Three Lines Model for Procurement Governance Training Course
| Course code | SD-P-034 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Procurement |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Procurement decisions are increasingly examined for fairness, delegated authority, conflict management, contract compliance, supplier risk and evidence of challenge. Yet many procurement teams operate with blurred ownership: buyers approve exceptions they later administer, category managers own controls without independent testing, and internal audit is engaged only after a disputed award or supplier failure. The Three Lines Model provides a practical way to separate management accountability, risk and compliance oversight, and independent assurance without creating unnecessary approval layers.
This course applies the Institute of Internal Auditors’ Three Lines Model directly to procurement governance. Participants define first-line procurement control ownership, second-line policy and risk oversight, and third-line internal-audit assurance roles. They build procurement risk-control matrices, map delegation-of-authority controls, distinguish preventive from detective controls, establish escalation routes, and design assurance testing for sourcing, supplier onboarding, contract variation and payment governance. The programme also addresses RACI design, evidence retention, control exceptions, conflicts of interest and reporting to procurement leadership and audit committees.
Instruction combines facilitated analysis with realistic procurement scenarios, including a contested tender award, a high-risk supplier onboarding case and uncontrolled contract changes. Participants work from templates used in class, review control evidence, challenge weak governance designs and receive structured feedback from the instructor. Each participant leaves with a procurement Three Lines operating model pack: a line-of-defence role map, RACI, risk-control matrix, assurance calendar, escalation workflow and a 90-day implementation plan for their organisation.
The course is suited to experienced procurement, supply chain, compliance, risk and internal-audit professionals who need to make governance responsibilities explicit and defensible. It is particularly valuable where an organisation is strengthening procurement controls after audit findings, regulatory scrutiny, rapid growth, decentralisation or a major procurement-system implementation.
Course objectives
By the end of this course, participants will be able to:
- Apply the IIA Three Lines Model to define first-, second- and third-line responsibilities across the procurement lifecycle
- Construct a procurement risk-control matrix covering sourcing, supplier onboarding, contracting, purchasing and supplier management
- Design a procurement governance RACI that separates decision rights, control ownership, oversight and assurance
- Map delegation-of-authority controls for tender awards, waivers, contract changes and supplier approvals
- Evaluate procurement controls as preventive, detective or corrective and identify evidence required for testing
- Develop a second-line monitoring and escalation framework for policy exceptions, conflicts and supplier risk
- Plan risk-based third-line assurance reviews using control objectives, test procedures and reporting criteria
- Produce a 90-day Three Lines implementation roadmap for a defined procurement governance gap
Benefits of attending
For you
- Gain a defensible method for explaining who owns procurement risks, controls and assurance activities
- Build confidence challenging unclear tender approvals, policy waivers and contract-change decisions
- Create governance artefacts that demonstrate readiness for senior procurement, compliance or risk roles
- Learn to translate audit findings into control ownership and practical remediation actions
- Strengthen credibility when presenting procurement governance issues to executives and audit committees
For your organisation
- Clarify accountability for procurement controls, reducing duplicated reviews and unmanaged control gaps
- Improve the quality and traceability of award, waiver, supplier-approval and contract-variation decisions
- Establish risk-based second-line monitoring before issues become audit findings or supplier failures
- Give internal audit a clearer basis for independent procurement assurance planning and testing
- Produce an implementable governance roadmap aligned to procurement policy, risk appetite and delegated authority
Target competencies
Who should attend
- Procurement Managers — who own purchasing controls and need clear accountability across their teams
- Category Managers — who lead sourcing and supplier decisions requiring defensible governance
- Head of Procurement — who must establish scalable oversight without slowing commercial delivery
- Procurement Compliance Managers — who monitor policy adherence, waivers and control exceptions
- Supply Chain Risk Managers — who need to connect supplier risk monitoring with procurement decision rights
- Internal Auditors — who assess procurement controls and require an independent assurance framework
Requirements and prerequisites
Participants should have practical experience in procurement, sourcing, contract management, supplier management, compliance, risk or internal audit. They should understand the basic procurement lifecycle, including requisitioning, tendering, evaluation, award, contracting and supplier performance management, and be familiar with terms such as delegation of authority, conflict of interest, policy exception and audit evidence. Experience using an ERP or source-to-pay system is helpful but not essential. No prior internal-audit qualification, formal risk-management certification, statistical expertise or specialist governance software is required; course templates are supplied.
Training methodology
The programme uses short instructor-led briefings followed by guided application to procurement cases and participants’ own operating contexts. Teams analyse tender, supplier-risk and contract-variation evidence; build risk-control matrices; assign Three Lines responsibilities; and test whether proposed controls can be evidenced and assured. Facilitated peer challenge focuses on practical tensions between commercial speed, control ownership and independent review. Daily outputs are progressively assembled into a procurement governance pack, and the final session converts this work into a prioritised 90-day application plan.
Course outline
Day 1: Applying the Three Lines Model to procurement
- Institute of Internal Auditors Three Lines Model principles
- Procurement lifecycle governance touchpoints
- Management accountability versus oversight responsibility
- First-line ownership in sourcing and purchasing
- Second-line procurement compliance and risk functions
- Third-line internal audit independence requirements
- Governance failure patterns in procurement decisions
Workshop: Participants diagnose a contested tender award case and produce an initial Three Lines responsibility map for the decision.
Day 2: Procurement risks, controls and evidence
- Procurement risk taxonomy and risk appetite
- Risk-control matrix design methodology
- Preventive, detective and corrective procurement controls
- Control objectives for competitive sourcing
- Supplier onboarding due diligence controls
- Contract variation and spend-authorisation controls
- Control evidence, retention and audit trails
Workshop: Participants build a risk-control matrix for a source-to-contract process, including owners, evidence and control classifications.
Day 3: Decision rights and second-line oversight
- Procurement governance RACI construction
- Delegation-of-authority matrix design
- Tender evaluation and award approval gates
- Single-source and waiver governance
- Conflict-of-interest declaration controls
- Second-line monitoring indicators and thresholds
- Exception logging and escalation workflows
Workshop: Participants redesign a flawed procurement approval workflow and produce a RACI, authority matrix and exception-escalation route.
Day 4: Independent assurance and governance reporting
- Risk-based procurement assurance planning
- Internal audit scope and independence boundaries
- Control testing procedures and sample selection
- Design effectiveness versus operating effectiveness
- Issue rating and root-cause analysis
- Procurement governance dashboards and KRIs
- Audit committee reporting for procurement risks
Workshop: Participants develop an assurance test plan for supplier onboarding and present findings, ratings and management actions to a mock audit committee.
Day 5: Implementing a workable procurement Three Lines model
- Target operating model for procurement governance
- Gap assessment against current control arrangements
- Stakeholder mapping and change sponsorship
- Policy, procedure and system-control alignment
- SAP Ariba workflow and approval-control considerations
- Assurance calendar and management review cadence
- Ninety-day implementation roadmap development
Workshop: Participants complete and peer-review a procurement Three Lines operating model pack and a prioritised 90-day implementation roadmap.
Tools & standards covered
IIA Three Lines Model, ISO 31000, COSO Enterprise Risk Management Framework, SAP Ariba
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Mombasa · USD 3,200 -
28 Sep – 02 Oct 2026Book
Dubai · USD 4,500 -
12 – 16 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Dubai · USD 4,500 -
12 – 16 Oct 2026Book
Kigali · USD 3,500 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Dubai · USD 4,500 -
26 – 30 Oct 2026Book
Nairobi · USD 3,000
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Procurement
Strategic Sourcing and Category Management Advanced Training Course
Strategic sourcing leaders are expected to deliver measurable value beyond unit-price reductions: continuity of supply, cost transparency, s…
Coupa Procure-to-Pay System Administration Training Course
Coupa procure-to-pay environments only deliver control and savings when requisitions, approvals, catalogs, purchase orders, receipts, invoic…
Workday Strategic Sourcing Event Management Training Course
Procurement teams need sourcing events that produce comparable supplier responses, transparent evaluations and defensible award recommendati…
Higher Education Procurement and Framework Agreement Training Course
Universities and colleges procure across a demanding mix of research equipment, laboratory consumables, estates works, ICT, professional ser…