Three Lines Model for Financial Risk Accountability Training Course
| Course code | SD-RM-037 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Risk Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Finance and accounting teams are often expected to own, challenge, report and assure risk at the same time. The result can be unclear control ownership, duplicated reviews, weak escalation, and internal audit plans that address symptoms rather than root causes. The IIA Three Lines Model provides a practical accountability structure: governing bodies oversee; management delivers and manages risk; risk, compliance and control functions provide expertise and challenge; and internal audit provides independent assurance. This course helps participants translate that structure into operating responsibilities for financial reporting, treasury, tax, procure-to-pay, record-to-report and regulatory risks.
Participants examine the IIA Three Lines Model alongside COSO ERM and ISO 31000, then apply the method to finance processes. They learn to distinguish management ownership from second-line challenge and third-line assurance; build risk and control ownership matrices; set escalation thresholds; map assurance coverage; and design reporting that gives audit committees and finance leaders a reliable view of material risk. Practical work includes risk appetite statements, RACI assignments, control-testing roles, issue-management routes and assurance maps.
The programme is delivered through instructor-led briefings, finance-sector cases, facilitated workshops and structured peer review. Participants work with a realistic financial close and payment-risk scenario, using templates that can be adapted to their own organisation. They leave with a completed Three Lines accountability pack containing a finance risk register, role matrix, assurance map, escalation protocol and 90-day implementation plan. The course is suited to professionals building or clarifying risk governance, as well as managers seeking defensible accountability across finance and assurance functions.
Course objectives
By the end of this course, participants will be able to:
- Interpret the IIA Three Lines Model for finance and accounting risk governance
- Differentiate first-line management ownership, second-line challenge and third-line assurance responsibilities
- Construct a RACI matrix for financial reporting, payment, treasury and compliance risks
- Develop a finance risk register with risk owners, control owners, indicators and escalation thresholds
- Map key financial controls to COSO ERM objectives and the relevant line of accountability
- Create an assurance map that identifies duplication, gaps and reliance opportunities across assurance providers
- Design an issue-escalation and remediation workflow for material control deficiencies
- Produce a 90-day Three Lines implementation plan for a selected finance process
Benefits of attending
For you
- Gain a practical method for explaining where finance risk ownership ends and independent assurance begins
- Build credible RACI and assurance maps for use in control committees, audit discussions and governance reviews
- Strengthen the ability to challenge unclear control ownership without assuming management responsibility
- Apply recognised IIA, COSO and ISO concepts to finance-process risks rather than discussing them only in theory
- Leave with a portfolio-ready accountability pack that demonstrates risk-governance design capability
For your organisation
- Clarify ownership for material finance risks, controls, action plans and escalation decisions
- Reduce duplicated testing and reporting across finance, risk, compliance and internal audit teams
- Improve audit committee visibility of assurance gaps in financial reporting and transaction processes
- Create more consistent remediation routes for control deficiencies and overdue risk actions
- Establish a reusable accountability framework that can be applied across finance processes and business units
Target competencies
Who should attend
- Finance Managers — who need clear ownership for financial controls, reporting risks and remediation actions
- Risk Managers — who must establish second-line challenge without taking over management accountability
- Internal Auditors — who need to plan independent assurance around management and second-line activity
- Financial Controllers — who oversee close, reporting and control processes requiring defensible accountability
- Compliance Officers — who coordinate regulatory obligations and need effective escalation routes into finance
- Treasury and Accounts Payable Leaders — who manage high-value transaction risks and control responsibilities
Requirements and prerequisites
This is a foundation-to-intermediate course. Participants should understand the basic purpose of internal controls, risk registers and management reporting, and have experience in at least one finance process such as financial close, accounts payable, treasury, budgeting, tax or financial reporting. Familiarity with spreadsheet-based risk logs is useful because exercises use Excel-style templates. No prior internal audit qualification, formal risk-management certification, COSO training or detailed knowledge of the IIA Three Lines Model is required. Complete beginners should expect a structured introduction before progressing to applied governance design.
Training methodology
The instructor introduces each component of the IIA Three Lines Model through short, targeted sessions before participants apply it to finance cases. Teams analyse a financial close and payment-control scenario, identify accountable roles, challenge conflicts of interest, and create risk, control and assurance artefacts using supplied templates. Facilitated discussions compare operating models across organisations. Daily exercises build toward an individual application pack, and the final session uses peer review and instructor feedback to refine each participant’s 90-day plan for implementation in their own finance environment.
Course outline
Day 1: Establishing financial risk accountability
- IIA Three Lines Model principles and purpose
- Finance governance roles from board to process owner
- Distinguishing risk ownership, oversight, challenge and assurance
- Financial risk taxonomy for reporting, liquidity, fraud and compliance
- Risk appetite and tolerance statements for finance activities
- COSO ERM governance and culture principles
- Common accountability failures in finance control environments
Workshop: Participants diagnose accountability failures in a financial reporting case and produce an initial Three Lines stakeholder map.
Day 2: Defining first- and second-line responsibilities
- First-line management accountability for financial controls
- Second-line risk and compliance challenge activities
- RACI matrix design for finance processes
- Control-owner versus process-owner responsibilities
- Segregation of duties and conflict-of-interest analysis
- Key risk indicators and control performance indicators
- Escalation thresholds for financial risk events
Workshop: Participants create a RACI matrix and escalation thresholds for an accounts payable and payment-approval process.
Day 3: Building risk and control accountability artefacts
- Finance risk register fields and scoring criteria
- Inherent, residual and target risk assessment
- Control objective and control activity documentation
- Mapping risks to preventive and detective controls
- COSO ERM performance principles in risk assessment
- Issue logging, root-cause analysis and remediation ownership
- Management risk reporting for finance leadership
Workshop: Participants build a risk-and-control register for a monthly close process, including owners, indicators and corrective actions.
Day 4: Planning independent assurance and governance reporting
- Third-line independence and internal audit mandate
- Assurance map design and assurance-provider inventory
- Assessing assurance coverage, reliance and duplication
- Risk-based internal audit planning for finance processes
- Reporting material control deficiencies to governance bodies
- Audit committee information needs and reporting formats
- ISO 31000 monitoring and review practices
Workshop: Participants develop an assurance map for financial reporting risk and identify coverage gaps, overlaps and proposed assurance actions.
Day 5: Implementing the Three Lines Model in finance
- Target operating model for finance risk governance
- Stakeholder engagement and role-clarification workshops
- Policy, procedure and committee charter updates
- Implementation sequencing and change-impact assessment
- Ninety-day action planning and success measures
- Testing accountability effectiveness after implementation
- Sustaining Three Lines discipline through reporting cycles
Workshop: Participants assemble and present a Three Lines accountability pack and a 90-day implementation plan for a chosen finance process.
Tools & standards covered
IIA Three Lines Model, COSO Enterprise Risk Management Framework, ISO 31000:2018 Risk Management, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Risk Management
MATLAB Financial Risk Simulation and Backtesting Training Course
Market-risk teams are expected to explain not only a portfolio's current VaR, expected shortfall, sensitivities and stress loss, but also wh…
Insurance Risk Management and Solvency Control Training Course
Insurers must make capital, pricing, underwriting and investment decisions with a clear view of risk appetite, solvency capacity and regulat…
Banking Risk Management for Commercial Banks Training Course
Commercial banks face risk decisions that cannot be managed through policy documents alone. Credit deterioration, liquidity pressure, intere…
Energy Commodity Risk Management for Energy Companies Training Course
Energy companies manage exposure across crude oil, refined products, natural gas, power, LNG, coal, emissions and renewable certificates whi…