Skip to main content

Three lines model

A governance framework in which the first line (operations/business) owns and manages risk, the second line (compliance/risk) provides oversight and monitoring, and the third line (internal audit) provides independent assurance; the AI compliance function most commonly sits in the second line for deployer organizations.

Defined in 3 GAGE programs, which carry 3 distinct definitions of it. The wording above is taught in EU AI Act Implementation Expert.

How each discipline defines it

The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.

EU AI Act Implementation Expert

A governance framework in which the first line (operations/business) owns and manages risk, the second line (compliance/risk) provides oversight and monitoring, and the third line (internal audit) provides independent assurance; the AI compliance function most commonly sits in the second line for deployer organizations.

Certified AI Governance Professional (CAIGP)

The Institute of Internal Auditors' July 2020 update to its earlier Three Lines of Defense framework, renamed to emphasize supporting sound decision-making alongside defensive risk management, while preserving the same structural separation between owning, validating, and auditing a risk.

Certified AI Practitioner: Workplace Foundations

The structure (first line: business units; second line: risk and compliance; third line: internal audit) that management runs to produce and assure AI risk information, which the board receives but does not operate.

Where it is taught

The exact lessons this term appears in. The first module of every program is free with a free account.

Terms it appears with

Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.