Hi everyone,
I’m Tim Buckley, and this is the weekly Beyond the Lines™ newsletter.
Beyond the Lines™ is an internal-audit-led platform for people working across audit, risk, controls, governance and culture who want to turn insight into better decisions, clearer ownership and stronger outcomes in a Human + AI world.
Less control theatre. More decisions, ownership and outcomes.
Modernising the Three Lines without creating more bureaucracy
The first Leadership Signals webinar took place last week, and I’m so pleased with how it went. We had a huge sign-up rate and turnout, so I’d just like to say thank you to everyone that attended, it is very much appreciated.
The recording is now available to watch back, and it feels like the right place to start this weeks edition.
The session was with Kristian Bollerup, VP Corporate Risk and Internal Audit at The LEGO Group, and the topic was one I think a lot of people in audit, risk, controls and governance will recognise immediately:
How do you modernise the Three Lines at scale without creating more bureaucracy for the business?
That question matters because most organisations do not struggle with the Three Lines model in theory. On paper, it usually makes sense. The business owns risk. Risk and compliance functions support, oversee and challenge. Internal audit provides independent assurance.
The difficulty is what happens when that model meets the reality of a large, complex organisation.
Different teams ask for similar evidence. Different functions look at the same issue through different lenses. The same process owner explains the same problem multiple times. Internal audit, external audit, risk, compliance, controls, regulators and leadership all need information, but the business experiences that demand as one cumulative burden.
That is where the Three Lines can start to create friction rather than clarity.
You can watch the full replay here:
The main lesson: the model is not the problem. The operating rhythm is.
One of the strongest messages from the conversation was that modernising the Three Lines is not about abandoning structure.
It’s about making the structure work better.
That distinction matters. There is a temptation in some organisations to respond to friction by adding more governance. Another forum. Another reporting layer. Another coordination meeting. Another template. Another escalation route.
But if the underlying problem is duplication, unclear ownership or poor handoffs, more governance can simply make the model heavier. It may create the appearance of control, while making the business slower and less clear on who actually owns what.
The better question is not “how do we coordinate more?”
It’s:
How do we create clearer ownership, better assurance coverage and stronger decisions with less friction for the business?
That is very much where Beyond the Lines™ sits. BtL is internal-audit-led, but not audit-siloed. The focus is helping current and aspiring internal audit leaders lead Internal Audit Transformation in a Human + AI world, while recognising that modern assurance only works when it connects properly with risk, controls, governance, culture and the business.
The Three Lines is a perfect example of that. Internal audit cannot be effective if it sits in isolation. But it also cannot create value if independence and ownership become blurred.
The work is in the balance.
1. Duplication isn’t just annoying. It’s a warning signal.
A very practical point from Kristian was to listen for friction in the business.
When people complain about repeated evidence requests, it’s easy for assurance teams to treat that as resistance or fatigue. Sometimes it is. But often, it is useful data.
It may be telling you that multiple functions are asking similar questions without knowing what others have already asked. It may be telling you that the same control evidence is being repackaged for different teams. It may be telling you that the business is spending more time servicing assurance activity than responding to the underlying risk.
That’s not a small operational irritation. It’s a signal that the assurance model may not be working properly.
Common symptoms include:
the same process owner explaining the same issue several times
the same evidence being requested in different formats
assurance teams not knowing what other assurance teams have already covered
multiple functions testing similar areas without a shared view of coverage
unclear ownership between management, risk, controls, compliance and internal audit
too much time spent producing artefacts and not enough time improving decisions
The business does not experience these things as separate, well-intentioned requests from separate teams. It experiences the total demand.
That is why duplication matters.
It damages trust. It creates fatigue. And, perhaps most importantly, it pulls attention away from the risk itself.
A mature assurance model should not just ask whether each individual function is doing its job. It should ask whether the combined effect of all assurance activity is helping the business understand risk, own action and make better decisions.
2. The lines should be clear, but they should not become walls.
There is a phrase that kept coming back to me after the session:
Keep the lines clear, but do not let them become walls.
The Three Lines still needs role clarity. That has not changed. The business must own risk. Second-line functions must support, guide, monitor and challenge. Internal audit must retain objectivity and provide independent assurance.
But role clarity should not become functional isolation.
In practice, the problems often start when each function designs its work around its own needs rather than the reality of the business. Internal audit has its plan. Risk has its reporting cycle. Compliance has its obligations. Controls teams have their testing requirements. External audit has its evidence needs.
All of that may be reasonable when viewed separately. But when viewed from the business side, it can feel like a badly coordinated system.
This is where internal audit leaders have an opportunity to show real leadership.
Not by owning everyone else’s work.
Not by becoming the coordinator of all governance activity.
But by helping the organisation see where assurance is duplicated, where gaps exist, where ownership is unclear and where better handoffs would improve the quality of insight reaching leadership and the audit committee.
That is a more valuable role than simply adding another report into the system.
3. Integration does not mean ownership transfer.
One of the most important distinctions in the webinar was the difference between integrated work and transferred ownership.
Kristian talked about bringing risk management and internal audit closer together in a practical operating model. Done well, that can make sense. It can reduce duplication, improve visibility and help the business get more joined-up support.
But it does not mean the business stops owning risk.
That point is critical.
A central risk, controls or audit function can help the business identify risks, develop criteria, assess exposure, improve reporting, challenge responses, highlight gaps and support better conversations with leadership. All of that can be valuable.
But it should not quietly become the owner of management’s risk.
That is where modernisation can go wrong. The central team becomes more involved. The business becomes more dependent. Management starts waiting for the framework, the challenge, the report, the meeting or the committee paper before taking action.
Over time, what was meant to strengthen ownership can weaken it.
A modern Three Lines model should make management ownership more visible, not easier to avoid.
A useful test is this:
After our involvement, is ownership clearer than it was before?
If the answer is no, the function may be helping in the short term while creating dependency in the long term.
4. Federated support can work, but only with guardrails.
The session also explored the value of a federated model.
This is the middle ground between leaving the business entirely alone and centralising risk ownership too heavily.
In a federated model, a central function provides structure, oversight, challenge and support, while the business retains day-to-day ownership. Where the business is progressing well, the central team does not need to intervene heavily. Where progress is weak, unclear or too slow, the central team can step in more actively to help sharpen planning, improve reporting and move the issue forward.
That approach can be very effective. It recognises that some parts of the business need more support than others. It also avoids the false purity of saying, “the first line owns risk, therefore we just leave them to it.”
But it only works if the guardrails are clear.
People need to understand when the central team steps in, what role it is playing, what it will and will not decide, when ownership remains with the business, and how independence is protected where internal audit is involved.
This is especially important for internal audit leaders.
If internal audit is operating close to risk management activity, the function needs to be explicit about its role in each interaction. Is it advising? Supporting? Facilitating? Challenging? Auditing?
Those are different capacities, and stakeholders need to understand the difference.
The audit committee also needs to understand the model. It is not enough to say independence is protected. The committee needs confidence that the guardrails are real, understood and consistently applied.
The simple rule is:
If you move the lines closer together, you need to work harder to protect clarity.
5. Assurance mapping is more than a diagram.
One of the most practical tools discussed was assurance mapping.
I think this is where many organisations have a real opportunity, because assurance mapping is often either missing, too theoretical or treated as a static document.
Used well, it can be much more powerful than that.

A good assurance map helps leadership, executives and audit committees understand which functions provide oversight or assurance over the organisation’s most important risks. It shows where coverage is strong, where effort is duplicated, where gaps exist and where ownership is unclear.
But the value is not the map itself.
The value is the conversation the map enables.
A good assurance map should help leaders ask:
Are we getting assurance over the risks that matter most?
Are multiple teams testing the same area while other risks are under-covered?
Are we giving the audit committee comfort in areas that are already heavily assured?
Where are we exposed?
Where is the business unclear on ownership?
Where do we need resilience rather than false comfort?
What decisions should this assurance activity support?
That final point is important.
Assurance mapping should not just show activity. It should improve the quality of leadership attention.
For internal audit leaders, this is where the conversation becomes board-relevant. The audit committee does not need a beautifully formatted map for its own sake. It needs a clearer view of assurance coverage, gaps, overlaps, ownership and decision points.
That is how assurance mapping becomes useful.
Not as a compliance artefact.
As a decision tool.
6. Technology can reduce friction, but it will not fix unclear ownership.
Technology came up in the session as an enabler, and rightly so.
A good GRC or assurance platform can help reduce repeated evidence requests. It can provide a shared view of risk, controls, issues, evidence and assurance activity. It can make it easier for teams to reuse evidence and avoid asking the business for the same thing multiple times.
But technology is not the whole answer.
If the model underneath is unclear, technology will only digitise the confusion.
A tool cannot decide who owns the risk. It cannot decide what evidence matters. It cannot explain why evidence is being requested. It cannot resolve unclear handoffs. It cannot make management take accountability.
Before organisations invest heavily in tooling, they should be able to answer some basic questions:
What evidence do we need?
Who needs it?
Why do they need it?
How will it be used?
Could one evidence set serve multiple purposes?
Who owns the underlying risk, control or action?
What decision should this support?
If those questions are not clear, the platform may look more efficient while the operating model remains messy.
This is particularly relevant in a Human + AI world. AI and technology can speed up the mechanics, organise information and reduce manual effort. But humans still need to validate the output, protect judgement and decide what the work is actually for.
AI drafts. Humans decide.
Technology organises. Humans validate.
Systems can reduce friction. Leaders still need to design the model.
7. The real test is better decisions.
Perhaps the strongest point from the whole discussion was this:
The goal is not better coordination. The goal is better decisions.
That is a subtle but important distinction.
Coordination is useful. Fewer repeated requests are useful. Cleaner handoffs are useful. Better assurance maps are useful.
But none of them are the final outcome.
The final outcome is that leaders get better information, ownership becomes clearer, risks are escalated earlier, issues are resolved faster, and the board or audit committee has a clearer view of where attention is needed.
If a Three Lines model is better coordinated but still does not improve decision-making, it is not mature. It is just tidier.
Signs of progress include:
better-quality information reaching leadership faster
clearer ownership of risks, issues and actions
fewer duplicated assurance activities
more focused audit committee conversations
better visibility of assurance gaps and overlaps
stronger resilience planning where risks cannot be fully controlled
faster movement from insight to action
This is the shift internal audit leaders should be leaning into.
The future of internal audit is not simply better audit execution. It is helping the organisation turn insight into decisions, ownership and outcomes.
That does not mean taking over management’s role. It means creating sharper visibility, stronger challenge and better decision support while protecting independence.
That is where internal audit becomes more board-trusted.
Do this Monday
Pick one area where assurance friction is visible.
Do not try to redesign the whole Three Lines model in one go. Start with one process, one risk area, one business function or one recurring evidence request that everyone knows is painful.
Then ask:
Who is asking the business for evidence?
What evidence are they asking for?
Why do they need it?
Is another function already asking for something similar?
Could the same evidence serve more than one purpose?
Could we agree one format or shared repository?
Who owns the underlying risk, control or issue?
What decision should this assurance activity support?
That last question matters most.
It moves the conversation away from “how do we coordinate activity?” and towards “how do we create useful assurance that improves decisions?”
That is the practical work.
Reflection questions for internal audit, risk & controls leaders
If you are a internal audit, risk or controls leader, this session raises some useful questions:
Is internal audit duplicating requests already made by risk, compliance, controls or external assurance providers?
Is your audit, risk or controls plan clearly linked to strategic risks and business priorities?
Do stakeholders understand when you are providing assurance versus advice or support?
Do you have a clear view of assurance coverage over the risks that matter most?
Are you using assurance mapping to improve audit and risk committee conversations?
Are audit and risk insights feeding back into strategic thinking?
Are your reports helping leaders make better decisions, or mainly documenting completed work?
These are the questions that move audit, risk and controls from activity to influence.
Final word
Modernising the Three Lines is not about creating a new model because the old one sounds outdated.
It is about making governance work better in the real world.
The best models create clarity without bureaucracy. They help the business understand and own risk without letting central functions take over. They protect independence without hiding behind silos. And they turn assurance into something that improves decisions, ownership and outcomes.
That is the purpose of the Beyond the Lines™ Leadership Signals series: practical conversations with experienced leaders about how internal audit, risk, controls and governance can work better in practice.
And if you found this useful, please share it with one audit, risk or controls leader who is trying to reduce friction and create more decision-ready assurance.
Best,
Founder Beyond the Lines™ | Integral Assurance
Useful BtL resources
If this edition was useful, I also share free practical resources, including tools on stakeholder influence and AI defensibility. These are designed to help you move from insight to traction.
ChatGPT gives you generic answers because you give it generic prompts.
You know the fix: longer prompts, more context, clearer constraints. But typing all that takes five minutes per prompt, so you shortcut it. Every time.
Wispr Flow lets you speak your prompts instead of typing them. Talk through your thinking naturally — include context, constraints, examples — and get clean text ready to paste. No filler words. No cleanup.
Works inside ChatGPT, Claude, Cursor, Windsurf, and every other AI tool. System-level, so there's nothing to install per app. Tap and talk.
Millions of users worldwide. Teams at OpenAI, Vercel, and Clay use Flow daily. Free on Mac, Windows, and iPhone.




