experts, names the defining feature of the current environment as “the accelerating scale, interconnectedness and speed of global risks” and frames 2026 as “an age of competition”. The Three Lines Model, last revised by the Institute of Internal Auditors in July 2020, was not designed for that environment. The result is a value gap, a structural space between what governance functions are mandated to provide and what they can actually deliver, that no existing function fills.
The Third Line: Internal Audit’s Capacity Trap
Internal audit, the third line, occupies a paradoxical position in most organisations. It is mandated to provide independent assurance to the board. It is increasingly expected to deliver strategic advisory services, forward-looking risk assessment, and insights on emerging threats. And it spends three-quarters of its time doing neither.
The IIA’s Vision 2035 report [1], based on a survey of over 7,000 respondents, found that internal audit currently allocates an average of 75% of its capacity to routine assurance work, including compliance audits, Sarbanes-Oxley testing, and regulatory obligations. The remaining 25% encompasses everything else, including advisory work, strategic risk assessment, emerging risk identification, and stakeholder engagement. The IIA’s own target is to shift this balance to 59% assurance and 41% advisory by 2035. That target implicitly acknowledges that the current allocation is failing to deliver the value that stakeholders require.
For functions with SOX responsibilities, the constraint is even more acute. Only 15% of their time is allocated to advisory work [1]. SOX compliance, by its nature, is retrospective, process-driven, and non-negotiable. It consumes capacity with limited room for strategic reallocation. Yet 55% of CFOs and 50% of audit committees report that they want more risk-focused work from internal audit. The demand exists, but the capacity does not.
The resource trajectory is deteriorating. The 2025 North American Pulse of Internal Audit [3] found that only 23% of internal audit functions received budget increases, down from 34% the previous year, and 19% reported outright cuts. Simultaneously, 42% of functions report lacking the skill sets they need, with data analytics, cybersecurity, and AI governance cited as the most critical gaps.
The result is a function that is simultaneously over-committed and under-resourced. Internal audit cannot perform routine assurance, strategic advisory, emerging risk identification, and continuous governance challenge with 75% of its capacity locked in compliance cycles and shrinking budgets. Something has to give, and what gives is the forward-looking, adversarial, strategic work that boards and regulators are increasingly demanding.
The outsourcing data confirms the structural nature of the gap. A KPMG SOX survey [4] found that 58% of organisations rely on outsourced providers for more than 20% of their SOX programme efforts, a structural dependence on external resources to perform work that internal functions cannot absorb. The outsourcing addresses routine compliance, not strategic challenge.
The capacity trap. Internal audit is asked to be a trusted strategic advisor to the board while spending 75% of its time on routine assurance, operating with shrinking budgets, and lacking the skills its stakeholders demand. The IIA’s own 2035 target acknowledges the problem. But even if the target is met, and current budget trajectories suggest it will not be, a 59/41 split still leaves no dedicated capacity for continuous, adversarial, board-level governance challenge. The capacity trap is an architectural problem, not simply a resourcing one.
The Second Line: Mandate Expansion Without Capacity
If internal audit’s problem is a capacity trap, the second line, risk management and compliance, faces an equivalent challenge from the opposite direction, an expanding mandate with no proportional increase in resources.
A PwC Global Risk Survey [5] found that 73% of risk functions report funding constraints for emerging-risk identification, and 75% lack sufficient funding for advanced monitoring capabilities. These are not requests for incremental improvement. Emerging-risk identification and advanced monitoring are core components of what regulators are now requiring (as Section 5 demonstrated). Yet three-quarters of risk functions report that they cannot afford to do the work regulators are demanding.
An EY and Institute of International Finance survey [6], covering 115 banks across 45 countries, found that CRO mandates have expanded significantly to encompass AI governance, cyber resilience, ESG, and operational resilience, risk categories that barely existed a decade ago and now command board attention. The survey found no proportional increase in resources.
The operational reality of the second line in most organisations is a function consumed by monitoring, regulatory reporting, issue remediation, and maintaining risk registers. These activities are necessary. They are also largely backward-looking or present-focused. Strategic, forward-looking analysis of governance architecture, decision-making quality, and systemic failure modes goes unperformed, not because it is unwanted, but because there is no capacity for it after the mandatory work is complete.
The consequence is a second line that satisfies regulatory expectations for risk monitoring while leaving the board without the strategic risk intelligence it needs. Boards receive risk reports. They do not receive adversarial challenge of the assumptions those reports are built on.
Between the Lines: Coordination Failures and Information Loss
Coordination failures between the lines compound the gap beyond what any individual line’s shortfall would suggest.
Bantleon et al. [7] lay out these coordination challenges empirically in a peer-reviewed study covering Chief Audit Executives across Austria, Germany, and Switzerland. Their detailed work paints a picture of governance architecture operating in silos rather than as an integrated system, with inconsistent and multiple reporting to the board, gaps in risk coverage between the lines, siloed risk functions duplicating effort in some areas while leaving others unmonitored, business fatigue from overlapping requests, confusion about the organisation’s aggregate risk profile, and layers of redundant controls that add cost without adding assurance.
The IIA itself acknowledged these structural weaknesses in its 2020 revision [8], noting that the original model’s “defence” framing had reinforced separation rather than collaboration, and that role ambiguity from overlapping responsibilities had blurred accountability. The revision emphasised that “independence does not imply isolation.” But the structural incentives of the model, where each line reports through different channels, operates on different cycles, and measures success by different metrics, continue to produce the isolation the revision sought to address.
Academic critics have gone further. The “defence” terminology, as several scholars have noted, implies a reactive, compliance-driven posture focused on protection rather than on proactive risk-taking and resilience. It fosters what Power [9] has characterised as a “tick-box mentality”, a focus on demonstrating compliance with process rather than delivering substance.
In cybersecurity governance, the coordination failure is particularly acute. Internal auditors typically review cyber-risk components annually on three-to-five-year audit cycles, a cadence that hinders internal audit’s capacity to provide comprehensive and timely assessment in an environment where threats evolve daily. The gap between the velocity of cyber risk and the periodicity of third-line assurance is structural. The model was designed for an environment where risk moved slowly enough to be reviewed on annual cycles. Cyber threats do not.
The Board Perspective: What Is Expected and What Is Delivered
Research on board risk reporting consistently finds a persistent disconnect between what boards receive and what they need. In practice, risk reporting for many boards amounts to standardised templates of backward-looking data with limited forward-looking situational analysis. Boards receive data. They do not receive the contextualised, adversarial analysis that would enable them to challenge management narratives and test governance assumptions.
The advisory industry reached the same conclusion over a decade earlier. In a 2010 McKinsey working paper written for boards, Brodeur et al. [10] asked why risk processes had failed to raise the alarm during the 2008 financial crisis and identified three structural reasons: the risk assessments “often miss large company-wide risks; they do not uncover the fundamental drivers of the large risks identified; and they fail to consider how multiple risks can operate in tandem.” The authors’ conclusion was unambiguous: “such processes fail to generate insight that management or boards can act on.” The defect is that the reports the second and third lines produce, by the advisory industry’s own assessment, do not give boards what boards need.
The same paper is equally direct on where risk oversight should sit within the board. Brodeur et al. [10] observed that many directors park risk oversight with the audit committee and stated that this is “likely a mistake, and might result from a deep-seated underestimation of the value and importance of risk oversight to the company’s performance and health. It could also result from a too-casual working definition of risk, leading directors to confuse the audit committee’s compliance-related approach to risk with a true ERM approach.” McKinsey, in 2010, was telling boards that parking risk with the audit committee produces a compliance frame rather than a risk frame, and that the two are categorically different. The architectural critique this paper advances is not a fringe position. It has been the advisory industry’s own diagnosis for over a decade.
AI governance provides a present-day test of whether that diagnosis has been acted on, and it is clear it has not. A Deloitte survey [11], covering 695 board members and C-suite executives across 56 countries in January and February 2025, found that 31% of boards do not have AI on the agenda at all. Only 17% address it at every meeting; 19% take it up once a year. The pattern is episodic by any definition. And it is not explained by indifference. Some 53% of respondents say their organisations need to accelerate AI adoption, and only 3% consider AI irrelevant. The board recognises the strategic weight of AI. The governance architecture does not equip it to oversee AI continuously. Sixteen years after McKinsey told boards their oversight was superficial, the most commercially significant emerging technology is governed on an annual or semi-annual cycle by two-thirds of respondent boards.
The framework authors have now confirmed the same diagnosis. COSO, the consortium of the AAA, AICPA, FEI, IMA, and IIA whose 2017 framework defines the global ERM standard, published From Guidance to Action in 2026 [12]. A global survey of risk leaders reported in that paper found that 54% of ERM programmes are perceived as compliance or assurance functions, 28% as strategic partners, and only 7% are fully integrated into strategy decisions. Yet 98% of respondents believe ERM should play a more strategic role. The 7%-to-98% spread measures the value gap in COSO’s own data. The diagnosis is therefore consistent across the consortium that authored the framework, the firms that most frequently advise on its implementation, and the boards on the receiving end of its outputs. What is missing is not awareness of the gap. It is a function whose explicit mandate is to close it.
The expectations gap extends to the relationship between audit committees and internal audit leadership. Audit committee chairs consistently report that they expect their Chief Audit Executive to be a “trusted advisor”, someone comfortable sharing perspectives informally, raising uncomfortable truths, and providing strategic insight beyond the audit plan. Yet practitioners acknowledge that “there is often an unfortunate gap between audit committee expectations and internal audit’s performance.” [13]
The result is predictable. Organisations that cannot obtain strategic governance intelligence from their internal functions turn to external providers. Big Four advisory revenues have surpassed their audit services revenues since the mid-2010s,1 with the consulting segment growing rapidly across all four firms as demand for AI governance and transformation advisory has accelerated.
Michael Power’s analysis in Organized Uncertainty provides the theoretical frame for this dynamic. Organisations invest heavily in demonstrating accountability for risks, the apparatus of governance, rather than in reducing actual risk exposure. The Three Lines Model produces assurance reports, risk registers, and audit opinions. What it does not produce, because this fell outside its design mandate, is continuous, adversarial intelligence about whether the governance framework itself is functioning as intended.
The Automation Paradox: Technology That Could Free Capacity But Hasn’t
A reasonable objection to the value gap argument is that technology should be solving it. Robotic process automation can perform routine audit work such as reconciliations, confirmations, and document reviews at speeds substantially faster than manual processes, enabling full-population testing rather than statistical sampling. AI adoption among internal auditors is expected to double significantly over the next two years [1]. Continuous auditing has been adopted by a growing minority of firms [3], with further adoption planned.
If these technologies were deployed at scale, they could, in principle, free 30–40% of the capacity currently consumed by routine assurance work. That freed capacity could be redirected toward the advisory, strategic, and challenge functions that stakeholders demand.
In practice, this has not happened. The barriers are organisational rather than purely technological. Internal audit functions lack the data science and AI skills required to implement and govern these tools. The technology exists, but organisational capability to deploy, validate, and maintain it at scale has not kept up with the pace of technical development.
This creates what might be called the automation paradox. The tools to release capacity from routine work are available, but the skills required to use those tools are the same skills the function lacks for its strategic mandate. Automation highlights the value gap rather than resolving it.
The paradox extends beyond the audit function to the board itself. A Deloitte survey [11], covering 695 board members and C-suite executives across 56 countries in early 2025, found that only 12% of boards engage with their Chief Risk Officer on AI, compared with 72% who engage with the CIO or CTO [11]. The board discusses AI as a technology opportunity through the technology function, not as a risk-bearing strategic commitment through the risk function. Deloitte’s companion research on generative AI enterprise adoption [11] reinforces the point. Organisational preparedness in technology infrastructure and strategy has improved, but preparedness has not improved in the critical area of risk and governance.
The gap requires the right people, with the right mandate and the right independence, to perform work of a fundamentally different character to anything in the existing lines.
The Structural Space: What the Value Gap Creates
The evidence presented in this section describes a governance architecture with a measurable and widening gap between mandate and capacity.
| Function | Mandate | Operational Reality | Gap |
|---|---|---|---|
| Third Line (Internal Audit) | Independent assurance; strategic advisory; emerging risk identification; continuous governance intelligence | 75% on routine assurance; 15–21% advisory; shrinking budgets; 42% skill gaps; 3–5 year audit cycles for cyber | No capacity for continuous, forward-looking, adversarial challenge at board level |
| Second Line (Risk & Compliance) | Risk monitoring; emerging-risk identification; advanced analytics; strategic risk intelligence | 73–75% funding constraints; CRO mandates expanding without resources; 61% talent barriers; consumed by monitoring and reporting | No capacity for adversarial stress-testing of governance assumptions and strategic decisions |
| Coordination (Between Lines) | Integrated risk coverage; consistent reporting; unified risk profile; efficient resource allocation | Silos; duplicated effort; gaps in coverage; inconsistent reporting; business fatigue; confusion on aggregate risk | No function mandated to ensure the governance architecture itself is coordinated, complete, and effective |
| Board Interface | Contextualised, forward-looking, adversarial governance intelligence; trusted advisory relationship | Stale data in standardised templates; expectations gap between audit committees and IA leadership | No function providing the continuous, challenging, strategic governance insight boards require |
The rightmost column of Table describes a consistent gap across every dimension of the governance architecture, namely the absence of a function that provides continuous, adversarial, forward-looking governance challenge at board level.
This is not a gap that can be closed by expanding internal audit budgets, hiring additional risk analysts, or deploying automation. These measures address resource constraints within the existing architecture. The gap is architectural. The Three Lines Model does not include a function whose explicit, full-time, permanent mandate is to challenge the governance framework itself, to ask whether the assurance is real, whether the risk intelligence is complete, whether the coordination is effective, and whether the board is receiving what it needs rather than what the existing functions are configured to produce.
The Financial Stability Institute recognised this gap in 2015, proposing a fourth line of defence [14]. But the FSI’s fourth line consisted of external auditors and regulatory supervisors, entities that add periodic assurance rather than continuous challenge. The gap the FSI identified remains open.
The value gap thesis The value gap thesis. The Three Lines Model was designed for layered assurance in a governance environment of bounded complexity. It now operates in an environment where risk velocity, regulatory volume, and stakeholder expectations exceed its design capacity. The result is a structural gap between what governance functions are mandated to provide and what they can deliver, a gap that is architectural rather than incremental, and one that no existing function within the model fills. This is the structural space that Strategic Governance as a Service occupies.
Section 8 defines the function that can fill it.
Based on individual firm revenue disclosures. Advisory and consulting lines now exceed assurance revenues for each of the four firms.↩︎
References
- Institute of Internal Auditors. (2024). Internal Audit Vision 2035: Creating Our Future Together. Internal Audit Foundation. https://ia-vision2035.org/
- World Economic Forum. (2026). The Global Risks Report 2026. World Economic Forum.
- Institute of Internal Auditors. (2026). North American Pulse of Internal Audit 2026. Internal Audit Foundation. https://www.theiia.org/
- KPMG LLP. (2025). The 2025 SOX Survey. KPMG LLP.
- PricewaterhouseCoopers. (2024). Global Risk Survey. PricewaterhouseCoopers.
- EY & Institute of International Finance. (2025). Global Bank Risk Management Survey. EY and Institute of International Finance.
- Ulrich Bantleon et al.. (2021). Coordination Challenges in Implementing the Three Lines of Defense Model. International Journal of Auditing. https://doi.org/10.1111/ijau.12201
- Institute of Internal Auditors. (2020). The IIA's Three Lines Model: An Update of the Three Lines of Defense. Institute of Internal Auditors. https://www.theiia.org/
- Michael Power. (2007). Organized Uncertainty: Designing a World of Risk Management. Oxford University Press.
- Andr\'e Brodeur et al.. (2010). A Board Perspective on Enterprise Risk Management. McKinsey & Company.
- Anna Marks et al.. (2025). Governance of AI: A Critical Imperative for Today's Boards. Deloitte Global Boardroom Program.
- Ryan Luttenton et al.. (2026). From Guidance to Action: Exploring Practical Enterprise Risk Management. Committee of Sponsoring Organizations of the Treadway Commission (COSO).
- (2026). Mind the Gap: CAE Strategies for Fortifying Audit Committee Relationships. Optro. https://optro.ai/blog/mind-the-gap-cae-strategies-fortifying-audit-committee-relationships
- Isabella Arndorfer & Andrea Minto. (2015). The ``Four Lines of Defence Model'' for Financial Institutions: Taking the Three-Lines-of-Defence Model Further to Reflect Specific Governance Features of Regulated Financial Institutions. Financial Stability Institute, Bank for International Settlements. https://www.bis.org/fsi/fsipapers11.htm