The IIA’s 2026 Three Lines Model: What It Misses in Nigerian Board Governance

The Institute of Internal Auditors has rewritten the Three Lines Model and pointed it at boards. For Nigerian directors, the more useful reading is not what the model says, but what it leaves for them to decide.


The most consequential change in the Institute of Internal Auditors’ (IIA) 2026 Three Lines Model is not a word in the model. It is where the IIA filed the document. The 2013 and 2020 releases were Position Papers written for internal auditors. The 2026 release is a Statement of Position, “Assurance and Advice in Support of Effective Governance,” placed deliberately outside the International Professional Practices Framework and, in the IIA’s own words, intended for “an executive audience, rather than primarily for internal auditors.” The audience has changed. For a Nigerian board, that should register before any debate about lines and roles begins, because it means the IIA is now speaking to you directly, and having done so, it leaves the first of several questions unanswered: in a governance structure like Nigeria’s, which committee owns the assurance it wants coordinated?

This article works through what the model misses for a Nigerian board: a second line drawn too loosely to be useful, an integrator role that strains internal audit’s independence, and, above all, the committee that should own integrated assurance and is never named. The recommendation, in one line: use the 2026 model to fix ownership of assurance, not to redraw the committee structure you already run.

Start with the structure, because it is the fact that makes this model land differently in Lagos than in London.

The Nigerian board does not have one oversight body: It has three

A Nigerian public company does not oversee its three lines through a single board or a single committee. It does so through a layered structure that the 2026 model does not contemplate. Section 404 of the Companies and Allied Matters Act 2020 (CAMA) requires every public company to establish a Statutory Audit Committee of five members: three shareholder representatives and two non-executive directors, elected annually, all financially literate, with at least one of them a member of a professional accounting body established by an Act of the National Assembly. That is an audit committee with shareholders sitting on it, elected on the floor of the annual general meeting. It has few parallels internationally.

Above and besides, it sits the Nigerian Code of Corporate Governance 2018 (NCCG), issued by the Financial Reporting Council of Nigeria. Principle 11 directs the board to delegate to well-structured committees without abdicating its own responsibility, and it recommends four: nomination and governance, remuneration, audit at Principle 11.4, and risk management at Principle 11.5. The Board Audit Committee under Principle 11.4 is a separate body from the Statutory Audit Committee that CAMA mandates; the Code says so expressly. The Code permits a company to combine these committees where its size and needs justify it, but the position it recommends is separation. Sector codes add further obligations: banks, insurers and pension fund operators each carry their own committee requirements, and the code for licensed pension operators mandates a risk management committee outright.

So, a listed Nigerian company may run a Statutory Audit Committee under CAMA, a Board Audit Committee under the NCCG, and a Risk Management Committee under the NCCG, each with a different composition, a different mandate, and a different reporting line. The IIA’s 2026 model collapses all of this into one defined term. It uses “board” to mean the board and any of its committees and notes only that the board may delegate to a committee “such as an audit committee.” That is a reasonable simplification in a jurisdiction with one unitary board committee for assurance. It is a material omission in ours.

What the model became, and why

The evolution is worth stating plainly, because each version was built to do a different job, and each should be judged against its own purpose rather than against the latest one.

The 2013 Position Paper, “The Three Lines of Defense in Effective Risk Management and Control,” was a control map bred in financial services. It named the second-line functions without ambiguity: financial control, security, risk management, quality, inspection, compliance. It achieved its stated aim, which was to explain internal audit and its relationships. It then suffered the fate of useful diagrams. Organisations adopted it as a rigid governance structure, which its own authors say was never meant to be.

The 2020 update dropped “of Defense,” reframed the model around creating and protecting value, and introduced “governing body” as the single point of accountability, removing an ambiguous layer of senior management that had sat between internal audit and the board. It moved from six principles built on named functions to principles built on roles. Its intent was partly achieved. The language landed. The rigidity eased. But once the named second-line functions disappeared, the second line began to blur.

The 2026 Statement of Position extends that blurring and reorganises everything around a new spine: the distinction between assurance and advice. It cuts to five principles. It reframes independence as a continuum and warns that independence should not harden into isolation. It casts the internal audit function as the integrator of assurance across the organisation. And it adds something the earlier versions lacked: practical safeguards for the messy reality of overlapping roles, including a twelve-month interval between owning a process and providing assurance over it, and explicit board approval where a chief audit executive’s remit expands.

That last contribution is the real one. As a conceptual model it is weaker than 2020, not stronger, because the second line is now drawn so loosely it will not hold, a failure addressed below. The operational guidance, by contrast, is genuinely new.

The value to the board is real, but narrower than advertised

The 2026 model does not strengthen a Nigerian audit committee’s hand. It does something more specific. By re-pointing the document at boards and executives, the IIA gives directors a plain-language account of where assurance comes from and why independence matters. That is useful to a Statutory Audit Committee whose shareholder members may not be career governance professionals, and it is useful to a Board Audit Committee weighing how much to rely on management’s own monitoring.

But the model does not expand the audit committee’s role, and any article claiming it does has misread it. The absence of an expanded audit committee mandate is not an oversight the IIA forgot to correct. It is a deliberate silence. The model declines to allocate oversight to any committee at all: a silence that bites wherever assurance oversight is split across more than one committee, as it is across much of the continent.

The question the model should have answered

Here is the gap, and it is sharper in Nigeria than in jurisdictions built around a single audit committee. The 2026 model’s headline is coordination: someone must receive the integrated view, hold the assurance map: the single picture of who assures which risks and arbitrate when the second and third lines disagree. The model champions that coordination and never names the coordinator.

In the Nigerian structure, that owner is not the audit committee. The Statutory Audit Committee is tied by CAMA to financial reporting and the external auditor; the Board Audit Committee’s centre of gravity is internal control and internal audit. Risk Management Committee mandates in Nigeria vary, and some are thin, but where a company runs one with real authority, its remit is the closest fit for integrated, forward-looking, enterprise-wide assurance. That is the committee the 2026 model never mentions, because it never descends below the word “board.”

That the audit committee’s remit is expanding is not in dispute. The debate over audit committee overload and whether risk oversight should move to a dedicated risk committee is well established internationally, though it is framed for boards weighing whether to create such a committee at all.

RSM’s review of audit oversight describes the pattern: as audit committees absorb cyber, sustainability and technology risk, boards carve that load off into a dedicated committee to protect the committee’s core work. Nigeria sits a step past that debate: its Code already recommends a Risk Management Committee at Principle 11.5 but has not given it the mandate so the question is not whether to create the committee, but whether to finish the job.

So, the correct question is not whether the audit committee’s role should expand. It is whether the Risk Management Committee’s role should be strengthened to own the integrated assurance agenda the IIA now promotes, and whether Nigerian boards should give it that mandate explicitly rather than leave integrated assurance homeless between three committees. They should, and the model’s silence is an argument for doing it deliberately rather than waiting for the IIA to do it for them.

Where the 2026 model contradicts itself

A document written for boards should resolve its own tensions. This one defers them: it is, in its own words, “applied using professional judgment,” and it leaves at least three tensions for the reader to reconcile. Because the board defines roles, but the chief audit executive operates the overlaps, those tensions fall in practice to internal audit which is precisely where a board-facing document should not put them.

First, the model’s stated purpose is role clarity, yet it has made its own middle line impossible to define. Having removed every named example, it describes the second line as roles providing “specialized expertise, support, monitoring, and challenge.” As Norman Marks observed on 13 July 2026, that definition sweeps in finance, information security, corporate security, and arguably senior management itself. A model built for clarity has made its second line unfalsifiable. The fix is modest: restore an illustrative, non-exhaustive list, or define the second line by a test, that it advises and challenges but does not own the control, rather than by a string of adjectives.

Second, the model treats independence as a continuum and encourages blended roles and chief-audit-executive supervision of second-line functions to reduce duplication, then states flatly that assurance cannot be credible where the reviewer designed or operated the process. Both propositions are correct. Presented in the same neutral register, they leave a board unsure whether the IIA is endorsing the blending or warning against it. The fix is to state the default, which is separation, and to treat blending as the exception that triggers the model’s own safeguards, rather than offering both as equivalent choices.

Third, the model asks internal audit to coordinate and consolidate assurance while avoiding ownership of second-line activities. Designing the assurance map and aligning methodologies, then auditing the framework you helped shape, is a self-review threat at the level of the framework itself. The fix is to cap the integrator role at facilitation and reporting, and to seat ownership of the assurance map with management or, in the Nigerian case, the Risk Management Committee.

The hardest objection, and why the model still earns its place

The strongest case against the 2026 model comes from Norman Marks, and it is fair to put it at its full strength. Marks concedes the second-line definition has improved, then asks the question that should worry the IIA: “What board or senior management action or decision does it change?” On the conceptual model, the point holds. Three lines, further diluted, changes no decision.

But the objection misses where the value moved. It did not stay in the diagram. It moved into the reclassification, which puts a governance document in front of the people who make governance decisions, and into the overlap safeguards, which do change decisions. A Nigerian board that reads the twelve-month rule and the requirement for explicit approval of an expanded chief-audit-executive remit has been given something to act on. That is not nothing. It is simply not in the part of the document most people will quote.

A note on independence

One caveat belongs to the record, because it runs through the subject rather than sitting beside it. The 2026 model tolerates a chief audit executive supervising second-line functions, and it tolerates internal audit designing, operating and later assuring the same framework, provided safeguards are in place. That is the classic self-review threat, and the safeguards do not remove it; they manage it. The sound default is separation: a party should not provide assurance over a framework it designed or operates. Where a board chooses to blend the roles, it should treat the model’s safeguards as the price of the exception, not the terms of the arrangement, and satisfy itself that an independent party assures the overlap for as long as it lasts.

What a Nigerian board should ask

Three things, then, the model leaves undone. It defines the second line as being too loosely to be useful. It hands internal audit an integrator role that strains its own independence. And it never says which committee owns the assurance it wants coordinated. The first two are the IIA’s to fix. The third is the boards.

So do not adopt the 2026 model as a structure. Adopt it as a prompt. Then answer the question it left open: of your Statutory Audit Committee, your Board Audit Committee, and your Risk Management Committee, which one owns the integrated view of assurance, holds the assurance map, and resolves conflicts between your second and third lines? If the honest answer is that no committee owns it, the model has done its most useful work simply by exposing the vacancy. Fill it on purpose.


Source: Norman Marks, “Is Risk Management a 2nd line function in the updated Three Lines Model?”, writing on his personal governance blog, 13 July 2026. https://normanmarks.wordpress.com/2026/07/13/is-risk-management-a-2nd-line-function-in-the-updated-three-lines-model/

Source: On audit committee overload and the case for moving risk oversight to a dedicated risk committee, see RSM US, “Audit oversight in 2024” (a Corporate Board Member roundtable in partnership with RSM, 10 January 2024), and, for the independent view, “Are Audit Committees Overloaded?” (Columbia Law School Blue Sky Blog, 2019).

RSM article: https://rsmus.com/insights/services/audit/audit-oversight-in-2024.html

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *