IIA Three Lines Model Governance Integration Training Course
| Course code | SD-CG-026 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Corporate Governance |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Boards and executive teams depend on clear accountability for risk, control and assurance, yet many organisations still experience duplicated reviews, unclear escalation routes, management-owned controls treated as internal audit work, and assurance gaps around major risks. The IIA Three Lines Model provides a practical governance architecture for resolving these issues: governing body oversight, management action and risk ownership, and independent internal audit assurance. This course helps participants translate the model from a diagram into operating arrangements that can be evidenced, monitored and improved.
Participants examine the 2020 IIA Three Lines Model alongside COSO and ISO 31000 principles to define responsibilities across the governing body, executive management, first-line operational teams, second-line risk and compliance functions, and third-line internal audit. They learn to map risk ownership, distinguish monitoring from independent assurance, design escalation and reporting routes, create an assurance map, identify duplication and gaps, and document a practical governance integration plan. Particular attention is given to preserving internal audit independence while improving coordination with risk, compliance, legal, quality and other assurance providers.
Delivery combines instructor-led explanation with worked governance scenarios, role-based workshops, assurance-mapping exercises and facilitated peer review. Participants apply the model to a realistic organisation with fragmented risk reporting and overlapping assurance activity. By the end of the week, each participant leaves with an IIA Three Lines governance integration pack: a stakeholder responsibility map, risk-to-assurance matrix, draft assurance map, escalation design and 90-day implementation plan that can be adapted for their own organisation.
The course is suited to governance, risk, compliance, internal audit and operational leaders who need a shared method for clarifying accountability without creating unnecessary committees or controls. It is equally valuable for managers sponsoring governance improvement who need staff able to turn board expectations into workable management practices.
Course objectives
By the end of this course, participants will be able to:
- Interpret the IIA Three Lines Model principles in relation to board oversight, management action and internal audit assurance
- Map first-, second- and third-line responsibilities using a governance responsibility matrix
- Differentiate risk ownership, control monitoring, compliance oversight and independent assurance activities
- Build a risk-to-assurance matrix that identifies assurance gaps, overlaps and unmanaged critical risks
- Design escalation routes and governance reporting requirements for material risk and control issues
- Assess internal audit independence safeguards when coordinating with risk, compliance and management functions
- Create an assurance map linking strategic objectives, principal risks, assurance providers and governing body reporting
- Produce a 90-day IIA Three Lines governance integration plan with owners, milestones and evidence measures
Benefits of attending
For you
- Gain a defensible method for explaining where management accountability ends and independent assurance begins
- Develop practical assurance-mapping capability for internal audit, risk, compliance or governance roles
- Build credibility in board and audit committee discussions through precise Three Lines terminology
- Prepare a portfolio-ready governance integration pack based on a recognised IIA model
- Improve readiness for roles involving enterprise risk, internal control, compliance leadership or audit management
For your organisation
- Clarify ownership of key risks and controls across operational management, risk, compliance and internal audit
- Reduce duplicated testing and reporting by identifying overlapping assurance activity
- Expose assurance gaps around principal risks before they become board-level control failures
- Strengthen audit committee reporting with a structured view of assurance coverage and residual risk
- Provide staff with an actionable 90-day plan for embedding the IIA Three Lines Model into governance practices
Target competencies
Who should attend
- Heads of Internal Audit — who must preserve independent assurance while coordinating with other control functions
- Chief Risk Officers and Risk Managers — who need to clarify management risk ownership and second-line oversight
- Compliance Directors and Compliance Managers — who must position compliance monitoring within the wider assurance framework
- Corporate Governance Managers — who design board, committee and accountability arrangements
- Operational Directors and Business Unit Leaders — who own risks and controls but need clear escalation and assurance routes
- Audit Committee Secretaries and Board Governance Professionals — who support oversight of assurance coverage and reporting
Requirements and prerequisites
This foundation-to-intermediate course is accessible to participants with basic workplace exposure to governance, risk, controls, audit, compliance or management reporting. Participants should be able to discuss how decisions are made and escalated in their organisation and should recognise common terms such as risk owner, control, policy, assurance and audit finding. Familiarity with the IIA Three Lines Model is helpful but not required; it is taught from first principles. No audit qualification, legal training, specialist governance software or advanced Excel capability is required. Complete beginners should expect to spend time learning core governance vocabulary before applying the model.
Training methodology
The programme uses short instructor-led modules to establish the IIA Three Lines Model, then moves quickly into structured application. Participants analyse governance charters, risk registers, assurance reports and audit committee packs from realistic scenarios. Small groups build responsibility matrices, test line-of-defence classifications, challenge duplicated assurance activity and present an assurance map to a simulated audit committee. Individual work throughout the week develops a tailored integration pack. The final session converts findings into a sequenced 90-day implementation plan with named owners, governance forums and evidence of progress.
Course outline
Day 1: Governance architecture and the IIA Three Lines Model
- Corporate governance purposes, accountabilities and decision rights
- The 2020 IIA Three Lines Model principles and terminology
- Governing body oversight versus executive management responsibility
- First-line management ownership of objectives, risks and controls
- Second-line roles in risk management, compliance and control support
- Third-line internal audit independence and objective assurance
- Comparison of Three Lines with COSO internal control components
Workshop: Participants diagnose a fictional organisation's governance failures and produce an initial Three Lines role classification for its key functions.
Day 2: Risk ownership, control accountability and role design
- Linking strategic objectives, principal risks and control activities
- Risk appetite, tolerance and management escalation thresholds
- RACI and responsibility matrices for governance accountabilities
- Distinguishing control performance from control monitoring
- Positioning specialist functions including legal, quality, security and finance
- Delegated authority frameworks and management accountability
- Documenting role conflicts, gaps and duplicated mandates
Workshop: Participants build a governance responsibility matrix for a major operational risk and identify conflicting or missing accountabilities.
Day 3: Assurance coordination and assurance mapping
- Definitions of assurance, monitoring, review and independent evaluation
- Risk-to-assurance matrix design and evidence requirements
- Sources of assurance from management, second line and internal audit
- Combined assurance coordination without compromising independence
- Assessing assurance coverage, quality, frequency and reliance
- Identifying duplicated assurance work and unassured risks
- Assurance map reporting for executive committees and audit committees
Workshop: Using a supplied risk register and audit plan, participants create an assurance map that highlights coverage gaps and duplicated testing.
Day 4: Reporting, escalation and internal audit independence
- Governance information flows from operations to the governing body
- Designing risk, control and assurance reporting packs
- Material issue escalation criteria and exception reporting
- Audit committee responsibilities for assurance oversight
- Internal audit charter provisions and functional reporting lines
- Safeguards for internal audit objectivity during advisory work
- Using ISO 31000 principles to improve risk governance communication
Workshop: Participants redesign an ineffective audit committee reporting pack and produce an escalation pathway for a material control failure.
Day 5: Embedding the model into organisational practice
- Assessing organisational maturity against the Three Lines Model
- Stakeholder analysis for governance change initiatives
- Integrating Three Lines expectations into charters and policies
- Updating risk registers, assurance plans and committee terms of reference
- Implementation milestones, accountable owners and decision forums
- Measures for monitoring governance integration effectiveness
- Communicating the model to boards, managers and assurance providers
Workshop: Participants complete and peer-review a 90-day IIA Three Lines governance integration plan containing a stakeholder map, assurance actions, milestones and success measures.
Tools & standards covered
IIA Three Lines Model, COSO Internal Control—Integrated Framework, ISO 31000:2018 Risk Management Guidelines, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Corporate Governance
UK Stewardship Code Corporate Governance Reporting Training Course
UK Stewardship Code reporting is not a narrative exercise. Asset owners, asset managers and service providers must show the Financial Report…
Sarbanes-Oxley Act Governance and Audit Committee Training Course
Sarbanes-Oxley compliance can fail long before an external auditor identifies a control deficiency. Boards, audit committees, finance leader…
UK Corporate Governance Code Compliance and Reporting Training Course
Boards, company secretaries, governance teams and senior assurance professionals must turn the UK Corporate Governance Code from a statement…
Corporate Governance Reporting for Investor Relations Managers Training Course
Investor relations managers are expected to explain not only financial performance, but also how the board governs strategy, risk, executive…