This publication explains roles and responsibilities in plain language. It does not evaluate a particular organization or provide organization-specific professional advice.
Before You Begin
Technology teams, risk functions, cybersecurity teams, internal auditors, executives, and boards may all discuss the same system, vulnerability, control, or incident. That shared subject does not mean they have the same responsibility.
In Two Minutes
Operations own and run the business process and its controls. Second-line roles provide specialized support, monitoring, and challenge. Internal audit independently evaluates whether governance, risk management, and controls are adequate and effective. Cybersecurity describes a risk domain and set of capabilities; the line depends on the responsibility being performed, not the department title.
First line
Cybersecurity operations
Primary job: operate capabilities and controls.
Second line
Technology-risk oversight
Primary job: support, monitor, and challenge.
Third line
IT audit
Primary job: independent assurance.
01 One Risk Ecosystem, Different Jobs
A critical software vulnerability can involve a technology owner, security operations, enterprise risk, compliance, senior management, a board committee, internal audit, and external examiners. Separate the roles by asking who owns the objective and risk, who operates the control, who monitors and challenges management, and who independently assures the board.
Start with the responsibility
A title may not reveal the line. Examine authority, reporting, decision rights, operational duties, and independence.
02 IT Audit: Independent Assurance
IT audit applies internal audit's systematic, disciplined, independent, and objective approach to technology-related governance, risk management, and controls. It may evaluate governance, system development, access, vulnerability management, resilience, data, third parties, architecture, operations, and the quality of first- and second-line work.
The independence test
Internal audit may advise, but it should not own management decisions, operate controls it later audits, or accept risk for management.
03 Technology Risk: Management and Oversight
First-line business and technology management own objectives and manage risks created by their systems, processes, vendors, and decisions. Second-line roles provide specialized expertise, frameworks, monitoring, aggregation, challenge, and escalation without taking over management's ownership.
Effective challenge asks
- Is the risk clearly defined and connected to an objective?
- Are the scope, population, data, criteria, and assumptions reliable?
- Does the control address the risk, and is the evidence sufficient?
- Is the remaining exposure within appetite or tolerance?
- Has the right decision-maker accepted or escalated the risk?
04 Cybersecurity: Operations and Oversight
Cybersecurity is a domain of outcomes and capabilities, not one fixed line. NIST CSF 2.0 organizes outcomes under Govern, Identify, Protect, Detect, Respond, and Recover. Operational security teams may perform many of those activities; second-line specialists may monitor and challenge them; internal audit may independently assess the full program.
Clarify “oversight”
Board oversight, management oversight, second-line challenge, and third-line assurance are different responsibilities. Name the responsibility rather than relying on the word.
05 The Three Lines Model
Governing body and senior management
Set purpose, risk appetite, expectations, authority, resources, and accountability and oversee the pursuit of objectives.
First line — management and operations
Own and manage risk; design and operate processes and controls; make decisions; maintain evidence; remediate deficiencies.
Second line — support and specialized roles
Provide expertise, frameworks, advice, monitoring, challenge, aggregation, and escalation. Their assurance is generally less independent than internal audit.
Third line — internal audit
Provides independent and objective assurance over governance, risk management, compliance, and control processes and may advise without assuming management responsibility.
06 Ownership, Oversight, and Assurance
- Risk owner: accountable for managing a defined risk and making or escalating the response decision.
- Control owner: accountable for control design, implementation, operation, evidence, maintenance, and correction.
- Second-line overseer: reviews the quality of management's risk process, monitors exposure, challenges conclusions, and escalates.
- Internal auditor: independently assesses adequacy and effectiveness against defined criteria and communicates supported conclusions.
07 Evidence-Based Review and Challenge
A strong challenge connects the objective, risk, criteria, control, scope, evidence, conclusion, decision authority, and follow-up action. For critical vulnerability remediation, first line identifies and remediates exposure, second line challenges the completeness and quality of the response, and internal audit independently evaluates the overall framework and its performance over the audited period.
Evidence before opinion
Strong challenge tests completeness, accuracy, timeliness, lineage, consistency, relevance, and the decision rights behind the conclusion.
08 Governance Connects the System
Governance establishes objectives, authority, appetite, policies, thresholds, reporting, escalation, assurance coverage, and corrective-action expectations. Coordination should reduce duplication and close gaps without erasing the independence needed for credible assurance.
09 Common Misconceptions
- Cybersecurity does not automatically own every cyber risk decision.
- Second line is not simply another internal-audit team.
- Internal audit may advise when it preserves objectivity and avoids management responsibility.
- The lines describe responsibilities, not department names.
- More review activity does not automatically produce better assurance.
- A control passing does not by itself make residual risk acceptable.
10 ORC Insights
ORC Insights provides free educational resources about IT audit, technology-risk management, governance, internal controls, cybersecurity oversight, regulatory developments, administrative processes, and related professional topics. The principal is a licensed Barrister in Nigeria and a CISA-certified professional with more than a decade of experience in the U.S. banking and capital-markets industry, including over five years in internal IT audit and current work in second-line cyber and technology-risk oversight.
The founder is not licensed to practice law in North Carolina or any other U.S. state. ORC does not provide U.S. legal advice or representation. No current or former employer sponsors, endorses, or is affiliated with ORC.
Official Sources & Further Reading
Sources revalidated for publication on August 12, 2026. Recheck the current official sources before relying on standards or guidance.
- The IIA — Three Lines Model: Assurance and Advice in Support of Effective Governance (2026) Current principles-based description of first-line management, second-line support, monitoring and challenge, third-line independent assurance, board oversight, coordination, and independence.
- The IIA — Global Internal Audit Standards Current standards for internal-audit purpose, independence, objectivity, governance, engagement work, conclusions, and follow-up.
- The IIA — Cybersecurity Topical Requirement Effective February 5, 2026; establishes a minimum baseline for internal-audit assessment of cybersecurity governance, risk management, and control processes.
- NIST Cybersecurity Framework (CSF) 2.0 High-level cybersecurity outcomes organized under Govern, Identify, Protect, Detect, Respond, and Recover; the framework does not prescribe one implementation method.
- NIST SP 800-39 — Managing Information Security Risk Organization-wide approach to framing, assessing, responding to, and monitoring information-security risk as part of broader enterprise risk management.
- NIST SP 800-37 Rev. 2 — Risk Management Framework Structured, flexible process for security and privacy risk, control selection and implementation, assessment, authorization, continuous monitoring, and accountability.
- NIST CSRC Glossary — Control Terminology support for controls as measures, processes, policies, practices, devices, or other actions that modify risk.
Publication ID: ORC-INS-001 · Version 1.0 · Published August 12, 2026 · Next scheduled review: August 2027, or earlier after a material change to the cited standards, frameworks, or ORC scope
Learn, Organize, Advance
Roles clarified. Responsibilities separated.
Explore more free ORC Insights or suggest a general IT audit, technology-risk, governance, or cybersecurity-oversight topic for a future article.