Office of the Inspector General
Theory and Practice: Application of the Three
Lines of Defence (3LoD)

A Public Sector Approach

Applying Three Lines of Defence
• Public Sector Particularities and Context
• Engaging Stakeholders
• Assurance Mapping
• Benefits and Lessons for Internal Audit

Why Consider 3LoD?
• Opportunity to engage with management on

Why Consider 3LoD?

• Provide an integrated view of organizational
assurance and its governance

Why Consider 3LoD?

Enhance and elevate internal audit’s role as a
strategic partner

What is the 3LoD Model?

Public Sector Particularities for 3LOD

• High degree of variation in second lines
Ø May be specialized oversight processes
Ø Varying degrees of maturity
• Can be multiple players in the third lines
Ø Evaluation, Investigation…
• Assurances outside the three lines

Unique Governance Structures
• Governance is a critical element of the 3LoD
• Variety of public sector governance structures
and actors
• Consider changing political directions and
public perceptions

Risk and Control Environments
• Control systems with redundancies,
bureaucracy, lack of integration, silos
• Complex service delivery, programs
operating in high risk environments
• Focus on reputational risk
and stewardship


Contextual Drivers for 3LOD
• Organizational change or restructuring
• New external or regulatory requirements
• Clarify oversight roles
• Need for something better…more


Variety of Approaches for IA
• Use 3LoD in dialogue with stakeholders
• Partnership with management oversight
• Incorporate into individual audits
• Imbed strategically in IA practice
• Lead role in an advisory


How to engage Stakeholders?
• Identify Stakeholders
Ø Users of assurance information
Ø Providers of assurance
• Classify Stakeholders
Ø Varying levels of interest, engagement
and involvement
Ø Who will you need to work closely with?


Plan for Stakeholder Engagement


Assurance Mapping
Portrays the results 3 LOD approach


Pulling it together…
• Complexity – importance of the basis to draw
the assurance map
• Reliance on second line of defence
• Diverse operations – need to develop a
common approach
• Align assurance to strategy and risk appetite


Identify a framework
• Corporate Risks
Ø Can miss many key assurance
• Business Process or Functional Area
Ø Provides overall coverage
Ø Commitment of time and effort
• Selected Areas or Programmes
Ø Focus on critical,
changing business

Identify Assurance Processes
• 3LOD can provide a simple framework
Ø Focus on key assurance processes that
support organizational objectives


How to assess strength or maturity
• Maturity model theory is highly useful
Ø Use a scale, generally 5 points that defines
how maturity will be assessed


Assessing Results
• 3LoD can provide a simple framework to
portray an assurance map


Practicalities of Assurance Mapping
• Build on IA’s existing knowledge
• Engage with management to confirm and
gather missing information
• Will you assess maturity and if so – how?
• To what extent will oversight processes be
• Other projects may be useful or necessary


Remember…Importance of Context
• What is driving a change in organizational
approach to assurance?
• What strategies and areas are already
aligned with 3LOD?
• Who are the key stakeholders?
• How does size, complexity and management
structure affect organizational assurance?


Lessons from Application
• Gaps and Overlaps - views can be
• “Traffic” in high risk areas - may be
• A common framework and means to assess
assurance is highly useful
• There will likely be other areas to explore,
particularly within the 2LODs


How can it be adopted by IA?
• Imbed in IA strategy and planning
Ø Redefine the audit universe
• Clarify IA involvement in 2LoD activities.
• Staff training and use
in individual audit
• Audits or advisories on
2LoD processes


Communicating with Stakeholders
• Enhanced understanding of oversight and
assurance processes
• Cultural shift in ownership of “assurance”
• Better coordination and cooperation


Organizational Assurance
• Align assurance and oversight to
organization strategy and risk appetite
• Opportunity to validate and strengthen key
oversight processes.
• Better governance
of assurance processes
and actors
• Greater efficiencies


Value Added to Internal Audit
• Engagement with Stakeholders as a Trusted
• Focus on foresight – align assurance with
strategy and risk appetite
• Ability to deliver more
cost effective and
coordinated assurance


Thank you for
your attention
World Food Programme
Office of the Inspector
General OIG

5-9 September 2016

