Blog

"Independence Does Not Imply Isolation." The IIA Just Put That in Writing.

Subscribe now to join the Risk Register community:

The Institute of Internal Auditors released two updated Statements of Position in July 2026, one on the Three Lines Model and one on internal audit's role in enterprise risk management. Anthony Pugliese, the IIA's President and CEO, framed the release plainly: internal auditors do more than provide assurance. They help their organizations understand risk more clearly and move with confidence.

We read both documents the day they came out. Our honest reaction: this is the clearest signal yet that the profession's center of gravity has moved from guarding the organization to helping it decide.

Confidence is a strategic asset. These updates finally treat it that way.

The Real Shift Is Coordination, Not a New Name

Let's clear up the one thing people will get wrong about this release. The IIA did not rename anything here. "Three Lines of Defense" became the "Three Lines Model" back in July 2020, when the IIA deliberately cut the word "defense" to stop framing risk as something you only build walls against. That argument is settled, and if you have been in the profession you had it years ago.

What is new sits one level deeper. The updated Statements of Position take the model almost everyone already adopted and sharpen how the three lines are supposed to work together. They describe a framework built for organizations of every size, structure, risk profile, and maturity level, and they do something practitioners have asked for over the years: they spell out the distinct value the board, management, and internal audit each bring, then explicitly call for coordination, collaboration, and reliance across those roles.

If you sit on an audit committee, read the two statements together rather than separately. The Three Lines paper explains the architecture. The ERM paper explains what internal audit actually does inside it.

This Is a Refinement of the Most Adopted Framework in the Profession

Here is why this deserves your attention rather than a skim. This is not a fringe proposal. In the IIA's 2024 North American Pulse of Internal Audit, 84% of organizations reported taking the Three Lines Model into consideration for governance. The model functions as a de facto standard, and a refinement to a standard ripples through every audit committee agenda in the country.

So when the IIA clarifies how the three lines should coordinate, that clarification lands in three places at once. It lands on the board and audit committee that set risk appetite and rely on assurance to govern well. It lands on management, who own risk in the first line and monitor it in the second. And it lands on the Chief Audit Executive, who now carries an explicit mandate to bring the enterprise-wide perspective together.

That last point hands CAEs both an opportunity and a test.

Independence Was Never Supposed to Mean Isolation

The most useful idea running through the Three Lines Model, and reinforced in these updates, fits in four words: independence does not imply isolation.

We have watched internal audit teams read independence as distance. They hold second-line risk and compliance functions at arm's length, communicate through formal reports, and sit on their observations until the audit closes. The intent is honorable. The result is a governance gap, because risk information stays trapped in silos while the organization makes decisions in real time.

The guidance takes a different stance. An effective internal audit function builds strong working relationships with first- and second-line colleagues and works collaboratively with them, while preserving the objectivity that makes its assurance credible. Coordination, collaboration, and reliance across the three lines strengthen risk coverage, improve the reliability of the information reaching the board, and support better decisions.

That reads like a mission statement for the next decade of the profession. Full stop.

Financial Services Already Ran This Experiment

Coordinated assurance sounds abstract until you watch it work, and financial services gives us the preview, because regulatory pressure forced those institutions to move first.

Audit leaders in banking report that all three lines have activated to connect their risk and control frameworks, taxonomies, and processes, encouraged by the tighter expectations around coordinated assurance. A meaningful share of those institutions now maintain a common risk taxonomy across the organization, which lets the three lines agree on which issues require escalation and which need only routine monitoring (IIA, 2026 research on internal audit and risk management synergy).

One detail from that experience stands out. The hard part was defining the value of connected risk for every stakeholder at the table, not the technical audit work. Getting the CRO, the compliance leader, the CFO, and the CAE to use the same language and trust each other's work takes deliberate effort. The IIA just handed you the authoritative document that makes that conversation easier to start.

The Funding Data Settles the Business Case

If you lead an internal audit function and you are weighing whether these updates deserve real investment, the money makes the call for you.

Internal audit functions fully aligned with strategic objectives hold a 31 percentage point funding advantage over functions that are only somewhat aligned, according to the 2025 North American Pulse of Internal Audit. Boards fund what they see as strategic. These Statements of Position give you the official framework for demonstrating that strategic role.

The same research shows where CAEs want to take their functions. Internal audit work today splits roughly 75% assurance and 25% advisory, and CAEs want advisory to reach 40%. The ERM Statement of Position matters here, because it draws the lines around what internal audit can advise on within enterprise risk management while keeping its assurance credibility intact.

Worth naming the tension honestly: the advisory ambition outpaces most teams' current bench. Risk expectations are growing faster than headcount, and chasing a 40% advisory mix with a team already stretched thin on core assurance creates its own governance gap. This is where specialized expertise you can rent per engagement, rather than hire permanently, becomes part of the plan. Senior co-sourced project support exists precisely so a function can expand coverage without carrying the fixed cost of a specialist it needs only a few weeks a year.

Where CAEs Can Start This Quarter

The updated statements are practical documents, and they reward practical responses. A few places we would start.

Brief your audit committee before they ask. Members will hear about these updates from somewhere, so bring them a one-page summary of what changed and what it means for your charter. Arriving first with the interpretation builds the credibility the profession keeps talking about.

Map your assurance coverage against the model. Lay out who provides assurance over each major risk across all three lines, and the gaps and overlaps surface fast. That map becomes the foundation for the coordinated assurance conversation the new guidance encourages.

Push for a common risk taxonomy. The financial services experience shows this is the unlock. Shared language across the lines makes escalation criteria clear and makes reliance on second-line work defensible.

Communicate like a CEO. Internal audit's influence has grown, and the functions that break through are the ones that sell their value across the organization rather than assume the work speaks for itself.

Decide where you need depth you do not have. Enterprise risk now runs through cybersecurity, AI governance, fraud, and technology risk, and few teams can staff all of it deeply. Name the gaps honestly, then plan for specialized support on the projects that demand it. Your team stays focused on its core mission while the coverage expands.

From Periodic Oversight to Ongoing Insight

Step back from the documents and a larger pattern comes into focus. The profession is moving from periodic oversight to ongoing insight, connecting audit findings back to the broader risk framework and giving leadership a view of what could be coming next. These Statements of Position give that movement its official architecture.

The organizations that treat this release as a filing exercise will get a filed document. The ones that use it as a forcing function for coordinated assurance, shared taxonomies, and a genuinely strategic internal audit function will get something more valuable: a governance system that helps them take intelligent risks with confidence.

The next disruption is already forming somewhere, in a technology shift, a regulatory change, or a risk nobody has named yet. When it arrives, the three lines that learned to coordinate will see it earlier, understand it faster, and respond with confidence. 

If your function needs senior bench strength to close the coverage gaps before then, that is the kind of work our team co-sources alongside internal audit, never in place of it. The readiness is there for any organization willing to do the work now.

Until next time.

Subscribe now to join the Risk Register community:

Nk it'